<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hak5 - Technolust since 2005 &#187; vpn</title>
	<atom:link href="http://Hak5.org/tag/vpn/feed" rel="self" type="application/rss+xml" />
	<link>http://Hak5.org</link>
	<description>Trust Your Technolust</description>
	<lastBuildDate>Thu, 17 May 2012 20:49:56 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Hak5 1105 &#8211; Bluetooth Magic, SXSW report and IEEE interview</title>
		<link>http://Hak5.org/episodes/hak5-1105</link>
		<comments>http://Hak5.org/episodes/hak5-1105#comments</comments>
		<pubDate>Wed, 21 Mar 2012 16:00:47 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 11]]></category>
		<category><![CDATA[bluetooth]]></category>
		<category><![CDATA[Hak.5]]></category>
		<category><![CDATA[ieee]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[proximity]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SXSW]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[Wallpapers]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=4619</guid>
		<description><![CDATA[<iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PL4251AFC28BE95902&#038;hl=en_US&#038;hd=1&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0&#038;wmode=Opaque" frameborder="0" allowfullscreen></iframe>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1105"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1105&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
This time on the show, locking down your PC with proximity and a little bluetooth magic -- I'll be showing you how. Then, what's the IEEE on about these days? Darren reports from South-by-South-West. More fun bash tips and VPN security - who do you trust? All that and more, this time on Hak5!
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1105/hak5--1105--ieee--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1105/hak5--1105--ieee--large.h264.mp4">Download MP4</a><br />
<span id="more-4619"></span> </p>
<div align="center"><iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PL4251AFC28BE95902&#038;hl=en_US&#038;hd=1&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0&amp;wmode=Opaque" frameborder="0" allowfullscreen></iframe></div>
If you're into Hak5 you'll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you're a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let's not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
<p>Youtube Description (No HTML):</p>
<p>This time on the show, locking down your PC with proximity and a little bluetooth magic -- I'll be showing you how. Then, what's the IEEE on about these days? Darren reports from South-by-South-West. More fun bash tips and VPN security - who do you trust? All that and more, this time on Hak5!</p>
<p>If you're into Hak5 you'll love our new show by hosts Darren Kitchen and Shannon Morse. Check out http://www.revision3.com/haktip</p>
<p>Whether you're a beginner or a pro, http://www.revision3.com/haktip is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let's not forget to mention that you can follow us on http://www.twitter.com/hak5 and http://www.facebook.com/technolust, http://revision3.com/hak5/subscribe to the show and get all your Hak5 goodies, including the infamous http://hakshop.com/collections/frontpage/products/wifi-pineapple over at http://hakshop.com . If you have any questions or suggestions please feel free to contact us at feedback@hak5.org.
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-1105/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Hak5 1101 &#8211; Source Code, Ponies and Cyborgs!</title>
		<link>http://Hak5.org/episodes/hak5-1101</link>
		<comments>http://Hak5.org/episodes/hak5-1101#comments</comments>
		<pubDate>Mon, 27 Feb 2012 19:04:01 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 11]]></category>
		<category><![CDATA[aliases]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[chorder]]></category>
		<category><![CDATA[cyborg]]></category>
		<category><![CDATA[Greg Priest-Dorman]]></category>
		<category><![CDATA[hammer]]></category>
		<category><![CDATA[Pelican Case]]></category>
		<category><![CDATA[Pineapple]]></category>
		<category><![CDATA[ponies]]></category>
		<category><![CDATA[ponykart]]></category>
		<category><![CDATA[strings]]></category>
		<category><![CDATA[subversion]]></category>
		<category><![CDATA[SVN]]></category>
		<category><![CDATA[the baltic restaurant]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[wearable computing]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=4569</guid>
		<description><![CDATA[<iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PLD9250765654EC4CD&#038;hl=en_US&#038;hd=1&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0&#038;wmode=Opaque" frameborder="0" allowfullscreen></iframe>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1101"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1101&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
Is wearable computing a practical reality? Darren speaks with Greg Priest-Dorman, a fellow geek who's been building and wearing the tech for 12 years. Plus open source gaming that involves Ponies!
