<rss version="2.0"><channel><title>Penetration Testing (pen-test) Mailing List</title>
<link>http://seclists.org/#pen-test</link>
<description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: SSL MITM not on port 443</title><description>Posted by Ahmad Taha on Aug 28&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;You can also try to redirect/tunnel the connection, use some tool to 
&lt;br /&gt;
listen on the required port and forward the traffic to ettercap on port 
&lt;br /&gt;
443, you can accomplish this with many ways. I hope this will fix your 
&lt;br /&gt;
problem:)
&lt;br /&gt;
&lt;p&gt;Regards,
&lt;br /&gt;
Ahmad Taha Zaki
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/pen-test/2008/Aug/0146.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0146.html</guid>
<pubDate>Thu, 28 Aug 2008 11:56:33 +0300</pubDate></item>
<item><title>Re: SSL MITM not on port 443</title><description>Posted by Roman Fulop on Aug 28&lt;p&gt;


&lt;p&gt;
you could always redirect traffic to certain port woth iptables.
&lt;br /&gt;
&lt;p&gt;christopher.riley_at_r-it&amp;#46;at wrote:
&lt;br /&gt;
&amp;gt; Unfortunately i&#39;ve already tried to use Paros as a MITM proxy for the 
&lt;br /&gt;
&amp;gt; connection. The application does complain about the certificate, as you&#39;d 
&lt;br /&gt;
&amp;gt; expect. However I need to...</description>
<link>http://seclists.org/pen-test/2008/Aug/0145.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0145.html</guid>
<pubDate>Thu, 28 Aug 2008 10:43:57 +0200</pubDate></item>
<item><title>RE: SSL MITM not on port 443</title><description>Posted by christopher.riley_at_r-it.at on Aug 28&lt;p&gt;


&lt;p&gt;
Unfortunately i&#39;ve already tried to use Paros as a MITM proxy for the 
&lt;br /&gt;
connection. The application does complain about the certificate, as you&#39;d 
&lt;br /&gt;
expect. However I need to replace the normal Paros certificate with one 
&lt;br /&gt;
that is faked especially for the application (such as the ones created by 
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2008/Aug/0144.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0144.html</guid>
<pubDate>Thu, 28 Aug 2008 08:21:16 +0200</pubDate></item>
<item><title>Re: SSL MITM not on port 443</title><description>Posted by James Matthews on Aug 27&lt;p&gt;


&lt;p&gt;
I have found that ethercap worked nicely!
&lt;br /&gt;
&lt;p&gt;On Wed, Aug 27, 2008 at 10:24 AM, Robbie Gill &amp;lt;rgill_at_arubanetworks&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Try pointing the application to a MITM proxy like Paros
&lt;br /&gt;
&amp;gt; (http://www.parosproxy.org/index.shtml) or WebScarab
&lt;br /&gt;
&amp;gt; (...</description>
<link>http://seclists.org/pen-test/2008/Aug/0143.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0143.html</guid>
<pubDate>Wed, 27 Aug 2008 13:13:24 -0700</pubDate></item>
<item><title>New Tool Released:  XTest1.0!</title><description>Posted by Jason Ostrom on Aug 27&lt;p&gt;


&lt;p&gt;
http://xtest.sourceforge.net
&lt;br /&gt;
&lt;p&gt;Sipera VIPER Lab has released a new &amp;amp; free test tool, XTest, that is a
&lt;br /&gt;
result of our research into the ability or inability (your choice) of
&lt;br /&gt;
wired 802.1x with EAP-MD5 to protect IP Phone endpoints and the VoIP
&lt;br /&gt;
Infrastructure.
&lt;br /&gt;
&lt;p&gt;Jason Ostrom
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/pen-test/2008/Aug/0142.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0142.html</guid>
<pubDate>Wed, 27 Aug 2008 12:51:39 -0500</pubDate></item>
<item><title>RE: SSL MITM not on port 443</title><description>Posted by Robbie Gill on Aug 27&lt;p&gt;


