<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5874595782324596419</id><updated>2011-04-21T21:30:26.597-07:00</updated><title type='text'>arp_fl00d</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5874595782324596419.post-5074521799194222134</id><published>2008-10-15T11:43:00.000-07:00</published><updated>2008-10-15T11:45:49.500-07:00</updated><title type='text'>The Peacefire initiative</title><content type='html'>Sooo&lt;br /&gt;&lt;br /&gt;I've been selected by the founder of Peacefire to participate on a team of researchers to test out new and innovative ways to avoid those pesky web filtering proxies we are all afflicted with.  As I come across anything hot, I'll be sure to post here.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5874595782324596419-5074521799194222134?l=arpfl00d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/5074521799194222134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5874595782324596419&amp;postID=5074521799194222134' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/5074521799194222134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/5074521799194222134'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/2008/10/peacefire-initiative.html' title='The Peacefire initiative'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5874595782324596419.post-2209395319417532787</id><published>2008-10-15T11:24:00.000-07:00</published><updated>2008-10-15T11:39:21.095-07:00</updated><title type='text'>The REAL Layer 2 attack</title><content type='html'>Sooo..&lt;br /&gt;&lt;br /&gt;There was this talk at this year's DEFCON talking about attacks which can occur at Layer 2 of the OSI model.  This will without a doubt go down as probably the worst talk in the history of any Security Conference.  Not to really bust on the guys giving the talk as they appeared to know the content of there talk very well..the problem was just that; the content of there talk.&lt;br /&gt;&lt;br /&gt;These guys talked about different attacks against VLANs, which as cool as it is...is not a reality anymore!  Any network administrator worth a sack of poop would not have a network succeptible to any type of VLAN hopping attack.  The true threat in Layer 2 clearly lies within ARP.&lt;br /&gt;&lt;br /&gt;Now, I'm not saying that ARP poisoning is the be all end all...but what I'm saying is that in 90% of networks I look at, ARP poisoning can be accomplished with great ease and minimal detection. The fact of the matter is that nobody is implementing  static ARP entries for there gateway, and we know that it is rare for anyone to monitor internal traffic.   In fact on my most recent pentest I went back to the old school well and decided to poison the ARP tables within the management subnet I sat on.   Not only did it go unnoticed, but I managed to man in the middle a password hash for the domain admin acct. crossing the network.&lt;br /&gt;&lt;br /&gt;The scary thing about this is that even if they did detect the bogus ARP traffic i was spewing across my subnet and blocked my IP or even launched a forensic investigation against me, they would have no idea that I had the hash for the domain admin.  Rock a little Pass the Hash, and it's game over...they would never detect me!&lt;br /&gt;&lt;br /&gt;So, if you decide you wanna have a little old school fun, fire up Ettercap....grab a few beers...and reminisce about the good ol' days!!!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5874595782324596419-2209395319417532787?l=arpfl00d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/2209395319417532787/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5874595782324596419&amp;postID=2209395319417532787' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/2209395319417532787'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/2209395319417532787'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/2008/10/real-layer-2-attack.html' title='The REAL Layer 2 attack'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5874595782324596419.post-8943223771239685659</id><published>2008-09-29T16:30:00.000-07:00</published><updated>2008-09-29T16:31:09.358-07:00</updated><title type='text'>back to websense.....</title><content type='html'>Sooo&lt;br /&gt;&lt;br /&gt;I figured I'd revisit an old flame.  Here is some of Websense's greatest hits..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.kindergarten.org/"&gt;KinderGarten.org&lt;/a&gt; -- an organization funding free vaccinations for children in India. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/kindergarten-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.crnavarra.org/"&gt;The Navarra, Spain chapter of the Red Cross&lt;/a&gt; -- in Spanish. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/crnavarra-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.keepnacbeautiful.org/"&gt;Keep Nacogdoches Beautiful&lt;/a&gt; -- a Nacogdoches, Texas cleanup project affiliated with Keep America Beautiful. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/keepnacbeautiful-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt; &lt;a href="http://www.abiq.org/"&gt;Autism Behavioural Intervention Queensland&lt;/a&gt; -- an Australian organization promoting treatment of children suffering from autism. