<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>CyberSpace Insecurity 2.X</title>
	<atom:link href="http://cyberinsec.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://cyberinsec.wordpress.com</link>
	<description>Simon Roses Femerling Blog: Technology, Pen Testing &#38; Economics...</description>
	<lastBuildDate>Mon, 10 May 2010 16:31:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='cyberinsec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>CyberSpace Insecurity 2.X</title>
		<link>http://cyberinsec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://cyberinsec.wordpress.com/osd.xml" title="CyberSpace Insecurity 2.X" />
	<atom:link rel='hub' href='http://cyberinsec.wordpress.com/?pushpress=hub'/>
		<item>
		<title>New Home, Check it out!</title>
		<link>http://cyberinsec.wordpress.com/2010/05/10/new-home-check-it-out/</link>
		<comments>http://cyberinsec.wordpress.com/2010/05/10/new-home-check-it-out/#comments</comments>
		<pubDate>Mon, 10 May 2010 16:31:54 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=191</guid>
		<description><![CDATA[Otra vez nos hemos mudado Por favor visita Simon Roses Website New site again Please visit us at the new Simon Roses Website See you / Nos vemos<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=191&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Otra vez nos hemos mudado <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Por favor visita <a title="Simon Roses Website" href="http://www.simonroses.com">Simon Roses Website</a></p>
<p><span style="color:#993300;">New site again <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></p>
<p><span style="color:#993300;">Please visit us at the new</span> <a title="Simon Roses Website" href="http://www.simonroses.com">Simon Roses Website</a></p>
<p><span style="color:#993300;">See you</span> / Nos vemos</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/191/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=191&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/05/10/new-home-check-it-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>
	</item>
		<item>
		<title>Source Conference: Boston Agenda &amp; Barcelona CFP</title>
		<link>http://cyberinsec.wordpress.com/2010/03/22/source-conference-boston-agenda-barcelona-cfp/</link>
		<comments>http://cyberinsec.wordpress.com/2010/03/22/source-conference-boston-agenda-barcelona-cfp/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 15:38:14 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=189</guid>
		<description><![CDATA[Si estas en US no te pierdas la conferencia SOURCE con su increíble agenda: http://www.sourceconference.com/index.php/boston2010/sb2010-schedule Y si estas por Europa pues te interesa venir a SOURCE Barcelona: http://www.sourceconference.com/index.php?option=com_rsform&#38;formId=18&#38;Itemid=99999 Nos vemos!!! If you are in US don&#8217;t miss the SOURCE Conference with its incredible schedule: http://www.sourceconference.com/index.php/boston2010/sb2010-schedule And if you in Europe you should come to SOURCE [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=189&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Si estas en US no te pierdas la conferencia SOURCE con su increíble agenda: <a href="http://www.sourceconference.com/index.php/boston2010/sb2010-schedule">http://www.sourceconference.com/index.php/boston2010/sb2010-schedule</a></p>
<p>Y si estas por Europa pues te interesa venir a SOURCE Barcelona: <a href="http://www.sourceconference.com/index.php?option=com_rsform&amp;formId=18&amp;Itemid=99999">http://www.sourceconference.com/index.php?option=com_rsform&amp;formId=18&amp;Itemid=99999</a></p>
<p>Nos vemos!!! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style="color:#993300;"><em>If you are in US don&#8217;t miss the SOURCE Conference with its incredible schedule:</em></span> <a href="http://www.sourceconference.com/index.php/boston2010/sb2010-schedule">http://www.sourceconference.com/index.php/boston2010/sb2010-schedule</a></p>
<p><span style="color:#993300;"><em>And if you in Europe you should come to SOURCE Barcelona</em></span>: <a href="http://www.sourceconference.com/index.php?option=com_rsform&amp;formId=18&amp;Itemid=99999">http://www.sourceconference.com/index.php?option=com_rsform&amp;formId=18&amp;Itemid=99999</a></p>
<p><span style="color:#993300;"><em>See you around!!! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></span></p>
<p><span style="color:#993300;"><span style="color:#333333;">&#8211; SRF</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/189/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/189/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/189/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=189&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/03/22/source-conference-boston-agenda-barcelona-cfp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>
	</item>
		<item>
		<title>Attack Surface Analysis Infinitum</title>
		<link>http://cyberinsec.wordpress.com/2010/03/03/attack-surface-analysis-infinitum/</link>
		<comments>http://cyberinsec.wordpress.com/2010/03/03/attack-surface-analysis-infinitum/#comments</comments>
		<pubDate>Wed, 03 Mar 2010 09:44:17 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[SDL]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Threat Modeling]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=173</guid>
		<description><![CDATA[En cualquier revisión de seguridad ya sea un test de intrusión, revisión de una aplicación web o de código fuente el Attack Surface Analysis (ASA) es una poderosa metodología que podemos utilizar para identificar los vectores de ataque del sistema. Personalmente siempre realizo este ejercicio en cualquier proyecto para determinar los puntos vulnerables y luego [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=173&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>En cualquier revisión de seguridad ya sea un test de intrusión, revisión de una aplicación web o de código fuente el Attack Surface Analysis (ASA) es una poderosa metodología que podemos utilizar para identificar los vectores de ataque del sistema. Personalmente siempre realizo este ejercicio en cualquier proyecto para determinar los puntos vulnerables y luego otro ejercicio llamado Attack Surface Reduction (ASR) para evaluar y mitigar los vectores de ataque.</p>
<p><em><span style="color:#993300;">In any security review whether is a pentesting, a web application or source code review Attack Surface Analysis (ASA) is a powerful methodology that we can use to identify the system attack vectors. Personally I always do this exercise in any project to determine the vulnerabilities and then another exercise called Attack Surface Reduction (ASR) to assess and mitigate attack vectors.</span></em></p>
<p>Por lo que podemos definir ASA como un análisis sistemático del sistema para identificar los vectores de ataque y ASR como el proceso de validación y mitigación de los vectores de ataque.</p>
<p><span style="color:#993300;"><em>We can define ASA as a systematic analysis of the system to identify attack vectors and ASR as the process of validation and mitigation of attack vectors.</em></span></p>
<p>Las organizaciones tienen multitud de vectores de ataques desde sus redes corporativas, aplicaciones, personas, etc. que pueden ser explotados. Los atacantes solo necesitan encontrar un vector de ataque que les permita conseguir su objetivo mientras que los defensores deben identificar todos los vectores de ataques y realizar un ASR.</p>
<p><span style="color:#993300;"><em>Organizations have many attack vectors from their corporate networks, applications, people, etc. that can be exploited. Attackers just need to find a single attack vector that enables them to achieve their goal while defenders must identify all attack vectors and perform an ASR.</em></span></p>
<p>Como dice un proverbio chino “<em>Si das pescado a un hombre hambriento, le nutres una jornada. Si le enseñas a pescar, le nutrirás toda la vida</em>”, veamos algunos ejemplos prácticos de ASA. </p>