&lt;p&gt;
Try pointing the application to a MITM proxy like Paros
&lt;br /&gt;
(http://www.parosproxy.org/index.shtml) or WebScarab
&lt;br /&gt;
(http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project). Such
&lt;br /&gt;
a proxy sits in the middle of the client application and the server and
&lt;br /&gt;
presents its own certificate to both...</description>
<link>http://seclists.org/pen-test/2008/Aug/0141.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0141.html</guid>
<pubDate>Wed, 27 Aug 2008 10:24:18 -0700</pubDate></item>
<item><title>New Nmap Features</title><description>Posted by Daniel Miessler on Aug 27&lt;p&gt;


&lt;p&gt;
For anyone interested, here&#39;s a summary of the list of features in
&lt;br /&gt;
Nmap&#39;s latest version---as presented by Fyodor at BH/DC.
&lt;br /&gt;
&lt;p&gt;http://dmiessler.com/blog/a-summary-of-new-nmap-features-from-blackhatdefcon-2008
&lt;br /&gt;
&lt;p&gt;Cheers,
&lt;br /&gt;
&lt;p&gt;</description>
<link>http://seclists.org/pen-test/2008/Aug/0140.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0140.html</guid>
<pubDate>Wed, 27 Aug 2008 09:32:21 -0400</pubDate></item>
<item><title>SSL MITM not on port 443</title><description>Posted by christopher.riley_at_r-it.at on Aug 27&lt;p&gt;


&lt;p&gt;
I&#39;ve come across a problem in a pentest that I&#39;m working on right now that 
&lt;br /&gt;
I thought the members of the list might be able to assist me with.
&lt;br /&gt;
&lt;p&gt;I&#39;m working with a propriatary software (written in C++) that communicates 
&lt;br /&gt;
on a high port number using HTTPS. I&#39;m trying to test to see if the 
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2008/Aug/0139.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0139.html</guid>
<pubDate>Wed, 27 Aug 2008 13:32:32 +0200</pubDate></item>
<item><title>Read MAPI emails and play VOIP traffic dump</title><description>Posted by mark mark on Aug 27&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;Is there any way you can read emails on Outlook/Exchange environment
&lt;br /&gt;
by listening on the wire? We have the traffic dump but wireshark only
&lt;br /&gt;
says the protocol used is MAPI. Also for the VOIP, traffic dump, we
&lt;br /&gt;
ended up with some file that won&#39;t play on any media player.. Any idea
&lt;br /&gt;
how to...</description>
<link>http://seclists.org/pen-test/2008/Aug/0138.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0138.html</guid>
<pubDate>Wed, 27 Aug 2008 15:48:58 +0400</pubDate></item>
<item><title>Re: Keylogger winlinux</title><description>Posted by michele dallachiesa on Aug 27&lt;p&gt;


&lt;p&gt;
2008/8/18 administrator - &amp;lt;illegal.visitor_at_gmail&amp;#46;com&amp;gt;:
&lt;br /&gt;
&amp;gt; Hi there,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I am new to the pentesting field and currently busy with OSCP. I have
&lt;br /&gt;
&amp;gt; read a great number of books and publications. From all of this I
&lt;br /&gt;
&amp;gt; compiled a handy toolset. However I am missing a good...</description>
<link>http://seclists.org/pen-test/2008/Aug/0137.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0137.html</guid>
<pubDate>Wed, 27 Aug 2008 10:48:18 +0200</pubDate></item>
<item><title>SensePost reDuh Tools now available for download</title><description>Posted by Glenn Wilkinson on Aug 27&lt;p&gt;


&lt;p&gt;
Hi there,
&lt;br /&gt;
&lt;p&gt;We have just blogged the availability of the reDuh tools covered in our
&lt;br /&gt;
BlackHat/Defcon 2008 talk. [http://www.sensepost.com/blog/2399.html]
&lt;br /&gt;
&lt;p&gt;reDuh allows you to tunnel TCP over well formed HTTP, effectively
&lt;br /&gt;
creating a full TCP circuit through an uploaded jsp, php or asp page. A
&lt;br /&gt;...</description>
<link>http://seclists.org/pen-test/2008/Aug/0136.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0136.html</guid>
<pubDate>Wed, 27 Aug 2008 09:25:56 +0200</pubDate></item>
<item><title>PacSec 2008 CFP (Deadline Sept. 1, Conference Nov. 1213) and BA-Con 2008 Speakers (Sept. 30 Oct. 1)</title><description>Posted by Dragos Ruiu on Aug 26&lt;p&gt;