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/abiq-org-blocked-gambling.11-27-2001.html"&gt;Blocked as "Gambling"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt; &lt;a href="http://www.shoahproject.org/"&gt;The Shoah Project&lt;/a&gt; -- in German. A Holocaust remembrance page that includes criticism of various "revisionist" historians who deny the Holocaust. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/shoahproject-org-blocked-racism-hate.11-26-2001.html"&gt;Blocked as "Racism/Hate"&lt;/a&gt;, probably because the page contains the names of several Holocaust deniers, including David Irving, even though the site itself is &lt;i&gt;attacking&lt;/i&gt; Holocaust denial. &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.dove-wa.org/"&gt;Dignity of Victims Everywhere&lt;/a&gt; -- a crime victims' organization. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/dove-wa-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;, possibly because of the presence of some words such as "Rape" and "Incest" on the pages. &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.hisgloryministries.org/"&gt;His Glory Ministries&lt;/a&gt; -- a religious ministry organization. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/hisgloryministries-org-blocked-tasteless.11-28-2001.html"&gt;Blocked as "Tasteless"&lt;/a&gt;.  WebSENSE's &lt;a href="http://www.websense.com/products/about/database/categories.cfm"&gt;category list&lt;/a&gt; defines "tasteless" sites as sites that "offer offensive, grotesque, frightening, lurid, material with no redeeming value". &lt;/li&gt;&lt;li&gt; &lt;a href="http://www.azccg.org/"&gt;Arizona Council on Compulsive Gambling&lt;/a&gt; -- a site providing information treatment for compulsive gamblers. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/azccg-org-blocked-gambling.11-28-2001.html"&gt;Blocked as "Gambling"&lt;/a&gt;.  WebSENSE's &lt;a href="http://www.websense.com/products/about/database/categories.cfm"&gt;category list&lt;/a&gt; defines "gambling" sites as: "Sites that provide information about or promote gambling or that support online gambling. Risk of losing money possible." While the Council site does "provide information about" gambling, WebSENSE's definition was probably not intended to include this kind of Web site. &lt;/li&gt;&lt;li&gt;The &lt;a href="http://www.jfednepa.org/"&gt;Jewish Federation of Northeastern Pennsylvania&lt;/a&gt; -- a Jewish community site promoting local activism and community building. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/jfednepa-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;.  Formerly the Scranton Jewish Federation, located at &lt;a href="http://www.scrantonjewishfed.org/"&gt;http://www.scrantonjewishfed.org/&lt;/a&gt;, which is also &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/scrantonjewishfed-org-blocked-sex.11-26-2001.html"&gt;blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt; The &lt;a href="http://www.redletterproject.org/"&gt;Red Letter Project&lt;/a&gt; -- a "forum for Christians and non-Christians alike" to discuss religious issues. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/redletterproject-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt; The &lt;a href="http://www.theposterproject.org/"&gt;Poster Project&lt;/a&gt; -- an organization that makes posters promoting liberal political causes, including views on the death penalty and abortion. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/theposterproject-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt; The &lt;a href="http://www.prochoiceresource.org/"&gt;Pro-Choice Resource Center&lt;/a&gt; -- a site listing resources for pro-choice political activism. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/prochoiceresource-org-blocked-sex.11-26-2001.html"&gt;Blocked as "Sex"&lt;/a&gt;. &lt;/li&gt;&lt;li&gt; &lt;a href="http://www.disabilityguide.org/"&gt;DisabilityGuide.org&lt;/a&gt; -- an online information resource about disability issues, based in Washington, DC. &lt;a href="http://peacefire.org/censorware/WebSENSE/caps/disabilityguide-org-blocked-gambling.11-28-2001.html"&gt;Blocked as "Gambling"&lt;/a&gt;. &lt;/li&gt;&lt;/ul&gt;damn...these people are retarded... Internet censorship is something that has to go. If you are as against it as I am, then visit www.peacefire.org to see what you can do to help!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5874595782324596419-8943223771239685659?l=arpfl00d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/8943223771239685659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5874595782324596419&amp;postID=8943223771239685659' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/8943223771239685659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/8943223771239685659'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/2008/09/back-to-websense.html' title='back to websense.....'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5874595782324596419.post-5199459600702423029</id><published>2008-09-18T14:37:00.000-07:00</published><updated>2008-09-18T14:38:05.761-07:00</updated><title type='text'>the audacity of some people.....