<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hak5 - Technolust since 2005 &#187; ssl</title>
	<atom:link href="http://Hak5.org/tag/ssl/feed" rel="self" type="application/rss+xml" />
	<link>http://Hak5.org</link>
	<description>Trust Your Technolust</description>
	<lastBuildDate>Mon, 06 Feb 2012 02:17:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Hak5 1001 &#8211; DEFCON 19 Part 2 &#8211; Moxie on Authenticity and Hackers for Charity</title>
		<link>http://Hak5.org/episodes/hak5-1001</link>
		<comments>http://Hak5.org/episodes/hak5-1001#comments</comments>
		<pubDate>Sat, 27 Aug 2011 01:02:47 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 10]]></category>
		<category><![CDATA[comodo]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[hackers for charity]]></category>
		<category><![CDATA[johnny long]]></category>
		<category><![CDATA[moxie]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[sslstrip]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=4040</guid>
		<description><![CDATA[<object width="640" height="360"><param name="movie" value="http://www.youtube.com/p/BF77D0F1CB05CAB1?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="640" height="360" src="http://www.youtube.com/p/BF77D0F1CB05CAB1?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1001"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1001&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In this DEFCON 19 episode of Hak5, Darren speaks with <a href="http://www.thoughtcrime.org/" target="_blank">Moxie Marlinspike</a> on the future of authenticity and Johnny Long on the latest at <a href="http://www.hackersforcharity.org/" target="_blank">Hackers For Charity</a>.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1001/hak5--1001--defcon11cont--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1001/hak5--1001--defcon11cont--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/1001/hak5--1001--defcon11cont--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-4040"></span></p>
<div align="center">
<object width="640" height="360"><param name="movie" value="http://www.youtube.com/p/BF77D0F1CB05CAB1?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="640" height="360" src="http://www.youtube.com/p/BF77D0F1CB05CAB1?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object>
</div>
<p>If you&#8217;re into Hak5 you&#8217;ll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you&#8217;re a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let&#8217;s not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
<p>There are two things IT professionals and their clients have in common, they want the job done right and they want it done fast. That’s why I highly recommend Go To Assist Express by Citrix to anyone in I.T. It puts clients at ease with its simple and secure remote support and puts you in position to do what you do best – Access, Diagnose and Resolve. Try Go To Assist Express FREE for 30 days. Visit <a href="http://www.GoToAssist.com/hak5" target="_blank">GoToAssist.com/hak5</a> to see how you can deliver LIVE tech support to anyone, anywhere with <a href="http://www.GoToAssist.com/hak5" target="_blank">GoToAssist Express</a>.</p>
<p>If you want to build a video site or if your website has a play button, I recommend getting a dot TV domain. A dot TV website lets you showcase your original content and create a unique site, not just another YouTube channel.<br />
Just go to <a href="http://www.domain.com" target="_blank">Domain.com</a> and search for the perfect dot TV domain for your new idea. Then use coupon code <b>Hak5</b> at checkout to save an extra 15%.<br />
If you need to host your dot TV website, don’t forget about Domain.com’s web hosting plans. They’re less than six bucks a month and have everything you need to build, maintain, and promote your site.<br />
Remember – when you think domain names, think <a href="http://www.domain.com" target="_blank">Domain.com</a>. Got a great idea? It all starts with a great domain. <a href="http://www.domain.com" target="_blank">Domain.com</a></p>
<p>The Ben Heck Show is an all-new online-TV-series created for (and by) electronics enthusiasts, and sponsored exclusively by element14. Join Ben and friends for bi-weekly episodes as they modify and build all kinds of community-suggested gadgets. Got an idea for a mod? Then share it with Ben. Or, if you’re ready to build, we’re ready with the parts list to make it happen. Either way, be sure to tune-in at <a href="http://www.element14.com/TBHS" target="_blank">element14.com/TBHS</a></p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-1001/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1001/hak5--1001--defcon11cont--hd720p30.h264.mp4" length="348841298" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1001/hak5--1001--defcon11cont--large.h264.mp4" length="194200616" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1001/hak5--1001--defcon11cont--large.wmv9.wmv" length="306798129" type="video/asf" />
		</item>
		<item>
		<title>HakTip &#8211; Session hijacking with Firesheep</title>
		<link>http://Hak5.org/hack/session-hijacking-with-firesheep</link>
		<comments>http://Hak5.org/hack/session-hijacking-with-firesheep#comments</comments>
		<pubDate>Thu, 31 Mar 2011 02:09:01 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[HakTip]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[cache poison]]></category>
		<category><![CDATA[cain and abel]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[firesheep]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[haktip]]></category>
		<category><![CDATA[hijacking]]></category>
		<category><![CDATA[http]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[Packet Sniff]]></category>
		<category><![CDATA[session]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=3173</guid>
		<description><![CDATA[
			
				
			
		
In this haktip Shannon shows us the setup and use of the cookie steeling tool Firesheep to hijack Darren&#8217;s twitter session.



