<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hak5 - Technolust since 2005 &#187; Pineapple</title>
	<atom:link href="http://Hak5.org/tag/pineapple/feed" rel="self" type="application/rss+xml" />
	<link>http://Hak5.org</link>
	<description>Trust Your Technolust</description>
	<lastBuildDate>Mon, 06 Feb 2012 02:17:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>WiFi Pineapple: your first connection</title>
		<link>http://Hak5.org/hack/wifi-pineapple-first-connect</link>
		<comments>http://Hak5.org/hack/wifi-pineapple-first-connect#comments</comments>
		<pubDate>Wed, 04 May 2011 22:48:45 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[WiFi Pineapple]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[OpenWRT]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[Teathering]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=3457</guid>
		<description><![CDATA[
			
				
			
		
So you&#8217;ve built, borrowed or bought a WiFi Pineapple and you&#8217;re new to OpenWRT and Jasager. Hopefully this guide will familiarize you with the many aspects of the the WiFi Pineapple. If you have specific ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fhack%2Fwifi-pineapple-first-connect"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fhack%2Fwifi-pineapple-first-connect&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>So you&#8217;ve built, borrowed or bought a <a target="_blank" href="http://hakshop.com/collections/frontpage/products/wifi-pineapple">WiFi Pineapple</a> and you&#8217;re new to OpenWRT and Jasager. Hopefully this guide will familiarize you with the many aspects of the the WiFi Pineapple. If you have specific questions please leave a comment or email feedback@hak5.org and we&#8217;ll try to keep this page updated.</p>
<p>This article will guide you through connecting to the <a target="_blank" href="http://hakshop.com/collections/frontpage/products/wifi-pineapple">WiFi Pineapple</a> for the first time. For more in-depth how-to&#8217;s involving command line control, modules, using the white and black listing functions, sharing Internet access and more please consult the <a href="http://www.hak5.org/forums/index.php?showforum=49">Jasager board on the Hak5 forums</a> and keep an eye on the <a href="http://hak5.org/category/wifi-pineapple-hack">WiFi Pineapple category of the Hak5.org blog</a> for future articles on these topics.<span id="more-3457"></span></p>
<h2>First and foremost</h2>
<p>The <a target="_blank" href="http://hakshop.com/collections/frontpage/products/wifi-pineapple">WiFi Pineapple</a> is a customized version of OpenWRT running the latest Jasager software by Robin Wood. Since OpenWRT is a Linux based wireless networking operating system you&#8217;ll want to be familiar with basic Linux and <a href="http://www.tcpipguide.com/free/t_NetworkingFundamentals.htm">networking fundamentals</a>.</p>
<h2>Tools you&#8217;ll find handy</h2>
<p>Right out of the box most everything can be configured with just about any web browser, but you&#8217;ll likely also want a tool or two to get a shell and transfer files. If you&#8217;re using Linux or Mac you already have the ssh and scp commands at your disposal. If you&#8217;re on Windows we recommend using the <a href="http://www.chiark.greenend.org.uk/~sgtatham/putty/">PuTTY</a> and <a href="http://winscp.net/eng/index.php">WinSCP</a> GUI tools or the command-line equivelent <a href="http://www.chiark.greenend.org.uk/~sgtatham/putty/">Plink</a>.</p>
<h2>Battery Powering the Pineapple</h2>
<p>The WiFi Pineapple requires 5V and 2A of DC power. If you&#8217;re looking to go mobile leave the wall-wart at home. Four AA rechargeable batteries work well at powering this puppy. It&#8217;s important to get AA batteries with a high mAh rating. We recommend <a href="http://www.amazon.com/s/ref=nb_sb_ss_c_1_21?url=search-alias%3Delectronics&amp;field-keywords=2500+mah+aa+batteries&amp;x=0&amp;y=0&amp;sprefix=2500+mah+aa+batteries">no less than 2400</a>, so pick up a few meant for digital cameras for best results. If your standard alkalines aren&#8217;t doing the trick it&#8217;s probably due to a low mAh rating. Check the packaging. Of course we recommend rechargeables over the landfill populating variety.</p>
<h2>Connecting for the first time</h2>
<p>There are many ways to connect to and configure a <a target="_blank" href="http://hakshop.com/collections/frontpage/products/wifi-pineapple">WiFi Pineapple</a>. Here are a few:</p>
<h3>Via Ethernet</h3>
<p>Power up and connect an Ethernet cable between your computer and the router&#8217;s. In its stock configuration the WiFi Pineapple is configured with the static IPv4 address of 192.168.1.1. It is also setup to hand out IP addresses in the 192.168.1.0/24 range via DHCP. If your machine is configured to obtain an IP address automatically you should get something like 192.168.1.100 from it momentarily.</p>
<h3>Configuring your interface to obtain an IP address from the WiFi Pineapple&#8217;s DHCP server</h3>
<p>In case your computer is not already setup to obtain an IP address on the Ethernet interface from a DHCP server, here are quick instructions for some common operating systems.</p>
<h3>Windows XP</h3>
<p>Open Network Connections from the Control Panel. Right-click on the Local Area Connection and choose Properties. From the dialog select Internet Protocol TCP/IP and click Properties. From the General tab choose Obtain an IP address automatically and Obtain DNS server address automatically. Click OK twice.</p>
<h3>Windows 7</h3>
<p>Click Choose Network Status and Tasks from the Control Panel. Click Change adapter settings. Right click the Local Area Connection and choose Properties. Select Internet Protocol Version 4 and click Properties. Select Obtain and IP address automatically and Obtain DNS server address automatically, then click OK twice.</p>
<h3>Linux / Mac</h3>
<p>Open a terminal and issue ifconfig eth0 where eth0 is the Ethernet interface connected to the WiFi Pineapple. Check the inet addr reported. If it is not a 192.168.1.x address you&#8217;ll want to manually ask for an address from the DHCP server on the pineapple. Depending on your distribution the command to do this may be &#8220;dhclient eth0&#8243; or &#8220;dhcpcd eth0&#8243;.</p>
<h3>Via Wireless</h3>
<p>By default the SSID of the WiFi Pineapple is either &#8220;Pineapple&#8221; or &#8220;OpenWRT&#8221; without encryption. Connect to it as you would to any ordinary wireless access point. The pineapple will assign you an IP address via DHCP. If for some reason your Wireless interface has not been configured to obtain an address automatically please consult the above instructions substituting your wireless interface for the Ethernet interface.</p>
<h3>Via Serial</h3>
<p>WiFi Pineapples bought or built on Fon 2100 or Accton MR3201A hardware sport shell access through a serial interface. For information on this access method please consult these fine documents:</p>
<ul>
<li><a href="http://www.digininja.org/projects/fon_serial_cable.php">Fon Serial Cable at digininja.org</a></li>
<li><a href="http://www.dd-wrt.com/wiki/index.php/LaFonera_Hardware_Serial-Cable-Port">LaFonera Hardware Serial-Cable-Port on dd-wrt.com</a></li>
</ul>
<p>&nbsp;</p>
<h2>Accessing the Jasager Interface</h2>
<p>Once connected via Ethernet or wireless you can point your web browser at the Jasager management interface. Here you can configure the interface, karma, mac address filtering, ssid white/black listing and execute commands on connected clients.</p>
<p>By default the Jasager interface can be found at http://192.168.1.1:1471. It&#8217;s important to note the :1471 bit as that specifies the non-standard port number of this http interface. Any modern web browser will work, be it Firefox, Chrome, Safari, Opera or Internet Explorer. I&#8217;ve even successfully used it with the text-only browser Lynx! You&#8217;ll need to login. By default the username is root and password is &#8220;pineapplesareyummy&#8221; (sans quotes).</p>
<h3>Status / Main Controls</h3>
<p>The options in this section allow you to control the wireless card and karma features. The SSID list is a list of SSIDs that the interface will either accept (whitelist mode) or ignore (blacklist mode). One thing to watch out for is that changing from blacklist to whitelist mode, and vise-versa does not reset the SSID list.</p>
<h3>Connected Clients</h3>
<p>The list of connected clients comes from a merger of wlanconfig output, information in the log file and the ARP cache. A blank IP address may mean the client hasn&#8217;t got an IP address or hasn&#8217;t used it for a while so it has slipped from the ARP table.<br />
The dropdown list of commands allows you to add the clients SSID to the watch list and kick the MAC address. Kicking is not blocking a MAC, just temporarily disconnecting it, most clients will attempt to reconnect within seconds of being kicked. Kicking can be useful if you blacklist a SSID and need to remove any currently associated clients. I have an idea that this list will grow with useful commands such as blocking MAC addresses and initiating things such as nmap scans. Watch out for new features in version 2.</p>
<h3>Log</h3>
<p>All activity is logged to /karma/log/status.log which gets dumped out to the log window.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/hack/wifi-pineapple-first-connect/feed</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Hak5 911 &#8211; Circumvent Windows Login Security with a USB boot-drive, Phishing with a Pineapple and anonymous torrenting!</title>
		<link>http://Hak5.org/episodes/episode-911</link>
		<comments>http://Hak5.org/episodes/episode-911#comments</comments>
