<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>IRON::Guard Security</title>
	<atom:link href="http://igsec.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://igsec.wordpress.com</link>
	<description>Words, wisdom and otherwise</description>
	<lastBuildDate>Wed, 10 Dec 2008 08:35:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='igsec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>IRON::Guard Security</title>
		<link>http://igsec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://igsec.wordpress.com/osd.xml" title="IRON::Guard Security" />
	<atom:link rel='hub' href='http://igsec.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Back on Track</title>
		<link>http://igsec.wordpress.com/2008/05/04/back-on-track/</link>
		<comments>http://igsec.wordpress.com/2008/05/04/back-on-track/#comments</comments>
		<pubDate>Sun, 04 May 2008 21:56:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[Black Hat USA 2008]]></category>
		<category><![CDATA[DefCon 16]]></category>
		<category><![CDATA[Hackin9]]></category>
		<category><![CDATA[ISSA Journal]]></category>
		<category><![CDATA[Russ McRee]]></category>
		<category><![CDATA[security assessments]]></category>
		<category><![CDATA[The Last HOPE]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/05/04/back-on-track/</guid>
		<description><![CDATA[We have been very busy as of late. Security Assessments, ISSA Regional Conference (Great presentation by Russ McRee by the way!), writing various articles for Hackin9, 2 submissions for Black Hat USA 2008 and Decfon 16 and general business administration. If all goes well I should have my itinerary for The Last HOPE in NYC [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=44&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:verdana;">We have been very busy as of late.  Security Assessments, ISSA Regional Conference (Great presentation by Russ McRee by the way!), writing various articles for Hackin9, 2 submissions for Black Hat USA 2008 and Decfon 16 and general business administration.  If all goes well I should have my itinerary for The Last HOPE in NYC July 18th &#8211; 20th (Thanks MAF!).</p>
<p>If anyone is planning on attending The Last HOPE, Black Hat USA 2008 and/or DefCon 16 please contact me if you are interested in meeting up, having a drink, talking tech/business, etc.<br /></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/44/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/44/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=44&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/05/04/back-on-track/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>
	</item>
		<item>
		<title>Blackhat 2 Day Recap [Bettalatethaneva]</title>
		<link>http://igsec.wordpress.com/2008/02/27/blackhat-2-day-recap-bettalatethaneva/</link>
		<comments>http://igsec.wordpress.com/2008/02/27/blackhat-2-day-recap-bettalatethaneva/#comments</comments>
		<pubDate>Wed, 27 Feb 2008 14:05:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[Blackhat DC 2008]]></category>
		<category><![CDATA[Brian Wilson]]></category>
		<category><![CDATA[Burger King]]></category>
		<category><![CDATA[Chris Gates]]></category>
		<category><![CDATA[Paraben]]></category>
		<category><![CDATA[SAINT]]></category>
		<category><![CDATA[Starbucks]]></category>
		<category><![CDATA[Steve Adegbite]]></category>
		<category><![CDATA[Sunbelt]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/27/blackhat-2-day-recap-bettalatethaneva/</guid>
		<description><![CDATA[It was another cold, long drive into Washington DC from Aberdeen, MD. The hour and a half commute was definitely wearing on us. We had to leave Joe&#8217;s house by 6:15am to get to the 8am registration on time. Something had to give&#8230;it was as if Law could read my mind. He looked at me, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=42&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VurlZeaFI/AAAAAAAAAC8/hMyUuYYvr-s/s1600-h/copyrighthead.gif"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VurlZeaFI/AAAAAAAAAC8/hMyUuYYvr-s/s200/copyrighthead.gif" alt="" border="0" /></a><span style="font-family:verdana;">It was another cold, long drive into Washington DC from Aberdeen, MD.  The hour and a half commute was definitely wearing on us.  We had to leave Joe&#8217;s house by 6:15am to get to the 8am registration on time.  Something had to give&#8230;it was as if Law could read my mind.  He looked at me, &#8220;Hey Ant, we have to have a Starbuck&#8217;s coffee on the way in today.&#8221;  &#8220;Your right&#8221;, I mused.  He punched STARBUCKS into the Garmin GPS in Joe&#8217;s car without waiting for affirmation from me. &#8220;Eight miles&#8221; the cold electronic voice said.  &#8220;DAMN&#8221; was the response in unison.  We went ahead and hit the nearest highway on our way to DC and lo and behold&#8230;a sign for Starbucks at the next truck stop 1.5 miles up the highway.  It had to be done, bless Joe&#8217;s heart but he had violated our Seattle coffee sensibilities when we asked him to stop for coffee earlier in the week and he stopped at Burger King.  Yes my dear readers, Burger King.   Being a Seattle native born and bred I can only do that once a lifetime.</p>