Websites always make you login with a username and password, but when you’re on their ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fhack%2Fsession-hijacking-with-firesheep"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fhack%2Fsession-hijacking-with-firesheep&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In this haktip Shannon shows us the setup and use of the cookie steeling tool Firesheep to hijack Darren&#8217;s twitter session.</p>
<div style="clear:both;"></div>
<p><span id="more-3173"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/zZVUb5A0HRw?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0&amp;start=450" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube.com/v/zZVUb5A0HRw?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0&amp;start=450" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p>Websites always make you login with a username and password, but when you’re on their page all cozy and logged in, you’re browsing insecurely on a regular old HTTP site. HTTP session hacking (called sidejacking) happens when an attacker gets the users cookie which you were transmitted when you first logged in, and they can use it to do anything you would normally do. The only way to really protect yourself from this is through SSL or HTTPS like what you see on your banking websites.</p>
<p><a href="http://codebutler.com/firesheep">Firesheep</a>, by Eric Butler, demonstrates how vunerable your login is. It’s a man in the middle attack firefox extension that anyone has the ability to use.</p>
<p>To use Firesheep, first make sure to download winpcap. Then download the browser extension and open it using firefox by dragging it into your list of extensions and add-ons. You may need to restart Firefox. Go to View–>Sidebar–>Firesheep and enable it. Now, simply click start capturing and you’ll be able to see the username and photo of anyone on your network that logs into one of the specific sites that Firesheep uses. Click on the name or photo of anyone on the list, and you are now logged in as them, with the ability to do whatever you want as them on that site. Scary huh? Luckily Twitter and Facebook have caught on to this and have enabled the ability to use HTTPS secure logins on their sites. So if you haven’t updated your settings, do it now!</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/hack/session-hijacking-with-firesheep/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hak5 906 &#8211; Cookies beware, we&#8217;re Session Hijacking! Blackbuntu vs BackTrack, Kompozer and a 28 foot multi-touch bar!</title>
		<link>http://Hak5.org/episodes/episode-906</link>
		<comments>http://Hak5.org/episodes/episode-906#comments</comments>
		<pubDate>Wed, 30 Mar 2011 19:32:09 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 9]]></category>
		<category><![CDATA[aaron bitler]]></category>
		<category><![CDATA[apr]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[ARP Cache Poison]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[automate 2011]]></category>
		<category><![CDATA[automate2011]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[blackbuntu]]></category>
		<category><![CDATA[blackbuntu vs blackbuntu]]></category>
		<category><![CDATA[cain and abel]]></category>
		<category><![CDATA[cookie]]></category>
		<category><![CDATA[Cookies]]></category>
		<category><![CDATA[Cookies beware]]></category>
		<category><![CDATA[crunchy logistics]]></category>
		<category><![CDATA[dreamwaver alternative]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[fake]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firesheep]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hack cookie]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hak.5]]></category>
		<category><![CDATA[haktip]]></category>
		<category><![CDATA[html]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[imaging source]]></category>
		<category><![CDATA[kompozer]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[mtbar]]></category>
		<category><![CDATA[Multi-Touch]]></category>
		<category><![CDATA[MultiTouch]]></category>
		<category><![CDATA[multitouch bar]]></category>
		<category><![CDATA[Packet Sniff]]></category>
		<category><![CDATA[pentoo]]></category>
		<category><![CDATA[Session Hijacking]]></category>
		<category><![CDATA[sidejacking]]></category>
		<category><![CDATA[sniff cookie]]></category>
		<category><![CDATA[sniffing]]></category>
		<category><![CDATA[snoop]]></category>
		<category><![CDATA[spoof]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[steal cookie]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[web authoring]]></category>
		<category><![CDATA[web page builder]]></category>
		<category><![CDATA[web site builder]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=3099</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/zZVUb5A0HRw?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/zZVUb5A0HRw?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-906"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-906&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show, Cookies beware! It&#8217;s Session Hijacking time. Darren reports from Automate 2011 with a 28 foot multi-touch bar. Plus, websites made easy with Kompozer, a Backtrack vs Blackbuntu review and a whole lot more.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0906/hak5--0906--with_robots--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0906/hak5--0906--with_robots--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0906/hak5--0906--with_robots--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-3099"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/zZVUb5A0HRw?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/zZVUb5A0HRw?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object></p>
<h4></h4>
<h4>Hacker Headlines</h4>
<p>SSL provider <a href="http://news.cnet.com/8301-31921_3-20046340-281.html" target="_blank">Comodo was hacked</a> allowing attackers to obtain secure certificates for Google, Yahoo, Skype and others. comodo is claiming that the sophisticated attack against its European partner must have been &#8220;state-driven.&#8221; <a href="http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html" target="_blank">Comodo&#8217;s own incident report</a>points out IP addresses from Iran responsible for the attack. While simply obtaining these certificates, which have since been disabled, wouldn&#8217;t make those sites vulnerable &#8212; it would allow passwords and emails to be snooped using man-in-the-middle attacks to impersonate the legitimate sites. That would be pretty trivial to do if, say, you were Iran, which controls the nations telecommunications infrastructure.</p>
<p>The <a href="http://www.engadget.com/2011/03/18/rsa-hacked-data-exposed-that-could-reduce-the-effectiveness-o/" target="_blank">RSA&#8217;s SecurID systems has been hacked!</a> The SecurID is a tool that authenticates by having you key in a password but also a series of random numbers. A few days ago the tool sent out an email to it&#8217;s users <a href="http://arstechnica.com/security/news/2011/03/rsa-says-hack-wont-allow-direct-attack-on-secureid-tokens.ars" target="_blank">saying it was a victim of a hack that extracted certain data from the RSA&#8217;s system</a>. Data that was directly related to their SecurID two-factor authentication tools. The RSA says it isn&#8217;t that bad, but make sure you beef up security at your company, i.e. make stronger passwords. Like that&#8217;s really going to get people to change their passwords.</p>
<p>Say you wanted to write your own <a href="http://www.wired.com/threatlevel/2011/03/scada-vulnerabilities/" target="_blank">Stuxnet like worm to attack SCADA systems?</a> Well your job just got a lot easier. <a href="http://www.zdnet.com/blog/security/researchers-release-details-on-34-scada-vulnerabilities/8483" target="_blank">Security researcher Luigi Auriemma</a> released proof of concept code for 34 vulnerabilities affecting SCADA systems from Siemens, Iconics, 7-Technologies and DATAC. The code, released on the bugtraq mailing list, doesn&#8217;t affect the backend systems, merely the operator platforms, however they would allow attackers to potentially crash systems, retrieve sensitive data or dig deeper into the network.</p>