</title><content type='html'>&lt;!-- headline start --&gt;    &lt;table width="100%" border="0" cellpadding="0" cellspacing="0"&gt;     &lt;tbody&gt;&lt;tr&gt;      &lt;td colspan="2"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="15" /&gt;&lt;/td&gt;     &lt;/tr&gt;          &lt;tr&gt;      &lt;td style="font-size: 20px; font-weight: bold; color: rgb(51, 204, 0);" valign="top" width="99%"&gt;Hacker impersonated Palin, stole e-mail password&lt;/td&gt;      &lt;td valign="top" align="right"&gt;&lt;a href="http://www.breitbart.com/partner.php?source=ap"&gt;&lt;img src="http://img.breitbart.com/images/ap.gif" border="0" /&gt;&lt;/a&gt;&lt;/td&gt;     &lt;/tr&gt;    &lt;/tbody&gt;&lt;/table&gt;    &lt;!-- headline end --&gt;               &lt;!-- date/author start --&gt;    &lt;table width="100%" border="0" cellpadding="0" cellspacing="0"&gt;     &lt;tbody&gt;&lt;tr&gt;      &lt;td colspan="2"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="3" /&gt;&lt;/td&gt;     &lt;/tr&gt;          &lt;tr&gt;      &lt;td valign="top" width="99%"&gt;&lt;span style="font-size: 12px; font-weight: bold; white-space: nowrap;"&gt;Sep 18 03:25 PM US/Eastern&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: 12px; font-style: italic; white-space: nowrap;"&gt;By TED BRIDIS&lt;br /&gt;Associated Press Writer&lt;/span&gt;&lt;/td&gt;                   &lt;td style="padding-top: 5px;" valign="bottom" align="right"&gt;       &lt;table style="border: 1px solid rgb(186, 186, 186); background-color: rgb(237, 240, 244);" width="1" border="0" cellpadding="0" cellspacing="0" height="33"&gt;                                           &lt;tbody&gt;&lt;tr&gt;&lt;td style="padding-left: 15px; padding-right: 15px; font-size: 9pt; white-space: nowrap;"&gt;&lt;a href="http://comments.breitbart.com/?id=D939AO101"&gt;36 Comments        &lt;/a&gt;&lt;/td&gt;                                    &lt;td background="http://www.breitbart.com/images/article/dots.gif"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="1" /&gt;&lt;/td&gt;                           &lt;td style="padding-left: 5px; padding-right: 5px;"&gt;&lt;a href="http://www.breitbart.com/email.php?link=%2Farticle.php%3Fid%3DD939AO101%26show_article%3D1&amp;amp;id=D939AO101"&gt;&lt;img src="http://www.breitbart.com/images/article/email.gif" width="25" border="0" height="18" /&gt;&lt;/a&gt;&lt;/td&gt;         &lt;td background="http://www.breitbart.com/images/article/dots.gif"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="1" /&gt;&lt;/td&gt;         &lt;td style="padding-left: 5px; padding-right: 5px;"&gt;&lt;a href="http://www.breitbart.com/print.php?id=D939AO101&amp;amp;show_article=1" target="_blank"&gt;&lt;img src="http://www.breitbart.com/images/article/print.gif" width="28" border="0" height="28" /&gt;&lt;/a&gt;&lt;/td&gt;         &lt;td background="http://www.breitbart.com/images/article/dots.gif"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="1" /&gt;&lt;/td&gt;         &lt;td style="padding-left: 5px; padding-right: 5px;"&gt;&lt;script type="text/javascript"&gt;         digg_url = 'http://www.breitbart.com/article.php?id=D939AO101&amp;show_article=1';         digg_title = 'Hacker+impersonated+Palin%2C+stole+e-mail+password';         digg_bodytext = 'WASHINGTON+%28AP%29+-+Details+emerged+Thursday+behind+the+break-in+of+Republican+vice+presidential+candidate+Sarah+Palin%27s+e-mail+account%2C+including+a+first-hand+account+suggesting+it+was+vulnerable+because+a+hacker+was+able+to+impersonate+her+online+to+obtain+her+password.+';         digg_media = 'news';         digg_topic = 'world_news';         digg_bgcolor = '#edf0f4';         digg_skin = 'compact';         digg_window = 'new';         &lt;/script&gt;&lt;script src="http://digg.com/tools/diggthis.js" type="text/javascript"&gt;&lt;/script&gt;&lt;iframe src="http://digg.com/tools/diggthis.php?u=http%3A//www.breitbart.com/article.php%3Fid%3DD939AO101%26show_article%3D1&amp;amp;t=Hacker+impersonated+Palin%252C+stole+e-mail+password&amp;amp;w=new&amp;amp;b=WASHINGTON+%2528AP%2529+-+Details+emerged+Thursday+behind+the+break-in+of+Republican+vice+presidential+candidate+Sarah+Palin%2527s+e-mail+account%252C+including+a+first-hand+account+suggesting+it+was+vulnerable+because+a+hacker+was+able+to+impersonate+her+online+to+obtain+her+password.+&amp;amp;m=news&amp;amp;c=world_news&amp;amp;k=%23edf0f4&amp;amp;s=compact" scrolling="no" width="120" frameborder="0" height="18"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;/td&gt;         &lt;td background="http://www.breitbart.com/images/article/dots.gif"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="1" /&gt;&lt;/td&gt;         &lt;td style="padding-left: 5px; padding-right: 5px;"&gt;&lt;script type="text/javascript"&gt;         farkItButton("Hacker impersonated Palin, stole e-mail password", "http://www.breitbart.com/article.php?id=D939AO101");         &lt;/script&gt;&lt;a href="http://cgi.fark.com/cgi/fark/farkit.pl?h=Hacker%20impersonated%20Palin,%20stole%20e-mail%20password&amp;amp;u=http://www.breitbart.com/article.php?id=D939AO101" target="_blank"&gt;&lt;img id="farkitButton" src="http://img.fark.net/pub/FarkItButton1_80x20.png" width="80" border="0" height="20" /&gt;&lt;/a&gt;&lt;/td&gt;                                  &lt;/tr&gt;       &lt;/tbody&gt;&lt;/table&gt;          &lt;/td&gt;     &lt;/tr&gt;          &lt;tr&gt;      &lt;td colspan="2"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="1" height="30" /&gt;&lt;/td&gt;     &lt;/tr&gt;    &lt;/tbody&gt;&lt;/table&gt;    &lt;!