Re: HackFest Series: TrueCrypt is Now Detectable

2009-04-30 Thread Jim March
In the US you generally don't need to hide encryption. The 5th Amendment usually protects any key stashed in your head. There's been an exception so far in a case where a guy allowed police browsing, they found kiddie porn or so they say, the system got shut off, and he wouldn't let them back in

Re: HackFest Series: TrueCrypt is Now Detectable

2009-04-30 Thread Charles Jones
Jim March wrote: In the US you generally don't need to hide encryption. The 5th Amendment usually protects any key stashed in your head. In these days of the Patriot Act and such, I'm not certain how well that would work. I'm sure they would at least charge you with obstruction of justice or

Re: HackFest Series: TrueCrypt is Now Detectable

2009-04-30 Thread Lisa Kachold
Ah, you guys? This is about the ability to determine if: 1) a header has been encrypted 2) a drive has an encrypted partition etc... It's a security issue. Not so much of a political one. That's OT, I believe? On 4/30/09, Jim March 1.jim.ma...@gmail.com wrote: In the US you generally don't

Re: HackFest Series: TrueCrypt is Now Detectable

2009-04-30 Thread Joshua Zeidner
you remember the whole 'Cypherpunks' episode right? one of the very early Wired magazines had an excellent article on them. -jmz On Thu, Apr 30, 2009 at 5:10 PM, Jim March 1.jim.ma...@gmail.com wrote: In the US you generally don't need to hide encryption.  The 5th Amendment usually

Re: HackFest Series: TrueCrypt is Now Detectable

2009-04-30 Thread Jim March
On Thu, Apr 30, 2009 at 5:49 PM, Lisa Kachold lisakach...@obnosis.com wrote: Ah, you guys? This is about the ability to determine if: 1) a header has been encrypted 2) a drive has an encrypted partition etc... It's a security issue. Not so much of a political one.  That's OT, I

HackFest Series: Kaspersky Linux Online Scanner

2009-04-30 Thread Lisa Kachold
http://www.kaspersky.com/virusscanner -- www.obnosis.com (503)754-4452 Contradictions do not exist. A. Rand --- PLUG-discuss mailing list - PLUG-discuss@lists.plug.phoenix.az.us To subscribe, unsubscribe, or to change your mail settings:

HackFest Series: Your Distro Might be Insecure

2009-04-14 Thread Lisa Kachold
Hope you enjoy this Linux Ragazine article that examines Ubuntu right out of the box. excerpt: During the last couple of years, Linux distributions have focused on improving the installation process of Linux in order to make the freely available operating system available to more people. It’s a

RE: HackFest: Linux Firewall ISO's or Debunking Cable/DSL Modem/RouterMarketing Myths - April 11, 2009

2009-04-05 Thread Lisa Kachold
Saturday (see that little blerb below) is the hackfest. I will try to get it going again for you all shut-ins! Obnosis | (503)754-4452 PLUG Linux Security Labs 2nd Saturday Each mo...@noon - 3PM From: bon...@cornerstonehome.com To: plug-discuss@lists.plug.phoenix.az.us Subject: RE

HackFest: Linux Firewall ISO's or Debunking Cable/DSL Modem/Router Marketing Myths - April 11, 2009

2009-04-04 Thread Lisa Kachold
April HackFest: Firewall ISO's or Debunking Cable/DSL Modem/Router Marketing Myths Join us at UAT.edu 2625 W. BASELINE RD., TEMPE, AZ 85283-1056 | Noon until 3PM (or whenever we all wander off) for a lab session centered around cable/DSL security and Linux box

RE: HackFest: Linux Firewall ISO's or Debunking Cable/DSL Modem/RouterMarketing Myths - April 11, 2009

2009-04-04 Thread Bryan O'Neal
Kachold Sent: Saturday, April 04, 2009 1:55 AM To: plug-discuss@lists.plug.phoenix.az.us Subject: HackFest: Linux Firewall ISO's or Debunking Cable/DSL Modem/RouterMarketing Myths - April 11, 2009 April HackFest: Firewall ISO's or Debunking Cable/DSL Modem/Router Marketing Myths Join us at UAT.edu

Re: HackFest Series: Firewall Building 101 April Lab 2nd Saturday Noon At UAT

2009-03-30 Thread mike havens
-- Date: Sun, 29 Mar 2009 02:30:53 -0400 Subject: Re: HackFest Series: Firewall Building 101 April Lab 2nd Saturday Noon At UAT From: bmi...@gmail.com To: plug-discuss@lists.plug.phoenix.az.us bh! I wish I could be there. On Sun, Mar 29, 2009 at 1:05 AM

Re: HackFest Series: Firewall Building 101 April Lab 2nd Saturday Noon At UAT

2009-03-29 Thread Alex Dean
I've run IPCop on several home networks and been pleased with the results. Lately I've been thinking about giving pfSense a try as well.Mainly, it looks like the web GUI in pfSense is a bit nicer to use, but learning a bit more BSD would be a plus. I was thinking of installing that