<p>After walking out of Starbucks cup in hand, there was a look in each mans eye, a pep in his step, for lack of better terms we had <span style="font-style:italic;">ENERGY</span>!  On to the Blackhat Tales.</p>
<p><span style="font-weight:bold;">Day One</span></p>
<p>We registered, claimed our badges and bags and immediately went schwag hunt&#8230;er I mean talked to some of the vendors including Paraben, SAINT and Sunbelt Software.  We missed most of the introduction and most of the keynote address.  We also bumped into Chris Gates from LSO and Brian Wilson and hung out with them most of the day including lunch.</p>
<p>We attended the following talks:</p>
<p>Cracking GSM</p>
<p>RFIDI0ts!!!&#8211;Practical RFID Hacking</p>
<p>Bad Sushi: Beating Phishers at their Own Game</p>
<p>Oracle Hacking</p>
<p>Scanning Applications 2.0</p>
<p>We grabbed a quick bite to eat and chatted with Steve Adegbite of Microsoft (always a pleasure!) before we had to leave to do the 1.5 hour commute (sigh)</p>
<p><span style="font-weight:bold;">Day Two</span></p>
<p>We slept in till noon and decided that a 1.5 hour commute both ways just wasn&#8217;t going to happen.  Instead we packed our suitcases and jumpbags, went bar hopping, shopped at WalMart, and had dinner at a Chinese Buffet.  (not necessarily in that order)</p>
<p>All in all it was pretty cool, the talks were a step up from Shmoocon overall and the atmosphere is nice (they also have Starbucks drip coffee going for them).  Its much smaller than BH USA Las Vegas which was a great time last year.  I think that next year I might just do Shmoo and then Defcon/BH Vegas in the summer.<br /></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/42/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/42/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/42/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/42/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/42/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=42&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/27/blackhat-2-day-recap-bettalatethaneva/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VurlZeaFI/AAAAAAAAAC8/hMyUuYYvr-s/s200/copyrighthead.gif" medium="image" />
	</item>
		<item>
		<title>802.11 Attacks</title>
		<link>http://igsec.wordpress.com/2008/02/27/80211-attacks/</link>
		<comments>http://igsec.wordpress.com/2008/02/27/80211-attacks/#comments</comments>
		<pubDate>Wed, 27 Feb 2008 04:26:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[802.11]]></category>
		<category><![CDATA[Brad Antoniewicz]]></category>
		<category><![CDATA[Joshua Wright]]></category>
		<category><![CDATA[PEAP]]></category>
		<category><![CDATA[Shmoocon]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/27/80211-attacks/</guid>
		<description><![CDATA[I regret that I was unable to see Joshua Wright and Brad Antoniewicz talk on PEAP: Pwned Extensible Authentication Protocol at Shmoocon 4. Josh was kind enough to put up slide of the talk on willhackforsushi.com. Brad also made slides available that are complimentary to the ones from the presentation. In conjunction this is a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=40&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp2.blogger.com/_Z4u4MkgQQuE/R8VlnVZeZ_I/AAAAAAAAACM/r3bV-kg4KK4/s1600-h/ieee802-11-logo.jpg"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp2.blogger.com/_Z4u4MkgQQuE/R8VlnVZeZ_I/AAAAAAAAACM/r3bV-kg4KK4/s200/ieee802-11-logo.jpg" alt="" border="0" /></a><br /><span style="font-family:verdana;">I regret that I was unable to see Joshua Wright and Brad Antoniewicz talk on PEAP: Pwned Extensible Authentication Protocol at Shmoocon 4.  Josh was kind enough to put up slide of the talk on <a href="http://www.willhackforsushi.com/presentations/PEAP_Shmoocon2008_Wright_Antoniewicz.pdf">willhackforsushi.com</a>.  Brad also made <a href="http://packetstormsecurity.org/papers/attack/802.11Attacks.pdf">slides available</a> that are complimentary to the ones from the presentation.</p>
<p>In conjunction this is a very informative compilation of slides that should interest anyone interested in 802.11 security and I would like to thank the both of them for making these resources available!</p>
