<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exploits and Security &#187; Q &amp; A</title>
	<atom:link href="http://www.exploitx.com/category/q-a/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.exploitx.com</link>
	<description>Technology &#38; Security Tips &#38; Guides</description>
	<lastBuildDate>Tue, 22 Dec 2009 03:28:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Testing of security of modems?</title>
		<link>http://www.exploitx.com/168/testing-of-security-of-modems/</link>
		<comments>http://www.exploitx.com/168/testing-of-security-of-modems/#comments</comments>
		<pubDate>Thu, 19 Jul 2007 00:25:35 +0000</pubDate>
		<dc:creator>Exploitx</dc:creator>
				<category><![CDATA[Q & A]]></category>

		<guid isPermaLink="false">http://www.exploitx.com/168/testing-of-security-of-modems/</guid>
		<description><![CDATA[Is there existing any methodology to test security of modems?
I am not asking about &#8220;war driving&#8221; (penetration testing of modem entry
points to the computer systems/networks) but testing of modems as devices?
What features shall one look for while assessing the security of modems
of various types (dial model, cable modem, DSL modem, GPRS modems, other
wireless modems, etc)?
Are [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Is there existing any methodology to test security of modems?</p>
<p>I am not asking about &#8220;war driving&#8221; (penetration testing of modem entry<br />
points to the computer systems/networks) but testing of modems as devices?</p>
<p>What features shall one look for while assessing the security of modems<br />
of various types (dial model, cable modem, DSL modem, GPRS modems, other<br />
wireless modems, etc)?</p>
<p>Are there any publicly accessible (or commercial) modem testing tools?</p>
<p>Thank you,<br />
John</p></blockquote>
<p>Passmark makes an inexpensive Windows based software test tool.</p>
<p><span id="more-168"></span></p>
<p>http://www.passmark.com/products/modemtst.htm</p>
<p>That would be &#8220;war dialing&#8221; hanging with the old school terminology.</p>
<p>One of the things you want to look for on modems is if they are set to<br />
&#8220;auto answer&#8221;.<br />
What applications are being used in conjunction with the modem and how<br />
are they configured.<br />
What authentication is being used by those applications (and how<br />
secure/reliable the authentication is).<br />
Also look to see if any encryption is being used. Keep in mind that<br />
all communication goes over POTS and the providers can monitor any<br />
line they want to at any time.<br />
What services are available over dial-up.</p>
<p><a href="http://www.google.com/search?aq=t&#038;oq=modem+security+tool&#038;hl=en&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;q=modem+security+tools&#038;btnG=Search">Google</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.exploitx.com/168/testing-of-security-of-modems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updating Live Security CD</title>
		<link>http://www.exploitx.com/165/updating-live-security-cd/</link>
		<comments>http://www.exploitx.com/165/updating-live-security-cd/#comments</comments>
		<pubDate>Thu, 19 Jul 2007 00:21:12 +0000</pubDate>
		<dc:creator>Exploitx</dc:creator>
				<category><![CDATA[Q & A]]></category>

		<guid isPermaLink="false">http://www.exploitx.com/165/updating-live-security-cd/</guid>
		<description><![CDATA[Say I want to add a few packages or updates to the latest Backtrack
LiveCD, such as Wireshark or Firefox 2, what is the best way to
accomplish that?
Is there a way to slipstream additional files onto the LiveCD, or can
I save changes onto a USB drive or something like that?
Any help would be greatly appreciated!
Best regards,
John
BackTrack [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Say I want to add a few packages or updates to the latest Backtrack<br />
LiveCD, such as Wireshark or Firefox 2, what is the best way to<br />
accomplish that?</p>
<p>Is there a way to slipstream additional files onto the LiveCD, or can<br />
I save changes onto a USB drive or something like that?</p>
<p>Any help would be greatly appreciated!</p>
<p>Best regards,<br />
John</p></blockquote>
<p>BackTrack is a distribution that was actually built to be modular (i.e. Add<br />
custom packages)</p>
<p><span id="more-165"></span><br />
All the details on how to do this can be found in the BackTrack wiki:</p>
<p>http://backtrack.offensive-security.com/index.php?title=Howto:Mod_Linux</p>
<p>Hope this gets you goin&#8217; in the right direction&#8230;</p>
<p>A new version is coming out shortly, you may not want to get too<br />
invested in updating your own copy until that one is out.  Probably a<br />
few weeks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exploitx.com/165/updating-live-security-cd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sql Injection and My Sql</title>
		<link>http://www.exploitx.com/161/sql-injection-and-my-sql/</link>
		<comments>http://www.exploitx.com/161/sql-injection-and-my-sql/#comments</comments>
		<pubDate>Sat, 03 Dec 2005 23:13:45 +0000</pubDate>
		<dc:creator>Exploitx</dc:creator>
				<category><![CDATA[Q & A]]></category>