RE: HackFest Series: Firewall Building 101 April Lab 2nd Saturday Noon At UAT

2009-03-29 Thread Lisa Kachold
Maybe I can setup a nice Live session for this! Obnosis | (503)754-4452 PLUG Linux Security Labs 2nd Saturday Each mo...@noon - 3PM Date: Sun, 29 Mar 2009 02:30:53 -0400 Subject: Re: HackFest Series: Firewall Building 101 April Lab 2nd Saturday Noon At UAT From: bmi...@gmail.com

HackFest Series: Reporting Encroachments

2009-03-27 Thread Lisa Kachold
HackFest). iptables -A INPUT -s 66.114.50.78 -j DROP iptables -A INPUT -s 70.38.56.186 -j DROP iptables -A INPUT -s 146.137.96.7 -j DROP iptables -A INPUT -s 169.237.215.148 -j DROP iptables -A INPUT -s 74.125.95.101 -j DROP iptables -A INPUT -s 208.80.152.2 -j DROP iptables -A INPUT -s 65.55.172.87 -j

OT: --(is it?); [Spaf to Senate panel:] the US needs more hackfest people, please!

2009-03-26 Thread Mike Schwartz
via http://membernet.acm.org/archives.cfm?fo=2009-03-mar/mar-26-2009.html#Cybersecurity (the above mentions [and has a link to] the following:) *Experts See Shortfall in Cybersecurity

HackFest Series: Airodumpng

2009-03-20 Thread Lisa Kachold
Mike, You just admitted on an international board, that you are attempting to steal the private property key of a neighbor. Can't I tell you how clueless you appear? Your technical skills are starting to get fairly good, so we don't want you to be taken for a long timeout in jail? I,

Re: HackFest Series: Airodumpng

2009-03-20 Thread mike havens
sorry sometimes I just don't think! On 3/20/09, Lisa Kachold lisakach...@obnosis.com wrote: Mike, You just admitted on an international board, that you are attempting to steal the private property key of a neighbor. Can't I tell you how clueless you appear? Your technical skills are

RE: Zen and the Art of Knowledge or Hack your Head - was HackFest Series: Airodumpng

2009-03-20 Thread Lisa Kachold
: Fri, 20 Mar 2009 15:20:08 + Subject: Re: HackFest Series: Airodumpng From: bmi...@gmail.com To: plug-discuss@lists.plug.phoenix.az.us sorry sometimes I just don't think! On 3/20/09, Lisa Kachold lisakach...@obnosis.com wrote: Mike, You just admitted on an international board

Re: Zen and the Art of Knowledge or Hack your Head - was HackFest Series: Airodumpng

2009-03-20 Thread Eric Shubert
by Daniel J. Levitin Obnosis http://www.obnosis.com/ | (503)754-4452 PLUG http://http//plug.phoenix.az.us Linux Security Labs http://uat.edu/ 2nd Saturday Each mo...@noon - 3PM Date: Fri, 20 Mar 2009 15:20:08 + Subject: Re: HackFest Series: Airodumpng From: bmi

Re: Zen and the Art of Knowledge or Hack your Head - was HackFest Series: Airodumpng

2009-03-20 Thread Eric Shubert
Lisa Kachold wrote: This is called a Thread child, main thread can continue happily. Or has in all my years of UseNet trees. You and others simply reply to the first thread. I realize that it doesn't disturb the original thread at all. It's just that your post's subject disappears when

RE: Zen and the Art of Knowledge or Hack your Head - was HackFest Series: Airodumpng

2009-03-20 Thread Lisa Kachold
Thanks very much for your help Eric. Obnosis | (503)754-4452 PLUG Linux Security Labs 2nd Saturday Each mo...@noon - 3PM To: plug-discuss@lists.plug.phoenix.az.us From: e...@shubes.net Subject: Re: Zen and the Art of Knowledge or Hack your Head - was HackFest Series: Airodumpng

HackFest Series: Tcp Treason Uncloaked

2009-03-18 Thread Lisa Kachold
A common kernel level TCP whine seen in dmesg is: TCP: Treason uncloaked! Peer 38.108.180.106:14059/80 shrinks window 1536549741:1536551189. Repaired. Treason? Give me liberty or give me death? Treason? As far as I know my peers are all loyal? Shrinks window? This is not a Windows box?

Hackfest

2009-03-14 Thread der.hans
moin moin, we had a low turnout for the security hackfest and some miscommunication with security, so we're closing down early today. ASU's Installfest is next Saturday ( see email from Bryan ) and we have both Stammtische this week. ciao, der.hans -- # http://www.LuftHans.com/http

HackFest This Saturday at UAT Noon until 3ISH BUFFER OVERFLOWs In Linux

2009-03-12 Thread Lisa Kachold
Join us at UAT in room 128, as we discuss the wonderful world of buffer overflow exploits in Linux Security: Agenda: Noon until 12:30 Greet, boot and rummage for last minute items. 12:30 to 12:45 Download presentation materials, get machines going. 12:45 Start Presentation - Lisa Kachold

