<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0" 
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">

<channel>
<title>The Professional Security Testers Warehouse for the CEH V7 GPEN CPTS CREST GCIH GREM OPST</title>
<link>http://www.professionalsecuritytesters.org</link>
<description>You need more than tools to defeat the adversary!</description>
<dc:language>en-us</dc:language>
<dc:creator>admins@cccure.org</dc:creator>
<dc:date>2012-05-17T14:22:19-04:00</dc:date>

<sy:updatePeriod>hourly</sy:updatePeriod>
<sy:updateFrequency>1</sy:updateFrequency>
<sy:updateBase>2012-05-17T14:22:19-04:00</sy:updateBase>

<item>
<title>Webcast: Penetration Testing - Not Just For Networks Anymore</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1379</link>
<description><![CDATA[<p><br>
<div>
<table border="0" cellspacing="0" cellpadding="0">

<tr>
<td align="center" valign="top">
<table border="0" cellspacing="0" cellpadding="0">

<tr>
<td rowspan="2">
<table border="0" cellspacing="0" cellpadding="0">

<tr>
<td>&#160;</td>
</tr>

</table>
</td>
<td>
<table border="0" cellspacing="0" cellpadding="0" width="100%">

<tr>
<td>&#160;</td>
<td>&#160; &#160;</td>
<td><img src="https://app.marketo.com/images/public-site/email/cornerNE-white.png" alt width="9" height="21"><br></td>
</tr>

</table>
</td>
<td rowspan="2">
<table border="0" cellspacing="0" cellpadding="0">

<tr>
<td>&#160;</td>
</tr>

</table>
</td>
</tr>
<tr>
<td>
<table border="0" cellspacing="0" cellpadding="0" width="100%">

<tr>
<td><img src="http://ws.coresecurity.com/rs/coresecurity/images/Core_Security_tag.gif" border="0" alt="Core Security" width="200" height="80" align="right">
<div>You're Invited: Penetration Testing Webcast</div>
<div>
<p><strong>Penetration Testing - Not Just For Networks Anymore<em></em></strong></p>
<p><strong><em>Identifying Endpoint, End-User, Web, Mobile, Wireless (and Network) Vulnerabilities with CORE Impact Pro v12.3</em></strong></p>
</div>
<br>
<div>
<div><strong>Date:&#160;&#160;</strong>Wednesday, May 16, 2012<br></div>
<div><strong>Time:&#160;</strong>2pm US Eastern Time&#160;<br></div>
<div><strong>Host:</strong>&#160; Alex Horan, Senior Product Manager, and Jonathan Daly, Solutions Marketing Director<br></div>
<div><br><a href="http://ws.coresecurity.com/CoreIMPACTv12.3Webcast.html">&#62; Click here to register</a><br><a href="http://ws.coresecurity.com/CoreIMPACTv12.3Webcast.html">http://ws.coresecurity.com/CoreIMPACTv12.3Webcast.html</a></div>
<p>*** A recording of the webcast will be sent to everyone who registers, so be sure to sign up&#160;even if you can&#8217;t make the live session. ***</p>
<div>Please join CORE Security for a webcast demonstration of the newly released CORE Impact Pro v12.3. With first-to-market new capabilities including automated endpoint testing for certifying desktop images, it&#8217;s a great time to catch up on the most comprehensive commercial-grade vulnerability assessment and penetration testing software solution available.<br><br>We&#8217;ll highlight the latest features and provide an overview of the solution&#8217;s unmatched multi-vector testing capabilities for network, endpoint, end-user, web, mobile, and wireless environments. You&#8217;ll learn how to &#8230;<br>
<ul>
<li>Replicate multi-staged attacks that pivot across systems, devices and applications, revealing paths to your organization&#8217;s mission-critical systems and data</li>
<li>Demonstrate vulnerability severity by replicating how an attacker would compromise and interact with at-risk systems and data</li>
<li>Confirm exploitable vulnerabilities, illustrate the efficacy of defenses, and validate compliance with comprehensive reports</li>
</ul>
</div>
<p>*** A recording of the webcast will be sent to everyone who registers, so be sure to sign up even if you can&#8217;t make the live session. ***</p>
<p><a href="http://ws.coresecurity.com/CoreImpactv12Preview.html">&#160;</a><a href="http://ws.coresecurity.com/CoreIMPACTv12.3Webcast.html">&#62; Click here to register</a><br>&#160;<a href="http://ws.coresecurity.com/CoreIMPACTv12.3Webcast.html">http://ws.coresecurity.com/CoreIMPACTv12.3Webcast.html</a><br>&#160;</p>
<div>Best Regards,</div>
<div><br></div>
<div><strong>Jonathan &#8220;JD&#8221; Daly</strong><br>Director, Solutions Marketing<br>Core Security | 41 Farnsworth Street | Boston, MA 02210 | USA<br>Main:&#160;<a href="tel:617.399.6980">617.399.6980</a>&#160;|&#160; fax:&#160;<a href="tel:617.399.6987">617.399.6987</a><br><a href="mailto:jdaly@coresecurity.com">jdaly@coresecurity.com</a>&#160;|&#160;<a href="http://www.coresecurity.com/">www.coresecurity.com&#160;</a></div>
</div>
</td>
</tr>

