<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Web Hacking</title>
	<atom:link href="http://www.darknet.org.uk/category/web-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>At Last &#8211; Adobe Launches Sandboxed Flash Player For Firefox</title>
		<link>http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/</link>
		<comments>http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/#comments</comments>
		<pubDate>Tue, 07 Feb 2012 18:34:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[adobe flash]]></category>
		<category><![CDATA[adobe flash player]]></category>
		<category><![CDATA[adobe flash security]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox-security]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flash exploit]]></category>
		<category><![CDATA[flash exploits]]></category>
		<category><![CDATA[flash player security]]></category>
		<category><![CDATA[flash sandbox]]></category>
		<category><![CDATA[flash security]]></category>
		<category><![CDATA[flash vulnerabilities]]></category>
		<category><![CDATA[hacking-firefox]]></category>
		<category><![CDATA[hacking-flash]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3254</guid>
		<description><![CDATA[Finally a proactive measure from Adobe to try and remedy the horrible security flaws they have introduced to Firefox with their Flash Player. There have been some massive hacks recently due to Flash - - Hackers Exploiting Latest Adobe Flash Bug On Large Scale - Adobe Patches Latest Flash Zero Day Vulnerability - Adobe Promises [...]]]></description>
			<content:encoded><![CDATA[<p>Finally a proactive measure from <a href="http://www.darknet.org.uk/tag/adobe/">Adobe</a> to try and remedy the horrible security flaws they have introduced to Firefox with their Flash Player.</p>
<p>There have been some massive hacks recently due to Flash -</p>
<p>- <a href="http://www.darknet.org.uk/2011/06/hackers-exploiting-latest-adobe-flash-bug-on-large-scale/">Hackers Exploiting Latest Adobe Flash Bug On Large Scale</a><br />
- <a href="http://www.darknet.org.uk/2011/04/adobe-patches-latest-flash-zero-day-vulnerability/">Adobe Patches Latest Flash Zero Day Vulnerability</a><br />
- <a href="http://www.darknet.org.uk/2011/03/adobe-promises-patch-for-flash-0-day-being-used-in-targeted-attacks/">Adobe Promises Patch For Flash 0-day Being Used In Targeted Attacks</a></p>
<p>Those 3 were all in 2011!</p>
<blockquote><p>Adobe has released a beta version of Flash Player for Firefox, which has better protection against vulnerability exploits because of a new sandboxed architecture.</p>
<p>&#8220;The design of this sandbox is similar to what Adobe delivered with Adobe Reader X Protected Mode and follows the same Practical Windows Sandboxing approach,&#8221; said Peleus Uhley, platform security strategist at Adobe, in a blog post on Monday. &#8220;Like the Adobe Reader X sandbox, Flash Player will establish a low integrity, highly restricted process that must communicate through a broker to limit its privileged activities.&#8221;</p>
<p>In secure software development, sandboxing refers to the practice of isolating a process from the operating system in order to minimize the fallout of a potential exploit. This type of technology has gained popularity in recent years, primarily because of its use in Google Chrome, a browser that has never experienced a successful remote code execution attack so far.</p>
<p>Adobe decided to implement sandboxing in Adobe Reader back in 2010 in order to counter the large number of exploits that targeted the product and its users. The technology was built into Adobe Reader X (10.0) and is based on the same sandboxing principles that Google used when developing Chrome.</p>
<p>Later that same year Adobe also launched a sandboxed version of Flash Player for Chrome and promised to explore the possibility of doing the same for other browsers. The new sandboxed Flash Player for Firefox, which works with Windows Vista and Windows 7, is the result of those efforts. </p></blockquote>
<p>They have been talking about sandboxing for a long time and did mention they wanted to sandbox <a href="http://www.darknet.org.uk/2010/10/adobe-pdf-reader-rewrite-to-include-sandbox-feature/">Adobe PDF Reader</a> too, <a href="http://www.darknet.org.uk/tag/chrome/">Chrome</a> has had great success with it&#8217;s sandbox model and I&#8217;m sure many more software vendors will follow suit.</p>
<p>It&#8217;s good to see this approach with the web becoming an extremely dangerous place and more and more commerce is moving online, this gives us a deadly mix of poor security and lots of money floating around.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Critical Flash Player vulnerabilities have regularly been exploited to infect computers with malware during the past several years. Along with Java and Adobe Reader, Flash Player is one of the most attacked software applications, because its vulnerabilities can usually be exploited by simply visiting a malicious website.</p>
<p>&#8220;Since its launch in November 2010, we have not seen a single successful exploit in the wild against Adobe Reader X,&#8221; Uhley said. &#8220;We hope to see similar results with the Flash Player sandbox for Firefox once the final version is released later this year.&#8221;</p>
<p>However, the success of this version at deterring cybercriminals from writing Flash Player exploits in the future will largely depend on how quickly it gets adopted. In order to speed up the process, Adobe is working on a new update mechanism, the company&#8217;s senior manager for corporate communications, Wiebke Lips, said.</p>
<p>Having a sandboxed version of Flash Player for every major browser, not just Chrome and Firefox, is also important, if Adobe wants cybercriminals to lose interest in its product. &#8220;We are currently in the process of researching the best path to provide Flash Player sandbox protection for Internet Explorer,&#8221; Lips said.</p>
<p>However, because Internet Explorer has a completely different plug-in architecture than Chrome and Firefox, namely ActiveX, developing a sandboxed Flash Player version for it requires a different approach, Lips said. Nevertheless, the current version of Flash Player supports Protected Mode in Internet Explorer 7 or later on Windows Vista and Windows 7. </p></blockquote>
<p>I&#8217;d like to see them implement a much better and more user-friendly update system for Flash player, so when the update comes out more users get it ASAP.</p>