<p>Check out those sweet Nintendo 3DS&#8217;s at your local retailer! Demo units have been available to play in stores, but they won&#8217;t let you check out the menu or the specs underneath the games that autoplay on the devices. Luckily, there is now <a href="http://gizmodo.com/#!5783427/how-to-access-a-demo-3ds-main-menu" target="_blank">a nice little hack</a> to let you get into the main menu and see what lies beneath inside these awesome new toys. Check the link and give it a try.</p>
<p>Is your government or ISP messing with your data? In the wake of the Internet blackouts of Egypt and Libya, <a href="http://research.google.com/university/relations/focused_research_awards.html" target="_blank">Google is announcing awards</a> of at least a million dollars to Georgia Tech researchers working on tools for web users, as well as smartphones and tablets, which <a href="http://www.networkworld.com/news/2011/032211-google-transparency-internet-gatech.html?page=1" target="_blank">detect whether ISPs are adhering to service level agreements</a> and if data is meing tampered with.</p>
<p>&#8211;</p>
<h4>HakTip: Session hijacking with Firesheep</h4>
<p>This week&#8217;s Hak Tip comes to us from Gary. Websites always make you login with a username and password, but when you&#8217;re on their page all cozy and logged in, you&#8217;re browsing insecurely on a regular old HTTP site. HTTP session hacking (called sidejacking) happens when an attacker gets the users cookie which you were transmitted when you first logged in, and they can use it to do anything you would normally do. The only way to really protect yourself from this is through SSL or HTTPS like what you see on your banking websites.</p>
<p><a href="http://codebutler.com/firesheep" target="_blank">Firesheep</a>, by Eric Butler, demonstrates how vunerable your login is. It&#8217;s a man in the middle attack firefox extension that anyone has the ability to use.</p>
<p>To use Firesheep, first make sure to download winpcap. Then download the browser extension and open it using firefox by dragging it into your list of extensions and add-ons. You may need to restart Firefox. Go to View&#8211;&gt;Sidebar&#8211;&gt;Firesheep and enable it. Now, simply click start capturing and you&#8217;ll be able to see the username and photo of anyone on your network that logs into one of the specific sites that Firesheep uses. Click on the name or photo of anyone on the list, and you are now logged in as them, with the ability to do whatever you want as them on that site. Scary huh? Luckily Twitter and Facebook have caught on to this and have enabled the ability to use HTTPS secure logins on their sites. So if you haven&#8217;t updated your settings, do it now!</p>
<p>Got a tip you want to share? Email them to tips@hak5.org and we&#8217;ll show them off!</p>
<p>&#8211;</p>
<h4>The 28 foot multi-touch bar!</h4>
<p>Darren reports from the <a href="http://www.automate2011.com/" target="_blank">Automate 2011</a> conference in Chicago checking out the <a href="http://photos.crunchylogistics.com/mtbar" target="_blank">mtBar</a> from <a href="http://crunchylogistics.com/" target="_blank">Crunchy Logistics</a> and <a href="http://www.theimagingsource.com/en_US/" target="_blank">Imaging Source</a>. This 28 foot rear diffused illumination multi-touch bar surface sports unlimited tracking of fingers and objects at 120 FPS. Darren gets the juicy details from Niel Dufva, Aaron Bitler and Brandon Hill from Crunchy Logistics, as well as John Berryman from Imaging Source.</p>
<p>&#8211;</p>
<h4>Trivia!</h4>
<p>Last week&#8217;s question was: In Season 5 of X Files, Esther Nairn is the creator of what &#8216;narly&#8217; entertainment software? The answer is: Autonomous Bots in Ninjitsu Princess. This weeks question is: In what episode of the X Files can the Lone Gunmen be seen attending DefCon in Vegas? Answer at <a href="http://www.hak5.org/trivia" target="_blank">hak5.org/trivia</a> for your chance to grab up some swag!</p>
<p>&#8211;</p>
<h4>Snubs Report: Kompozer</h4>
<p>Shannon checks out the easy web authoring tool <a href="http://www.kompozer.net/" target="_blank">Kompozer</a>. Here are some of her favorite features:</p>
<ul>
<li>Web authoring tool</li>
<li>No HTML or coding needed</li>
<li>FTP Site Manager- browseable side bar and tree view (kind of like Explorer&#8217;s folder pane)</li>
<li>Color Picker- Easy to use color swap, just click with your mouse.</li>
<li>Tabs- Can edit several docs at once</li>
<li>CSS Editor- Easy to create stylesheets</li>
<li>Styler- Toolbar lets you change style instantly</li>
<li>Customize toolbars</li>
<li>Forms- XUL-based UI to edit forms</li>
<li>Cleaner- get rid of annoying<br />
&#8216;s- make valid documents</li>
<li>XFN- Can add XHTML info saying you know and trust an external link</li>
<li>Visible Marks- can view carriage returns and block borders.</li>
<li>Table/ Cell resizing rulers- Adjust rows and columns easily</li>
<li>Automated Spellchecker</li>
</ul>
<p>&#8211;</p>
<h4>Road Test: Corsair Force SSD</h4>
<p>In the words of Mr Horse: &#8220;No sir, I don&#8217;t like it&#8221;</p>
<p>While the Corsair Force SSD has great performance numbers, a few major annoyances are harshing on my technolust.</p>
<p>No SSD should BSOD Windows on S3 resume. Nor should it report &#8220;No bootable device&#8221; upon cold boot.</p>
<p>Sorry Corsair, I gave it a fair chance for just about a month and even with the latest firmware this thing&#8217;s a dud.</p>
<p>&#8211;</p>
<h4>Emails: Computer models and Blackbuntu vs Backtrack</h4>
<blockquote><p>Victor writes: I was wondering whats the computer that you usually have in the show cause it looks really good i think i might want to get one but i don&#8217;t know the model or manufacturer.</p></blockquote>
<p>Darren and Shannon have both recently upgraded to the 11.6&#8243; Acer Aspire TimelineX 1830T. Darren has the Intel Core i7 version while Shannon has opted for the i3.</p>
<p>Prior to these Shannon was using the 9&#8243; Acer Aspire One and the 10&#8243; Nokia Booklet 3G while Darren has had the 7&#8243; ASUS eee PC 701, 9&#8243; Acer Aspire One and 15&#8243; ASUS N53J.</p>
<blockquote><p>Juan writes: I was watching episode 903 and at the end you mention Blackbuntu. I have use Backtrack before but have never herd of Blackbuntu I start it to poking around the internet and found not only Blackbuntu but GnackTrack too both are sort of the same idea both are base on ubuntu both use gnome and both have the standard Backtrack program suit so I was think all tree of them make for a good head to head battle or just for a review</p></blockquote>
<p>Darren has been playing with Blackbuntu for about a week now. Prior to that he&#8217;s been using BackTrack since 3.0, but never as a primary OS. Here are some of his initial observations:</p>
<ul>
<li>Blackbuntu is based on ubuntu 10.10 using Gnome as the window manager and contains a similar feature set to BackTrack.</li>
<li>BackTrack is more established, while Blackbuntu is on version 0.2 it&#8217;s counterpart BackTrack is nearing beta of version 5.</li>
<li>BackTrack is the basis for the Offensive Security courses and certifications, which teach all sorts of pentesting and wireless attacks in both live-in-person and online learning scenarios</li>
<li>In comparison to BackTrack, Blackbuntu doesn&#8217;t have much of a community. You&#8217;re more likely to find tutorials and help for BackTrack</li>
<li>That said, most of what you&#8217;d do with BackTrack will run very similarly on Blackbuntu.</li>
<li>The biggest strong point Blackbuntu has in my book is the fact that it&#8217;s a highly customized version of Ubuntu with Gnome, which I&#8217;m already familiar with, and to me is better suited as a primary Linux OS.</li>
