<?xml version="1.0" encoding="ISO-8859-1"?>

<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN"
 "http://my.netscape.com/publish/formats/rss-0.91.dtd">

<rss version="0.91">

<channel>
<title>Professional Security Testers resources warehouse</title>
<link>http://www.professionalsecuritytesters.org</link>
<description>The Professional Security Tester Warehouse</description>
<language>en-us</language>

<item>
<title>The Academy.ca has new videos available</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=899</link>
<description>Hey everybody,&lt;br&gt;&lt;br&gt;This week has been really busy both from a personal and business perspective. We spent a ton of time at SANS Toronto 2008 participating in panel discussions and giving SANS@Night talks. &lt;br&gt;&lt;br&gt;Video production suffered due to our hectic schedules, but we still managed to get three videos uploaded for you. &lt;br&gt;&lt;br&gt;We added a new category for SIM products as well. &lt;br&gt;&lt;br&gt;We want to thank Q1 Labs and SecurityNexus for becoming the latest sponsors of The Academy and as always, don't forget to join The Academy LinkedIn Group at: &lt;br&gt;&lt;br&gt;&lt;strong&gt;&lt;a href=&quot;http://www.linkedin.com/e/gis/71823/29A0DF7FB943&quot;&gt;http://www.linkedin.com/e/gis/71823/29A0DF7FB943&lt;/a&gt;&lt;/strong&gt;&lt;br&gt; &lt;br&gt;New videos are posted to the 'Featured Videos' section of the website.&lt;br&gt;&lt;br&gt;Find our new videos at:  &lt;a href=&quot;http://www.theacademy.ca/&quot;&gt;www.theacademy.ca&lt;/a&gt; &lt;br&gt;&lt;strong&gt;Firewalls&lt;/strong&gt;&lt;br&gt;Configuring a Site-to-Site VPN Tunnel with Cisco PIX&lt;br&gt;&lt;br&gt;&lt;strong&gt;Security Information Management (SIM) NEW CATEGORY!!!&lt;/strong&gt;&lt;br&gt;Exporting Windows Event Logs Using the Adaptive Log Exporter&lt;br&gt;&lt;br&gt;&lt;strong&gt;VA/Penetration Testing&lt;/strong&gt;&lt;br&gt;Creating Favorites with Shavlik NetChk Protect&lt;br&gt;&lt;br&gt;Thank you all for your on-going support and recommendations.&lt;br&gt;&lt;br&gt;Peter Giannoulis&lt;br&gt;The Academy&lt;br&gt;&lt;strong&gt;&lt;a href=&quot;http://www.theacademy.ca/&quot;&gt;www.theacademy.ca&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;&lt;br&gt;This update has been brought to you by &lt;strong&gt;&lt;a href=&quot;http://www.checkpoint.com/index.html&quot;&gt;Check Point Software&lt;/a&gt;&lt;/strong&gt; Technologies &amp;amp; &lt;strong&gt;&lt;a href=&quot;http://www.ossec.net/&quot;&gt;OSSEC&lt;/a&gt;&lt;/strong&gt;.</description>
</item>