<p>Also, this is only for <a href="http://www.darknet.org.uk/tag/firefox/">Firefox</a> and the largest target for malware peddlers is Internet <del datetime="2012-02-07T18:31:59+00:00">Exploder</del> Explorer &#8211; so they better get that version sorted out soon too.</p>
<p>Source: <a href="http://www.networkworld.com/news/2012/020612-adobe-launches-sandboxed-flash-player-255783.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3254+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;t=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/&amp;title=At+Last+%E2%80%93+Adobe+Launches+Sandboxed+Flash+Player+For+Firefox" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2012%2F02%2Fat-last-adobe-launches-sandboxed-flash-player-for-firefox%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2012/02/at-last-adobe-launches-sandboxed-flash-player-for-firefox/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>theHarvester &#8211; Gather E-mail Accounts, Subdomains, Hosts, Employee Names &#8211; Information Gathering Tool</title>
		<link>http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/</link>
		<comments>http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 15:29:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking tool]]></category>
		<category><![CDATA[info gathering]]></category>
		<category><![CDATA[info gathering tool]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[information gathering tool]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[shodan]]></category>
		<category><![CDATA[snooping]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3253</guid>
		<description><![CDATA[theHarvester is a tool to gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database. This tools is intended to help Penetration testers in the early stages of the project It&#8217;s a really simple tool, but very effective. The sources supported [...]]]></description>
			<content:encoded><![CDATA[<p>theHarvester is a tool to gather emails, subdomains, hosts, employee names, open ports and banners from different public sources like search engines, PGP key servers and SHODAN computer database. </p>
<p>This tools is intended to help Penetration testers in the early stages of the project It&#8217;s a really simple tool, but very effective.</p>
<p>The sources supported are:</p>
<ul>
<li>    Google &#8211; emails,subdomains/hostnames</li>
<li>    Google profiles &#8211; Employee names</li>
<li>    Bing search &#8211; emails, subdomains/hostnames,virtual hosts</li>
<li>    Pgp servers &#8211; emails, subdomains/hostnames</li>
<li>    Linkedin &#8211; Employee names</li>
<li>    Exalead &#8211; emails,subdomain/hostnames</li>
</ul>
<p><strong>New Features</strong></p>
<ul>
<li>    Time delays between requests</li>
<li>    XML and HTML results export</li>
<li>    Search a domain in all sources</li>
<li>    Virtual host verifier</li>
<li>    Shodan computer database integration</li>
<li>    Active enumeration (DNS enumeration,DNS reverse lookups, DNS TLD expansion)</li>
<li>    Basic graph with stats</li>
</ul>
<p><strong>Examples</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>Searching emails accounts for the domain microsoft.com, it will work with the first 500 google results:</p>
<pre><code>./theharvester.py -d microsoft.com -l 500 -b google</code></pre>
<p>Searching emails accounts for the domain microsoft.com in a PGP server, here it&#8217;s not necessary to specify the limit.</p>
<pre><code>./theharvester.py -d microsoft.com -b pgp</code></pre>
<p>Searching for user names that works in the company microsoft, we use google as search engine, so we need to specify the limit of results we want to use:</p>
<pre><code>./theharvester.py -d microsoft.com -l 200 -b linkedin</code></pre>
<p>Searching in all sources at the same time, with a limit of 200 results:</p>
<pre><code>./theHarvester.py -d microsoft.com -l 200 -b all</code></pre>
<p>You can download theHarvester here:</p>
<p><a href="https://theharvester.googlecode.com/files/theHarvester-2.1_BH2011_Arsenal.tar">theHarvester-2.1_BH2011_Arsenal.tar</a></p>
<p>Or read more <a href="http://www.edge-security.com/theHarvester.php">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=theHarvester+%E2%80%93+Gather+E-mail+Accounts%2C+Subdomains%2C+Hosts%2C+Employee+Names+%E2%80%93+Information+Gathering+To...+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3253+from+%40THEdark..." title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/&amp;t=theHarvester+%E2%80%93+Gather+E-mail+Accounts%2C+Subdomains%2C+Hosts%2C+Employee+Names+%E2%80%93+Information+Gathering+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/&amp;title=theHarvester+%E2%80%93+Gather+E-mail+Accounts%2C+Subdomains%2C+Hosts%2C+Employee+Names+%E2%80%93+Information+Gathering+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/&amp;title=theHarvester+%E2%80%93+Gather+E-mail+Accounts%2C+Subdomains%2C+Hosts%2C+Employee+Names+%E2%80%93+Information+Gathering+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/&amp;title=theHarvester+%E2%80%93+Gather+E-mail+Accounts%2C+Subdomains%2C+Hosts%2C+Employee+Names+%E2%80%93+Information+Gathering+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/&amp;title=theHarvester+%E2%80%93+Gather+E-mail+Accounts%2C+Subdomains%2C+Hosts%2C+Employee+Names+%E2%80%93+Information+Gathering+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2012%2F01%2Ftheharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2012/01/theharvester-gather-e-mail-accounts-subdomains-hosts-employee-names-information-gathering-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Arachni v0.4 Released &#8211; High-Performance (Open Source) Web Application Security Scanner Framework</title>
		<link>http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/</link>
		<comments>http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 17:38:47 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[arachni]]></category>
		<category><![CDATA[arachni v0.4]]></category>
		<category><![CDATA[path traversal scanner]]></category>
		<category><![CDATA[ruby]]></category>
		<category><![CDATA[sql-injection-scanner]]></category>
		<category><![CDATA[web application security scanner]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[web-security-framework]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3248</guid>
		<description><![CDATA[Arachni is a high-performance (Open Source) Web Application Security Scanner Framework written in Ruby. This version includes lots of goodies, including: A new light-weight RPC implementation (No more XMLRPC) High Performance Grid (HPG) &#8212; Combines the resources of multiple nodes for lightning-fast scans Updated WebUI to provide access to HPG features and context-sensitive help Accuracy [...]]]></description>
