<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hak5 - Technolust since 2005 &#187; crack</title>
	<atom:link href="http://Hak5.org/tag/crack/feed" rel="self" type="application/rss+xml" />
	<link>http://Hak5.org</link>
	<description>Trust Your Technolust</description>
	<lastBuildDate>Mon, 06 Feb 2012 02:17:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Hak5 916 &#8211; Secure Passwords the Old School way&#8230;but better, a Javascript PC Emulator, Rainbow Tables and more</title>
		<link>http://Hak5.org/episodes/episode-916</link>
		<comments>http://Hak5.org/episodes/episode-916#comments</comments>
		<pubDate>Wed, 08 Jun 2011 14:16:07 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 9]]></category>
		<category><![CDATA[1password]]></category>
		<category><![CDATA[azure]]></category>
		<category><![CDATA[card]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[Emulator]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[keypass]]></category>
		<category><![CDATA[lanman]]></category>
		<category><![CDATA[lastpass]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MD5]]></category>
		<category><![CDATA[nt]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password card]]></category>
		<category><![CDATA[password management]]></category>
		<category><![CDATA[passwordcard]]></category>
		<category><![CDATA[qeum]]></category>
		<category><![CDATA[Rainbow Tables]]></category>
		<category><![CDATA[rainbowtables]]></category>
		<category><![CDATA[sha1]]></category>
		<category><![CDATA[time memory tradeoff]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[VM]]></category>
		<category><![CDATA[windows azure]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=3639</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/fhJnvji41K0?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube.com/v/fhJnvji41K0?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-916"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-916&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show, Shannon demonstrates a novel password management technique. Darren&#8217;s explains Time Memory Trade-off and Rainbow Tables. Jason gets started programming for Windows Azure and it&#8217;s Linux in your web browser time! A PC Emulator in Javascript.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0916/hak5--0916--hakfiles--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0916/hak5--0916--hakfiles--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0916/hak5--0916--hakfiles--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-3639"></span><br />
<center><br />
<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/fhJnvji41K0?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube.com/v/fhJnvji41K0?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object><br />
</center></p>
<p><b>A novel approach to password management</b></p>
<p>I have about a million websites that I have to log onto day-to-day. Seriously. And with all the hype about website infiltration and stolen data, it makes me worry a bit about my own usernames and passwords. I have recently upgraded my Google Mail account to use 2-step verification, which I explained a few weeks ago in a Snubs Report, but what about my facebook? Twitter? My online banking?</p>
<p>These sites all say things like, &#8216;Password must be so-and-so characters long with at least one letter and number&#8217;, but some aren&#8217;t so secure. How will I know what sites will have a data breach? I don&#8217;t. So I use somewhat different passwords for all sites. But honestly, if someone had the balls and the time to figure out my pattern, they could probably do it. But I don&#8217;t want to download a password protection program to use on my home computer because I use several different computers and may not have access to the software or my saved encrypted passwords when I&#8217;m using a public PC.</p>
<p>Well, there are other options out there if you don&#8217;t want to use more software, you could use something a little less technical.</p>
<p>This is PasswordCard from <a href="http://www.passwordcard.org/en" target="_blank">passwordcard.org</a>. It&#8217;s a card the size of a credit card that I can stick in my wallet and carry with me. What makes this unique is the series of random digits and letters that are included on it. The rows are different colors and the columns have a different symbol at the top. You can use this card to think up a very strong and tough password and use the colors and symbols to remember it.</p>
<p>Better yet, each code card is randomly generated and there are Android and iPhone apps.</p>
<p>So here is an example of how to use this tool:</p>
<p>First off, go to the website and print out your unique card. I have a laser black and white printer, but if you have a color printer I&#8217;d suggest printing in color to give you more options for remembering passwords.</p>
<p>You can then cut out your card and laminate it if needed. Keep the rest of the page, because it has your unique card number on it. More on that in just a bit.</p>
<p>Then you can choose your password. Choose a symbol and a color or row number and use the letters and numbers that are seen in that row or column.</p>
<p>All you have to do after that is go to your website and change your password. If you lost your PasswordCard, you can go back to the website, type in your unique card number and hit print, or pull it up on  your mobile phone.<br />
So for example, I printed out my card and I&#8217;m going to choose something I would remember. I&#8217;ll go with the music note, and number 7. So my password would be HAg8kgntQUG.</p>
<p>This tool is super simple to use and completely free. The website can be visited safely via HTTPS and the algorithm used to create the codes is available in case the website goes down and you need to reprint your card.</p>
<p>If you don&#8217;t feel safe printing a card, just download the free app off the Android Marketplace or the Apple App Store. This app will let you generate a random card or pull up your own card. It&#8217;ll also let you generate your own personal PasswordCard based on a series of random hexidecimal digits. For example, I can hit enter number, and type in a number that I have memorized. That number will always pull up my card for me to use.</p>
<p>If you&#8217;re worried that someone can get ahold of your unique card number, not to worry! They still wouldn&#8217;t have your actual passwords because those were created from the numbers and letters found on the card, and they could be thousands of different password combinations.</p>
<p>I think this is a pretty cool idea, and it&#8217;s easy enough that I could probably show my mom how to use this. So, enough of using crappy passwords!</p>
<p>This is just one of the tools available out there for password generation. Do you have one? Email it to me: feedback@hak5.org. Now for the haktip.&#8221;</p>
<p><b>Start programming in Windows Azure</b></p>
<p><a href="http://twitter.com/appelbaum" target="_blank">Jason</a>. begins a three-part mini-series on programming for <a href="http://www.microsoft.com/windowsazure/" target="_blank">Windows Azure</a>. In this part Jason demonstrates <a href="http://www.microsoft.com/windowsazure/getstarted/" target="_blank">how to get started</a>. In coming parts Jason will develop an cloud-based application that maps Kismet KML data to a Bing map.</p>
<p>If you&#8217;re into Hak5 you&#8217;ll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you&#8217;re a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let&#8217;s not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-916/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0916/hak5--0916--hakfiles--hd720p30.h264.mp4" length="636494737" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0916/hak5--0916--hakfiles--large.h264.mp4" length="290475779" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0916/hak5--0916--hakfiles--large.wmv9.wmv" length="429671977" type="video/asf" />