<li>Then again I&#8217;ve run into stability issues with Blackbuntu that have me, for the time being, switching back to Backtrack 4r2</li>
<li>I&#8217;ll reassess these in the near future when BackTrack 5 debuts, which will be both 32 and 64 bit compatible, running on Ubuntu 10.04 with official support for KDE, Gnome and Fluxbox</li>
</ul>
<p>&#8211;</p>
<p>Keep up with the latest on Hak5 by following us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>. <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> and get your weekly technolust delivered automatically. Or show your support and grab some swag from the <a href="http://hak5.org/store" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> and <a href="http://www.hak5.org/store/hak5-hoodie" target="_blank">hoodie</a>. Finally if you&#8217;d like to suggest a topic for ask a question feel free to hit up <a href="https://mail.google.com/mail/?view=cm&amp;fs=1&amp;tf=1&amp;to=feedback@hak5.org" target="_blank">feedback@hak5.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-906/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0906/hak5--0906--with_robots--hd720p30.h264.mp4" length="541033957" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0906/hak5--0906--with_robots--large.h264.mp4" length="358420624" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0906/hak5--0906--with_robots--large.wmv9.wmv" length="362009896" type="video/asf" />
		</item>
		<item>
		<title>Hak5 901 – Multiplexing screens, Nexpose at RSA, Packet Sniffers and File Automation</title>
		<link>http://Hak5.org/episodes/episode-901</link>
		<comments>http://Hak5.org/episodes/episode-901#comments</comments>
		<pubDate>Fri, 25 Feb 2011 01:18:51 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 9]]></category>
		<category><![CDATA[11.04]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[belvedere]]></category>
		<category><![CDATA[chris kirsch]]></category>
		<category><![CDATA[citrix]]></category>
		<category><![CDATA[command line]]></category>
		<category><![CDATA[crack the code challenge]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[domain.com]]></category>
		<category><![CDATA[draw]]></category>
		<category><![CDATA[file management]]></category>
		<category><![CDATA[geohot]]></category>
		<category><![CDATA[george hotz]]></category>
		<category><![CDATA[gnome]]></category>
		<category><![CDATA[gotoassist]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacker challenge]]></category>
		<category><![CDATA[hacker headlines]]></category>
		<category><![CDATA[haktip]]></category>
		<category><![CDATA[html5]]></category>
		<category><![CDATA[jailbreak]]></category>
		<category><![CDATA[kintect]]></category>
		<category><![CDATA[legal defense]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mrdoob]]></category>
		<category><![CDATA[natty narwhal]]></category>
		<category><![CDATA[nexpose]]></category>
		<category><![CDATA[ngrep]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[packet sniffer]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[Playstation]]></category>
		<category><![CDATA[rapid7]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[screen]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[sdk]]></category>
		<category><![CDATA[sketch]]></category>
		<category><![CDATA[Snubs]]></category>
		<category><![CDATA[sony]]></category>
		<category><![CDATA[split]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tcpdump]]></category>
		<category><![CDATA[trivia]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[unity]]></category>
		<category><![CDATA[unix]]></category>
		<category><![CDATA[virtualbox]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=2797</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/sN9BGmfAk9c?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/sN9BGmfAk9c?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-901"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-901&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Season 9 Premieres with the return of Shannon &#8220;Snubs&#8221; Morse and Paul &#8220;the camera guy&#8221; Tobias. We kick around the hacker headlines, get the low-down on Nexpose from Rapid7 at RSA, automate file mangement in windows, multiplex some screen sessions, capture packets from the command line and a lot more.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0901/hak5--0901--reunited--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0901/hak5--0901--reunited--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0901/hak5--0901--reunited--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-2797"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/sN9BGmfAk9c?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/sN9BGmfAk9c?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object></p>
<h2>Hacker Headlines</h2>
<p>Kinect hackers rejoice! <a href="http://www.techflash.com/seattle/2011/02/microsoft-plans-kinect-sdk.html" target="_blank">Microsoft confirms that a Kinect SDK is coming</a> for PC and Mac this spring, allowing developers to deal with the motion and voice sensor at a higher level than the informal Kinect hacks. The SDK will be free for personal use with a commercial version expected to follow.</p>
<p>Sony is <a href="http://www.wired.com/threatlevel/2011/02/sony-threatens-jailbreakers/" target="_blank">threatening to permanently disconnect jail broken PlayStation 3 consoles</a> from the PlayStation Network. Jeff Rubenstein, Sony’s Social-Media Manager wrote in his blog “To avoid this, customers must immediately cease use and remove all circumvention devices and delete all unauthorized or pirated software from their PlayStation 3 systems”</p>
<p>Donations have closed for the <a href="http://geohotgotsued.blogspot.com/2011/02/first-round-of-donations-is-closed.html" target="_blank">legal defense fund of George Hotz</a>, notable iPhone jailbreaker and PS3 hacker. Sony has tied the hacker up in San Francisco federal since January court facing unspecified damages on DMCA violations. Hotz writes on his blog “I have enough to cover my legal fees for the time being.” and “For now, the best you can do is spread the word”</p>
<p>The latest <a href="http://www.h-online.com/open/news/item/VirtualBox-4-0-4-supports-Ubuntu-11-04-alpha-guests-1193850.html" target="_blank">VirtualBox 4.0.4 update adds support for Ubuntu 11.04 alpha guests</a>. The Ubuntu Alpha, code named Natty Narwhal, introduces Unity as the default desktop session. Gnome can still be accessed as a “Ubuntu Classic Session”</p>
<p><a href="http://r03.tumblr.com/post/3199199234/urban-sql-injection-win" target="_blank">Urban SQL Injection</a> &#8212; full of win.</p>
<h2>Crack the Code Challenge</h2>
<p> Do you have what it takes to compete in the <a href="http://www.hak5.org/challenge/" target="_blank">Crack The Code Challenge?</a> Test your skills in our private lab network and bid for the title supreme leet hax0r. Winners will be featured on future episodes of Hak5!</p>
<p>Our next event will be this <b>Sunday, February 27th at 3pm Pacific</b>. Visit <a href="http://www.hak5.org/challenge/" target="_blank">Hak5.org/challenge</a> for all of the details. We’ll be live streaming at <a href="http://www.hak5.org/live/" target="_blank">hak5.org/live</a> throughout the day. We&#8217;d like to thank Citrix and <a href="http://www.gotoassist.com/hak5" target="_blank">GoToAssist Express</a> for sponsoring the Crack the Code Challenge.</p>
<h2>Rapid7&#8242;s Nexpose at RSA 2011</h2>
<p>Darren meets with Chris Kirsch of Rapid7 to find out what&#8217;s new in <a href="http://www.rapid7.com/products/nexpose-community-edition.jsp" target="_blank">Nexpose</a></p>
<h2>Trivia!</h2>
<p>Our last question was &#8220;In the Millennium Trilogy, what is the name of the hacker community?&#8221; and the answer is: &#8220;Hacker Republic&#8221;</p>
<p>Our new question is: &#8220;From March 5, 1975 to December 1986, this club of computer hoppyists would meet in the Silicon Valley Area.&#8221;</p>
<p>Participate at <a href="http://www.hak5.org/trivia" target="_blank">hak5.org/trivia</a></p>
<h2>Hak5 finally goes HTTPS</h2>
