<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Aegis</title>
	<atom:link href="http://www.securityaegis.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityaegis.com</link>
	<description>Life, Liberty, and the pursuit of root...</description>
	<lastBuildDate>Mon, 30 Jan 2012 20:38:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Mozilla CTF &amp;&amp; Not Dead, Just Busy</title>
		<link>http://www.securityaegis.com/mozilla-ctf-not-dead-just-busy/</link>
		<comments>http://www.securityaegis.com/mozilla-ctf-not-dead-just-busy/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 20:31:01 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[Auto]]></category>
		<category><![CDATA[chance]]></category>
		<category><![CDATA[CTF]]></category>
		<category><![CDATA[Dead]]></category>
		<category><![CDATA[Draft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[Web Application]]></category>
		<category><![CDATA[while]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/?p=2257</guid>
		<description><![CDATA[<p>So, it&#8217;s been a while since we&#8217;ve done anything on SA. Honestly my new gig at HP/Fortify (Director of Pentesting) has kept me busy. I did get a chance to play the Mozilla CTF though with a few other HP/Fortify pentesters. The competition was a worldwide CTF run by Mozilla. The Mozilla CTF (capture the [...]</p><p><a href="http://www.securityaegis.com/mozilla-ctf-not-dead-just-busy/">Mozilla CTF &#038;&#038; Not Dead, Just Busy</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/mozilla-ctf-not-dead-just-busy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LinkedIn Harvesting for OSINT (esearchy video)</title>
		<link>http://www.securityaegis.com/linkedin-harvesting-for-osint-esearchy-video/</link>
		<comments>http://www.securityaegis.com/linkedin-harvesting-for-osint-esearchy-video/#comments</comments>
		<pubDate>Thu, 08 Dec 2011 08:15:15 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[Auto]]></category>
		<category><![CDATA[Draft]]></category>
		<category><![CDATA[esearchy]]></category>
		<category><![CDATA[Harvesting]]></category>
		<category><![CDATA[LinkedIn]]></category>
		<category><![CDATA[LinkedIn Harvesting]]></category>
		<category><![CDATA[OSINT]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/?p=2251</guid>
		<description><![CDATA[<p></p><p><a href="http://www.securityaegis.com/linkedin-harvesting-for-osint-esearchy-video/">LinkedIn Harvesting for OSINT (esearchy video)</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/linkedin-harvesting-for-osint-esearchy-video/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>esearchy &#8211; my new favorite OSINT script</title>
		<link>http://www.securityaegis.com/esearchy-my-new-favorite-osint-script/</link>
		<comments>http://www.securityaegis.com/esearchy-my-new-favorite-osint-script/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 08:32:55 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[Auto]]></category>
		<category><![CDATA[doug lombardi]]></category>
		<category><![CDATA[Draft]]></category>
		<category><![CDATA[esearchy]]></category>
		<category><![CDATA[joe rohde]]></category>
		<category><![CDATA[kerry davis]]></category>
		<category><![CDATA[kircher michael]]></category>
		<category><![CDATA[mark behm]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[reason]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spear]]></category>
		<category><![CDATA[test]]></category>
		<category><![CDATA[Valve]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/?p=2234</guid>
		<description><![CDATA[<p>So you&#8217;re on a social engineering test&#8230; and you need to target some users for spear phishing. Previously we&#8217;ve used theHarvester and metasploit for this, but I&#8217;ve now fully switched over to esearchy by Matias P. Brutti. Install on BT5: sudo gem sources --add http://gems.github.com sudo gem install gemcutter sudo gem install esearchy Let&#8217;s Pick [...]</p><p><a href="http://www.securityaegis.com/esearchy-my-new-favorite-osint-script/">esearchy &#8211; my new favorite OSINT script</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/esearchy-my-new-favorite-osint-script/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Taking Dirbuster Output into Burp Suite</title>
		<link>http://www.securityaegis.com/taking-dirbuster-output-into-burp-suite/</link>
		<comments>http://www.securityaegis.com/taking-dirbuster-output-into-burp-suite/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 10:45:38 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[cat]]></category>
		<category><![CDATA[cat report]]></category>
		<category><![CDATA[dev]]></category>
		<category><![CDATA[error results]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[scan line]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[stdout]]></category>
		<category><![CDATA[Suite]]></category>
		<category><![CDATA[target]]></category>
		<category><![CDATA[web requests]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/taking-dirbuster-output-into-burp-suite/</guid>
