<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Ramblings of the änal security guy</title>
	<atom:link href="http://c22blog.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://c22blog.wordpress.com</link>
	<description>Sometimes pointless, always rambling, best ignored...</description>
	<lastBuildDate>Mon, 09 Nov 2009 19:18:43 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='c22blog.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/1b6c05a022094e3a7342e6b645c9cfce?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Ramblings of the änal security guy</title>
		<link>http://c22blog.wordpress.com</link>
	</image>
			<item>
		<title>GWAPT / SEC542</title>
		<link>http://c22blog.wordpress.com/2009/11/09/gwapt-sec542/</link>
		<comments>http://c22blog.wordpress.com/2009/11/09/gwapt-sec542/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 19:18:43 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Study]]></category>
		<category><![CDATA[GIAC]]></category>
		<category><![CDATA[gwapt]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1009</guid>
		<description><![CDATA[After almost a year I&#8217;ve finally managed to take the GWAPT (Web Application Penetration Tester) exam, just in time to head to SANS London and the Security Essentials class. I have mixed feelings on the exam. Even though I passed with a good mark (96.67%), the 5 that I got wrong were (in my opinion) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=1009&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://c22blog.files.wordpress.com/2009/11/gwapt_silver.jpg"><img class="alignleft size-full wp-image-1010" style="margin:8px;" title="GWAPT_Silver" src="http://c22blog.files.wordpress.com/2009/11/gwapt_silver.jpg?w=276&#038;h=276" alt="GWAPT_Silver" width="276" height="276" /></a>After almost a year I&#8217;ve finally managed to take the <a title="GWAPT" href="http://www.giac.org/certifications/security/GWAPT.php" target="_blank">GWAPT</a> (Web Application Penetration Tester) exam, just in time to head to SANS London and the Security Essentials class. I have mixed feelings on the exam. Even though I passed with a good mark (96.67%), the 5 that I got wrong were<em> (in my opinion)</em> a little questionable. Still, I&#8217;m sure I&#8217;ll hit the holy grail (100%) sooner or later <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  It will just take time, and patience.</p>
<p>For a little history on this, I first attended the 4-day version of the SEC-542 back in December last year. The course was good, and I wrote about the contents on the blog (<a title="Day-1" href="http://c22blog.wordpress.com/2008/12/04/sans-web-app-penetration-testing-and-ethical-hacking-class-day-1/" target="_blank">day-1</a>, <a title="Day-3" href="http://c22blog.wordpress.com/2008/12/05/sans-web-app-penetration-testing-and-ethical-hacking-class-day-2/" target="_blank">day-2</a> ,<a title="Day-3" href="http://c22blog.wordpress.com/2008/12/05/sans-web-app-penetration-testing-and-ethical-hacking-class-day-3/" target="_blank">day-3</a>. <a title="Day-4" href="http://c22blog.wordpress.com/2008/12/06/sans-web-app-penetration-testing-and-ethical-hacking-class-day-4/" target="_blank">day-4</a>). The 6-day version of the class has incorporated a number of welcome additions and helps the course really grow. I always felt that the 4-day version lacked a certain something, and the new version really fills the gaps with new sections on Flash, WebServices <em>(WSDL, UDDI, SOAP&#8230;)</em> and nice coverage of Python, JavaScript and PHP for Penetration Testers. The last day is also now a Capture the Flag event which will really help to solidify the knowledge and let people get a hands-on approach to testing.</p>
<p>I can&#8217;t finish this post without saying a little something about the OnDemand program. The new OnDemand system is certainly a step in the right direction. As SEC-542 is one of the first on the BETA OnDemand it lacks the additional links that will come with maturity. I think that the OnDemand option of training has become more of an option than previously. The support you get is also great, especially as Kevin is very approachable. If all else fails you can shoot me an email and I&#8217;ll see if I can help. Hopefully this will be the class I&#8217;ll be Mentoring in Vienna next year (given the chance).</p>
<p>Overall I&#8217;d give the class 95/100 &#8211;&gt; There&#8217;s room for some additional coverage of things like JBoss, Coldfusion and Tomcat. Still you can&#8217;t fit everything into 6 days <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  I can&#8217;t wait for SEC-642, for some advanced WebApp fu.</p>
<p>GWAPT Certified Professionals &#8211;&gt; <a title="GWAPT Certified Professionals" href="http://www.giac.org/certified_professionals/listing/GWAPT.php" target="_blank">LISTING</a></p>
<p>GWAPT Exam Coverage &#8211;&gt; <a title="GWAPT Coverage" href="http://www.giac.org/certbulletin/gwapt.php" target="_blank">Coverage</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1009/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=1009&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/11/09/gwapt-sec542/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/11/gwapt_silver.jpg" medium="image">
			<media:title type="html">GWAPT_Silver</media:title>
		</media:content>
	</item>
		<item>
		<title>Projects are like buses</title>
		<link>http://c22blog.wordpress.com/2009/11/03/projects-are-like-buses/</link>
		<comments>http://c22blog.wordpress.com/2009/11/03/projects-are-like-buses/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 13:30:31 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[General Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[not in service]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[scripting]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1001</guid>
		<description><![CDATA[I know, I know, what a strange title for a blog post. Then again, I&#8217;ve never really been known for  being the most normal of people bloggers. Then again projects really are like buses. There&#8217;s none for ages then 2 come along at once   Things have been a little quiet on the blog [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=1001&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p style="text-align:center;"><img class="aligncenter" style="margin-top:6px;margin-bottom:6px;" src="http://farm1.static.flickr.com/140/353800004_5843b87789.jpg" alt="Photo by by angelocesare (CC)" width="306" height="229" />I know, I know, what a strange title for a blog post. Then again, I&#8217;ve never really been known for  being the most normal of <span style="text-decoration:line-through;">people</span> bloggers. Then again projects really are like buses. There&#8217;s none for ages then 2 come along at once <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Things have been a little quiet on the blog for several reasons. The first was my nagging neck problem, which I&#8217;m hoping is back under control. The second is the start of a few projects that have been in the works for a while now.</p>
<ul>
<li>€urotrash security podcast</li>