-- date/author end --&gt;               &lt;!-- article start --&gt;                          &lt;table width="100%" border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td rowspan="6" style="font-size: 10px;" valign="top" align="center"&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="25" height="10" /&gt;&lt;table style="border: 1px solid rgb(186, 186, 186); background-color: rgb(237, 240, 244);" width="168"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="font-size: 11px; padding-left: 6px;"&gt;&lt;br /&gt;&lt;a href="http://www.breitbart.com/image.php?id=app-0c4e0f3d-90ea-4b9b-bb4a-707d82a5dd82&amp;amp;show_article=1&amp;amp;article_id=D939AO101"&gt;&lt;img src="http://www.breitbart.com/images/2008/9/17/ap-p/0c4e0f3d-90ea-4b9b-bb4a-707d82a5dd82_preview.jpg" style="border: 1px solid rgb(186, 186, 186);" width="148" /&gt;&lt;br /&gt;&lt;br /&gt;Republican vice presidential candidate, Alaska Gov., Sarah Palin, answers...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.breitbart.com/image.php?id=app-3e36ff14-8524-4921-a27a-5b88800c743f&amp;amp;show_article=1&amp;amp;article_id=D939AO101"&gt;&lt;img src="http://www.breitbart.com/images/2008/9/17/ap-p/3e36ff14-8524-4921-a27a-5b88800c743f_preview.jpg" style="border: 1px solid rgb(186, 186, 186);" width="148" /&gt;&lt;br /&gt;&lt;br /&gt;This screenshot from Gawked.com shows an email account of Republican vice...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/td&gt;&lt;td&gt;&lt;img src="http://www.breitbart.com/images/common/dot.gif" width="25" height="1" /&gt;&lt;/td&gt;                &lt;td style="font-size: 14px; color: rgb(51, 204, 0);" valign="top" width="99%"&gt;&lt;span class="lingo_region"&gt;WASHINGTON (AP) - Details emerged Thursday behind the break-in of Republican vice presidential candidate Sarah Palin's e-mail account, including a first-hand account suggesting it was vulnerable because a hacker was able to impersonate her online to obtain her password. &lt;p&gt; The hacker guessed that Alaska's governor had met her husband in high school, and knew Palin's date of birth and home Zip code. Using those details, the hacker tricked Yahoo Inc.'s service into assigning a new password, "popcorn," for Palin's e-mail account, according to a chronology of the crime published on the Web site where the hacking was first revealed. &lt;/p&gt;&lt;p&gt; The FBI and &lt;a style="text-decoration: underline; cursor: pointer; display: inline; font-family: Arial,Helvetica,sans-serif; font-size: 14px; font-weight: 400; font-style: normal;" class="lingo_link" href="http://search.breitbart.com/q?s=Secret%20Service&amp;amp;sid=breitbart.com" rel="nofollow"&gt;Secret Service&lt;/a&gt; launched a formal investigation Wednesday. Yahoo declined to comment Thursday on details of the investigation, citing Palin's privacy and the sensitivity of such investigations. &lt;/p&gt;&lt;p&gt; The person who claimed responsibility for the break-in did not respond Thursday to an e-mail inquiry from The Associated Press. &lt;/p&gt;&lt;p&gt; "i am the lurker who did it, and i would like to tell the story," the person wrote in the account, which circulated on the Internet. What started as a prank was cut short because of panic over the possibility the FBI might investigate, the hacker wrote. &lt;/p&gt;&lt;p&gt; Investigators were waiting to speak with Gabriel Ramuglia of Athens, Ga., who operates an Internet anonymity service used by the hacker. Ramuglia told the AP on Thursday he was reviewing his own logs and promised to turn over any helpful information to authorities because the hacker violated rules against using the anonymity service for illegal activities. &lt;/p&gt;&lt;p&gt; "If you're doing something illegal and causing me issues by doing this, I'm willing to cooperate," Ramuglia said. "Obviously this is the most high profile situation I've dealt with." &lt;/p&gt;&lt;p&gt; The break-in of Palin's private account is especially significant because Palin sometimes uses non-government e-mail to conduct state business. Previously disclosed e-mails indicate her administration embraced Yahoo accounts as an alternative to government e-mail, which could possibly be released to the public under Alaska's Open Records Act. &lt;/p&gt;&lt;p&gt; At the time, critics of Palin's administration were poring over official e-mails they had obtained from the governor's office looking for evidence of improper political activity. &lt;/p&gt;&lt;p&gt; Details of this week's break-in, if authentic, were consistent with speculation by &lt;a style="text-decoration: underline; cursor: pointer; display: inline; font-family: Arial,Helvetica,sans-serif; font-size: 14px; font-weight: 400; font-style: normal;" class="lingo_link" href="http://search.breitbart.com/q?s=computer%20security%20experts&amp;amp;sid=breitbart.com" rel="nofollow"&gt;computer