<item>
<title>Hack In The Box (HITB) Malaysia -- Call for papers</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=898</link>
<description>Hello from Malaysia! &lt;br&gt; &lt;br&gt;The Call for Papers (CFP) for the 6th Hack In The Box Security Conference in Malaysia (27th - 30th October 2008) is now open. &lt;br&gt; &lt;br&gt;We've got some really cool stuff lined up this year including an open-hack competition for charity, a third track in the conference (hitb-labs), 4 keynote speakers + 30 international experts, the usual team based capture the flag competition, a new wireless (bluetooth, rfid, 802.11) village and lock picking village! &lt;br&gt; &lt;br&gt;Summaries not exceeding 1250 words should be submitted (in plain text format) to cfp -at- hackinthebox.org for review and possible inclusion in the programme. &lt;br&gt; &lt;br&gt;Submissions are due no later than 30th of June 2008 &lt;br&gt; &lt;br&gt;TOPICS &lt;br&gt; &lt;br&gt;Topics of interest include, but are not limited to the following: &lt;br&gt; &lt;br&gt;# 3G/4G Cellular Networks &lt;br&gt;# Apple / OS X security vulnerabilities &lt;br&gt;# SS7/Backbone telephony networks &lt;br&gt;# Analysis of network and security vulnerabilities &lt;br&gt;# Firewall technologies &lt;br&gt;# Intrusion detection &lt;br&gt;# Data Recovery, Forensics and Incident Response &lt;br&gt;# HSDPA and CDMA Security &lt;br&gt;# Identification and Entity Authentication &lt;br&gt;# Network Protocol and Analysis &lt;br&gt;# Smart Card and Physical Security &lt;br&gt;# Virus and Worms &lt;br&gt;# WLAN, RFID and Bluetooth Security &lt;br&gt;# Analysis of malicious code &lt;br&gt;# Applications of cryptographic techniques &lt;br&gt;# Analysis of attacks against networks and machines &lt;br&gt;# File system security &lt;br&gt; &lt;br&gt;PLEASE NOTE: &lt;br&gt; &lt;br&gt;We do not accept product or vendor related pitches. If your talk involves an advertisement for a new product or service your company is offering, please do not submit. &lt;br&gt; &lt;br&gt;Your submission should include: &lt;br&gt; &lt;br&gt;# Name, title, address, email and phone/contact number &lt;br&gt;# Short biography, qualification, occupation, achievement and &lt;br&gt;affiliations (limit 250 words). &lt;br&gt;# Summary or abstract for your presentation (limit 1250 words) &lt;br&gt;# Technical requirements (video, internet, wireless, audio, etc.) &lt;br&gt; &lt;br&gt;Each non-resident speaker will receive accommodation for 2 nights/3 days. For each non-resident speaker, HITB will cover travel expenses up to USD 1,000.00. &lt;br&gt; &lt;br&gt;HITBSecConf2008 - Malaysia - Sponsorship Options &lt;br&gt; &lt;br&gt;For an opportunity to position your company as a major supporter of this event, we have several sponsorship packages which offers an extensive variety of direct and exclusive mechanisms for pre-event exposure and &lt;br&gt;direct business generation during the event. If you are interested in further details regarding sponsorship of HITBSecConf2008 - Malaysia, please contact us. &lt;br&gt; &lt;br&gt;=== &lt;br&gt; &lt;br&gt;On a related note, the keynote presentation videos from HITBSecConf2008 - Dubai is also now available for download from here: &lt;br&gt; &lt;br&gt;Day 1 Keynote:  &lt;a href=&quot;http://materials.hitbsecconf.org/hitbsecconf2008dubai/videos/Keynote-1.mov&quot;&gt;http://materials.hitbsecconf.org/hitbsecconf2008dubai/videos/Keynote-1.mov&lt;/a&gt; &lt;br&gt;Day 2 Keynote:  &lt;a href=&quot;http://materials.hitbsecconf.org/hitbsecconf2008dubai/videos/Keynote-2.mov&quot;&gt;http://materials.hitbsecconf.org/hitbsecconf2008dubai/videos/Keynote-2.mov&lt;/a&gt; &lt;br&gt; &lt;br&gt;See you guys in October! &lt;br&gt; &lt;br&gt;The HITB Team.</description>
</item>