<p><span style="color:#993300;"><em>As said by a Chinese quote &#8220;Give a man a fish and you feed him for a day. Teach him how to fish and you feed him for a lifetime”, let&#8217;s look at some practical examples of ASA.</em></span></p>
<p><span style="text-decoration:underline;">ASA Corp. Network</span></p>
<p>El siguiente grafico es un diagrama de una red corporativo típico que podemos encontrar en muchas organizaciones.</p>
<p><span style="color:#993300;"><em>The following graphic is a diagram of a typical corporate network found in many organizations.</em></span></p>
<p><span style="color:#993300;"><a href="http://cyberinsec.files.wordpress.com/2010/03/visio20diagram.jpg"><img class="alignnone size-medium wp-image-174" title="visio%20diagram" src="http://cyberinsec.files.wordpress.com/2010/03/visio20diagram.jpg?w=415&#038;h=208" alt="visio%20diagram" width="415" height="208" /></a></span></p>
<p><span style="color:#993300;"><a href="http://cyberinsec.files.wordpress.com/2010/03/visio20diagram.jpg"></a></span></p>
<p><a href="http://oahucomputers.com/_library/images/visio%20diagram.jpg">http://oahucomputers.com/_library/images/visio%20diagram.jpg</a></p>
<p> Realizando un ASA superficial algunos vectores de ataque podrían ser:</p>
<ul>
<li>¿Está el Firewall y/o routers correctamente configurados? ¿Tienen vulnerabilidades?</li>
<li>¿Cuál es la relación de confianza de las oficinas remotas?</li>
<li>¿Atacar el Access Point (AP) y/o a los clientes?</li>
<li>¿Acceder a un ordenador portátil, PDA y/o Smartphone?</li>
<li>¿Atacar a los clientes (navegador, ficheros malicioso, email, etc.)?</li>
<li>¿La postura de seguridad de los servidores (parches, configuraciones, etc.)?</li>
<li>¿Atacar la red?</li>
</ul>
<p><span style="color:#993300;"><em>Performing a superficial ASA some attacks vectors could be:</em></span></p>
<ul>
<li><span style="color:#993300;"><em>¿Is the Firewall and/or routers properly configured? ¿Have vulnerabilities?</em></span></li>
<li><span style="color:#993300;"><em>¿What is the trusted relationship of remote offices?</em></span></li>
<li><span style="color:#993300;"><em>¿Can you attack the access Point (AP) and/or clients?</em></span></li>
<li><span style="color:#993300;"><em>¿Having access to a laptop, PDA or Smartphone?</em></span></li>
<li><span style="color:#993300;"><em>¿Can you attack clients systems (browser, malicious files, email, etc.)?</em></span></li>
<li><span style="color:#993300;"><em>¿What is the security posture of servers (patches, configurations, etc.)?</em></span></li>
<li><span style="color:#993300;"><em>¿Can you attack the network?</em></span></li>
</ul>
<p> Herramientas / <span style="color:#993300;"><em>Tools</em></span></p>
<ul>
<li><a title="Bing" href="http://www.bing.com/">Bing</a> &amp; <a title="Google" href="http://www.google.com">Google</a> queries</li>
<li><a title="Nmap" href="http://nmap.org/">Nmap</a></li>
<li><a title="Maltego" href="http://www.paterva.com/web4/index.php/maltego">Maltego</a></li>
<li><a title="Nessus" href="http://www.nessus.org">Nessus</a> / <a title="OpenVAS" href="http://www.openvas.org/">Openvas</a></li>
<li><a title="Metasploit" href="http://www.metasploit.com/">Metasploit</a> / <a title="CANVAS" href="http://www.immunitysec.com/products-canvas.shtml">CANVAS</a> / <a title="Core Impact" href="http://www.coresecurity.com/content/core-impact-overview">Core Impact</a> / <a title="Inguma" href="http://inguma.sourceforge.net/">Inguna</a> / <a title="Ronin" href="http://ronin.rubyforge.org/">Ronin</a></li>
</ul>
<p><span style="text-decoration:underline;">ASA Web App</span></p>
<p>En este ejemplo realizaremos un ASA de una aplicación web.</p>
<p><span style="color:#993300;"><em>In this example we will make an ASA of a web application.</em></span></p>
<p><span style="color:#993300;"><a href="http://cyberinsec.files.wordpress.com/2010/03/web.jpg"><img class="alignnone size-medium wp-image-177" title="web" src="http://cyberinsec.files.wordpress.com/2010/03/web.jpg?w=370&#038;h=207" alt="web" width="370" height="207" /></a></span></p>
<p>Realizando un ASA superficial algunos vectores de ataque podrían ser:</p>
<ul>
<li>¿Es el usuario el usuario? ¿Puede el usuario realizar mas acciones de las necesarias?</li>
<li>¿Hasta dónde llega el admin?</li>
<li>¿Servidor web inseguro?</li>
<li>¿Aplicación web desarrollado sin SDL-LOB?</li>
<li>¿Comprometer la información en tránsito (MITM) y/o en reposo?</li>
<li>¿Atacar la base de datos?</li>
<li>¿Cómo gestiona la aplicación la información?</li>
</ul>
<p><span style="color:#993300;"><em>Performing a superficial ASA some attacks vectors could be:</em></span></p>
<ul>
<li><span style="color:#993300;"><em>¿Is the user the user? ¿Can the user perform more actions than necessary?</em></span></li>
<li><span style="color:#993300;"><em>¿How far can the admin go?</em></span></li>
<li><span style="color:#993300;"><em>¿Insecure web server?</em></span></li>
<li><span style="color:#993300;"><em>¿Was the web application developed without SDL-LOB?</em></span></li>
<li><span style="color:#993300;"><em>¿Can you compromise information in transit (MITM) and/or rest?</em></span></li>
<li><span style="color:#993300;"><em>¿Can you attack the database?</em></span></li>
<li><span style="color:#993300;"><em>¿How the app manages information?</em></span></li>
</ul>
<p>Herramientas / <span style="color:#993300;"><em>Tools</em></span></p>
<ul>
<li><a title="Microsoft Threat Analysis and Modeling (TAM)" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=aad6dec7-26cf-4053-9963-d5974631c070&amp;displaylang=en">Threat Analysis &amp; Modeling (TAM)</a> /<a title="SDL TM" href="http://download.microsoft.com/download/E/5/3/E5318D25-7AEF-4A66-A147-81BBA727F2C1/SDLTM.msi"> SDL TM</a></li>
<li><a title="Nikto" href="http://cirt.net/nikto2">Nikto</a></li>
<li><a title="W3af" href="http://w3af.sourceforge.net/">W3af</a></li>
<li><a title="SiteScope" href="http://www.foundstone.com/us/resources/proddesc/sitescope.htm">SiteScope</a></li>
<li><a title="OWASP Pantera" href="http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project">OWASP Pantera</a> <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ul>
<p><span style="text-decoration:underline;">ASA Code Review</span></p>
<p>En una revisión de código fuente el ASA podría ser:</p>
<ul>
<li>¿Lee la aplicación de ficheros, sockets, registro, memoria compartida, etc.?</li>
<li>¿Realiza algún tipo de autenticación y autorización?</li>
<li>¿Encripta información? ¿Algoritmo de cifrado?</li>
<li>¿Tiene código antiguo?</li>
<li>¿Interactúa con otras aplicaciones?</li>
<li>¿Qué permisos necesita para ejecutarse?</li>
<li>¿Tecnologías que utiliza la aplicación?</li>
</ul>
<p><span style="color:#993300;"><em>For a code review source ASA could be:</em></span></p>
<ul>
<li><span style="color:#993300;"><em>¿Reads the application from files, sockets, registry, shared memory, etc.?</em></span></li>
<li><span style="color:#993300;"><em>¿Does some kind of authentication and authorization?</em></span></li>
<li><span style="color:#993300;"><em>¿is information encrypted? ¿What encryption algorithm?</em></span></li>
<li><span style="color:#993300;"><em>¿Have the app old code?</em></span></li>
<li><span style="color:#993300;"><em>¿Does the app interact with other applications?</em></span></li>
<li><span style="color:#993300;"><em>¿What permissions it needs to run?</em></span></li>
<li><span style="color:#993300;"><em>¿What technologies is the app using?</em></span></li>
</ul>
<p>Herramientas / <span style="color:#993300;"><em>Tools</em></span></p>
<ul>
<li><a title="Attack Surface Explorer" href="http://ase.codeplex.com/">Attack Surface Explorer</a></li>
<li><a title="BinScope" href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;FamilyID=90e6181c-5905-4799-826a-772eafd4440a">BinScope</a></li>
<li><a title="CAT.NET" href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=734&amp;DownloadID=23328">CAT.NET</a></li>
<li><a title="SDL Template" href="http://www.microsoft.com/security/sdl/getstarted/processtemplate.aspx">SDL Template</a></li>