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1101/hak5--1101--cyborgponies--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1101/hak5--1101--cyborgponies--large.h264.mp4">Download MP4</a><br />
<span id="more-4569"></span> </p>
<div align="center"><iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PLD9250765654EC4CD&#038;hl=en_US&#038;hd=1&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0&amp;wmode=Opaque" frameborder="0" allowfullscreen></iframe></div>
This time on the show, CYBORGS! Is wearable computing a practical reality? Darren speaks with Greg Priest-Dorman, a fellow geek who's been building and wearing the tech for 12 years. Plus open source gaming that involves Ponies! OMG Ponies. Oh, and Subversion too. Source code, ponies and cyborgs! All that and more this time on Hak5!</p>
<p>If you're into Hak5 you'll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you're a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let's not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-1101/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Hak5 1012 &#8211; Virtual Acces Point Gui&#8217;s, Google Doc tools, and EXT partition file Recovery</title>
		<link>http://Hak5.org/episodes/hak5-1012</link>
		<comments>http://Hak5.org/episodes/hak5-1012#comments</comments>
		<pubDate>Thu, 10 Nov 2011 18:00:13 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 10]]></category>
		<category><![CDATA[access point]]></category>
		<category><![CDATA[ad-hoc]]></category>
		<category><![CDATA[base station]]></category>
		<category><![CDATA[docs]]></category>
		<category><![CDATA[dslrs]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[gui]]></category>
		<category><![CDATA[hostap]]></category>
		<category><![CDATA[hostednetwork]]></category>
		<category><![CDATA[infrastructure]]></category>
		<category><![CDATA[notifier]]></category>
		<category><![CDATA[partition]]></category>
		<category><![CDATA[recovery]]></category>
		<category><![CDATA[rfc]]></category>
		<category><![CDATA[Router]]></category>
		<category><![CDATA[softap]]></category>
		<category><![CDATA[software access point]]></category>
		<category><![CDATA[virtual]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=4270</guid>
		<description><![CDATA[<iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PL40862F470AE7ED21&#38;hl=en_US&#38;hd=1&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" frameborder="0" allowfullscreen></iframe>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1012"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1012&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show, GUIs for Virtual Access Points, we round up the<br />
best Google Docs tools, recovering files from EXT partitions and VPN<br />
routes. All that and more this time on Hak5.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1012/hak5--1012--guidockycameray--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1012/hak5--1012--guidockycameray--large.h264.mp4">Download MP4</a></p>
<p><span id="more-4270"></span></p>
<div align="center">
<iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PL40862F470AE7ED21&amp;hl=en_US&amp;hd=1&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" frameborder="0" allowfullscreen></iframe>
</div>
<p><b>Google Doc Addons</b></p>
<p>Google Docs has been around for a while now and it&#8217;s been my doc<br />
sharing tool of choice. It&#8217;s pretty easy to get around Google Docs-<br />
everything from sharing to editing- but there are some handy addons to<br />
give you extra abilities.</p>
<p>First is Google Docs Notifier. This is a simple windows add-on that<br />
notifies you of any unread edits to existing docs in Google Docs. You<br />
download the program, log-in (and I should mention, if you use two<br />
factor auth like I do, you&#8217;ll need to add this program to your app<br />
specific passwords in the security settings in your Google account),<br />
and it&#8217;ll show you all the Documents that have been updated since you<br />
last logged into the program. It&#8217;ll be minimized to your taskbar, and<br />
will show you a little popup bubble if anything is updated while the<br />
program is open. Also, if you hover over the icon, it&#8217;ll give you a<br />
bubble saying &#8220;&#8221;&#8212; Unread Documents&#8221;". Just double click on a<br />
document to open it in the browser.</p>