Re: HackFest This Saturday at UAT Noon until 3ISH BUFFER OVERFLOWs In Linux

2009-03-12 Thread Lyle Tuttle
At 05:21 PM 3/12/2009, you wrote: Join us at UAT in room 128, as we discuss the wonderful world of buffer overflow exploits in Linux Security: Agenda: Noon until 12:30 Greet, boot and rummage for last minute items. 12:30 to 12:45 Download presentation materials, get machines going. 12:45

HackFest Series: Socket Capable Browsers, Intercepting Proxy Servers Transparent Proxy Abuses

2009-03-10 Thread Lisa Kachold
Transparent proxies allow organizations to influence and monitor thetraffic from its users without their knowledge or participation.Transparent proxies act as intermediaries between a user and enddestination, and aren't generally apparent to users sitting behindthem. Enterprises, Hotels, and

HackFest Series: US-CERT Vulnerabilities for Week Ending March 2, 2009

2009-03-10 Thread Lisa Kachold
This Week's Security Issues In case you love OpenSolaris and laughing at all the new SSH issues: http://en.securitylab.ru/notification/369202.php And of course the best reading for exploits and honeypot trap fodder: http://www.us-cert.gov/cas/bulletins/SB09-068.html There are a great

HackFest Linux Security Series: Sumolinux DVL

2009-03-01 Thread Lisa Kachold
Linux Security Distros: http://www.securitydistro.com/ Sumolinux comes with various security distros that you can select at boot. Damn Vulnerable Linux like all good security distros comes disabled in various ways to control stupid use of the powerful tools, assuming of course that

HackFest Series: Kristy Westphal's Forensics Presentation Video

2009-02-28 Thread Lisa Kachold
We have been unable to get the presentation video past YouTube.com's processing to make available via private Drupal YouTube plugin at hackfest.obnosis.com. Kristy Westphal requested private (registration only) downloads for the materials. Therefore, we setup the video from Ecommerce Drupal

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-27 Thread Joshua Zeidner
for those of you who followed this thread, there is a recent development involving John Kyl (R-AZ). http://atlasshrugs2000.typepad.com/atlas_shrugs/2009/02/action-alert-senator-kyl-under-pressure-for-hosting-fitna.html have a good weekend, jmz On Mon, Feb 2, 2009 at 11:51 AM, Joshua

Re: Hackfest Linux Security Series: Security Distros

2009-02-27 Thread David Huerta
On Fri, Feb 27, 2009 at 4:51 PM, Lisa Kachold lisakach...@obnosis.com wrote: Backtrack 4 Beta is available, but so is Samarai (from InGuardians) and  more: BackTrack Chaox-NG Damn Vulnerable Linux ( DVL ) DEFT FCCU Frenzy grml Hakin9 Helix HeX KCPentrix Knoppix-NSM Network Security

HackFest Series: KeyLoggers or When Bad Kiddies Go Right

2009-02-25 Thread Lisa Kachold
How to challenge youth or keeping the kiddies off drugs. Keyloggers 101 Make your own C/C++ Keylogger: http://www.youtube.com/watch?v=o8I-VhtO-ssfeature=related Software Keyloggers: http://www.youtube.com/watch?v=Od5YJ6Cw4BMfeature=related Hardware Keyloggers:

Re: HackFest Series: KeyLoggers or When Bad Kiddies Go Right

2009-02-25 Thread Stephen
thats the last thing i want to have my son watching... he is smart enough to figure it out and lacking in common sense enough to know what to do with it still. On Wed, Feb 25, 2009 at 12:10 PM, Lisa Kachold lisakach...@obnosis.com wrote: How to challenge youth or keeping the kiddies off drugs.

RE: HackFest Series: KeyLoggers or When Bad Kiddies Go Right

2009-02-25 Thread Lisa Kachold
Just like drug use, eh? obnosis.com | wiki.obnosis.com| (503)754-4452 PLUG HACKFESTS 2nd Saturday Each mo...@noon - 3PM Date: Wed, 25 Feb 2009 15:41:46 -0700 Subject: Re: HackFest Series: KeyLoggers or When Bad Kiddies Go Right From: cryptwo...@gmail.com To: plug-discuss

Re: HackFest Series: KeyLoggers or When Bad Kiddies Go Right

2009-02-25 Thread Stephen
On Wed, Feb 25, 2009 at 4:05 PM, Lisa Kachold lisakach...@obnosis.com wrote: Just like drug use, eh? obnosis.com | wiki.obnosis.com| (503)754-4452 PLUG HACKFESTS 2nd Saturday Each mo...@noon - 3PM Date: Wed, 25 Feb 2009 15:41:46 -0700 Subject: Re: HackFest Series: KeyLoggers or When Bad

RE: HackFest Series: KeyLoggers or When Bad Kiddies Go Right

2009-02-25 Thread Lisa Kachold
Fact, According to psychologists the brain is incapable of equating consequences until 26 on average. obnosis.com | wiki.obnosis.com| (503)754-4452 PLUG HACKFESTS 2nd Saturday Each mo...@noon - 3PM Date: Wed, 25 Feb 2009 16:56:00 -0700 Subject: Re: HackFest Series: KeyLoggers or When

