Pipes OutputPipes Output
http://pipes.yahoo.com/pipes/pipe.info?_id=5f1dcd4397142867d586ae88e192f796
Wed, 23 May 2012 10:25:02 +0000http://pipes.yahoo.com/pipes/FULL FEED LOCATED AT feeds.rmccurdy.comFULL FEED LOCATED AT feeds.rmccurdy.com THIS IS ONLY max ~50 yahoo trims the feeds !
http://pipes.yahoo.com/pipes/pipe.info?_id=5f1dcd4397142867d586ae88e192f796
Wed, 23 May 2012 10:25:03 +0000http://pipes.yahoo.com/pipes/CODENAME: Samurai Skills – Real World Penetration Testing Training
http://feedproxy.google.com/~r/darknethackers/~3/whHlgz-flc0/
http://www.darknet.org.uk/?p=3270Mon, 14 May 2012 08:30:25 +0000
Read the full post at darknet.org.uk
]]>t2'12: Call for Papers 2012 (Helsinki / Finland)
http://seclists.org/pen-test/2012/May/4
http://seclists.org/pen-test/2012/May/4Sun, 13 May 2012 00:05:55 +0000A survey on web application attacks
http://seclists.org/pen-test/2012/May/3
http://seclists.org/pen-test/2012/May/3Sat, 12 May 2012 00:34:18 +0000Webcast: Penetration Testing - Not Just For Networks Anymore
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1379
1379@http://www.professionalsecuritytesters.orgFri, 11 May 2012 00:08:42 +0000TA12-129A: Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA12-129A.html
http://www.us-cert.gov/cas/techalerts/TA12-129A.htmlTue, 08 May 2012 21:01:03 +0000Basic Fuzzing Framework (BFF) From CERT – Linux & Mac OSX Fuzzer Tool
http://feedproxy.google.com/~r/darknethackers/~3/GDBZuVhVWIo/
http://www.darknet.org.uk/?p=3313Tue, 08 May 2012 10:36:23 +0000
Read the full post at darknet.org.uk
]]>Announce: Italian Hacker Game Cracca al Tesoro - Crack A Treasure
http://seclists.org/pen-test/2012/May/2
http://seclists.org/pen-test/2012/May/2Fri, 04 May 2012 17:01:15 +0000VU#520827: PHP-CGI query string parameter vulnerability
http://www.kb.cert.org/vuls/id/520827
US-CERThttp://www.kb.cert.org/vuls/id/520827Thu, 03 May 2012 18:18:40 +0000nullcon Delhi 2012 Call for Paper/Call for Event
http://seclists.org/pen-test/2012/May/1
http://seclists.org/pen-test/2012/May/1Wed, 02 May 2012 04:22:39 +0000VU#359816: Oracle database TNS listener vulnerability
http://www.kb.cert.org/vuls/id/359816
US-CERThttp://www.kb.cert.org/vuls/id/359816Tue, 01 May 2012 18:43:31 +0000xSQL Scanner 1.6 - Released
http://seclists.org/pen-test/2012/May/0
http://seclists.org/pen-test/2012/May/0Tue, 01 May 2012 16:48:52 +0000With a real team, it's not about the numbers
http://seclists.org/dailydave/2012/q2/41
http://seclists.org/dailydave/2012/q2/41Tue, 01 May 2012 14:15:35 +0000Russian Cyber-Crime Market Doubled In 2011
http://feedproxy.google.com/~r/darknethackers/~3/3-oIv8M-UcA/
http://www.darknet.org.uk/?p=3317Mon, 30 Apr 2012 12:18:24 +0000
Read the full post at darknet.org.uk
]]>[Tool update] VoIP Hopper 2.04 released
http://seclists.org/pen-test/2012/Apr/15
http://seclists.org/pen-test/2012/Apr/15Sun, 29 Apr 2012 17:40:21 +0000ERPScan has released ERPScan Security Scanner for Sap 2.0
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1378
1378@http://www.professionalsecuritytesters.orgSat, 28 Apr 2012 07:10:22 +000072 hours
http://seclists.org/dailydave/2012/q2/40
http://seclists.org/dailydave/2012/q2/40Thu, 26 Apr 2012 21:24:46 +0000Spooked at RSA 2012
http://seclists.org/dailydave/2012/q2/39
http://seclists.org/dailydave/2012/q2/39Thu, 26 Apr 2012 14:22:23 +0000Abusing Password Managers with XSS
http://seclists.org/webappsec/2012/q2/6
http://seclists.org/webappsec/2012/q2/6Thu, 26 Apr 2012 01:51:05 +0000What's happening at SyScan'12 Singapore
http://seclists.org/dailydave/2012/q2/38
http://seclists.org/dailydave/2012/q2/38Wed, 25 Apr 2012 14:46:39 +0000Anti-fingerprinting techniques
http://seclists.org/pen-test/2012/Apr/14
http://seclists.org/pen-test/2012/Apr/14Wed, 25 Apr 2012 14:34:55 +0000creepy – A Geolocation Information Aggregator AKA OSINT Tool
http://feedproxy.google.com/~r/darknethackers/~3/rNb4CLC6NAM/
http://www.darknet.org.uk/?p=3291Wed, 25 Apr 2012 08:14:23 +0000
Read the full post at darknet.org.uk
]]>[HITB-Announce] HITB Magazine Issue 008 (now with print edition!)
http://seclists.org/pen-test/2012/Apr/13
http://seclists.org/pen-test/2012/Apr/13Tue, 24 Apr 2012 02:40:07 +0000[New tool] - Exploit Pack - Web Security
http://seclists.org/pen-test/2012/Apr/12
http://seclists.org/pen-test/2012/Apr/12Mon, 23 Apr 2012 22:17:21 +0000Save yourself 20% by tweeting
http://seclists.org/dailydave/2012/q2/37
http://seclists.org/dailydave/2012/q2/37Mon, 23 Apr 2012 19:48:25 +0000Anonymous Take Down Official F1 Site As Bahrain Protest
http://feedproxy.google.com/~r/darknethackers/~3/6hbw9vVCvXM/
http://www.darknet.org.uk/?p=3290Mon, 23 Apr 2012 11:34:10 +0000
Read the full post at darknet.org.uk
]]>Clowns Base Key Financial Rate on Feelings, Not Data
http://taosecurity.blogspot.com/2012/04/clowns-base-key-financial-rate-on.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-5301280322248621142Sat, 21 Apr 2012 14:44:00 +0000TIME IS RUNNING OUT
http://seclists.org/dailydave/2012/q2/36
http://seclists.org/dailydave/2012/q2/36Fri, 20 Apr 2012 14:29:42 +0000Ruxcon 2012 Call For Papers
http://seclists.org/pen-test/2012/Apr/11
http://seclists.org/pen-test/2012/Apr/11Thu, 19 Apr 2012 10:50:52 +0000RIT!