<p> Thanks to <a href="http://www.domain.com" target="_blank">Domain.com</a> our very own Hak5.org is finally sporting a shiny new SSL certificate. Darren recaps some of the nifty things you can do with one and recommends <a href="http://www.domain.com/ssl/" target="_blank">thawte SSL 123</a>. Thanks Domain.com for hosting Hak5.org and sponsoring for over a year!</p>
<h2>Automating Windows File Managment</h2>
<p>Belvedere
<p>
What it does:<br />
Automating file management and scripting on Windows: <a href="http://lifehacker.com/341950/belvedere-automates-your-self+cleaning-pc" target="_blank">Belvedere</a>.</p>
<p>Belvedere lets you organize any folders on your harddrive. You can create rules to move, copy, delete, rename, or open files based on name, extension, size, creation, date, and even more. So basically it&#8217;s a self-cleaner tool for Windows Only. There&#8217;s also a Mac cleaner called Hazel that you might want to check out if you are an Apple user.</p>
<p>It was created by Adam Pash back in &#8217;08, and you can check out the source of this tool over at <a href="https://github.com/adampash/belvedere" target="_blank">GitHub</a>. </p>
<p>It&#8217;s a .exe so just install it from the download link. You can make Belvedere startup when Windows starts, but you&#8217;ll have to add it manually.</p>
<p>How you use it:<br />
Belvedere is really easy to use, it&#8217;s just simple point and clicks. You create a folder, then name your rule from one of the choices, and build conditions with the drop down menus.</p>
<p>Belvedere gives me the ability to multitask and not worry so much about how clean my PC is.</p>
<p>Do you have another tool that works like Belve? Let me know at feedback@hak5.org.</p>
<h2>HakTip: Multiplexing Screen Sessions</h2>
<p>What’s more wicked than a screen session? Two screen sessions! As we’ve talked about recently the unix command Screen is a great way to maintain bash sessions from multiple SSH clients without losing your work. My favorite shortcut after invoking the “screen” command is CTRL+a followed by “S”, which splits the screen horizontally in two. Use CTRL+a then Tab to switch between the views. Debian users get the added sexyness of vertical split by hitting CTRL+a then Pipe.</p>
<p>What little gems are rocking your world? Hit us up, we’ll share ‘em with the world. <a href="mailto:tips@hak5.org">tips@hak5.org</a></p>
<h2>Email: Command Line Packet Sniffers</h2>
<p>Hey, I&#8217;m in dire need of a command line linux packet sniffer. My servers are 3 hours away, and none have X11 installed. I used to use sniffit a long time ago, but it looks like they&#8217;ve added a GUI to it. Just wondering if you had any ideas off the top of your head.</p>
<p>Darren recommends <a href="http://www.tcpdump.org/" target="_blank">TCPDUMP</a> and <a href="http://ngrep.sourceforge.net/" target="_blank">NGREP</a></p>
<p>Have others to share? feedback@hak5.org</p>
<h2>Sketching with the Harmony Project</h2>
<p>Sparkleface writes in to share the <a href="http://mrdoob.com/projects/harmony/" target="_blank">Harmony Project</a> &#8212; a nifty sketching program in HTML5. Check out the <a href="http://github.com/mrdoob/harmony" target="_blank">source code</a> and <a href="http://mrdoob.com/blog/post/689" target="_blank">more info</a></p>
<p>Keep up with the latest on Hak5 by following us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>. <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> and get your weekly technolust delivered automatically. Or show your support and grab some swag from the <a href="http://hak5.org/store" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> and <a href="http://www.hak5.org/store/hak5-hoodie" target="_blank">hoodie</a>. Finally if you&#8217;d like to suggest a topic<br />
for ask a question feel free to hit up <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-901/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0901/hak5--0901--reunited--hd720p30.h264.mp4" length="494575639" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0901/hak5--0901--reunited--large.h264.mp4" length="326839773" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0901/hak5--0901--reunited--large.wmv9.wmv" length="317007892" type="video/asf" />
		</item>
		<item>
		<title>Strip SSL security with a man-in-the-middle attack</title>
		<link>http://Hak5.org/hack/strip-out-ssl-security-with-a-man-in-the-middle-attack</link>
		<comments>http://Hak5.org/hack/strip-out-ssl-security-with-a-man-in-the-middle-attack#comments</comments>
		<pubDate>Mon, 14 Dec 2009 08:09:08 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[break ssl]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[intercept ssl]]></category>
		<category><![CDATA[interceptor]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[moxie]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network monkey]]></category>
		<category><![CDATA[remove ssl]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[sslstrip]]></category>
		<category><![CDATA[strip ssl]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1633</guid>
		<description><![CDATA[
			
				
			
		
Darren demonstrates a little man-in-the-middle attack using SSLStrip, an epic tool for removing that pesky encryption from your victims browsing session. Go from secure site to clear-text passwords in one simple step.



Moxie Marlinspike&#8216;s SSLStrip, released ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fhack%2Fstrip-out-ssl-security-with-a-man-in-the-middle-attack"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fhack%2Fstrip-out-ssl-security-with-a-man-in-the-middle-attack&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Darren demonstrates a little man-in-the-middle attack using SSLStrip, an epic tool for removing that pesky encryption from your victims browsing session. Go from secure site to clear-text passwords in one simple step.</p>
<div style="clear:both;"></div>
<p><span id="more-1633"></span></p>
<p><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/PmtkJKHFX5Q&#038;hl=en_US&#038;fs=1&#038;start=442"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/PmtkJKHFX5Q&#038;hl=en_US&#038;fs=1&#038;start=442" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></p>
<p><a href="http://www.thoughtcrime.org" target="_blank">Moxie Marlinspike</a>&#8216;s <a href="http://www.thoughtcrime.org/software/sslstrip/" target="_blank">SSLStrip</a>, released at Blackhat/DEFCON this year, is a tool that transparently hijacks HTTP traffic and redirects HTTPS links to look-alike HTTP links. While this description barely scratches the surface, Darren&#8217;s segment takes a closer look including a pracitcal demonstration of a <a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack" target="_blank">man-in-the-middle attack</a> using <a href="http://arpspoof.sourceforge.net/" target="_blank">arpspoof</a> and a little luck with remote-exploit&#8217;s <a href="http://remote-exploit.org/backtrack_download.html" target="_blank">BackTrack 4</a> penetration testing distribution.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/hack/strip-out-ssl-security-with-a-man-in-the-middle-attack/feed</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Hacking PPTP VPNs with ASLEAP</title>
		<link>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap</link>
		<comments>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap#comments</comments>
		<pubDate>Mon, 14 Dec 2009 07:58:05 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[client handshake authentication protocol]]></category>
		<category><![CDATA[cowpatty]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[joshua wright]]></category>
		<category><![CDATA[l2tp]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[point to point tunneling protocol]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1627</guid>
		<description><![CDATA[
			
				
			
		
Darren demonstrates cracking Microsoft VPN tunnels using the MS-CHAPv2 authentication protocol using Joshua Wright&#8217;s tool ASLEAP and talks about the theory behind the attack.