		<pubDate>Wed, 04 May 2011 19:00:30 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 9]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[Circumvent Windows Login Security with a USB boot-drive]]></category>
		<category><![CDATA[citrix]]></category>
		<category><![CDATA[crack the code challenge]]></category>
		<category><![CDATA[emails]]></category>
		<category><![CDATA[episode 911]]></category>
		<category><![CDATA[express]]></category>
		<category><![CDATA[gotoassist]]></category>
		<category><![CDATA[gotoassist express]]></category>
		<category><![CDATA[gtae]]></category>
		<category><![CDATA[gtax]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacker challenge]]></category>
		<category><![CDATA[hacker headlines]]></category>
		<category><![CDATA[Hak.5]]></category>
		<category><![CDATA[hak5kerby]]></category>
		<category><![CDATA[haktip]]></category>
		<category><![CDATA[headlines]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Katana]]></category>
		<category><![CDATA[kerby]]></category>
		<category><![CDATA[kon-boot]]></category>
		<category><![CDATA[konboot]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Phishing with a Pineapple and anonymous torrenting!]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[sudo]]></category>
		<category><![CDATA[tee]]></category>
		<category><![CDATA[trivia]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=3420</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/3uNdu9TM3HM?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/3uNdu9TM3HM?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-911"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-911&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show we&#8217;re Breaking into Windows boxes with no skillz necessary using Konboot for USB, Spear-Phishing with a WiFi Pineapple, Sudo with pipes in Linux and downloading torrents anonymously</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0911/hak5--0911--hotlattemod--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0911/hak5--0911--hotlattemod--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0911/hak5--0911--hotlattemod--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-3420"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/3uNdu9TM3HM?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube.com/v/3uNdu9TM3HM?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p><span style="font-weight: bold;">Hacker Headlines</span></p>
<div id="segmentDetails">
<div>
<div>
<p>Remember how Skype had a gaping security hole last week where third party apps could steal your data? <a href="http://www.engadget.com/2011/04/20/skype-for-android-update-adds-us-3g-calling-fixes-personal-data/" target="_blank">They fixed it!</a> And now if you own an Android 2.1 device, you can get Skype 3G calling without a Verizon Wireless sanctioned app. Pretty cool! Good job Skype!</p>
<p>If you&#8217;re a PS3 gamer with a credit card tied to your PlayStation Network account, now might be a good time to check your bank statements. After day long <a href="http://blog.us.playstation.com/2011/04/26/update-on-playstation-network-and-qriocity/" target="_blank">outages of PlayStation Network</a> and Qriocity, Sony is reporting that account information including name, address, email, birthdate, login, password and handles have been obtained by an unauthorized person. Sony isn&#8217;t ruling out the possibility that credit cards data was taken and is advising users to check their credit, keep an eye out for suspicious activity and follow up with the FTCs Identity Theft site. Sony has gone as far as to have provided the names and contact information of effected parties to the three major U.S. credit bureaus so that users may place a &#8220;fraud alert&#8221; on their files for free.</p>
<p>If you have an Xperia unbranded Play, Arc, Neo, or Pro, you can now try out custom ROM&#8217;s and mods. Sony Ericsson released the<a href="http://www.engadget.com/2011/04/13/sony-ericssons-android-bootloader-unlocking-site-goes-live-mod/" target="_blank">Android bootloader unlocking site</a>, so you can tinker to your hearts desire on those machines. But modders be aware! If it goes wrong, your warranty will too&#8230;</p>
<p>While Google has announced encryption support in the third version of its yet to be open sourced Android operating system, many are looking to <a href="https://guardianproject.info/" target="_blank">the Guardian Project</a> for features like full-disk encryption, secure instant messanging and anonymous web browsing. The project aims to create apps and open-source firmware for those looking to protect their communications.</p>
<p>Use that old CD ROM laser to create a <a href="http://diytechgadgets.blogspot.com/2011/04/laser-triggered-waterbomb-trap.html" target="_blank">laser triggered water bomb trap!</a> Great for pranks and giggles!</p>
</div>
<div>
<div>
<p><span style="font-weight: bold;"><br />
Crack the Code Challenge</span></p>
</div>
</div>
</div>
<div>
<div>
<p>Did you have what it took to compete in our Crack The Code Challenge, brought to you by GoToAssist Express? These Hak5 viewers did last Sunday. Mad props go to Mr-Protocol and Hack_sipop215 who made it to the first of three timed checkpoints.</p>
<p>A big thanks go out to all that participated, joined the live stream and chat, and of course GoToAssist Express for sponsoring our Hak5 Lab Network. Stay tuned for info on the next, even bigger Crack the Code Challenge.</p>
<p>And be sure to tune in next week as we&#8217;ll have a detailed walk through on how the challenge was completed.</p>
</div>
<div>
<div>
<p><span style="font-weight: bold;"><br />
Phishing with a WiFi Pineapple</span></p>
</div>
</div>
</div>
<div>
<div>
<p>Following up on last weeks <a href="http://hak5.org/hack/auto-rickrolling-wifi-pineapple" target="_blank">auto-rickrolling WiFi Pinepaple</a> I decided to take it a step further with a little phishing expedition in Berkeley. See the entire step-by-step at <a href="http://hak5.org/hack/pineapple-phishing" target="_blank">hak5.org/hack/pineapple-phishing</a>.</p>
</div>
<div>
<div>
<p><span style="font-weight: bold;"><br />
Trivia!</span></p>
</div>
</div>
</div>
<div>
<div>
<p>Last weeks trivia: What is the name of the virus, considered the first known use of polymorphic code?</p>
<p>The Answer was: 1260</p>
<p>This week&#8217;s question is: The UK version of this device represents 10 Pence with a 1000 Hz tone. What is the device?</p>
<p>Answer at <a href="http://hak5.org/trivia" target="_blank">hak5.org/trivia</a> to win some sweet swag.</p>
</div>
<div>
<p><span style="font-weight: bold;">Circumvent Windows Security with Konboot for USB</span></p>
</div>
</div>
<div>
<div>
<p>&#8220;Konboot from a USB</p>
<p>I did a segment on Konboot back on <a href="http://hak5.org/episodes/episode-518" target="_blank">episode 518</a>, but I wanted to recap it and show you how to boot <a href="http://www.piotrbania.com/all/kon-boot/" target="_blank">Konboot</a> from a USB instead. If you haven&#8217;t checked it out already, Konboot is a tool that lets you change the contents of a Windows or Linux kernel while booting, enabling you to bypass the root user password while logging in. It was originally created for the user to boot in case they forgot their own password, so you shouldn&#8217;t use this for malicious purposes. Konboot was made for CD and floppy, so you have to follow these simple steps to get it working from a USB. These steps only work for 32 bit machines, so if you have a 64 bit machine, hold tight and I&#8217;ll show you how to do that afterwards.</p>
<p><strong>32 bit:</strong></p>
<p>First, download UNetbootin and install the program. Then, download the Konboot Floppy image from the Konboot website and extract the zip file (password is kon-boot) so you can get the FD0-konboot-v1.1-2in1.img file. You&#8217;ll also have to extract the floppy image file folder as well. Plug in your USB flash drive. It doesn&#8217;t have to be very big, I&#8217;m just using a little 1 GB flashdrive.</p>
<p>Run <a href="http://unetbootin.sourceforge.net/" target="_blank">UNetbootin</a> on your computer, select Diskimage, click the drop down menu to select floppy and browse for the .img konboot file. Under type, choose USB drive and under Drive, choose your USB drive letter. Double and triple check this so you don&#8217;t overwrite your main harddrive! Now click ok and wait for the Konboot floppy image to install onto your USB drive.</p>
<p>Now that you have the USB ready, reboot your computer with the USB plugged in, choose to boot from USB first, and you should see a UNetbootin screen pop up.</p>
<p>Select Default, which is your USB and you should see the Kryptos Logic boot screen, which is KonBoot.</p>
<p>Press any key and you&#8217;ll see some Konboot ASCII art and it starts to boot into Windows. You may run into a problem with an infinite loop, and if you do, follow IronGeek&#8217;s tutorial for fixing this problem. He was able to modify the syslinux.cfg file to fix this problem.</p>
<p>Go over to <a href="http://www.irongeek.com/i.php?page=security/kon-boot-from-usb" target="_blank">IronGeek&#8217;s blog</a> and download his .zip file. Extract it, and save the two files onto the root of your USB stick.</p>
<p>Restart your computer and boot from your USB drive again, this time starting with the 1st KonBoot and click through until you get back to the syslinux screen again.</p>
<p>This time choose &#8220;&#8221;2nd try boot as hd1&#8243;&#8221;, then try hd2, and hd3 until one of the boots lets you through to Windows.</p>
<p><strong>64-bit</strong></p>