		<guid isPermaLink="false">http://www.exploitx.com/161/sql-injection-and-my-sql/</guid>
		<description><![CDATA[Dear List,
I would like to know if there is any tutorial which describes sql injection in context of My Sql. I feel that the errors returned by mysql when performing a sql injection are less revealing then that returned by other DBs.
Thanks
404
- While it&#8217;s not DB specific, the paper &#8220;SQL Injection Attacks by Example&#8221;
by  [...]]]></description>
			<content:encoded><![CDATA[<p>Dear List,<br />
I would like to know if there is any tutorial which describes sql injection in context of My Sql. I feel that the errors returned by mysql when performing a sql injection are less revealing then that returned by other DBs.<br />
Thanks<br />
404</p>
<p>- While it&#8217;s not DB specific, the paper &#8220;SQL Injection Attacks by Example&#8221;<br />
by  Steve Friedl is a great introduction to this topic.</p>
<p>http://www.unixwiz.net/techtips/sql-injection.html</p>
<p>Regards,<br />
Jim Halfpenny</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exploitx.com/161/sql-injection-and-my-sql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blocking Limewire/P2P apps Upload Only</title>
		<link>http://www.exploitx.com/160/blocking-limewirep2p-apps-upload-only/</link>
		<comments>http://www.exploitx.com/160/blocking-limewirep2p-apps-upload-only/#comments</comments>
		<pubDate>Sat, 03 Dec 2005 23:12:49 +0000</pubDate>
		<dc:creator>Exploitx</dc:creator>
				<category><![CDATA[Q & A]]></category>

		<guid isPermaLink="false">http://www.exploitx.com/160/blocking-limewirep2p-apps-upload-only/</guid>
		<description><![CDATA[Hi List,
Is there a way I can block the likes of limewire uploading (without
blocking d/l) at a network level preferably via a filter rule on the
router or server s/w in a home network environment.
The problem I have is ppl on the network forget to close limewire and
leave their machines on and of course this gobbles [...]]]></description>
			<content:encoded><![CDATA[<p>Hi List,</p>
<p>Is there a way I can block the likes of limewire uploading (without<br />
blocking d/l) at a network level preferably via a filter rule on the<br />
router or server s/w in a home network environment.</p>
<p>The problem I have is ppl on the network forget to close limewire and<br />
leave their machines on and of course this gobbles up all the<br />
bandwidth. I have successfully implemented a rule to block limewire<br />
altogether at the router but this does not go down to well with my<br />
users!</p>
<p>Many thanks,</p>
<p>Sam</p>
<p>- Why not get a bandwidth/QoS control device (you can even build one with<br />
a linux box if you so desire) and limit the amount of upload bandwidth<br />
they can use? There are small programs that can be installed in linux<br />
firewalls, there are also dedicated devices to do this..</p>
<div style="float: left;"><!--adsense--></div>
<p>The options only depend on what you&#8217;re most comfortable with.</p>
<p>The nice thing about QoS controls is that you can say, other traffic<br />
gets priority, but if there is no other traffic, limewire can use all<br />
available bandwidth.</p>
<p>- My advice would simply be to go with the plan to ban P2P traffic. Your<br />
user&#8217;s complaints can be ignored if there is not legitimate use that<br />
provides value to your organisation. You users griping over the bar on P2P<br />
file sharing is nothing compared to the headache of policing illegal<br />
content and malware which is a constant part of P2P life.</p>
<p>If you allow it and it causes trouble would you want to be responsible?</p>
<p>Jim Halfpenny</p>
<p>- There are several packet classification projects out there that may help<br />
you.</p>
<p>http://ipp2p.org/</p>
<p>http://www.shorewall.net/IPP2P.html</p>
<p>http://l7-filter.sourceforge.net/</p>
<p>http://hippie.oofle.com/tiki-view_articles.php</p>
]]></content:encoded>
			<wfw:commentRss>http://www.exploitx.com/160/blocking-limewirep2p-apps-upload-only/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco IOS Version audit (Vulnrable or Not?)</title>
		<link>http://www.exploitx.com/159/cisco-ios-version-audit-vulnrable-or-not/</link>
		<comments>http://www.exploitx.com/159/cisco-ios-version-audit-vulnrable-or-not/#comments</comments>
		<pubDate>Sat, 03 Dec 2005 23:11:05 +0000</pubDate>
		<dc:creator>Exploitx</dc:creator>
				<category><![CDATA[Q & A]]></category>