		</item>
		<item>
		<title>HakTip 3 &#8211; Packet Sniffing 101: Promiscuous Mode</title>
		<link>http://Hak5.org/episodes/haktip-3</link>
		<comments>http://Hak5.org/episodes/haktip-3#comments</comments>
		<pubDate>Tue, 31 May 2011 19:20:19 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[HakTip]]></category>
		<category><![CDATA[802.11]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[monitor mode]]></category>
		<category><![CDATA[packet sniffing]]></category>
		<category><![CDATA[promiscuous mode]]></category>
		<category><![CDATA[wep]]></category>
		<category><![CDATA[wireless network]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=3602</guid>
		<description><![CDATA[<object width="555" height="342"><param name="movie" value="http://www.youtube.com/v/_Kz8C7g7XOY?version=3&#38;hl=en_US&#38;fs=1&#38;hd=1&#38;showinfo=0&#38;rel=0&#38;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="342" src="http://www.youtube.com/v/_Kz8C7g7XOY?version=3&#38;hl=en_US&#38;fs=1&#38;hd=1&#38;showinfo=0&#38;rel=0&#38;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhaktip-3"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhaktip-3&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>We&#8217;re getting promiscuous, with wireless cards! As part of our foundation series of HakTips Darren covers the fundamentals of wireless packet sniffing with a practical approach in BackTrack Linux using the Aircrack-ng suite.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/haktip/0003/hak5--haktip--0003--promiscuous--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/haktip/0003/hak5--haktip--0003--promiscuous--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/haktip/0003/hak5--haktip--0003--promiscuous--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-3602"></span></p>
<p><object width="555" height="342"><param name="movie" value="http://www.youtube.com/v/_Kz8C7g7XOY?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="342" src="http://www.youtube.com/v/_Kz8C7g7XOY?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p>Let&#8217;s think about network traffic as a cocktail party. Picture Alice and Bob on the love seat chatting it up while Charlie is deep in conversation with Dave at the bar. Meanwhile, Eve is nearby sipping a Hendrix Martini listening in on everyone&#8217;s conversations.</p>
<p>You see, in order for Alice to send a message to Bob she has to address it to him by his network interfaces MAC address &#8212; or Media Access Control Address. This address is unique every network interface on the planet. Bob&#8217;s is going to be different from Charlie&#8217;s, Dave&#8217;s or anyone else.</p>
<p>On a hub based network, Alice&#8217;s message is heard by all. But by default when Charlie or Dave hear a message addressed to a mac address other their own, their network interface will drop the frame completely.</p>
<p>This is where promiscuous mode comes into play. If Eve&#8217;s network interface is in promiscuous mode she doesn&#8217;t drop frames not addressed to her. This is great for packet sniffing, say if Eve was a network administrator attempting to debug a faulty network. Likewise, if Eve had malicious intent the same applies to eavesdropping.</p>
<p>Now promiscuous mode assumes a hub based network. Switches thwart this by only sending messages to their intended recipients instead of everyone.</p>
<p>Which brings us to Monitor mode. Monitor mode, or RFMON for Radio Frequency Monitor, is one of six modes that wireless network interfaces can assume. Similar to Promiscuous mode, Monitor mode allows the wireless network interface to &#8220;sniff packets&#8221; not intended for it. </p>
<p>Unline promiscuous mode however, an interface in monitor mode can sniff packets from access points it isn&#8217;t even associated with. Again this is great for, say, an administrator troubleshooting a network, or on the darker side for malicious purposes such as eavesdropping and cracking encrypted networks.</p>
<p>What program or command is giving you warm fuzzies? Hit me up &#8212; <a href="mailto:tips@hak5.org">tips@hak5.org</a></p>
<p>And be sure to check out our sister show, <a href="http://www.hak5.org" target="_blank">Hak5</a> for more great stuff just like this.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/haktip-3/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/haktip/0003/hak5--haktip--0003--promiscuous--hd720p30.h264.mp4" length="126887847" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/haktip/0003/hak5--haktip--0003--promiscuous--large.h264.mp4" length="57575306" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/haktip/0003/hak5--haktip--0003--promiscuous--large.wmv9.wmv" length="85722009" type="video/asf" />
		</item>
		<item>
		<title>Episode 822 – Penetration Testing with Armitage for Metasploit</title>
		<link>http://Hak5.org/episodes/episode-822</link>
		<comments>http://Hak5.org/episodes/episode-822#comments</comments>
		<pubDate>Thu, 20 Jan 2011 20:36:33 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 8]]></category>
		<category><![CDATA[armitage]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[back track]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[box]]></category>
		<category><![CDATA[bt]]></category>
		<category><![CDATA[client side attack]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[easy]]></category>
		<category><![CDATA[fast]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[front end]]></category>
		<category><![CDATA[gui]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[identify]]></category>
		<category><![CDATA[interface]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[lookup]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[own]]></category>
		<category><![CDATA[pass the hash]]></category>
		<category><![CDATA[pivoting]]></category>
		<category><![CDATA[pop]]></category>
		<category><![CDATA[probe]]></category>
		<category><![CDATA[pwn]]></category>
		<category><![CDATA[query]]></category>
		<category><![CDATA[raphael mudge]]></category>
		<category><![CDATA[rapid7]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[Rob Fuller]]></category>
		<category><![CDATA[room362]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=2715</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/Z0x_O75tRAU?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/Z0x_O75tRAU?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-822"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-822&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Raphael Mudge of <a href="http://www.fastandeasyhacking.com" target="_blank">FastAndEasyHacking.com</a> joins Rob Fuller, aka <a href="http://www.room362.com" target="_blank">Mubix</a>, to talk about his project Armitage; a cross-platform GUI front-end for Rapid7&#8242;s Metasploit. Mudge demonstrate setting up the software, scanning for targets, attacking hosts with client side attacks or remote exploits, and finally pivoting throughout the network using pass-the-hash techniques. Time to grab some paper, pencil and an unsuspecting virtual machine!</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0822/hak5--0822--armitage--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0822/hak5--0822--armitage--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0822/hak5--0822--armitage--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-2715"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/Z0x_O75tRAU?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/Z0x_O75tRAU?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object></p>
<p>Keep up with the latest on Hak5 by follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>. <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> and get your weekly technolust delivered automatically. Or show your support and grab some swag from the <a href="http://hak5.org/store" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> and <a href="http://www.hak5.org/store/hak5-hoodie" target="_blank">hoodie</a>. Finally if you&#8217;d like to suggest a topic<br />