<p>UPDATE: A related article can be found <a href="http://www.channelregister.co.uk/2008/02/26/wpa_enterprise_pwnage/">here</a>.<br /></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/40/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/40/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/40/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=40&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/27/80211-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp2.blogger.com/_Z4u4MkgQQuE/R8VlnVZeZ_I/AAAAAAAAACM/r3bV-kg4KK4/s200/ieee802-11-logo.jpg" medium="image" />
	</item>
		<item>
		<title>Your Client Side Security Sucks [really, it does]</title>
		<link>http://igsec.wordpress.com/2008/02/26/your-client-side-security-sucks-really-it-does/</link>
		<comments>http://igsec.wordpress.com/2008/02/26/your-client-side-security-sucks-really-it-does/#comments</comments>
		<pubDate>Tue, 26 Feb 2008 11:39:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[Kurt Grutzmacher]]></category>
		<category><![CDATA[OWASP]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/26/your-client-side-security-sucks-really-it-does/</guid>
		<description><![CDATA[I returned to Seattle from Shmoocon/BH DC last Friday and have been experiencing a serious case of jet lag. To get through the fatigue I have been spending time getting caught up on the 266 RSS feeds that I follow via Google Reader and came across the following OWASP presentation by Kurt Grutzmacher. This is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=39&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:verdana;">I returned to Seattle from Shmoocon/BH DC last Friday and have been experiencing a serious case of jet lag.  To get through the fatigue I have been spending time getting caught up on the 266 RSS feeds that I follow via Google Reader and came across the following <a href="http://grutz.jingojango.net/presentations/Your%20Client%20Security%20Sucks%20-%20OWASP.pdf">OWASP presentation</a> by Kurt Grutzmacher.</p>
<p>This is an excellent read that I would suggest to anyone trying to understand why client side security is so vulnerable and error prone on the development side of things.</p>
<p></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/39/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/39/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/39/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/39/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/39/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=39&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/26/your-client-side-security-sucks-really-it-does/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Breach Notification Laws, State By State</title>
		<link>http://igsec.wordpress.com/2008/02/26/data-breach-notification-laws-state-by-state/</link>
		<comments>http://igsec.wordpress.com/2008/02/26/data-breach-notification-laws-state-by-state/#comments</comments>
		<pubDate>Tue, 26 Feb 2008 10:14:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[breach notification]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[US]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/26/data-breach-notification-laws-state-by-state/</guid>
		<description><![CDATA[I have long been an avid follower of breach notification legislation but usually in reagards to the west coast of the USA. While reading my RSS feeds yesterday I came across an interesting resource. The link will take you to a map of the US that shows the breach notification status of each state in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=38&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><span style="font-family:verdana;">I have long been an avid follower of breach notification legislation but usually in reagards to the west coast of the USA.  While reading my RSS feeds yesterday I came across <a href="http://www.csoonline.com/read/020108/ammap/ammap.html">an interesting resource</a>.  The link will take you to a map of the US that shows the breach notification status of each state in the Union via color coding and a nifty popup.  Far too useful and interesting to keep to myself.</p>
<p>Enjoy!<br /></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/38/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/38/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/38/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=38&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/26/data-breach-notification-laws-state-by-state/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>
	</item>
		<item>
		<title>MySQL, SHA1 and me</title>
		<link>http://igsec.wordpress.com/2008/02/25/mysql-sha1-and-me/</link>
		<comments>http://igsec.wordpress.com/2008/02/25/mysql-sha1-and-me/#comments</comments>
		<pubDate>Mon, 25 Feb 2008 00:07:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[Abel]]></category>
		<category><![CDATA[Cain]]></category>
		<category><![CDATA[john the ripper]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[mysqlfast]]></category>