<p>The next one is a tool called Nocs &#8211; basically a notepad for Google<br />
Docs. From Nocs, you can open up any docs that are on your Google Docs<br />
account, edit them, and save them. You can also create new files and<br />
save them to your Google Docs as well or load documents from your PC.<br />
Then, next time you open your docs on your browser, you&#8217;ll see the new<br />
edits and files waiting in your list.</p>
<p>Next is Send To Google Docs. Send to Google Docs is a chrome extension<br />
that will save any website as a PDF and port it over to your Google<br />
Docs. This tool requires no extra authentication since it&#8217;s in Chrome,<br />
and to use it just browse to a page you want to save, click the Send<br />
To Google Docs icon, wait for it to convert, then it&#8217;ll give you the<br />
option to look at the PDF and save it. I could think of a few really<br />
good uses for this program already!</p>
<p>I&#8217;ll have links to each of these programs in the shownotes, but I also<br />
want to hear your feedback on Google Doc tools. Email me your favs at<br />
feedback@hak5.org or comment below.&#8221;</p>
<p><b>Nibble</b></p>
<p>Psyhomb writes:</p>
<blockquote><p>how to exclude the grep command from grep instead of this cmd</p>
<pre>ps aux | grep init | grep -v grep ;done</pre>
<p>You can use this cmd (you can put any letter, in square braces)</p>
<blockquote><p>ps aux | grep [i]nit ;done</p></blockquote>
<p>If you&#8217;re into Hak5 you&#8217;ll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you&#8217;re a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let&#8217;s not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
<p>No matter what your project is <a href="http://www.domain.com" target="_blank">Domain.com</a> has what you need to register, host and promote your next big idea&#8230;even if it&#8217;s ffffggggggggggggggghjk.com. Domain.com is owning the competition with cheap domain names and hassle-free service. Their easy checkout process and domain discovery system makes it easy to select the domain that&#8217;s right for you and setup your website without hassle. <a href="http://www.domain.com" target="_blank">Domain.com</a> will even transfer your domain from another registrar and hook you up with another year of service for under $6.50 when you use coupon code <b>HAK5</b> at checkout. That&#8217;s right, our code <b>HAK5</b> will score you 15% off. Don&#8217;t forget, when you think domain names, think <a href="http://www.domain.com" target="_blank">Domain.com</a></p>
<p>There are two things IT professionals and their clients have in common. They want the job done right and they want it done fast! That‚Äôs why I highly recommend GoToAssist Express, by Citrix to anyone in IT. It‚Äôs the fastest, most reliable support tool and the only service I trust! Don‚Äôt wait &#8211; start using <a href="http://www.gotoassist.com/hak5" target="_blank">GoToAssist Express</a> today! Hak5 viewers can try it FREE for 30 Days Visit <a href="http://www.gotoassist.com/hak5" target="_blank">GoToAssist.com/hak5</a>.</p>
<p>Computer disasters eventually happen to everyone ‚Äì (your computer crashes, gets infected with a virus, you drop it, theft, fire, etc.) but if you get Carbonite Online Backup before your disaster then NO NEED TO WORRY because your files will be backed up ‚Äì automatically and safely offsite ‚Äì and it‚Äôs really easy to get them back. Plus, you get anytime, anywhere access to your backed up files from any computer ‚Äì or on your smartphone or iPad with a free Carbonite app! With Carbonite, unlimited backup for your PC or Mac is just $59 a year. That‚Äôs less than $5 a month. But when you use the offer code <b>hak5</b> to start your Free 15-day Trial you‚Äôll get Two Months Free if you decide to<br />
buy. All the details are at <a href="http://www.Carbonite.com" target="_blank">Carbonite.com</a> and remember to use the offer code </b>hak5<b><br />
to get Two Months Free with purchase.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-1012/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1012/hak5--1012--guidockycameray--hd720p30.h264.mp4" length="0" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1012/hak5--1012--guidockycameray--large.h264.mp4" length="0" type="video/mp4" />
		</item>
		<item>
