<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Dan Kaminsky &amp; Kevin Mitnick Hacked</title>
	<atom:link href="http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158636</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Tue, 11 Aug 2009 11:40:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158636</guid>
		<description>I&#039;ve got to agree with Morgan on this one. By far the easiest way to get behind a firewall is to abuse the wetware - the human - behind it. Either by redirecting to a malicious site or emailing a custom trojan.

There is always the possibility to find a o-day in the firewall, where a malformed packet causes the firewall to barf and fall over in an open state, but that&#039;s pretty unlikely, the leaks are usually from within.

Also, there is the risk of information leaking from your system via other channels, assuming it&#039;s worth an attackers effort - Google &#039;tempest&#039;</description>
		<content:encoded><![CDATA[<p>I&#8217;ve got to agree with Morgan on this one. By far the easiest way to get behind a firewall is to abuse the wetware &#8211; the human &#8211; behind it. Either by redirecting to a malicious site or emailing a custom trojan.</p>
<p>There is always the possibility to find a o-day in the firewall, where a malformed packet causes the firewall to barf and fall over in an open state, but that&#8217;s pretty unlikely, the leaks are usually from within.</p>
<p>Also, there is the risk of information leaking from your system via other channels, assuming it&#8217;s worth an attackers effort &#8211; Google &#8216;tempest&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158623</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Mon, 10 Aug 2009 08:04:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158623</guid>
		<description>@Null: there could still be an 0-day in something you are using or the easiest target you, they could simply social engineer you to go to a site that drive by downloads something that then makes a connection out to them through your pfsense firewall. Nothing is unhackable, even un connected boxes have theoretical hacks bury it in concrete or destory it if you don&#039;t want it to leak.</description>
		<content:encoded><![CDATA[<p>@Null: there could still be an 0-day in something you are using or the easiest target you, they could simply social engineer you to go to a site that drive by downloads something that then makes a connection out to them through your pfsense firewall. Nothing is unhackable, even un connected boxes have theoretical hacks bury it in concrete or destory it if you don&#8217;t want it to leak.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: id</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158615</link>
		<dc:creator>id</dc:creator>
		<pubDate>Sat, 08 Aug 2009 21:50:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158615</guid>
		<description>&quot;No one has ANY idea how long they</description>
		<content:encoded><![CDATA[<p>&#8220;No one has ANY idea how long they</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Price</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158554</link>
		<dc:creator>Jeff Price</dc:creator>
		<pubDate>Wed, 05 Aug 2009 16:42:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158554</guid>
		<description>Is that really all that impressive? Mitnick&#039;s strong points were Social Engineering and Buffer Overflows. Does it really surprise you? This isn&#039;t the first time he&#039;s been hacked. Hes even said too that there if no fool proof security, repeatedly in his books.</description>
		<content:encoded><![CDATA[<p>Is that really all that impressive? Mitnick&#8217;s strong points were Social Engineering and Buffer Overflows. Does it really surprise you? This isn&#8217;t the first time he&#8217;s been hacked. Hes even said too that there if no fool proof security, repeatedly in his books.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lol @ null</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158541</link>
		<dc:creator>lol @ null</dc:creator>
		<pubDate>Tue, 04 Aug 2009 22:36:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158541</guid>
		<description>@ null
if the server does not accept connections on any ports. then no.</description>
		<content:encoded><![CDATA[<p>@ null<br />
if the server does not accept connections on any ports. then no.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: katphyte</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158539</link>
		<dc:creator>katphyte</dc:creator>
		<pubDate>Tue, 04 Aug 2009 19:53:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158539</guid>
		<description>This just validates the fact that if you want something to stay secure, don&#039;t ever put it on the web.  And it&#039;s more than just a little freaky when you think about the fact that the h ackers behind it probably did it just to see if they could.  So what would a malicious attacker who is out for blood do?

I&#039;ll be the first one to say that no matter how much you know, there&#039;s someone out there who knows more. Too much confidence in yourself can make you forget that you&#039;re really just as vulnerable as the next person.</description>
		<content:encoded><![CDATA[<p>This just validates the fact that if you want something to stay secure, don&#8217;t ever put it on the web.  And it&#8217;s more than just a little freaky when you think about the fact that the h ackers behind it probably did it just to see if they could.  So what would a malicious attacker who is out for blood do?</p>
<p>I&#8217;ll be the first one to say that no matter how much you know, there&#8217;s someone out there who knows more. Too much confidence in yourself can make you forget that you&#8217;re really just as vulnerable as the next person.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: null</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158531</link>
		<dc:creator>null</dc:creator>
		<pubDate>Tue, 04 Aug 2009 15:39:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158531</guid>
		<description>can &quot;they&quot; hack a pfsense or openbsd router without open ports? just for web surfing, without servers listening?
this is not a chalenge, it is just a question...</description>
		<content:encoded><![CDATA[<p>can &#8220;they&#8221; hack a pfsense or openbsd router without open ports? just for web surfing, without servers listening?<br />
this is not a chalenge, it is just a question&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SpiderM@N</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158530</link>
		<dc:creator>SpiderM@N</dc:creator>
		<pubDate>Tue, 04 Aug 2009 14:57:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158530</guid>
		<description></description>
		<content:encoded><![CDATA[]]></content:encoded>
	</item>
	<item>
		<title>By: Sploo</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158519</link>
		<dc:creator>Sploo</dc:creator>
		<pubDate>Tue, 04 Aug 2009 05:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158519</guid>
		<description>Yes, i believe they CAN be that hidden.</description>
		<content:encoded><![CDATA[<p>Yes, i believe they CAN be that hidden.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Black of Hat</title>
		<link>http://www.darknet.org.uk/2009/08/dan-kaminsky-kevin-mitnick-hacked/#comment-158518</link>
		<dc:creator>Black of Hat</dc:creator>
		<pubDate>Tue, 04 Aug 2009 05:26:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1987#comment-158518</guid>
		<description>So who is this Zero For Owned group? I have read two of their zines. But there seems to be a lack of information about the group itself. Surely they can&#039;t be that well hideen underground.</description>
		<content:encoded><![CDATA[<p>So who is this Zero For Owned group? I have read two of their zines. But there seems to be a lack of information about the group itself. Surely they can&#8217;t be that well hideen underground.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

