<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>JW Network Consulting &#187; security tools</title>
	<atom:link href="http://www.jwnetworkconsulting.com/tag/security-tools/feed" rel="self" type="application/rss+xml" />
	<link>http://www.jwnetworkconsulting.com</link>
	<description>Watching the network so you don't have to.</description>
	<lastBuildDate>Thu, 22 Jul 2010 01:23:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Reconnoiter featured on Pauldotcom Podcast</title>
		<link>http://www.jwnetworkconsulting.com/security/reconnoiter-on-pauldotcom-podcast</link>
		<comments>http://www.jwnetworkconsulting.com/security/reconnoiter-on-pauldotcom-podcast#comments</comments>
		<pubDate>Wed, 14 Oct 2009 03:05:34 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[pauldotcom episode 170]]></category>
		<category><![CDATA[reconnoiter project]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[username generation]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=280</guid>
		<description><![CDATA[The last week was really busy while I prepared to do my presentation at the Utah Open Source Conference.  While I was engaged in this process I got a message from Larry Pesce of the Pauldotcom Podcast.  He had some updates to Reconnoiter and wanted to shoot them over to me.  He said that he [...]]]></description>
			<content:encoded><![CDATA[<p>The last week was really busy while I prepared to do my presentation at the Utah Open Source Conference.  While I was engaged in this process I got a message from Larry Pesce of the Pauldotcom Podcast.  He had some updates to Reconnoiter and wanted to shoot them over to me.  He said that he would be doing a tech segment on harvesting usernames via social media and was going to use the script as part of it.  I thought that was quite cool and figured that it would be one of the tools he mentioned.  I checked the <a href="http://pauldotcom.com/wiki/index.php/Episode170" target="_blank">show notes </a>after the recording and found that the entire segment was built around Reconnoiter!</p>
<p>One of the things that I really liked about the podcast was that the guys spent some time on how it could be better.  The requests I heard were the following:</p>
<ul>
<li>Configure what format it generates the user names into.  Perhaps you already know the format a client uses and need just want a dictionary.  Why have a bunch of user names that you know are bad.</li>
<li>Add some kind of GUI or website.  Good point.  Particularly for the Yahoo version of the script.  That API key is insanely long to put in as a command line argument.</li>
<li>Instead of spewing to STDOUT, save it to a file.  Larry has already provided the code for this and implemented it into both scripts.</li>
</ul>
<p>I&#8217;ve been kicking around a couple other ideas, but will need to get some time to implement them.  I&#8217;ve also got another script in mind that may or may not help deduce what the user name format for a company might be.  Depends on how the target has their email server configured.  No hacking, just taking note of what the email server tells me.</p>
<p>You can check out the episode at <a href="http://pauldotcom.com/2009/10/pauldotcom-security-weekly---e-29.html" target="_blank">pauldotcom.com</a>.  Thanks guys!</p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/pauldotcom+episode+170' rel='tag' target='_self'>pauldotcom episode 170</a>, <a class='technorati-link' href='http://technorati.com/tag/reconnoiter+project' rel='tag' target='_self'>reconnoiter project</a>, <a class='technorati-link' href='http://technorati.com/tag/security+tools' rel='tag' target='_self'>security tools</a>, <a class='technorati-link' href='http://technorati.com/tag/social+media' rel='tag' target='_self'>social media</a>, <a class='technorati-link' href='http://technorati.com/tag/username+generation' rel='tag' target='_self'>username generation</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/reconnoiter-on-pauldotcom-podcast/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UTOS 2009 Presentation Resources</title>
		<link>http://www.jwnetworkconsulting.com/security/utos_2009_resources</link>
		<comments>http://www.jwnetworkconsulting.com/security/utos_2009_resources#comments</comments>
		<pubDate>Thu, 08 Oct 2009 05:27:40 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security tools]]></category>
		<category><![CDATA[utos 2009]]></category>
		<category><![CDATA[utos presentation]]></category>