		<category><![CDATA[poc]]></category>
		<category><![CDATA[SHA1]]></category>
		<category><![CDATA[unhash]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/25/mysql-sha1-and-me/</guid>
		<description><![CDATA[While hacking around with SQL injection on the LSO (LearnSecurityOnline) labs, the subject of being able to crack a MySQL SHA1 password hash came up and became a topic of interest and a challenge of sorts. I have never come across this one before so I impulsively decided to pick it up and see what [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=37&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VlJlZeZ-I/AAAAAAAAACE/Qrxk_5XkJ_0/s1600-h/MySQL_logo.png"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VlJlZeZ-I/AAAAAAAAACE/Qrxk_5XkJ_0/s200/MySQL_logo.png" alt="" border="0" /></a>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">While hacking around with SQL injection on the LSO (LearnSecurityOnline) labs, the subject of being able to crack a  MySQL SHA1 password hash came up and became a topic of interest and a challenge of sorts.  I have never come across this one before so I impulsively decided to pick it up and see what I could do with it before I had to get on a plane back to Seattle.</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">./poc</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">A quick Google search turned up this tool.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">A proof of concept (hence the name) MySQL password hash cracker.  Optimized for quad core CPU implementations</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Can be downloaded  from </span><span style="color:rgb(0,0,128);font-size:100%;"><u><a href="http://www.sqlhack.com/poc.c"><span style="font-family:Verdana,sans-serif;">http://www.sqlhack.com/poc.c</span></a></u></span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><code><span style="font-family:Verdana,sans-serif;">gcc -O3 -o poc poc.c</span></code></span><span style="color:rgb(0,0,128);font-size:100%;"><u><span style="font-family:Verdana,sans-serif;"> </span></u></span> </p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">I ran this for about 12 hours until it determined that the password was beyond 8 character and therefore out of scope for this particular program.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Performed on a Dell D600 Pentium M 1.4 Ghz Machine with 1 GB of RAM</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">./mysqlfast</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Some initial Googling turned up this tool.  I was able to run this one the longest albeit without any success.</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><a href="http://packetstorm.linuxsecurity.com/Crackers/msqlfast.c"><span style="font-family:Verdana,sans-serif;">http://packetstorm.linuxsecurity.com/Crackers/msqlfast.c</span></a></span></p>
<pre style="margin-bottom:.2in;"><span style="font-family:Verdana,sans-serif;font-size:100%;">gcc -O2 -fomit-frame-pointer mysqlfast.c -o mysqlfast</span></pre>
<p style="margin-bottom:0;"> <span style="font-family:Verdana,sans-serif;font-size:100%;">I ran this tool for about 15 hours without success.  It was checking 9 character passwords when I ended execution of the program.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Performed on a Dell D600 Pentium M 1.4 Ghz Machine with 1 GB of RAM</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">./unhash</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">I came across this one looking for MySQL SHA1 crackers on PacketStorm Security.  I was only able to run it for a few hours before I had to pack up my laptops in preparation to catch my flight.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">http://packetstorm.codar.com.br/Crackers/unhash-0.9.tgz</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Performed on a Dell D600 Pentium M 1.4 Ghz Machine with 1 GB of RAM</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Cain &amp; Abel</span></p>
<p style="margin-bottom:0;"><span style="font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Identified the hash as MySQL v3.23.  I attempted to use the built in dictionary running as many permutations as possible without any success.  It took about an hour or so to make it through the dictionary file.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Performed on a HP nc6000 Pentium M 1.6 Ghz laptop with 2 GB of RAM</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">John the Ripper (Joe McCray performed this test)</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">John is not natively capable of cracking MySQL SHA1 hashes and requires a patch to do so.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">[j0e@LinuxLaptop john-1.7.2]$ wget<br /><a href="http://openwall.com/john/contrib/john-1.7-all-4.diff.gz" target="_blank">http://openwall.com/john/contrib/john-1.7-all-4.diff.gz</a></p>