<li><a title="VS /analyze" href="http://blogs.msdn.com/vcblog/archive/2008/02/05/prefast-and-sal-annotations.aspx">VS /analyze</a></li>
</ul>
<p>Lo cierto es que me he quedado muy lejos de realizar un ASA completo pero como bien refleja el título de este post existen multitud de vectores de ataque en las organizaciones pero es un ejercicio que debemos realizar a consciencia y constantemente.</p>
<p>Para ello tenemos mucha documentación, metodologías (Attack Trees, Threat Models, etc.) y herramientas a nuestra disposición.</p>
<p><strong>¿Y vosotros como realizáis un ASA en vuestras revisiones de seguridad?</strong></p>
<p><span style="color:#993300;"><em>The truth is that I’m far away for a full ASA but as reflected in the post title there are many different attack vectors in organizations but is an exercise we must perform consciousness and constantly.</em></span></p>
<p><span style="color:#993300;"><em>We have lots of documentation, methodologies (Attack Trees, Threat Models, etc.) and tools at our disposal.</em></span></p>
<p><strong><span style="color:#993300;"><em>¿How do you do your ASA in your security reviews?</em></span></strong></p>
<p>Links:</p>
<ul>
<li>Mitigate Security Risks by Minimizing the Code You Expose to Untrusted Users<br />
<a href="http://msdn.microsoft.com/en-us/magazine/cc163882.aspx">http://msdn.microsoft.com/en-us/magazine/cc163882.aspx</a></li>
<li>Attack Surface Measurement<br />
<a href="http://www.cs.cmu.edu/~pratyus/as.html#introduction">http://www.cs.cmu.edu/~pratyus/as.html#introduction</a></li>
<li>Minimize attack surface area<br />
<a href="http://www.owasp.org/index.php/Minimize_attack_surface_area">http://www.owasp.org/index.php/Minimize_attack_surface_area</a></li>
<li>Windows Vista: Network Attack Surface Analysis<br />
<a href="http://www.symantec.com/connect/blogs/windows-vista-network-attack-surface-analysis">http://www.symantec.com/connect/blogs/windows-vista-network-attack-surface-analysis</a></li>
<li>Using Attack Surface in Threat Models<br />
<a href="http://1raindrop.typepad.com/1_raindrop/2009/06/using-attack-surface-in-threat-models.html">http://1raindrop.typepad.com/1_raindrop/2009/06/using-attack-surface-in-threat-models.html</a></li>
</ul>
<p>&#8211; SRF</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=173&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/03/03/attack-surface-analysis-infinitum/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/03/visio20diagram.jpg?w=300" medium="image">
			<media:title type="html">visio%20diagram</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/03/web.jpg?w=300" medium="image">
			<media:title type="html">web</media:title>
		</media:content>
	</item>
		<item>
		<title>Privacy concerns on Google Buzz</title>
		<link>http://cyberinsec.wordpress.com/2010/02/15/privacy-concerns-on-google-buzz/</link>
		<comments>http://cyberinsec.wordpress.com/2010/02/15/privacy-concerns-on-google-buzz/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 20:19:37 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=165</guid>
		<description><![CDATA[ Actualización 18/02/10: Era cuestión de tiempo, 1) vulnerabilidad en Buzz y 2) demanda de privacidad contra Buzz por parte de EPIC. Prácticamente todo el mundo a estas alturas ha oído hablar del nuevo servicio de Google llamado Buzz,  que acaba de lanzar la semana pasada para competir contra Facebook y Twitter. He de confesar que [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=165&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p> <strong>Actualización 18/02/10:</strong> Era cuestión de tiempo, 1) <a title="vulnerabilidad en Buzz" href="http://ha.ckers.org/blog/20100216/google-buzz-security-flaw/">vulnerabilidad en Buzz</a> y 2) demanda de privacidad contra Buzz por parte de <a title="EPIC" href="http://epic.org/2010/02/epic-urges-federal-trade-commi.html">EPIC</a>.</p>
<p>Prácticamente todo el mundo a estas alturas ha oído hablar del nuevo servicio de <a title="Google" href="http://www.google.com">Google</a> llamado <a title="Buzz" href="http://www.google.com/buzz">Buzz</a>,  que acaba de lanzar la semana pasada para competir contra <a title="Facebook" href="http://www.facebook.com/">Facebook</a> y <a title="Twitter" href="http://twitter.com/">Twitter</a>. He de confesar que el servicio no es mala idea, ya que integra de forma cómoda <a title="Gmail" href="http://www.gmail.com">Gmail</a> con <a title="Google Maps" href="http://maps.google.com">Google Maps</a> desde el PC o incluso desde el móvil <a title="Android" href="http://www.android.com/">Android</a> y otros dispositivos.</p>
<p>Pero desde el punto de vista de la privacidad Google Buzz tiene grandes fallos y debería aprender de la competencia como Facebook, que ha mejorado bastante en estos temas.</p>
<p>Algunas de las cuestiones que me preocupan y mucho del uso de Buzz son:</p>
<ol>
<li>Por defecto en tu página principal de Buzz te salen amigos que les haces seguimiento sin haberlo definido.</li>
<li>Por defecto cuando publicas en Buzz todo el mundo lo puede ver!</li>
<li>Tus mensajes en Buzz aparecen en Google Maps indicando nombre y lugar, incluso la calle, con lo que estás indicando tu posición real.</li>
<li>Por defecto puedo ver a quiénes siguen mis amigos y quiénes siguen a mis amigos.</li>
</ol>
<p>El punto 3 es realmente preocupante ya que se va a poder seguir físicamente a una persona con cualquier finalidad! Estoy seguro que irán apareciendo más cuestiones de privacidad y seguridad en breve, por lo que desde CyberSpace Insecurity les seguiremos la pista y os mantendremos informados <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>Y tú que piensas sobre Buzz?</strong></p>
<p><span style="color:#993300;"><strong>Update  02/18/10:</strong> Just a matter of time, 1)<a title="Buzz vulnerability" href="http://ha.ckers.org/blog/20100216/google-buzz-security-flaw/"> Buzz vulnerability</a> and 2) <a title="EPIC" href="http://epic.org/2010/02/epic-urges-federal-trade-commi.html">EPIC</a> complains regarding Buzz privacy.</span></p>
<p><em><span style="color:#993300;">Virtually everyone at this stage has heard of the new <a title="Google" href="http://www.google.com">Google</a> service called <a title="Buzz" href="http://www.google.com/buzz">Buzz</a> released last week to compete against <a title="Facebook" href="http://www.facebook.com/">Facebook</a> and <a title="Twitter" href="http://twitter.com/">Twitter</a>. I must confess that the service is not a bad idea since it integrates <a title="Gmail" href="http://www.gmail.com">Gmail</a> and <a title="Google Maps" href="http://maps.google.com">Google Maps</a> from your PC or even from the <a title="Android" href="http://www.android.com/">Android</a> mobile and other devices.</span></em></p>
<p><em><span style="color:#993300;">But from the point of view of privacy Google has done some big mistakes and should learn from competitors such as Facebook that has improved on these issues.</span></em></p>
<p><em><span style="color:#993300;">Some of the issues that seriously concern me about the use of Buzz are:</span></em></p>
<ol>
<li><em><span style="color:#993300;">By default on your Buzz homepage you are following your friends without explicitly configuring it.</span></em></li>
<li><em><span style="color:#993300;">By default posting on Buzz is public. Everybody can see it!</span></em></li>
<li><em><span style="color:#993300;">Your Buzz messages appear in Google Maps indicating name and location, even the street, indicating your real spot.</span></em></li>
<li><em><span style="color:#993300;">By default I can see my friends’ followers and who they follow.</span></em></li>
</ol>
<p><em><span style="color:#993300;">Point 3 is really worrying as you can follow physically a person to who knows what! I am sure more issues of privacy and security will appear shortly but from CyberSpace Insecurity we will   continue to track them and keep you posted <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></em></p>
<p><span style="color:#993300;"><strong>And what do you think about Buzz?</strong></span></p>