		<title>Hak5 1010 &#8211; Derbycon 2011: Raphael Mudge from Armitage, Nerdcore&#8217;s Dual Core and forensics, and Octothropes?</title>
		<link>http://Hak5.org/episodes/hak5-1010</link>
		<comments>http://Hak5.org/episodes/hak5-1010#comments</comments>
		<pubDate>Wed, 26 Oct 2011 21:35:57 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 10]]></category>
		<category><![CDATA[armitage]]></category>
		<category><![CDATA[derbycon]]></category>
		<category><![CDATA[Dual Core]]></category>
		<category><![CDATA[dualcoremusic]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[nerdcore]]></category>
		<category><![CDATA[octothrope]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[rap]]></category>
		<category><![CDATA[raphael mudge]]></category>
		<category><![CDATA[shebang]]></category>
		<category><![CDATA[ssid]]></category>
		<category><![CDATA[ssid broadcast]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=4204</guid>
		<description><![CDATA[<iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PL1D72B6EC9E5FFB07&#38;hl=en_US&#38;hd=1&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" frameborder="0" allowfullscreen></iframe>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1010"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-1010&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This time on the show, Raphael Mudge chats about Armitage &#8212; the GUI front-end to Metasploit. Plus, Nerdcore sensation Dual Core is making the lives of forensics investigators much more difficult. Plus PPTP VPNs, SSID broadcasting and what the F* is an Octothrope? All that and more, this time on Hak5.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1010/hak5--1010--inbinaryonly--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/1010/hak5--1010--inbinaryonly--large.h264.mp4">Download MP4</a></p>
<p><span id="more-4204"></span></p>
<div align="center">
<iframe width="640" height="360" src="http://www.youtube-nocookie.com/embed/videoseries?list=PL1D72B6EC9E5FFB07&amp;hl=en_US&amp;hd=1&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" frameborder="0" allowfullscreen></iframe>
</div>
<p>If you&#8217;re into Hak5 you&#8217;ll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you&#8217;re a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let&#8217;s not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
<p><a href="http://www.domain.com" target="_blank">Domain.com</a> is owning the competition with cheap domain names and no hassle service. Our Hak5 fans our making <a href="http://www.domain.com" target="_blank">Domain.com</a> one of the fastest growing domain registrars in the world.<br />
If you’re setting up a website to show off pictures of your cat, brag about your n00b owning skills, or do something more business related, <a href="http://www.domain.com" target="_blank">Domain.com</a> is the best place to buy a domain name for your new idea. <a href="http://www.domain.com" target="_blank">Domain.com</a>’s easy checkout process makes it simple to find your domain name and set up your website without the hassle. <a href="http://www.domain.com" target="_blank">Domain.com</a>’s Domain Discovery System quickly shows you available names, making it easy to select the domain extension that’s right for you. Find a sweet dot COM or get a dot CO and save a character. Already have a domain somewhere else? It’s cool, transfer it to Domain.com for only $7.61 and get an extra year free. The guys at <a href="http://www.domain.com" target="_blank">Domain.com</a> are huge fans of Hak5 and want to hook up other Hak5 fans. Use coupon code <b>HAK5</b> and get 15% off your next domain purchase or transfer. That’s only $6.47 for domain transfers. Don’t forget, when you think domain names, think <a href="http://www.domain.com" target="_blank">Domain.com</a>.</p>
<p>&#8220;Being in IT and not using the right tools to get the best results for your clients is like a surgeon not using the best, most reliable medical equipment…<br />
How can you expect your clients to work with you? That’s why I use GoToAssist Express by Citrix – the BEST remote support tool…<br />
It’s the only one I trust and rely on to get the job done right! GoToAssist Express is designed with speed and usability in mind and makes it easy to get in, diagnose and resolve the problem – fast!<br />