			<content:encoded><![CDATA[<p>Arachni is a high-performance (Open Source) Web Application Security Scanner Framework written in Ruby.</p>
<p>This version includes lots of goodies, including:</p>
<ul>
<li>A new light-weight RPC implementation (No more XMLRPC)</li>
<li>High Performance Grid (HPG) &#8212; Combines the resources of multiple nodes for lightning-fast scans</li>
<li>Updated WebUI to provide access to HPG features and context-sensitive help</li>
<li>Accuracy improvements and bugfixes for the XSS, SQL Injection and Path Traversal modules</li>
<li>New report formats (JSON, Marshal, YAML)</li>
<li>Cygwin package for Windows</li>
</ul>
<p><strong>New plugins</strong></p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>ReScan — It uses the AFR report of a previous scan to extract the sitemap in order to avoid a redundant crawl.</li>
<li>BeepNotify — Beeps when the scan finishes.</li>
<li>LibNotify — Uses the libnotify library to send notifications for each discovered issue and a summary at the end of the scan.</li>
<li>EmailNotify — Sends a notification (and optionally a report) over SMTP at the end of the scan.</li>
<li>Manual verification — Flags issues that require manual verification as untrusted in order to reduce the signal-to-noise ratio.</li>
<li>Resolver — Resolves vulnerable hostnames to IP addresses.</li>
</ul>
<p>IF you want a slightly more detailed description of what&#8217;s changed you can check <a href="http://trainofthought.segfault.gr/2012/01/07/arachni-v0-4-is-out/">here</a>, or view the <a href="http://arachni.segfault.gr/latest#v0.4">ChangeLog</a>.</p>
<p>You can download Arachni v0.4 here:</p>
<p>Windows &#8211; <a href="http://downloads.segfault.gr/arachni/arachni-v0.4.0.2-cygwin.exe">arachni-v0.4.0.2-cygwin.exe</a><br />
Linux &#8211; <a href="https://github.com/Zapotek/arachni/downloads/arachni-v0.4.0.2-cde.tar.gz">arachni-v0.4.0.2-cde.tar.gz</a></p>
<p>Or read more <a href="http://arachni.segfault.gr">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Arachni+v0.4+Released+%E2%80%93+High-Performance+%28Open+Source%29+Web+Application+Security+Scanner+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3248+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/&amp;t=Arachni+v0.4+Released+%E2%80%93+High-Performance+%28Open+Source%29+Web+Application+Security+Scanner+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/&amp;title=Arachni+v0.4+Released+%E2%80%93+High-Performance+%28Open+Source%29+Web+Application+Security+Scanner+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/&amp;title=Arachni+v0.4+Released+%E2%80%93+High-Performance+%28Open+Source%29+Web+Application+Security+Scanner+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/&amp;title=Arachni+v0.4+Released+%E2%80%93+High-Performance+%28Open+Source%29+Web+Application+Security+Scanner+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/&amp;title=Arachni+v0.4+Released+%E2%80%93+High-Performance+%28Open+Source%29+Web+Application+Security+Scanner+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2012%2F01%2Farachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2012/01/arachni-v0-4-released-high-performance-open-source-web-application-security-scanner-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ramnit Worm Stealing Facebook Account Passwords, E-mail Address &amp;  Bank Details</title>
		<link>http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/</link>
		<comments>http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 16:38:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spammers & Scammers]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[banking trojan]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[facebook malware]]></category>
		<category><![CDATA[facebook security]]></category>
		<category><![CDATA[facebook trojan]]></category>
		<category><![CDATA[facebook worm]]></category>
		<category><![CDATA[hack email]]></category>
		<category><![CDATA[hacking-facebook]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ramnit]]></category>
		<category><![CDATA[steal facebook account]]></category>
		<category><![CDATA[viruses]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3246</guid>
		<description><![CDATA[Oh look, another Facebook worm &#8211; this one seems pretty nasty and as usual it&#8217;s going for Facebook access details and then diving into banking credentials if it can find them. It&#8217;s mostly targeted at the UK though, worms of these type usually are geographically limited as they are targeting bank information &#8211; it&#8217;s better [...]]]></description>
			<content:encoded><![CDATA[<p>Oh look, another <a href="http://www.darknet.org.uk/tag/facebook/">Facebook</a> worm &#8211; this one seems pretty nasty and as usual it&#8217;s going for Facebook access details and then diving into banking credentials if it can find them.</p>
<p>It&#8217;s mostly targeted at the UK though, worms of these type usually are geographically limited as they are targeting bank information &#8211; it&#8217;s better to go after a certain niche of users.</p>
<p>45,000 isn&#8217;t a huge number though considering the latest stats say there are over 30 millions Facebook users from the UK alone.</p>
<blockquote><p>A bank account-raiding worm has started spreading on Facebook, stealing login credentials as it creeps across the site, security researchers have revealed.</p>
<p>Evidence recovered from a command-and-control server used to coordinate the evolving Ramnit worm confirms that the malware has already stolen 45,000 Facebook passwords and associated email addresses. Experts from Seculert, who found the controller node, have supplied Facebook with a list of all the stolen credentials found on the server. Most of the victims are from either the UK or France.</p>
<p>Ramnit differs from other worms, such as Koobface, that have used Facebook to spread because it relies on multiple infection techniques and has only recently extended onto social networks. Koobface, by contrast, only uses Facebook or Twitter to spread.</p>
<p>&#8220;Ramnit started as a file infector worm which steals FTP credentials and browser cookies, then added some financial-stealing capabilities, and now recently added Facebook worm capabilities,&#8221; Aviv Raff, CTO  at Seculert, told El Reg.</p>