http://seclists.org/dailydave/2012/q2/35
http://seclists.org/dailydave/2012/q2/35Wed, 18 Apr 2012 16:34:49 +0000CISPA == MAPP
http://seclists.org/dailydave/2012/q2/34
http://seclists.org/dailydave/2012/q2/34Wed, 18 Apr 2012 16:28:57 +0000Passwords^12 : Call for Presentations
http://seclists.org/webappsec/2012/q2/3
http://seclists.org/webappsec/2012/q2/3Wed, 18 Apr 2012 11:10:02 +0000winAUTOPWN v3.0 Released
http://seclists.org/webappsec/2012/q2/2
http://seclists.org/webappsec/2012/q2/2Wed, 18 Apr 2012 11:07:24 +0000SEC Consult whitepaper :: The Source Is A Lie
http://seclists.org/webappsec/2012/q2/1
http://seclists.org/webappsec/2012/q2/1Wed, 18 Apr 2012 11:03:32 +0000NfSpy – ID-spoofing NFS Client Tool – Mount NFS Shares Without Account
http://feedproxy.google.com/~r/darknethackers/~3/zMuQwjwUjZI/
http://www.darknet.org.uk/?p=3286Wed, 18 Apr 2012 10:44:38 +0000
Read the full post at darknet.org.uk
]]>Android Trojan Targets Japanese Market – Steals Personal Data
http://feedproxy.google.com/~r/darknethackers/~3/eGSIYlAU7bM/
http://www.darknet.org.uk/?p=3285Mon, 16 Apr 2012 10:38:22 +0000
Read the full post at darknet.org.uk
]]>web-sorrow – Remote Web Security Scanner (Enumeration/Version Detection etc)
http://feedproxy.google.com/~r/darknethackers/~3/h17CDz9k4T4/
http://www.darknet.org.uk/?p=3284Thu, 12 Apr 2012 18:32:58 +0000
Read the full post at darknet.org.uk
]]>TA12-101B: Adobe Reader and Acrobat Security Updates and Architectural Improvements
http://www.us-cert.gov/cas/techalerts/TA12-101B.html
http://www.us-cert.gov/cas/techalerts/TA12-101B.htmlTue, 10 Apr 2012 22:02:05 +0000TA12-101A: Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA12-101A.html
http://www.us-cert.gov/cas/techalerts/TA12-101A.htmlTue, 10 Apr 2012 18:37:12 +0000VU#400619: Pluck SiteLife software multiple XSS vulnerabilities
http://www.kb.cert.org/vuls/id/400619
US-CERThttp://www.kb.cert.org/vuls/id/400619Tue, 10 Apr 2012 15:21:12 +0000OWASP ZAP 1.4.0 released
http://seclists.org/webappsec/2012/q2/0
http://seclists.org/webappsec/2012/q2/0Mon, 09 Apr 2012 01:25:37 +0000Salvaging Poorly Worded Statistics
http://taosecurity.blogspot.com/2012/04/salvaging-poorly-worded-statistics.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-5162147431216105139Wed, 04 Apr 2012 20:43:00 +0000VU#232979: Multiple vulnerabilities in Intuit QuickBooks
http://www.kb.cert.org/vuls/id/232979
US-CERThttp://www.kb.cert.org/vuls/id/232979Mon, 02 Apr 2012 18:26:39 +0000VU#928795: Netgear FVS318N router default remote management vulnerability
http://www.kb.cert.org/vuls/id/928795
US-CERThttp://www.kb.cert.org/vuls/id/928795Mon, 02 Apr 2012 15:42:13 +0000VU#834723: TP-Link 8840T DSL router default remote management vulnerability
http://www.kb.cert.org/vuls/id/834723
US-CERThttp://www.kb.cert.org/vuls/id/834723Mon, 02 Apr 2012 14:12:13 +0000Rootcon Blog: Introducing 35 Pentesting Tools Used for Web Sec Assessments
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1376
<p>Original post at:<br /><a rel="nofollow" target="_blank" href="http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1">http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1</a>  </p>
<p><strong>1. w3af</strong></p>
<div class="separator"><a rel="nofollow" target="_blank" href="http://2.bp.blogspot.com/-DX7otj2qBdY/T1Ssp_poKhI/AAAAAAAAAWU/fiHjjX3Cyu8/s1600/w3af.png"><img src="http://2.bp.blogspot.com/-DX7otj2qBdY/T1Ssp_poKhI/AAAAAAAAAWU/fiHjjX3Cyu8/s280/w3af.png" border="0" alt="w3af" width="280" height="214"/></a></div>
<p> </p>
<div>w3af or Web Application Attack and Audit Framework is an open source penetration testing tool for finding web vulnerabilities and an exploit tool that comes with cool plugins like sqlmap, xssBeef, and davShell. w3af automatically updates itself every time you launch the tool making it a very reliable tool for website hacking.  For more information just check out their website hosted at <a rel="nofollow" target="_blank" href="http://w3af.sourceforge.net/">SourceForge</a>.</div>
<div></div>
<div><strong>2. Acunetix Web Vulnerability Scanner</strong></div>
<div></div>
<div class="separator"><a rel="nofollow" target="_blank" href="http://1.bp.blogspot.com/-TXYrp6uX3i4/T1SyHNSv_2I/AAAAAAAAAWc/ELNI_8YXnKQ/s1600/wvs-SQL_Injection.gif"><img src="http://1.bp.blogspot.com/-TXYrp6uX3i4/T1SyHNSv_2I/AAAAAAAAAWc/ELNI_8YXnKQ/s280/wvs-SQL_Injection.gif" border="0" alt="Acunetix WVS" width="280" height="208"/></a></div>
<div><br />Acunetix WVS or Web Vulnerability Scanner is a pentesting tool for Windows users so that they may be able to check for SQL Injection, Cross Site Scripting (XSS), CRLF injection, Code execution, Directory Traversal, File inclusion, checks for vulnerabilities in File Upload forms and other serious web vulnerabilities. You can download this tool <a rel="nofollow" target="_blank" href="http://www.acunetix.com/vulnerability-scanner/download.htm">here</a>.<br /><br /><strong>3. SQLninja</strong><br /><br />SQLninja is a an sql injection tool for web applications that use Microsoft SQL Server as its back-end though it runs only in Linux, Mac and BSD. It requires perl modules; NetPacket, Net-Pcap, Net-DNS, Net-RawIP, and IO-Socket-SSL. You can download this tool <a rel="nofollow" target="_blank" href="http://sqlninja.sourceforge.net/download.html">here</a>.<br /><br /><strong>4. Nikto</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://1.bp.blogspot.com/-gq7uNhlYDYM/T1S17kzBSFI/AAAAAAAAAWk/XPYsACRIRr4/s1600/nikto.png"><img src="http://1.bp.blogspot.com/-gq7uNhlYDYM/T1S17kzBSFI/AAAAAAAAAWk/XPYsACRIRr4/s280/nikto.png" border="0" alt="nikto" width="280" height="192"/></a></div>
<br />Nikto is an open source web server scanner “<em>which performs comprehensive tests against web servers for multiple items, including over 6400 potentially dangerous files or CGIs, checks for outdated versions of over 1200 servers, and version specific problems on over 270 servers.</em>" The good thing about Nikto is that it easy to use and and performs scanning faster. Nikto is coded in Perl and written by Chris Sullo and David Lodge. Although not all checks are really a big security problem but most are like XSS (Cross Site Scripting) Vulnerabilities, phpmyadmin logins, etc. Nikto alerts and gives you security tips in order to prevent your website from various attacks.<br /><br /><strong>5. SQLmap</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://3.bp.blogspot.com/-Bn9u4yEfJ9Q/T1S4CHz_VyI/AAAAAAAAAW0/swC9JH8jfwU/s1600/sqlmap.jpeg"><img src="http://3.bp.blogspot.com/-Bn9u4yEfJ9Q/T1S4CHz_VyI/AAAAAAAAAW0/swC9JH8jfwU/s280/sqlmap.jpeg" border="0" alt="" width="280" height="163"/></a></div>