		<description><![CDATA[<p>Seeing as DirBuster is my brute forcer of choice, and Burp is my interception proxy of choice, bridging the gap between these 2 tools and getting the output from DirBuster into Burp for further analysis is crucial. As you can see below, one bash command, about 140 characters long, does the trick. It takes the [...]</p><p><a href="http://www.securityaegis.com/taking-dirbuster-output-into-burp-suite/">Taking Dirbuster Output into Burp Suite</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/taking-dirbuster-output-into-burp-suite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Honey Potting for MS11-083</title>
		<link>http://www.securityaegis.com/honey-potting-for-ms11-083/</link>
		<comments>http://www.securityaegis.com/honey-potting-for-ms11-083/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 09:42:55 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[bash script]]></category>
		<category><![CDATA[could allow remote code execution]]></category>
		<category><![CDATA[Host]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[port]]></category>
		<category><![CDATA[portlist]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[self]]></category>
		<category><![CDATA[target system]]></category>
		<category><![CDATA[UDP]]></category>
		<category><![CDATA[udp traffic]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/honey-potting-for-ms11-083/</guid>
		<description><![CDATA[<p>MS11-083 has arrived and people are getting both excited and scared, it looks like its going to be the next MS08-067. Which if you remember, Conficker used to bend windows over and have a jol. Time for a honeypot? In anycase I took a moment and decided to write a script that would capture potential [...]</p><p><a href="http://www.securityaegis.com/honey-potting-for-ms11-083/">Honey Potting for MS11-083</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/honey-potting-for-ms11-083/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Web Application Hacking &amp; Testing Resources</title>
		<link>http://www.securityaegis.com/application-testing-resources/</link>
		<comments>http://www.securityaegis.com/application-testing-resources/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 04:31:19 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[application]]></category>
		<category><![CDATA[article]]></category>
		<category><![CDATA[Check]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[http://danielmiessler.com/projects/webappsec_testing_resources/#methodologies#]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[logic flaws]]></category>
		<category><![CDATA[logic test]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[marcus pinto]]></category>
		<category><![CDATA[page]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Testing]]></category>
		<category><![CDATA[testing methodologies]]></category>
		<category><![CDATA[Testing Resources]]></category>
		<category><![CDATA[User]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[Web Application]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/web-application-testing-resources/</guid>
		<description><![CDATA[<p>The quoting of this page has been removed, please visit: http://danielmiessler.com/projects/webappsec_testing_resources/#methodologies# for the full article.</p><p><a href="http://www.securityaegis.com/application-testing-resources/">Web Application Hacking &#038; Testing Resources</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/application-testing-resources/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Office 2007 Excel .xlb Metasploit Module (MS11-021)</title>
		<link>http://www.securityaegis.com/microsoft-office-2007-excel-xlb-metasploit-module-ms11-021/</link>
		<comments>http://www.securityaegis.com/microsoft-office-2007-excel-xlb-metasploit-module-ms11-021/#comments</comments>
		<pubDate>Sun, 06 Nov 2011 19:37:21 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[arbitrary code execution]]></category>
		<category><![CDATA[File]]></category>
		<category><![CDATA[file format converter]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[meterpreter]]></category>
		<category><![CDATA[microsoft excel viewer]]></category>
		<category><![CDATA[microsoft office xp]]></category>
		<category><![CDATA[office xp service pack]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[PoC]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Service]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/microsoft-office-2007-excel-xlb-metasploit-module-ms11-021/</guid>
		<description><![CDATA[<p>Timeline : Vulnerability discovered and reported to ZDI by Aniway Vulnerability reported to vendor by ZDI the 2010-10-18 Coordinated release of the vulnerability the 2011-04-12 Metasploit PoC provided the 2011-11-05 PoC provided by : Aniway abysssec sinn3r juan vazquez Reference(s) : CVE-2011-0105 MS11-021 ZDI-11-121 Affected version(s) : Microsoft Office XP Service Pack 3 Microsoft Office [...]</p><p><a href="http://www.securityaegis.com/microsoft-office-2007-excel-xlb-metasploit-module-ms11-021/">Microsoft Office 2007 Excel .xlb Metasploit Module (MS11-021)</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/microsoft-office-2007-excel-xlb-metasploit-module-ms11-021/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecTools.Org 2011 Top Network Security Tools</title>