<p>&#8211; SRF</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/165/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/165/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/165/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=165&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/02/15/privacy-concerns-on-google-buzz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>
	</item>
		<item>
		<title>Nessus 4.2 Visual Tutorial</title>
		<link>http://cyberinsec.wordpress.com/2010/02/02/nessus-4-2-visual-tutorial/</link>
		<comments>http://cyberinsec.wordpress.com/2010/02/02/nessus-4-2-visual-tutorial/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 21:15:53 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=65</guid>
		<description><![CDATA[Como muchos ya sabréis Tenable Network Security ha lanzado la nueva versión de Nessus 4.2, un potente scanner de vulnerabilidades con las siguientes mejoras: La instalación en Windows es más sencilla. El cliente es una aplicación basada en flash que comunica con el Nessus servidor Web y es totalmente intuitiva. Mejora del rendimiento del scanner, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=65&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Como muchos ya sabréis <a title="Tenable Network Security" href="http://www.tenablesecurity.com">Tenable Network Security</a> ha lanzado la nueva versión de Nessus 4.2, un potente scanner de vulnerabilidades con las siguientes mejoras:</p>
<ul>
<li>La instalación en Windows es más sencilla.</li>
<li>El cliente es una aplicación basada en flash que comunica con el Nessus servidor Web y es totalmente intuitiva.</li>
<li>Mejora del rendimiento del scanner, mayor velocidad y estabilidad.</li>
<li>Más de 33000 plugins para todo tipo de vulnerabilidades (Windows, Linux, Web, etc.)</li>
<li>Los informes son mucho más cómodos de leer. (Truco: Excel 2007 lee sin problemas el formato .nessus basado en XML que facilita el parsing <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ul>
<p>Os dejo el tutorial visual para hacer un escaneo a un equipo WinXP con la nueva versión de Nessus <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><em><span style="color:#993300;">As you may already know </span></em><a title="Tenable Network Security" href="http://www.tenablesecurity.com"><em><span style="color:#993300;">Tenable Network Security</span></em></a><em><span style="color:#993300;"> has released the new version of Nessus 4.2, a powerful vulnerability scanner, with noticeable improvements such as:</span></em></p>
<ul>
<li><em><span style="color:#993300;">Installing Nessus on Windows is simpler.</span></em></li>
<li><em><span style="color:#993300;">The client is a flash app that communicates with the Nessus Web Server and is totally intuitive.</span></em></li>
<li><em><span style="color:#993300;">Improved performance of the scanner with greater speed and stability.</span></em></li>
<li><em><span style="color:#993300;">More than 33000 plugins for all kinds of vulnerabilities (Windows, Linux, Web, etc.)</span></em></li>
<li><em><span style="color:#993300;">Reports are much more comfortable to read. (Trick: Excel 2007 reads smoothly the .nessus XML-based format for easy parsing <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></em></li>
</ul>
<p><em><span style="color:#993300;">Let’s run a scan of a WinXP machine with the new version of Nessus through the following visual tutorial <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </span></em></p>
<p>1)</p>
<p>Realizar un login con la cuenta que hayamos creado. Nota: El navegador nos dará un aviso de seguridad sobre certificado pero podemos continuar.</p>
<p><span style="color:#993300;"><em>Let’s login with the account we created. Note: The browser will warning us about the certificate but we can continue.</em></span></p>
<p> <a href="http://cyberinsec.files.wordpress.com/2010/02/nessus114.jpg"><img class="alignnone size-medium wp-image-131" title="nessus1" src="http://cyberinsec.files.wordpress.com/2010/02/nessus114.jpg?w=300&#038;h=206" alt="nessus1" width="300" height="206" /></a></p>
<p>2)</p>
<p>Creamos una política de escaneo. (Policies -&gt; Add)</p>
<p><span style="color:#993300;"><em>Let’s create scan policy. (Policies -&gt; Add)</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus24.jpg"><img class="alignnone size-medium wp-image-134" title="nessus2" src="http://cyberinsec.files.wordpress.com/2010/02/nessus24.jpg?w=300&#038;h=205" alt="nessus2" width="300" height="205" /></a></p>
<p>3)</p>
<p>Rellenamos el nombre de la política y las opciones que nos interesen. “Safe Checks” impide que se ejecuten aquellos ataques peligrosos para el sistema ideal para escaneos en servidores. Si nos ponemos encima de cualquier opción con el puntero del ratón nos saldrá una ventana de información sobre qué hace la opción.</p>
<p><span style="color:#993300;"><em>Fill the policy name and options that interest us. &#8220;Safe Checks&#8221; prevents running those attacks that pose danger to the system ideal for server scans. If we hover on top of any option with the mouse pointer an information window will show up regarding what that option does.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus34.jpg"><img class="alignnone size-medium wp-image-135" title="nessus3" src="http://cyberinsec.files.wordpress.com/2010/02/nessus34.jpg?w=300&#038;h=205" alt="nessus3" width="300" height="205" /></a></p>
<p>4)</p>
<p>En el siguiente apartado introducimos las credenciales. En mi caso he metido una cuenta administrador Windows para ejecutar escaneos locales a través de SMB. Igualmente podemos meter credenciales para otros protocolos como SSH, base de datos, Telnet, etc.</p>
<p><span style="color:#993300;"><em>In the following section we introduce credentials. In my case I got a windows administrator account to run local scans over SMB. We can also set credentials for other protocols such as SSH, databases, Telnet, etc.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus44.jpg"><img class="alignnone size-medium wp-image-136" title="nessus4" src="http://cyberinsec.files.wordpress.com/2010/02/nessus44.jpg?w=300&#038;h=206" alt="nessus4" width="300" height="206" /></a></p>
<p>5)</p>
<p>Seleccionamos los plugins que nos interesan aunque podemos dejar todos activados, ya que Nessus es lo suficiente inteligente para ejecutar aquellos que apliquen al sistema.</p>
<p><span style="color:#993300;"><em>Select those plugins that interest us but we can enable all since Nessus is sufficiently intelligent to run those which apply to the system only.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus54.jpg"><img class="alignnone size-medium wp-image-137" title="nessus5" src="http://cyberinsec.files.wordpress.com/2010/02/nessus54.jpg?w=300&#038;h=205" alt="nessus5" width="300" height="205" /></a></p>
<p>6)</p>
<p>A continuación podemos configurar multitud de parámetros del escaneo como HTTP, Windows, Web, etc. para hacerlo más efectivo. Esto requiere un conocimiento avanzado para conseguir máxima efectividad.</p>
<p><span style="color:#993300;"><em>We can then configure the scan parameters such as HTTP, Windows, Web, etc. to make the scanning more effective. This requires advanced knowledge to maximize the benefits.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus63.jpg"><img class="alignnone size-medium wp-image-139" title="nessus6" src="http://cyberinsec.files.wordpress.com/2010/02/nessus63.jpg?w=300&#038;h=205" alt="nessus6" width="300" height="205" /></a></p>
<p>7)</p>
<p>Ahora ya tenemos una política de escaneo lista y podemos empezar el escaneo pinchando en Scans.</p>
<p><span style="color:#993300;"><em>Now we have our policy scan ready and we can begin scanning by clicking on Scans.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus73.jpg"><img class="alignnone size-medium wp-image-140" title="nessus7" src="http://cyberinsec.files.wordpress.com/2010/02/nessus73.jpg?w=300&#038;h=206" alt="nessus7" width="300" height="206" /></a></p>