</table>
</td>
</tr>

</table>
</td>
</tr>

</table>
</div>
</p>]]></description>
<guid isPermaLink="false">1379@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Web_App_Sec</dc:subject>
<dc:date>2012-05-10T20:08:42-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>ERPScan has released ERPScan Security Scanner for Sap 2.0</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1378</link>
<description><![CDATA[<p>As seen on the great&#160;<a href="http://www.net-security.org/">http://www.net-security.org/</a>&#160;web site:</p>
<p>ERPScan has released ERPScan Security Scanner for SAP 2.0 - a complex solution to continuously monitor all areas of SAP security, from vulnerability assessment and misconfigurations to ABAP code review and analysis of business-critical privileges.</p>
<p>One of the most significant changes is a new module which can make static analysis of ABAP code security. It makes ERPScan the only solution on the market which makes both security assessment of platform and code review.</p>
<p>The number of anonymous checks which can be performed in Penetration testing mode ha been significantly increased to help companies identify issues without using credentials in the system.</p>
<p>The new engine can help to perform audit and compliance checks not just through RFC - it allows making complete scan through the web-interface which is a great feature for external penetration tests and can make pen-testers' lives easier.</p>
<p>More new functions:</p>
<ul>
<li>Support of different web application types (bsp/iviews/jsp/webservices/webdynpro's)</li>
<li>More than 5000 different checks covering misconfigurations, vulnerabilities, access to web-applications; search for 50 different types of vulnerabilities in ABAP code</li>
<li>Elaborated black-box vulnerability assessment</li>
<li>Cataloguing of SAP systems and services</li>
</ul>
<p>&#160;</p>
<p><br>"Today, almost all critical operations like procurements, stock resources management, human resources management, financial reports and much more, and all the data related to them, are stored in SAP system. This is why the main target for an insider or an external attacker would be to gain illicit access to SAP with the purpose of malicious manipulation of company resources," says Alexander Polyakov, CTO of ERPScan.</p>
<p>"In spite of the increasing popularity of ERP systems security in the security community, companies are still vulnerable to cybercriminal and insider attacks. At this moment SAP has released more than 2000 Security notes closing various vulnerabilities, which is quite a lot, especially if you keep in mind that sometimes it is enough to get access to all business critical data through only one issue. An example was presented at BlackHat last summer. On the other side, almost every company develops custom ABAP code which can also have vulnerabilities and backdoors left by developers",</p>
<p>"SAP security assessment, according to our experience, usually takes quite a long time. Additionally, the complexity of the system and the large amount of different installation types require the participation of specialists from various fields of security. Even the application server may have either ABAP or Java platform, and they require completely different specialists, not to mention particular applications and modules. ERPScan allows you to significantly simplify the task of assessment by automating most of the ordinary checks, so you can pay more attention to the analysis of the customized part", he concludes.</p>
<p>You can see more info at: &#160;<a href="http://erpscan.com/">http://erpscan.com/</a></p>
<p>&#160;</p>
<p>&#160;</p>]]></description>
<guid isPermaLink="false">1378@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Web_App_Sec</dc:subject>
<dc:date>2012-04-28T03:10:22-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Hack In The Box Magazine Issue #8 has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1377</link>
<description><![CDATA[<p><a href="http://magazine.hackinthebox.org/issues/HITB-Ezine-Issue-008.pdf">Issue #8 is now available CLICK HERE to get it!</a></p>
<p align="justify">Hello readers and welcome to issue #8.</p>
<p>It's been a while since the release of the last issue and no, we are not dead yet.</p>
<p>First, some bad news - this issue has less goodies compared to all the previous issues :( but that's only because we've been busy preparing something really REALLY special for you before the world ends ;)</p>
<p>Yes, we are big fans of the ancient Mayans and since this will be the last ever HITB conference in their calendar, we are working extremely hard to make sure HITB2012KUL in Malaysia will be the biggest and baddest HITB conference... ever! Trust us when we say the pain of missing our 10th year anniversary event is beyond words!</p>
<p>In the meantime, please enjoy all the little things we've put together for you in Issue 008 and be prepared for some really juicy stuff coming to you later this year! Till then - keep on hacking!</p>
<p align="justify">Have fun reading this issue and more to come in issue #9!!</p>
<p align="justify"><a href="http://magazine.hackinthebox.org/issues/HITB-Ezine-Issue-008.pdf">Issue #8 is now available CLICK HERE to get it!</a></p>
<p align="justify"><strong>Zarul Shahrin Suhaimi</strong><br>Editor-in-Chief,<br>Hack in The Box Magazine</p>
<p>&#160;</p>]]></description>
<guid isPermaLink="false">1377@http://www.professionalsecuritytesters.org</guid>
<dc:subject>HITB_Magazine</dc:subject>
<dc:date>2012-04-23T11:28:11-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Rootcon Blog:  Introducing 35 Pentesting Tools Used for Web Sec Assessments</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1376</link>
<description><![CDATA[<p>Original post at:<br /><a href="http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1">http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1</a>&#160;&#160;</p>
<p><strong>1. w3af</strong></p>
<div class="separator"><a href="http://2.bp.blogspot.com/-DX7otj2qBdY/T1Ssp_poKhI/AAAAAAAAAWU/fiHjjX3Cyu8/s1600/w3af.png"><img src="http://2.bp.blogspot.com/-DX7otj2qBdY/T1Ssp_poKhI/AAAAAAAAAWU/fiHjjX3Cyu8/s280/w3af.png" border="0" alt="w3af" width="280" height="214" /></a></div>
<p>&#160;</p>
<div>w3af or Web Application Attack and Audit Framework is an open source penetration testing tool for finding web vulnerabilities and an exploit tool that comes with cool plugins like sqlmap, xssBeef, and davShell. w3af automatically updates itself every time you launch the tool making it a very reliable tool for website hacking.&#160; For more information just check out their website hosted at&#160;<a href="http://w3af.sourceforge.net/">SourceForge</a>.</div>
<div></div>
<div><strong>2. Acunetix Web Vulnerability Scanner</strong></div>
<div></div>
<div class="separator"><a href="http://1.bp.blogspot.com/-TXYrp6uX3i4/T1SyHNSv_2I/AAAAAAAAAWc/ELNI_8YXnKQ/s1600/wvs-SQL_Injection.gif"><img src="http://1.bp.blogspot.com/-TXYrp6uX3i4/T1SyHNSv_2I/AAAAAAAAAWc/ELNI_8YXnKQ/s280/wvs-SQL_Injection.gif" border="0" alt="Acunetix WVS" width="280" height="208" /></a></div>
<div><br />Acunetix WVS or Web Vulnerability Scanner is a pentesting tool for Windows users so that they may be able to check for SQL Injection, Cross Site Scripting (XSS), CRLF injection, Code execution, Directory Traversal, File inclusion, checks for vulnerabilities in File Upload forms and other serious web vulnerabilities. You can download this tool&#160;<a href="http://www.acunetix.com/vulnerability-scanner/download.htm">here</a>.<br /><br /><strong>3. SQLninja</strong><br /><br />SQLninja is a an sql injection tool for web applications that use Microsoft SQL Server as its back-end though it runs only in Linux, Mac and BSD. It requires perl modules; NetPacket, Net-Pcap, Net-DNS, Net-RawIP, and IO-Socket-SSL. You can download this tool&#160;<a href="http://sqlninja.sourceforge.net/download.html">here</a>.<br /><br /><strong>4. Nikto</strong><br /><br />
<div class="separator"><a href="http://1.bp.blogspot.com/-gq7uNhlYDYM/T1S17kzBSFI/AAAAAAAAAWk/XPYsACRIRr4/s1600/nikto.png"><img src="http://1.bp.blogspot.com/-gq7uNhlYDYM/T1S17kzBSFI/AAAAAAAAAWk/XPYsACRIRr4/s280/nikto.png" border="0" alt="nikto" width="280" height="192" /></a></div>
<br />Nikto is an open source web server scanner &#8220;<em>which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files or CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers.</em>" The good thing about Nikto is that it easy to use and and performs scanning faster. Nikto is coded in Perl and written by Chris Sullo and David Lodge. Although not all checks are really a big security problem but most are like XSS (Cross Site Scripting) Vulnerabilities, phpmyadmin logins, etc. Nikto alerts and gives you security tips in order to prevent your website from various attacks.<br /><br /><strong>5. SQLmap</strong><br /><br />
<div class="separator"><a href="http://3.bp.blogspot.com/-Bn9u4yEfJ9Q/T1S4CHz_VyI/AAAAAAAAAW0/swC9JH8jfwU/s1600/sqlmap.jpeg"><img src="http://3.bp.blogspot.com/-Bn9u4yEfJ9Q/T1S4CHz_VyI/AAAAAAAAAW0/swC9JH8jfwU/s280/sqlmap.jpeg" border="0" alt="" width="280" height="163" /></a></div>