<p>[j0e@LinuxLaptop john-1.7.2]$ gunzip -c john-1.7-all-4.diff.gz | patch<br />-p0</p>
<p>[j0e@LinuxLaptop john-1.7.2]$ cd src/</p>
<p>[j0e@LinuxLaptop src]$ su<br />Password:</p>
<p>[root@LinuxLaptop src]# make linux-x86-any </span> </p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">John was fed a 7 million entry password dictionary</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">[j0e@LinuxLaptop run]$ ./john<br />&#8211;wordlist=../../../wordlistz/MassiveDictionary.txt mysql_hash.txt<br />Loaded 1 password hash (Raw SHA1 [raw-sha1])<br />guesses: 0  time: 0:00:00:03 100%  c/s: 862538  trying: zwolle </span> </p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">This was NOT the correct password.</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">Performed on a Dell D620 Core Duo 2 1.83 laptop with 2GB of RAM</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">If anyone out there has any suggestions on more efficient ways to go about this I would LOVE to hear about them.</span></p>
<p style="margin-bottom:0;"></p>
<p style="margin-bottom:0;"><span style="font-family:verdana;">UPDATE: Sandro Gauci of <a href="http://sipvicious.org/">SipVicious.org</a> pointed me to a <a href="http://www.matasano.com/log/958/enough-with-the-rainbow-tables-what-you-need-to-know-about-secure-password-schemes/">great resource</a>.  Any other feedback and suggestions are welcome!</span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;"><br /></span></p>
<p style="margin-bottom:0;"><span style="font-family:Verdana,sans-serif;font-size:100%;">May Your Skill Prevail.</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/37/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/37/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=37&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/25/mysql-sha1-and-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VlJlZeZ-I/AAAAAAAAACE/Qrxk_5XkJ_0/s200/MySQL_logo.png" medium="image" />
	</item>
		<item>
		<title>The DC/Maryland Saga Continues</title>
		<link>http://igsec.wordpress.com/2008/02/19/the-dcmaryland-saga-continues/</link>
		<comments>http://igsec.wordpress.com/2008/02/19/the-dcmaryland-saga-continues/#comments</comments>
		<pubDate>Tue, 19 Feb 2008 11:50:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[Blackhat DC 2008]]></category>
		<category><![CDATA[Burger King]]></category>
		<category><![CDATA[DC]]></category>
		<category><![CDATA[Maryland]]></category>
		<category><![CDATA[Starbucks]]></category>
		<category><![CDATA[wardriving]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/19/the-dcmaryland-saga-continues/</guid>
		<description><![CDATA[Today we actually made it back in by 2AM after eating dinner at Applebee&#8217;s while watching the NBA All Star Game and then doing some wardriving of Aberdeen, Maryland (~800 Aps). Joe, evil1, Law and myself all stayed up most of the night hacking away and talking. Around noon we all had to drag ourselves [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=36&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp0.blogger.com/_Z4u4MkgQQuE/R8VmH1ZeaAI/AAAAAAAAACU/oVMZ-yG6saI/s1600-h/100px-Seal-DC.png"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp0.blogger.com/_Z4u4MkgQQuE/R8VmH1ZeaAI/AAAAAAAAACU/oVMZ-yG6saI/s200/100px-Seal-DC.png" alt="" border="0" /></a><br /><span style="font-family:verdana;font-size:100%;">Today we actually made it back in by 2AM after eating dinner at Applebee&#8217;s while watching the NBA All Star Game and then doing some wardriving of Aberdeen, Maryland (~800 Aps). Joe, evil1, Law and myself all stayed up most of the night hacking away and talking.</span><span style="font-family:arial;font-size:100%;"></p>
<p></span><span style="font-family:verdana;font-size:100%;">Around noon we all had to drag ourselves out of bed to get evil1 to the airport to catch a 4:30pm flight. After dropping him off Lawrence and I had to stop at Starbuck&#8217;s coffee (Burger King coffee is like kryptonite to Seattle denizens) and note that it appears that we had brought the overcast cloudy and rainy weather with us. </span><span style="font-family:arial;font-size:100%;"></p>
<p></span><span style="font-family:verdana;font-size:100%;">Since we were already in the area and had our wardriving gear with us we decided that some good &#8216;ol AP detection was in order. We were able to get a pretty good haul of ~10,000 AP&#8217;s after about 3 hours then headed north for the long journey home.</span><span style="font-family:arial;font-size:100%;"></p>