<p> <img src='http://s0.wp.com/wp-includes/images/smilies/icon_cool.gif' alt='8)' class='wp-smiley' /> </p>
<p>Rellenamos el nombre del escaneo, seleccionamos la política de escaneo en nuestro caso “xp” y los sistemas. Para los sistemas podemos meter directamente los nombres o IPs de las máquinas o leerlos desde un fichero en formato texto mediante la opción “Target File”. Una vez listos pinchamos en Launch Scan.</p>
<p><span style="color:#993300;"><em>Fill the name of the scan and select the scan policy in our case &#8220;xp&#8221;. For entering systems we can directly write the names or IPs of the machines or read them from a file in text format using the &#8220;Target File&#8221; option. Once ready click on Launch Scan.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus82.jpg"><img class="alignnone size-medium wp-image-141" title="nessus8" src="http://cyberinsec.files.wordpress.com/2010/02/nessus82.jpg?w=300&#038;h=205" alt="nessus8" width="300" height="205" /></a></p>
<p>9)</p>
<p>El escaneo ha comenzado y ahora a esperar <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style="color:#993300;"><em>The scan has begun and now we have to wait <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus92.jpg"><img class="alignnone size-medium wp-image-142" title="nessus9" src="http://cyberinsec.files.wordpress.com/2010/02/nessus92.jpg?w=300&#038;h=205" alt="nessus9" width="300" height="205" /></a></p>
<p>10)</p>
<p>El escaneo ha terminado en 4 minutos porque la máquina era local, y podemos ver los resultados pinchando en Reports.</p>
<p><span style="color:#993300;"><em> The scan has finished in 4 minutes, was localhost, and we can see the results by going to Reports.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus102.jpg"><img class="alignnone size-medium wp-image-145" title="nessus10" src="http://cyberinsec.files.wordpress.com/2010/02/nessus102.jpg?w=300&#038;h=205" alt="nessus10" width="300" height="205" /></a></p>
<p>11)</p>
<p>Abrimos el informe y podemos ver un sumario de los resultados como número de máquinas, vulnerabilidades y puertos.  Para ver los detalles pinchamos encima de una máquina.</p>
<p><span style="color:#993300;"><em>When opening the report we can see a summary of the results such as number of machines, vulnerabilities and ports.  To view more details click on a system.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus115.jpg"><img class="alignnone size-medium wp-image-146" title="nessus11" src="http://cyberinsec.files.wordpress.com/2010/02/nessus115.jpg?w=300&#038;h=204" alt="nessus11" width="300" height="204" /></a></p>
<p>12)</p>
<p>Podemos ver los puertos y las vulnerabilidades asociadas de nuestra máquina escaneada. Pinchando encima del puerto veremos más detalles.</p>
<p><span style="color:#993300;"><em>We can see the ports and the associated vulnerabilities of the scanned system. By clicking on top of a port we will see more details.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus123.jpg"><img class="alignnone size-medium wp-image-147" title="nessus12" src="http://cyberinsec.files.wordpress.com/2010/02/nessus123.jpg?w=300&#038;h=205" alt="nessus12" width="300" height="205" /></a></p>
<p>13)</p>
<p>Podemos apreciar la cantidad de vulnerabilidades, muchas de ellas de una criticidad alta. Estos resultados fueron obtenidos por las credenciales del punto 4 por lo que siempre es recomendable realizar el escaneo con credenciales de administrador.</p>
<p><span style="color:#993300;"><em> We can see a lot of vulnerabilities, many highly critical. These results were obtained from the steps 4 to enter credentials, and that is why it is always recommended to do the scanning with administrator credentials.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus133.jpg"><img class="alignnone size-medium wp-image-148" title="nessus13" src="http://cyberinsec.files.wordpress.com/2010/02/nessus133.jpg?w=300&#038;h=205" alt="nessus13" width="300" height="205" /></a></p>
<p>14)</p>
<p>Hemos seleccionado una vulnerabilidad crítica para ver más en detalle donde se nos explica impacto y solución además de enlaces externos donde encontrar más información. Nota: La barra multicolor (azul, rojo y amarillo) abajo nos permite pinchar sobre ella para desplazarnos cómodamente por las vulnerabilidades.</p>
<p><span style="color:#993300;"><em>We have selected a critical vulnerability to view more details where impact and solution are explained apart from external links where to find more information. Note: the multi-colored bar (blue, red and yellow) below allows us to click it to move around the vulnerabilities more comfortably.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus142.jpg"><img class="alignnone size-medium wp-image-149" title="nessus14" src="http://cyberinsec.files.wordpress.com/2010/02/nessus142.jpg?w=300&#038;h=206" alt="nessus14" width="300" height="206" /></a></p>
<p>15)</p>
<p>Ahora si queremos podemos generar un informe en algún formato de los disponibles por Nessus (HTML, .nessus basado en XML o NBE) Recordad que para el formato .nessus Excel 2007 es vuestro amigo <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style="color:#993300;"><em>Now if we want we can generate a report in some format available by Nessus (.nessus based on XML, NBE or HTML) remember that for .nessus format Excel 2007 is your friend <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus152.jpg"><img class="alignnone size-medium wp-image-150" title="nessus15" src="http://cyberinsec.files.wordpress.com/2010/02/nessus152.jpg?w=300&#038;h=205" alt="nessus15" width="300" height="205" /></a></p>
<p>16)</p>
<p>Informe en HTML.</p>
<p><span style="color:#993300;"><em>HTML report.</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus162.jpg"><img class="alignnone size-medium wp-image-151" title="nessus16" src="http://cyberinsec.files.wordpress.com/2010/02/nessus162.jpg?w=300&#038;h=205" alt="nessus16" width="300" height="205" /></a></p>
<p>17)</p>
<p>Y eso es todo amigos!</p>
<p><span style="color:#993300;"><em>And that’s all folks!</em></span></p>
<p><a href="http://cyberinsec.files.wordpress.com/2010/02/nessus172.jpg"><img class="alignnone size-medium wp-image-152" title="nessus17" src="http://cyberinsec.files.wordpress.com/2010/02/nessus172.jpg?w=300&#038;h=205" alt="nessus17" width="300" height="205" /></a></p>
<p>Como podéis ver realizar un escaneo mediante el nuevo Nessus es fácil e intuitivo y es una herramienta recomendada para cualquier profesional de la seguridad. En futures posts os contaré usos más avanzados de Nessus.</p>
<p>Los informes que genera son mejorables, pero nada es perfecto <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Existe una versión open source alternativa llamada <a title="OpenVAS" href="http://www.openvas.org/">OpenVAS</a> pero recibes lo que das <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><strong>¿Qué os ha parecido? ¿Cuál es vuestro escáner de vulnerabilidades favorito?</strong></p>
<p><span style="color:#993300;"><em>As you can see performing a scan through the new Nessus is easy and intuitive and is a recommended tool for any security professional. In future posts I will show you more advanced uses of Nessus.</em></span></p>
<p><span style="color:#993300;"><em>The generated reports could be better, but nothing is perfect <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></span></p>
<p><span style="color:#993300;"><em>There is an open source alternative called </em></span><a title="OpenVAS" href="http://www.openvas.org/"><span style="color:#993300;"><em>OpenVAS</em></span></a><span style="color:#993300;"><em> but you get what you give <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </em></span></p>
<p><span style="color:#993300;"><em><strong>What are your thoughts on this? What is your favorite vulnerability scanner?</strong></em></span></p>
<p>&#8211; SRF</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/65/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=65&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/02/02/nessus-4-2-visual-tutorial/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus114.jpg?w=300" medium="image">