<li>PenTester Scripting</li>
</ul>
<p><a href="http://www.eurotrashsecurity.eu"><img class="alignleft" style="margin:5px;" src="http://www.eurotrashsecurity.eu/images/eurotrash.jpg" alt="" width="223" height="52" /></a>The €urotrash security Podcast has been in the planning phase for a while now, with the initial meeting to discuss particulars at the recent BruCON conference in Brussels. Episode 1 has just been released, so head over to <a title="€urotrash Security Podcast" href="http://www.eurotrashsecurity.eu" target="_blank">http://www.eurotrashsecurity.eu</a> and grab a copy. Let us know what you think. As with any new Podcast we&#8217;re looking for feedback on how to make things better and cover what you want us to cover. You can load up your favourite RSS reader <a title="€urotrash RSS feed" href="http://www.eurotrashsecurity.eu/episodes/eurotrash.xml" target="_blank">HERE</a> for updates on the next Podcast release..</p>
<p><a href="http://www.pentesterscripting.com"><img class="alignright" style="margin:5px;" src="http://www.pentesterscripting.com/_media/ptsv1.gif" alt="" width="184" height="92" /></a>The second project I&#8217;m involved with came out of a simple remark on Twitter. I&#8217;m not much of a scripter, but it&#8217;s something I&#8217;m looking at improving. When I commented that a SANS course cover scripting for Penetration Testers would be a good thing, Kevin Johnson agreed and the project was born. <a title="http://www.pentesterscripting.com" href="http://www.pentesterscripting.com" target="_blank">PenTesterScripting</a> is still in it&#8217;s early phases, but we hope it will turn into a place for Penetration Testers to come and find useful scripts to help automate some of the more tedious and long-winded parts of penetration testing. Head over to the site and vote on our logo competition, and feel free to email us scripts you want us to host on the site.</p>
<p>For updates to both projects, follow me on twitter as <a title="http://twitter.com/ChrisJohnRiley" href="http://twitter.com/ChrisJohnRiley" target="_blank">@ChrisJohnRiley</a>, or follow the projects directly, <a title="http://twitter.com/PenTesterScript" href="http://twitter.com/PenTesterScript" target="_blank">@PenTesterScript</a> and <a title="http://twitter.com/EurotrashSec" href="http://twitter.com/EurotrashSec" target="_blank">@EurotrashSec</a></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1001/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1001/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1001/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=1001&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/11/03/projects-are-like-buses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://farm1.static.flickr.com/140/353800004_5843b87789.jpg" medium="image">
			<media:title type="html">Photo by by angelocesare (CC)</media:title>
		</media:content>

		<media:content url="http://www.eurotrashsecurity.eu/images/eurotrash.jpg" medium="image" />

		<media:content url="http://www.pentesterscripting.com/_media/ptsv1.gif" medium="image" />
	</item>
		<item>
		<title>TYPO3 Advisories (TYPO3-SA-2009-016)</title>
		<link>http://c22blog.wordpress.com/2009/10/24/typo3-advisories-typo3-sa-2009-016/</link>
		<comments>http://c22blog.wordpress.com/2009/10/24/typo3-advisories-typo3-sa-2009-016/#comments</comments>
		<pubDate>Sat, 24 Oct 2009 10:50:49 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[typo3]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=987</guid>
		<description><![CDATA[ Some people may have noticed the addition of an &#8220;advisories&#8221; section to the blog over the last few days. Despite the fact I&#8217;m drugged up on painkillers and muscle relaxants, I managed to post up some information about the newest TYPO3 Security Advisories released in the past week.
Although the latest additions are basic XSS [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=987&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><img class="alignleft" style="margin:5px 7px;" src="http://typo3.com/fileadmin/templates/images/logo-typo3.gif" alt="" width="123" height="34" align="left" /> Some people may have noticed the addition of an &#8220;advisories&#8221; section to the blog over the last few days. Despite the fact I&#8217;m drugged up on painkillers and muscle relaxants, I managed to post up some information about the newest TYPO3 Security Advisories released in the past week.</p>
<p>Although the latest additions are basic XSS type vulnerabilities, I thought it was worth adding some information to the text from the TYPO3 security team. Once I&#8217;m a little less dosed up, I&#8217;ll try and add some example XSS strings (purely for educational purposes). I&#8217;m a believer in responsible disclosure, but a part of that is obviously disclosing the vulnerability and how it can be tested. Without that, security practitioners end up with a list of possible exploits and no way to demonstrate this to their clients. I personally hate nothing more than having to write &#8220;vulnerable to unpublished exploit&#8221; in a report, and often see those kind of vulns ignored or pushed to the back of the pile.</p>
<ul>
<li><a href="http://www.c22.cc/advisories/" target="_blank">New Advisories section</a></li>
<li>Original advisory (<a title="typo3-sa-2009-016" href="http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-016/" target="_blank">TYPO3-SA-2009-016</a>)</li>
</ul>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/987/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/987/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/987/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/987/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/987/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/987/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/987/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/987/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/987/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/987/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=987&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/10/24/typo3-advisories-typo3-sa-2009-016/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://typo3.com/fileadmin/templates/images/logo-typo3.gif" medium="image" />
	</item>
		<item>
		<title>Interviews and podcasts</title>
		<link>http://c22blog.wordpress.com/2009/10/21/interviews-and-podcasts/</link>
		<comments>http://c22blog.wordpress.com/2009/10/21/interviews-and-podcasts/#comments</comments>
		<pubDate>Wed, 21 Oct 2009 08:15:14 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[General Life]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[dvwa]]></category>
		<category><![CDATA[interviews]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[security justice]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=950</guid>
		<description><![CDATA[This week has been an eventful one. Not only am I reduced to typing slowly and painfully with my left hand (don&#8217;t ask, it&#8217;s a long story *), but the audio for my guest appearance on the Security Justice podcast is out as well.