<br />SQLmap is an open source automatic SQL injection and database takeover tool that fully supports MySQL, Oracle, PostgreSQL and Microsoft SQL Server. It partially supports Microsoft Access, DB2, Informix, Sybase and Interbase. Download sqlmap <a rel="nofollow" target="_blank" href="http://sqlmap.sourceforge.net/">here</a>.<br /><strong><br /></strong><br /><strong>6. Pangolin 3.2.3</strong><br /><br />Pangolin is another sql injection scanner for web applications using Access,DB2,Informix,Microsoft SQL Server 2000,Microsoft SQL Server 2005,Microsoft SQL Server 2008, MySQL, Oracle, PostgreSQL, Sqlite3, and Sybase. Its features include keyword auto analysis, supports HTTPS, has bypass firewall setting, injection digger, data dumper, etc. You can download its zip file <a rel="nofollow" target="_blank" href="http://down3.nosec.org/pangolin_free_edition_3.2.3.1105.zip">here</a>. <br /><br /><strong>7. Havij v1.15 Advanced SQL Injection</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://3.bp.blogspot.com/-kRGeeFd6tRU/T1S8RTNcUDI/AAAAAAAAAXE/McZcMHRlasw/s1600/md5_cracker.png"><img src="http://3.bp.blogspot.com/-kRGeeFd6tRU/T1S8RTNcUDI/AAAAAAAAAXE/McZcMHRlasw/s280/md5_cracker.png" border="0" alt="" width="280" height="308"/></a></div>
<br />Havij is another famous automatic sql injection tool that has a <a rel="nofollow" target="_blank" href="http://www.itsecteam.com/files/havij/Havij1.15Free.rar">free</a> and premium version. The free version only supports a few injection methods like MsSQL 2000/2005 with error, MsSQL 2000/2005 no error union based, MySQL union based, MySQL Blind, MySQL error based, MySQL time based, Oracle union based, MsAccess union based, and Sybase (ASE). It also includes an admin finder and an md5 cracker. <br /><strong><br /></strong><br /><strong>8. SQL Power Injector </strong><br /><br />SQL Power Injector is a web pentesting application created in .Net 1.1 that helps the penetration tester and hackers find and exploit SQL injections on a web application that uses SQL Server, Oracle, MySQL, Sybase/Adaptive Server and DB2 compliant, but it is possible to use it with any existing Database Management System when using the inline injection or normal mode. You can download the latest version of this tool which includes a Firefox plugin <a rel="nofollow" target="_blank" href="http://www.sqlpowerinjector.com/download.htm">here</a>.<br /><br /><strong>9. VulnDetector</strong><br /><br />VulnDetector is a project coded in python which scans a website and detects various web based security vulnerabilities in the website. It was developed by Brad Cable who is into coding open source tools. You can download the script <a rel="nofollow" target="_blank" href="http://bcable.net/archive.php?vulndetector-0.0.2pa.py">here</a>.<br /><br /><strong>10. SQLIer 0.8.2b</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-H0ixnzHlTq4/T1S_sz2rSkI/AAAAAAAAAXM/BBNNMFTEoYo/s1600/screenshot01.jpg"><img src="http://4.bp.blogspot.com/-H0ixnzHlTq4/T1S_sz2rSkI/AAAAAAAAAXM/BBNNMFTEoYo/s280/screenshot01.jpg" border="0" alt="" width="280" height="238"/></a></div>
SQLIer is another project of Brad Cable and is a shell script that determines all the necessary information to build and exploit an SQL Injection vulnerability to a URL by itself without user interaction unless it can't guess the table or field names for the database correctly. SQLIer can build a UNION SELECT query designed to brute force passwords out of the database. This script also does not use quotes in the exploit to operate, meaning it will work for a wider range of sites. Download the shell script <a rel="nofollow" target="_blank" href="http://bcable.net/archive.php?sqlier-0.8b.sh">here</a>.<br /><br /><strong>11. bsqlbf-v2</strong><br /><br />bsqlbf-v2 or Blind Sql Injection Brute Forcer version 2 is a perl script that allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections. It supports MySQL, Oracle, PostgreSQL and Microsoft SQL Server databases. You can download the perl <a rel="nofollow" target="_blank" href="http://code.google.com/p/bsqlbf-v2/downloads/list">script</a> on a Google hosted project.<br /><br /><strong>12. Marathon Tool </strong><br /><br />Marathon Tool is an alpha release SQL Injection tool or project that extracts information from web applications using Microsoft SQL Server, Microsoft Access, MySQL or Oracle Databases by using Time-Based Blind SQL Injection attack. The alpa release can be found <a rel="nofollow" target="_blank" href="http://marathontool.codeplex.com/">here</a>.<br /><br /><strong>13. XSSer </strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-NK1m0qxTfpg/T1TFJDDH_lI/AAAAAAAAAX0/fR3Ezvfy0DY/s1600/xsser.png"><img src="http://4.bp.blogspot.com/-NK1m0qxTfpg/T1TFJDDH_lI/AAAAAAAAAX0/fR3Ezvfy0DY/s280/xsser.png" border="0" alt="" width="280" height="192"/></a></div>
<br />XSSer or Cross Site "Scripter" is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. It also includes a GUI interface by using the command : ./xxser --gtk. You can download xxser's beta version <a rel="nofollow" target="_blank" href="http://xsser.sourceforge.net/">here</a>.<br /><br /><strong>14. ASP Auditor v2.2</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://2.bp.blogspot.com/-v_LxfSVLR84/T1TIPYh_l6I/AAAAAAAAAX8/h1jjbQEh5Ew/s1600/aspaudit.png"><img src="http://2.bp.blogspot.com/-v_LxfSVLR84/T1TIPYh_l6I/AAAAAAAAAX8/h1jjbQEh5Ew/s280/aspaudit.png" border="0" alt="" width="280" height="171"/></a></div>
<br />ASP Auditor v2.2<strong> </strong>is a an auditing tool for ASP that sends initial probe request, path discovery request, ASP.NET validate discovery request, ASP.NET Apr/07 XSS Check, application trace request, and null remoter service request. By using the opt command -bf, it allows you to brute force ASP.NET version using JS Validate directories.<br /><br /><strong>15.Absinthe</strong><br /><br /><em>"Absinthe is a GUI-based tool that automates the process of downloading the schema and contents of a database that is vulnerable to Blind SQL Injection.    This tool does not aid in the discovery of SQL Injection holes but speeds up the process of data recovery.</em>" It supports Microsoft SQL Server, MSDE, Oracle, and Postgres and the tool runs on Linux, Windows and Mac OSX. Download <a rel="nofollow" target="_blank" href="http://www.0x90.org/releases/absinthe/download.php">here</a>.<br /><br /><strong>16. SQID</strong><br /><br />SQID or SQL injection digger is a command line tool written in ruby by Metaeye Security Group that looks for SQL injections and common errors in web sites. It performs a Google search when finding for SQL injections and common errors in web site URLs and crawls a webpage. You can download this tool by checking out its project SVN:<br /><br /><em>svn checkout svn://rubyforge.org/var/svn/sqid </em><br /><br /><strong>17.DarkMySQLi</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://3.bp.blogspot.com/-llVUlhQ280w/T1TPaxv8H9I/AAAAAAAAAYE/X4IZrxaChW4/s1600/darkmysqli.png"><img src="http://3.bp.blogspot.com/-llVUlhQ280w/T1TPaxv8H9I/AAAAAAAAAYE/X4IZrxaChW4/s280/darkmysqli.png" border="0" alt="" width="280" height="105"/></a></div>