for ask a question feel free to hit up <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-822/feed</wfw:commentRss>
		<slash:comments>14</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0822/hak5--0822--armitage--large.wmv9.wmv" length="371183420" type="video/asf" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0822/hak5--0822--armitage--hd720p30.h264.mp4" length="610618356" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0822/hak5--0822--armitage--large.h264.mp4" length="401116198" type="video/mp4" />
		</item>
		<item>
		<title>Episode 626 — Shmoocon 2010</title>
		<link>http://Hak5.org/episodes/episode-626</link>
		<comments>http://Hak5.org/episodes/episode-626#comments</comments>
		<pubDate>Tue, 09 Feb 2010 16:18:41 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[802.11]]></category>
		<category><![CDATA[aircrack]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[airdrop]]></category>
		<category><![CDATA[airdrop-ng]]></category>
		<category><![CDATA[airdump]]></category>
		<category><![CDATA[airodump]]></category>
		<category><![CDATA[and decrypting GSM]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[archive team]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[bot net]]></category>
		<category><![CDATA[cloning]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[de-auth]]></category>
		<category><![CDATA[de-authentication]]></category>
		<category><![CDATA[deassociation]]></category>
		<category><![CDATA[deauth]]></category>
		<category><![CDATA[deauthentication]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[geocities]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker con]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[ipwn]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[jason scott]]></category>
		<category><![CDATA[Karma]]></category>
		<category><![CDATA[linked-in]]></category>
		<category><![CDATA[Man-in-the-middle sniffing]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[OUI]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[riocities]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[shmoocon 2010]]></category>
		<category><![CDATA[spoofing]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[textfiles]]></category>
		<category><![CDATA[theX1le]]></category>
		<category><![CDATA[tom eston]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wifi bomb]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1975</guid>
		<description><![CDATA[
			
				
			
		
We head out to DC for Shmoocon, our favorite hacker conference on the east coast, to talk to some of the brightest minds in security. We talk to Tom Eston about social media security, TheX1le ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-626"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-626&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>We head out to DC for Shmoocon, our favorite hacker conference on the east coast, to talk to some of the brightest minds in security. We talk to Tom Eston about social media security, TheX1le about his new tool airdrop-ng, Jason Scott about preserving our digital heritage, Chris Paget about man-in-the-middle attacks against GSM networks, and much more.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1975"></span><br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="555" height="312" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube-nocookie.com/v/7BUz3vYXac0&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" /><param name="wmode" value="transparent" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube-nocookie.com/v/7BUz3vYXac0&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" wmode="transparent" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><strong>Airdrop-ng</strong></p>
<p>Self taught packet junkie TheX1le shares with us his new tool for wireless de-authentication and deassociation. Airdrop-ng facilitates client control with versatile rule based control.</p>
<p><strong>Cloning, Spoofing, Man-in-the-middle sniffing, and decrypting GSM</strong></p>
<p>
Chris Paget of <a href="http://www.h4rdw4re.com/" target="_blank">h4rdw4re</a> shares with us the in&#8217;s and out&#8217;s of GSM hacking. Armed with a USRP and his open-source software, Paget pretends to be your GSM tower, and a lot more.
</p>
<p><strong> Jason Scott &#8211; Defender of Digital Heritage</strong><br />
<a href="http://www.textfiles.com" target="_blank">Textfiles.com</a> very own Jason Scott joins us to talk about preserving our digital heritage with <a href="http://www.archiveteam.org" target="_blank">Archive Team</a> and why it&#8217;s important to keep Geocities, Netscape Now buttons, and *gasp* Hamster Dance.
</p>
<p><strong>Social Media Security</strong></p>
<p>Tom Eston shares with us the delicious dangers of social networks while in the hands of web-application exploiting hackers. No worries, he&#8217;s got you covered at <a href="http://www.socialmediasecurity.com" target="_blank">socialmediasecurity.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-626/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking PPTP VPNs with ASLEAP</title>
		<link>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap</link>
		<comments>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap#comments</comments>
		<pubDate>Mon, 14 Dec 2009 07:58:05 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[client handshake authentication protocol]]></category>
		<category><![CDATA[cowpatty]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[joshua wright]]></category>
		<category><![CDATA[l2tp]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[point to point tunneling protocol]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1627</guid>
		<description><![CDATA[
			
				
			
		
Darren demonstrates cracking Microsoft VPN tunnels using the MS-CHAPv2 authentication protocol using Joshua Wright&#8217;s tool ASLEAP and talks about the theory behind the attack.



Continuing on with our VPN series I find it important to highlight ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fhack%2Fhacking-pptp-vpns-with-asleap"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fhack%2Fhacking-pptp-vpns-with-asleap&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Darren demonstrates cracking Microsoft VPN tunnels using the MS-CHAPv2 authentication protocol using Joshua Wright&#8217;s tool ASLEAP and talks about the theory behind the attack.</p>
<div style="clear:both;"></div>
<p><span id="more-1627"></span></p>
<p><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/IPPHJBp3bXU&#038;hl=en_US&#038;fs=1&#038;start=262"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/IPPHJBp3bXU&#038;hl=en_US&#038;fs=1&#038;start=262" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></p>
<p>Continuing on with our VPN series I find it important to highlight the weaknesses in the protocols we have talked about thus far. In <a target="_blank" href="http://www.hak5.org/episodes/episode-610">my last segment</a> I highlighted a tool that allows an attacker to easily hijack an SSL session using a man-in-the-middle attack. Couple this with Adito (aka OpenVPN-ALS), <a target="_blank" href="http://www.hak5.org/episodes/episode-607">my favorite open-source SSL VPN server</a>, and you can see the problem.</p>
<p>But what about the basic <a target="_blank" href="http://www.hak5.org/episodes/episode-605">Microsoft VPN</a> we setup <a target="_blank" href="http://www.hak5.org/episodes/episode-605">a few weeks back?</a> The VPN servers that we setup on Windows XP and Server 2003 used either active directory or local windows accounts to authenticate users.</p>
<p>And looking back at <a target="_blank" href="http://www.hak5.org/episodes/episode-419">our discussions</a> on pwdump, rainbow tables and the like you&#8217;ll remember the inherent weaknesses in Windows account credentials.</p>