<item>
<title>Pangolin Sql Injection tool version 1.2.5.604 has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=897</link>
<description>Hi, all:
I&amp;rsquo;m glad to tell you that Pangolin, the wonderful Sql injection tool, has been updated to version 1.2.5.604.
You can download it from here:&lt;strong&gt; &lt;a href=&quot;http://www.nosec.org/web/pangolin&quot;&gt;http://www.nosec.org/web/pangolin &lt;br&gt;&lt;/a&gt;&lt;/strong&gt;
Pangolin is a GUI tool running on Windows to perform as more as possible pen-testing through SQL injection. This version now supports following databases and operations:
* MSSQL : Server informations, Datas, CMD execute, Regedit, Write file, Download file, Read file, File Browser... * MYSQL : Server informations, Datas, Read file, Write file...&lt;br&gt; * ORACLE : Server informations, Datas, Accounts cracking...&lt;br&gt; * PGSQL : Server informations, Datas, Read file...&lt;br&gt; * DB2 : Server informations, Datas, ...&lt;br&gt; * INFORMIX : Server informations, Datas, ...&lt;br&gt; * SQLITE : Server informations, Datas, ...&lt;br&gt; * ACCESS : Server informations, Datas, ...&lt;br&gt; * SYBASE : Server informations, Datas, ...&lt;br&gt; etc. And supports: * HTTPS support&lt;br&gt; * Pre-Login&lt;br&gt; * Proxy&lt;br&gt; * Specify any HTTP headers(User-agent, Cookie, Referer and so on)&lt;br&gt; * Bypass firewall setting&lt;br&gt; * Auto-analyzing keyword&lt;br&gt; * Detailed check options&lt;br&gt; * Injection-points management&lt;br&gt; etc. &lt;strong&gt;&lt;/strong&gt;
&lt;strong&gt; What's the differents to the others?&lt;/strong&gt;
* Easy-of-use : What I try to do is making pen-tester more care about result, not the process. All you should do is clicking the buttons.&lt;br&gt; * Amazing Speed : so many people told you things about brute sql injection, is it really necessary? Forget char-by-char, we can row-by-row(of cource, not every injection-point can do this)?&lt;br&gt; * The exact check mothod : do you really think automated tools like AWVS,APPSCAN can find all injection-points?
So, whatever, just check it out, and then enjoy your feeling ;)</description>
</item>

<item>
<title>Illegal Credit Card Skimming Device</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=896</link>
<description>&lt;em&gt;As seen on Redbox.com&lt;/em&gt; &lt;br&gt; A tester has to remember that logical access is NOT always the easiest way to gather credit card numbers. &lt;em&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/em&gt; &lt;em&gt;&lt;strong&gt;&lt;br&gt;SUMMARY&lt;/strong&gt;&lt;/em&gt; &lt;br&gt; Skimming involves the placement of an illegal device above the credit/debit card reader on a vending machine, ATM, or in this case a redbox. These devices are used to illegally read or store personal credit card information. &lt;br&gt;&lt;br&gt; This article provides pictures of approved credit card readers and of skimmer devices. This is the first time I have seen a company take an active stance in educating their customers regarding this threat. &lt;em&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;&lt;em&gt;&lt;strong&gt;For the full article:&lt;br&gt;&lt;/strong&gt;&lt;/em&gt; &lt;a href=&quot;http://www.redbox.com/creditcardsecurity/&quot;&gt;http://www.redbox.com/creditcardsecurity/&lt;/a&gt;</description>
</item>

<item>
<title>oCERT Open Source Computer Emergency Response Team</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=895</link>
<description>Robert McMillan, IDG News Service&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://news.yahoo.com/s/pcworld/20080506/tc_pcworld/145508&amp;amp;printer=1;_ylt=AoQ9ZrUeNtSO4_0KHFsk5VoRSLMF&quot;&gt;http://news.yahoo.com/s/pcworld/20080506/tc_pcworld/145508&amp;amp;printer=1;_ylt=AoQ9ZrUeNtSO4_0KHFsk5VoRSLMF&lt;/a&gt;&lt;br&gt;&lt;br&gt;Google has thrown its weight behind a fledgling security reporting  group for the open-source community.&lt;br&gt;&lt;br&gt;The search engine giant, long a proponent of open-source software, is  now one of three sponsors of oCERT, the Open Source Computer Emergency  Response Team.&lt;br&gt;&lt;br&gt;Launched in late March, oCERT aims to be a clearinghouse for data on  security vulnerabilities in open-source products, keeping open-source  distributors on top of flaws and helping small software projects  &lt;br&gt;ensure that users of their code are aware of any issues.&lt;br&gt;&lt;br&gt;OCERT has published four advisories since its inception. In addition  to Google, it is sponsored by Inverse Path and the Open Source Lab.&lt;br&gt;&lt;br&gt;There are already many national CERT efforts, which coordinate  countrywide responses to security threats, but oCERT hopes to meet the  unique requirements of the open-source community, where software is  often re-used but patches are not always circulated to everyone who  needs them.&lt;br&gt;&lt;br&gt;&quot;It is my hope that this initiative will not only aid in remediating  security issues in a timely fashion, but also provide a means for  additional security contributions to the open source community,&quot; wrote  Google's Will Drewry in a Monday post to the company's security blog.   Visit the oCERT web site at:  &lt;a href=&quot;http://www.ocert.org/&quot;&gt;http://www.ocert.org/&lt;/a&gt;</description>
</item>