<p>If you have a 64 bit machine, you won&#8217;t be able to use these steps above. The only way I could get it to work on my Windows 7 64 bit laptop was to download the new version of Katana from Hack From A Cave.</p>
<p>Download the Katana RAR file and extract everything to the root of your USB stick. This is 4 gigs so you&#8217;ll need a bigger drive. Mine is 8 GB.</p>
<p>Click Start, type CMD, right click and choose Run As Administrator. Type in your USB drive, mine is D:, then enter. Type dir to view files, then type bootinst.bat and press enter. Follow the on screen steps.</p>
<p>Now you&#8217;re ready to boot! Restart your computer and boot off the USB. Katana should open. Choose Konboot and log onto Windows.</p>
<p>Now you can get back onto your computer if you forgot your password!</p>
<p>Email me at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a> with questions or comments!</p>
<p><span style="font-weight: bold;"><br />
HakTip</span></p>
</div>
</div>
<div>
<div>
<p>This HakTip was sent in from Matt who recently saw me opening a root shell when I was unable to run</p>
<blockquote>
<pre>sudo echo 1 &gt; /proc/sys/net/ipv4/ip_forward</pre>
</blockquote>
<p>He wanted to let me know that there is a way to use echo to write to files that need root permissions without getting a root shell by running:</p>
<blockquote>
<pre>echo 1 | sudo tee /proc/sys/net/ipv4/ip_forward</pre>
</blockquote>
<p>running <a href="http://ss64.com/bash/tee.html" target="_blank">tee</a> this way will act like a &gt; and if you want to use tee to act like &gt;&gt; then just use tee -a.</p>
<p>Also, Matt votes for vi over nano <img src='http://Hak5.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> &#8221;</p>
<p><span style="font-weight: bold;"><br />
Emails</span></p>
</div>
</div>
<div>
<div>
<blockquote><p>Hey guys and gal, Been sharing your segments on proxmox and I am very curious besides the fact that its free, how does it compare to the big boys like vmware ? Also is it good enough for production use say in a small business of 25 users? One lasts question have you heard of ulteo? If so what do you think of using it with proxmox?</p></blockquote>
<blockquote><p>Christian Writes: Love all your shows,very interesting stuff. I had a question regarding torrents and proxies. I am using &#8220;&#8221;"&#8221;utorrent&#8221;"&#8221;" and would like to mask my real IP. I know there are a couple of paying services out there which would let me use utorrent and not show my real ip address and also encrypt my connection. I was looking at a service like www.btguard.com, I was also looking at open vpn. What are your best suggestions,ideas or recommended services for what I want to do?</p></blockquote>
</div>
<div>
<div>
Keep up with the latest on Hak5 by follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>. <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> and get your weekly technolust delivered automatically. Or show your support and grab some swag from the <a href="http://hak5.org/store" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> and<a href="http://www.hak5.org/store/hak5-hoodie" target="_blank">hoodie</a>. Finally if you&#8217;d like to suggest a topic for ask a question feel free to hit up <a href="mailto:feedback@hak5.org" target="_blank">feedback@hak5.org</a>.</p>
</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-911/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0911/hak5--0911--hotlattemod--hd720p30.h264.mp4" length="" type="" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0911/hak5--0911--hotlattemod--large.wmv9.wmv" length="0" type="video/asf" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0911/hak5--0911--hotlattemod--large.h264.mp4" length="439404353" type="video/mp4" />
		</item>
		<item>
		<title>Hak5 910 &#8211; OpenWRT and WiFi Pineapple mods, Gmail 2-step verification, zScreen screencaptures, Image burning and MD5 hashes</title>
		<link>http://Hak5.org/episodes/episode-910</link>
		<comments>http://Hak5.org/episodes/episode-910#comments</comments>
		<pubDate>Wed, 27 Apr 2011 07:15:55 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 9]]></category>
		<category><![CDATA[2 step verification]]></category>
		<category><![CDATA[bebo]]></category>
		<category><![CDATA[berlin]]></category>
		<category><![CDATA[burn]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[cd burn]]></category>
		<category><![CDATA[chaos computer club]]></category>
		<category><![CDATA[dnsmasq]]></category>
		<category><![CDATA[fastsum]]></category>
		<category><![CDATA[flickr]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[google mail]]></category>
		<category><![CDATA[Hak.5]]></category>
		<category><![CDATA[haktip]]></category>
		<category><![CDATA[imgburn]]></category>
		<category><![CDATA[iso]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[MD5]]></category>
		<category><![CDATA[md5sum]]></category>
		<category><![CDATA[OpenWRT]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[rickroll]]></category>
		<category><![CDATA[screenshot]]></category>
		<category><![CDATA[Snubs]]></category>
		<category><![CDATA[trivia]]></category>
		<category><![CDATA[twitpic]]></category>
		<category><![CDATA[utility]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>
		<category><![CDATA[zscreen]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=3389</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/aMqmv0q0AAc?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/aMqmv0q0AAc?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-910"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-910&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show, the Gmail 2-step verification, the easiest screen shot utility in the world, Image burning, MD5 integrity verification and the auto-rickrolling pineapple of doom!</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0910/hak5--0910--twosteprickrolldoom--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0910/hak5--0910--twosteprickrolldoom--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0910/hak5--0910--twosteprickrolldoom--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-3389"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/aMqmv0q0AAc?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/aMqmv0q0AAc?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object></p>
<p><b>Hacker Headlines</b></p>
<p><a href="http://arstechnica.com/gaming/news/2011/04/hotz-lawyer-ps3-hacking-case-over-dmca-and-ip-abuse-live-on.ars" target="_blank">Sony and George Hotz have called a truce</a>. Settling outside court famed PS3 hacker GeoHot agreed not to be &#8220;engaging in any unauthorized access to any SONY PRODUCT under the law&#8221; etc&#8230; Following the settlement <a href="http://arstechnica.com/gaming/news/2011/04/hacker-george-hotz-donates-10k-to-eff-mocks-sony.ars" target="_blank">Hotz donated $10k to the Electronic Frontier Foundation</a>, money left over from his donated legal defense fund.</p>
<p>Skype made a boo-boo. Android Police found this little <a target="_blank" href="http://www.engadget.com/2011/04/14/skype-for-android-vulnerable-to-hack-that-compromises-personal-i/">vulnerability in the Skype app for Android</a>, where it seems that the SQLite3 databases where all your chat logs and info is stored was never protected. Skype forgot to encrypt the databases. That means a rogue app could potentially steal data out of your Skype app and send it back to the bad guy. Android Police created this app called Skypwned just to show how the breached can effect you. Oops!</p>
<p>Revealed at the Where 2.0 conference this week, security researchers published details on how <a target="_blank" href="http://arstechnica.com/apple/news/2011/04/how-apple-tracks-your-location-without-your-consent-and-why-it-matters.ars">iPhones and 3G iPads have been periodically logging your location</a>. Since iOS 4.0 the file consolidated.db has been storing timestamps with latitude-longitude coordinates. The researchers <a target="_blank" href="http://radar.oreilly.com/2011/04/apple-location-tracking.html">published an open source tool</a>, dubbed <a target="_blank" href="http://petewarden.github.com/iPhoneTracker/">iPhone Tracker</a>, which maps your devices stored locations.</p>
<p>Looks like Skype isn&#8217;t the only one with trouble brewing. <a target="_blank" href="http://techcrunch.com/2011/04/13/hacker-gains-access-to-wordpress-com-servers/">WordPress.com&#8217;s servers were hacked</a> pretty deep, root-access level deep. They say a bunch of customer&#8217;s source codes were accessible, so they&#8217;re having the vulnerable site change their passwords and API&#8217;s. The breach was on Automattic.com&#8217;s servers to be exact, the software company behind the WordPress platform. Obviously, a lot of information was viewable, but hopefully all the customer&#8217;s have already fixed any problems on their sites.</p>
<p>Mad Scientists Photonicinduction bring happyness to the world with a video demonstrating <a target="_blank" href="http://www.youtube.com/watch?v=Zi_bMYFmFGg">how to erase the data off a CD by spinning between it between two high voltage transformers</a>. </p>
<p><b>HakTip: zScreen</b></p>
<p>Want to capture print screens and share them, but don&#8217;t want to go through the hassle of saving, uploading, and all that jazz? Try zScreen. </p>
<p>zScreen will automatically capture screenshots, text, or files from your computer clipboard and upload them to a destination of your choice, as well as have the link to it automatically copied to your computer when it&#8217;s completed.  </p>