<br />DarkMySQLi is a multi purpose MySQL Injection tool coded in python which is also available for BackTrack 5 as one of its packed tools.<br /><br /><strong>18. fimap </strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-7SqQuM4sLXI/T1TSEnlmClI/AAAAAAAAAYM/d_1SvcS6PuQ/s1600/fimap.png"><img src="http://4.bp.blogspot.com/-7SqQuM4sLXI/T1TSEnlmClI/AAAAAAAAAYM/d_1SvcS6PuQ/s280/fimap.png" border="0" alt="" width="280" height="192"/></a></div>
<br />fimap is an automatic LFI/RFI scanner and exploiter coded in python by Iman Karim. It allows a pentester to scan a single URL for File inclusion errors, scan a list of URLS for File Inclusion errors, scan Google search results for FiIe inclusion errors, and harvest all links of a webpage with recurse level of 3 and write the URLs to a file directory.<br /><br /><strong>19.Script Hex Dump – Forensic Tool</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://1.bp.blogspot.com/-TP6AIMUdDIU/T1TXU0VvrSI/AAAAAAAAAYc/jRQ2QxWNuvs/s1600/scripthex.jpg"><img src="http://1.bp.blogspot.com/-TP6AIMUdDIU/T1TXU0VvrSI/AAAAAAAAAYc/jRQ2QxWNuvs/s280/scripthex.jpg" border="0" alt="forensic tool" width="280" height="149"/></a></div>
<br />Script Hex Dump - Forensic Tool is a java application that helps you in parsing your scripts like PHP and automatically converts it as a hex value, some penetration testers use this to test for possible sql injection vulnerability in a website. SQL Injection attack has been a chronic threat especially for those websites running PHP and MySQL as the backend of their database server, one of its capability if the server is not properly configure is the command for writing arbitrary files. You can download this tool <a rel="nofollow" target="_blank" href="http://www.theprojectxblog.net/script-hex-dump/">here</a>.<br /><br /><strong>20. PHP Vulnerability Hunter</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://2.bp.blogspot.com/-gUM16ftIh8M/T1TYSK-ZjhI/AAAAAAAAAYk/8wGFJOuPTUs/s1600/phpscanner1.png"><img src="http://2.bp.blogspot.com/-gUM16ftIh8M/T1TYSK-ZjhI/AAAAAAAAAYk/8wGFJOuPTUs/s280/phpscanner1.png" border="0" alt="php fuzzer" width="280" height="377"/></a></div>
<br />PHP Vulnerability Hunter is a PHP web application fuzzer that scans for common vulnerabilities like local file inclusion, SQL Injection, full path disclosure, arbitrary command execution and many more. A good tool for analyzing your own web server. You can grab the new version of this tool<a rel="nofollow" target="_blank" href="http://code.google.com/p/php-vulnerability-hunter/downloads/list">here</a> which is 1.1.4.6.<br /><br /><strong>21. WSTOOL : Web vulnerable scan tool</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-WCNKtQbiXDs/T1TbZ7RYzUI/AAAAAAAAAYs/DFSpbJHJxzc/s1600/wstool.png"><img src="http://4.bp.blogspot.com/-WCNKtQbiXDs/T1TbZ7RYzUI/AAAAAAAAAYs/DFSpbJHJxzc/s280/wstool.png" border="0" alt="wstool" width="280" height="172"/></a></div>
<br />WATOOL is a server error and SQL Injection, XSS or Cross Site Scripting scanner which uses PHP Check up collate with HTML FORM and LINK. You can download this tool <a rel="nofollow" target="_blank" href="http://sourceforge.net/projects/wstool/">here</a>.<br /><br /><strong>22. ProjectX WHMCS Pentesting Tool v.1</strong><br /><strong><br /></strong><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://3.bp.blogspot.com/-GsS9fkxOBHQ/T1Typ9432SI/AAAAAAAAAY0/S3mNHqNfUQY/s1600/whmcs.png"><img src="http://3.bp.blogspot.com/-GsS9fkxOBHQ/T1Typ9432SI/AAAAAAAAAY0/S3mNHqNfUQY/s280/whmcs.png" border="0" alt="" width="280" height="214"/></a></div>
<strong><br /></strong><br />Projectx WHMCS Pentesting Tool v.1 is a vulnerability scanner coded in VB.NET that uses a black box approach. It echos the db_username and the db_password of a website that is vulnerable to WHMCS Local File Disclosure. This kind of vulnerability is only applicable to versions 3.x.x and some 4.x.x which was a viral exploit last year that some website administrators took for granted. You can download the tool <a rel="nofollow" target="_blank" href="http://www.theprojectxblog.net/projectx-whmcs-pentesting-tool-v-1/">here</a>.<br /><br /><strong>23. Wpscan </strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://3.bp.blogspot.com/-vGEwwWY0yKU/T1YLYpBkZDI/AAAAAAAAAY8/aKJAvITV2kc/s1600/wpscan.png"><img src="http://3.bp.blogspot.com/-vGEwwWY0yKU/T1YLYpBkZDI/AAAAAAAAAY8/aKJAvITV2kc/s280/wpscan.png" border="0" alt="" width="280" height="186"/></a></div>
<br />WPscan or Wordpress Security Scanner is a pentesting tool written in ruby for Wordpress installations. The tools is coed by Ryan Dewhurst which uses a black box approach in finding security holes for Wordpress like timthumb, easy to guess passwords, plugin holes, etc. You can download wpscan <a rel="nofollow" target="_blank" href="http://code.google.com/p/wpscan/">here</a>.<br /><br /><strong>24. Skipfish</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-xMqOkiAz2Xo/T1YQDuMt2eI/AAAAAAAAAZM/bFibZbFNcJM/s1600/skipfish.png"><img src="http://4.bp.blogspot.com/-xMqOkiAz2Xo/T1YQDuMt2eI/AAAAAAAAAZM/bFibZbFNcJM/s280/skipfish.png" border="0" alt="" width="280" height="193"/></a></div>
Skipfish is an active web application security reconnaissance tool written by Michal Zalewski. Skipfish spiders a URL using the wordlists, a very powerful web scanning tool with a simple implementation. It also scans for vulnerabilities like php injection, XSS, format string vulnerabilities, overflow vulnerabilities, file inclusions , etc. You can download this tool <a rel="nofollow" target="_blank" href="http://code.google.com/p/skipfish/downloads/list">here</a>.<br /><strong><br /></strong><br /><strong>25. WhatWeb</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-oNozabsvZ-Q/T1YWALoao-I/AAAAAAAAAZU/TPSQGiZDsXM/s1600/whatweb.png"><img src="http://4.bp.blogspot.com/-oNozabsvZ-Q/T1YWALoao-I/AAAAAAAAAZU/TPSQGiZDsXM/s280/whatweb.png" border="0" alt="" width="280" height="192"/></a></div>