<item>
<title>EC-Council Offers Details and Insights on CEH v6</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=894</link>
<description>&lt;em&gt;As seen on the Ethical Hacker Network:&lt;br&gt;&lt;br&gt;&lt;strong&gt;SUMMARY&lt;br&gt;&lt;/strong&gt;&lt;/em&gt;&lt;br&gt;The latest version of the Certified Ethical Hacker (CEH) Courseware is due to be released and presented for the first time at Hacker Halted USA 2008 in June. Many small details of CEH Version 6 have been peppered on the Internet, as well as snippets of teaser copy on EC-Council&amp;rsquo;s own web site.&lt;br&gt;&lt;br&gt;&amp;ldquo;With a total of 28 new and never seen before modules, covering the latest concepts, featuring more real life cases, and showcasing the latest hacking and security tools, the Certified Ethical Hacker (Version 6) will be the most advanced course ever.&amp;rdquo;&lt;br&gt;&lt;br&gt;...an interview with EC-Council to see if we could get confirmation as well as clarification.&lt;br&gt;&lt;br&gt;&lt;strong&gt;&lt;em&gt;For the full article:&lt;br&gt;&lt;/em&gt;&lt;/strong&gt;&lt;a href=&quot;http://www.ethicalhacker.net/content/view/190/24/&quot;&gt;http://www.ethicalhacker.net/content/view/190/24/&lt;/a&gt;</description>
</item>