Security Justice International BBQ Edition – Chris John Riley (@ChrisJohnRiley) and Robin [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=950&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This week has been an eventful one. Not only am I reduced to typing slowly and painfully with my left hand <em>(don&#8217;t ask, it&#8217;s a long story *)</em>, but the audio for my guest appearance on the <a title="http://securityjustice.com/" href="http://securityjustice.com/" target="_blank">Security Justice</a> podcast is out as well.</p>
<blockquote>
<h2><a title="Permanent Link: Security Justice International BBQ Edition – Chris John Riley (@ChrisJohnRiley) and Robin Wood (@digininja)" rel="bookmark" href="http://securityjustice.com/archives/86">Security Justice International BBQ Edition – Chris John Riley (@ChrisJohnRiley) and Robin Wood (@digininja)</a></h2>
<p>October 20th, 2009 Tom Posted in <a title="View all posts in Podcast Special Editions" rel="category tag" href="http://securityjustice.com/archives/category/podcast-special-editions">Podcast Special Editions</a> |   <a title="Comment on Security Justice International BBQ Edition – Chris John Riley (@ChrisJohnRiley) and Robin Wood (@digininja)" href="http://securityjustice.com/archives/86#respond">No Comments »</a></p>
<p><img class="alignright" title="chris-robin" src="http://securityjustice.com/wp-content/uploads/2009/10/chris-robin.jpg" alt="chris-robin" width="233" height="183" />This special edition was recorded during our <a href="http://securityjustice.com/archives/76">1st annual International BBQ podcast</a>.</p>
<p><a href="http://twitter.com/ChrisJohnRiley">Chris John Riley</a> is a penetration tester and <a href="http://www.c22.cc/">well known security blogger</a> currently located in Austria.  <a href="http://twitter.com/digininja">Robin Wood</a> is from the UK and is the creator of many well known open source security projects including <a href="http://www.digininja.org/jasager/">Jasager</a>, <a href="http://www.digininja.org/interceptor">the Interceptor</a> and <a href="http://www.digininja.org/projects/kreiosc2.php">KreiosC2</a>. Find out more about Chris on his <a href="http://www.c22.cc/">awesome blog</a>.  You can find out more about Robin and his projects on his <a href="http://www.digininja.org/">website</a>.  Chris and Robin talk to us about <a href="http://en.wikipedia.org/wiki/Cider">Cider</a>, <a href="https://wiki.har2009.org/page/Main_Page">HAR</a>, blogging, <a href="http://www.brucon.org/index.php/Main_Page">BruCON</a>, security/pentest certifications, metasploit modules, Jasager updates, talks at security conferences and more!</p>
<p>Thanks again to Chris and Robin for being on the show!</p>
<p><a href="http://securityjustice.com/podpress_trac/web/86/0/Security_Justice_InternationalBBQ_ChrisJohnRiley_RobinWood.mp3" target="new"><img src="http://securityjustice.com/wp-content/plugins/podpress/images/audio_mp3_button.png" border="0" alt="icon for podpress" align="top" /></a> Security Justice International BBQ &#8211; Chris John Riley and Robin Wood [34:39m]: <a href="http://securityjustice.com/archives/86#"><span id="podPressPlayerSpace_1_PlayLink">Play Now</span></a> | <a href="http://securityjustice.com/archives/86#">Play in Popup</a> | <a href="http://securityjustice.com/podpress_trac/web/86/0/Security_Justice_InternationalBBQ_ChrisJohnRiley_RobinWood.mp3" target="new">Download</a></p></blockquote>
<p>Many thanks to all the guys over at Security Justice for letting me get on the show and be a general media whore <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><a title="twitter.com/ethicalhack3r" href="http://twitter.com/ethicalhack3r" target="_blank">Ryan Dewhurst</a> over at <a href="http://www.ethicalhack3r.co.uk/">http://www.ethicalhack3r.co.uk</a> also asked me to do a short written interview for his Blogs  &#8220;people in infosec&#8221; feature. I&#8217;m a bit long winded, but aren&#8217;t I always ! So if you want to read my comments on conferences, ethical hacking courses and general <span style="text-decoration:underline;">stuff,</span> pop over to his blog and take a <a href="http://www.ethicalhack3r.co.uk/2009/10/20/interview-chris-john-riley-the-anal-security-guy/" target="_blank">look</a>. While you&#8217;re there, take make sure to take a peek at his excellent <a title="http://www.dvwa.co.uk" href="http://www.dvwa.co.uk" target="_blank">DVWA </a><em>(Damn Vulnerable Web App)</em> project.</p>
<p><span style="color:#888888;">* Well, it&#8217;s not really that long. Needless to say a neck/back injury that&#8217;s been plaguing me for a few years have flared up again. Currently I have numbness and tingling in (mostly) my right hand. So, I&#8217;m banned from prolonged use of computer currently. Yes, it&#8217;s hell&#8230;.</span></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/950/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/950/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/950/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/950/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/950/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/950/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/950/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/950/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/950/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/950/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=950&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/10/21/interviews-and-podcasts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://securityjustice.com/podpress_trac/web/86/0/Security_Justice_InternationalBBQ_ChrisJohnRiley_RobinWood.mp3" length="33330542" type="audio/mpeg" />
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://securityjustice.com/wp-content/uploads/2009/10/chris-robin.jpg" medium="image">
			<media:title type="html">chris-robin</media:title>
		</media:content>

		<media:content url="http://securityjustice.com/wp-content/plugins/podpress/images/audio_mp3_button.png" medium="image">
			<media:title type="html">icon for podpress</media:title>
		</media:content>
	</item>
		<item>
		<title>Nikto 2.10 released</title>
		<link>http://c22blog.wordpress.com/2009/10/18/nikto-2-10-released/</link>
		<comments>http://c22blog.wordpress.com/2009/10/18/nikto-2-10-released/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 12:26:30 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Penetration Test]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[nikto]]></category>
		<category><![CDATA[web scanner]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=938</guid>
		<description><![CDATA[The guys over at CIRT.NET has released an update to the Nikto web server scanner tool. According to the blog post discussing the release, this version has undergone &#8220;significant rewrites under the hood &#8230;&#8221; &#8220;&#8230; to make it more expandable and usable&#8221;. Sounds interesting.