Continuing on with our VPN series I find it important to highlight ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fhack%2Fhacking-pptp-vpns-with-asleap"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fhack%2Fhacking-pptp-vpns-with-asleap&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Darren demonstrates cracking Microsoft VPN tunnels using the MS-CHAPv2 authentication protocol using Joshua Wright&#8217;s tool ASLEAP and talks about the theory behind the attack.</p>
<div style="clear:both;"></div>
<p><span id="more-1627"></span></p>
<p><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/IPPHJBp3bXU&#038;hl=en_US&#038;fs=1&#038;start=262"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/IPPHJBp3bXU&#038;hl=en_US&#038;fs=1&#038;start=262" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></p>
<p>Continuing on with our VPN series I find it important to highlight the weaknesses in the protocols we have talked about thus far. In <a target="_blank" href="http://www.hak5.org/episodes/episode-610">my last segment</a> I highlighted a tool that allows an attacker to easily hijack an SSL session using a man-in-the-middle attack. Couple this with Adito (aka OpenVPN-ALS), <a target="_blank" href="http://www.hak5.org/episodes/episode-607">my favorite open-source SSL VPN server</a>, and you can see the problem.</p>
<p>But what about the basic <a target="_blank" href="http://www.hak5.org/episodes/episode-605">Microsoft VPN</a> we setup <a target="_blank" href="http://www.hak5.org/episodes/episode-605">a few weeks back?</a> The VPN servers that we setup on Windows XP and Server 2003 used either active directory or local windows accounts to authenticate users.</p>
<p>And looking back at <a target="_blank" href="http://www.hak5.org/episodes/episode-419">our discussions</a> on pwdump, rainbow tables and the like you&#8217;ll remember the inherent weaknesses in Windows account credentials.</p>
<p>There are two ways Windows stores a user&#8217;s account credentials, or password. <a target="_blank" href="http://en.wikipedia.org/wiki/LM_hash">LAN Manager</a> hashes which are comprised of watered-down weaksauce and <a target="_blank" href="http://en.wikipedia.org/wiki/NTLM">NTLM</a> which are succeptable to time-memory tradeoff attacks.</p>
<p>The default VPN server implemented in Windows XP and Server 2003&#8242;s Routing and Remote Access service uses Point-To-Point-Tunneling-Protocol. This is convenient because the Windows clients have supported Microsoft PPTP VPN connections natively since 2000, and in Windows 95/98 with <a target="_blank" href="http://support.microsoft.com/kb/191494">Dual Up Networking version 1.3</a>.</p>
<p>The modern authentication protocol of Microsoft&#8217;s PPTP is <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc739678(WS.10).aspx">MS-CHAPv2</a>. This <a target="_blank" href="http://en.wikipedia.org/wiki/Challenge-handshake_authentication_protocol">Challenge Handshake Authentication Protocol</a> suffers from inherent weaknesses.</p>
<p>As far back at 1999 these weaknesses have been widely known. If you&#8217;re interested in reading more on the cryptanalysis of MS-CHAPv2 there&#8217;s a <a target="_blank" href="http://www.schneier.com/paper-pptpv2.html">nifty paper</a> written by Bruce Schneier and L0pht that I&#8217;ll link in the show notes.</p>
<p>And while other options exist such as <a target="_blank" href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx">Radius</a>, this is still the default option for PPTP authentication in Windows environments.</p>
<p><a target="_blank" href="http://www.willhackforsushi.com/?page_id=87">Joshua Wright</a>, author of <a target="_blank" href="http://www.willhackforsushi.com/?p=284">coWPAtty</a> (See <a target="_blank" href="http://www.hak5.org/episodes/episode-518">our segment here</a>), released in 2004 a proof of concept tool to demonstrate weaknesses in <a target="_blank" href="http://en.wikipedia.org/wiki/Lightweight_Extensible_Authentication_Protocol">LEAP</a> and PPTP protocols.</p>
<p>This tool, <a target="_blank" href="http://www.willhackforsushi.com/Asleap.html">ASLEAP</a>, was updated in 2007 to include an option to just crack MS-CHAP v2. Either by examining a packet capture that includes a MS-CHAP handshake ASLEAP or specifying an MS-CHAP challenge and response ASLEAP is able to deduce the username and last two bytes of the NT hash. Using this information, and a dictionary file, ASLEAP is able to brute-force the hash.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Episode 612 &#8211; Hacking PPTP VPNs with ASLEAP</title>
		<link>http://Hak5.org/episodes/episode-612</link>
		<comments>http://Hak5.org/episodes/episode-612#comments</comments>
		<pubDate>Wed, 04 Nov 2009 16:52:17 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[client handshake authentication protocol]]></category>
		<category><![CDATA[cowpatty]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[joshua wright]]></category>
		<category><![CDATA[l2tp]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[point to point tunneling protocol]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1440</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3867" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  wmode="transparent"  />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-612"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-612&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Continuing with the VPN Series, Darren discusses the inherent weaknesses in Microsoft&#8217;s PPTP authentication protocol, MS-CHAPv2, and demos a Linux tool that exploits these weaknesses.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1440"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3867" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  wmode="transparent"  /></p>
<p>Continuing on with our VPN series I find it important to highlight the weaknesses in the protocols we have talked about thus far. In <a target="_blank" href="http://www.hak5.org/episodes/episode-610">my last segment</a> I highlighted a tool that allows an attacker to easily hijack an SSL session using a man-in-the-middle attack. Couple this with Adito (aka OpenVPN-ALS), <a target="_blank" href="http://www.hak5.org/episodes/episode-607">my favorite open-source SSL VPN server</a>, and you can see the problem.</p>
<p>But what about the basic <a target="_blank" href="http://www.hak5.org/episodes/episode-605">Microsoft VPN</a> we setup <a target="_blank" href="http://www.hak5.org/episodes/episode-605">a few weeks back?</a> The VPN servers that we setup on Windows XP and Server 2003 used either active directory or local windows accounts to authenticate users.</p>
<p>And looking back at <a target="_blank" href="http://www.hak5.org/episodes/episode-419">our discussions</a> on pwdump, rainbow tables and the like you&#8217;ll remember the inherent weaknesses in Windows account credentials.</p>
<p>There are two ways Windows stores a user&#8217;s account credentials, or password. <a target="_blank" href="http://en.wikipedia.org/wiki/LM_hash">LAN Manager</a> hashes which are comprised of watered-down weaksauce and <a target="_blank" href="http://en.wikipedia.org/wiki/NTLM">NTLM</a> which are succeptable to time-memory tradeoff attacks.</p>