RE: HackFest Linux Security Series: XSS Gates or Security is EXPLOIT of TRUST

2009-02-20 Thread Lisa Kachold
I have built and have mail sent directly to my shell based pine or other client (another HackFest lab session will cover insecurities simply from being able to lay on a file via mail clients). Because I use MSN web mail, this MS based XSS exploit (like any other XSS javascript tools

Hackfest Linux Security Series: Patch Procrastinators Recovery Lab

2009-02-19 Thread Lisa Kachold
Last chance to test NTP before patching? NTP FingerPrinting Tool: http://www.securiteam.com/tools/6F00Q20EKY.html Next Generation NTP Reverse Shell: http://www.securebits.org/presentations/AR_NGRS_HITB_08.ppt obnosis.com | wiki.obnosis.com| (503)754-4452 PLUG HACKFESTS 2nd Saturday Each

HackFest Linux Security Series: XSS Gates

2009-02-19 Thread Lisa Kachold
Still itching to prove that Linux is more secure than Windows? XSS Shell - XSS Tunnel tool can be configured and tested in wine or OpenVZ, then unleashed against any Gates system victim (with written permission of course). Should you want to explore this extremely common security exploit,

OT HackFest Linux Secondurity Series: XSS Gates

2009-02-19 Thread Stephen
I find this amusing from a ms email service /snicker On 2/19/09, Lisa Kachold lisakach...@obnosis.com wrote: Still itching to prove that Linux is more secure than Windows? XSS Shell - XSS Tunnel tool can be configured and tested in wine or OpenVZ, then unleashed against any Gates system

Valentines HackFest Room 107 at UAT.edu PLANNING UPDATES

2009-02-16 Thread Lisa Kachold
running a DNS server and everyone can use it as a gateway; albeit SLOWLY - Laugh! Any such local HackFest DNS server or laptop wireless/wired proxy will certainly work for external browsing. However, we will coordinate with UAT's staff for solutions, as recommended. We went over new subjects

RE: HackFest Linux Security Series: Happy Valentines Day - How to Create a Linux Virus in Five Minutes Required Reading for the Enlightened MailLister

2009-02-14 Thread Lisa Kachold
Click on this attachment and save it to your desktop and we can test if this works?Just kidding! But if you are game, let me know and we can actually prove it with a lab?obnosis.com | wiki.obnosis.com| (503)754-4452PLUG HACKFESTS 2nd Saturday Each mo...@noon - 3PM Subject: Re: HackFest Linux

RE: HackFest Linux Security Series: Happy Valentines Day - How to Create a Linux Virus in Five Minutes Required Reading for the Enlightened MailLister

2009-02-14 Thread Lisa Kachold
: Re: HackFest Linux Security Series: Happy Valentines Day - How to Create a Linux Virus in Five Minutes Required Reading for the Enlightened MailLister From: cryptwo...@gmail.com To: plug-discuss@lists.plug.phoenix.az.us But how many ppl run with near root like access? Here not many

HackFest Today Room 107 at UAT.edu

2009-02-14 Thread Lisa Kachold
The shiny new UAT HackFest (InstallFest) lab room #107 includes bootable workstations, power and networking!Show up today (bring your LiveCD's) and help me check it out!Open Presentation format - Loosely called Patch Procrastinators Recovery Group!Noon - 3PM!obnosis.com | wiki.obnosis.com

Re: HackFest Today Room 107 at UAT.edu

2009-02-14 Thread mike havens
I sure wish I could be there! On Sat, Feb 14, 2009 at 12:12 PM, Lisa Kachold lisakach...@obnosis.comwrote: The shiny new UAT HackFest (InstallFest) lab room #107 includes bootable workstations, power and networking! Show up today (bring your LiveCD's) and help me check it out! Open

Re: HackFest Linux Security Series: Happy Valentines Day - How to Create a Linux Virus in Five Minutes Required Reading for the Enlightened MailLister

2009-02-13 Thread Jason
Umm, no offense, but this article is a ton of if-then-else type thinking. You can...no, really, you can...if... I love the line about Just because it can't affect the whole system doesn't mean it can't cause damage. That's the *whole point* of using *nix! A user cannot kill the *system*. That

Re: HackFest Linux Security Series: Happy Valentines Day - How to Create a Linux Virus in Five Minutes Required Reading for the Enlightened MailLister

2009-02-13 Thread Sharkscott
*That's the *whole point* of using *nix! A user cannot kill the *system*. That is the whole point* And that is something that they will just never never get. Scott On Fri, Feb 13, 2009 at 9:48 PM, Jason jas...@spatafore.net wrote: Umm, no offense, but this article is a ton of if-then-else

Re: HackFest Linux Security Series: Happy Valentines Day - How to Create a Linux Virus in Five Minutes Required Reading for the Enlightened MailLister