<p>&#8220;We suspect that they use the Facebook logins to post on a victim&#8217;s friends&#8217; wall links to malicious websites which download Ramnit,&#8221; he added.</p></blockquote>
<p>There was indeed <a href="http://www.darknet.org.uk/2009/03/koobface-worm-variant-hits-facebook/" title="Koobface Worm Variant Hits Facebook">Koobface</a> some time back, but that was purely on Facebook &#8211; the danger with worms like Ramnit is that Facebook is only 1 of the vectors they are using to spread.</p>
<p>It&#8217;s a good job researchers got hold of one the command and control nodes &#8211; or this could have gotten a whole lot messier. Facebook has been pretty good lately blocking malicious strings and clamping down on worms as soon as they show up.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Ramnit first appeared in April 2010. By last July variants of the malware accounted for 17.3 per cent of all new malicious software infections, according to Symantec. A month later Trusteer reported that flavours of Ramnit were packing sophisticated banking login credential snaffling capabilities &#8211; technologies culled from the leak of the source code of the notorious ZeuS cybercrime toolkit at around the same time.</p>
<p>The new Ramnit configuration was able to bypass two-factor authentication and transaction-signing systems used by financial institutions to protect online banking sessions. The same technology might also be used to bypass two-factor authentication mechanisms in order to gain remote access to corporate networks, Seculert warns.</p>
<p>The move onto Facebook by the miscreants behind Ramnit seems designed primarily to expand the malware&#8217;s distribution network and infect more victims.</p>
<p>&#8220;We suspect that the attackers behind Ramnit are using the stolen credentials to expand the malware’s reach,&#8221; Seculert concludes, adding that capturing the login credentials of Facebook accounts creates a means to attack more sensitive accounts that happen to use the same email address and password combination.</p>
<p>&#8220;The cyber-criminals are also taking advantage of the fact that people usually use the same passwords for different web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks,&#8221; it said.</p>
<p>The Ramnit outbreak on Facebook follows the November outbreak of an earlier worm that tried to infect victims with a variant of ZeuS.</p></blockquote>
<p>The scary part is that the latest version of Ramnit can bypass two factor authentication! I&#8217;m not exactly sure how it does that, but it seems to have snagged a lot of features from the source code leak of <a href="http://www.darknet.org.uk/tag/zeus/">ZeuS</a>.</p>
<p>I would agree with the article though, people do tend to re-use passwords, they trust things shared on Facebook and it&#8217;s a good platform to spread malware rapidly.</p>
<p>Source: <a href="http://www.theregister.co.uk/2012/01/05/ramnit_social_networking/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Ramnit+Worm+Stealing+Facebook+Account+Passwords%2C+E-mail+Address+%26+Bank+Details+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3246+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/&amp;t=Ramnit+Worm+Stealing+Facebook+Account+Passwords%2C+E-mail+Address+%26++Bank+Details" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/&amp;title=Ramnit+Worm+Stealing+Facebook+Account+Passwords%2C+E-mail+Address+%26++Bank+Details" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/&amp;title=Ramnit+Worm+Stealing+Facebook+Account+Passwords%2C+E-mail+Address+%26++Bank+Details" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/&amp;title=Ramnit+Worm+Stealing+Facebook+Account+Passwords%2C+E-mail+Address+%26++Bank+Details" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/&amp;title=Ramnit+Worm+Stealing+Facebook+Account+Passwords%2C+E-mail+Address+%26++Bank+Details" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2012%2F01%2Framnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2012/01/ramnit-worm-stealing-facebook-account-passwords-e-mail-address-bank-details/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>sslyze &#8211; Fast and Full-Featured SSL Configuration Scanner</title>
		<link>http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/</link>
		<comments>http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/#comments</comments>
		<pubDate>Wed, 07 Dec 2011 21:29:26 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[detecting ssl renegotiation]]></category>
		<category><![CDATA[hacking ssl]]></category>
		<category><![CDATA[iSEC]]></category>
		<category><![CDATA[preventing ssl renegotiation]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[ssl config scanner]]></category>
		<category><![CDATA[ssl configuration scanner]]></category>
		<category><![CDATA[ssl renegotiation]]></category>
		<category><![CDATA[ssl renegotiations]]></category>
		<category><![CDATA[ssl scanner]]></category>
		<category><![CDATA[ssl server security]]></category>
		<category><![CDATA[sslyze]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3236</guid>
		<description><![CDATA[Transport Layer Security (TLS), commonly called SSL, is one of the most widely used protocols to secure network communications. As costs fall and user security and privacy expectations rise companies are deploying it more widely every year. Attacks against the CA system, SSL implementation flaws and aging protocol versions have grabbed news headlines, bringing attention [...]]]></description>
			<content:encoded><![CDATA[<p>Transport Layer Security (TLS), commonly called SSL, is one of the most widely used protocols to secure network communications. As costs fall and user security and privacy expectations rise companies are deploying it more widely every year. Attacks against the CA system, SSL implementation flaws and aging protocol versions have grabbed news headlines, bringing attention to weak configurations, and the need to avoid them. Additionally, server misconfiguration has always greatly increased the overhead caused by SSL, slowing the transition to improved communications security.</p>
<p>To help improve system configurations, iSEC is releasing the free software “SSLyze” tool. They have found this tool helpful for analyzing the configuration of SSL servers and for identifying misconfiguration such as the use of outdated protocol versions, weak hash algorithms in trust chains, insecure renegotiation, and session resumption settings.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>SSLyze is a stand-alone python application that looks for classic SSL misconfiguration, while providing the advanced user with the opportunity to customize the application via a simple plugin interface.</p>