<p>The default VPN server implemented in Windows XP and Server 2003&#8242;s Routing and Remote Access service uses Point-To-Point-Tunneling-Protocol. This is convenient because the Windows clients have supported Microsoft PPTP VPN connections natively since 2000, and in Windows 95/98 with <a target="_blank" href="http://support.microsoft.com/kb/191494">Dual Up Networking version 1.3</a>.</p>
<p>The modern authentication protocol of Microsoft&#8217;s PPTP is <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc739678(WS.10).aspx">MS-CHAPv2</a>. This <a target="_blank" href="http://en.wikipedia.org/wiki/Challenge-handshake_authentication_protocol">Challenge Handshake Authentication Protocol</a> suffers from inherent weaknesses.</p>
<p>As far back at 1999 these weaknesses have been widely known. If you&#8217;re interested in reading more on the cryptanalysis of MS-CHAPv2 there&#8217;s a <a target="_blank" href="http://www.schneier.com/paper-pptpv2.html">nifty paper</a> written by Bruce Schneier and L0pht that I&#8217;ll link in the show notes.</p>
<p>And while other options exist such as <a target="_blank" href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx">Radius</a>, this is still the default option for PPTP authentication in Windows environments.</p>
<p><a target="_blank" href="http://www.willhackforsushi.com/?page_id=87">Joshua Wright</a>, author of <a target="_blank" href="http://www.willhackforsushi.com/?p=284">coWPAtty</a> (See <a target="_blank" href="http://www.hak5.org/episodes/episode-518">our segment here</a>), released in 2004 a proof of concept tool to demonstrate weaknesses in <a target="_blank" href="http://en.wikipedia.org/wiki/Lightweight_Extensible_Authentication_Protocol">LEAP</a> and PPTP protocols.</p>
<p>This tool, <a target="_blank" href="http://www.willhackforsushi.com/Asleap.html">ASLEAP</a>, was updated in 2007 to include an option to just crack MS-CHAP v2. Either by examining a packet capture that includes a MS-CHAP handshake ASLEAP or specifying an MS-CHAP challenge and response ASLEAP is able to deduce the username and last two bytes of the NT hash. Using this information, and a dictionary file, ASLEAP is able to brute-force the hash.</p>
<p>PS: Check out <a href="http://www.player2rentals.com" target="_blank">Player2Rentals.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-612/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--hd720p30.h264.mp4" length="549041844" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.h264.mp4" length="358047282" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.xvid.avi" length="315159934" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.wmv9.wmv" length="307796076" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 610 &#8211; Man in the Middle fun with SSL Strip</title>
		<link>http://Hak5.org/episodes/episode-610</link>
		<comments>http://Hak5.org/episodes/episode-610#comments</comments>
		<pubDate>Wed, 21 Oct 2009 11:49:03 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[break ssl]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[intercept ssl]]></category>
		<category><![CDATA[interceptor]]></category>
		<category><![CDATA[Jasager]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[moxie]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[network monkey]]></category>
		<category><![CDATA[remove ssl]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[sslstrip]]></category>
		<category><![CDATA[strip ssl]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[Wifi Pineapple]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1428</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3566" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"   wmode="transparent" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-610"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-610&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show Darren&#8217;s having a little man-in-the-middle fun with a demonstration os SSLStrip, an epic tool for removing that pesky encryption from your victims browsing session.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1428"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3566" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"   wmode="transparent" /></p>
<p><a href="http://www.thoughtcrime.org" target="_blank">Moxie Marlinspike</a>&#8216;s <a href="http://www.thoughtcrime.org/software/sslstrip/" target="_blank">SSLStrip</a>, released at Blackhat/DEFCON this year, is a tool that transparently hijacks HTTP traffic and redirects HTTPS links to look-alike HTTP links. While this description barely scratches the surface, Darren&#8217;s segment takes a closer look including a pracitcal demonstration of a <a href="http://en.wikipedia.org/wiki/Man-in-the-middle_attack" target="_blank">man-in-the-middle attack</a> using <a href="http://arpspoof.sourceforge.net/" target="_blank">arpspoof</a> and a little luck with remote-exploit&#8217;s <a href="http://remote-exploit.org/backtrack_download.html" target="_blank">BackTrack 4</a> penetration testing distribution.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-610/feed</wfw:commentRss>
		<slash:comments>38</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--hd720p30.h264.mp4" length="408006323" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--large.h264.mp4" length="266609981" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--large.xvid.avi" length="231512844" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0610/hak5--0610--mitm-fun-with-SSL-Strip--large.wmv9.wmv" length="247681294" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 605 &#8211; Three VPN Servers and a Kindle Console</title>
		<link>http://Hak5.org/episodes/episode-605</link>
		<comments>http://Hak5.org/episodes/episode-605#comments</comments>
		<pubDate>Wed, 16 Sep 2009 12:38:50 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[arm]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[console]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[kindle]]></category>
		<category><![CDATA[kindle hack]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux vpn]]></category>
		<category><![CDATA[mac vpn]]></category>
		<category><![CDATA[mschap]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[openvpn]]></category>
		<category><![CDATA[openvpn-as]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[serial]]></category>
		<category><![CDATA[server 2003]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[systems admin]]></category>
		<category><![CDATA[ttl]]></category>
		<category><![CDATA[usb to serial]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[Windows Server]]></category>
		<category><![CDATA[windows vpn]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1399</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3561" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-605"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-605&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This week Shannon taps into a hidden Kindle serial port using a inty bitsy ribbon cable, a USB to Serial TTL cable and some jumpers in an attempt to hack root and finds herself upon the bootloader and nearly at a bash prompt. Darren guides you through the installation of VPN servers on Windows XP, Windows Server and Linux so you can keep your traffic secure in an encrypted tunnel while on untrusted networks.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1399"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3561" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  /></p>