<p></span><span style="font-family:verdana;font-size:100%;">Tomorrow we are planning to drive back down to DC and do the BH DC 2008 Briefings early registration. If all goes well we may drive up to Philadelphia and do some wardriving before it gets too late.</span><span style="font-family:verdana;font-size:100%;"></span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/36/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/36/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=36&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/19/the-dcmaryland-saga-continues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp0.blogger.com/_Z4u4MkgQQuE/R8VmH1ZeaAI/AAAAAAAAACU/oVMZ-yG6saI/s200/100px-Seal-DC.png" medium="image" />
	</item>
		<item>
		<title>Shmoocon Day Three</title>
		<link>http://igsec.wordpress.com/2008/02/17/shmoocon-day-three/</link>
		<comments>http://igsec.wordpress.com/2008/02/17/shmoocon-day-three/#comments</comments>
		<pubDate>Sun, 17 Feb 2008 16:42:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[blackhat]]></category>
		<category><![CDATA[Brad Antoniewicz]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[Josh Wright]]></category>
		<category><![CDATA[PEAP]]></category>
		<category><![CDATA[Shmoocon]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/17/shmoocon-day-three/</guid>
		<description><![CDATA[After 3 nights of 2-3 hours of sleep and a 1 ½ hour commute both ways everyone was exhausted today. We made the decision to stay at the house and catch up on our rest before we got to a BBQ at Wolf&#8217;s house. I regret missing the PEAP: Pwned Extensible Authentication Protocol by Josh [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=35&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VijlZeZ9I/AAAAAAAAAB8/Ol-rgia107g/s1600-h/shmoocon_logo.png"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VijlZeZ9I/AAAAAAAAAB8/Ol-rgia107g/s200/shmoocon_logo.png" alt="" border="0" /></a><br /><span style="font-family:verdana;">After 3 nights of 2-3 hours of sleep and a 1 ½ hour commute both ways everyone was exhausted today.  We made the decision to stay at the house and catch up on our rest before we got to a BBQ at Wolf&#8217;s house.   I regret missing the PEAP: Pwned Extensible Authentication Protocol by Josh Wright and Brad Antoniewicz presentation.</span></p>
<p><span style="font-family:verdana;">As I type this Joe and Lawrence are sitting at the dining room table with laptops with evil1 still in his room sleeping.  Overall shmoocon was a blast, the talks were o.k. but the people and side channel conversations we had were excellent.</span></p>
<p><span style="font-family:verdana;">Will I be going next year?  Absolutely! </span></p>
<p><span style="font-family:verdana;">Shouts out to to CG, Kev, Marco and Steve A.  I&#8217;ll catch those who are going to BH Federal at the briefings next week or at DefCon later in the year.  If not see you guys on SILC.</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/35/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/35/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/35/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/35/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/35/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=35&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/17/shmoocon-day-three/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp3.blogger.com/_Z4u4MkgQQuE/R8VijlZeZ9I/AAAAAAAAAB8/Ol-rgia107g/s200/shmoocon_logo.png" medium="image" />
	</item>
		<item>
		<title>Shmoocon Day Two</title>
		<link>http://igsec.wordpress.com/2008/02/17/shmoocon-day-two/</link>
		<comments>http://igsec.wordpress.com/2008/02/17/shmoocon-day-two/#comments</comments>
		<pubDate>Sun, 17 Feb 2008 07:40:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[802.11]]></category>
		<category><![CDATA[citrix]]></category>
		<category><![CDATA[fuzzing]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[SPIKE]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/17/shmoocon-day-two/</guid>
		<description><![CDATA[We were able to actually make it in on time today after getting 2 hours of sleep! Watched the Active 802.11 Fingerprinting: Gibberish and &#8220;Secret Handshakes&#8221; to Know Your AP by Sergey Bratus, Cory Cornelius and Daniel Peebles. I found this to be an interesting talk and hope that this research begins to delve into [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=34&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp3.blogger.com/_Z4u4MkgQQuE/R8ViNlZeZ8I/AAAAAAAAAB0/A9iAvRtTEvQ/s1600-h/shmoocon_logo.png"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp3.blogger.com/_Z4u4MkgQQuE/R8ViNlZeZ8I/AAAAAAAAAB0/A9iAvRtTEvQ/s200/shmoocon_logo.png" alt="" border="0" /></a><br /><span style="font-family:verdana;">We were able to actually make it in on time today after getting 2 hours of sleep!  Watched the Active 802.11 Fingerprinting: Gibberish and &#8220;Secret Handshakes&#8221; to Know Your AP by Sergey Bratus, Cory Cornelius and Daniel Peebles.  I found this to be an interesting talk and hope that this research begins to delve into the client realm in the near future.</span></p>