<p>Simply download zScreen from code.google.com and install. Once installed, choose your destination for images, files, and text, and the type of URL shortener you would like to use. Under destinations, you can authenticate and authorize zScreen to upload to your FTP, ImageShack, Flickr, even Twitter page, and tons of others. For myself, I&#8217;m going to upload to my Flickr page. zScreen uses OAuth, so all it requires is your username, not your password. It&#8217;ll authenticate through your Flickr site. You can even choose settings such as what window you want the print screen to copy, you can add a watermark, and tons of other options. Once you&#8217;ve gotten your settings squared away, hit your favorite HotKey and watch as your image gets uploaded to your account automatically. </p>
<p>So I hit PrtSc, and my full size image gets uploaded to my Flickr just like that. After it&#8217;s uploaded I can easily copy the image link from my clipboard. The link is also saved in zScreen.</p>
<p>It&#8217;s a great time saver, and perfect for easily taking notes on your screen and sharing them with others. Thanks to Patrick F for sending this in to us. Do you have a time saver or something cool to share? Email <a href="mailto:tips@hak5.org">tips@hak5.org</a> and we&#8217;ll share them.</p>
<p><b>OpenWRT / WiFi Pineapple mod: Auto-Rickroll</b></p>
<p>&#8220;John Bebo&#8217;s Auto-Rickroll payload for the WiFi Pineapple is an excellent example of using Dnsmasq to forward targets to a hosted site. While this site could be malicious, perhaps hosing the Browser Exploitation Framework, Bebo&#8217;s payload is a safe and simple prank. Any web site a victim attempts to browse to brings them to a WiFi Pineapple hosted page containing Rick Astley ASCII Art and looping audio. It uses a similar technique employed by Captive Portals – something we&#8217;ll explore in more detail soon – except a lot more annoying.</p>
<p>Thanks to great documentation from Bebo and Hak5 forum member Psychosis setting up your own Auto-rickrolling WiFi Pineapple is super simple. In fact, this will work on just about any OpenWRT based wireless access point – but we&#8217;ll be focusing on the WiFi Pineapple specifically for its Jasager abilities.</p>
<p>Follow the step-by-step article with pictures and video at <a target="_blank" href="http://www.hak5.org/hack/auto-rickrolling-wifi-pineapple">hak5.org/hack/auto-rickrolling-wifi-pineapple</a></p>
<blockquote><p>
scp * pineapple<br />
mv *. /etc/config<br />
mv * /www/<br />
touch /etc/dnsmasq.conf<br />
echo address=/#/192.168.1.1 > /etc/dnsmasq.conf<br />
vi /etc/init.d/jasager<br />
add to start()<br />
wlanconfig ath0 create wlandev wifi0 wlanmode master 2>&#038;1 > /dev/null<br />
iwpriv ath0 karma 1<br />
brctl addif br-lan ath0<br />
ifconfig eth0 up<br />
#comment out iptables<br />
reboot
</p></blockquote>
<p><b>Trivia</b></p>
<p>Our last trivia question was: What is the name of this prominent computer club that was founded in Berlin in 1981? And the answer was: Chaos Computer Club</p>
<p>This week&#8217;s trivia question is: What is the name of this virus, considered the first known use of polymorphic code?</p>
<p>Answer at <a target="_blank" href="http://www.hak5.org/trivia/">hak5.org/trivia</a> for a chance to win some swag! </p>
<p><b>2 Step Verification in Gmail</b></p>
<p>Although I know all of you out there protect your online accounts like crazy, there is always a way to get more protection. Maybe you don&#8217;t like using an encryption program or you use the same password for all of your sites. Although this is really bad, I think all of us have done that once or twice in the past. So perhaps you want to try something new.</p>
<p>I just discovered Gmail 2 Step Verification process for my google mail account. I&#8217;ve been a little paranoid lately with all the cyber attacks going on, so I decided to up my security, especially because my email is the one site I really don&#8217;t want hacked. </p>
<p><a target="_blank" href="http://gmailblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html">2 Step Verification</a> can help prevent unauthorized access that someone might have with just a stolen password. Now, when I sign in to gmail, I&#8217;ll not only need my password, but also a code that generates on my phone.</p>
<p>You might be thinking, &#8216;Well, what if your phone gets stolen?&#8217;. I set up a passcode on my phone, a series of random numbers that only I remember, and I set it so if I try brute forcing the passcode, after 10 wrong codes, it&#8217;ll wipe my phone. </p>
<p>Back to Gmail. When setting this up, first you&#8217;ll need your phone. If you won&#8217;t have a secure phone nearby when you sign in to Gmail, perhaps this isn&#8217;t the tool for you. </p>
<p>Click on &#8220;&#8221;Set Up 2 Step Verification&#8221;" and choose your phone. Androids, Blackberries, and Iphones have a special Google Authenticator app that will generate your random codes. </p>
<p>The first time you open the app, it&#8217;ll ask you to scan a QR code with your phone&#8217;s camera. This QR code generates your first series of random digits, and it ties you, the phone holder, to your gmail account. If you don&#8217;t have a usable camera or can&#8217;t read the QR code, choose to create a time-based key instead, and type your secret key into your phone.</p>
<p>Click next after taking your photo and verify your generated code. Gmail will then ask you to set up a backup in case your phone is lost or stolen. Next you will need a printer or a safe place to save your backup codes. I had a printer installed so I printed my backup codes. Each of these codes will let you sign in once to your gmail. </p>
<p>After printed, click next and choose a backup phone. This can be a home phone, a spouses phone, etc. Type in the phone number and you can then test it if you want. I set up my personal number to my home phone, and when I tested it, it called me and left me a message with a new generated code. When you hit next, confirm your account, and turn on 2 Step Verification.</p>
<p>When you first log in, you&#8217;ll type in your account name, password, then your verification code off your phone. You can also choose if you want the code remembered for 30 days or if you want it to ask you for a new code every time you log in.</p>
<p>You&#8217;ll notice after you turn on 2 Step Verification that all your devices tied to your gmail account are logged out. Things like gmail for iphone, the mail app, etc, don&#8217;t have a place to type in a verification code. To help your security, you&#8217;ll need to set up application specific passwords. To do this, under the 2 Step Verification main page, choose application specific passwords.</p>
<p>Choose a name of your device, for example, mine will be &#8220;&#8221;Shannon&#8217;s Iphone&#8221;". Click next and you&#8217;ll see a series of letters and numbers that you&#8217;ll have to type in to your Iphone. So I type in my username, and under the password box I type in this generated password and click next. I only have to do this one time, ever. So I won&#8217;t need to memorize this code.</p>
<p>But what happens if someone gets ahold of Shannon&#8217;s Iphone? Luckily, under the code, you can see my Iphone. If I choose &#8216;Revoke&#8217;, all access to my mail will be logged out on my Iphone until I authorize it again.</p>
<p>If at any time I need new printed codes, or I need to change my phones, I can go under account settings, 2 Step Verification and edit anything I need. I can even turn off 2 Step Verification if needed.</p>
<p>I LOVE 2 Step Verification. It makes me feel a lot more secure about my mail and personal information. Questions? Comments? Have another program for me? Email <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
<p><b>Emails: CD Burning and nomnomfish</b></p>
<blockquote><p>Max S writes: I have been watching your show since season 6. Since then you mentioned a program named Konboot few times.<br />
I was curious and tried getting it. But  I have a problem, I successfully download it, and extract it using winrar but when I burn it to a blank CD it doesn’t work.<br />
Am I missing something or does konboot not function anymore?</p></blockquote>
<p>Shannon recommends verifying the integrity of the download using a tool like <a target="_blank" href="http://www.fastsum.com/">Fast Sum</a> or MD5SUM and burning with a tool like <a href="http://www.imgburn.com/">IMG Burn</a></p>
<p>Keep up with the latest on Hak5 by follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>. <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> and get your weekly technolust delivered automatically. Or show your support and grab some swag from the <a href="http://hak5.org/store" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> and <a href="http://www.hak5.org/store/hak5-hoodie" target="_blank">hoodie</a>. Finally if you&#8217;d like to suggest a topic<br />
for ask a question feel free to hit up <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-910/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0910/hak5--0910--twosteprickrolldoom--hd720p30.h264.mp4" length="572165795" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0910/hak5--0910--twosteprickrolldoom--large.h264.mp4" length="363285983" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0910/hak5--0910--twosteprickrolldoom--large.wmv9.wmv" length="153225688" type="video/asf" />
		</item>
		<item>
		<title>Episode 724 &#8211; Bypassing NSFW filters and Android Packet Sniffing</title>
		<link>http://Hak5.org/episodes/episode-724</link>
		<comments>http://Hak5.org/episodes/episode-724#comments</comments>
		<pubDate>Fri, 30 Jul 2010 02:14:32 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 7]]></category>
		<category><![CDATA[2.2]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[atheros]]></category>