<p><strong>Features</strong></p>
<ul>
<li>    Insecure renegotiation testing</li>
<li>    Scanning for weak strength ciphers</li>
<li>    Checking for SSLv2, SSLv3 and TLSv1 versions</li>
<li>    Server certificate information dump and basic validation</li>
<li>    Session resumption capabilities and actual resumption rate measurement</li>
<li>    Support for client certificate authentication</li>
<li>    Simultaneous scanning of multiple servers, versions and ciphers</li>
</ul>
<p>For example, SSLyze can help user’s identify server configurations vulnerable to <a href="http://www.darknet.org.uk/2011/10/thc-ssl-dosddos-tool-released-for-download/">THC’s recently released SSL DOS attack</a> by checking the server’s support for client-initiated renegotiations. For more information on testing for client-initiated renegotiations, you can read <a href="http://code.google.com/p/sslyze/wiki/ThcSslDOS">here</a>.</p>
<p>You can download sslyze here:</p>
<p><a href="http://sslyze.googlecode.com/files/sslyze-0.3_src.zip">sslyze-0.3_src.zip</a></p>
<p>Or read more <a href="http://code.google.com/p/sslyze/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3236+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;t=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/&amp;title=sslyze+%E2%80%93+Fast+and+Full-Featured+SSL+Configuration+Scanner" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fsslyze-fast-and-full-featured-ssl-configuration-scanner%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/sslyze-fast-and-full-featured-ssl-configuration-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Purchases WhisperCore &#8211; Full Disk Encryption For Android Phones</title>
		<link>http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/</link>
		<comments>http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/#comments</comments>
		<pubDate>Tue, 29 Nov 2011 16:55:56 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[android encryption]]></category>
		<category><![CDATA[android full disk encryption]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[full disk encyrption]]></category>
		<category><![CDATA[mobile encryption]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[twitter security]]></category>
		<category><![CDATA[twitter security software]]></category>
		<category><![CDATA[whisper systems]]></category>
		<category><![CDATA[whispercore]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3232</guid>
		<description><![CDATA[This is certainly an interesting acquisition and not one I would have expected, I&#8217;m not even exactly sure what Twitter is planning and why they would want a company focused on mobile encryption (and specifically on the Android platform). I can&#8217;t see any real corporate use for Twitter, so they won&#8217;t be pushing the security [...]]]></description>
			<content:encoded><![CDATA[<p>This is certainly an interesting acquisition and not one I would have expected, I&#8217;m not even exactly sure what <a href="http://www.darknet.org.uk/tag/twitter/">Twitter</a> is planning and why they would want a company focused on mobile encryption (and specifically on the Android platform).</p>
<p>I can&#8217;t see any real corporate use for Twitter, so they won&#8217;t be pushing the security aspects of it in terms of the application. Perhaps it&#8217;s just an equity play and has nothing to do with Twitter, or perhaps they have another offering up their sleeves which isn&#8217;t public yet.</p>
<blockquote><p>Twitter may be planning to boost its mobile security options with the acquisition of Whisper Systems, a company that offers security products for Android phones.</p>
<p>Whisper Systems&#8217; offerings include WhisperCore, software that enables full disk encryption as well as management tools for Android phones. It&#8217;s free for individual users while enterprise customers pay for the software. Other Whisper Systems products include text encryption, voice encryption, firewall software and encrypted backup.</p>
<p>In a blog post about the acquisition, Whisper Systems didn&#8217;t say much about what Twitter might be planning to do with the technology. &#8220;Now that we&#8217;re joining Twitter, we&#8217;re looking forward to bringing our technology and our expertise into Twitter&#8217;s products and services,&#8221; the company wrote on the blog.</p>
<p>It said that Whisper Systems software will continue to be available but that during a transition period the company will take the products and services offline. In a forum on Whisper Systems&#8217; website, people who are apparently unaware of the acquisition are already wondering why they can&#8217;t download products. Twitter did not reply to a request for comment about its plans for the technologies.</p></blockquote>
<p>The only path I can see, obvious path that is, would be for Twitter to integrate the encryption technology offered by WhisperCore into the official Twitter apps &#8211; making them more secure in both storing data locally and in transmitting data over insecure networks.</p>
<p>I don&#8217;t see how it really offers any value though, it&#8217;s not like anyone is actually sending anything important out over Twitter &#8211; apart from the odd DM (Direct Message) I would imagine.</p>
<p>It&#8217;ll be interesting to see what direction they take though and if we can actually find out why this acquisition took place.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>WhisperCore has a number of features designed to make up for security shortcomings in Android. For instance, WhisperCore users can selectively revoke permissions that an app requests while allowing the user to still use the app.</p>
<p>The software also includes a feature aimed at thwarting someone who has stolen a phone from determining the phone&#8217;s unlock code based on finger smudges on the screen. Some Android phones display rows of dots and a user unlocks the phone by dragging a finger over certain dots in a set pattern. An attacker might be able to recreate the pattern by examining finger smudges on the screen. WhisperCore displays unlock numbers in a column, so an attacker doesn&#8217;t know in which order the user hits the numbers to unlock the phone.</p>
<p>Earlier this year Whisper Systems released a software development kit so that developers could start building some WhisperCore features into their applications.</p>