<p>There are two ways Windows stores a user&#8217;s account credentials, or password. <a target="_blank" href="http://en.wikipedia.org/wiki/LM_hash">LAN Manager</a> hashes which are comprised of watered-down weaksauce and <a target="_blank" href="http://en.wikipedia.org/wiki/NTLM">NTLM</a> which are succeptable to time-memory tradeoff attacks.</p>
<p>The default VPN server implemented in Windows XP and Server 2003&#8242;s Routing and Remote Access service uses Point-To-Point-Tunneling-Protocol. This is convenient because the Windows clients have supported Microsoft PPTP VPN connections natively since 2000, and in Windows 95/98 with <a target="_blank" href="http://support.microsoft.com/kb/191494">Dual Up Networking version 1.3</a>.</p>
<p>The modern authentication protocol of Microsoft&#8217;s PPTP is <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc739678(WS.10).aspx">MS-CHAPv2</a>. This <a target="_blank" href="http://en.wikipedia.org/wiki/Challenge-handshake_authentication_protocol">Challenge Handshake Authentication Protocol</a> suffers from inherent weaknesses.</p>
<p>As far back at 1999 these weaknesses have been widely known. If you&#8217;re interested in reading more on the cryptanalysis of MS-CHAPv2 there&#8217;s a <a target="_blank" href="http://www.schneier.com/paper-pptpv2.html">nifty paper</a> written by Bruce Schneier and L0pht that I&#8217;ll link in the show notes.</p>
<p>And while other options exist such as <a target="_blank" href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx">Radius</a>, this is still the default option for PPTP authentication in Windows environments.</p>
<p><a target="_blank" href="http://www.willhackforsushi.com/?page_id=87">Joshua Wright</a>, author of <a target="_blank" href="http://www.willhackforsushi.com/?p=284">coWPAtty</a> (See <a target="_blank" href="http://www.hak5.org/episodes/episode-518">our segment here</a>), released in 2004 a proof of concept tool to demonstrate weaknesses in <a target="_blank" href="http://en.wikipedia.org/wiki/Lightweight_Extensible_Authentication_Protocol">LEAP</a> and PPTP protocols.</p>
<p>This tool, <a target="_blank" href="http://www.willhackforsushi.com/Asleap.html">ASLEAP</a>, was updated in 2007 to include an option to just crack MS-CHAP v2. Either by examining a packet capture that includes a MS-CHAP handshake ASLEAP or specifying an MS-CHAP challenge and response ASLEAP is able to deduce the username and last two bytes of the NT hash. Using this information, and a dictionary file, ASLEAP is able to brute-force the hash.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Episode 614 &#8211; Firewall evasion, SSH and virtual appliances!</title>
		<link>http://Hak5.org/episodes/episode-614</link>
		<comments>http://Hak5.org/episodes/episode-614#comments</comments>
		<pubDate>Wed, 18 Nov 2009 14:49:32 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[asleap]]></category>
		<category><![CDATA[bypass filter]]></category>
		<category><![CDATA[bypass firewall]]></category>
		<category><![CDATA[bypass school filter]]></category>
		<category><![CDATA[convert virtualbox]]></category>
		<category><![CDATA[convert vmware]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[DimDim]]></category>
		<category><![CDATA[dropbear]]></category>
		<category><![CDATA[easy proxy]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[free proxies]]></category>
		<category><![CDATA[free proxy]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hack filter]]></category>
		<category><![CDATA[hack firewall]]></category>
		<category><![CDATA[hack school filter]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[hacking firewalls]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[internet proxy]]></category>
		<category><![CDATA[internet tunneling]]></category>
		<category><![CDATA[lanman]]></category>
		<category><![CDATA[LM]]></category>
		<category><![CDATA[local forward]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[mschap]]></category>
		<category><![CDATA[mschapv2]]></category>
		<category><![CDATA[network scan]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[office firewall]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[open ssh]]></category>
		<category><![CDATA[open wifi]]></category>
		<category><![CDATA[OpenSSH]]></category>
		<category><![CDATA[Packet Sniff]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php proxy]]></category>
		<category><![CDATA[phpproxy]]></category>
		<category><![CDATA[port forward]]></category>
		<category><![CDATA[port redirection]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[proxies]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[Putty]]></category>
		<category><![CDATA[quick proxy]]></category>
		<category><![CDATA[restrictions]]></category>
		<category><![CDATA[safe wifi]]></category>
		<category><![CDATA[school firewall]]></category>
		<category><![CDATA[secure irc]]></category>
		<category><![CDATA[secure network]]></category>
		<category><![CDATA[secure shell]]></category>
		<category><![CDATA[secure tunnel]]></category>
		<category><![CDATA[secure wifi]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[shell account]]></category>
		<category><![CDATA[simply proxy]]></category>
		<category><![CDATA[sniffing]]></category>
		<category><![CDATA[socks]]></category>
		<category><![CDATA[socks proxy]]></category>
		<category><![CDATA[socks5]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[ssh client]]></category>
		<category><![CDATA[ssh forward]]></category>
		<category><![CDATA[ssh server]]></category>
		<category><![CDATA[ssh tunnel]]></category>
		<category><![CDATA[static ip]]></category>
		<category><![CDATA[traffic tunneling]]></category>
		<category><![CDATA[university firewall]]></category>
		<category><![CDATA[virtual appliance]]></category>
		<category><![CDATA[virtual appliance marketplace]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[virtual private server]]></category>
		<category><![CDATA[virtualbox]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[vmdk]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vps]]></category>
		<category><![CDATA[web proxy]]></category>
		<category><![CDATA[work firewall]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1457</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3869" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-614"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-614&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Got a restrictive firewall blocking sites at school or work? Evade &#8216;em easily with your own private web proxy. Want to securely tunnel any port through an SSH session? Darren&#8217;s got just the trick. Wondering how to properly use Asleap to crack MS-CHAPv2 PPTP VPN handshakes &#038; LM Hashes? Interested in trying out neat free enterprise applications but don&#8217;t feel like spending hours in a terminal? Try deploying a virtual appliance in minutes, the free and open source way.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1457"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3869" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent" /></p>
<p><b>Port Tunneling and Socks5 Proxies with a Secure Shell (SSH)</b></p>
<p>SSH Tunneling isn&#8217;t new to the show, we&#8217;ve done it <a href="http://www.hak5.org/episodes/episode-504">before over DNS</a> or in conjunction <a href="http://www.hak5.org/episodes/hak5-episode-7-released">with VNC</a>. Today we&#8217;re looking at two SSH tricks for tunneling just about any traffic.</p>
<p>First up, <i>ssh -D</i>. The <i>-D</i> option specified a local &quote;Dynamic&quote; application-level port forwarding. Any connection made to the specified port goes through the tunnel as a SOCKS4 or SOCKS5 proxy. Perfect for secure web browsing as demonstrated with Firefox in this segment.</p>
<p><u>Usage</u></p>
<blockquote><pre>ssh -D 8080 user@server</pre>
</blockquote>