2009-02-13 Thread Stephen
But how many ppl run with near root like access? Here not many but my first nix box I did.. And isn't the partial point of hack fest to get ppl going? On 2/13/09, Sharkscott sharksc...@gmail.com wrote: *That's the *whole point* of using *nix! A user cannot kill the *system*. That is the

HackFest Series: January Presentation From Kristy Westphal from Arizona Department of Economic Security

2009-02-11 Thread Lisa Kachold
January Forensics Presentation Materials Get the KWestphal-Forensics-Video Presentation Materials. February Fest is Saturday, February 14th, 2009 at UAT RM 106 Noon-3PM. obnosis.com | wiki.obnosis.com| (503)754-4452 PLUG HACKFESTS 2nd Saturday Each mo...@noon - 3PM

RE: [PLUG-Devel] HackFest Series: EVERY Second SATURDAY @ UAT fromNoon until 3 PM

2009-02-10 Thread Lisa Kachold
PLUG Linux Security Hackfests are the 2nd Saturday at UAT.edu! Get the original Labs. February 14th will be a Presentation Fest with open question and answer format. Hackfest obnosis.com | wiki.obnosis.com| (503)754-4452 PLUG HACKFESTS 2nd Saturday Each mo...@noon - 3PM Date: Mon, 9 Feb

Hackfest Series: Drive Slagging

2009-02-06 Thread Lisa Kachold
Secure Data Destruction PLUG HACKFESTS - http://uat.edu Second Saturday Every mo...@noon - 3PM _ Windows Live™: Keep your life in sync.

HackFest Series: Video - Rooting via Mysql Injection or Nicht Gefunden

2009-02-04 Thread Lisa Kachold
http://www.milw0rm.org/video/watch.php?id=88 Milw0rm.org has a great deal of great information here: http://www.milw0rm.org/# http://www.Obnosis.com | (503)754-4452 http://wiki.obnosis.com | http://hackfest.obnosis.com | http://nuke.obnosis.com PLUG HACKFESTS - http://uat.edu Second Saturday

Hackfest Series: EtterCap - Plain Text Passwords - or What everyone might be doing at the Coffee Shop?

2009-02-03 Thread Lisa Kachold
How to listen on local networks (wireless/wired) for plain text passwords (Yahoo is the example): http://ettercap.sourceforge.net/forum/viewtopic.php?t=2833 Ettercap http://125.16.88.84/corpisit/ettercap2.htm Simple Examples: ettercap -Nzs victim.my.net ANY:23 ettercap -Nzs -F etter.filter

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Tameek Henderson
@lists.plug.phoenix.az.us Subject: Re: Hackfest Security: Dubai Hackinthebox Convention Anyone? --- PLUG-discuss mailing list - PLUG-discuss@lists.plug.phoenix.az.us To subscribe, unsubscribe, or to change your mail settings: http://lists.PLUG.phoenix.az.us/mailman

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Joshua Zeidner
On Mon, Feb 2, 2009 at 8:25 AM, Alex Dean a...@crackpot.org wrote: You are confusing Muslim with Arab. how is he confusing them? -jmz Most of the world's Muslims are not Arabs. You also need to be aware that not all Arab countries are identical. Dubai (UAE) has a far more open society

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Craig White
On Mon, 2009-02-02 at 08:25 -0700, Alex Dean wrote: Between this and all the 'why I hate Microsoft', 'my ISP is the worst', and 'the Googles are dumb' threads lately, this list is being a real drag to read lately. you neglected the thread about using Outlook w/ Gmail which also has

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Joshua Zeidner
On Mon, Feb 2, 2009 at 10:31 AM, Craig White craigwh...@azapple.com wrote: On Mon, 2009-02-02 at 08:25 -0700, Alex Dean wrote: Between this and all the 'why I hate Microsoft', 'my ISP is the worst', and 'the Googles are dumb' threads lately, this list is being a real drag to read lately.

Re: EMAIL LIST EXPANSION: Was Hackfest Security: Dubai HackintheboxConvention Anyone?

2009-02-02 Thread Tameek Henderson
: EMAIL LIST EXPANSION: Was Hackfest Security: Dubai Hackinthebox Convention Anyone? --- PLUG-discuss mailing list - PLUG-discuss@lists.plug.phoenix.az.us To subscribe, unsubscribe, or to change your mail settings: http://lists.PLUG.phoenix.az.us

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Alex Dean
You are confusing Muslim with Arab. Most of the world's Muslims are not Arabs. You also need to be aware that not all Arab countries are identical. Dubai (UAE) has a far more open society than Saudi Arabia, for instance. This thread started with information about a tech conference

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Alex Dean
On Feb 2, 2009, at 10:10 AM, Joshua Zeidner wrote: On Mon, Feb 2, 2009 at 8:25 AM, Alex Dean a...@crackpot.org wrote: You are confusing Muslim with Arab. how is he confusing them? -jmz The dress standards you cited are specific to UAE. There are many Muslim-majority countries, and