<br />SQLmap is an open source automatic SQL injection and database takeover tool that fully supports MySQL, Oracle, PostgreSQL and Microsoft SQL Server. It partially supports Microsoft Access, DB2, Informix, Sybase and Interbase. Download sqlmap&#160;<a href="http://sqlmap.sourceforge.net/">here</a>.<br /><strong><br /></strong><br /><strong>6. Pangolin 3.2.3</strong><br /><br />Pangolin is another sql injection scanner for web applications using Access,DB2,Informix,Microsoft SQL Server 2000,Microsoft SQL Server 2005,Microsoft SQL Server 2008, MySQL, Oracle, PostgreSQL, Sqlite3, and Sybase. Its features include keyword auto analysis, supports HTTPS, has bypass firewall setting, injection digger, data dumper, etc. You can download its zip file&#160;<a href="http://down3.nosec.org/pangolin_free_edition_3.2.3.1105.zip">here</a>.&#160;<br /><br /><strong>7. Havij v1.15 Advanced SQL Injection</strong><br /><br />
<div class="separator"><a href="http://3.bp.blogspot.com/-kRGeeFd6tRU/T1S8RTNcUDI/AAAAAAAAAXE/McZcMHRlasw/s1600/md5_cracker.png"><img src="http://3.bp.blogspot.com/-kRGeeFd6tRU/T1S8RTNcUDI/AAAAAAAAAXE/McZcMHRlasw/s280/md5_cracker.png" border="0" alt="" width="280" height="308" /></a></div>
<br />Havij is another famous automatic sql injection tool that has a&#160;<a href="http://www.itsecteam.com/files/havij/Havij1.15Free.rar">free</a>&#160;and premium version. The free version only supports a few injection methods like MsSQL 2000/2005 with error, MsSQL 2000/2005 no error union based, MySQL union based, MySQL Blind, MySQL error based, MySQL time based, Oracle union based, MsAccess union based, and Sybase (ASE). It also includes an admin finder and an md5 cracker.&#160;<br /><strong><br /></strong><br /><strong>8. SQL Power Injector&#160;</strong><br /><br />SQL Power Injector is a web pentesting application created in .Net 1.1 that helps the penetration tester and hackers find and exploit SQL injections on a web application that uses SQL Server, Oracle, MySQL, Sybase/Adaptive Server and DB2 compliant, but it is possible to use it with any existing Database Management System when using the inline injection or normal mode. You can download the latest version of this tool which includes a Firefox plugin&#160;<a href="http://www.sqlpowerinjector.com/download.htm">here</a>.<br /><br /><strong>9. VulnDetector</strong><br /><br />VulnDetector is a project coded in python which scans a website and detects various web based security vulnerabilities in the website. It was developed by Brad Cable who is into coding open source tools. You can download the script&#160;<a href="http://bcable.net/archive.php?vulndetector-0.0.2pa.py">here</a>.<br /><br /><strong>10. SQLIer 0.8.2b</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-H0ixnzHlTq4/T1S_sz2rSkI/AAAAAAAAAXM/BBNNMFTEoYo/s1600/screenshot01.jpg"><img src="http://4.bp.blogspot.com/-H0ixnzHlTq4/T1S_sz2rSkI/AAAAAAAAAXM/BBNNMFTEoYo/s280/screenshot01.jpg" border="0" alt="" width="280" height="238" /></a></div>
SQLIer is another project of Brad Cable and is a shell script that determines all the necessary information to build and exploit an SQL Injection vulnerability to a URL by itself without user interaction unless it can't guess the table or field names for the database correctly. SQLIer can build a UNION SELECT query designed to brute force passwords out of the database. This script also does not use quotes in the exploit to operate, meaning it will work for a wider range of sites. Download the shell script&#160;<a href="http://bcable.net/archive.php?sqlier-0.8b.sh">here</a>.<br /><br /><strong>11. bsqlbf-v2</strong><br /><br />bsqlbf-v2 or Blind Sql Injection Brute Forcer version 2 is a perl script that allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections. It supports MySQL, Oracle, PostgreSQL and Microsoft SQL Server databases. You can download the perl&#160;<a href="http://code.google.com/p/bsqlbf-v2/downloads/list">script</a>&#160;on a Google hosted project.<br /><br /><strong>12. Marathon Tool&#160;</strong><br /><br />Marathon Tool is an alpha release SQL Injection tool or project that extracts information from web applications using Microsoft SQL Server, Microsoft Access, MySQL or Oracle Databases by using Time-Based Blind SQL Injection attack. The alpa release can be found&#160;<a href="http://marathontool.codeplex.com/">here</a>.<br /><br /><strong>13. XSSer&#160;</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-NK1m0qxTfpg/T1TFJDDH_lI/AAAAAAAAAX0/fR3Ezvfy0DY/s1600/xsser.png"><img src="http://4.bp.blogspot.com/-NK1m0qxTfpg/T1TFJDDH_lI/AAAAAAAAAX0/fR3Ezvfy0DY/s280/xsser.png" border="0" alt="" width="280" height="192" /></a></div>
<br />XSSer or Cross Site "Scripter" is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It also includes a GUI interface by using the command : ./xxser --gtk. You can download xxser's beta version&#160;<a href="http://xsser.sourceforge.net/">here</a>.<br /><br /><strong>14. ASP Auditor v2.2</strong><br /><br />
<div class="separator"><a href="http://2.bp.blogspot.com/-v_LxfSVLR84/T1TIPYh_l6I/AAAAAAAAAX8/h1jjbQEh5Ew/s1600/aspaudit.png"><img src="http://2.bp.blogspot.com/-v_LxfSVLR84/T1TIPYh_l6I/AAAAAAAAAX8/h1jjbQEh5Ew/s280/aspaudit.png" border="0" alt="" width="280" height="171" /></a></div>
<br />ASP Auditor v2.2<strong>&#160;</strong>is a an auditing tool for ASP that sends initial probe request, path discovery request, ASP.NET validate discovery request, ASP.NET Apr/07 XSS Check, application trace request, and null remoter service request. By using the opt command -bf, it allows you to brute force ASP.NET version using JS Validate directories.<br /><br /><strong>15.Absinthe</strong><br /><br /><em>"Absinthe is a GUI-based tool that automates the process of downloading the schema and contents of a database that is vulnerable to Blind SQL Injection.&#160; &#160; This tool does not aid in the discovery of SQL Injection holes but speeds up the process of data recovery.</em>" It supports Microsoft SQL Server, MSDE, Oracle, and Postgres and the tool runs on Linux, Windows and Mac OSX. Download&#160;<a href="http://www.0x90.org/releases/absinthe/download.php">here</a>.<br /><br /><strong>16. SQID</strong><br /><br />SQID or SQL injection digger is a command line tool written in ruby by Metaeye Security Group that looks for SQL injections and common errors in web sites. It performs a Google search when finding for SQL injections and common errors in web site URLs and crawls a webpage. You can download this tool by checking out its project SVN:<br /><br /><em>svn checkout svn://rubyforge.org/var/svn/sqid&#160;</em><br /><br /><strong>17.DarkMySQLi</strong><br /><br />
<div class="separator"><a href="http://3.bp.blogspot.com/-llVUlhQ280w/T1TPaxv8H9I/AAAAAAAAAYE/X4IZrxaChW4/s1600/darkmysqli.png"><img src="http://3.bp.blogspot.com/-llVUlhQ280w/T1TPaxv8H9I/AAAAAAAAAYE/X4IZrxaChW4/s280/darkmysqli.png" border="0" alt="" width="280" height="105" /></a></div>
<br />DarkMySQLi is a multi purpose MySQL Injection tool coded in python which is also available for BackTrack 5 as one of its packed tools.<br /><br /><strong>18. fimap&#160;</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-7SqQuM4sLXI/T1TSEnlmClI/AAAAAAAAAYM/d_1SvcS6PuQ/s1600/fimap.png"><img src="http://4.bp.blogspot.com/-7SqQuM4sLXI/T1TSEnlmClI/AAAAAAAAAYM/d_1SvcS6PuQ/s280/fimap.png" border="0" alt="" width="280" height="192" /></a></div>
<br />fimap is an automatic LFI/RFI scanner and exploiter coded in python by Iman Karim. It allows a pentester to scan a single URL for File inclusion errors, scan a list of URLS for File Inclusion errors, scan Google search results for FiIe inclusion errors, and harvest all links of a webpage with recurse level of 3 and write the URLs to a file directory.<br /><br /><strong>19.Script Hex Dump &#8211; Forensic Tool</strong><br /><br />
<div class="separator"><a href="http://1.bp.blogspot.com/-TP6AIMUdDIU/T1TXU0VvrSI/AAAAAAAAAYc/jRQ2QxWNuvs/s1600/scripthex.jpg"><img src="http://1.bp.blogspot.com/-TP6AIMUdDIU/T1TXU0VvrSI/AAAAAAAAAYc/jRQ2QxWNuvs/s280/scripthex.jpg" border="0" alt="forensic tool" width="280" height="149" /></a></div>
<br />Script Hex Dump - Forensic Tool is a java application that helps you in parsing your scripts like PHP and automatically converts it as a hex value, some penetration testers use this to test for possible sql injection vulnerability in a website. SQL Injection attack has been a chronic threat especially for those websites running PHP and MySQL as the backend of their database server, one of its capability if the server is not properly configure is the command for writing arbitrary files. You can download this tool&#160;<a href="http://www.theprojectxblog.net/script-hex-dump/">here</a>.<br /><br /><strong>20. PHP Vulnerability Hunter</strong><br /><br />
<div class="separator"><a href="http://2.bp.blogspot.com/-gUM16ftIh8M/T1TYSK-ZjhI/AAAAAAAAAYk/8wGFJOuPTUs/s1600/phpscanner1.png"><img src="http://2.bp.blogspot.com/-gUM16ftIh8M/T1TYSK-ZjhI/AAAAAAAAAYk/8wGFJOuPTUs/s280/phpscanner1.png" border="0" alt="php fuzzer" width="280" height="377" /></a></div>
<br />PHP Vulnerability Hunter is a PHP web application fuzzer that scans for common vulnerabilities like local file inclusion, SQL Injection, full path disclosure, arbitrary command execution and many more. A good tool for analyzing your own web server. You can grab the new version of this tool<a href="http://code.google.com/p/php-vulnerability-hunter/downloads/list">here</a>&#160;which is 1.1.4.6.<br /><br /><strong>21. WSTOOL : Web vulnerable scan tool</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-WCNKtQbiXDs/T1TbZ7RYzUI/AAAAAAAAAYs/DFSpbJHJxzc/s1600/wstool.png"><img src="http://4.bp.blogspot.com/-WCNKtQbiXDs/T1TbZ7RYzUI/AAAAAAAAAYs/DFSpbJHJxzc/s280/wstool.png" border="0" alt="wstool" width="280" height="172" /></a></div>