In fact, GoToAssist users report an average 40% increase in productivity. That’s like getting 7 days’ worth of work out of your 5 day week! And with Unlimited Use you can support all you want for one flat fee!<br />
I’ve used remote support tools for years…GoToAssist Express is the best &#8211; so fast and reliable! Start using GoToAssist Express today, you’ll see why it’s the leader in remote support! Right now – Hak5 viewers can try it FREE for 30 Days Visit  <a href="http://www.GoToAssist.com/hak5" target="_blank">GoToAssist.com/hak5</a></p>
<p>Join modding wizard <a href="http://www.revision3.com/tbhs/" target="_blank">Ben Heck</a> and friends as they build and modify a host of amazing community-inspired creations. Be sure to watch new episodes of <a href="http://www.revision3.com/tbhs/" target="_blank">The Ben Heck Show</a> every two weeks right here at <a href="http://www.revision3.com/tbhs/" target="_blank">Revision3.com/TBHS</a> In the latest episode of <a href="http://www.revision3.com/tbhs/" target="_blank">The Ben Heck Show</a>, Ben assembles his crack squad of paranormal investigators for a very special Halloween episode. Stay Tuned at <a href="http://www.element14.com" target="_blank">element14.com/tbhs</a> to find out how you can enter to win Ben&#8217;s latest builds from his show.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-1010/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1010/hak5--1010--inbinaryonly--hd720p30.h264.mp4" length="524773147" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/1010/hak5--1010--inbinaryonly--large.h264.mp4" length="289773310" type="video/mp4" />
		</item>
		<item>
		<title>Hak5 922 &#8211; Bypass GeoIP filters, VPN in BackTrack 5, AndLinux, Prettier Traceroutes</title>
		<link>http://Hak5.org/episodes/hak5-922</link>
		<comments>http://Hak5.org/episodes/hak5-922#comments</comments>
		<pubDate>Thu, 21 Jul 2011 01:11:58 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 9]]></category>
		<category><![CDATA[andlinux]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack 5]]></category>
		<category><![CDATA[backtrack5]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[bbc]]></category>
		<category><![CDATA[bt5]]></category>
		<category><![CDATA[bypass]]></category>
		<category><![CDATA[CoLinux]]></category>
		<category><![CDATA[curses]]></category>
		<category><![CDATA[filters]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[geoip]]></category>
		<category><![CDATA[gnome]]></category>
		<category><![CDATA[Hulu]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[mtr]]></category>
		<category><![CDATA[network manager]]></category>
		<category><![CDATA[nibble]]></category>
		<category><![CDATA[ping]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[terminal]]></category>
		<category><![CDATA[traceroute]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[VM]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vpn client]]></category>
		<category><![CDATA[wicd]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://Hak5.org/?p=3866</guid>
		<description><![CDATA[<object width="640" height="360"><param name="movie" value="http://www.youtube.com/p/01138D89B292128C?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="640" height="360" src="http://www.youtube.com/p/01138D89B292128C?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-922"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fhak5-922&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Hulu and the BBC iPlayer everywhere with a little VPN action to bypass Geo IP filters. We&#8217;ll be setting up Network Manager in BackTrack5. Plus, Linux inside of Windows, graphing trace-routes in terminal and a whole lot more this time on Hak5!</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0922/hak5--0922--britishthemesong--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://videos.revision3.com/revision3/web/hak5/0922/hak5--0922--britishthemesong--large.h264.mp4">Download MP4</a> <a class="wmv" href="http://videos.revision3.com/revision3/web/hak5/0922/hak5--0922--britishthemesong--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-3866"></span></p>
<div align="center">
<object width="640" height="360"><param name="movie" value="http://www.youtube.com/p/01138D89B292128C?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="640" height="360" src="http://www.youtube.com/p/01138D89B292128C?version=3&#038;hl=en_US&#038;fs=1&#038;hd=1&#038;autohide=1&#038;showinfo=0&#038;rel=0&#038;showsearch=0" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object>