<p>Second, <i>ssh -L</i>. The <i>-L</i> option enables port forwarding. Using this option tells the SSH client to listen to traffic on a specified port and forward it along through the tunnel. The server receives this data and points it to the specified destination, whether it be on the destination network or otherwise. In our example we use the <i>-L</i> option to securely connect to an open IRC server.</p>
<p><u>Usage</u></p>
<blockquote><pre>ssh user@server -L local-listen-port:destination-ip:destination-port</pre>
</blockquote>
<p>For more SSH-fu check out the <a href="http://unixhelp.ed.ac.uk/CGI/man-cgi?ssh+1">ssh man page</a> or Linux Journal&#8217;s interesting series on <a href="http://www.linuxjournal.com/article/4412">101 uses of openssh</a>.</p>
<p><b>Bypassing site-blocking firewalls with your own private web proxy</b></p>
<p>The age old scheme for bypassing restrictive firewalls, like those that block sites at school or work, has been to use a web proxy. Of course this is followed up by the network administrator blocking all mainstream proxies. But what if you could run your own? Well, you can and it&#8217;s really freaking easy. In this segment Darren demonstrates <a href="http://sourceforge.net/projects/poxy/">PHProxy</a></p>
<p><b>Cracking MS-CHAPv2 PPTP VPN handshakes &#038; LM Hashes Followup from 6&#215;12</b></p>
<p>On <a href="http://www.hak5.org/episodes/episode-612">episode 612</a> we demonstrated a tool, asleap, designed to crack MS-CHAPv2, the authentication protocol commonly found in Microsoft PPTP VPNs. The final demo was unsuccessful due to the encoding of the handshake and response sniffed by Wireshark. Viewer Sc00bz was kind enough to post a PHP script that accepts the challenge, response and username and provides you with the proper asleap command to run with the properly encoded byte sequences. Sc00bz has well documented the code, which lives now on this <a href="http://hak5.org/forums/index.php?showtopic=14755">Hak5 forum</a> thread. Thanks Sc00bz!</p>
<p><b>Deploying Virtual Appliances in minutes the open source way</b></p>
<p>A Virtual Appliance can be though of as a software image containing a supporting stack designed to run inside a virtual machine. A quick look at vmware&#8217;s <a href="http://www.vmware.com/appliances/">virtual appliance directory</a> shows that there are hundreds of applications that can be quickly and easily deployed. In this segment I take the <a href="http://www.dimdim.com/hak5">Dimdim</a> open source virtual appliance, designed for vmware, and deploy it with <a rhef="http://www.virtualbox.org">VirtualBox</a> (just becasue I can).</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-614/feed</wfw:commentRss>
		<slash:comments>38</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--hd720p30.h264.mp4" length="345088325" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.h264.mp4" length="225102421" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.xvid.avi" length="194242128" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.wmv9.wmv" length="180435644" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 612 &#8211; Hacking PPTP VPNs with ASLEAP</title>
		<link>http://Hak5.org/episodes/episode-612</link>
		<comments>http://Hak5.org/episodes/episode-612#comments</comments>
		<pubDate>Wed, 04 Nov 2009 16:52:17 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[client handshake authentication protocol]]></category>
		<category><![CDATA[cowpatty]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[joshua wright]]></category>
		<category><![CDATA[l2tp]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[point to point tunneling protocol]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1440</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3867" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  wmode="transparent"  />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-612"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-612&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Continuing with the VPN Series, Darren discusses the inherent weaknesses in Microsoft&#8217;s PPTP authentication protocol, MS-CHAPv2, and demos a Linux tool that exploits these weaknesses.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1440"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3867" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  wmode="transparent"  /></p>
<p>Continuing on with our VPN series I find it important to highlight the weaknesses in the protocols we have talked about thus far. In <a target="_blank" href="http://www.hak5.org/episodes/episode-610">my last segment</a> I highlighted a tool that allows an attacker to easily hijack an SSL session using a man-in-the-middle attack. Couple this with Adito (aka OpenVPN-ALS), <a target="_blank" href="http://www.hak5.org/episodes/episode-607">my favorite open-source SSL VPN server</a>, and you can see the problem.</p>
<p>But what about the basic <a target="_blank" href="http://www.hak5.org/episodes/episode-605">Microsoft VPN</a> we setup <a target="_blank" href="http://www.hak5.org/episodes/episode-605">a few weeks back?</a> The VPN servers that we setup on Windows XP and Server 2003 used either active directory or local windows accounts to authenticate users.</p>
<p>And looking back at <a target="_blank" href="http://www.hak5.org/episodes/episode-419">our discussions</a> on pwdump, rainbow tables and the like you&#8217;ll remember the inherent weaknesses in Windows account credentials.</p>
<p>There are two ways Windows stores a user&#8217;s account credentials, or password. <a target="_blank" href="http://en.wikipedia.org/wiki/LM_hash">LAN Manager</a> hashes which are comprised of watered-down weaksauce and <a target="_blank" href="http://en.wikipedia.org/wiki/NTLM">NTLM</a> which are succeptable to time-memory tradeoff attacks.</p>
<p>The default VPN server implemented in Windows XP and Server 2003&#8242;s Routing and Remote Access service uses Point-To-Point-Tunneling-Protocol. This is convenient because the Windows clients have supported Microsoft PPTP VPN connections natively since 2000, and in Windows 95/98 with <a target="_blank" href="http://support.microsoft.com/kb/191494">Dual Up Networking version 1.3</a>.</p>
<p>The modern authentication protocol of Microsoft&#8217;s PPTP is <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc739678(WS.10).aspx">MS-CHAPv2</a>. This <a target="_blank" href="http://en.wikipedia.org/wiki/Challenge-handshake_authentication_protocol">Challenge Handshake Authentication Protocol</a> suffers from inherent weaknesses.</p>
<p>As far back at 1999 these weaknesses have been widely known. If you&#8217;re interested in reading more on the cryptanalysis of MS-CHAPv2 there&#8217;s a <a target="_blank" href="http://www.schneier.com/paper-pptpv2.html">nifty paper</a> written by Bruce Schneier and L0pht that I&#8217;ll link in the show notes.</p>
<p>And while other options exist such as <a target="_blank" href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx">Radius</a>, this is still the default option for PPTP authentication in Windows environments.</p>
<p><a target="_blank" href="http://www.willhackforsushi.com/?page_id=87">Joshua Wright</a>, author of <a target="_blank" href="http://www.willhackforsushi.com/?p=284">coWPAtty</a> (See <a target="_blank" href="http://www.hak5.org/episodes/episode-518">our segment here</a>), released in 2004 a proof of concept tool to demonstrate weaknesses in <a target="_blank" href="http://en.wikipedia.org/wiki/Lightweight_Extensible_Authentication_Protocol">LEAP</a> and PPTP protocols.</p>
<p>This tool, <a target="_blank" href="http://www.willhackforsushi.com/Asleap.html">ASLEAP</a>, was updated in 2007 to include an option to just crack MS-CHAP v2. Either by examining a packet capture that includes a MS-CHAP handshake ASLEAP or specifying an MS-CHAP challenge and response ASLEAP is able to deduce the username and last two bytes of the NT hash. Using this information, and a dictionary file, ASLEAP is able to brute-force the hash.</p>