<br />WATOOL is a server error and SQL Injection, XSS or Cross Site Scripting scanner which uses PHP Check up collate with HTML FORM and LINK. You can download this tool&#160;<a href="http://sourceforge.net/projects/wstool/">here</a>.<br /><br /><strong>22.&#160;ProjectX WHMCS Pentesting Tool v.1</strong><br /><strong><br /></strong><br />
<div class="separator"><a href="http://3.bp.blogspot.com/-GsS9fkxOBHQ/T1Typ9432SI/AAAAAAAAAY0/S3mNHqNfUQY/s1600/whmcs.png"><img src="http://3.bp.blogspot.com/-GsS9fkxOBHQ/T1Typ9432SI/AAAAAAAAAY0/S3mNHqNfUQY/s280/whmcs.png" border="0" alt="" width="280" height="214" /></a></div>
<strong><br /></strong><br />Projectx WHMCS Pentesting Tool v.1 is a vulnerability scanner coded in VB.NET that uses a black box approach. It echos the db_username and the db_password of a website that is vulnerable to WHMCS Local File Disclosure. This kind of vulnerability is only applicable to versions&#160;3.x.x and some 4.x.x which was a viral exploit last year that some website administrators took for granted. You can download the tool&#160;<a href="http://www.theprojectxblog.net/projectx-whmcs-pentesting-tool-v-1/">here</a>.<br /><br /><strong>23. Wpscan&#160;</strong><br /><br />
<div class="separator"><a href="http://3.bp.blogspot.com/-vGEwwWY0yKU/T1YLYpBkZDI/AAAAAAAAAY8/aKJAvITV2kc/s1600/wpscan.png"><img src="http://3.bp.blogspot.com/-vGEwwWY0yKU/T1YLYpBkZDI/AAAAAAAAAY8/aKJAvITV2kc/s280/wpscan.png" border="0" alt="" width="280" height="186" /></a></div>
<br />WPscan or Wordpress Security Scanner is a pentesting tool written in ruby for Wordpress installations. The tools is coed by Ryan Dewhurst which uses a black box approach in finding security holes for Wordpress like timthumb, easy to guess passwords, plugin holes, etc. You can download wpscan&#160;<a href="http://code.google.com/p/wpscan/">here</a>.<br /><br /><strong>24. Skipfish</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-xMqOkiAz2Xo/T1YQDuMt2eI/AAAAAAAAAZM/bFibZbFNcJM/s1600/skipfish.png"><img src="http://4.bp.blogspot.com/-xMqOkiAz2Xo/T1YQDuMt2eI/AAAAAAAAAZM/bFibZbFNcJM/s280/skipfish.png" border="0" alt="" width="280" height="193" /></a></div>
Skipfish is an active web application security reconnaissance tool written by Michal Zalewski. Skipfish spiders a URL using the wordlists, a very powerful web scanning tool with a simple implementation. It also scans for vulnerabilities like php injection, XSS, format string vulnerabilities, overflow vulnerabilities, file inclusions , etc. You can download this tool&#160;<a href="http://code.google.com/p/skipfish/downloads/list">here</a>.<br /><strong><br /></strong><br /><strong>25. WhatWeb</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-oNozabsvZ-Q/T1YWALoao-I/AAAAAAAAAZU/TPSQGiZDsXM/s1600/whatweb.png"><img src="http://4.bp.blogspot.com/-oNozabsvZ-Q/T1YWALoao-I/AAAAAAAAAZU/TPSQGiZDsXM/s280/whatweb.png" border="0" alt="" width="280" height="192" /></a></div>
<br />WhatWeb is a web scanner coded by Andrew Horton aka urbanadventurer from Security-Assessment.com. It is used for information gathering because it identifies content management systems (CMS), blogging platforms, stats/analytics packages, javascript libraries, servers, etc. You can download this tool&#160;<a href="http://www.morningstarsecurity.com/downloads/whatweb-0.4.3.tar.gz">here</a>.<br /><br /><strong>26. OWASP ZAP&#160;</strong><br /><br />Zed Attack Proxy (ZAP) is a project of OWASP which is a GUI penetration testing tool for finding website vulnerabilities and flaws. This open source tool includes features like&#160; intercepting proxy, active scanner, passive scanner, brute force scanner, spider, fuzzer, port scanner,&#160; dynamic SSL certificates, API, and Beanshell integration. For more information about this tool, check out their&#160;<a href="https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project">website</a>.<br /><br /><strong>27.&#160; Webshag</strong><br /><br />
<div class="separator"><a href="http://1.bp.blogspot.com/-lCoITXQ_8Ys/T1YhDS27GLI/AAAAAAAAAZk/2KjuNxyFbvs/s1600/webshag1.10.png"><img src="http://1.bp.blogspot.com/-lCoITXQ_8Ys/T1YhDS27GLI/AAAAAAAAAZk/2KjuNxyFbvs/s280/webshag1.10.png" border="0" alt="" width="280" height="162" /></a></div>
<br />Webshag is a multi-threaded, multi-platform web server auditing tool coded in python. It is used for crawling a URL, port scanning, file fuzzing and audits your website. You can download this security auditing tool&#160;<a href="http://www.scrt.ch/outils/webshag/ws100_linux.tar.gz">here</a>.<br /><br /><strong>28. OWASP DirBuster</strong><br /><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-KHo2_xTxVR8/T1YkCtrH-0I/AAAAAAAAAZs/EB9fZN_i6ek/s1600/WebApplicationBrute+Forcing.png"><img src="http://4.bp.blogspot.com/-KHo2_xTxVR8/T1YkCtrH-0I/AAAAAAAAAZs/EB9fZN_i6ek/s280/WebApplicationBrute+Forcing.png" border="0" alt="" width="280" height="198" /></a></div>
<br />DirBuster is another project of OWASP that a multi threaded java application designed to brute force directories and files names on web/application servers that uses a black box approach for application testing by trying to find hidden content. You can download this tool&#160;<a href="http://sourceforge.net/projects/dirbuster/files/DirBuster%20%28jar%20%2B%20lists%29/1.0-RC1/">here</a>.<br /><br /><strong>29. Grendel-Scan</strong><br /><br />Grendel-Scan is free and open source web application pentesting tool that has an automatic scanning feature which detects common web application vulnerabilities, and features geared at aiding manual penetration tests. Get this tool&#160;<a href="http://grendel-scan.com/download.htm">now</a>.<br /><br /><strong>30. Mopest</strong><br /><br />
<div class="separator"><a href="http://3.bp.blogspot.com/-fMeV8zXVS0c/T1YoTVLQvTI/AAAAAAAAAZ0/w3z3ZhOuLAY/s1600/mopest.png"><img src="http://3.bp.blogspot.com/-fMeV8zXVS0c/T1YoTVLQvTI/AAAAAAAAAZ0/w3z3ZhOuLAY/s280/mopest.png" border="0" alt="" width="280" height="147" /></a></div>
<br />Mopest is a PERL Local PHP Vulnerability Scanner for exploits PhpBB 2.0.20 Disable Administrator, PhpBB 2.0.19 Denial of Service - Infinitely topic, phpBB 2.0.15 Database Authentication Details, Invision Power Board 2.0.2 Multipl Users DoS, Invision Power Board 2.1.5 Code Execution, MyBB 1.0 RC4 Sql injection, MyBB 1.1.3 Create An Admin, MyBB Sql Injection, and WordPress 1.5.11 Sql Injection. It also has tools like Fake Mailer, Email Bomber, and MD5 Cracker.&#160; You can check out this project&#160;<a href="http://code.google.com/p/mopest/downloads/list">here</a>.<br /><br /><strong>31. SecuBat</strong><br /><br />SecuBat is another web vulnerability scanner which automatically analyzes web sites with the aim of finding exploitable SQL injection and XSS vulnerabilities. You can check this tool&#160;<a href="http://secubat.codeplex.com/">here</a>.<br /><br /><strong>32. Arachni</strong><br /><strong><br /></strong><br />
<div class="separator"><a href="http://2.bp.blogspot.com/-3PrKD8fBARw/T1ogkwECsMI/AAAAAAAAAZ8/QHnKUPPR4qA/s1600/log.png"><img src="http://2.bp.blogspot.com/-3PrKD8fBARw/T1ogkwECsMI/AAAAAAAAAZ8/QHnKUPPR4qA/s280/log.png" border="0" alt="" width="280" height="166" /></a></div>
<strong><br /></strong><br />Arachni is an open source web application security scanner framework coded in ruby that helps website administrators and penetration testers evaluate the security of a web application. Arachni asks you for the URL of the&#160;target&#160;and it automatically&#160;performs&#160;a simple scan and presents you with its findings which could be a very risky flaw or loophole. You can download this tool&#160;<a href="http://arachni-scanner.com/">here</a>.<br /><br /><strong>33.&#160;WebSlayer</strong><br /><strong><br /></strong><br />WebSlayer is another OWASP project that slays your web application by brute forcing the GET and POST parameters, checking the&#160;directories, brute forcing the login forms, fuzzing, brute forcing sessions,&#160;Ntml brute forcing, and many more. For more information of this&#160;project&#160;just check this&#160;<a href="https://www.owasp.org/index.php/Category:OWASP_Webslayer_Project">site</a>.<br /><br /><strong>34. Burp Suite</strong><br /><strong><br /></strong><br />
<div class="separator"><a href="http://4.bp.blogspot.com/-ODa4YprJuGM/T1olZJvXItI/AAAAAAAAAaE/TJO-CWOhzLM/s1600/intruder_3.png"><img src="http://4.bp.blogspot.com/-ODa4YprJuGM/T1olZJvXItI/AAAAAAAAAaE/TJO-CWOhzLM/s280/intruder_3.png" border="0" alt="" width="280" height="210" /></a></div>
<strong><br /></strong><br />Burp Suite is penetration testing tool and integrated platform for website security. Burp Suite has cool features like an intercepting proxy, application spider for crawling, detects numerous web application vulnerabilities, repeater tool, allows you to write your own plugins, and many more. The free edition is available for download&#160;<a href="http://portswigger.net/burp/download.html">here</a>.<br /><br /><strong>35. ProxMon</strong><br /><strong><br /></strong><br />ProxMon is not a Digimon but a Python based open source framework that automates web application tests. Its key features include:<br /><br />- automatic value tracing of set cookies, sent cookies, query strings and post parameters across sites,<br />- proxy agnostic<br />-&#160;included library of vulnerability checks<br />-&#160;active testing mode<br />-&#160;cross platform<br />-&#160;easy to program extensible python framework<br /><br />You can download this tool&#160;<a href="http://www.isecpartners.com/application-security-tools/proxmon.html">here</a>.</div>