			<media:title type="html">nessus1</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus24.jpg?w=300" medium="image">
			<media:title type="html">nessus2</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus34.jpg?w=300" medium="image">
			<media:title type="html">nessus3</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus44.jpg?w=300" medium="image">
			<media:title type="html">nessus4</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus54.jpg?w=300" medium="image">
			<media:title type="html">nessus5</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus63.jpg?w=300" medium="image">
			<media:title type="html">nessus6</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus73.jpg?w=300" medium="image">
			<media:title type="html">nessus7</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus82.jpg?w=300" medium="image">
			<media:title type="html">nessus8</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus92.jpg?w=300" medium="image">
			<media:title type="html">nessus9</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus102.jpg?w=300" medium="image">
			<media:title type="html">nessus10</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus115.jpg?w=300" medium="image">
			<media:title type="html">nessus11</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus123.jpg?w=300" medium="image">
			<media:title type="html">nessus12</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus133.jpg?w=300" medium="image">
			<media:title type="html">nessus13</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus142.jpg?w=300" medium="image">
			<media:title type="html">nessus14</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus152.jpg?w=300" medium="image">
			<media:title type="html">nessus15</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus162.jpg?w=300" medium="image">
			<media:title type="html">nessus16</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2010/02/nessus172.jpg?w=300" medium="image">
			<media:title type="html">nessus17</media:title>
		</media:content>
	</item>
		<item>
		<title>Blast from the past: my security presentations</title>
		<link>http://cyberinsec.wordpress.com/2010/01/12/blast-from-the-past-my-security-presentations/</link>
		<comments>http://cyberinsec.wordpress.com/2010/01/12/blast-from-the-past-my-security-presentations/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 17:49:59 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=60</guid>
		<description><![CDATA[He recopilado muchas de mis presentaciones públicas durante los años que espero sean de vuestro interés ———————————————————————————————————————————————– I have collected many of my public presentations during the years and I hope you would like them Microsoft Infosec Team: Security Tools Roadmap (IBWAS 09. Madrid, Spain. 2009)http://www.ibwas.com/files/presentations/Simon_Roses_MS_INFOSEC_IBWAS09.pdf Microsoft Seguridad IT al descubierto (OWASP Spain. Barcelona, Spain. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=60&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>He recopilado muchas de mis presentaciones públicas durante los años que espero sean de vuestro interés <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>———————————————————————————————————————————————–</p>
<p><span style="color:#993300;"><em>I have collected many of my public presentations during the years and I hope you would like them <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></span></p>
<ul>
<li>Microsoft Infosec Team: Security Tools Roadmap (IBWAS 09. Madrid, Spain. 2009)<a title="http://www.ibwas.com/files/presentations/Simon_Roses_MS_INFOSEC_IBWAS09.pdf" href="http://www.ibwas.com/files/presentations/Simon_Roses_MS_INFOSEC_IBWAS09.pdf">http://www.ibwas.com/files/presentations/Simon_Roses_MS_INFOSEC_IBWAS09.pdf</a></li>
<li>Microsoft Seguridad IT al descubierto (OWASP Spain. Barcelona, Spain. 2008<br />
<a title="https://www.owasp.org/images/c/c7/MS_SDL_IT_ProtegiendoElNegocio.pdf" href="https://www.owasp.org/images/c/c7/MS_SDL_IT_ProtegiendoElNegocio.pdf">https://www.owasp.org/images/c/c7/MS_SDL_IT_ProtegiendoElNegocio.pdf</a></li>
<li> OWASP Pantera  Unleash (OWASP Day. Belgium. 2007)<a title="http://www.owasp.org/images/f/f4/OWASPDay2007Belgium_Pantera_Unleash.ppt" href="http://www.owasp.org/images/f/f4/OWASPDay2007Belgium_Pantera_Unleash.ppt">http://www.owasp.org/images/f/f4/OWASPDay2007Belgium_Pantera_Unleash.ppt</a></li>
<li> OWASP PANTERA – Dissecting Web Applications (OWASP AppSec 2007. Milan, Italy. 2007)<br />
 <a title="http://www.owasp.org/images/0/00/OWASPAppSec2007Milan_Pantera.ppt" href="http://www.owasp.org/images/0/00/OWASPAppSec2007Milan_Pantera.ppt">http://www.owasp.org/images/0/00/OWASPAppSec2007Milan_Pantera.ppt</a></li>
<li>Microsoft ACE Team – Application Security from the Core (OWASP AppSec 2007, Milan, Italy. 2007)<a title="http://www.owasp.org/images/8/8d/OWASPAppSec2007Milan_MS_ACETeamAppSecfromTheCore.ppt" href="http://www.owasp.org/images/8/8d/OWASPAppSec2007Milan_MS_ACETeamAppSecfromTheCore.ppt">http://www.owasp.org/images/8/8d/OWASPAppSec2007Milan_MS_ACETeamAppSecfromTheCore.ppt</a></li>
<li>MS ACE Team &#8211; Seguridad en el Código (SDL-IT) (Madrid, Spain, 2007)<a title="http://download.microsoft.com/download/9/e/7/9e76ad03-f690-42e8-be4f-25af5a372417/6_Mejores_practicas_para_el_desarrollo_seguro.ppt" href="http://download.microsoft.com/download/9/e/7/9e76ad03-f690-42e8-be4f-25af5a372417/6_Mejores_practicas_para_el_desarrollo_seguro.ppt">http://download.microsoft.com/download/9/e/7/9e76ad03-f690-42e8-be4f-25af5a372417/6_Mejores_practicas_para_el_desarrollo_seguro.ppt</a></li>
<li>Carmen, Rogue Web Server (DeepSec 2007)<br />
<a href="http://video.google.com/videoplay?docid=-1362446912192581498">http://video.google.com/videoplay?docid=-1362446912192581498</a></li>
<li>Introduccion al Fuzzer (Madrid, SpaiN. 2004)<br />
<a title="http://www.roseslabs.com/innovations/RL_FuzzerIntro.pdf " href="http://www.roseslabs.com/innovations/RL_FuzzerIntro.pdf">http://www.roseslabs.com/innovations/RL_FuzzerIntro.pdf<span id="_marker"> </span></a></li>
</ul>
<p class="MsoNormal" style="margin:0 0 10pt;"><span style="line-height:115%;font-family:&amp;" lang="EN-US">&#8211; SRF</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=60&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/01/12/blast-from-the-past-my-security-presentations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>
	</item>
		<item>
		<title>www.eu2010.es $ecurity $candal (aka $pain is Different)</title>
		<link>http://cyberinsec.wordpress.com/2010/01/05/www-eu2010-es-ecurity-candal-aka-pain-is-different/</link>
		<comments>http://cyberinsec.wordpress.com/2010/01/05/www-eu2010-es-ecurity-candal-aka-pain-is-different/#comments</comments>
		<pubDate>Tue, 05 Jan 2010 09:40:37 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=56</guid>
		<description><![CDATA[España desde el 1 de Enero es la encargada de la Presidencia de la EU durante los próximos 6 meses y con este fin se ha creado un portal www.eu2010.es que se anuncio a bombo y platillo en todos los medios. El escándalo salto ayer, 4 días de la publicación de la web, cuando un [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=56&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>España desde el 1 de Enero es la encargada de la Presidencia de la EU durante los próximos 6 meses y con este fin se ha creado un portal <a href="http://www.eu2010.es/">www.eu2010.es</a> que se anuncio a bombo y platillo en todos los medios.</p>
<p>El escándalo salto ayer, 4 días de la publicación de la web, cuando un atacante identifico una vulnerabilidad de Cross-Site Scripting (XSS) permitiéndole inyectar código en el motor de búsqueda de la web. Dicho código colocaba una foto de Mr. Bean.</p>
<p>Si bien es cierto que esta vulnerabilidad tiene una criticidad baja a  mí entender existen otros problemas:</p>
<ol>
<li>Las vulnerabilidades XSS no deben ser infravaloras ya que permiten realizar ataques mucho más sofisticados que atacar el navegador del cliente.</li>