<item>
<title>Kiwicon 2008, Wellington, New Zealand</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=893</link>
<description>[--- &lt;a href=&quot;http://www.kiwicon.org/&quot;&gt;www.kiwicon.org&lt;/a&gt; ---]&lt;br&gt;&lt;br&gt;Holy sheepshit, internets! Blanket-Man[1] has wrung out his loin cloth  and is ready to fly-tackle more heavy metal t-shirt wearing nerds with large egos and irc handles. Yes, it's time to open up your ~/haxing  folder and get your talk together for Kiwicon 2k8! We've put out the black t-shirts, and deflated some satellite radomes, so where, as our more criminal yet fetchingly bikini clad cousins might say, the bloody hell are you?&lt;br&gt;&lt;br&gt;The Kiwicon Cr&amp;uuml;e is proud to announce the initial call for presenters for the second installment of New Zealand's very own security conference: Kiwicon 2k8.&lt;br&gt;&lt;br&gt;&lt;strong&gt;[About]&lt;/strong&gt;&lt;br&gt;&lt;br&gt;Kiwicon2k8 is intended to be an informal conference, drawing on the wider security community of Australia and New Zealand. It will be held  in Wellington, New Zealand, on the weekend of the 27th and 28th of September, 2008.&lt;br&gt;&lt;br&gt;Kiwicon's focus is on sharing information; ideas, code, and good whisky, in a rabelaisan carnival of security, nerdery, and *nix beards.&lt;br&gt;&lt;br&gt;Last year, the inaugural Kiwicon ended up being kind of a big deal:  highlights included tmasky's mighty Crackstation, the debut of Beau Butler as an &quot;ethical hacker&quot; making Microsoft &quot;look like turkeys&quot;, and &lt;br&gt;of course the Kiwicon Hax0r Quiz, with the winner taking the grand prize of An Illustrated Guide to the Commoner Skin Diseases. Hope it came in  handy for the post-con diagnosis phase, dude.&lt;br&gt;&lt;br&gt;This year, Kiwicon's own Bogan is already making anti-virus vendors  quake in their little signature-laden booties at Defcon's Race to Zero, and the cauldron of 0h-0h-0hday in Brett Moore's secret Insomnia lair is &lt;br&gt;bubbling over with pernicious brew. If you missed last Kiwicon (not  &quot;professional enough&quot;? couldn't convince your boss it wasn't a hoax?) then find one of the 230+ people who were there and ask them if they're &lt;br&gt;just-not-gonna-bother this year.&lt;br&gt;&lt;br&gt;&lt;strong&gt;[Venue]&lt;/strong&gt;&lt;br&gt;&lt;br&gt;Our hosts for the weekend will, once again, be Victoria University of Wellington. If you have any memory of last year's Kiwicon, then it'll look disturbingly familiar.&lt;br&gt;&lt;br&gt;The campus has the advantage of being close to the center of the city and its' various amenities. This includes cheap accommodation, good coffee, and, more importantly, several good pubs serving good, &lt;br&gt;non-Australian, beer.&lt;br&gt;&lt;br&gt;&lt;strong&gt;[Costs]&lt;/strong&gt;&lt;br&gt;&lt;br&gt;Kiwicon2k8 is a non-profit, non-commercial, non-corporate-funded event.&lt;br&gt;&lt;br&gt;Attendance for the entire weekend will cost $50 for employed individuals (self-employed and salaried). There is a discounted rate of $30 for students and the unemployed. GST receipts can be issued upon request. If your management can't be convinced of the value of something that only costs $50, we're happy to issue you with some kind of personalised limited edition invitation in crayon, glitter pen, and macaroni &lt;br&gt;(spray-painted gold for that luxe look) for the low enterprise-only price of $500.