		<link>http://www.securityaegis.com/sectools-org-top-network-security-tools/</link>
		<comments>http://www.securityaegis.com/sectools-org-top-network-security-tools/#comments</comments>
		<pubDate>Sat, 05 Nov 2011 02:32:13 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[decade]]></category>
		<category><![CDATA[favorite tools]]></category>
		<category><![CDATA[form]]></category>
		<category><![CDATA[network connector]]></category>
		<category><![CDATA[network security tools]]></category>
		<category><![CDATA[nmap security scanner]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[SecTools]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[suggestion form]]></category>
		<category><![CDATA[Top]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/sectools-org-top-network-security-tools/</guid>
		<description><![CDATA[<p>SecTools.Org: Top 125 Network Security Tools For more than a decade, the Nmap Project has been cataloguing the network security community&#8217;s favorite tools. In 2011 this site became much more dynamic, offering ratings, reviews, searching, sorting, and a new tool suggestion form. This site allows open source and commercial tools on any platform, except those [...]</p><p><a href="http://www.securityaegis.com/sectools-org-top-network-security-tools/">SecTools.Org 2011 Top Network Security Tools</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/sectools-org-top-network-security-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Easy Wireless Honey-Pots using Win7 and Metasploit</title>
		<link>http://www.securityaegis.com/easy-wireless-honey-pots-using-win7-and-metasploit/</link>
		<comments>http://www.securityaegis.com/easy-wireless-honey-pots-using-win7-and-metasploit/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 22:31:07 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[ap points]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[honey pots]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[meterpreter]]></category>
		<category><![CDATA[payload]]></category>
		<category><![CDATA[penetration testers]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[victim]]></category>
		<category><![CDATA[wireless access points]]></category>
		<category><![CDATA[wireless nics]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/easy-wireless-honey-pots-using-win7-and-metasploit/</guid>
		<description><![CDATA[<p>I found myself inspired by Vivek Ramachandran’s videos, I thought I would take the honor in creating the simple meterpreter script that basically does what you see in the third installation of the Swse Addendum videos. When I watched the third video I thought to myself, “This shouldn’t be too difficult to do”. From my [...]</p><p><a href="http://www.securityaegis.com/easy-wireless-honey-pots-using-win7-and-metasploit/">Easy Wireless Honey-Pots using Win7 and Metasploit</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/easy-wireless-honey-pots-using-win7-and-metasploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Framework Domain Token Scanner</title>
		<link>http://www.securityaegis.com/simple-framework-domain-token-scanner/</link>
		<comments>http://www.securityaegis.com/simple-framework-domain-token-scanner/#comments</comments>
		<pubDate>Fri, 04 Nov 2011 17:38:17 +0000</pubDate>
		<dc:creator>Jhaddix</dc:creator>
				<category><![CDATA[infosec]]></category>
		<category><![CDATA[Domain]]></category>
		<category><![CDATA[domain admin]]></category>
		<category><![CDATA[module]]></category>
		<category><![CDATA[open sessions]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[post]]></category>
		<category><![CDATA[rc file]]></category>
		<category><![CDATA[Scanner]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[single run]]></category>
		<category><![CDATA[tokens]]></category>
		<category><![CDATA[use]]></category>

		<guid isPermaLink="false">http://www.securityaegis.com/simple-framework-domain-token-scanner/</guid>
		<description><![CDATA[<p>Pretty straightforward little pattern here that will run a post module against all open sessions. ## This RC file assumes that you've got a bunch of open sessions, and now you want to go searching for a domain admin token. use post/windows/gather/enum_domain_tokens ## Now run against all open sessions framework.sessions.count.each do &#124;session&#124; run_single("set SESSION #{session.first}") [...]</p><p><a href="http://www.securityaegis.com/simple-framework-domain-token-scanner/">Simple Framework Domain Token Scanner</a> belongs to <a href="http://www.securityaegis.com">Security Aegis</a> </p>]]></description>
		<wfw:commentRss>http://www.securityaegis.com/simple-framework-domain-token-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching using disk: basic
Object Caching 1329/1528 objects using disk: basic

Served from: www.securityaegis.com @ 2012-02-04 07:18:46 -->