		<category><![CDATA[darren kitchen]]></category>
		<category><![CDATA[droid]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[free proxy]]></category>
		<category><![CDATA[froyo]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[Hak.5]]></category>
		<category><![CDATA[honey pot]]></category>
		<category><![CDATA[hot spot]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[jailbroken]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Karma]]></category>
		<category><![CDATA[linksys]]></category>
		<category><![CDATA[madwifi]]></category>
		<category><![CDATA[nsfw]]></category>
		<category><![CDATA[office filter]]></category>
		<category><![CDATA[open]]></category>
		<category><![CDATA[packet sniffing]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[san francisco]]></category>
		<category><![CDATA[school filter]]></category>
		<category><![CDATA[shannon morse]]></category>
		<category><![CDATA[shark]]></category>
		<category><![CDATA[sniff]]></category>
		<category><![CDATA[ssid]]></category>
		<category><![CDATA[web filter]]></category>
		<category><![CDATA[wep]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>
		<category><![CDATA[wifi tether]]></category>
		<category><![CDATA[wireshark]]></category>
		<category><![CDATA[work filter]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=2254</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/1hRaIqZZRUo&#038;hl=en_US&#038;fs=1&#038;hd=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/1hRaIqZZRUo&#038;hl=en_US&#038;fs=1&#038;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-724"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-724&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This week Shannon is bypassing NSFW filters while Darren goes sniffing for packets in all the wrong places.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-2254"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/1hRaIqZZRUo&#038;hl=en_US&#038;fs=1&#038;hd=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/1hRaIqZZRUo&#038;hl=en_US&#038;fs=1&#038;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object></p>
<p>Darren takes <a href="http://code.google.com/p/android-wifi-tether/" target="_blank">Android WiFi Tether</a> and <a href="http://forum.xda-developers.com/showthread.php?t=675206" target="_blank">Shark</a> for a spin and ends up learning an important geography lesson.</p>
<p>Shannon is demonstrating a few techniques to detecting NSFW links and bypassing potential work filters with a few web tools, including: <a href="http://www.longurl.com" target="_blank">LongURL.com</a>, <a hrer="http://www.PDFmyURL.com" target="_blank">PDFmyURL.com</a>, <a href="http://aviary.com" target="_blank">Aviary.com</a> and <a href="http://variablysfw.appspot.com" target="_blank">Variably Safe For Work</a>.</p>
<p>&#8212;</p>
<p><b>You’re Invited to Hak5’s Birthday!</b></p>
<p>Join us to celebrate 5 years of technolust at the Hotsy Totsy Club &#8211; an Albany institution since 1939! Come for drinks, pool, shuffleboard and a live performance from nerdcore sensation, <a href="http://www.dualcoremusic.com" target="_blank">Eighty of Dual Core</a>! 21+. No cover. Street parking. 7 blocks from El Cerrito BART. WiFi. Taco’s Autlense Taco Truck parked in lot. Need we say more?</p>
<p><a href="http://revision3.com/blog/2010/07/29/youre-invited-to-hak5s-birthday/"><img src="http://bitcast-a.bitgravity.com/revision3/assets/hak5_anniversary/poster.jpg" border="0"></a></p>
<p>Saturday, August 14th at 7:00 PM<br />
Hotsy Totsy Club<br />
601 San Pablo Ave.<br />
Albany, CA 94706</p>
<p><a href="http://www.facebook.com/event.php?eid=143146699044983" target="_blank">RSVP now via Facebook</a> &#8211; can’t wait to celebrate the grand years of old school hacking with you!</p?</p>
<p>If you want to know the latest on Hak5 be sure to follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>.</p>
<p>Also, now is also a great time to grab some swag from the <a href="http://www.hak5.org/shop/" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> with free world-wide shipping.</p>
<p>And finally if you&#8217;d like to suggest a topic for a future show feel free to hit up <a href="mailto:feedback@hak5.org">feedback@hak5.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-724/feed</wfw:commentRss>
		<slash:comments>10</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--hd720p30.h264.mp4" length="217" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--large.h264.mp4" length="214" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--large.xvid.avi" length="214" type="video/avi" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0724/hak5--0724--the-sound-of-wifi--large.wmv9.wmv" length="214" type="video/asf" />
		</item>
		<item>
		<title>Episode 706 – Deauth Detection and Cloud Data Backups</title>
		<link>http://Hak5.org/episodes/episode-706</link>
		<comments>http://Hak5.org/episodes/episode-706#comments</comments>
		<pubDate>Wed, 24 Mar 2010 16:08:24 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 7]]></category>
		<category><![CDATA[802.11]]></category>
		<category><![CDATA[backupify]]></category>
		<category><![CDATA[cloud data]]></category>
		<category><![CDATA[deauth]]></category>
		<category><![CDATA[deauth attack]]></category>
		<category><![CDATA[deauth ddos]]></category>
		<category><![CDATA[deauthorize]]></category>
		<category><![CDATA[deauthorize attack]]></category>
		<category><![CDATA[delicious backup]]></category>
		<category><![CDATA[flickr backup]]></category>
		<category><![CDATA[Fon]]></category>
		<category><![CDATA[frame injection]]></category>
		<category><![CDATA[gmail backup]]></category>
		<category><![CDATA[google docs backup]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Karma]]></category>
		<category><![CDATA[management frame]]></category>
		<category><![CDATA[monitor mode]]></category>
		<category><![CDATA[packet injection]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[raw frame injection]]></category>
		<category><![CDATA[twitter backup]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wifi attack]]></category>
		<category><![CDATA[wifi ddos]]></category>
		<category><![CDATA[wifi hacks]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>
		<category><![CDATA[wordpress backup]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1759</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v5043" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent"  />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-706"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-706&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Back in studio with Shannon this week. Darren has answers to your WiFi deauthorization attack questions and a demo of a nifty deuth watching script. Shannon&#8217;s all about free and open source alternatives to online backup services like Backupify. Can these tools keep your cloud data secure?</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0706/hak5--0706--deauth--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0706/hak5--0706--deauth--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0706/hak5--0706--deauth--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0706/hak5--0706--deauth--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1759"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v5043" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent"  /></p>
<p><B>Deauthorization Attacks explained (with demo)</B></p>
<p>This week we&#8217;re answering viewer questions regarding last week&#8217;s wireless deauthorization attacks.</p>
<blockquote><p>
How does Deauth work if a client connected to an AP using encryption?<br />
-Mark B
</p></blockquote>
<p>The answer lies in the fact that 802.11b/a/n/g management frames, special packets used to establish and maintain communications, are all sent unencrypted. These include:</p>
<ul>
<li>Authentication</li>
<li>Association request</li>
<li>Association response</li>
<li>Reassociation request</li>
<li>Reassociation response</li>
<li>Beacon</li>
<li>Probe request</li>
<li>Probe response</li>
<ul>
<p>And finally our favorite&#8230;</p>
<ul>
<li>Deauthentication</li>
</ul>
<blockquote><p>
I was wondering how do I prevent the de authorize attacks and man-in-the-middle attacks on my laptop or computer<br />
-Test Account
</p></blockquote>
<p>Short of rewriting your wireless radio&#8217;s firmware to ignore deauthorization packets I&#8217;m at a loss when it comes to preventing the attack. If you know of a way please get in touch. That said, deauth attacks are quite simple to detect.</p>
<p>Viewer <a href="http://www.twitter.com/tinman2k/" target="_blank">Tinman2k</a> wrote in with a simple python script that uses airmon-ng and scappy to scan for associations, authentications and deauthentications.</p>
<p>You&#8217;ll need to begin by placing your card into monitor mode. For example: airmon-ng wlan0 start. Then pass your monitor interface to readAuthDeauth.py</p>
<blockquote>
<pre>
#!/usr/bin/env python

######################################################
#	authWatch.py v. 0.1 (Quick, Dirty and Loud) - by TinMan
#	Place card in monitor mode and set the channel.
#	If you want channel hopping, run airodump-ng in
#	another terminal. Will add channel hopping
# 	in the next version.
######################################################
#
#	Usage: python authWatch.py <monitor-interface>
#	

import sys
from scapy import *

interface = sys.argv[1]

def sniffReq(p):
     if p.haslayer(Dot11Deauth):
# Look for a deauth packet and print the AP BSSID, Client BSSID and the reason for the deauth.
           print p.sprintf("Deauth Found from AP [%Dot11.addr2%] Client [%Dot11.addr1%], Reason [%Dot11Deauth.reason%]")