<p>&#160;</p>
<p>Original post at:<br /><a href="http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1">http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1</a>&#160;&#160;</p>]]></description>
<guid isPermaLink="false">1376@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Web_App_Sec</dc:subject>
<dc:date>2012-04-02T08:53:12-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Job opportunities in Kuwait and Dubai</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1375</link>
<description><![CDATA[<p>&#160;</p>
<p class="MsoNormal">Good day everyone,</p>
<p class="MsoNormal">My good friend Balwant Rathore has jobs opening in both Kuwait and Dubai.</p>
<p class="MsoNormal">See the profiles he is looking for below. &#160;Please only answer if you have the full 5 years+ of practical experience and you're willing to work in Kuwait or Dubai.</p>
<p class="MsoNormal">See job offers below and contact information.</p>
<p class="MsoNormal">Best regards</p>
<p class="MsoNormal">Clement</p>
<p class="MsoNormal"><strong>SEE MESSAGE FROM BALWANT BELOW:</strong></p>
<p class="MsoNormal">I am looking for Freelancer/Consultant for followings projects:</p>
<p><strong>1.&#160;&#160;&#160;&#160;&#160;&#160;ITIL Implementation</strong></p>
<p><strong>2.&#160;&#160;&#160;&#160;&#160;&#160;Business Continuity Management (BCM) Implementation</strong></p>
<p><strong>3.&#160;&#160;&#160;&#160;&#160;&#160;Information Security Management System Implementation</strong></p>
<p class="MsoNormal"><strong>For all three categories some amount of training skills are also required.</strong></p>
<p class="MsoNormal">Experience required = 5+ years.</p>
<p class="MsoNormal">Project Location = Dubai and Kuwait</p>
<p class="MsoNormal">Start Date = As soon as possible, even today.</p>
<p class="MsoNormal">Payment &#8211; Best in Industry, as per experience.</p>
<p class="MsoNormal">If you know anybody who may be fit for above, please ask them to contact me at&#160;<a href="mailto:balwant_rathore@oissg.org">balwant_rathore@oissg.org</a></p>
<p class="MsoNormal">Kind regards,</p>
<p class="MsoNormal">Balwant</p>
<p>&#160;</p>]]></description>
<guid isPermaLink="false">1375@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Jobs</dc:subject>
<dc:date>2012-03-24T21:37:08-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>The CISSP exam is available online as of 1st of June 2012 at VUE testing</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1374</link>
<description><![CDATA[<p>After much speculation and questions as to when the exam would be available online in English, it is now official, (ISC)&#178;&#174; is going to offer the exam online for English speaking students as of  the 1st of June.&#160; This is a major change and it is very welcome. <br><br>You  can begin registering for computer-based testing (CBT) for CISSP,   CISSP concentrations and the SSCP certifications on June 1, 2012. <br><br>You  no longer have to wait for an exam to show up in your area a few times a  year or as it is the case with many countries once a year only.&#160; You  can now book your exam with VUE testing when&#160; you are ready and in a  location close to you as well.&#160; This is so much more flexible than the  outdated paper based approach they were using until now.</p>
<p align="start">Accordint to the ISC&#178;&#174; press release this transition  provides numerous benefits to  candidates, members and the information  security community, including:</p>
<ul>
<li>Fair and precise evaluation of a candidate&#8217;s competency </li>
<li>Rapid turnaround of exam results </li>
<li>More choices as to when and where to take the exam </li>
<li>Easier registration </li>
<li>Fortified&#160;exam security </li>
</ul>
<p align="start">All (ISC)&#178; credential exams will be offered globally at  approved Pearson VUE testing centers.</p>
<p align="start">Currently, all (ISC)&#178; exams offered via CBT are  available in  English, with the CISSP and SSCP exams also available in  Brazilian  Portuguese at any of the approved&#160; Pearson VUE testing centers in Latin America.&#160; The CISSP exam is also available in Spanish throughout Latin America.&#160; &#160;</p>
<p align="start">Candidates can register directly through <a href="http://www.pearsonvue.com/isc2">PearsonVUE</a></p>
<p align="start">This is really good news for all</p>
<p align="start">Best regards</p>
<p align="start">Clement</p>
<p align="start">Clement Dupuis, CD<br>Owner and Founder of CCCure<br>CLO at Secure Ninja</p>]]></description>
<guid isPermaLink="false">1374@http://www.professionalsecuritytesters.org</guid>
<dc:subject>ISC2</dc:subject>
<dc:date>2012-03-06T04:02:07-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Secure Ninja Appoints Leonard Chin as VP to Lead International Expansion</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1373</link>
<description><![CDATA[<p>
<p>With 80% of its target market overseas Secure  Ninja expands globally  to meet the growing demand for Information  Security training and  service solutions.</p>
<p>Secure Ninja is pleased to announce the appointment of Leonard Chin  as Vice  President to lead its international marketing and business  development. &#160; In response to the global opportunity for its leading  edge security  services, Secure Ninja also announces its expansion into  Europe, the  Middle East and Africa (EMEA), along with select markets in  Asia Pacific  and South America. <br><br>With a decade of experience in  developing new  business and driving international sales, Leonard will  be a key asset to  Secure Ninja as the company grows its customer and  value-added reseller  (VAR) base in the coming year.</p>
<p>Leonard possesses extensive field experience specializing in sales   and marketing functions across numerous industries including finance,   conference, seminars, franchise, technical training and education.    Leonard has established countless strategic partnerships with numerous   Fortune 500 companies and government organizations.  Leonard is well   known as a conference specialist, having successfully managed a string   of highly successful EC-Council conferences during his tenure.  He was   instrumental in conceptualizing and organizing the first Hacker Halted   USA in 2008 and thereafter making it a mainstay in Miami. Leonard was   responsible for launching, designing and directing the highly technical   TakeDownCon series, which was recently hosted in Dallas and Las Vegas  in  2011.</p>
<p>&#8220;We are delighted to have Leonard Chin on our team.  He is an   extremely knowledgeable and well-connected infosec business professional   who possesses great leadership ability and outstanding communication   skills, which are crucial elements to effectively manage and influence   people towards meeting our company&#8217;s international business objectives,&#8221;   said Ned Snow, President, Secure Ninja.  &#8220;By combining Leonard&#8217;s   expertise to manage a strong team of subject matter experts and sales   engineers in key regions, Secure Ninja will be well positioned for our   next phase of innovation and growth.&#8221;</p>
<p>Prior to this appointment, Leonard was a key executive at EC-Council,   creator of the world renowned Certified Ethical Hacker (CEH) programs   as well as numerous other recognized certifications such as the CHFI,   ECSA and Licensed Penetration Tester (LPT). He held various roles within   the organization including Director of Marketing, and Director of   Conferences &#38; Events, as well as concurrently being the Conference   Director for both the TakeDownCon and Hacker Halted conference series.   And in 2011, he was appointed as the Vice Chair of the world&#8217;s first   international team ethical hacking games - the Global CyberLympics.</p>
<p>"It is an honor and I&#8217;m excited to be part of Secure Ninja&#8217;s   immensely qualified team, which is on the leading edge of information   security services and training methodology development," said Leonard.   "I'm looking forward to expanding Secure Ninja&#8217;s suite of security   services and training offerings internationally, ensuring its growth and   market captivity, as well as attaining global branding.&#8221;</p>
<p><strong>About Secure Ninja </strong><br><br>Secure Ninja is a leader in  Information Security, IT training and  certification such as CISSP,  Security+, CEH, CAP, CISM, ISSEP, ISSMP,  ISSAP, Cloud Security,  Wireless Security and Computer Forensics to name a  few. Secure Ninja  has been providing businesses with programs that  answer regulatory  needs and skills gaps for over 8 years.  Our training  programs educate  and certify employees in the areas that are critical to  business  operations.  With certified professionals on staff, the  company  demonstrates that it is seriously engaged in producing ROI on   technology investments and handling compliance requirements competently.    Our programs also create solutions for the DOD and the system   integrator community by answering the certification needs of the   8570.01-M mandate. Secure Ninja&#8217;s assessment, consulting and security   services division specializes in governance, risk and compliance   programs for both corporate &#38; government agencies including   information assurance, IV&#38;V security audits and cyber-security   solutions.&#160;  For more information visit <a href="http://www.secureninja.com/">http://www.secureninja.com</a></p>
</p>
<table border="0" cellspacing="1" cellpadding="6" width="100%">