&lt;br&gt;&lt;br&gt;&lt;strong&gt;[Topics]&lt;/strong&gt;&lt;br&gt;&lt;br&gt;Suggested topics include but are not limited to:&lt;br&gt;&lt;br&gt; - Crowd Control Techniques and Panic Modeling&lt;br&gt; - Information Warfare / Industrial Espionage&lt;br&gt; - Malware (Viruses, Spam, Phishing, Botnets)&lt;br&gt; - Cellular Networks (GSM,GPRS,CDMA,3G,4G)&lt;br&gt; - Application Security, Testing, Fuzzing&lt;br&gt; - Government Spy Networks / Surveillance&lt;br&gt; - Nanotechnology / Quantum Computing&lt;br&gt; - Access Control and Authentication&lt;br&gt; - Wireless / Bluetooth / Infrared&lt;br&gt; - Social Engineering / Trolling&lt;br&gt; - Breaking EAL Certified Kit&lt;br&gt; - Forensics / Antiforensics&lt;br&gt; - Banking / ATMs / Carding&lt;br&gt; - Exploitation Techniques&lt;br&gt; - Layer 1/2/3 Nastiness&lt;br&gt; - Reverse Engineering&lt;br&gt; - Phreaking / VoIP&lt;br&gt; - Virtualisation&lt;br&gt; - Web Security&lt;br&gt; - Lockpicking&lt;br&gt; - Biometrics&lt;br&gt; - Hypnosis&lt;br&gt; - Crypto&lt;br&gt; - Ohday&lt;br&gt; - 23&lt;br&gt;&lt;br&gt;There is no pre-determined talk length but we ask that speakers limit their presentation to an hour, including some question time.&lt;br&gt;&lt;br&gt;Since Kiwicon is a non-profit organisation, there is no funding available for travel and/or accomodation, even for IT rockstars.  However, if your talk is accepted, a formal letter will be provided for employer leverage, and almost certainly, unless you're a complete jackoff, people will try and buy you beer.&lt;br&gt;&lt;br&gt;To submit a presentation to Kiwicon2k8, send an email to &lt;a href=&quot;mailto:cfp@kiwicon.org&quot;&gt;cfp@kiwicon.org&lt;/a&gt; with the following information:&lt;br&gt;&lt;br&gt;Name or Handle:&lt;br&gt;Country of Residence:&lt;br&gt;Employer (if applicable):&lt;br&gt;Presentation Title:&lt;br&gt;Presentation Length:&lt;br&gt;Presentation Synopsis:&lt;br&gt;Brief Bio:&lt;br&gt;&lt;br&gt;[CFP Submissions]&lt;br&gt;&lt;br&gt;Please submit your CFP by email to &lt;a href=&quot;mailto:cfp@kiwicon.org&quot;&gt;cfp@kiwicon.org&lt;/a&gt;, no later than 8:47pm NZST, Sunday 17th September 2008. There will be two rounds of selection,  with the first half of the talks chosen in August, so submit early for a better chance of acceptance.&lt;br&gt;&lt;br&gt;&lt;strong&gt;[Contacts &amp;amp; Further Information]&lt;/strong&gt;&lt;br&gt;&lt;br&gt;Email us: &lt;a href=&quot;mailto:kiwicon@kiwicon.org&quot;&gt;kiwicon@kiwicon.org&lt;/a&gt;&lt;br&gt;Check the site: &lt;a href=&quot;http://www.kiwicon.org/&quot;&gt;http://www.kiwicon.org/&lt;/a&gt;&lt;br&gt;Drop by silc: silc.isig.org.nz:2706/kiwicon&lt;br&gt;Join the list: &lt;a href=&quot;mailto:kiwicon-subscribe@lists.isig.org.nz&quot;&gt;kiwicon-subscribe@lists.isig.org.nz&lt;/a&gt;&lt;br&gt;&lt;br&gt;Greetz and thanks to all who helped make Kiwicon 2k7 the awesomeness it was, we'll see you *****ers again this year. Thick, meaty props to Pipes for stepping up and making 2k7 happen. We would miss you, but Sharrow's just as tall, and better looking. Sorry pal.&lt;br&gt;&lt;br&gt;-- The Kiwicon Cr&amp;uuml;e, 2k8 - Bogan, Metlstorm &amp;amp; Sharrow. m/&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://en.wikipedia.org/wiki/Ben_Hana&quot;&gt;http://en.wikipedia.org/wiki/Ben_Hana&lt;/a&gt;</description>
</item>