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Joshua Zeidner
On Mon, Feb 2, 2009 at 11:07 AM, Alex Dean a...@crackpot.org wrote: On Feb 2, 2009, at 10:10 AM, Joshua Zeidner wrote: On Mon, Feb 2, 2009 at 8:25 AM, Alex Dean a...@crackpot.org wrote: You are confusing Muslim with Arab. how is he confusing them? -jmz The dress standards you cited are

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Craig White
On Mon, 2009-02-02 at 12:44 -0500, bmike1 wrote: gmail is google I thiunk that makes it topical. isn't google open source? google is a corporation providing services to the computer user community and a sponsor of many things open source and reportedly runs their operation on open

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Joshua Zeidner
WARNING: Flame War Alert is at ORANGE. :) -jmz On Mon, Feb 2, 2009 at 12:05 PM, Craig White craigwh...@azapple.com wrote: On Mon, 2009-02-02 at 12:44 -0500, bmike1 wrote: gmail is google I thiunk that makes it topical. isn't google open source? google is a corporation providing

EMAIL LIST EXPANSION: Was Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-02 Thread Lisa Kachold
Yes, the new Drupal upgrade project for the list mail plugin includes expansion of the lists: PLUG-DISCUSS PLUG-DIALOGUE PLUG-HACKFEST http://www.Obnosis.com | (503)754-4452 http://l0calh0st.obnosis.com | http://wiki.obnosis.com | http://hackfest.obnosis.com | http://nuke.obnosis.com PLUG

Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Lisa Kachold
http://conference.hitb.org/hitbsecconf2009dubai/ Note that Microsoft is a Convention sponsor? Also note that HackintheBox is a first reporter for Microsoft security issues: http://www.hackinthebox.org/modules.php?op=modloadname=Newsfile=articlesid=29609mode=thread www.Obnosis.com |

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Joshua Zeidner
I wonder if women have special clothing requirements for this conference, like in many Arab countries. -jmz On Sun, Feb 1, 2009 at 12:58 PM, Lisa Kachold lisakach...@obnosis.com wrote: http://conference.hitb.org/hitbsecconf2009dubai/ Note that Microsoft is a Convention sponsor? Also

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Sharkscott
No, I think as long as your in pants and a shirt your good, I am just wondering how much plane tickets to Dubai would set me back... On Sun, Feb 1, 2009 at 1:04 PM, Joshua Zeidner jjzeid...@gmail.com wrote: I wonder if women have special clothing requirements for this conference, like in many

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Joshua Zeidner
this article says: Females should make an effort not to wear too figure hugging clothes and to cover up their flesh. http://www.grapeshisha.com/UAE-National-clothing.html -jmz On Sun, Feb 1, 2009 at 1:12 PM, Sharkscott sharksc...@gmail.com wrote: No, I think as long as your in pants and a

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Sharkscott
Nice, Heck of a night life they must have, oh wait, their MUSLIM! Guess I won't be going then...lol On Sun, Feb 1, 2009 at 1:17 PM, Joshua Zeidner jjzeid...@gmail.com wrote: this article says: Females should make an effort not to wear too figure hugging clothes and to cover up their

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Joshua Zeidner
you don't like Muslims? -jmz On Sun, Feb 1, 2009 at 2:24 PM, Sharkscott sharksc...@gmail.com wrote: Nice, Heck of a night life they must have, oh wait, their MUSLIM! Guess I won't be going then...lol On Sun, Feb 1, 2009 at 1:17 PM, Joshua Zeidner jjzeid...@gmail.com wrote: this

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Sharkscott
I'm saying that they way they treat women. I will not be going. My Mother was treated bad enough for being single in the mid 1970's midwest. God help me being the son of a single woman there.. On Sun, Feb 1, 2009 at 2:28 PM, Joshua Zeidner jjzeid...@gmail.com wrote: you don't like Muslims?

Re: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Joshua Zeidner
no doubt. I dont think Ill be going either. Last time I checked, I wasn't allowed to step foot in that country. -jmz On Sun, Feb 1, 2009 at 2:40 PM, Sharkscott sharksc...@gmail.com wrote: I'm saying that they way they treat women. I will not be going. My Mother was treated bad enough for

RE: Hackfest Security: Dubai Hackinthebox Convention Anyone?

2009-02-01 Thread Lisa Kachold
-4452 Date: Sun, 1 Feb 2009 15:08:49 -0700 Subject: Re: Hackfest Security: Dubai Hackinthebox Convention Anyone? From: jjzeid...@gmail.com To: plug-discuss@lists.plug.phoenix.az.us no doubt. I dont think Ill be going either. Last time I checked, I wasn't allowed to step foot

RE: HackFest Security: Patch Procrastinators Anonymous February 1...@uat

2009-02-01 Thread Lisa Kachold
Second Saturday Every mo...@noon - 3PM From: lisakach...@obnosis.com To: plug-de...@lists.plug.phoenix.az.us; plug-discuss@lists.plug.phoenix.az.us Subject: HackFest Security: Patch Procrastinators Anonymous February 1...@uat Date: Mon, 19 Jan 2009 04:30:42 + Catch the Patch