<tr>
<td bgcolor="#D9E0E8"><strong>Contact Information</strong></td>
</tr>
<tr>
<td bgcolor="#EBEFF3"><strong>Ned Snow</strong><br>Secure Ninja<br><a href="http://www.secureninja.com/">http://www.secureninja.com</a><br>(703) 535-8600 ext. 15</td>
</tr>

</table>]]></description>
<guid isPermaLink="false">1373@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Inthenews</dc:subject>
<dc:date>2012-02-22T21:56:44-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Pen Tests Evolved: The Advanced Threat Cycle</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1371</link>
<description><![CDATA[<div style="color: #45555f; font-size: 14px; font-weight: bold; line-height: 21px;">
<div>
<div>You're Invited: Penetration Testing Webcast<br></div>
</div>
</div>
<div style="color: #922126; font-size: 23px; font-weight: bold; line-height: 26px;">
<div></div>
</div>
<p><img src="http://ws.coresecurity.com/rs/coresecurity/images/Core_Security_tag.gif" alt height="64"></p>
<div><strong>Date:&#160; </strong>Tuesday, February 14, 2012<br></div>
<div><strong>Time:</strong> 2pm US Eastern Time (GMT -4:00, New York) <br></div>
<div>
<div><strong>Host:</strong>&#160; Dave Shackleford, Voodoo Security<br></div>
</div>
<div><br><a href="http://ws.coresecurity.com/PenTestsEvolved.html">Click here to register</a><br><a href="http://ws.coresecurity.com/PenTestsEvolved.html">http://ws.coresecurity.com/PenTestsEvolved.html</a></div>
<p>*** A recording of the webcast will be sent to everyone who registers, so be sure to sign up even if you can&#8217;t make the live session. ***</p>
<div>Over  the last few years, we've heard a lot of discussion in the security  community about "advanced threats". Whether persistent or not, the  attackers are using a vast arsenal of techniques to compromise systems  and steal data, some newer and more cutting-edge, while others are more  tried and true. No matter your opinion on the "APT", the attacks are  happening and organizations are losing data left and right. How can you  determine your susceptibility to these attacks? There's no one answer to  this, but proactive security assessments that emulate some of the  attackers' methods can help you to pinpoint your weak spots.</div>
<div><br></div>
<div>During this presentation, Dave Shackleford will cover:</div>
<ul>
<li>
<div>The advanced threat      cycle, and what attack techniques and tools are seen most frequently</div>
</li>
<li>
<div>What most internal      pen testing teams are doing today, and why it may not be adequate for      today's threat landscape</div>
</li>
<li>
<div>How  internal pen      testing teams can switch up their normal testing  regimens to better      represent advanced threats to organizations</div>
</li>
<li>
<div>Tips for how to      prevent and detect advanced malware as part of your assessment program</div>
</li>
</ul>
<p><a href="http://ws.coresecurity.com/PenTestsEvolved.html">Click here to register</a><br>&#160;<a href="http://ws.coresecurity.com/PenTestsEvolved.html">http://ws.coresecurity.com/PenTestsEvolved.html</a>&#160;</p>
<div>***  A recording of the webcast will be sent to everyone who registers, so  be sure to sign up even if you can&#8217;t make the live session. ***</div>
<div><br></div>
<div>Best Regards,&#160;</div>
<div>Core Security</div>]]></description>
<guid isPermaLink="false">1371@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2012-02-09T11:40:05-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