		<guid isPermaLink="false">http://www.exploitx.com/159/cisco-ios-version-audit-vulnrable-or-not/</guid>
		<description><![CDATA[I am looking for people to share there advise or any software that will
allow me to achieve the following.
I would like to do an SNMP walk over all of my Cisco devices, to get the
hardware and IOS version information.
With this information I would then like to audit each IOS version to see
   &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p>I am looking for people to share there advise or any software that will<br />
allow me to achieve the following.</p>
<p>I would like to do an SNMP walk over all of my Cisco devices, to get the<br />
hardware and IOS version information.<br />
With this information I would then like to audit each IOS version to see<br />
   &#8211; Latest IOS image ave liable<br />
   &#8211; Recommended IOS Image<br />
   &#8211; Last IOS image that doesn&#8217;t have any vulnerabilities<br />
   &#8211; Then possibly an advanced check to see if my Cisco device supports<br />
the mimimum hardware requirements</p>
<p>The main difficulty here is an easy automated way to get this information.</p>
<p>Any suggesions?</p>
<p>- Search for kiwicattools ( http://www.kiwisyslog.com/cattools2.htm ) .. That<br />
may solve all of your MASS CISCO problems. We have a network of 300+ routers<br />
and switches and it works nicely.</p>
<p>Muhammad</p>
<p>- I&#8217;ve had great success doing much of the things your interested in. Did<br />
it under linux
<div style="float: left;"><!--adsense--></div>
<p>using snmpwalk/snmpget and python with some shell for<br />
glue (or was that in shell with python for glue?), but I suspect any<br />
number of other *nix type OSes would work, dunno about cygwin on<br />
windows. Probably an equivalent library or toolset somewhere if you<br />
wanna do windows natively.</p>
<p>As for cisco IOS versions, these 3 charts @</p>
<p>http://www.cisco.com/en/US/products/sw/iosswrel/ps5012/products_tech_note09186a00800afdb6.shtml</p>
<p>are very illustrative, I&#8217;m sure something like this exists in an ordered<br />
parseable form somewhere&#8230;</p>
<p>- Ciscoworks ???   should be able to get it if you have CCO.</p>
<p>Could try OpenNMS if you using *nix    /   so you would not have to pay alot<br />
of licensing fees.</p>
<p>http://www.opennms.org/wiki//</p>
<p>Hope that helps &#8230;</p>
<p>- </p>
]]></content:encoded>
			<wfw:commentRss>http://www.exploitx.com/159/cisco-ios-version-audit-vulnrable-or-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