<p>PS: Check out <a href="http://www.player2rentals.com" target="_blank">Player2Rentals.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-612/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--hd720p30.h264.mp4" length="549041844" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.h264.mp4" length="358047282" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.xvid.avi" length="315159934" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.wmv9.wmv" length="307796076" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 525 &#8211; Sea Salt for your Hashes</title>
		<link>http://Hak5.org/episodes/episode-525</link>
		<comments>http://Hak5.org/episodes/episode-525#comments</comments>
		<pubDate>Wed, 05 Aug 2009 17:59:52 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 5]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[keepass]]></category>
		<category><![CDATA[MD5]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password generator]]></category>
		<category><![CDATA[password safe]]></category>
		<category><![CDATA[salt]]></category>
		<category><![CDATA[salt hash]]></category>
		<category><![CDATA[sha1]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1364</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3289" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-525"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-525&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>While on Vacation at the beach Darren and Shannon talk password security. Shannon covers her favorite free open source password safe, Keepass, and how it can take the nightmare out of remembering a different password for every site. Then, Darren goes over salting and what it does to protect your password&#8217;s hash on the back end.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1364"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3289" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  /></p>
<p>With the dozens&#8211;or in the case of many administrators hundreds&#8211;of passwords one must use and remember every day, how is one to ensure a secure and original password every time? Sure you could come up with some crazy algorythm that involves information in the WHOIS record of the domain you&#8217;re logging into, or you could live in normal land and get a password safe. Shannon goes over her favorite free open source offering <a href="http://www.keepass.info" target="_blank">KeePass</a>.</p>
<p>Using industry standard encryption to keep your passwords safe, KeePass is the most full featured password safe we&#8217;ve tested. With versions for just about every OS under the sun, including many smart phones, there is no reason to ever reuse a password again.</p>
<p>If you&#8217;re a fan of KeePass and have a story or <a href="http://keepass.info/plugins.html" target="_blank">plugin</a> you want to sare with us be sure to hit up <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>!</p>
<p>When it comes to storing passwords on the back end, whether they be in a database or flat file, it&#8217;s important to keep &#8216;em salted. In this episode Darren goes over what Hash salting is &#8212; what it means to users, administrators, and would-be password crackers.</p>
<p>Don&#8217;t forget about our first ever official Hak5 Meetup at Busch Gardens Williamsburg on August 15th. Find all the details at <a href="http://hak5meetup.squarespace.com" target="_blank">hak5meetup.squarespace.com</a> or <a href="http://www.facebook.com/event.php?eid=100749273500&#038;ref=nf" target="_blank">RSVP on Facebook</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-525/feed</wfw:commentRss>
		<slash:comments>42</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--hd720p30.h264.mp4" length="269782500" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--large.h264.mp4" length="179821605" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--large.xvid.avi" length="185919552" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0525/hak5--0525--saltyhashes--large.wmv9.wmv" length="179451794" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 419 &#8212; GPU accelerated MD5 Brute Forcing, Easy Windows Password Recovery with Ophcrack live USB and Dave Randolph</title>
		<link>http://Hak5.org/episodes/episode-419</link>
		<comments>http://Hak5.org/episodes/episode-419#comments</comments>
		<pubDate>Wed, 07 Jan 2009 17:43:08 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[CUDA]]></category>
		<category><![CDATA[GPU]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[LM]]></category>
		<category><![CDATA[MD5]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[Nvidia]]></category>
		<category><![CDATA[Ophcrack]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Rainbow Tables]]></category>
		<category><![CDATA[Randolph]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=557</guid>
		<description><![CDATA[<embed src="http://bitcast-a.bitgravity.com/revision3/swf/player/Player.swf" quality="high" pluginspage="http://www.macromedia.com/go/getflashplayer" play="true" loop="true" scale="showall" wmode="window" devicefont="false" bgcolor="#000000" name="Player" menu="true" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" align="middle" height="312" width="555" flashvars="videoId=2477&#038;quality=high" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-419"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-419&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In this first episode of &#8217;09 Dave Randolph joins us to geek out about all things video. Darren whips up a Password Cracking Cocktail and shows off a wicked fast MD5 brute force tool that harnesses the power of your Nvidia graphics card. Shannon saves the day by recovering her sisters Windows password with Ophcrack Live. And Evil Server gets his evil on while we were away on holiday.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0419/hak5--0419--GPU-Brute-Force-MD5-and-Ophcrack--large.h264.mp4">MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0419/hak5--0419--GPU-Brute-Force-MD5-and-Ophcrack--large.xvid.avi">XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0419/hak5--0419--GPU-Brute-Force-MD5-and-Ophcrack--large.wmv9.wmv">WMV</a><br />
<span id="more-557"></span></p>
<h2>Watch</h2>
<p><embed src="http://bitcast-a.bitgravity.com/revision3/swf/player/Player.swf" quality="high" pluginspage="http://www.macromedia.com/go/getflashplayer" play="true" loop="true" scale="showall" wmode="window" devicefont="false" bgcolor="#000000" name="Player" menu="true" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash" align="middle" height="312" width="555" flashvars="videoId=2477&#038;quality=high" /></p>
<h2>Show Notes</h2>
<p><b>MD5 Brute Forcing with your graphics card</b></p>
<p>Since Nvidia released the <a href="http://www.nvidia.com/object/cuda_home.html" target="_blank">CUDA</a> API for Windows, Mac and Linux a number of advances have taken place in the world of brute forcing. In this episode I feature a tool by Svarychevski Michail Aleksandrovich that claims to be the world&#8217;s fastest MD5 cracker &#8212; <a href="http://3.14.by/en/md5" target="_blank">BarsWF</a></p>
<p>Using the brute forcer with a couple Nvidia 8 series or newer graphics cards you&#8217;re able to achieve unprecidented speeds. I&#8217;ve seen claims of nearly 4 <a href="http://blog.red-database-security.com/2008/12/08/md5-bruteforcer-barswf/" target="_blank">billion hashes per second</a> with quad SLI.</p>
<p>CUDA has also spurred other developments, such as this <a href="http://3.14.by/forum/viewtopic.php?f=8&#038;t=60&#038;">NTLM brute forcer for Linux</a>.</p>
<p>In my segment I go into the very basics of password cracking theory and MD5 hashes with some simple scenarios. My aim is to provide a fundamental understanding of the concepts. If you&#8217;re interested in reading more I suggest starting <a href="http://en.wikipedia.org/wiki/Md5">here</a>.</p>
<p>&#8211;<a href="http://www.darrenkitchen.net">Darren Kitchen</a></p>
<p><b>Windows Password Recovery with Ophcrack Live USB</b></p>