<item>
<title>Security Kaizen Magazine Issue 4 is released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1370</link>
<description><![CDATA[<div style="text-align: center;"><strong>Security Kaizen Magazine               Yearly issue. <br> An issue that you shouldn't miss</strong><br></div>
<blockquote>In Egypt : 30 % discount Coupon for EC council         Courses inside the Printed Copy.<br><br> <a href="https://spreadsheets9.google.com/viewform?hl=en&#38;formkey=dFhVbGFZUlpZM3BXMHpjWUdkUndqeXc6MQ#gid=0">Printed           Copy Request</a><br> Coming Soon : Arabic Version<br></blockquote>
<div style="text-align: center;"><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"><strong>Download the English Edition now</strong><br> </a></div>
<p><br> <a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"></a></p>
<p style="text-align: center;"><a href="http://www.bluekaizen.org/security-kaizen-magazine/issue-4/"><img src="https://mail.google.com/mail/u/0/?ui=2&#38;ik=0793b57c9a&#38;view=att&#38;th=135349096fe28fa9&#38;attid=0.1&#38;disp=emb&#38;realattid=a364c6ec898db2e0_0.1.1&#38;zw" border="0" alt height="507"></a></p>]]></description>
<guid isPermaLink="false">1370@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Training</dc:subject>
<dc:date>2012-02-03T14:58:28-04:00</dc:date>
<dc:creator>Posted by cdupuis</dc:creator>
</item>