security experts&lt;/a&gt; who said Yahoo's "forgot-my-password" service almost certainly was exploited. The mechanism allows customers to retrieve or change their password if they can verify their identity by confirming personal information such as birthdate, zip code and the answer to a "secret question," such as a childhood pet's name or school mascot. &lt;/p&gt;&lt;p&gt; Palin's hacker was challenged to guess where Alaska's governor met her husband, Todd. Palin herself recounted in her speech at the &lt;a style="text-decoration: underline; cursor: pointer; display: inline; font-family: Arial,Helvetica,sans-serif; font-size: 14px; font-weight: 400; font-style: normal;" class="lingo_link" href="http://search.breitbart.com/q?s=Republican%20National%20Convention&amp;amp;sid=breitbart.com" rel="nofollow"&gt;Republican National Convention&lt;/a&gt; that the pair began dating two decades ago in high school in Wasilla, a town near Anchorage. &lt;/p&gt;&lt;p&gt; "I found out later though (sic) more research that they met at high school, so I did variations of that, high, high school, eventually hit on 'Wasilla high'," the person wrote. &lt;/p&gt;&lt;p&gt; The McCain campaign issued a statement describing the hacking as an invasion of Palin's privacy. &lt;/p&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5874595782324596419-5199459600702423029?l=arpfl00d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/5199459600702423029/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5874595782324596419&amp;postID=5199459600702423029' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/5199459600702423029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/5199459600702423029'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/2008/09/audacity-of-some-people.html' title='the audacity of some people.....'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5874595782324596419.post-6001940909311581735</id><published>2008-09-17T07:10:00.000-07:00</published><updated>2008-09-17T07:18:29.135-07:00</updated><title type='text'>Helpdesks can be so helpful!!!!!!</title><content type='html'>So.... I recently did a Social Engineering project for a major US financial institution.   The goal was to try and get someone at the helpdesk to reset a users password.  This helpdesk was in Ft. Wayne Indiana.   I found the user name through some google searches on the company and had previously called another one of there helpdesks where they generously gave me the format of user ids.....    Here is a play by play of how this went down....&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD -   Helpdesk, Charlie speaking&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - Hey Charlie, I think I'm having a problem with my passwd&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - What is the problem?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - I just got back from a break and when I tried to unlock my computer it said the password was no good&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - alright, that happens from time to time..What's your user id ?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - v3pXXX&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - John Doe?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - yeah, that's me.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - like I said, this happens sometimes, the only way to fix this is to reboot your computer and start over&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - alright, so just hit the power button&lt;/span&gt;?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - yeah, you will have to since you can't log back in&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - alright..hold on i guess this will take a minute&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - alright, I'll stay on the phone with you to make sure you get in alright....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;(Pause for 10-15 secs)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - so did you watch the hall of fame game last night?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - Yeah, I watched a little bit, but it's hard to get excited about preseason football.. You a colts fan?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - of course!!!!!!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - Oh, I'm a cowboys fan&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - the cowboys should be very good this year now that they fixed there secondary, I think they'll probably win there division&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - yeah, if they can get past the Giants&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - alright, I'm back.... nope just tried to login, still says my password is no good.... I know I'm typing the right password!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - are you sure the caps lock is not on?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - oh, let me try it again... (put phone close to keyboard so he could hear me hitting keys )    nope still didn't work....