<li>Este evento es un claro ejemplo que no por usar soluciones Open Source se es más seguro automáticamente. La seguridad es un proceso y por eso tenemos metodologías como MS SDL y OWASP CLASP.</li>
<li>Enlazando con el punto 2 un WAF podría haberles salvado el mal trago y en la línea Open Source tenemos el ModSecurity.</li>
</ol>
<p>Como no podía ser de otra manera el Gobierno niega que el portal haya sido “hackeado” y en cierta manera tiene razón aunque no debemos olvidar que si existía una vulnerabilidad que no debería haber sucedido en primer lugar.  </p>
<p>Este ataque XSS  es más anecdótico que otra cosa pero el verdadero escándalo que ha destapado este evento es el alto coste de soporte técnico y seguridad que el Gobierno ha pagado a Telefónica: 11,9 millones de Euros.</p>
<p>Sorprende la desorbitada cifra para un portal con una duración de 6 meses y utilizando soluciones Open Source. Esto sí que es un verdadero escándalo y una vergüenza.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p><span style="color:#993300;"><em>Spain starting January 1 is in charge of the Presidency of the EU during the next 6 months and for this purpose the portal </em></span><a href="http://www.eu2010.es/"><span style="color:#993300;"><em>www.eu2010.es</em></span></a><span style="color:#993300;"><em> was created and announced in all media.</em></span></p>
<p><span style="color:#993300;"><em>The scandal jumped yesterday, 4 days after the publication of the web, when an attacker identify a vulnerability of Cross-site Scripting (XSS) allowing to inject code into the web search engine. That code placed a photo of Mr. Bean.</em></span></p>
<p><span style="color:#993300;"><em>While it is true that this vulnerability has a low criticality there are other problems:</em></span></p>
<ol>
<li><span style="color:#993300;"><em>XSS vulnerabilities should not be underestimated as they allow performing more sophisticated attacks that just attacking the client browser.</em></span></li>
<li><span style="color:#993300;"><em>This event is a clear example that using Open Source solutions is not more secure automatically. Security is a process and therefore we have methodologies such as MS SDL and OWASP CLASP.</em></span></li>
<li><span style="color:#993300;"><em>Linking with point 2 a WAF could have safe them some troubles and keeping with Open Source we have ModSecurity.</em></span></li>
</ol>
<p><span style="color:#993300;"><em>It could not be otherwise the Government denies that the portal has been &#8220;hacked&#8221; and somehow is right but we must not forget that there was a vulnerability that should not have happened in the first place. </em></span></p>
<p><span style="color:#993300;"><em>This XSS attack is more anecdotal than anything else but the real scandal this event has uncovered is the high cost of technical support and security that the Government has paid to Telefónica: 11.9 million Euros.</em></span></p>
<p><span style="color:#993300;"><em>Is surprising the huge figure for a portal with a duration of 6 months and using Open Source solutions. This is scandalous and disgraceful.</em></span></p>
<ul>
<li><a href="http://www.eu2010.es/">http://www.eu2010.es</a></li>
<li><a href="http://www.mpr.es/ServiciosCiudadano/LicitacionesYContratosPublicos/201042.htm">http://www.mpr.es/ServiciosCiudadano/LicitacionesYContratosPublicos/201042.htm</a></li>
<li><a href="http://msdn.microsoft.com/en-us/security/cc448177.aspx">http://msdn.microsoft.com/en-us/security/cc448177.aspx</a></li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_CLASP_Project">http://www.owasp.org/index.php/Category:OWASP_CLASP_Project</a></li>
<li><a href="http://www.modsecurity.org/">http://www.modsecurity.org/</a></li>
</ul>
<p>&#8211; SRF</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=56&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/01/05/www-eu2010-es-ecurity-candal-aka-pain-is-different/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>
	</item>
		<item>
		<title>XMAS Hangover and 2010 Roadmap</title>
		<link>http://cyberinsec.wordpress.com/2010/01/04/xmas-hangover-and-2010-roadmap/</link>
		<comments>http://cyberinsec.wordpress.com/2010/01/04/xmas-hangover-and-2010-roadmap/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 08:25:19 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=53</guid>
		<description><![CDATA[Querido lectores desearos un prospero 2010 y espero que hayáis tenido unas buenas fiestas y ya estéis recuperados Para 2010 desde CyberSpace Insecurity 2.X esperamos traeros post innovadores sobre los temas que nos interesan. Feliz 2010 Dear readers I want to wish you a prosper 2010 and I hope you have had good holydays and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=53&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Querido lectores desearos un prospero 2010 y espero que hayáis tenido unas buenas fiestas y ya estéis recuperados <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Para 2010 desde CyberSpace Insecurity 2.X esperamos traeros post innovadores sobre los temas que nos interesan.</p>
<p>Feliz 2010</p>
<p><span style="color:#993300;"><em>Dear readers I want to wish you a prosper 2010 and I hope you have had good holydays and have already recover <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </em></span></p>
<p><span style="color:#993300;"><em>By 2010 from CyberSpace Insecurity 2.X we hope to bring innovator posts on topics that interest us</em></span></p>
<p><span style="color:#993300;"><em>Happy 2010</em></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=53&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2010/01/04/xmas-hangover-and-2010-roadmap/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>
	</item>
		<item>
		<title>Network Authentication Cracking at speed of light</title>
		<link>http://cyberinsec.wordpress.com/2009/12/17/network-authentication-cracking-at-speed-of-light/</link>
		<comments>http://cyberinsec.wordpress.com/2009/12/17/network-authentication-cracking-at-speed-of-light/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 17:21:46 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=48</guid>
		<description><![CDATA[ES: Las viejas técnicas nunca mueran y ataques de fuerza bruta contra autenticación de red no es ningún excepción.  Desde hace años existen este tipo de herramientas como pueden ser Brutus y HTC Hydra además es bien sabido que los “malos” han desarrollado sistemas masivos para realizar estos ataques en Internet a gran escala. Ahora [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=48&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>ES:</strong> Las viejas técnicas nunca mueran y ataques de fuerza bruta contra autenticación de red no es ningún excepción.  Desde hace años existen este tipo de herramientas como pueden ser Brutus y HTC Hydra además es bien sabido que los “malos” han desarrollado sistemas masivos para realizar estos ataques en Internet a gran escala.</p>
<p>Ahora tenemos una nueva e interesante herramienta llamada Ncrack desarrollada por ithilgore y Fyodor el autor de Nmap. Es por eso que Ncrack sigue la misma línea que Nmap a lo que interface y comandos se refiere y nos permite realizar ataques de fuerza bruta a una velocidad de vértigo!!!</p>
<p>Por el momento está limitado a pocos protocolos como son Telnet, FTP, HTTP Basic y SSH pero son un buen comienzo <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Además de la velocidad tiene otras características interesantes como son:</p>
<ul>
<li>Salva la sesión y poder continuar en otro momento</li>
<li>Compatibilidad con Nmap</li>
<li>Trae unas listas de las contraseñas más comunes</li>
<li>Fácil desarrollar nuevos protocolos</li>
</ul>
<p>Examinando los listados de contraseñas podemos ver las típicas y contraseñas reales basadas en “hackeos” de myspace, phpbb y Hotmail.  Tranquilo que mis contraseñas no están <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Desde luego una herramienta para tener en la caja de herramientas cuando tengas que realizar un test de intrusión.</p>