<p>Recovering Windows Passwords coulnd&#8217;t be easier with Ophcrack Live on USB. Whether it&#8217;s your sister&#8217;s forgotten XP account or [insert other legit reason] a little USB booting and Rainbow Table loving&#8217;s got you covered.</p>
<p>Preparing an Ophcrack USB key is as simple as formatting your drive for FAT32 with the <a href="http://files.filefront.com/SP27608exe/;9868201;/fileinfo.html" target="_blank">HP USB format tool</a>. Downloading and launching <a href="http://www.pendrivelinux.com/downloads/USBOphcrack.exe" target="_blank">USBOphcrack.exe</a> and running the included batch file. The program will download a small set of rainbow tables and prepare your USB drive.</p>
<p>For even higher password recovering accuracy I recommend finding a larger set of <a href="http://ophcrack.sourceforge.net/tables.php" target="_blank">Ophcrack compatible rainbow tables</a>. Or if you&#8217;re feeling adventerous why not try out the <a href="http://wiki.hak5.org/wiki/Community_Rainbow_Tables" target="_blank">Hak5 community rainbow tables</a> &#8212; a whopping 120GB of NTLM goodness.</p>
<p>&#8211;<a href="http://www.snubsie.com" target="_blank">Shannon Morse</a></p>
<p>Be sure to follow one of us on Twitter if you&#8217;ll be at CES this week. We&#8217;ll be there finding all the best hackable gadgets!</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-419/feed</wfw:commentRss>
		<slash:comments>32</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0419/hak5--0419--GPU-Brute-Force-MD5-and-Ophcrack--large.h264.mp4" length="274356613" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0419/hak5--0419--GPU-Brute-Force-MD5-and-Ophcrack--large.xvid.avi" length="291237494" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0419/hak5--0419--GPU-Brute-Force-MD5-and-Ophcrack--large.wmv9.wmv" length="301636986" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 412 &#8212; Session Hijacking and Virtualizing Servers</title>
		<link>http://Hak5.org/episodes/episode-412</link>
		<comments>http://Hak5.org/episodes/episode-412#comments</comments>
		<pubDate>Wed, 19 Nov 2008 17:03:52 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[Camstudio]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[Converter]]></category>
		<category><![CDATA[Cookies]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[Ed Piskor]]></category>
		<category><![CDATA[Errata]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[Ferret]]></category>
		<category><![CDATA[FRAPS]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hakhouse]]></category>
		<category><![CDATA[Hamster]]></category>
		<category><![CDATA[Helmer]]></category>
		<category><![CDATA[Ikea]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Nikki Colp]]></category>
		<category><![CDATA[Pacsec]]></category>
		<category><![CDATA[Pacsec08]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[Screencast]]></category>
		<category><![CDATA[Session Hijacking]]></category>
		<category><![CDATA[Techsmith]]></category>
		<category><![CDATA[TKIP]]></category>
		<category><![CDATA[tkiptun-ng]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=431</guid>
		<description><![CDATA[<embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=2277&#038;fwVideoDuration=3293&#038;fwNumSlots=8&#038;adSlotPosition_0=0&#038;adSlotClass_0=PREROLL&#038;adSlotProfile_0=R3_video&#038;adSlotPosition_1=180&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=780&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1215&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=1620&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;adSlotPosition_5=2040&#038;adSlotClass_5=OVERLAY&#038;adSlotProfile_5=R3_overlay&#038;adSlotPosition_6=2460&#038;adSlotClass_6=OVERLAY&#038;adSlotProfile_6=R3_overlay&#038;adSlotPosition_7=2880&#038;adSlotClass_7=OVERLAY&#038;adSlotProfile_7=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-412"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-412&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.hak5.org/episodes/episode-412/"><img src="http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--medium.thumb.jpg" border="0"/></a><br />Session Hijacking with a Pineapple, Hamster and Ferret and cell phone? A free and easy way to virtualize physical servers! And is WPA Broken? Ikea clusters, screencasting, and canvas technolust. <br />[ <a href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.h264.mp4">MP4</a> | <a href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.xvid.avi">XviD</a> | <a href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.wmv9.wmv">WMV</a> ]<span id="more-431"></span></p>
<div style="clear:both;"></div>
<h2>Watch</h2>
<p><embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=2277&#038;fwVideoDuration=3293&#038;fwNumSlots=8&#038;adSlotPosition_0=0&#038;adSlotClass_0=PREROLL&#038;adSlotProfile_0=R3_video&#038;adSlotPosition_1=180&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=780&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1215&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=1620&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;adSlotPosition_5=2040&#038;adSlotClass_5=OVERLAY&#038;adSlotProfile_5=R3_overlay&#038;adSlotPosition_6=2460&#038;adSlotClass_6=OVERLAY&#038;adSlotProfile_6=R3_overlay&#038;adSlotPosition_7=2880&#038;adSlotClass_7=OVERLAY&#038;adSlotProfile_7=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" /></p>
<h2>Show Notes</h2>
<p>Is WPA Broken? Interesting stuff coming out of <a href="http://pacsec.jp" target="_blank">PacSec</a> this year. Ars has a great <a href="http://arstechnica.com/articles/paedia/wpa-cracked.ars/" target="_blank">writeup</a> about it our check out Martin Beck and Erik Tews&#8217; paper <a href="http://dl.aircrack-ng.org/breakingwepandwpa.pdf" target="_blank">Practical attacks against WEP and WPA</a> (PDF). There is a proof of concept tool available from the Aircrack-NG folks. Take a look at <a href="http://www.aircrack-ng.org/doku.php?id=tkiptun-ng" target="_blank">Tkiptun-ng</a>. At time of writing the tool is not fully functional. Something to keep an eye on.</p>
<p>Steve P. writes to us about the <a href="http://helmer.sfe.se/" target="_blank">Helmer beowulf cluster</a>. This 6xCore2Quad is sure to make any geek smile. <a href="http://helmer.sfe.se/2-delar-helmer.JPG" target="_blank">Kitty approved</a> too! While stuffing a personal cluster into an Ikea cabinet is novel in and of itself the mad scientist behind it has thought some insane cluster designs including the 50 tflop <a href="http://helmer2.sfe.se/" target="_blank">Helmer 2</a> and the 4 pflop <a href="http://helmer3.sfe.se/" target="_blank">Helmer 3</a>. All I can say is I want one. Thanks for the links Steve.</p>
<p>Darren enjoys a <a href="http://www.webtender.com/db/drink/3627" target="_blank">Bondages&#8217; No Problem</a> while Matt and Shannon stick with the margaritas.</p>
<p>More importantly Darren talks about Session Hijacking and demos a tool from <a href="http://www.erratasec.com/" target="_blank">Errata Security</a> called <a href="http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html" target="_blank">Hamster and Ferret</a> that, in conjunction with the latest 2.0 build of <a href="http://www.digininja.org/jasager/index.php" target="_blank">Jasager</a>, an ICS&#8217;d EVDO connection and <a href="http://tftpd32.jounin.net/" target="blank">Tftpd32</a> we&#8217;re able to &#8220;sidejack&#8221; with our little man-in-the-middle setup. Lesson learned? Be suspicious of <u>any</u> wifi. Check for signatures of trusted networks and <a href="http://www.ssh.com/support/documentation/online/ssh/winhelp/32/Tunneling_Explained.html" target="_blank">tunnel your traffic</a>. We&#8217;ll come back to this topic with a more indepth segment on Jasager detection and traffic encryption soon.</p>