<br />WhatWeb is a web scanner coded by Andrew Horton aka urbanadventurer from Security-Assessment.com. It is used for information gathering because it identifies content management systems (CMS), blogging platforms, stats/analytics packages, javascript libraries, servers, etc. You can download this tool <a rel="nofollow" target="_blank" href="http://www.morningstarsecurity.com/downloads/whatweb-0.4.3.tar.gz">here</a>.<br /><br /><strong>26. OWASP ZAP </strong><br /><br />Zed Attack Proxy (ZAP) is a project of OWASP which is a GUI penetration testing tool for finding website vulnerabilities and flaws. This open source tool includes features like  intercepting proxy, active scanner, passive scanner, brute force scanner, spider, fuzzer, port scanner,  dynamic SSL certificates, API, and Beanshell integration. For more information about this tool, check out their <a rel="nofollow" target="_blank" href="https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project">website</a>.<br /><br /><strong>27.  Webshag</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://1.bp.blogspot.com/-lCoITXQ_8Ys/T1YhDS27GLI/AAAAAAAAAZk/2KjuNxyFbvs/s1600/webshag1.10.png"><img src="http://1.bp.blogspot.com/-lCoITXQ_8Ys/T1YhDS27GLI/AAAAAAAAAZk/2KjuNxyFbvs/s280/webshag1.10.png" border="0" alt="" width="280" height="162"/></a></div>
<br />Webshag is a multi-threaded, multi-platform web server auditing tool coded in python. It is used for crawling a URL, port scanning, file fuzzing and audits your website. You can download this security auditing tool <a rel="nofollow" target="_blank" href="http://www.scrt.ch/outils/webshag/ws100_linux.tar.gz">here</a>.<br /><br /><strong>28. OWASP DirBuster</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-KHo2_xTxVR8/T1YkCtrH-0I/AAAAAAAAAZs/EB9fZN_i6ek/s1600/WebApplicationBrute+Forcing.png"><img src="http://4.bp.blogspot.com/-KHo2_xTxVR8/T1YkCtrH-0I/AAAAAAAAAZs/EB9fZN_i6ek/s280/WebApplicationBrute+Forcing.png" border="0" alt="" width="280" height="198"/></a></div>
<br />DirBuster is another project of OWASP that a multi threaded java application designed to brute force directories and files names on web/application servers that uses a black box approach for application testing by trying to find hidden content. You can download this tool <a rel="nofollow" target="_blank" href="http://sourceforge.net/projects/dirbuster/files/DirBuster%20%28jar%20%2B%20lists%29/1.0-RC1/">here</a>.<br /><br /><strong>29. Grendel-Scan</strong><br /><br />Grendel-Scan is free and open source web application pentesting tool that has an automatic scanning feature which detects common web application vulnerabilities, and features geared at aiding manual penetration tests. Get this tool <a rel="nofollow" target="_blank" href="http://grendel-scan.com/download.htm">now</a>.<br /><br /><strong>30. Mopest</strong><br /><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://3.bp.blogspot.com/-fMeV8zXVS0c/T1YoTVLQvTI/AAAAAAAAAZ0/w3z3ZhOuLAY/s1600/mopest.png"><img src="http://3.bp.blogspot.com/-fMeV8zXVS0c/T1YoTVLQvTI/AAAAAAAAAZ0/w3z3ZhOuLAY/s280/mopest.png" border="0" alt="" width="280" height="147"/></a></div>
<br />Mopest is a PERL Local PHP Vulnerability Scanner for exploits PhpBB 2.0.20 Disable Administrator, PhpBB 2.0.19 Denial of Service - Infinitely topic, phpBB 2.0.15 Database Authentication Details, Invision Power Board 2.0.2 Multipl Users DoS, Invision Power Board 2.1.5 Code Execution, MyBB 1.0 RC4 Sql injection, MyBB 1.1.3 Create An Admin, MyBB Sql Injection, and WordPress 1.5.11 Sql Injection. It also has tools like Fake Mailer, Email Bomber, and MD5 Cracker.  You can check out this project <a rel="nofollow" target="_blank" href="http://code.google.com/p/mopest/downloads/list">here</a>.<br /><br /><strong>31. SecuBat</strong><br /><br />SecuBat is another web vulnerability scanner which automatically analyzes web sites with the aim of finding exploitable SQL injection and XSS vulnerabilities. You can check this tool <a rel="nofollow" target="_blank" href="http://secubat.codeplex.com/">here</a>.<br /><br /><strong>32. Arachni</strong><br /><strong><br /></strong><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://2.bp.blogspot.com/-3PrKD8fBARw/T1ogkwECsMI/AAAAAAAAAZ8/QHnKUPPR4qA/s1600/log.png"><img src="http://2.bp.blogspot.com/-3PrKD8fBARw/T1ogkwECsMI/AAAAAAAAAZ8/QHnKUPPR4qA/s280/log.png" border="0" alt="" width="280" height="166"/></a></div>
<strong><br /></strong><br />Arachni is an open source web application security scanner framework coded in ruby that helps website administrators and penetration testers evaluate the security of a web application. Arachni asks you for the URL of the target and it automatically performs a simple scan and presents you with its findings which could be a very risky flaw or loophole. You can download this tool <a rel="nofollow" target="_blank" href="http://arachni-scanner.com/">here</a>.<br /><br /><strong>33. WebSlayer</strong><br /><strong><br /></strong><br />WebSlayer is another OWASP project that slays your web application by brute forcing the GET and POST parameters, checking the directories, brute forcing the login forms, fuzzing, brute forcing sessions, Ntml brute forcing, and many more. For more information of this project just check this <a rel="nofollow" target="_blank" href="https://www.owasp.org/index.php/Category:OWASP_Webslayer_Project">site</a>.<br /><br /><strong>34. Burp Suite</strong><br /><strong><br /></strong><br />
<div class="separator"><a rel="nofollow" target="_blank" href="http://4.bp.blogspot.com/-ODa4YprJuGM/T1olZJvXItI/AAAAAAAAAaE/TJO-CWOhzLM/s1600/intruder_3.png"><img src="http://4.bp.blogspot.com/-ODa4YprJuGM/T1olZJvXItI/AAAAAAAAAaE/TJO-CWOhzLM/s280/intruder_3.png" border="0" alt="" width="280" height="210"/></a></div>
<strong><br /></strong><br />Burp Suite is penetration testing tool and integrated platform for website security. Burp Suite has cool features like an intercepting proxy, application spider for crawling, detects numerous web application vulnerabilities, repeater tool, allows you to write your own plugins, and many more. The free edition is available for download <a rel="nofollow" target="_blank" href="http://portswigger.net/burp/download.html">here</a>.<br /><br /><strong>35. ProxMon</strong><br /><strong><br /></strong><br />ProxMon is not a Digimon but a Python based open source framework that automates web application tests. Its key features include:<br /><br />- automatic value tracing of set cookies, sent cookies, query strings and post parameters across sites,<br />- proxy agnostic<br />- included library of vulnerability checks<br />- active testing mode<br />- cross platform<br />- easy to program extensible python framework<br /><br />You can download this tool <a rel="nofollow" target="_blank" href="http://www.isecpartners.com/application-security-tools/proxmon.html">here</a>.</div>
<p> </p>