<p><a title="Ncrack" href="http://nmap.org/ncrack/">Ncrack</a></p>
<p><strong> US:</strong> Old techniques never die and brute-force against network authentication is no exception.  For years there have been such tools as Brutus and HTC Hydra and is well known that the &#8220;bad guys&#8221; have developed massive systems to perform these attacks on Internet at a large-scale.</p>
<p>We now have an exciting new tool called Ncrack developed by ithilgore and Fyodor Nmap’s author. This is why Ncrack follows the same style as Nmap regarding interface and commands and allows us to perform brute-force attacks at a speed of light!!!</p>
<p>Is currently limited to few protocols such as Telnet, FTP, HTTP Basic, and SSH but is a good starting point <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>In addition to the speed it has other interesting features such as:</p>
<p>• Saves session and continues at a later time</p>
<p>• Support for Nmap</p>
<p>• Brings a few lists of common passwords</p>
<p>• Easy to develop new protocols</p>
<p>Examining the password listings we can see common and real passwords based on 0wned of myspace, phpbb and Hotmail.  Don’t worry my passwords are not in the lists <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Truly a tool to have in the Toolbox when you have to perform a pen testing.</p>
<p><a title="Ncrack" href="http://nmap.org/ncrack/">Ncrack</a></p>

<a href='http://cyberinsec.wordpress.com/2009/12/17/network-authentication-cracking-at-speed-of-light/ncrack_action/' title='Ncrack in Action'><img data-attachment-id='49' data-orig-size='1280,769' data-liked='0'width="150" height="90" src="http://cyberinsec.files.wordpress.com/2009/12/ncrack_action.jpg?w=150&#038;h=90" class="attachment-thumbnail" alt="Ncrack in Action" title="Ncrack in Action" /></a>
<a href='http://cyberinsec.wordpress.com/2009/12/17/network-authentication-cracking-at-speed-of-light/ncrack_pwds/' title='Ncrack Password List'><img data-attachment-id='50' data-orig-size='1057,432' data-liked='0'width="150" height="61" src="http://cyberinsec.files.wordpress.com/2009/12/ncrack_pwds.jpg?w=150&#038;h=61" class="attachment-thumbnail" alt="Ncrack Password List" title="Ncrack Password List" /></a>

<p>&#8211; SRF</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/48/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=48&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2009/12/17/network-authentication-cracking-at-speed-of-light/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2009/12/ncrack_action.jpg?w=150" medium="image">
			<media:title type="html">Ncrack in Action</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2009/12/ncrack_pwds.jpg?w=150" medium="image">
			<media:title type="html">Ncrack Password List</media:title>
		</media:content>
	</item>
		<item>
		<title>Snow, Technology Failures on the Road and what else!</title>
		<link>http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/</link>
		<comments>http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 08:49:24 +0000</pubDate>
		<dc:creator>SRF</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cyberinsec.wordpress.com/?p=36</guid>
		<description><![CDATA[ESP: Me acabo de levantar y al asomarme por la ventana veo nieve! Desde luego que viste las navidades aunque en Madrid no pasara de un día nevado. Durante mis viajes me suelo encontrar mensajes de errores en las pantallas de información de sistemas informáticos y por regla siempre saco una foto lo que llamo [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=36&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>ESP:</strong> Me acabo de levantar y al asomarme por la ventana veo nieve! Desde luego que viste las navidades aunque en Madrid no pasara de un día nevado.</p>
<p>Durante mis viajes me suelo encontrar mensajes de errores en las pantallas de información de sistemas informáticos y por regla siempre saco una foto lo que llamo “Documentando Errores en la Tecnología Diaria”. Las fotos son un buen ejemplo que ningún sistema es infalible ya sea Windows o Linux y todavía queda mucho por hacer. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>US:</strong> I just did wake up and looked out of the window and can see snow! Certainly dresses the Christmas but in Madrid should not last more than a day.  </p>
<p>During my travels I usually find error messages on the screens of computer systems and my rule is to always take a photo what I call &#8220;Daily Technology Errors Documentary&#8221;.  These photos are good examples that any system is not foolproof either Windows or Linux and much remains to be done. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="mceTemp">

<a href='http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/a_deepsec_hotel_08-2/' title='DeepSec 08 Hotel System Crash 1'><img data-attachment-id='42' data-orig-size='600,480' data-liked='0'width="150" height="120" src="http://cyberinsec.files.wordpress.com/2009/12/a_deepsec_hotel_081.jpg?w=150&#038;h=120" class="attachment-thumbnail" alt="DeepSec 08 Hotel System Crash 1" title="DeepSec 08 Hotel System Crash 1" /></a>
<a href='http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/b_deepsec_hotel_08-2/' title='DeepSec 08 Hotel System Crash 2'><img data-attachment-id='43' data-orig-size='600,480' data-liked='0'width="150" height="120" src="http://cyberinsec.files.wordpress.com/2009/12/b_deepsec_hotel_081.jpg?w=150&#038;h=120" class="attachment-thumbnail" alt="DeepSec 08 Hotel System Crash 1" title="DeepSec 08 Hotel System Crash 2" /></a>
<a href='http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/heatrow_t3_09-2/' title='Heatrow T3 System Error'><img data-attachment-id='44' data-orig-size='600,480' data-liked='0'width="150" height="120" src="http://cyberinsec.files.wordpress.com/2009/12/heatrow_t3_091.jpg?w=150&#038;h=120" class="attachment-thumbnail" alt="Heatrow T3 System Error" title="Heatrow T3 System Error" /></a>
<a href='http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/2009-12-14-08-14-35-2/' title='Madrid Snow Day 14/12/09'><img data-attachment-id='41' data-orig-size='2048,1536' data-liked='0'width="150" height="112" src="http://cyberinsec.files.wordpress.com/2009/12/2009-12-14-08-14-351.jpg?w=150&#038;h=112" class="attachment-thumbnail" alt="Madrid Snow Day 14/12/09" title="Madrid Snow Day 14/12/09" /></a>

</div>
<p>&#8211; SRF</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cyberinsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cyberinsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cyberinsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cyberinsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cyberinsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cyberinsec.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cyberinsec.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cyberinsec.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cyberinsec.wordpress.com&amp;blog=10668786&amp;post=36&amp;subd=cyberinsec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cyberinsec.wordpress.com/2009/12/14/snow-technology-failures-on-the-road-and-what-else/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/cedff36a6032396ff3447e0afccd5ea1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">SRF</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2009/12/a_deepsec_hotel_081.jpg?w=150" medium="image">
			<media:title type="html">DeepSec 08 Hotel System Crash 1</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2009/12/b_deepsec_hotel_081.jpg?w=150" medium="image">
			<media:title type="html">DeepSec 08 Hotel System Crash 2</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2009/12/heatrow_t3_091.jpg?w=150" medium="image">
			<media:title type="html">Heatrow T3 System Error</media:title>
		</media:content>

		<media:content url="http://cyberinsec.files.wordpress.com/2009/12/2009-12-14-08-14-351.jpg?w=150" medium="image">
			<media:title type="html">Madrid Snow Day 14/12/09</media:title>
		</media:content>
	</item>
	</channel>
</rss>