<p>A note on trivia. Please answer trivia questions on the <a href="http://www.hak5.org/forums" target="_blank">Hak5 forums</a> from now on. We would love to continue doing dual winners but with growing prize costs we cannot. Also, if you&#8217;re interested in volunteering to help with trivia code challenges lend a hand in the Dev5 board.</p>
<p>Matt shows us how to convert a physical server into a virtual server locally using the free <a href="http://www.vmware.com/products/converter" target="_blank">VMware converter</a> tool and talks about some of the concerns you must consider when preparing to virtualize. If you have virtualization questions hit up Matt and we&#8217;ll cover &#8216;em on future segments. Matt at Hak5 d0t org.</p>
<p>Alex W. writes with a question about screen recording. We highly recommend the open source <a href="http://camstudio.org" target="_blank">Camstudio</a> as well as <a href="http://www.fraps.com">FRAPS</a> and Techsmith&#8217;s <a href="http://www.techsmith.com/camtasia.asp" target="_blank">Camtasia Studio</a> (warning: sticker shock may occur at techsmith.com). Paul (our &#8220;camera guy&#8221;) suggests checking out the new screen capturing functionality of the latest verison of <a href="http://www.videolan.org" target="_blank">VLC</a>, especially if you&#8217;re on the Linux or Mac side.</p>
<p>As always we&#8217;d love to hear your feedback. Your questions, comments or concerns can be directed to <a href="mailto:feedback@hak5.org</a>feedback@hak5.org</a>. And lastly we&#8217;d like to thank Nikki Colp for the amazing Hak5 painting. We have it prominently displayed in our living room. You can watch it (and us) live 24&#215;7 at <a href="http://www.hakhouse.com" target="_blank">HakHouse.com</a>. It&#8217;s a crazy interactive project we&#8217;re working on. Just wait &#8217;till we get the web-enabled robots up in there. <img src='http://Hak5.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Trust your Technolust</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-412/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.h264.mp4" length="466132773" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.xvid.avi" length="418839284" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.wmv9.wmv" length="536656180" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 409 &#8212; HappyHakoween: Password Cracking Clusters, Remote Control Services, Wireshark Packet Filtering</title>
		<link>http://Hak5.org/episodes/episode-409</link>
		<comments>http://Hak5.org/episodes/episode-409#comments</comments>
		<pubDate>Wed, 29 Oct 2008 16:29:25 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[beowulf cluster]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[grid computing]]></category>
		<category><![CDATA[Headers]]></category>
		<category><![CDATA[IP]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[mosix]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[Packet]]></category>
		<category><![CDATA[Packet Sniff]]></category>
		<category><![CDATA[Panel Dameon]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[pxe]]></category>
		<category><![CDATA[service.msc]]></category>
		<category><![CDATA[srvany]]></category>
		<category><![CDATA[tcp]]></category>
		<category><![CDATA[Windows Service]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=402</guid>
		<description><![CDATA[<embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0409/hak5--0409--HappyHakoween--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0409/hak5--0409--HappyHakoween--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1863&#038;fwVideoDuration=2710&#038;fwNumSlots=5&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=780&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1460&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1860&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=2280&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-409"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-409&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.hak5.org/episodes/episode-409/"><img src="http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0409/hak5--0409--HappyHakoween--medium.thumb.jpg" border="0"/></a><br />Matt shows us how to turn anything into a service and provide a web frontend to manage them windows server, great for game server administration. Chris Gerling wraps up his three part series on Packet Sniffing with Wireshark techniques for packet filtering. Darren harnesses the CPU power of the HakHouse for good or evil to demonstrate cluster computing. Plus details on our Hak5 Halloween LAN Party!<br />[ <a href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0409/hak5--0409--HappyHakoween--large.h264.mp4">MP4</a> | <a href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0409/hak5--0409--HappyHakoween--large.xvid.avi">XviD</a> | <a href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0409/hak5--0409--HappyHakoween--large.wmv9.wmv">WMV</a> ]<span id="more-402"></span></p>
<div style="clear:both;"></div>
<h2>Watch</h2>
<p><embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0409/hak5--0409--HappyHakoween--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0409/hak5--0409--HappyHakoween--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1863&#038;fwVideoDuration=2710&#038;fwNumSlots=5&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=780&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1460&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1860&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=2280&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" /></p>
<h2>Show Notes</h2>
<p><a href="http://www.mattlestock.com" target="_blank">Matt Lestock</a> turns any windows application into a service using <a href="http://support.microsoft.com/kb/137890" target="_blank">instsrv and srvany</a> and demonstrates how we use this technique, coupled with <a href="http://www.paneldaemon.com/" target="_blank">Panel Daemon</a> to delegate game server administration at the Hak5 playground.</p>
<p><a href="http://www.chrisgerling.com" target="_blank">Chris Gerling</a> shows us some packet filtering techniques using the network analyzer <a href="http://www.wireshark.org" target="_blank">Wireshark</a>. He covers capture filters, display filters, colors and statistics. Read more on packet sniffing on his blog at <a href="http://www.chrisgerling.com" target="_blank">ChrisGerling.com</a></p>
<p><a href="http://www.darrenkitchen.net" target="_blank">Darren Kitchen</a> talks about parallel computing. He touches on grid computing and massively parallel processors though he mainly focuses on clustering. Darren demonstrates simple windows password cracking techniques using an openMosix based image and discusses the theory behind setup. Darren has a lot of further reading for you to check out on <a href="http://www.darrenkitchen.net" target="_blank">his blog</a> and would like to hear your feedback about building the Hak5 beowulf cluster!</p>
<p>And on a production note: We&#8217;ve switched over from a standard-def composite based video mixing solution to a high-def HDMI based system. Unfortunately until we get a Mac Pro and switch to Final Cut Pro for editing we&#8217;re unable to release a 720p version of Hak5. But we&#8217;re well on our way to bringing you guys truly high def technolust thanks to everyone who has continued to <a href="http://www.hak5.org/stickers/">support this cause</a>. Thanks!</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-409/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0409/hak5--0409--HappyHakoween--large.h264.mp4" length="383516843" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0409/hak5--0409--HappyHakoween--large.xvid.avi" length="347637444" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0409/hak5--0409--HappyHakoween--large.wmv9.wmv" length="448609572" type="video/x-ms-wmv" />
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  hak5.org/tag/crack/feed ) in 0.99830 seconds, on Feb 7th, 2012 at 6:46 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Feb 7th, 2012 at 7:46 am UTC -->