<p>Few other companies are doing full disk encryption for Android, although there are many other companies taking other approaches to securing Android phones. Companies like 3LM and Good Technology offer mobile security services for enterprises. In addition, mobile device management products from companies including Sybase, BoxTone, Zenprise, Mobile Iron and Fiberlink let IT managers set basic policies like password requirement and remote wipe, and offer additional security capabilities. </p></blockquote>
<p>The other whacky idea could be to make Twitter into a dual-functioning security product &#8211; I don&#8217;t really see how that would work though. Social Networking + Device security = confused users.</p>
<p>If anyone has any bright ideas as to why you think this deal took place, do drop them in the comments section below.</p>
<p>Source: <a href="http://www.networkworld.com/news/2011/112811-twitter-scoops-up-mobile-security-253493.html?source=nww_rss">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Twitter+Purchases+WhisperCore+%E2%80%93+Full+Disk+Encryption+For+Android+Phones+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3232+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/&amp;t=Twitter+Purchases+WhisperCore+%E2%80%93+Full+Disk+Encryption+For+Android+Phones" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/&amp;title=Twitter+Purchases+WhisperCore+%E2%80%93+Full+Disk+Encryption+For+Android+Phones" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/&amp;title=Twitter+Purchases+WhisperCore+%E2%80%93+Full+Disk+Encryption+For+Android+Phones" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/&amp;title=Twitter+Purchases+WhisperCore+%E2%80%93+Full+Disk+Encryption+For+Android+Phones" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/&amp;title=Twitter+Purchases+WhisperCore+%E2%80%93+Full+Disk+Encryption+For+Android+Phones" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Ftwitter-purchases-whispercore-full-disk-encryption-for-android-phones%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/twitter-purchases-whispercore-full-disk-encryption-for-android-phones/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>sqlsus 0.7.1 Released &#8211; MySQL Injection &amp; Takeover Tool</title>
		<link>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/</link>
		<comments>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/#comments</comments>
		<pubDate>Mon, 21 Nov 2011 14:15:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[database-security]]></category>
		<category><![CDATA[hacking mysql]]></category>
		<category><![CDATA[hacking toold]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysql hacking tool]]></category>
		<category><![CDATA[mysql injection]]></category>
		<category><![CDATA[mysql injection tool]]></category>
		<category><![CDATA[mysql security]]></category>
		<category><![CDATA[mysql takeover]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1680</guid>
		<description><![CDATA[sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever [...]]]></description>
			<content:encoded><![CDATA[<p>sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface, you can retrieve the database(s) structure, inject your own SQL queries (even complex ones), download files from the web server, crawl the website for writable directories, upload and control a backdoor, clone the database(s), and much more&#8230;Whenever relevant, sqlsus will mimic a MySQL console output.</p>
<p>sqlsus focuses on speed and efficiency, optimising the available injection space, making the best use (I can think of) of MySQL functions. It uses stacked subqueries and an powerful blind injection algorithm to maximise the data gathered per web server hit. Using multithreading on top of that, sqlsus is an extremely fast database dumper, be it for inband or blind injection.If the privileges are high enough, sqlsus will be a great help for uploading a backdoor through the injection point, and takeover the web server.</p>
<p>It uses SQLite as a backend, for an easier use of what has been dumped, and integrates a lot of usual features (see below) such as cookie support, socks/http proxying, https..</p>
<p><strong>What&#8217;s New</strong></p>
<p>Starting with version 0.7, sqlsus now supports time-based blind injection and automatically detects web server / suhosin / etc.. length restrictions.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<ul>
<li>Added time-based blind injection support (added option &#8220;blind_sleep&#8221;, and renamed &#8220;string_to_match&#8221; to &#8220;blind_string&#8221;).</li>
<li>It is now possible to force sqlsus to exit when it&#8217;s hanging (i.e.: retrieving data), by hitting Ctrl-C more than twice.</li>
<li>Rewrite of &#8220;autoconf max_sendable&#8221;, so that sqlsus will properly detect which length restriction applies (WEB server / layer above). (removed option &#8220;max_sendable&#8221;, added options &#8220;max_url_length&#8221; and &#8220;max_inj_length&#8221;)</li>
<li>Uploading a file now sends it into chunks under the length restriction.</li>
<li>sqlsus now saves variables after each command, so that forcing it to quit (or killing it) will not discard the changes that were made.</li>
<li>Added a progress bar to inband mode, sqlsus now determines the number of rows to be returned prior to fetching them.</li>
<li>get db (tables/columns) in inband mode now uses multithreading (like everything else).</li>
<li>clone now uses count(*) if available (set by &#8220;get count&#8221; / &#8220;get db&#8221;), instead of using fetch-ahead.</li>
<li>In blind mode, &#8220;start&#8221; will now test if things work the way they should, by injecting 2 queries : one true and one false.</li>
<li>sqlsus now prints what configuration options are overridden (when a saved value differs from the configuration file).</li>
</ul>
<p>You can download sqlsus 0.7.1 here:</p>
<p><a href="http://sourceforge.net/projects/sqlsus/files/sqlsus/sqlsus-0.7.1.tgz/download">sqlsus-0.7.1.tgz</a></p>
<p>Or read more <a href="http://sqlsus.sourceforge.net/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1680+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;t=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/&amp;title=sqlsus+0.7.1+Released+%E2%80%93+MySQL+Injection+%26+Takeover+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fsqlsus-0-7-1-released-mysql-injection-takeover-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/sqlsus-0-7-1-released-mysql-injection-takeover-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GoLISMERO &#8211; Web Application Mapping Tool</title>