The newest version includes a number of bug-fixes, as well as some [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=938&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://cirt.net/nikto2"><img class="alignright" style="margin:12px;" src="http://cirt.net/images/nikto.png" alt="" width="152" height="280" /></a>The guys over at <a title="http://cirt.net" href="http://cirt.net/node/56" target="_blank">CIRT.NET</a> has released an update to the Nikto web server scanner tool. According to the blog post discussing the release, this version has undergone &#8220;significant rewrites under the hood &#8230;&#8221; &#8220;&#8230; to make it more expandable and usable&#8221;. Sounds interesting.</p>
<p>The newest version includes a number of bug-fixes, as well as some enhanced functionality .:</p>
<ul>
<li>Added test for asp source code disclosure through the Translate header</li>
<li>New plugin added to identify embedded devices</li>
<li>Added check for multiple index files for request</li>
<li>Add plugin to use dirbuster lists with mutate 6 and mutate-options</li>
<li>Added subdomain buteforcer as mutate option 5, thanks to <a title="ethicalhack3r" href="http://twitter.com/ethicalhack3r" target="_blank">Ryan DewHurst</a></li>
<li>Added extra tests to pull information if scanning ePO agent or HP WBEM</li>
<li>Added test to recognise a Dell Remote Access Console</li>
<li>Now supports NTLM authentication</li>
<li>Added tests to identify Ampache</li>
<li>Altered favicon database to use dynamic database</li>
<li>&#8230;</li>
</ul>
<p>For a full list of fixes, enhancements and changes see the project <a title="2.1.0/CHANGES.txt" href="http://cirt.net/nikto/UPDATES/2.1.0/CHANGES.txt" target="_blank">changelog.</a></p>
<p>By looking at the <a title="2.1.0/versions.txt" href="http://cirt.net/nikto/UPDATES/2.1.0/versions.txt" target="_blank">versions.txt</a> released with this version it appears that the following plugins have been updated .:</p>
<ul>
<li>nikto_user_enum_apache.plugin</li>
<li>nikto_core.plugin</li>
</ul>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/938/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/938/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/938/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/938/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/938/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/938/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/938/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/938/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/938/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/938/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=938&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/10/18/nikto-2-10-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://cirt.net/images/nikto.png" medium="image" />
	</item>
		<item>
		<title>Number of the beast</title>
		<link>http://c22blog.wordpress.com/2009/10/18/number-of-the-beast/</link>
		<comments>http://c22blog.wordpress.com/2009/10/18/number-of-the-beast/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 00:21:17 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[General Life]]></category>
		<category><![CDATA[Strange]]></category>
		<category><![CDATA[666]]></category>
		<category><![CDATA[Number of the beat]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=933</guid>
		<description><![CDATA[Well I&#8217;ve finally hit the milestone I&#8217;m sure everybody on Twitter aims for at one point or another. I&#8217;ve managed to brain-wash 666 people into following my inane ramblings and random comments on Twitter. I&#8217;m sure I&#8217;d have hit this milestone a lot quicker if I didn&#8217;t have a horrible tendency to block anybody who [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=933&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Well I&#8217;ve finally hit the milestone I&#8217;m sure everybody on Twitter aims for at one point or another. I&#8217;ve managed to brain-wash 666 people into following my inane ramblings and random comments on Twitter. I&#8217;m sure I&#8217;d have hit this milestone a lot quicker if I didn&#8217;t have a horrible tendency to block anybody who looks remotely like a bot <em>(there are a lot more than you&#8217;d think)</em>, and of course n3td3v, I blocked him too to stop him retweeting anything <em>(who&#8217;d want to be associated with that kind of thing ???)</em>. Sorry if you weren&#8217;t a bot, thems the breaks <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align:left;"><img class="size-full wp-image-934 aligncenter" style="margin-top:8px;margin-bottom:8px;" title="666followers" src="http://c22blog.files.wordpress.com/2009/10/666followers.png?w=198&#038;h=94" alt="666followers" width="198" height="94" />In celebration of this milestone I&#8217;ll make sure to bite the head off a bat at the next available opportunity. Next up <span style="color:#800000;">1337</span>, at which point I hope to release a stunningly uninteresting XSS  zero-day exploit in an application nobody uses or cares about. Keep an eye out for that one&#8230;</p>
<p style="text-align:center;"><a href="http://c22blog.files.wordpress.com/2009/10/2009-10-18-021922.png"><img class="aligncenter size-medium wp-image-936" title="2009-10-18-021922" src="http://c22blog.files.wordpress.com/2009/10/2009-10-18-021922.png?w=300&#038;h=109" alt="2009-10-18-021922" width="300" height="109" /></a><a title="twitterstats.com" href="http://twittercounter.com/chrisjohnriley/all/followers" target="_blank">3 Months stats &#8211; twittercounter.com</a></p>
<p style="text-align:left;">
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/933/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/933/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/933/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/933/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/933/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/933/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/933/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/933/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/933/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/933/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=933&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/10/18/number-of-the-beast/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/666followers.png" medium="image">
			<media:title type="html">666followers</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/2009-10-18-021922.png?w=300" medium="image">
			<media:title type="html">2009-10-18-021922</media:title>
		</media:content>
	</item>
		<item>
		<title>Strange twitterings from the BBC</title>
		<link>http://c22blog.wordpress.com/2009/10/16/strange-twitterings-from-the-bbc/</link>
		<comments>http://c22blog.wordpress.com/2009/10/16/strange-twitterings-from-the-bbc/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 12:02:40 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Strange]]></category>