# Look for an association request packet and print the Station BSSID, Client BSSID, AP info.
     if p.haslayer(Dot11AssoReq):
           print p.sprintf("Association request from Station [%Dot11.addr1%], Client [%Dot11.addr2%], AP [%Dot11Elt.info%]")
# Look for an authentication packet and print the Client and AP BSSID
		   if p.haslayer(Dot11Auth):
	   print p.sprintf("Authentication Request from [%Dot11.addr1%] to AP [%Dot11.addr2%]")
 	   print p.sprintf("------------------------------------------------------------------------------------------")
sniff(iface=interface,prn=sniffReq)
</pre>
</blockquote>
<p><B>Backing up your Cloud Data</B></p>
<p>One of these day the monkeys will rise up and conquer the net as we know it. That&#8217;s why having good backups of your online data is important. So rather than getting screwed when gmail, google docs, flickr, delicious, twitter and wordpress go down, let&#8217;s use free and open source software to make proper backups.</p>
<p>Online services like <a href="http://www.backupify.com" target="_blank">Backupify</a> make it easy to backup your cloud data &#8212; but it&#8217;s just from one cloud to another (Amazon S3). If you&#8217;d like a local copy of your data check out these programs</p>
<ul>
<li><a href="http://sunkencity.org/flickredit" target="_blank">FlickrEdit</a></li>
<li><a href="http://www.gmail-backup.com/" target="_blank">Gmail-Backup</a></li>
<li><a href="http://code.google.com/p/gdocbackup/" target="_blank">GDocBackup</a></li>
<li><a href="http://sourceforge.net/projects/googlebackup/" target="_blank">Google Doc Backup</a></li>
<li><a href="http://lifehacker.com/5136845/backup-delicious-bookmarks-from-the-shell" target="_blank">Backing up Delicious with wget</a></li>
<li><a href="http://tweetake.com/" target="_blank">Tweetake</a></li>
<li><a href="http://tweetbackup.com/" target="_blank">TweetBackup</a></li>
<li><a href="http://johannburkard.de/blog/programming/java/backup-twitter-tweets-with-twitterbackup.html" target="_blank">Johann Burkard&#8217;s Open Source Twitter Backup tool</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-706/feed</wfw:commentRss>
		<slash:comments>27</slash:comments>
		</item>
		<item>
		<title>Episode 705 – Airport WiFi Challenge and your Ultra Software Picks</title>
		<link>http://Hak5.org/episodes/episode-705</link>
		<comments>http://Hak5.org/episodes/episode-705#comments</comments>
		<pubDate>Wed, 17 Mar 2010 11:07:11 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 7]]></category>
		<category><![CDATA[accton]]></category>
		<category><![CDATA[aircrack]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[airdrop]]></category>
		<category><![CDATA[airport]]></category>
		<category><![CDATA[alfa]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack 4]]></category>
		<category><![CDATA[bt4]]></category>
		<category><![CDATA[deauth]]></category>
		<category><![CDATA[Fon]]></category>
		<category><![CDATA[free wifi]]></category>
		<category><![CDATA[Freeware]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Karma]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[ultra]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1753</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v4941" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-705"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-705&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>While meeting up with family in Florida this week Darren takes on a WiFi Challenge using the airport friendly Pineapple Mark II and Airdrop-ng. Plus, Shannon has a follow-up to the Ultra Software including your picks.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0705/hak5--0705--airportchallenge--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0705/hak5--0705--airportchallenge--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0705/hak5--0705--airportchallenge--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0705/hak5--0705--airportchallenge--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1753"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v4941" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent" /></p>
<p><b>Airport WiFi Challenge &#8211; Jasager and Deauths</b></p>
<p>Once again my travels take me to a wonderful and target rich environment &#8212; the airport.</p>
<p>And while I typically don&#8217;t take on challenges, this one tickled my technolust. I was asked how many clients I could harness with a <a href="http://www.hak5.org/store/" target="_blank">WiFi Pineapple</a> during a typical hour long layover at the airport. I figured this was a great opportunity to test out <a href="http://airodump.net/airdropng-video-presentation-security-conference-shmoocon-2010/" target="_blank">Airdrop-ng</a>.</p>
<p><b>Your Ultra Software Picks</b></p>
<p>In a follow-up from episode 703, Shannon counts down your Ultra software picks, including:</p>
<ul>
<li><a href="" target="_blank">Total Commander</a></li>
<li><a href="" target="_blank">JkDefrag</a></li>
<li><a href="" target="_blank">Ultimate Boot CD</a></li>
<li><a href="" target="_blank">Super Anti-Spyware</a></li>
<li><a href="" target="_blank">Process Explorer</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-705/feed</wfw:commentRss>
		<slash:comments>41</slash:comments>
		</item>
		<item>
		<title>Episode 626 — Shmoocon 2010</title>
		<link>http://Hak5.org/episodes/episode-626</link>
		<comments>http://Hak5.org/episodes/episode-626#comments</comments>
		<pubDate>Tue, 09 Feb 2010 16:18:41 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[2010]]></category>
		<category><![CDATA[802.11]]></category>
		<category><![CDATA[aircrack]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[airdrop]]></category>
		<category><![CDATA[airdrop-ng]]></category>
		<category><![CDATA[airdump]]></category>
		<category><![CDATA[airodump]]></category>
		<category><![CDATA[and decrypting GSM]]></category>
		<category><![CDATA[app]]></category>
		<category><![CDATA[archive team]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[bot net]]></category>
		<category><![CDATA[cloning]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[de-auth]]></category>
		<category><![CDATA[de-authentication]]></category>
		<category><![CDATA[deassociation]]></category>
		<category><![CDATA[deauth]]></category>
		<category><![CDATA[deauthentication]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[geocities]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker con]]></category>
		<category><![CDATA[Hackers]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[ipwn]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[jason scott]]></category>
		<category><![CDATA[Karma]]></category>
		<category><![CDATA[linked-in]]></category>
		<category><![CDATA[Man-in-the-middle sniffing]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[OUI]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[riocities]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[shmoocon 2010]]></category>
		<category><![CDATA[spoofing]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[textfiles]]></category>
		<category><![CDATA[theX1le]]></category>
		<category><![CDATA[tom eston]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wifi bomb]]></category>
		<category><![CDATA[wireless]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1975</guid>
		<description><![CDATA[
			
				
			
		
We head out to DC for Shmoocon, our favorite hacker conference on the east coast, to talk to some of the brightest minds in security. We talk to Tom Eston about social media security, TheX1le ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-626"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-626&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>We head out to DC for Shmoocon, our favorite hacker conference on the east coast, to talk to some of the brightest minds in security. We talk to Tom Eston about social media security, TheX1le about his new tool airdrop-ng, Jason Scott about preserving our digital heritage, Chris Paget about man-in-the-middle attacks against GSM networks, and much more.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0626/hak5--0626--shmoocon2010--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1975"></span><br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="555" height="312" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube-nocookie.com/v/7BUz3vYXac0&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" /><param name="wmode" value="transparent" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube-nocookie.com/v/7BUz3vYXac0&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" wmode="transparent" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><strong>Airdrop-ng</strong></p>
<p>Self taught packet junkie TheX1le shares with us his new tool for wireless de-authentication and deassociation. Airdrop-ng facilitates client control with versatile rule based control.</p>
<p><strong>Cloning, Spoofing, Man-in-the-middle sniffing, and decrypting GSM</strong></p>
<p>
Chris Paget of <a href="http://www.h4rdw4re.com/" target="_blank">h4rdw4re</a> shares with us the in&#8217;s and out&#8217;s of GSM hacking. Armed with a USRP and his open-source software, Paget pretends to be your GSM tower, and a lot more.
</p>
<p><strong> Jason Scott &#8211; Defender of Digital Heritage</strong><br />
<a href="http://www.textfiles.com" target="_blank">Textfiles.com</a> very own Jason Scott joins us to talk about preserving our digital heritage with <a href="http://www.archiveteam.org" target="_blank">Archive Team</a> and why it&#8217;s important to keep Geocities, Netscape Now buttons, and *gasp* Hamster Dance.
</p>
<p><strong>Social Media Security</strong></p>
<p>Tom Eston shares with us the delicious dangers of social networks while in the hands of web-application exploiting hackers. No worries, he&#8217;s got you covered at <a href="http://www.socialmediasecurity.com" target="_blank">socialmediasecurity.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-626/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Episode 412 &#8212; Session Hijacking and Virtualizing Servers</title>
		<link>http://Hak5.org/episodes/episode-412</link>
		<comments>http://Hak5.org/episodes/episode-412#comments</comments>
		<pubDate>Wed, 19 Nov 2008 17:03:52 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[aircrack-ng]]></category>
		<category><![CDATA[Camstudio]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[Converter]]></category>
		<category><![CDATA[Cookies]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[Ed Piskor]]></category>
		<category><![CDATA[Errata]]></category>
		<category><![CDATA[ESX]]></category>
		<category><![CDATA[Ferret]]></category>
		<category><![CDATA[FRAPS]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hakhouse]]></category>
		<category><![CDATA[Hamster]]></category>
		<category><![CDATA[Helmer]]></category>
		<category><![CDATA[Ikea]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Nikki Colp]]></category>
		<category><![CDATA[Pacsec]]></category>
		<category><![CDATA[Pacsec08]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[Screencast]]></category>
		<category><![CDATA[Session Hijacking]]></category>
		<category><![CDATA[Techsmith]]></category>
		<category><![CDATA[TKIP]]></category>
		<category><![CDATA[tkiptun-ng]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[WPA]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=431</guid>