<item>
<title>Modeling Security Pentests - New Issue of WebAppPentesting is  Out!</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=1369</link>
<description><![CDATA[<p><strong>Inside Web App Pentesting:</strong></p>
<p>Open Source Web Application Security Testing Tools by Vinodh Velusamy</p>
<p>Author  shows the significance of Open Source Web Application Security Testing  Tools. As he claims &#8222;When you choose and use good tools, you&#8217;ll know it.  Amazingly, you&#8217;ll minimize your time and effort installing them,  running your tests, reporting your results &#8211; everything from start to  finish. <br><br>Most importantly, with a good web vulnerability scanner  you&#8217;ll be able to maximize the number of legitimate vulnerabilities  discovered to help reduce the risks associated with your information  systems. <br>At the end of the day and over the long haul, this will add up to considerable business value you can&#8217;t afford to overlook&#8221;. <br><br><strong>More Articles:</strong></p>
<p>- Modeling Security Penetration Tests with Stringent Time Constraints by Alan Cao <br>- The puzzlepices by Daniel Clemens <br>- WebAppSecurity for Newbies part 2 Herman Stevens <br>- Web Application Common Vulnerabilities &#8211; Part I by Bryan Soliman <br>- CYBER STYLETTO by Mike Brennan and Richard Siennon <br><br><br><strong>SUBSCRIBE NOW AND GET 2 AMAZING E-BOOKS !</strong></p>
<p>1. CISO's Guide to Penetration Testing: A Framework to Plan, Manage,  and Maximize Benefits details the methodologies, framework, and  unwritten conventions penetration tests should cover to provide the most  value to your organization and your customers.<br><br>2. In his new  book "Save the Database, Save the World!" John Ottman captures the  essence of the threats we face to the information that drives business.  Organized crime, underhanded competitors and even foreign governments  are looking to gain any financial, competitive or operational advantage  and these enemies are going directly after the databases and the  applications that access data.</p>
<p>After subscribing contact <strong><a href="mailto:katarzyna.zwierowicz@software.com.pl">katarzyna.zwierowicz@software.com.pl</a></strong> with "WAPT" in the tittle of the message.</p>
<p>You can visit us at: <a href="http://www.pentestmag.com"><strong>http://www.pentestmag.com</strong></a></p>]]></description>
<guid isPermaLink="false">1369@http://www.professionalsecuritytesters.org</guid>
<dc:subject>Hakin9</dc:subject>
<dc:date>2012-01-25T12:58:26-04:00</dc:date>
<dc:creator>Posted by </dc:creator>
</item>

</channel>
</rss>