HackFest Series: DSL Router Exploits, Stack/Email/UPnP WRT

2009-01-31 Thread Lisa Kachold
Most home based routers can be easily exploited in a variety of ways. This is a list of a great many historic security exploits: http://attrition.org/security/advisory/ ...but it's probably going to work best to just google your router version. Even the open-wrt and dd-wrt 3rd party

RE: TrueCrypt lolwut / Zenwalk Curiousities - HackFest Presentation Invitation

2009-01-30 Thread Lisa Kachold
Please contact me if you would like to drag us all through disk notebook encryption benefits, basics and implementation tradeoffs for any distro as a HackFest presenter? www.Obnosis.com | http://wiki.obnosis.com | http://hackfest.obnosis.com | http://nuke.obnosis.com (503)754-4452 PLUG

Re: TrueCrypt lolwut / Zenwalk Curiousities - HackFest Presentation Invitation

2009-01-30 Thread Tuna
Lisa Kachold wrote: Please contact me if you would like to drag us all through disk notebook encryption benefits, basics and implementation tradeoffs for any distro as a HackFest presenter? Was this directed at me? I really don't know much about either of those things

February 14th Valentines Day HackFest

2009-01-28 Thread Lisa Kachold
Catch the Patch Procrastinators Recovery Group PLUG February HackFest Various important security daemon patches have only recently been released including Bind9, OpenSSL, cups NTP for Ubuntu; Redhat5 Avahi (FC 10) and SquirrelMail. So we will demonstrate exploits available

HackFest Series: Imbedded Graphics Exploits

2009-01-25 Thread Lisa Kachold
DLL_Injection_In_Vista.tgz - Whitepaper discussing DLL injection on Windows Vista (32bit). Includes an executable for injecting a DLL in a process of your choice and the original source code is in the pdf. mediamonkey-overflow.txt - MediaMonkey version 3.0.6 local buffer overflow proof of

HackFest Series: Embedded Executable Scripts

2009-01-24 Thread Lisa Kachold
Current list of Executable Virus/Script that use browser, javascript PDF, or graphics: http://www.esecurityplanet.com/tags/index.php/88852 www.Obnosis.com | http://wiki.obnosis.com | http://hackfest.obnosis.com | http://nuke.obnosis.com (503)754-4452 PLUG HACKFESTS - http://uat.edu Second

RE: HackFest Series: Local Security Meetings

2009-01-19 Thread Lisa Kachold
://hackfest.obnosis.com (503)754-4452 PLUG HACKFESTS - http://uat.edu Second Saturday of Each Month Noon - 3PM Date: Mon, 19 Jan 2009 00:11:17 -0700 From: lthiels...@gmail.com To: plug-discuss@lists.plug.phoenix.az.us Subject: Re: HackFest Series: Local Security Meetings On Sun, Jan 18, 2009 at 9:15 AM, Lisa

HackFest Series: Local Security Meetings

2009-01-18 Thread Lisa Kachold
- TBD for 2009 http://www.owasp.org/index.php/Phoenix (Web Systems Browsers, Microsoft, Encryption, Wireless) - PLUG HackFest Labs - Second Saturday of Every Month at UAT.EDU Noon-3PM Lab formats (Linux based - with some overflow into Web Systems and cross platform

Re: HackFest Security: Patch Procrastinators Anonymous February 7...@uat

2009-01-18 Thread bmike1
from the November Hackfest and discuss ways to protect (arp, VPN/VLAN, Switches, SELINUX) from the inevitable pwnership in a production or users system. We will not discuss squirrelmail, since it's only a XSS issue (similar to 9 out of 10 running versions of Apache httpd). We will not discuss

Re: HackFest Security: Patch Procrastinators Anonymous February 7...@uat

2009-01-18 Thread Ryan Rix
://cybexin.blogspot.com/2009/01/introduction-to-netcat.html 3) Overview of BEef: http://www.bindshell.net/tools/beef We will also look at forensic image from the November Hackfest and discuss ways to protect (arp, VPN/VLAN, Switches, SELINUX) from the inevitable pwnership in a production or users

RE: HackFest Security: Patch Procrastinators Anonymous February 7...@uat

2009-01-18 Thread Lisa Kachold
Subject: Re: HackFest Security: Patch Procrastinators Anonymous February 7...@uat bind9 is the most prolific DNS server application. It attempts to fill DNS requests. On Sun, Jan 18, 2009 at 5:20 PM, bmike1 bmi...@gmail.com wrote: bind9 is a distribution? let's talk about it what

HackFest Security: Patch Procrastinators Anonymous February 1...@uat

2009-01-18 Thread Lisa Kachold
: http://www.bindshell.net/tools/beef We will also look at forensic image from the November Hackfest and discuss ways to protect (arp, VPN/VLAN, Switches, SELINUX) from the inevitable pwnership in a production or users system. We will not discuss squirrelmail, since it's only a XSS issue (similar