		<link>http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/</link>
		<comments>http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 19:58:51 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[golismero]]></category>
		<category><![CDATA[web application mapping]]></category>
		<category><![CDATA[web application mapping tool]]></category>
		<category><![CDATA[web mapping tool]]></category>
		<category><![CDATA[web site security]]></category>
		<category><![CDATA[web-application-hacking]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>
		<category><![CDATA[website mapping tool]]></category>
		<category><![CDATA[website scanner]]></category>
		<category><![CDATA[website security]]></category>
		<category><![CDATA[website-hacking]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3224</guid>
		<description><![CDATA[GoLISMERO helps you to map a web application, displaying the results in a readable format for security auditors and also prepares the results for integration with other web hacking tools as w3af, wfuzz, netcat, nikto, etc. Features Map a web aplication. Show all links and forms params as confortable format. Save results with some formats: [...]]]></description>
			<content:encoded><![CDATA[<p>GoLISMERO helps you to map a web application, displaying the results in a readable format for security auditors and also prepares the results for integration with other web hacking tools as <a href="http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/">w3af</a>, <a href="http://www.darknet.org.uk/2007/07/wfuzz-a-tool-for-bruteforcingfuzzing-web-applications/">wfuzz</a>, netcat, <a href="http://www.darknet.org.uk/2009/10/nikto-2-1-0-released-web-server-security-scanning-tool/">nikto</a>, etc.</p>
<p><strong>Features</strong></p>
<ul>
<li>    Map a web aplication.</li>
<li>    Show all links and forms params as confortable format.</li>
<li>    Save results with some formats: text, cvs, html, raw (for parsing with bash script) and wfuzz script.</li>
<li>    Detect common vulnerabilites of web application.</li>
<li>    Filter web information retaining only what is important.</li>
<li>    Many other features you can find very useful. </li>
</ul>
<p>You can download GoLISMERO here:</p>
<p><a href="http://golismero.googlecode.com/files/GoLISMERO_last.zip">GoLISMERO_last.zip</a></p>
<p>Or read more <a href="https://code.google.com/p/golismero/ ">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=GoLISMERO+%E2%80%93+Web+Application+Mapping+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3224+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/&amp;t=GoLISMERO+%E2%80%93+Web+Application+Mapping+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/&amp;title=GoLISMERO+%E2%80%93+Web+Application+Mapping+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/&amp;title=GoLISMERO+%E2%80%93+Web+Application+Mapping+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/&amp;title=GoLISMERO+%E2%80%93+Web+Application+Mapping+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/&amp;title=GoLISMERO+%E2%80%93+Web+Application+Mapping+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fgolismero-web-application-mapping-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/golismero-web-application-mapping-tool/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>w3af v1.1 Released For Download &#8211; Web Application Attack &amp; Audit Framework</title>
		<link>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/</link>
		<comments>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/#comments</comments>
		<pubDate>Mon, 14 Nov 2011 17:37:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Database Hacking]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[auditing-framework]]></category>
		<category><![CDATA[cross site scriping]]></category>
		<category><![CDATA[hacking-web-application]]></category>
		<category><![CDATA[hacking-web-sites]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[sql-injection-tool]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[web-applicaton-security]]></category>
		<category><![CDATA[web-auditing]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3225</guid>
		<description><![CDATA[w3af is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend. The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/w3af/">w3af</a> is a Web Application Attack and Audit Framework. The project&#8217;s goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.</p>
<p>The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for <a href="http://www.darknet.org.uk/tag/sql-injection/">SQL injection</a>, cross site scripting (<a href="http://www.darknet.org.uk/tag/xss/">xss</a>), local and remote file inclusion and much </p>
<p>Finally it&#8217;s out of BETA and RC and there&#8217;s now a stable core for the codebase.</p>
<p><strong>New in v1.1</strong></p>
<ul>
<li>Considerably increased performance by implementing gzip encoding</li>
<li>Enhanced embedded bug report system using Trac&#8217;s XMLRPC</li>
<li>Fixed hundreds of bugs</li>
<li>Fixed critical bug in auto-update feature</li>
<li>Enhanced integration with other tools (bug fixed and addedmore info to the file)</li>
</ul>
<p>You can download w3af v1.1 here:</p>
<p><a href="http://downloads.sourceforge.net/project/w3af/w3af/w3af%201.1/w3af-1.1.tar.bz2?r=http%3A%2F%2Fsourceforge.net%2Fprojects%2Fw3af%2Ffiles%2Fw3af%2Fw3af%25201.1%2F&#038;ts=1321290325&#038;use_mirror=cdnetworks-kr-1">w3af-1.1.tar.bz2</a></p>
<p>Or you can read more <a href="http://www.w3af.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3225+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;t=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/&amp;title=w3af+v1.1+Released+For+Download+%E2%80%93+Web+Application+Attack+%26+Audit+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2Fw3af-v1-1-released-for-download-web-application-attack-audit-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/w3af-v1-1-released-for-download-web-application-attack-audit-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>13 Out Of 15 Popular CAPTCHA Schemes Vulnerable To Automated Attacks</title>
		<link>http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/</link>
		<comments>http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 17:54:10 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[automated captcha cracking]]></category>
		<category><![CDATA[CAPTCHA]]></category>
		<category><![CDATA[captcha cracking]]></category>
