<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Viewpoints &#187; Interesting</title>
	<atom:link href="http://advosys.ca/viewpoints/category/interesting-articles-on-other-sites/feed/" rel="self" type="application/rss+xml" />
	<link>http://advosys.ca/viewpoints</link>
	<description>Security, operating systems and the IT industry</description>
	<lastBuildDate>Wed, 30 Jun 2010 14:18:17 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Interesting links &#8211; June 30</title>
		<link>http://advosys.ca/viewpoints/2010/06/interesting-links-june-30/</link>
		<comments>http://advosys.ca/viewpoints/2010/06/interesting-links-june-30/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 14:18:16 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Interesting]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[disk]]></category>
		<category><![CDATA[endpoint+security]]></category>
		<category><![CDATA[evasion]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[flex]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[image]]></category>
		<category><![CDATA[interesting]]></category>
		<category><![CDATA[intrusion+prevention]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[tcpip]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[tracking]]></category>
		<category><![CDATA[vmdk]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=878</guid>
		<description><![CDATA[Potentially interesting links for June 30:

ZeuS Tracker &#8211; Tracks ZeuS Command&#38;Control servers (hosts) around the world and provides you a domain- and a IP-blocklist.
raw2vmdk &#124; Download raw2vmdk software for free at SourceForge.net &#8211; Mount raw disk images (e.g. dd) on VMware, VirtualBox or other VM platform supporting the VMDK disk format. Cross-platform Java.
Penetrating Intranets through [...]]]></description>
			<content:encoded><![CDATA[<p>Potentially interesting links for June 30:</p>
<ul>
<li><a href="https://zeustracker.abuse.ch/">ZeuS Tracker</a> &#8211; Tracks ZeuS Command&amp;Control servers (hosts) around the world and provides you a domain- and a IP-blocklist.</li>
<li><a href="http://sourceforge.net/projects/raw2vmdk/">raw2vmdk | Download raw2vmdk software for free at SourceForge.net</a> &#8211; Mount raw disk images (e.g. dd) on VMware, VirtualBox or other VM platform supporting the VMDK disk format. Cross-platform Java.</li>
<li><a href="http://www.gdssecurity.com/l/b/2010/03/17/penetrating-intranets-through-adobe-flex-applications/">Penetrating Intranets through Adobe Flex Applications</a> &#8211; How to exploit Adobe Flex applications that use BlazeDS to access internal networks and other hosts behind the firewall.</li>
<li><a href="http://www.packetstan.com/2010/06/recently-ive-been-on-campaign-to-make.html">IDS/IPS Evasion</a> &#8211; One way to fool most IPS into thinking a TCP session is closed (and thus no longer track it) when it&#8217;s actually still open on the host.</li>
</ul>
Copyright &copy; 2010 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2010/06/interesting-links-june-30/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting links &#8211; June 14</title>
		<link>http://advosys.ca/viewpoints/2010/06/interesting-links-june-14/</link>
		<comments>http://advosys.ca/viewpoints/2010/06/interesting-links-june-14/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 19:06:21 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Interesting]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[content+filtering]]></category>
		<category><![CDATA[interesting]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[obfuscation]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=874</guid>
		<description><![CDATA[Potentially interesting links for June 14:

LZH Compression vulnerability &#8211; &#8220;Most of anti-virus softwares can&#8217;t detect viruses embedded in LZH files with falsified header. And most archivers are capable to uncompress them, just as specified.&#8221;
Google IPv6 Implementors Conference &#8211; Slides from the event held June 10 and 11 2010.

Copyright &#169; 2010 Advosys Consulting Inc.

No related posts.]]></description>
			<content:encoded><![CDATA[<p>Potentially interesting links for June 14:</p>
<ul>
<li><a href="http://en.gigazine.net/index.php?/news/comments/20100607_lzh_end/">LZH Compression vulnerability</a> &#8211; &#8220;Most of anti-virus softwares can&#8217;t detect viruses embedded in LZH files with falsified header. And most archivers are capable to uncompress them, just as specified.&#8221;</li>
<li><a href="https://sites.google.com/site/ipv6implementors/2010/agenda">Google IPv6 Implementors Conference</a> &#8211; Slides from the event held June 10 and 11 2010.</li>
</ul>
Copyright &copy; 2010 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2010/06/interesting-links-june-14/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting links &#8211; June 3</title>
		<link>http://advosys.ca/viewpoints/2010/06/interesting-links-june-3-2/</link>
		<comments>http://advosys.ca/viewpoints/2010/06/interesting-links-june-3-2/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 14:17:06 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Interesting]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[guidelines]]></category>
		<category><![CDATA[interesting]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI+DSS]]></category>
		<category><![CDATA[reverse_engineering]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[unpacker]]></category>
		<category><![CDATA[vulnerability+assessment]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=862</guid>
		<description><![CDATA[Potentially interesting links for June 3:

AV bypass made stupid &#8211; Step-by-step example of how easy it can be to bypass antivirus detection. Demonstrates using a Windows resource editor to modify an executable so that (most) antivirus no longer detect it.
Payment Systems Group End-To-End Encryption Guidelines (pdf) &#8211; Guidelines on the application of encryption to payment card data used for retail financial transactions.
Nessus parsing tools &#8211; Parses Nessus NBE files [...]]]></description>
			<content:encoded><![CDATA[<p>Potentially interesting links for June 3:</p>
<ul>
<li><a title="AV bypass made stupid" href="http://www.room362.com/blog/2010/6/2/av-bypass-made-stupid.html">AV bypass made stupid</a> &#8211; Step-by-step example of how easy it can be to bypass antivirus detection. Demonstrates using a Windows resource editor to modify an executable so that (most) antivirus no longer detect it.</li>
<li><a href="http://spva.org/Files/E2E_EncryptionSecurityRequirements_WP10_May27.pdf">Payment Systems Group End-To-End Encryption Guidelines (pdf)</a> &#8211; Guidelines on the application of encryption to payment card data used for retail financial transactions.</li>
<li><a href="http://westcoasthackers.net/blog/category/tools/">Nessus parsing tools</a> &#8211; Parses Nessus NBE files into an sqlite database and provides scripts to generate various HTML reports. Windows only.</li>
<li><a href="http://code.google.com/p/fuu/">fuu unpacker</a> &#8211; Helps unpack, decompress and decrypt most of the programs packed, compressed or encrypted with well known utils like UPX, ASPack, FSG, ACProtect, etc. Windows only.</li>
<li><a href="http://malzilla.sourceforge.net/">Malzilla</a> &#8211; Useful for exploring malicious web sites, including deobfuscating javascript.</li>
</ul>
Copyright &copy; 2010 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2006/07/pgp-symmetric-encryption/' rel='bookmark' title='Permanent Link: Little known features: Symmetric encryption with PGP/GPG'>Little known features: Symmetric encryption with PGP/GPG</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2010/06/interesting-links-june-3-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting links &#8211; May 28</title>
		<link>http://advosys.ca/viewpoints/2010/06/interesting-links-may-28/</link>
		<comments>http://advosys.ca/viewpoints/2010/06/interesting-links-may-28/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 13:33:14 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Interesting]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[disk]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[interesting]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[papers]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[security+awareness]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=856</guid>
		<description><![CDATA[Potentially interesting links for May 28:

Khobe &#8211; Defeating antivirus via kernel driver hooks &#8211; Describes an attack exploiting kernel driver hooks in Microsoft Windows XP to intercept and alter communication between components and AV applications.
Rubberhose cryptographically deniable disk encryption &#8211; Claims to be more secure, portable, uses steganography / deniable cryptography, works with any file [...]]]></description>
			<content:encoded><![CDATA[<p>Potentially interesting links for May 28:</p>
<ul>
<li><a href="http://www.matousec.com/info/articles/khobe-8.0-earthquake-for-windows-desktop-security-software.php">Khobe &#8211; Defeating antivirus via kernel driver hooks</a> &#8211; Describes an attack exploiting kernel driver hooks in Microsoft Windows XP to intercept and alter communication between components and AV applications.</li>
<li><a href="http://iq.org/~proff/marutukku.org/">Rubberhose cryptographically deniable disk encryption</a> &#8211; Claims to be more secure, portable, uses steganography / deniable cryptography, works with any file system and has source freely available. Alpha quality. Linux only with NetBSD and FreeBSD support coming soon.</li>
<li><a href="http://www.theatlantic.com/magazine/archive/2010/06/the-enemy-within/8098/1/">The Enemy Within</a> &#8211; Long, detailed novice-level history of conficker worm and the implications. Good awareness material for the uninformed.</li>
</ul>
Copyright &copy; 2010 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2009/03/conficker-detection-and-containment/' rel='bookmark' title='Permanent Link: Conficker detection and containment tools'>Conficker detection and containment tools</a></li>
<li><a href='http://advosys.ca/viewpoints/2009/03/detecting-botnets-for-free/' rel='bookmark' title='Permanent Link: Detecting botnet infections for free'>Detecting botnet infections for free</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2010/06/interesting-links-may-28/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting links &#8211; May 5</title>
		<link>http://advosys.ca/viewpoints/2010/05/interesting-links-may-5/</link>
		<comments>http://advosys.ca/viewpoints/2010/05/interesting-links-may-5/#comments</comments>
		<pubDate>Thu, 06 May 2010 02:47:43 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Interesting]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[interesting]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[performance]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=852</guid>
		<description><![CDATA[Potentially interesting links for May 5:

Top Ten Tips for Auditors &#8211; Interesting advice from the SANS auditors blog.
Namebench &#8211; Discovers the fastest DNS servers for your location via direct performance measurements. Windows and Mac executables, Unix source.
A decade since the ILOVEYOU worm &#8211; Yes, it&#8217;s been ten years already.

Copyright &#169; 2010 Advosys Consulting Inc.

No related [...]]]></description>
			<content:encoded><![CDATA[<p>Potentially interesting links for May 5:</p>
<ul>
<li><a href="http://blogs.sans.org/it-audit/2010/04/30/top-ten-tips-auditors/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=top-ten-tips-auditors">Top Ten Tips for Auditors</a> &#8211; Interesting advice from the SANS auditors blog.</li>
<li><a href="http://code.google.com/p/namebench/">Namebench</a> &#8211; Discovers the fastest DNS servers for your location via direct performance measurements. Windows and Mac executables, Unix source.</li>
<li><a href="http://news.bbc.co.uk/2/hi/technology/10095957.stm">A decade since the ILOVEYOU worm</a> &#8211; Yes, it&#8217;s been ten years already.</li>
</ul>
Copyright &copy; 2010 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2010/05/interesting-links-may-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting links &#8211; April 26</title>
		<link>http://advosys.ca/viewpoints/2010/04/interesting-links-april-26/</link>
		<comments>http://advosys.ca/viewpoints/2010/04/interesting-links-april-26/#comments</comments>
		<pubDate>Mon, 26 Apr 2010 14:54:11 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Interesting]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[interesting]]></category>
		<category><![CDATA[metadata+recovery]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=848</guid>
		<description><![CDATA[Potentially interesting links for April 26:

Pentesting Adobe Flex Applications (pdf) &#8211; Nice deck describing Adobe Flex / AIR , their communication protocols (eg. Adobe message format AMF),  and how to assess and attack them. Also introduces Blazentoo exploit tool.
Manual Verification of SSL/TLS Certificate Trust Chains using Openssl &#8211; Validating chained SSL server certificates. Helpful [...]]]></description>
			<content:encoded><![CDATA[<p>Potentially interesting links for April 26:</p>
<ul>
<li><a href="http://www.gdssecurity.com/l/OWASP_NYNJMetro_Pentesting_Flex.pdf">Pentesting Adobe Flex Applications (pdf)</a> &#8211; Nice deck describing Adobe Flex / AIR , their communication protocols (eg. Adobe message format AMF),  and how to assess and attack them. Also introduces Blazentoo exploit tool.</li>
<li><a href="http://isc.sans.org/diary.html?storyid=8686">Manual Verification of SSL/TLS Certificate Trust Chains using Openssl</a> &#8211; Validating chained SSL server certificates. Helpful in determine whether an SSL error message is due to the browser not having an intermediary  cert, or due to a man-in-the-middle attack.</li>
<li><a href="http://www.visual-literacy.org/periodic_table/periodic_table.html">A Periodic Table of Visualization Methods</a> &#8211; Nifty reference of visualization of information, data, concepts, strategy, and metaphors (!).</li>
<li><a href="http://research.zscaler.com/2010/04/fun-with-n-gram-analysis.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+zscaler%2Fresearch+%28Zscaler+Research%29">Fun with N-gram Analysis</a> &#8211; Neat idea: identifying malicious Internet domain names using n-gram analysis.</li>
<li><a href="http://www.informatica64.com/DownloadFOCA/">FOCA</a> &#8211; Extracts metadata from common file types.</li>
</ul>
Copyright &copy; 2010 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2010/04/interesting-links-april-26/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