<p>Original post at:<br /><a rel="nofollow" target="_blank" href="http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1">http://blog.rootcon.org/2012/03/introducing-35-pentesting-tools-used.html?m=1</a>  </p>1376@http://www.professionalsecuritytesters.orgMon, 02 Apr 2012 12:53:12 +0000Time based Blind SQL injection
http://seclists.org/webappsec/2012/q1/37
http://seclists.org/webappsec/2012/q1/37Fri, 30 Mar 2012 22:29:05 +0000Inside a Commission Hearing on the Chinese Threat
http://taosecurity.blogspot.com/2012/03/inside-commission-hearing-on-chinese.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-3468684415706257064Mon, 26 Mar 2012 20:09:00 +0000Job opportunities in Kuwait and Dubai
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1375
1375@http://www.professionalsecuritytesters.orgSun, 25 Mar 2012 01:37:08 +0000VU#551715: Quagga contains multiple vulnerabilities
http://www.kb.cert.org/vuls/id/551715
US-CERThttp://www.kb.cert.org/vuls/id/551715Fri, 23 Mar 2012 12:10:13 +0000Zend Server Multiple HTML Injection Vulnerabilities
http://www.net-security.org/vuln.php?id=16279
Fri, 23 Mar 2012 07:08:47 +0000EJBCA "issuer" Parameter Cross-Site Scripting
http://www.net-security.org/vuln.php?id=16278
Fri, 23 Mar 2012 07:08:32 +0000Vegas Movie Studio HD "CFHDDecoder.dll" DLL Loading Arbitrary Code Execution
http://www.net-security.org/vuln.php?id=16276
Fri, 23 Mar 2012 07:08:00 +0000Microsoft Expression "wintab32.dll" DLL Loading Arbitrary Code Execution
http://www.net-security.org/vuln.php?id=16275
Fri, 23 Mar 2012 07:07:38 +0000Jenkins Multiple Cross-Site Scripting and Directory Traversal Vulnerabilities
http://www.net-security.org/vuln.php?id=16274
Thu, 22 Mar 2012 13:19:48 +0000SquirrelMail Autocomplete Plugin Email Addresses Cross-Site Scripting
http://www.net-security.org/vuln.php?id=16273
Thu, 22 Mar 2012 13:19:35 +0000Google Chrome Remote Code Execution
http://www.net-security.org/vuln.php?id=16272
Thu, 22 Mar 2012 13:19:23 +0000XnView Multiple Buffer Overflow Vulnerabilities
http://www.net-security.org/vuln.php?id=16271
Thu, 22 Mar 2012 13:19:10 +0000VU#743555: @Mail Open webmail client contains multiple vulnerabilities
http://www.kb.cert.org/vuls/id/743555
US-CERThttp://www.kb.cert.org/vuls/id/743555Thu, 22 Mar 2012 12:40:14 +0000VU#523027: LG-Nortel ELO GS24M Switch contains multiple vulnerabilities
http://www.kb.cert.org/vuls/id/523027
US-CERThttp://www.kb.cert.org/vuls/id/523027Wed, 21 Mar 2012 12:40:14 +0000winAUTOPWN v2.9 - As [ C4 - WAST ]
http://seclists.org/webappsec/2012/q1/34
http://seclists.org/webappsec/2012/q1/34Wed, 21 Mar 2012 11:16:36 +0000VU#364363: WebGlimpse command injection vulnerability
http://www.kb.cert.org/vuls/id/364363
US-CERThttp://www.kb.cert.org/vuls/id/364363Tue, 20 Mar 2012 20:35:13 +0000VU#212651: InspIRCd heap corruption vulnerability
http://www.kb.cert.org/vuls/id/212651
US-CERThttp://www.kb.cert.org/vuls/id/212651Mon, 19 Mar 2012 20:33:49 +0000VU#913483: Quantum Scalar i500, Dell ML6000 and IBM TS3310 tape libraries web interface and preconfigured password vulnerabilities
http://www.kb.cert.org/vuls/id/913483
US-CERThttp://www.kb.cert.org/vuls/id/913483Mon, 19 Mar 2012 19:00:12 +0000FBController - (Facebook Control Utility) version 4.0 { With 0-DAY Features }
http://seclists.org/webappsec/2012/q1/33
http://seclists.org/webappsec/2012/q1/33Thu, 15 Mar 2012 21:00:26 +0000VU#624051: Microsoft Remote Desktop Protocol (RDP) insecurely deallocates memory
http://www.kb.cert.org/vuls/id/624051
US-CERThttp://www.kb.cert.org/vuls/id/624051Thu, 15 Mar 2012 19:05:13 +0000VU#339177: Cisco AnyConnect Clientless SSL VPN Portforwarder ActiveX control buffer overflow
http://www.kb.cert.org/vuls/id/339177
US-CERThttp://www.kb.cert.org/vuls/id/339177Wed, 14 Mar 2012 18:17:27 +0000Impressions: Fuzzing
http://taosecurity.blogspot.com/2012/03/impressions-fuzzing.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-2040779975053102051Wed, 14 Mar 2012 06:00:00 +0000TA12-073A: Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA12-073A.html
http://www.us-cert.gov/cas/techalerts/TA12-073A.htmlTue, 13 Mar 2012 18:34:31 +0000Impressions: Hunting Security Bugs
http://taosecurity.blogspot.com/2012/03/impressions-hunting-security-bugs.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-4089451143334615130Tue, 13 Mar 2012 06:00:00 +0000Impressions: The Web Application Hacker's Handbook, 2nd Ed
http://taosecurity.blogspot.com/2012/03/impressions-web-application-hackers.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-5576136962433111557Mon, 12 Mar 2012 06:00:00 +0000Impressions: Web Application Security: A Beginner's Guide
http://taosecurity.blogspot.com/2012/03/impressions-web-application-security.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-723133348327294529Sun, 11 Mar 2012 14:33:00 +0000VU#504019: AjaXplorer contains multiple vulnerabilities
http://www.kb.cert.org/vuls/id/504019
US-CERThttp://www.kb.cert.org/vuls/id/504019Thu, 08 Mar 2012 12:40:14 +0000Review of SSH Mastery Posted
http://taosecurity.blogspot.com/2012/03/review-of-ssh-mastery-posted.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-2780462214094977435Tue, 06 Mar 2012 06:00:00 +0000Keep CIRT and Internal Investigations Separate
http://taosecurity.blogspot.com/2012/03/keep-cirt-and-internal-investigations.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-8429188336111030381Sun, 04 Mar 2012 12:00:00 +0000TaoSecurity Blog Wins Most Educational Security Blog
http://taosecurity.blogspot.com/2012/03/taosecurity-blog-wins-most-educational.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-340475546839584820Sat, 03 Mar 2012 15:31:00 +0000VU#523889: libpng chunk decompression integer overflow vulnerability
http://www.kb.cert.org/vuls/id/523889
US-CERThttp://www.kb.cert.org/vuls/id/523889Thu, 23 Feb 2012 21:48:14 +0000Secure Ninja Appoints Leonard Chin as VP to Lead International Expansion
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1373
1373@http://www.professionalsecuritytesters.orgThu, 23 Feb 2012 01:56:44 +0000VU#273502: EasyVista single sign-on authentication bypass vulnerability
http://www.kb.cert.org/vuls/id/273502
US-CERThttp://www.kb.cert.org/vuls/id/273502Tue, 21 Feb 2012 21:05:13 +0000VU#707254: UTC Fire & Security Master Clock contains hardcoded default administrator login credentials
http://www.kb.cert.org/vuls/id/707254
US-CERThttp://www.kb.cert.org/vuls/id/707254Mon, 20 Feb 2012 21:39:31 +0000VU#885499: HP StorageWorks P2000 G3 directory traversal vulnerability
http://www.kb.cert.org/vuls/id/885499
US-CERThttp://www.kb.cert.org/vuls/id/885499Mon, 20 Feb 2012 12:17:14 +0000TA12-045A: Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA12-045A.html
http://www.us-cert.gov/cas/techalerts/TA12-045A.htmlTue, 14 Feb 2012 18:37:26 +0000I Want to Detect and Respond to Intruders But I Don't Know Where to Start!