<item>
<title>Netcat over SSL  (Neat...)</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=892</link>
<description>Hello list,&lt;br&gt;&lt;br&gt;I updated a tool I wrote a long time ago. This time, it &lt;br&gt;features:&lt;br&gt;&lt;br&gt;- full SSL support (client and server with certificates)&lt;br&gt;- port proxying (TCP and UDP)&lt;br&gt;- SSL proxying&lt;br&gt;- IPv4/IPv6 proxying&lt;br&gt;- IPv4 and IPv6 support&lt;br&gt;&lt;br&gt;To know more:&lt;br&gt;&lt;a href=&quot;http://www.gomor.org/bin/view/GomorOrg/SslNetcat&quot;&gt;http://www.gomor.org/bin/view/GomorOrg/SslNetcat&lt;/a&gt;</description>
</item>

<item>
<title>fgdump (2.0.0) and pwdump (1.7.1) has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=891</link>
<description>Folks,&lt;br&gt;&lt;br&gt;The foofus.net team is pleased to announce updates to both fgdump (2.0.0) and pwdump (1.7.1), which incorporate a number of new features, the most significant of which is that both tools now support 64-bit targets.&lt;br&gt;&lt;br&gt;We are also pleased to announce the creation of a mailing list for the purposes of tool support, bug reports, feature requests and new revision announcements. This mailing list currently covers fgdump, pwdump and medusa.  Feel free to sign up at  &lt;a href=&quot;http://lists.foofus.net/listinfo.cgi/foofus-tools-foofus.net&quot;&gt;http://lists.foofus.net/listinfo.cgi/foofus-tools-foofus.net&lt;/a&gt;.&lt;br&gt;&lt;br&gt;For all the details on the latest fgdump and pwdump releases, please visit their home pages:&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.foofus.net/fizzgig/fgdump&quot;&gt;http://www.foofus.net/fizzgig/fgdump&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.foofus.net/fizzgig/pwdump&quot;&gt;http://www.foofus.net/fizzgig/pwdump&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;As always, please contact me with any bug reports or feature requests.&lt;br&gt;&lt;br&gt;--f fizzgig@foofus.net</description>
</item>

<item>
<title>Issue 16 of Insecure Magazine has been released</title>
<link>http://www.professionalsecuritytesters.org/modules.php?name=News&amp;file=article&amp;sid=890</link>
<description>(IN)SECURE Magazine is a freely available digital security magazine discussing some of the hottest  information security topics.&lt;br&gt;&lt;br&gt;Issue 16 has just been released. Download it from: &lt;a href=&quot;http://www.insecuremag.com/&quot;&gt;http://www.insecuremag.com&lt;/a&gt;&lt;br&gt;&lt;strong&gt;&lt;br&gt;The covered topics include:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;- Security policy considerations for virtual worlds&lt;br&gt;- US political elections and cybercrime&lt;br&gt;- Using packet analysis for network troubleshooting&lt;br&gt;- The effectiveness of industry certifications&lt;br&gt;- Building a secure future: lessons learned from 2007's highest profile security events&lt;br&gt;- Advanced social engineering and human exploitation, part 2&lt;br&gt;- Interview with Nitesh Dhanjani, Senior Manager at Ernst &amp;amp; Young&lt;br&gt;- Is your data safe? Secure your web apps&lt;br&gt;- RSA Conference 2008&lt;br&gt;- Producing secure software with security enhanced software development processes&lt;br&gt;- Network event analysis with Net/FSE&lt;br&gt;- Security risks for mobile computing on public WLANs: hotspot registration&lt;br&gt;- Black Hat Europe 2008 Briefings &amp;amp; Training&lt;br&gt;- A Japanese perspective on Software Configuration Management&lt;br&gt;- Windows log forensics: did you cover your tracks?&lt;br&gt;- Traditional vs. non-tranditional database auditing&lt;br&gt;- Payment card data: know your defense options&lt;br&gt;&lt;br&gt;Visit the (IN)SECURE Magazine web site at: &lt;a href=&quot;http://www.insecuremag.com/&quot;&gt;http://www.insecuremag.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;Subscribe to our RSS feed at:  &lt;a href=&quot;http://feeds.feedburner.com/insecuremagazine&quot;&gt;http://feeds.feedburner.com/insecuremagazine&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thanks goes to the following companies for their support of (IN)SECURE magazine:&lt;br&gt;&lt;br&gt;Qualys - &lt;a href=&quot;http://www.qualys.com/pci_compliance/se-g&quot;&gt;http://www.qualys.com/pci_compliance/se-g&lt;/a&gt;&lt;br&gt;GFI - &lt;a href=&quot;http://www.gfi.com/adentry.asp?adv=62&amp;amp;loc=41&quot;&gt;http://www.gfi.com/adentry.asp?adv=62&amp;amp;loc=41&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;strong&gt;Contact:&lt;/strong&gt;&lt;br&gt;&lt;br&gt;- For information on contributing to (IN)SECURE Magazine, please contact Chief Editor Mirko Zorz at editor( at )insecuremag.com&lt;br&gt;- For marketing inquiries do contact Marketing Director Berislav Kucan at marketing( at )insecuremag.com</description>
</item>

</channel>
</rss>