&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - alright, looks like we are gonna have to reset your password...What's your employee number?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - 529406&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD -  529406???  should be a 5 digit number&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - Oh sorry....11865&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - no, that's not what I have on file with you...it should begin with a 2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - no, it's definitely 11865&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - is that the number you log on to ??????? system with?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - yeah&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - well we can go ahead and reset your password..  Hopefully there will not be a problem with ???  system&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD- What's your current password?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - aren't we not supposed to give out our passwords to anyone?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - it's alright, you can give it to us, sometimes we can login as you without having to reset your password&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - Oh, I didn't know that, I remember going to some training and they said not to give your password to anyone...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - yeah, that's right, tell you what, I can just reset your password, and it'll force you to change it..  try Summer08&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - (phone next to keyboard again) alright, cool... it worked, now its asking me to change my password...thanks alot!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;HD - Your'e welcome....have a good day&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;me - thanks...you too!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5874595782324596419-6001940909311581735?l=arpfl00d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/6001940909311581735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5874595782324596419&amp;postID=6001940909311581735' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/6001940909311581735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/6001940909311581735'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/2008/09/helpdesks-can-be-so-helpful.html' title='Helpdesks can be so helpful!!!!!!'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5874595782324596419.post-9007816572973845541</id><published>2008-09-17T06:23:00.000-07:00</published><updated>2008-09-17T07:06:14.723-07:00</updated><title type='text'>Websense????  more like NO sense</title><content type='html'>So....Who are all of the content monitoring companies getting there blacklists from???  Take Websense for example.....  I as a penetration tester am not allowed to go to insecure.org while I'm at work because it is classified as "Hacking;Computers/Internet".  This is inherently wrong on multiple levels....&lt;br /&gt;&lt;br /&gt;First off... why would anyone not be able to go anywhere because it is labeled Computers / Internet.  I guess in my profession it is only acceptable to visit sites pertaining to food recipes.&lt;br /&gt;&lt;br /&gt;Second.....Insecure.org is not a "Hacking" website.  It's not like I'm visiting the webpage for the Canadian Mafia.  Insecure.org is a website for security professionals to download the award winning NMAP scanner which is a tool EVERY security professional should know like the back of there hand.&lt;br /&gt;&lt;br /&gt;Metasploit.com    NOPE&lt;br /&gt;Milw0rm.com  NOPE&lt;br /&gt;Packetstorm.org  NOPE&lt;br /&gt;&lt;br /&gt;Not only does Websense deny visits to insecure.org but it also will prohibit you from visiting sectools.org&lt;br /&gt;&lt;br /&gt;ARE YOU KIDDING ME???  websense in there infinite wisdom declares that a security professional should not have the ability to go view or download the top 100 security tools?  I would definitely say that a computer security professional going to sectools.org is probably going to get a tool for use in there daily job function...&lt;br /&gt;&lt;br /&gt;That's enough ranting for now...  I could have sworn that we don't live in China.....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5874595782324596419-9007816572973845541?l=arpfl00d.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://arpfl00d.blogspot.com/feeds/9007816572973845541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5874595782324596419&amp;postID=9007816572973845541' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/9007816572973845541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5874595782324596419/posts/default/9007816572973845541'/><link rel='alternate' type='text/html' href='http://arpfl00d.blogspot.com/2008/09/websense-more-like-no-sense.html' title='Websense????  more like NO sense'/><author><name>DK</name><uri>http://www.blogger.com/profile/16110142218699046600</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://3.bp.blogspot.com/_0qpEgxf0-ik/SNEEErXhpUI/AAAAAAAAAAM/JNeAltoIg7Q/S220/avtar.gif'/></author><thr:total>2</thr:total></entry></feed>