		<category><![CDATA[bbc]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=922</guid>
		<description><![CDATA[Earlier today I was catching up on some tidbits of world news from various sources when I stumbled across something that caught my eye. BBC World News offer a twitter feed of their latest headlines. I sometimes browse the list to see whats going on in the world and to reaffirm my opinion that we&#8217;re [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=922&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Earlier today I was catching up on some tidbits of world news from various sources when I stumbled across something that caught my eye. BBC World News offer a <a title="BBC_News_World" href="http://twitter.com/BBC_News_World" target="_blank">twitter feed</a> of their latest headlines. I sometimes browse the list to see whats going on in the world and to reaffirm my opinion that we&#8217;re all doomed. Today however a specific article in the list caught my eye.</p>
<blockquote>
<h2 style="text-align:center;"><span style="color:#800000;">&#8220;It&#8217;s Time To Legalize Cannabis.&#8221;</span></h2>
</blockquote>
<p>This snippet of news, and the associated link didn&#8217;t really fit with the other news. For starters the capitalisation and use of the American spelling of legalize (legalise). There was also the fact that a majority of other news snippets started off with BBC Business News, whereas this didn&#8217;t. By using Twitters<a href="http://search.twitter.com" target="_blank"> search function</a> I could also see that the exact same tweet had been sent out on a regular basis for at least 10 days (possibly longer). The last thing that made me think this wasn&#8217;t really a tweet from BBC_News_World was the from label under the tweet</p>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/10/bbc_news.png"><img class="size-medium wp-image-924 aligncenter" style="margin-top:5px;margin-bottom:5px;" title="bbc_news" src="http://c22blog.files.wordpress.com/2009/10/bbc_news.png?w=300&#038;h=239" alt="bbc_news" width="300" height="239" /></a></p>
<p style="text-align:left;">Whereas all other tweets come from Twitterfeed, these are the only ones that report to come from twitRobot. Very strange.</p>
<p style="text-align:left;">By pulling up the link on a test system the bit.ly link took me to a Facebook cause with the same title at the tweets posted through the BBC Twitter feed &#8220;It&#8217;s Time To Legalize Cannabis&#8221;.</p>
<p style="text-align:center;"><a href="http://c22blog.files.wordpress.com/2009/10/clipboard05.png"><img class="size-medium wp-image-925 aligncenter" style="margin-top:5px;margin-bottom:5px;" title="Clipboard05" src="http://c22blog.files.wordpress.com/2009/10/clipboard05.png?w=300&#038;h=102" alt="Clipboard05" width="300" height="102" /></a></p>
<p style="text-align:left;">By pulling up the <a title="bit.ly Stats" href="http://bit.ly/info/3kGYt">bit.ly statistics</a> I could see that this link had been actively used since the end of September and had been clicked over 665 times. It also showed the original creator of the link as a user called therealtwitter. This appears to be the name used when Twitter automatically shortens a URL in a post for the user. So no tracking information there unfortunately.</p>
<p style="text-align:center;"><a href="http://c22blog.files.wordpress.com/2009/10/clipboard02.png"><img class="size-medium wp-image-927 aligncenter" style="margin-top:5px;margin-bottom:5px;" title="Clipboard02" src="http://c22blog.files.wordpress.com/2009/10/clipboard02.png?w=300&#038;h=212" alt="Clipboard02" width="300" height="212" /></a></p>
<p style="text-align:left;">More detailed information can be found on the bit.ly info page for this link. Including breakdown of clicks by country and clicks by referrer. By looking at the referrer stats it&#8217;s evident that this bit.ly link is also being sent out through email and IM.</p>
<p style="text-align:left;">Although the Facebook cause at the end of the link appears benign at first appearance, it certainly warrants further investigation into why this link is spreading through the BBC Twitter feed (possibly without their knowledge). This cause could be something as simple as a person trying to drum up members for their cause. Then again it could just as easily be a phishing site designed to steal logon credentials, or perform attacks against the users browser. Further work is needed to see exactly whats behind this.</p>
<p style="text-align:left;">If I receive response regarding this I&#8217;ll certainly post a followup. Until then, watch out just incase.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/922/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/922/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/922/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/922/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/922/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/922/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/922/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/922/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/922/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/922/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=922&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/10/16/strange-twitterings-from-the-bbc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/bbc_news.png?w=300" medium="image">
			<media:title type="html">bbc_news</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/clipboard05.png?w=300" medium="image">
			<media:title type="html">Clipboard05</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/clipboard02.png?w=300" medium="image">
			<media:title type="html">Clipboard02</media:title>
		</media:content>
	</item>
		<item>
		<title>The secrets of scr.im</title>
		<link>http://c22blog.wordpress.com/2009/10/07/the-secrets-of-scr-im/</link>
		<comments>http://c22blog.wordpress.com/2009/10/07/the-secrets-of-scr-im/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 21:31:59 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[CAPTCHA]]></category>
		<category><![CDATA[flaws]]></category>
		<category><![CDATA[web app]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=894</guid>