		<guid isPermaLink="false">http://www.jwnetworkconsulting.com/?p=270</guid>
		<description><![CDATA[On Friday October 9th at 12:00 PM I will be speaking at the Utah Open Source Conference on how to put together a kit of security tools using open source software.  I discuss a fictional company that we work at and some of the things that we can put in place to help secure the [...]]]></description>
			<content:encoded><![CDATA[<p>On Friday October 9th at 12:00 PM I will be speaking at the <a href="http://2009.utosc.com/presentation/90/" target="_blank">Utah Open Source Conference</a> on how to put together a kit of security tools using open source software.  I discuss a fictional company that we work at and some of the things that we can put in place to help secure the environment and handle some of the requests that get thrown our way.  The slides can be <a href="http://www.jwnetworkconsulting.com/downloads/OpenSourceToolkit.pdf" target="_self">downloaded here</a>.  I hope to have video of the presentation up later.</p>
<p>Here are the apps I cover and where you can got to get more information on them.  I&#8217;ve also got some community resources to go check out.</p>
<p><strong>Network Security and Monitoring</strong><br />
Nmap &#8211; <a href="http://nmap.org/" target="_blank">http://nmap.org/</a><br />
OpenVAS &#8211; <a href="http://openvas.org/" target="_blank">http://openvas.org/</a><br />
Snort  &#8211; <a href="http://www.snort.org/" target="_blank">http://www.snort.org/</a><br />
Emerging Threats &#8211; Snort rules &#8211; <a href="http://www.emergingthreats.net/" target="_blank">http://www.emergingthreats.net/</a><br />
BASE &#8211; <a href="http://base.secureideas.net/" target="_blank">http://base.secureideas.net/</a><br />
Sguil &#8211; <a href="http://sguil.sourceforge.net/" target="_blank">http://sguil.sourceforge.net/</a><br />
OSSEC &#8211; <a href="http://www.ossec.net/" target="_blank">http://www.ossec.net/</a><br />
Kismet &#8211; <a href="http://www.kismetwireless.net/" target="_blank">http://www.kismetwireless.net/</a></p>
<p><strong>Web Security</strong><br />
Nikto &#8211; <a href="http://www.cirt.net/nikto2" target="_blank">http://www.cirt.net/nikto2</a><br />
Log Analysis &#8211; <a href="http://www.loganalysis.org" target="_blank">http://www.loganalysis.org</a><br />
PHPIDS &#8211; <a href="http://php-ids.org/" target="_blank">http://php-ids.org/</a><br />
ModSecurity &#8211; <a href="http://www.modsecurity.org/" target="_blank">http://www.modsecurity.org/</a></p>
<p><strong>Penetration Testing</strong><br />
WebGoat &#8211; <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project</a><br />
Mutillidae &#8211; <a href="http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10" target="_blank">http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10</a><br />
Hacme Bank, Books, etc &#8211; <a href="http://www.foundstone.com/us/resources-free-tools.asp" target="_blank">http://www.foundstone.com/us/resources-free-tools.asp</a><br />
Paros &#8211; <a href="http://www.parosproxy.org/" target="_blank">http://www.parosproxy.org/</a><br />
WebScarab &#8211; <a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project" target="_blank">http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project</a><br />
Burp Suite &#8211; <a href="http://portswigger.net/suite/" target="_blank">http://portswigger.net/suite/</a><br />
Privoxy &#8211; <a href="http://www.privoxy.org/" target="_blank">http://www.privoxy.org/</a><br />
Tor &#8211; <a href="http://www.torproject.org/" target="_blank">http://www.torproject.org/</a><br />
w3af &#8211; <a href="http://w3af.sourceforge.net/" target="_blank">http://w3af.sourceforge.net/</a><br />
Beef &#8211; <a href="http://www.bindshell.net/tools/beef/" target="_blank">http://www.bindshell.net/tools/beef/</a><br />
Metasploit &#8211; <a href="http://metasploit.com/" target="_blank">http://metasploit.com/</a><br />
Backtrack -<a href="http://www.remote-exploit.org/backtrack.html" target="_blank"> http://www.remote-exploit.org/backtrack.html</a><br />
SamuraiWTF- <a href="http://samurai.inguardians.com/" target="_blank">http://samurai.inguardians.com/</a></p>
<p><strong>Forensics</strong><br />
Caine &#8211; <a href="http://www.caine-live.net/" target="_blank">http://www.caine-live.net/</a><br />
Deft Linux &#8211; <a href="http://www.deftlinux.net/" target="_blank">http://www.deftlinux.net/</a><br />
Helix &#8211; <a href="http://www.e-fense.com/" target="_blank">http://www.e-fense.com/</a></p>
<p><strong>Etc&#8230;</strong><br />
Top 100 Security Tools -<a href="http://sectools.org/" target="_blank"> http://sectools.org/</a></p>
<p><strong>Podcasts</strong><br />
Pauldotcom &#8211; <a href="http://pauldotcom.com/" target="_blank">http://pauldotcom.com/</a><br />
Exotic Liability &#8211; <a href="http://exoticliability.com/" target="_blank">http://exoticliability.com/</a><br />
Securabit &#8211; <a href="http://www.securabit.com/" target="_blank">http://www.securabit.com/</a><br />
CyberSpeak (forensics) &#8211; <a href="http://cyberspeak.libsyn.com/" target="_blank">http://cyberspeak.libsyn.com/</a></p>
<p><strong>Community Groups</strong><br />
ISSA &#8211; <a href="http://www.issa-utah.org/" target="_blank">http://www.issa-utah.org/</a><br />
OWASP &#8211; <a href="http://owasp.org/" target="_blank">http://owasp.org/</a><br />
Hack SLC hacker space &#8211; <a href="http://www.hackslc.com/forum/latestnews.php" target="_blank">http://www.hackslc.com/forum/latestnews.php</a><br />
Defcon &#8211; <a href="http://defcon.org/" target="_blank">http://defcon.org/</a></p>

<!-- start wp-tags-to-technorati 1.01 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/open+source' rel='tag' target='_self'>open source</a>, <a class='technorati-link' href='http://technorati.com/tag/security+tools' rel='tag' target='_self'>security tools</a>, <a class='technorati-link' href='http://technorati.com/tag/utos+2009' rel='tag' target='_self'>utos 2009</a>, <a class='technorati-link' href='http://technorati.com/tag/utos+presentation' rel='tag' target='_self'>utos presentation</a></p>

<!-- end wp-tags-to-technorati -->
]]></content:encoded>
			<wfw:commentRss>http://www.jwnetworkconsulting.com/security/utos_2009_resources/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