<p>Hacking into the Kindle Bootloader Part 1</p>
<p>This week, I&#8217;m introducing the bootloader Kindle 1st gen hack.</p>
<p><b>Equipment:</b><br />
<a target="_blank" href="http://www.amazon.com/Kindle-Amazons-Original-Wireless-generation/dp/B000FI73MA/ref=sr_1_2?ie=UTF8&#038;s=electronics&#038;qid=1252876057&#038;sr=8-2">Kindle 1st Generation</a><br />
<a  target="_blank" href="http://stopallthedownloadin.ytmnd.com/">A computah!</a><br />
<a  target="_blank" href="http://www.google.com/products?q=usb%20to%20serial%20ttl%20cable&#038;oe=utf-8&#038;rls=org.mozilla:en-US:official&#038;client=firefox-a&#038;um=1&#038;ie=UTF-8&#038;sa=N&#038;hl=en&#038;tab=wf">USB to Serial TTL Cable</a><br />
<a  target="_blank" href="http://parts.digikey.com/1/parts/35672-cable-flat-flex-4-50mm-20-pos-21020-0211.html">20 pin 0.5 mm flat cable</a><br />
1 pin Jumper cables</p>
<p><b>Programs:</b><br />
<a  target="_blank" href="http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html">Putty</a></p>
<p>Igor Skochinsky explains how to hack into the bootloader of the Kindle very nicely on his blog, Reverse Everything.  He includes screenshots, photos, and descriptions of everything you need to know to do this hack.<br />
<a  target="_blank" href="http://igorsk.blogspot.com/2007/12/hacking-kindle-part-1-getting-console.html">Part 1</a><br />
<a  target="_blank" href="http://igorsk.blogspot.com/2007/12/hacking-kindle-part-2-bootloader-and.html">Part 2</a></p>
<p>If you have any questions, you can email me at snubs@hak5.org!</p>
<p>Windows VPN Servers</p>
<p>In this segment I demonstrate setting up a <a target="_blank" href="http://www.onecomputerguy.com/networking/xp_vpn_server.htm">VPN server in Windows XP</a> which is rather limited at 1 concurrent connection. I also demonstrate building a <a target="_blank" href="http://technet.microsoft.com/en-us/network/bb545655.aspx">Routing and Remote Access VPN</a> server in Windows Server 2003.</p>
<p>Open Source VPN Server</p>
<p>I&#8217;m a big fan of open source. I&#8217;m also an overwhelmed systems administrator that likes easy. And when it comes to VPNs in Linux, OpenVPN is the go to solution. That&#8217;s why I&#8217;m excited about <a target="_blank" href="http://www.openvpn.net/index.php/access-server/section-faq-openvpn-as/32-general/133-what-is-openvpn-access-server.html">OpenVPN Access Server</a> &#8212; an set of installation and configuration tools that simplifies rapid deployment of a VPN solution.</p>
<p>
In this segment I demonstrate setting up this nifty, lightweight and powerful server in a typical home user scenario. I also speak to the fact that it can integrate with Active Directory via LDAP or even a RADIUS server for authentication. The web based backend makes administration a breeze and the web frontend makes client setup even easier. All the clients have to do is login to a website and download a prepackaged and configured connection app for Windows, Mac or Linux.</p>
<p>This package makes it incredibly easy to deploy a VPN server. But it comes at a cost. OpenVPN-AS requires a <a href="http://www.openvpn.net/index.php/access-server/license-key.html" target="_blank">license key</a> for each concurrent connection. Two are provided for free and additional licenses are $10 ea. Still a far cry from a windows Client Access License!
</p>
<p>In future segments we&#8217;ll be getting our hands dirty with OpenVPN standard as well as some other interesting VPN technologies so be sure to send your feedback, requests and flames to darren@hak5.org</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-605/feed</wfw:commentRss>
		<slash:comments>21</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--hd720p30.h264.mp4" length="668713893" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--large.h264.mp4" length="445590851" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--large.xvid.avi" length="389634744" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0605/hak5--0605--3VPNs-and-a-Kindle-Console--large.wmv9.wmv" length="408295800" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Season 1 Episode 4</title>
		<link>http://Hak5.org/episodes/hak5-episode-4-released</link>
		<comments>http://Hak5.org/episodes/hak5-episode-4-released#comments</comments>
		<pubDate>Sat, 05 Nov 2005 18:08:25 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 1]]></category>
		<category><![CDATA[arcade]]></category>
		<category><![CDATA[Game]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[homebrew]]></category>
		<category><![CDATA[jenn cutter]]></category>
		<category><![CDATA[Mod]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[XP]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=50</guid>
		<description><![CDATA[
			
				
			
		

In this episode of Hak.5 Wess builds a mini arcade cabinet for under $100, Harrison attacks SSL with Whoppix, Darren defends himself by setting up a VPN server on XP, and Jon &#038; Harrison take ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-episode-4-released"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-episode-4-released&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p><img src="/images/thumbnails/release1x04.jpg"/><br />
In this episode of Hak.5 Wess builds a mini arcade cabinet for under $100, Harrison attacks SSL with Whoppix, Darren defends himself by setting up a VPN server on XP, and Jon &#038; Harrison take on buffer overflows with beer. Plus an interview with a <a href="http://www.goldeneyesource.com">Goldeneye Source</a> developer, exclusive in-game video, and more Microshaft than you can wave a rounded IDE cable at. Special guest intro by Jenn Cutter from <a href="http://www.openalpha.tv">OpenAlpha</a> and new theme music by <a href="http://www.tenhauser.com">Ashley Witt</a>.<br />
<span id="more-50"></span></p>
<div style="clear:both;"></div>
<h3>Download</h3>
<p><img src="/images/icons/divx.png" border="0"/>    <a href="http://www.podtrac.com/pts/redirect.avi?http://content.wuala.com/contents/Creative%20Commons/videos/Hak5/Season%201/Hak5-ep4.avi?dl=1">Download Xvid</a></p>
<p><img src="/images/icons/youtube.png" border="0"/>    <a href="http://www.youtube.com/watch?v=R4dr8cZZc-8">Watch on Youtube</a></p>
<p>Length: 34:30</p>
<p><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/R4dr8cZZc-8&#038;rel=1"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/R4dr8cZZc-8&#038;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-episode-4-released/feed</wfw:commentRss>
		<slash:comments>20</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.avi?http://content.wuala.com/contents/Creative%20Commons/videos/Hak5/Season%201/Hak5-ep4.avi?dl=1" length="210" type="video/avi" />
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  hak5.org/tag/ssl/feed ) in 0.79215 seconds, on Feb 8th, 2012 at 4:16 pm UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on Feb 8th, 2012 at 5:16 pm UTC -->