		<description><![CDATA[A few days back I was alerted to a new website that was offering a new way to hide your email address online. It sounded interesting so I headed over to the scr.im website and had a quick poke around. As you can guess, I&#8217;m a bit suspicious of these kind of services and web [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=894&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>A few days back I was alerted to a new website that was offering a new way to hide your email address online. It sounded interesting so I headed over to the <a href="http://scr.im" target="_blank">scr.im</a> website and had a quick poke around. As you can guess, I&#8217;m a bit suspicious of these kind of services and web application security is what I do (at least recently). So there were a few things that really jumped out at me straight off in reference to the sites use of CAPTCHA.</p>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/10/scr-im.png?w=300"><img class="size-medium wp-image-895 aligncenter" style="margin-top:8px;margin-bottom:8px;" title="scr.im" src="http://c22blog.files.wordpress.com/2009/10/scr-im.png?w=336&#038;h=247" alt="scr.im" width="336" height="247" /></a>Now I&#8217;m pretty sure a big portion of people reading this are already saying WTF just by looking at the above screenshot. This is not the way to use CAPTCHA. For a visitor to the site this is nice and quick, however for a script this is just a matter of playing the odds. The correct CAPTCHA has to be one of the 9 possible links displayed, certainly much better odds than attempting to crack the CAPTCHA itself. If a link is selected and it&#8217;s incorrect, the CAPTCHA screen can be reloaded (with new CAPTCHA options of course) and you can try again. Sure for a human it&#8217;s tedious to do this, it took me 11 tries to get through by simply always selecting the first CAPTCHA option (top left corner, Y9VJJ in the above screenshot). However for a scripted attack, this is a no brainer and shouldn&#8217;t take more than a few seconds. The slowest part would be the page reload. There doesn&#8217;t seem to be any timeout, lockout or any other such protections to prevent this kind of attack. Still the page reload is the bottleneck here.</p>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/10/burp_scrim.png"><img class="alignleft size-medium wp-image-896" style="margin:8px;" title="burp_scrim" src="http://c22blog.files.wordpress.com/2009/10/burp_scrim.png?w=240&#038;h=139" alt="burp_scrim" width="240" height="139" /></a>The above solution was too messy for me, and I hate nothing more than having to click buttons constantly, it bores me. So how can we do the same thing, but work more effectively, with less overhead. By taking a look at the scrim.js JavaScript you can see how the CAPTCHA buttons translate directly to POST requests. Although the value of the CAPTCHA is obfuscated, the code is simple enough to understand if you use BURP Suite to capture and examine the requests and responses. The Burp screenshot (LEFT) shows the POST request that sends the CAPTCHA together with a token number and some other information. Initially I thought this token value was used as a replay prevention function, however by capturing all 9 possible POST requests from a simple scr.im page <em>(using Burp naturally)</em>, I found that you could send each request in sequence to the remote server until the correct CAPTCHA is found and the desired email address is returned.</p>
<p style="text-align:left;">As with most web applications the POST request isn&#8217;t strictly enforced on the server side. As such you can easily change this to a single GET request (e.g. http://scr.im/test?captcha=46UU8&amp;action=view&amp;token=e6f0006403ab0c714034f25bc571aa93&amp;ajax=y) which makes things a little easier when scripting a solution.</p>
<p style="text-align:center;">The screenshots below show the responses from the scr.im server (both negative and positive).</p>
<div id="attachment_897" class="wp-caption aligncenter" style="width: 310px"><a href="http://c22blog.files.wordpress.com/2009/10/scrim_neg.png"><img class="size-medium wp-image-897 " title="scrim_neg" src="http://c22blog.files.wordpress.com/2009/10/scrim_neg.png?w=300&#038;h=142" alt="scrim negative response" width="300" height="142" /></a><p class="wp-caption-text">scrim negative response</p></div>
<div id="attachment_899" class="wp-caption aligncenter" style="width: 310px"><a href="http://c22blog.files.wordpress.com/2009/10/scrim_pos1.png"><img class="size-medium wp-image-899 " title="scrim_pos" src="http://c22blog.files.wordpress.com/2009/10/scrim_pos1.png?w=300&#038;h=152" alt="scrim positive response" width="300" height="152" /></a><p class="wp-caption-text">scrim positive response</p></div>
<p style="text-align:left;">
<p style="text-align:left;">As most of the heavy work is done on the client-side using JavaScript <em>(obfuscation of the CAPTCHA value, etc..)</em>, I don&#8217;t think it would take much for a good scripter <em>(that rules me out most likely) </em>to script up something that could quite simply go through and harvest addresses from the site. Normally this wouldn&#8217;t surprise me much as spammers are harvesting emails all the time from various sources. However scr.im is placing itself as a way to <em>&#8220;&#8230; protect your email address before sharing it, so only real people will use it &#8230;&#8221;</em> That&#8217;s a problem, as most people will blindly think that the service <span style="text-decoration:underline;">must</span> be secure.</p>
<p style="text-align:left;">Don&#8217;t get me wrong here, the idea is sound, and I&#8217;d really like to use something like this myself under certain circumstances <em>(not for my primary accounts, but for some things certainly)</em>. So what can be done to fix things up .:</p>
<ul>
<li>Add protection to prevent multiple options from being selected from the same CAPTCHA options <em>(one-time token)</em> *
<ul>
<li>Resolves: The possibility to select <span style="text-decoration:underline;">ALL</span> 9 CAPTCHA options and scraping the responses</li>
<li>Issue: Doesn&#8217;t stop an attacker reloading and trying again</li>
</ul>
</li>
<li>Add protection to stop more than <em>X</em> number of requests per URL, per second/minute *
<ul>
<li>Resolves: Brute-Force style attacks, automated attacks <em>(to some extent)</em></li>
<li>Issue: Could cause DoS against peoples links</li>
</ul>
</li>
<li>If the wrong CAPTCHA is selected <em>X</em> times, revert to traditional CAPTCHA entry *
<ul>
<li>Resolves: Brute-Force style attacks, automated attacks<em> </em></li>
<li>Issues: Same issues as traditional CAPTCHA, breakable</li>
</ul>
</li>
</ul>
<p style="text-align:right;"><span style="color:#808080;">* Won&#8217;t prevent all possible attacks if implemented alone</span></p>
<p style="text-align:left;"><span style="color:#808080;"><span style="color:#000000;">By mixing and matching the above solutions the attack vectors could easily be reduced, but never truly removed completely. However with the use of the 3&#215;3 grid CAPTCHA there is always that 1 in 9 chance of the attacker choosing the correct CAPTCHA on the first try. Given these odds a single attacker could <em>(in theory)</em> harvest 11.11% of email addresses on the first attempt purely by guessing <em>(even with the above implemented restrictions)</em>. Depending on how/what protections are implemented, the attacker could then come back 8 more times <em>(within minutes, hours, days)</em> to scrape the remaining addresses. There will certainly be email addresses not scraped, but for a spammer, this isn&#8217;t a big issue. </span></span></p>