<p><span style="font-family:verdana;">I also had the pleasure of catching the following talks:</span></p>
<p><span style="font-family:verdana;">Got Citrix? Hack It! By Shanit Gupta and Advanced Protocol Fuzzing &#8211; What We Learned when Bringing Layer2 Logic to &#8220;SPIKE Land&#8221; by Enno Rey and Daniel Mende.  There was also an impromptu talk by muts covering AV circumvention using ollydebug and Windows Vista ASLR circumvention.</span></p>
<p><span style="font-family:verdana;">I had lunch with Kevin Figueora of K&amp;T International Consulting, Marco Figueroa of MAF Consulting, Inc, Joe McCray of LearnSecurityOnline, Lawrence White of IGS and evil1 at the Chipotle down the street from the hotel.  All of us also got together later in the evening and had the most amazing time eating dinner, watching the All-Star 3 point shooting and Slam Dunk contest and having drinks and talking shop.  The talks at any convention are good to go to but these are the experiences that stay with you for a lifetime.</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/34/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/34/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/34/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=34&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/17/shmoocon-day-two/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp3.blogger.com/_Z4u4MkgQQuE/R8ViNlZeZ8I/AAAAAAAAAB0/A9iAvRtTEvQ/s200/shmoocon_logo.png" medium="image" />
	</item>
		<item>
		<title>Shmoocon Day One</title>
		<link>http://igsec.wordpress.com/2008/02/16/shmoocon-day-one/</link>
		<comments>http://igsec.wordpress.com/2008/02/16/shmoocon-day-one/#comments</comments>
		<pubDate>Sat, 16 Feb 2008 12:44:00 +0000</pubDate>
		<dc:creator>igsec</dc:creator>
				<category><![CDATA[AirTight]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[LearnSecurityOnline]]></category>
		<category><![CDATA[Midnight Research Labs]]></category>
		<category><![CDATA[Offensive Security]]></category>
		<category><![CDATA[Rick Farina]]></category>
		<category><![CDATA[Shmoocon]]></category>

		<guid isPermaLink="false">http://igsec.wordpress.com/2008/02/16/shmoocon-day-one/</guid>
		<description><![CDATA[Overslept like a bunch of jet lagged bums! Arrived 2 hours late and missed all of the talks getting social with my peers. Met some cool guys: muts from Offensive Security/Back&#124;Track, Aaron Petersen from MRL (Midnight Research Labs) and Rick Farina from AirTight. As is usual for my con experiences hung out with the LSO [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=33&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://bp0.blogger.com/_Z4u4MkgQQuE/R8Vh51ZeZ7I/AAAAAAAAABs/cX9LB3fv9CY/s1600-h/shmoocon_logo.png"><img style="float:left;cursor:pointer;margin:0 10px 10px 0;" src="http://bp0.blogger.com/_Z4u4MkgQQuE/R8Vh51ZeZ7I/AAAAAAAAABs/cX9LB3fv9CY/s200/shmoocon_logo.png" alt="" border="0" /></a><br /><span style="font-family:verdana;">Overslept like a bunch of jet lagged bums!  Arrived 2 hours late and missed all of the talks getting social with my peers.  Met some cool guys: muts from Offensive Security/Back|Track, Aaron Petersen from MRL (Midnight Research Labs) and Rick Farina from AirTight.  As is usual for my con experiences hung out with the LSO (LearnSecurityOnline) j0e and Chris and evil1 (mad props for webapp kung fu).</span></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/igsec.wordpress.com/33/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/igsec.wordpress.com/33/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/igsec.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/igsec.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/igsec.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/igsec.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/igsec.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/igsec.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/igsec.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/igsec.wordpress.com/33/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=igsec.wordpress.com&amp;blog=5801780&amp;post=33&amp;subd=igsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://igsec.wordpress.com/2008/02/16/shmoocon-day-one/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e1c334744bd14728655f213ad5d25384?s=96&#38;d=identicon" medium="image">
			<media:title type="html">igsec</media:title>
		</media:content>

		<media:content url="http://bp0.blogger.com/_Z4u4MkgQQuE/R8Vh51ZeZ7I/AAAAAAAAABs/cX9LB3fv9CY/s200/shmoocon_logo.png" medium="image" />
	</item>
	</channel>
</rss>