		<description><![CDATA[<embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=2277&#038;fwVideoDuration=3293&#038;fwNumSlots=8&#038;adSlotPosition_0=0&#038;adSlotClass_0=PREROLL&#038;adSlotProfile_0=R3_video&#038;adSlotPosition_1=180&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=780&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1215&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=1620&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;adSlotPosition_5=2040&#038;adSlotClass_5=OVERLAY&#038;adSlotProfile_5=R3_overlay&#038;adSlotPosition_6=2460&#038;adSlotClass_6=OVERLAY&#038;adSlotProfile_6=R3_overlay&#038;adSlotPosition_7=2880&#038;adSlotClass_7=OVERLAY&#038;adSlotProfile_7=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-412"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-412&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.hak5.org/episodes/episode-412/"><img src="http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--medium.thumb.jpg" border="0"/></a><br />Session Hijacking with a Pineapple, Hamster and Ferret and cell phone? A free and easy way to virtualize physical servers! And is WPA Broken? Ikea clusters, screencasting, and canvas technolust. <br />[ <a href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.h264.mp4">MP4</a> | <a href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.xvid.avi">XviD</a> | <a href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.wmv9.wmv">WMV</a> ]<span id="more-431"></span></p>
<div style="clear:both;"></div>
<h2>Watch</h2>
<p><embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=2277&#038;fwVideoDuration=3293&#038;fwNumSlots=8&#038;adSlotPosition_0=0&#038;adSlotClass_0=PREROLL&#038;adSlotProfile_0=R3_video&#038;adSlotPosition_1=180&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=780&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1215&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=1620&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;adSlotPosition_5=2040&#038;adSlotClass_5=OVERLAY&#038;adSlotProfile_5=R3_overlay&#038;adSlotPosition_6=2460&#038;adSlotClass_6=OVERLAY&#038;adSlotProfile_6=R3_overlay&#038;adSlotPosition_7=2880&#038;adSlotClass_7=OVERLAY&#038;adSlotProfile_7=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" /></p>
<h2>Show Notes</h2>
<p>Is WPA Broken? Interesting stuff coming out of <a href="http://pacsec.jp" target="_blank">PacSec</a> this year. Ars has a great <a href="http://arstechnica.com/articles/paedia/wpa-cracked.ars/" target="_blank">writeup</a> about it our check out Martin Beck and Erik Tews&#8217; paper <a href="http://dl.aircrack-ng.org/breakingwepandwpa.pdf" target="_blank">Practical attacks against WEP and WPA</a> (PDF). There is a proof of concept tool available from the Aircrack-NG folks. Take a look at <a href="http://www.aircrack-ng.org/doku.php?id=tkiptun-ng" target="_blank">Tkiptun-ng</a>. At time of writing the tool is not fully functional. Something to keep an eye on.</p>
<p>Steve P. writes to us about the <a href="http://helmer.sfe.se/" target="_blank">Helmer beowulf cluster</a>. This 6xCore2Quad is sure to make any geek smile. <a href="http://helmer.sfe.se/2-delar-helmer.JPG" target="_blank">Kitty approved</a> too! While stuffing a personal cluster into an Ikea cabinet is novel in and of itself the mad scientist behind it has thought some insane cluster designs including the 50 tflop <a href="http://helmer2.sfe.se/" target="_blank">Helmer 2</a> and the 4 pflop <a href="http://helmer3.sfe.se/" target="_blank">Helmer 3</a>. All I can say is I want one. Thanks for the links Steve.</p>
<p>Darren enjoys a <a href="http://www.webtender.com/db/drink/3627" target="_blank">Bondages&#8217; No Problem</a> while Matt and Shannon stick with the margaritas.</p>
<p>More importantly Darren talks about Session Hijacking and demos a tool from <a href="http://www.erratasec.com/" target="_blank">Errata Security</a> called <a href="http://erratasec.blogspot.com/2007/08/sidejacking-with-hamster_05.html" target="_blank">Hamster and Ferret</a> that, in conjunction with the latest 2.0 build of <a href="http://www.digininja.org/jasager/index.php" target="_blank">Jasager</a>, an ICS&#8217;d EVDO connection and <a href="http://tftpd32.jounin.net/" target="blank">Tftpd32</a> we&#8217;re able to &#8220;sidejack&#8221; with our little man-in-the-middle setup. Lesson learned? Be suspicious of <u>any</u> wifi. Check for signatures of trusted networks and <a href="http://www.ssh.com/support/documentation/online/ssh/winhelp/32/Tunneling_Explained.html" target="_blank">tunnel your traffic</a>. We&#8217;ll come back to this topic with a more indepth segment on Jasager detection and traffic encryption soon.</p>
<p>A note on trivia. Please answer trivia questions on the <a href="http://www.hak5.org/forums" target="_blank">Hak5 forums</a> from now on. We would love to continue doing dual winners but with growing prize costs we cannot. Also, if you&#8217;re interested in volunteering to help with trivia code challenges lend a hand in the Dev5 board.</p>
<p>Matt shows us how to convert a physical server into a virtual server locally using the free <a href="http://www.vmware.com/products/converter" target="_blank">VMware converter</a> tool and talks about some of the concerns you must consider when preparing to virtualize. If you have virtualization questions hit up Matt and we&#8217;ll cover &#8216;em on future segments. Matt at Hak5 d0t org.</p>
<p>Alex W. writes with a question about screen recording. We highly recommend the open source <a href="http://camstudio.org" target="_blank">Camstudio</a> as well as <a href="http://www.fraps.com">FRAPS</a> and Techsmith&#8217;s <a href="http://www.techsmith.com/camtasia.asp" target="_blank">Camtasia Studio</a> (warning: sticker shock may occur at techsmith.com). Paul (our &#8220;camera guy&#8221;) suggests checking out the new screen capturing functionality of the latest verison of <a href="http://www.videolan.org" target="_blank">VLC</a>, especially if you&#8217;re on the Linux or Mac side.</p>
<p>As always we&#8217;d love to hear your feedback. Your questions, comments or concerns can be directed to <a href="mailto:feedback@hak5.org</a>feedback@hak5.org</a>. And lastly we&#8217;d like to thank Nikki Colp for the amazing Hak5 painting. We have it prominently displayed in our living room. You can watch it (and us) live 24&#215;7 at <a href="http://www.hakhouse.com" target="_blank">HakHouse.com</a>. It&#8217;s a crazy interactive project we&#8217;re working on. Just wait &#8217;till we get the web-enabled robots up in there. <img src='http://Hak5.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Trust your Technolust</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-412/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.h264.mp4" length="466132773" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.xvid.avi" length="418839284" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0412/hak5--0412--SessionHijackingAndVirtualizing--large.wmv9.wmv" length="536656180" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 408 &#8212; Dissect TCP/IP, Dos Box, Alice, Day-Con, and Fon Batteries</title>
		<link>http://Hak5.org/episodes/episode-408</link>
		<comments>http://Hak5.org/episodes/episode-408#comments</comments>
		<pubDate>Wed, 22 Oct 2008 16:26:25 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[Abandonware]]></category>
		<category><![CDATA[Alice]]></category>
		<category><![CDATA[Battery]]></category>
		<category><![CDATA[Day-Con]]></category>
		<category><![CDATA[DayCon]]></category>
		<category><![CDATA[DOS]]></category>
		<category><![CDATA[Dos Box]]></category>
		<category><![CDATA[DOS Games]]></category>
		<category><![CDATA[Emulation]]></category>
		<category><![CDATA[Emulator]]></category>
		<category><![CDATA[ethereal]]></category>
		<category><![CDATA[Fon]]></category>
		<category><![CDATA[Headers]]></category>
		<category><![CDATA[IP]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Ninja]]></category>
		<category><![CDATA[Packet]]></category>
		<category><![CDATA[Packet Sniff]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[tcp]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=396</guid>
		<description><![CDATA[<embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0408/hak5--0408--BuildingPackets--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0408/hak5--0408--BuildingPackets--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1862&#038;fwVideoDuration=2544&#038;fwNumSlots=5&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=600&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1020&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1800&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=2220&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-408"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-408&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.hak5.org/episodes/episode-408/"><img src="http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0408/hak5--0408--BuildingPackets--medium.thumb.jpg" border="0"/></a><br />Chris Gerling breaks down IP and TCP headers with Wireshark and building blocks. Shannon Morse shows us DosBox, a free IBM PC DOS emulator. Christine Bourquin talks about Alice, a teaching programming language for beginners. Darren Kitchen summarises his experience at Day-Con and answers some questions about Fon batteries. [ <a href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0408/hak5--0408--BuildingPackets--large.h264.mp4">MP4</a> | <a href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0408/hak5--0408--BuildingPackets--large.xvid.avi">XviD</a> | <a href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0408/hak5--0408--BuildingPackets--large.wmv9.wmv">WMV</a> ]<span id="more-396"></span></p>
<div style="clear:both;"></div>
<h2>Watch</h2>
<p><embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0408/hak5--0408--BuildingPackets--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0408/hak5--0408--BuildingPackets--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1862&#038;fwVideoDuration=2544&#038;fwNumSlots=5&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=600&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1020&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1800&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=2220&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" /></p>
<h2>Show Notes</h2>
<p><a href="http://www.chrisgerling.com">Chris Gerling</a> dives into the structure of IP and TCP headers in part two of his three part series on packet sniffing. He covers everything from source ports to checksums and everything inbetween offering insight into TCP packets in plain English. Then in part three he covers basic Wireshark usage and advanced techniques. Read more on packet sniffing on his blog at <a href="http://www.chrisgerling.com">ChrisGerling.com</a></p>
<p><a href="http://www.snubsie.com">Shannon Morse</a> shares with us <a href="http://www.dosbox.com">DosBox</a>, the free and open source IBM PC emulator that allows you to break out those old floppies and play your DOS games once again. While we wait for DNF, anyone for a Duke Nukem 3D deathmatch?</p>
<p><a href="http://www.christinemelissa.com">Christine Bourquin</a> demos <a href="http://www.alice.org">Alice</a>, an innovative 3D programming language that makes it easy to teach programming using a simple drag-and-drop interface. Perfect for the next generation of computer scientists.</p>