&lt;p&gt;
Spanish url: http://ba-con.com.ar/speakers.html?language=es
&lt;br /&gt;
&lt;p&gt;Speaker list and Dojos for BA-Con, September 30, October 1st.
&lt;br /&gt;
(all presentations in both Spanish and English)
&lt;br /&gt;
&lt;p&gt;&nbsp; Presentations:
&lt;br /&gt;
&lt;p&gt;&nbsp; WPA/WPA2: how long is it gonna make it - C&eacute;dric Blancher &amp;amp; Simon Mar&eacute;chal, 
&lt;br /&gt;
EADS &amp;amp; SGDN
&lt;br /&gt;
&nbsp;...</description>
<link>http://seclists.org/pen-test/2008/Aug/0135.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0135.html</guid>
<pubDate>Tue, 26 Aug 2008 13:02:12 -0700</pubDate></item>
<item><title>Re: Comprehensive firewall test using Nmap?</title><description>Posted by Gabriele Brosulo on Aug 26&lt;p&gt;


&lt;p&gt;
On Saturday 23 August 2008 21:32:07 Bill Weiss wrote:
&lt;br /&gt;
&amp;gt; Gabriele Brosulo(brosulo_at_edisoft&amp;#46;net)&amp;#64;Thu, Aug 21, 2008 at 11:08:02AM +0200:
&lt;br /&gt;
&amp;gt; &amp;gt; On Thursday 21 August 2008 09:00:02 Alexander Sandstr?m Krantz A wrote:
&lt;br /&gt;
&amp;gt; &amp;gt; &amp;gt; Is it possible to automatically alter the source...</description>
<link>http://seclists.org/pen-test/2008/Aug/0134.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0134.html</guid>
<pubDate>Tue, 26 Aug 2008 09:33:11 +0200</pubDate></item>
<item><title>Re: Comprehensive firewall test using Nmap?</title><description>Posted by M.B.Jr. on Aug 22&lt;p&gt;


&lt;p&gt;
No CJ,
&lt;br /&gt;
I guess Alexander means an automatic port alteration during your
&lt;br /&gt;
&lt;p&gt;nmap -g $srcport -oA blabla-$srcport etc
&lt;br /&gt;
&lt;p&gt;suggestion.
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;Regards,
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;On 8/21/08, Carl-Johan Bostorp &amp;lt;Carl-Johan.Bostorp_at_hps&amp;#46;se&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt;  Using simple scripting would be a good way to get things...</description>
<link>http://seclists.org/pen-test/2008/Aug/0133.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0133.html</guid>
<pubDate>Fri, 22 Aug 2008 18:00:19 -0300</pubDate></item>
<item><title>Re: a quotgoodquot vulnerability for educational purposes</title><description>Posted by eldraco on Aug 25&lt;p&gt;


&lt;p&gt;
hi all, 
&lt;br /&gt;
&lt;p&gt;we are teaching pentesting too, and we use:
&lt;br /&gt;
&lt;p&gt;Solution a:
&lt;br /&gt;
1- webgoat (you can use the one in www.damnvulnerablelinux.org)
&lt;br /&gt;
2- metasploit
&lt;br /&gt;
&lt;p&gt;Solution b:
&lt;br /&gt;
We also use w3af, that comes with a lot of .php files (all what it can test) 
&lt;br /&gt;
for apache, so you can test your w3af installation. This...</description>
<link>http://seclists.org/pen-test/2008/Aug/0132.html</link><guid isPermaLink="true">http://seclists.org/pen-test/2008/Aug/0132.html</guid>
<pubDate>Mon, 25 Aug 2008 22:38:02 -0300</pubDate></item>
</channel></rss>