Re: HackFest Security: Patch Procrastinators Anonymous February 7...@uat

2009-01-18 Thread Dazed_75
Lisa, did you repost this for the 14th because you remembered the APCUG session on 2/7-8 and that you are working the installfest for it on Saturday? If you said so, I missed it. --- PLUG-discuss mailing list - PLUG-discuss@lists.plug.phoenix.az.us

Re: HackFest Series: Local Security Meetings

2009-01-18 Thread Dazed_75
On Sun, Jan 18, 2009 at 9:15 AM, Lisa Kachold lisakach...@obnosis.com wrote: snip PLUG HackFest Labs - Second Saturday of Every Month at UAT.EDU Noon-3PM Lab formats (Linux based - with some overflow into Web Systems and cross platform integration issues (SAMBA, LDAP) for Administrators

Re: HackFest Series: OpenSSL, MD5, CA security flaws

2009-01-17 Thread James Mcphee
I have NOT seen this alert flash across the internal APAR systems of a couple major services companies either. I've done my best to fix what's available to me, but that doesn't excuse the industry's lack of response to this problem. Maybe they're waiting on CNN to show some poor mompop shop

HackFest Series: Open Source and Security Links AtomSmasher.org

2009-01-17 Thread Lisa Kachold
Open Source Security Links· Open Sourcewww.Obnosis.com | http://wiki.obnosis.com | http://hackfest.obnosis.com (503)754-4452 PLUG HACKFESTS - http://uat.edu Second Saturday of Each Month Noon - 3PM _ Windows Live™ Hotmail®:

HackFest Series: OpenSSL, MD5, CA security flaws

2009-01-16 Thread Lisa Kachold
I just talked with two admins from a well known solutions provider who didn't know anything about these issues? Is anyone taking this seriously? From: lisakach...@obnosis.com To: plug-discuss@lists.plug.phoenix.az.us Subject: HackFest Series: OpenSSL, MD5, CA security flaws Date: Thu, 8 Jan

Re: HackFest Series: OpenSSL, MD5, CA security flaws

2009-01-16 Thread James Lee Bell
I know my company sure as heck did. When all our feeds got the news on the 30th, we were digging through all of our own certs ensuring we didn't have an issue there. Then pushing plans to the server guys to start looking at OpenSSL upgrades soon as they came out. All of the certs/listed CA's that

FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Lisa Kachold
...@obnosis.com To: kai...@gmail.com Subject: RE: Kristy Westphal's Forensic Presentation from January Hackfest Date: Mon, 12 Jan 2009 22:25:04 + Sorry that appears to strip the audio on my system. [r...@spider html]# /usr/local/bin/ffmpeg -i m2u00092.mpg video_kwestphal.aviFFmpeg version SVN

Re: {Disarmed} FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Craig White
On Tue, 2009-01-13 at 17:13 +, Lisa Kachold wrote: I am attempting to compress a raw dvd format mpg2 using ffmpeg. I built the source myself. My ffmpeg appears to strip the audio? Did I fail to compile the options correctly? Outside of Mac, what is the best tool for manipulating and

RE: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Bob Elzer
Westphal's Forensic Presentation from January Hackfest I am attempting to compress a raw dvd format mpg2 using ffmpeg. I built the source myself. My ffmpeg appears to strip the audio? Did I fail to compile the options correctly? Outside of Mac, what is the best tool for manipulating and exporting DVD's

Re: FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Joe Fleming
...@obnosis.com To: kai...@gmail.com Subject: RE: Kristy Westphal's Forensic Presentation from January Hackfest Date: Mon, 12 Jan 2009 22:25:04 + Sorry that appears to strip the audio on my system. [r...@spider html]# /usr/local/bin/ffmpeg -i m2u00092.mpg video_kwestphal.aviFFmpeg version

Re: {Disarmed} Re: FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Craig White
On Tue, 2009-01-13 at 11:41 -0700, Joe Fleming wrote: Mencoder has always worked really well for me, though I've only ever used it to transcode videos for playback on my n800, I've never started from DVD. A preliminary Google seems to indicate that you can go from DVD to DivX pretty easily and

Re: FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread der.hans
Am 13. Jan, 2009 schwätzte Lisa Kachold so: I am attempting to compress a raw dvd format mpg2 using ffmpeg. I built the source myself. My ffmpeg appears to strip the audio? Did I fail to compile the options correctly? Outside of Mac, what is the best tool for manipulating and exporting

Re: {Disarmed} FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Craig White
On Tue, 2009-01-13 at 17:13 +, Lisa Kachold wrote: I am attempting to compress a raw dvd format mpg2 using ffmpeg. I built the source myself. My ffmpeg appears to strip the audio? Did I fail to compile the options correctly? Outside of Mac, what is the best tool for manipulating and

Re: FW: Kristy Westphal's Forensic Presentation from January Hackfest

2009-01-13 Thread Sir Light
Lisa, Lisa Kachold lisakach...@obnosis.com wrote: I am attempting to compress a raw dvd format mpg2 using ffmpeg. I built the source myself. My ffmpeg appears to strip the audio? Might it becuse it's missing this -acodec codec in the command? If the option is not there, ffmpeg

<    1   2   3   4   >