		<category><![CDATA[captcha security]]></category>
		<category><![CDATA[cracking recaptcha]]></category>
		<category><![CDATA[decaptcha]]></category>
		<category><![CDATA[google captchac]]></category>
		<category><![CDATA[recaptcha]]></category>
		<category><![CDATA[recaptcha security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3220</guid>
		<description><![CDATA[This is not a real shock to be if I&#8217;m perfectly honestly, I only use reCAPTCHA whenever I need a CAPTCHA implementation for anything. And well even then, it&#8217;s not totally safe as apparently you can farm out your CAPTCHA cracking (those the fail the automated attempts) to India for a few dollars. It does [...]]]></description>
			<content:encoded><![CDATA[<p>This is not a real shock to be if I&#8217;m perfectly honestly, I only use reCAPTCHA whenever I need a CAPTCHA implementation for anything.</p>
<p>And well even then, it&#8217;s not totally safe as apparently you can farm out your CAPTCHA cracking (those the fail the automated attempts) to India for a few dollars. It does help cut down on sign-ups and bot spam &#8211; but it&#8217;s certainly not fool proof.</p>
<p>The report just reinforces my stance proving that 13 out of 15 popular captures could be cracked with automated software.</p>
<blockquote><p>Security researchers have discovered the vast majority of text-based anti-spam tests are easily defeated.</p>
<p>Computer scientists from Stanford University discovered 13 of 15 CAPTCHA schemes from popular websites were vulnerable to automated attacks. The CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) has been used for several years to prevent automated sign-ups to webmail accounts or online forums in order to block spam bots. Surfers are typically asked during a registration process to identify distorted letters as depicted in an image. A variety of other approaches – including pictures of cats, audio clips and calculus puzzles – have been applied to the problem over the years.</p>
<p>Cybercrooks have responded to the challenge posed by CAPTCHAs by devising techniques that typically involve semi-automatically signing up for new accounts, while relying on the human cogs in 21st century sweatshops – typically located in India – to solve the CAPTCHA puzzles themselves.</p>
<p>The Stanford team, by contrast, looked at whether it was possible to fully automate the process of breaking CAPTCHAs. Their techniques including removing deliberately introduced image background noise and breaking text strings into single characters for easier recognition. The team built an automated tool, called Decaptcha, that applied these various tricks. The approach was partially inspired by techniques used to orientate robots in unknown environments.</p></blockquote>
<p>It&#8217;s interesting to see an academic take on this subject though as it&#8217;s usually the realm of blackhats and hobbyists. I&#8217;m sure with a fair bit of science they did an excellent job at removing the &#8216;noise&#8217; that most CAPTCHA systems tend to add to the image to try and foil automatic solving.</p>
<p>I&#8217;m also glad to see reCAPTCHA once again stood up well to automated cracking, you&#8217;d have to rely on the sweatshops to get past that.</p>
<p>The worst seems to be Authorize.net from VISA &#8211; which is surprising and also sad as it&#8217;s dealing with banking.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Decaptcha was turned against the challenge response CAPTCHAs used by 15 high-profile websites, enjoying excellent bowling figures against the majority.</p>
<p>For example, Visa&#8217;s Authorize.net payment gateway CAPTCHA was defeated 66 per cent of the time. eBay&#8217;s CAPTCHA was sidestepped 43 per cent of the time. Lower, but still workable, bypass rates were achieved against Wikipedia, Digg and CNN.</p>
<p>Google and reCAPTCHA were the only two CAPTCHA systems that consistently thwarted Decaptcha during the tests.</p>
<p>Authorize.net and Digg have both switched to reCAPTCHA since these tests were run, Computerworld adds.</p>
<p>In a research paper (PDF), the Stanford team suggest several approaches towards making CAPTCHAs harder to beat, including making the length of a text string changeable and randomising character font and size. Lines in the background of CAPTCHAs might also prove effective. In addition, the Stanford team highlighted features that are ineffective against automated attacks but may counter the activities of humans.</p>
<p>The researchers, Elie Bursztein, Matthieu Martin and John C Mitchel, who previously developed techniques for breaking audio CAPTCHAs, presented their latest research at the recent ACM Conference On Computer and Communication Security in Chicago. </p></blockquote>
<p>Fortunately both Authorize.net and Digg have switched to reCAPTCHA since this report came out making them safer, it&#8217;s probably a case of responsible disclosure by the Stanford scientists.</p>
<p>It&#8217;s definitely worth a read if you have anything to do with CAPTCHA implementation and especially relevant if you are thinking of developing your own rather than just using something like reCAPTCHA.</p>
<p>You can grab the full report here:</p>
<p><a href="http://cdn.ly.tl/publications/text-based-captcha-strengths-and-weaknesses.pdf">text-based-captcha-strengths-and-weaknesses.pdf</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2011/11/02/popular_captchas_easily_defeated/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=13+Out+Of+15+Popular+CAPTCHA+Schemes+Vulnerable+To+Automated+Attacks+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3220+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/&amp;t=13+Out+Of+15+Popular+CAPTCHA+Schemes+Vulnerable+To+Automated+Attacks" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/&amp;title=13+Out+Of+15+Popular+CAPTCHA+Schemes+Vulnerable+To+Automated+Attacks" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/&amp;title=13+Out+Of+15+Popular+CAPTCHA+Schemes+Vulnerable+To+Automated+Attacks" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/&amp;title=13+Out+Of+15+Popular+CAPTCHA+Schemes+Vulnerable+To+Automated+Attacks" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/&amp;title=13+Out+Of+15+Popular+CAPTCHA+Schemes+Vulnerable+To+Automated+Attacks" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F11%2F13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/11/13-out-of-15-popular-captcha-schemes-vulnerable-to-automated-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