<p style="text-align:left;"><span style="color:#808080;"><span style="color:#000000;">With this in mind, the only workable solution is to alter the way CAPTCHA protection is implemented to go with the more traditional &#8220;typing&#8221; option. It&#8217;s tried and tested, and although it&#8217;s not perfect, it does resolve a number of the issues faced by scr.im currently.<br />
</span></span></p>
<p style="text-align:left;"><span style="color:#808080;"><span style="color:#000000;"><strong>Disclaimer</strong>: I&#8217;m not a developer, and I have the utmost respect for those who take time to put up services like this online. Hopefully people can learn from what I&#8217;ve explained here, so we don&#8217;t all make the same mistakes next time.</span><br />
</span></p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/894/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/894/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/894/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/894/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/894/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/894/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/894/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/894/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/894/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/894/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=894&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/10/07/the-secrets-of-scr-im/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/scr-im.png?w=300" medium="image">
			<media:title type="html">scr.im</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/burp_scrim.png?w=300" medium="image">
			<media:title type="html">burp_scrim</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/scrim_neg.png?w=300" medium="image">
			<media:title type="html">scrim_neg</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/10/scrim_pos1.png?w=300" medium="image">
			<media:title type="html">scrim_pos</media:title>
		</media:content>
	</item>
		<item>
		<title>SANS London 2009 Webcast Series</title>
		<link>http://c22blog.wordpress.com/2009/09/24/sans-london-2009/</link>
		<comments>http://c22blog.wordpress.com/2009/09/24/sans-london-2009/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 18:14:58 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Study]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS London]]></category>
		<category><![CDATA[webcast]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=880</guid>
		<description><![CDATA[About a weak back I posted about the upcoming SANS London 2009 event (28 November &#8211; 6 December). The guys behind the conference have put together a list of webcasts that they&#8217;ll be running to showcase the various courses on offer. You can find a list below of the upcoming events that are especially for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=880&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="https://www.sans.org/webcasts/"><img class="alignright" src="http://loglogic.com/images/logos/webcasts/sans-webcasts.gif" alt="" width="140" height="77" /></a>About a weak back I posted about the upcoming <a title="SANS London 2009" href="http://www.sans.org/london09/" target="_blank">SANS London 2009</a> event <em>(28 November &#8211; 6 December). </em>The guys behind the conference have put together a list of webcasts that they&#8217;ll be running to showcase the various courses on offer. You can find a list below of the upcoming events that are especially for the European security community. A full list of the webcasts in the series along with a breakdown of the topics covered can be found on the <a title="SANS Webcasts" href="http://www.sans.org/info/49044" target="_blank">SANS website</a>.</p>
<p>Upcoming Webcasts .:</p>
<ul>
<li>Friday, 25 September
<ul>
<li>Topic: SEC401: SANS Security Essentials Bootcamp Style</li>
<li>Instructor: Dr. Eric Cole</li>
<li>Time: 15:00 CET</li>
</ul>
</li>
</ul>
<ul>
<li>Tuesday, 29 September
<ul>
<li>Topic: DEV541: Secure Coding in Java/JEE: Developing Defensible Applications</li>
<li>Instructor: Sahba Kazerooni</li>
<li>Time: 15:00 CET</li>
</ul>
</li>
</ul>
<ul>
<li>Wednesday, 30 September
<ul>
<li>Topic: SEC508: Computer Forensics, Investigation &amp; Response</li>
<li>Instructor: Jess Garcia</li>
<li>Time: 15:00 CET</li>
</ul>
</li>
</ul>
<ul>
<li>Thursday, 01 October
<ul>
<li>Topic: SEC542: Web App Penetration Testing &amp; Ethical Hacking</li>
<li>Instructor: Raul Siles</li>
<li>Time: 15:00 CET</li>
</ul>
</li>
</ul>
<ul>
<li>Friday, 02 October
<ul>
<li>Topic: SEC566: 20 Critical Security Controls</li>
<li>Instructor: James Tarala</li>
<li>Time: 15:00 CET</li>
</ul>
</li>
</ul>
<ul>
<li>Wednesday, 07 October
<ul>
<li>Topic: What Course Should I Take at SANS London 2009 &amp; Question and Answer session</li>
<li>Instructor: Johannes Ulrich</li>
<li>Time:15:00 CET</li>
</ul>
</li>
</ul>
<p>Previous webcasts in the series .:</p>
<ul>
<li>SEC560: Network Penetration Testing &amp; Ethical Hacking
<ul>
<li>John Strand</li>
</ul>
</li>
<li>SEC709: Developing Exploits for Penetration Testers and Security Researchers
<ul>
<li>Stephen Sims</li>
</ul>
</li>
</ul>
<p>For those who didn&#8217;t manage to catch the live webcasts that have already taken place, the recording is now available from the <a title="Webcast Archive" href="http://www.sans.org/info/49049" target="_blank">webcast archives</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/880/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/880/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/880/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/880/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/880/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/880/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/880/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/880/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/880/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/880/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=880&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/09/24/sans-london-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://loglogic.com/images/logos/webcasts/sans-webcasts.gif" medium="image" />
	</item>
		<item>
		<title>[BruCON] The Belgian beer lovers guide to Cloud Security</title>
		<link>http://c22blog.wordpress.com/2009/09/19/brucon-the-belgian-beer-lovers-guide-to-cloud-security/</link>
		<comments>http://c22blog.wordpress.com/2009/09/19/brucon-the-belgian-beer-lovers-guide-to-cloud-security/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 16:55:34 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[brucon]]></category>
		<category><![CDATA[cloud]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=877</guid>
		<description><![CDATA[Craig Balding &#8211; The Belgian beer lovers guide to Cloud Security
High-level talk covering cloud security with the goal to get people thinking about whats possible.
The CFO view on cloud computing purely bottom line. The less things appear on the balance sheet the better for the company. This isn&#8217;t always better for security.