<p><a href="http://www.darrenkitchen.net">Darren Kitchen</a> brings us his review of <a href="http://www.day-con.org">Day-Con</a> with photos courtesy of the <a href="http://n0where.org/security-twits/">security twits</a>. He also talks about Jasager <a href="http://hak5.org/forums/index.php?showforum=49">batteries</a> both big and small.</p>
<p>And on a production note: We&#8217;ve switched over from a standard-def composite based video mixing solution to a high-def HDMI based system. We&#8217;re not ready to release the full 720p quite yet as we&#8217;re ironing out (read: developing on the fly) the post production process but in the mean time we&#8217;ve got damn good looking 480p and we&#8217;re looking for your feedback. Thanks a million to everyone who has <a href="http://www.hak5.org/stickers/">donated</a> and helped make this happen!</p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-408/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0408/hak5--0408--BuildingPackets--large.h264.mp4" length="360801245" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0408/hak5--0408--BuildingPackets--large.xvid.avi" length="441959774" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0408/hak5--0408--BuildingPackets--large.wmv9.wmv" length="418296984" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 407 &#8212; Toorcon 2008: Robin Wood, Dan Griffin, and Jacob Appelbaum</title>
		<link>http://Hak5.org/episodes/episode-407</link>
		<comments>http://Hak5.org/episodes/episode-407#comments</comments>
		<pubDate>Wed, 15 Oct 2008 16:03:11 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[Cold Boot Attack]]></category>
		<category><![CDATA[Dan Griffin]]></category>
		<category><![CDATA[David Hulton]]></category>
		<category><![CDATA[Geo]]></category>
		<category><![CDATA[George Spillman]]></category>
		<category><![CDATA[h1kari]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Jacob Appelbaum]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[Robin Wood]]></category>
		<category><![CDATA[Sharepoint]]></category>
		<category><![CDATA[Toorcon]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=387</guid>
		<description><![CDATA[<embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0407/hak5--0407--toorcon2008--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0407/hak5--0407--toorcon2008--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1861&#038;fwVideoDuration=2300&#038;fwNumSlots=5&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=720&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1200&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1620&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=2040&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-407"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-407&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.hak5.org/episodes/episode-407/"><img src="http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0407/hak5--0407--toorcon2008--medium.thumb.jpg" border="0"/></a><br />Darren and Shannon head to San Diego for Toorcon and meet up with Robin Wood, Dan Griffin, and Jacob Appelbaum to talk about Jasager, Sharepoint Hacking, and the Cold Boot Attack. Plus Darren&#8217;s travel tips and &#8220;name that aircraft&#8221;. [ <a href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.h264.mp4">MP4</a> | <a href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.xvid.avi">XviD</a> | <a href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.wmv9.wmv">WMV</a> ]<span id="more-387"></span></p>
<div style="clear:both;"></div>
<h2>Watch</h2>
<p><embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0407/hak5--0407--toorcon2008--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0407/hak5--0407--toorcon2008--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1861&#038;fwVideoDuration=2300&#038;fwNumSlots=5&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=720&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1200&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1620&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;adSlotPosition_4=2040&#038;adSlotClass_4=OVERLAY&#038;adSlotProfile_4=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" /></p>
<h2>Show Notes</h2>
<p><a href="http://www.digininja.org">Robin Wood</a> describes the development and future of <a href="http://www.digininja.org/jasager/index.php">Jasager</a></p>
<p><a href="http://www.jwsecure.com">Dan Griffin</a> talks to us about his latest research into <a href="http://www.jwsecure.com/dan/2008/04/26/sharepoint-administration-port-security/">hacking sharepoint</a>.</p>
<p><a href="http://www.appelbaum.net/">Jacob Appelbaum</a> talks to us about the <a href="http://citp.princeton.edu/memory/">Cold Boot Attack</a></p>
<p>Interview with David Hulton (h1kari) and George Spillman (Geo) can be found at <a href="http://www.hak5.org/episodes/episode-407">hak5.org</a>.</p>
<p>Special thanks to <a href="http://www.dualcoremusic.com">Dual Core</a> for providing music for this episode.</p>
<h2>Supplemental Interview</h2>
<p><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/cuAyMHwijBY&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><embed src="http://www.youtube.com/v/cuAyMHwijBY&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"></embed></object></p>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-407/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.h264.mp4" length="327375257" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.h264.mp4" length="327375257" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.xvid.avi" length="399349346" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.xvid.avi" length="399349346" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.wmv9.wmv" length="382748438" type="video/x-ms-wmv" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0407/hak5--0407--toorcon2008--large.wmv9.wmv" length="382748438" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 401 &#8212; Wi-Fi Pineapples</title>
		<link>http://Hak5.org/episodes/episode-401-wi-fi-pineapples</link>
		<comments>http://Hak5.org/episodes/episode-401-wi-fi-pineapples#comments</comments>
		<pubDate>Mon, 08 Sep 2008 02:51:08 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 4]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Game]]></category>
		<category><![CDATA[homebrew]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[maltego]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=285</guid>
		<description><![CDATA[
			
				
			
		

In this season premiere episode of Hak5 Mubix joins us to talk about what&#8217;s new in Maltego, an open source forensics and intelligence gathering tool. Shannon rocks out with Audio surf, and Darren heads downtown ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-401-wi-fi-pineapples"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-401-wi-fi-pineapples&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.hak5.org/episodes/episode-401-wi-fi-pineapples"><img src="http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0401/hak5--0401--pineapples--medium.thumb.jpg" border="0"/></a><br />
In this season premiere episode of Hak5 Mubix joins us to talk about what&#8217;s new in Maltego, an open source forensics and intelligence gathering tool. Shannon rocks out with Audio surf, and Darren heads downtown to the coffee shop to own a wireless network with a pineapple. Grab some hax0rflakes &#8217;cause the bricks are gone and we&#8217;re back! <br /> [ <a href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0401/hak5--0401--pineapples--large.h264.mp4">MP4</a> | <a href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0401/hak5--0401--pineapples--large.xvid.avi">XviD</a> | <a href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0401/hak5--0401--pineapples--large.wmv9.wmv">WMV</a> ]</p>
<p><span id="more-285"></span></p>
<div style="clear:both;"></div>
<h2>Production Note</h2>
<p>Video issues will be resolved by 403. We&#8217;re using new equipment and didn&#8217;t catch a nasty bug in our system until after the second shoot</p>
<h2>Watch</h2>
<p><embed loop="false" quality="high" bgcolor="#171717" width="555" height="337" name="rev3_player" id="rev3_player" align="middle" allowScriptAccess="always" allowFullScreen="true" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" src="http://bitcast-a.bitgravity.com/revision3/swf/rev3_player.swf?AutoPlay=off&#038;Buffer=10&#038;File=http://www.podtrac.com/pts/redirect.flv/bitcast-a.bitgravity.com/revision3/flv/hak5/0401/hak5--0401--pineapples--large.fl8.flv&#038;ScrubMode=advanced&#038;Thumb=http://bitcast-a.bitgravity.com/revision3/images/shows/hak5/0401/hak5--0401--pineapples--large.thumb.jpg&#038;DefaultRatio=0.56&#038;AutoSize=off&#038;allowFullScreen=true&#038;AutoPlay=off&#038;videoId=1800&#038;fwVideoDuration=2133&#038;fwNumSlots=4&#038;adSlotPosition_0=180&#038;adSlotClass_0=OVERLAY&#038;adSlotProfile_0=R3_overlay&#038;adSlotPosition_1=600&#038;adSlotClass_1=OVERLAY&#038;adSlotProfile_1=R3_overlay&#038;adSlotPosition_2=1020&#038;adSlotClass_2=OVERLAY&#038;adSlotProfile_2=R3_overlay&#038;adSlotPosition_3=1500&#038;adSlotClass_3=OVERLAY&#038;adSlotProfile_3=R3_overlay&#038;PostRoll=" base="http://bitcast-a.bitgravity.com/revision3/swf/" /></p>
<h2>Show Notes</h2>
<p>Wi-Fi Pineapple</p>
<p>Why target individuals on a wireless network when you could have them come to you. Darren talks about the Jasager project, a small portable honey pot with a hunger for clients based on the La Fonera router. <a href="http://www.fon.com">http://www.fon.com</a>. <a href="http://www.digininja.org/jasager/index.php">Download Jasager</a>.</p>
<p>Maltego</p>
<p><a href="http://www.room362.com">Mubix</a> heads down to show us some fun new features in the open source forensics and intelligence gathering tool Maltego. Download at <a href="http://www.paterva.com">http://www.paterva.com</a> or find in the latest version of BackTrack at <a href="http://www.remote-exploit.org">http://www.remote-exploit.org</a>. Read more in <a href="http://www.room362.com/archives/225-Maltego-2-and-beyond-Part-1.html">Mubix&#8217;s Maltego article</a> at room362.</p>
<p>Audio-Surf</p>
<p>Shannon reviews the IGF award winning music game by Invisible Handlebar. Audio-Surf is like the result of F-Zero and Guitar Hero hooking up with the ability to import your own music. Single, 2-player and co-op modes make this highly addictive game one of our favorites. Available through steam at <a href="http://www.audio-surf.com">www.audio-surf.com</a></p>
<p>LAN Party</p>
<p>We&#8217;ll be hosting our first LAN Party this season all day Saturday, September 20th at game.hak5.org. Join in for some Counter-Strike: Source action. We&#8217;ll be shooting two episodes back to back that day so feel free to hit up the setcam at http://hak5.org and watch as we fumble lines and try not to team-kill. </p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-401-wi-fi-pineapples/feed</wfw:commentRss>
		<slash:comments>22</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0401/hak5--0401--pineapples--large.h264.mp4" length="298720919" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0401/hak5--0401--pineapples--large.xvid.avi" length="364497974" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0401/hak5--0401--pineapples--large.wmv9.wmv" length="351527364" type="video/x-ms-wmv" />
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  hak5.org/tag/pineapple/feed ) in 0.87739 seconds, on Feb 7th, 2012 at 7:16 am UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Feb 7th, 2012 at 8:16 am UTC -->