http://taosecurity.blogspot.com/2012/02/i-want-to-detect-and-respond-to.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-228653806604250785Mon, 13 Feb 2012 13:59:00 +0000Pen Tests Evolved: The Advanced Threat Cycle
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1371
1371@http://www.professionalsecuritytesters.orgThu, 09 Feb 2012 15:40:05 +0000VU#542123: ISC BIND 9 resolver cache vulnerability
http://www.kb.cert.org/vuls/id/542123
US-CERThttp://www.kb.cert.org/vuls/id/542123Wed, 08 Feb 2012 19:11:14 +0000Impressions: Network Warrior, 2nd Ed
http://taosecurity.blogspot.com/2012/02/impressions-network-warrior-2nd-ed.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-5058946238126313348Sat, 04 Feb 2012 15:18:00 +0000Impressions: Windows Sysinternals Administrator's Reference
http://taosecurity.blogspot.com/2012/02/impressions-windows-sysinternals.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-6924512416289179389Sat, 04 Feb 2012 15:01:00 +0000Impressions: The Tangled Web
http://taosecurity.blogspot.com/2012/02/impressions-tangled-web.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-3119771784646940772Sat, 04 Feb 2012 14:23:00 +0000VU#732115: Project Open cross-site scripting vulnerability
http://www.kb.cert.org/vuls/id/732115
US-CERThttp://www.kb.cert.org/vuls/id/732115Fri, 03 Feb 2012 19:48:32 +0000Security Kaizen Magazine Issue 4 is released
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1370
1370@http://www.professionalsecuritytesters.orgFri, 03 Feb 2012 18:58:28 +0000VU#410281: Apple Mac OS X CoreText embedded font vulnerability
http://www.kb.cert.org/vuls/id/410281
US-CERThttp://www.kb.cert.org/vuls/id/410281Thu, 02 Feb 2012 15:10:14 +0000VU#403593: Apple Mac OS X ATS data-font memory corruption vulnerability
http://www.kb.cert.org/vuls/id/403593
US-CERThttp://www.kb.cert.org/vuls/id/403593Thu, 02 Feb 2012 15:10:14 +0000VU#763355: 802.1X password exploit on many HTC Android devices
http://www.kb.cert.org/vuls/id/763355
US-CERThttp://www.kb.cert.org/vuls/id/763355Wed, 01 Feb 2012 14:59:32 +0000VU#470151: Linux Kernel local privilege escalation via SUID /proc/pid/mem write
http://www.kb.cert.org/vuls/id/470151
US-CERThttp://www.kb.cert.org/vuls/id/470151Fri, 27 Jan 2012 15:22:35 +0000Modeling Security Pentests - New Issue of WebAppPentesting is Out!
http://www.professionalsecuritytesters.org/modules.php?name=News&file=article&sid=1369
1369@http://www.professionalsecuritytesters.orgWed, 25 Jan 2012 16:58:26 +0000VU#738961: Oracle Outside In contains an exploitable vulnerability in Lotus 123 v4 parser
http://www.kb.cert.org/vuls/id/738961
US-CERThttp://www.kb.cert.org/vuls/id/738961Thu, 19 Jan 2012 01:00:48 +0000TA12-010A: Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA12-010A.html
http://www.us-cert.gov/cas/techalerts/TA12-010A.htmlTue, 10 Jan 2012 19:11:29 +0000Best Book Bejtlich Read in 2011
http://taosecurity.blogspot.com/2012/01/its-time-to-name-winner-of-best-book.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-8764662679602315693Mon, 09 Jan 2012 21:40:00 +0000Telling a Security Story with Charts
http://taosecurity.blogspot.com/2012/01/telling-security-story-with-charts.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-3606061486707477361Sun, 08 Jan 2012 17:10:00 +0000Happy 9th Birthday TaoSecurity Blog
http://taosecurity.blogspot.com/2012/01/happy-9th-birthday-taosecurity-blog.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-4470680822517511717Sun, 08 Jan 2012 16:07:00 +0000TA11-350A: Adobe Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA11-350A.html
http://www.us-cert.gov/cas/techalerts/TA11-350A.htmlFri, 16 Dec 2011 19:19:11 +0000FULL FEED LOCATED AT feeds.rmccurdy.comFULL FEED LOCATED AT feeds.rmccurdy.com THIS IS ONLY max ~50 yahoo trims the feeds !
http://pipes.yahoo.com/pipes/pipe.info?_id=5f1dcd4397142867d586ae88e192f796
Wed, 23 May 2012 10:25:06 +0000http://pipes.yahoo.com/pipes/TA11-347A: Microsoft Updates for Multiple Vulnerabilities
http://www.us-cert.gov/cas/techalerts/TA11-347A.html
http://www.us-cert.gov/cas/techalerts/TA11-347A.htmlTue, 13 Dec 2011 20:47:45 +0000Mandiant Webinar Wednesday; Help Us Break a Record!