Speed of provisioning makes [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=877&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><em><img class="alignleft" src="http://www.rationalsurvivability.com/blog/wp-content/media/2009/04/jericho-cloudcube.jpg" alt="" width="205" height="148" />Craig Balding</em> &#8211; The Belgian beer lovers guide to Cloud Security</p>
<p>High-level talk covering cloud security with the goal to get people thinking about whats possible.</p>
<p>The CFO view on cloud computing purely bottom line. The less things appear on the balance sheet the better for the company. This isn&#8217;t always better for security.</p>
<p>Speed of provisioning makes it an easy sell to the CEO.</p>
<p>Not everyone is happy &#8211; IT Security people are cynical people. Same problems in a different guise. From a security standpoint though, we as security professionals need to know about it. The business wants the cloud, so we have to work with it.</p>
<p>Cloud is painting a vision that doesn&#8217;t yet exist. Marketing is out of sync with their engineering department. Easy to write it off, but it shouldn&#8217;t be that way.</p>
<p>Talking about the cloud is hard. There are so many different kinds. It&#8217;s like walking into a Belgian pub and asking  for a beer. Sure, but what kind of beer do you want ?</p>
<p>Cloud properties .:</p>
<ul>
<li>Abstraction of Resources</li>
<li>On Demand</li>
<li>Elastic</li>
<li>Scalable</li>
<li>API</li>
<li>as a Service (aaS)</li>
</ul>
<p>Virtualisation != Cloud != Virtualisation</p>
<p>Dynamic resources meet static security &#8211; The systems you have to secure as flexible, constantly growing and changing, so how does your security measures adapt to those issues.</p>
<p>Cloud != Outsourcing</p>
<p>You can visit an outsourcing company to check them out. Any large cloud company won&#8217;t be willing to show you around the data-center. Cloud is more of a black box solution, with an API interface.</p>
<p>Cloud Platforms are often stitched together open-source software with an API. These combinations and uses are all new. New doesn&#8217;t mean secure. Untested combinations are dangerous.</p>
<ul>
<li>Infrastructure as a service (i.e. Virtual servers)</li>
<li>Platform as a service (i.e. Google AppEngine,&#8230;)</li>
<li>Software as a service (i.e. Salesforce.com,&#8230;)</li>
</ul>
<p>Software as a service is no longer a dedicated machine or environment for your software. Shared platform amongst many companies.</p>
<p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011278fea80e28a4-500wi" target="_blank">Cloud Taxonomy and Ontology</a> ==&gt; More details can be found<a href="http://rationalsecurity.typepad.com/blog/2009/01/cloud-computing-taxonomy-ontology-please-review.html" target="_blank"> HERE </a><br />
<a href="http://www.rationalsurvivability.com/blog/wp-content/media/2009/04/jericho-cloudcube.jpg" target="_blank">Jericho Cloud Cube</a> ==&gt; More details can be found <a href="http://www.opengroup.org/jericho/cloud_cube_model_v1.0.pdf" target="_blank">HERE</a></p>
<p>Cloud can be public or private. Virtual private cloud solutions using VPNs to connect you to the cloud. The level of sharing here opens up attack vectors where moving from the public cloud to the private cloud could be possible. VPN driver vulnerabilities ?</p>
<p>Government clouds &#8212; Apps.gov offering cloud storage, software development, virtual machines for government use</p>
<p>Cloud specific security concerns .:</p>
<ul>
<li>What are they hiding in the basement &#8211; Where is your data stored ?</li>
<li>Uptime &#8211; Is 99.9% enough ?</li>
<li>Lock-in &#8211; Can you get your VMs out if you need to ? What format are they in ? Apps coded to a specific API ?</li>
<li>Multi Tenancy &#8211; Shared systems with mixed security. Shared Databases with mixed customer data</li>
<li>Change Control &#8211; What did they change and when ? Do Google have change logs ? Are they public ?</li>
<li>Visibility &#8211; What logs do you have ? Can you see if somebody is brute-forcing your account ?</li>
<li>Cloud Layers &#8211; Services layered on-top of services. Subcontractors. What risk level do these dependencies introduce ?</li>
<li>Identity &#8211; Multiple accounts. Problems in-house, worse on the internet. SSO for the cloud ? Using your AD to authenticate in the cloud ?</li>
<li>SLAs &#8211; Have you read them ? How often are they changed ? Can you negotiate better SLAs ?</li>
<li>Terms of Service &#8211; If they screw up you get service credit ? is that ok if you&#8217;re down a week or more ?</li>
<li>Legal Issues &#8211; (Search &amp; Seize) &#8211; What if the FBI takes the servers out of the datacenter ?</li>
<li>Auditor &#8211; They&#8217;ve only just learnt about virtualization, do they know what cloud is ?</li>
<li>Pay As You Go &#8211; Paying with a credit card. Where are your payment details stored ? Do they have anti-fraud systems ? Attackers driving up your CPU usage or bandwidth may cost you more. Can you set a limit?</li>
<li>Data Wiping &#8211; Can&#8217;t do it. You can delete them, but there&#8217;s no REALLYDELETETHIS API call.</li>
<li>Distributed Programming &#8211; Developers have to code to the API, are they experienced with distributed environments ? Race conditions.</li>
<li>Cloud APIs &#8211; Protected through SSL. Other options</li>
</ul>
<p>How can a tester (PCI, PenTester,..) verify your security. Will the systems be the same today as they are tomorrow. It&#8217;s like changing a tyre at 70mph.</p>
<p>The cloud is like the wild-wild-west right now.</p>
<p>More researchers are needed to rally shed light on these security issues.</p>
<p><a href="http://www.cloudsecurityalliance.org/" target="_blank">Cloud Security Aliance</a> &#8211; Shape the future of Cloud</p>
<p><a href="http://cloudsecurity.org/" target="_blank">Cloudsecurity.org</a> &#8211; Craig Baldings Blog</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/877/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/877/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/877/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/877/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/877/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/877/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/877/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/877/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/877/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/877/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c22blog.wordpress.com&blog=1599597&post=877&subd=c22blog&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://c22blog.wordpress.com/2009/09/19/brucon-the-belgian-beer-lovers-guide-to-cloud-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://www.rationalsurvivability.com/blog/wp-content/media/2009/04/jericho-cloudcube.jpg" medium="image" />
	</item>
	</channel>
</rss>