http://taosecurity.blogspot.com/2011/12/mandiant-webinar-wednesday-help-us.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-2879193110665395747Tue, 06 Dec 2011 22:06:00 +0000Tripwire Names Bejtlich #1 of "Top 25 Influencers in Security"
http://taosecurity.blogspot.com/2011/12/tripwire-names-bejtlich-1-of-top-25.html
Richard Bejtlichtag:blogger.com,1999:blog-4088979.post-7142337222581948572Tue, 06 Dec 2011 21:52:00 +0000Bugtraq: [ MDVSA-2012:079 ] sudo
http://www.securityfocus.com/archive/1/522811
Bugtraq: DC4420 - London DEFCON - May meet - Tuesday May 22nd 2012
http://www.securityfocus.com/archive/1/522822
Bugtraq: [Announcement] CHMag's Issue 28, May 2012 Released
http://www.securityfocus.com/archive/1/522821
Xen PV Bootloader Bug Lets Local Guest Users Crash the System
http://www.securitytracker.com/id/1027090
PHP Windows com_print_typeinfo() Buffer Overflow Lets Local Users Gain Elevated Privileges
http://www.securitytracker.com/id/1027089
Linux Kernel kiocb_batch_free() Bug Lets Local Users Deny Service
http://www.securitytracker.com/id/1027085
Linux Kernel KVM Memory Slot Management Flaw Lets Local Guest Users Deny Service on the Guest Operating System
http://www.securitytracker.com/id/1027083
SANSFIRE 2011
http://www.sans.org/info/74039
http://www.sans.org/info/74039(1) HIGH: Google Chrome Sandbox Escapes
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#widely1
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#widely1(2) HIGH: Microsoft Remote Desktop Protocol Vulnerability
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#widely2
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#widely2(3) HIGH: Mozilla Firefox Use-After-Free Vulnerability
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#widely3
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#widely32.8 Mozilla Firefox/Thunderbird/SeaMonkey "shlwapi.dll"
Use-After-Free Memory Corruption
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#2.8
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#2.812.11.11 IBM DB2 Multiple Security Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.11
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1112.11.12 IBM Maximo Asset Management Multiple Security Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.12
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1212.11.14 Google Chrome Remote Code Execution
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.14
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1412.11.16 Apple Safari International Domain Name URI Spoofing
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.16
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1612.11.5 Microsoft Expression "wintab32.dll" DLL Loading Arbitrary Code
Execution
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.5
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.512.11.6 Microsoft Visual Studio Add-In Local Privilege Escalation
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.6
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.612.11.7 DAEMON Tools "IOCTL" Handling Local Privilege Escalation
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.7
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.712.11.9 XnView Multiple Buffer Overflow Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.9
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.912.11.10 Vegas Movie Studio HD "CFHDDecoder.dll" DLL Loading Arbitrary
Code Execution
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.10
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1012.11.23 LotusCMS Multiple PHP Code Execution Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.23
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2312.11.24 Jenkins Multiple Cross-Site Scripting and Directory Traversal
Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.24
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2412.11.25 Zend Server Multiple HTML Injection Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.25
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2512.11.26 Invision Power Board Unspecified HTML Injection
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.26
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2612.11.18 Splunk Unspecified Cross-Site Scripting
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.18
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1812.11.19 SquirrelMail Autocomplete Plugin Email Addresses Cross-Site
Scripting
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.19
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1912.11.20 EJBCA "issuer" Parameter Cross-Site Scripting
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.20
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2012.11.21 Synology Photo Station "photo_one.php" Script Cross-Site
Scripting
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.21
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2112.11.22 Aurora WebOPAC "txtEmailAliasBarcode" Parameter SQL Injection
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.22
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.2212.11.1 Microsoft Remote Desktop Protocol Multiple Vulnerabilities
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.1
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.112.11.3 Microsoft Windows Kernel "Win32k.sys" Local Privilege
Escalation
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.3
http://www.sans.org/newsletters/risk/display.php?v=11&i=11&rss=Y#12.11.3ffmpeg library multiple security vulnerabilities
http://securityvulns.com/news/ffmpeg/1205.html
12385.ffmpeg/1205.21.05.2012.libraryOpenOffice multiple security vulnerabilities
http://securityvulns.com/news/OpenOffice/1205.html
12384.OpenOffice/1205.21.05.2012.clientOpenSSL DoS
http://securityvulns.com/news/OpenSSL/CVE-2012-2333.html
12383.OpenSSL/CVE-2012-2333.21.05.2012.libraryApple QuickTime multiple security vulnerabilities
http://securityvulns.com/news/Apple/QuickTime/1205.html
12382.Apple/QuickTime/1205.21.05.2012.libraryMicrosoft Windows Keyboard Layout Local Privilege Escalation
http://www.vupen.com/english/ADV-2012-0267.php
Symantec Web Gateway Remote Code Execution and Data Manipulation
http://www.vupen.com/english/ADV-2012-0266.php
HP Business Service Management Remote Code Execution Vulnerability
http://www.vupen.com/english/ADV-2012-0265.php
HP OpenVMS ACMELOGIN Local Unauthorized Access Vulnerability
http://www.vupen.com/english/ADV-2012-0264.php
Off-the-Record Messaging (OTR) for Pidgin Remote Format String
http://www.vupen.com/english/ADV-2012-0262.php
RealNetworks RealPlayer Data Processing Remote Code Execution
http://www.vupen.com/english/ADV-2012-0261.php
Opera Browser URL Constructs Processing Remote Code Execution
http://www.vupen.com/english/ADV-2012-0259.php
Google Chrome Multiple Use-after-free and Memory Corruptions
http://www.vupen.com/english/ADV-2012-0258.php
Sympa "wwsympa/wwsympa.fcgi.in" Archives Access Control Issue
http://www.vupen.com/english/ADV-2012-0257.php
Socat "xioscan_readline()" Data Processing Heap Buffer Overflow
http://www.vupen.com/english/ADV-2012-0256.php
Apple QuickTime Data Processing Multiple Remote Code Execution
http://www.vupen.com/english/ADV-2012-0253.php
Apple Safari WebKit Remote Code Execution and Cross Site Scripting
http://www.vupen.com/english/ADV-2012-0252.php
Apple Mac OS X Multiple Remote Code Execution and Security Bypass
http://www.vupen.com/english/ADV-2012-0251.php
TorBrowser SOCKS Proxy DNS Configuration Bypass Weakness
http://www.vupen.com/english/ADV-2012-0250.php
PHP Remote Command Injection and Buffer Overflow Vulnerabilities
http://www.vupen.com/english/ADV-2012-0249.php
Pidgin XMPP File Transfer Requests Remote Memory Corruption
http://www.vupen.com/english/ADV-2012-0247.php
Apple iOS Code Execution and Location Bar Spoofing Vulnerabilities
http://www.vupen.com/english/ADV-2012-0246.php
Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities
http://www.vupen.com/english/ADV-2012-0245.php
Adobe Flash Professional Data Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/ADV-2012-0244.php
Adobe Photoshop Data Processing Code Execution Vulnerabilities
http://www.vupen.com/english/ADV-2012-0243.php
Adobe Illustrator Data Processing Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/ADV-2012-0242.php
Microsoft Products Multiple Code Execution and Privilege Escalation
http://www.vupen.com/english/ADV-2012-0241.php
IBM AIX RPC Portmapper Access Restriction Bypass Vulnerability
http://www.vupen.com/english/ADV-2012-0240.php
Adobe Flash Player Object Confusion Remote Code Execution vulnerability
http://www.vupen.com/english/ADV-2012-0239.php
PHP "QUERY_STRING" Parameter Processing Command Injection
http://www.vupen.com/english/ADV-2012-0238.php
IBM AIX LDAP Authentication "getpwnam()" Local Privilege Escalation
http://www.vupen.com/english/ADV-2012-0237.php
FULL FEED LOCATED AT feeds.rmccurdy.comFULL FEED LOCATED AT feeds.rmccurdy.com THIS IS ONLY max ~50 yahoo trims the feeds !
http://pipes.yahoo.com/pipes/pipe.info?_id=5f1dcd4397142867d586ae88e192f796
Wed, 23 May 2012 10:25:08 +0000http://pipes.yahoo.com/pipes/