</div>
<p><strong>VPN in BackTrack 5 with Network Manager</strong></p>
<p><a href="http://www.backtrack-linux.org/" target="_blank">BackTrack 5</a> is rocking my world as of late. I&#8217;ve been running the gnome 32bit version as my primary os on one of my laptops since release and I so far it has been fantastic out of the box.</p>
<p>That is until I wanted to easily connect to a PPTP VPN. While BackTrack5 includes <a href="http://wicd.sourceforge.net/" target="_blank">Wicd</a> &#8212; the Wireless (and wired) Interface Connection Daemon I&#8217;m more familiar with <a href="http://projects.gnome.org/NetworkManager/" target="_blank">Network Manager</a>, which includes a VPN client. Two birds, one stone!</p>
<p>In this segment I setup Network Manager in BackTrack 5.</p>
<blockquote>
<li>apt-get install network-manager-gnome
<li>cp /etc/network/interfaces{,.backup}
<li>echo &#8220;&#8221;auto lo&#8221;" > /etc/network/interfaces
<li>echo &#8220;&#8221;iface lo inet loopback&#8221;" >> /etc/network/interfaces
<li>service network-manager start
<li>nm-applet&#038;
<li>reboot
</p></blockquote>
<p><strong>Run Linux apps in Windows with AndLinux</strong></p>
<p>If you want to run Ubuntu seamlessly inside a Windows box, perhaps you&#8217;ll be interested in this tool called andLinux. AndLinux is a complete Ubuntu system that runs in Windows (all except 64-bit 7) and uses a program called coLinux as it&#8217;s core. CoLinux is a port of the Linux kernel to Windows. It&#8217;s kind of like running linux in a VM, except with coLinux, andLinux merges itself with Windows and the Linux kernel instead of running through an emulated PC. andLinux is for fun and development and it can run almost any Linux applications without having to do any modifications.<br />
So, with andLinux you get a fully functional Linux system, with no desktop interface. It gives you a second panel or start menu where you can load Linux apps. The apps can be run simultaneously with Windows apps and you can cut and paste text between them.</p>
<p>AndLinux comes in a couple of different versions- KDE version (which is a full version) or XFCE (minimal). When you go through the andLinux installation on Windows, there are a few important steps to keep in mind.<br />
Choosing your start up type: I chose run andLinux automatically as a NT service because it is the most convenient choice. You don&#8217;t have to do any kind of configurations if you choose this option.<br />
You&#8217;ll be asked to create a username and password for andLinux login.<br />
For Windows file access, I chose COFS as it gives you easier configuration compared to Samba. Samba will, though, let you share files with special characters.<br />
Also, if Windows starts freakin because it&#8217;s not Microsoft certified, just click continue anyway.</p>
<p>Once the installation has finished, just restart your computer and unblock any windows firewall settings that may occur from the installation. To start using andLinux, first run the NT console. This will open a command prompt that&#8217;ll ask you for your username and password. You can then close that window and start using any of the programs and applications that are available in the boot menu. It&#8217;s kind of like downloading all the Linux programs straight into Windows without using a Linux OS.</p>
<p>So I&#8217;m just going to try some of these programs out, and they all seem to work just fine. So andLinux looks to be a very handy way to use Linux applications indeed! If you like it, tell me so! <a href="mailto:feedback@hak5.org" target="_blank">feedback@hak5.org</a>.</p>
<p><strong>Nibble: MTR isn&#8217;t your fathers traceroute</strong></p>
<p>MTR isn&#8217;t your father&#8217;s Traceroute. It&#8217;s the ultimate command line tool for finding out where those tasty little packets are getting lost. From bash issue mtr &#8211;report-wide &#8211;curses and your destination of choice. </p>
<blockquote><p>mtr &#8211;report-wide &#8211;curses 8.8.8.8</p></blockquote>
<p>MTR will bring up a curses terminal interface with a constantly updating report on hops and pings, complete with hostname, best and average latency, and percentage of packets lost at each link.</p>
<p>Thanks to Brian for sending this in and scoring some complimentary hak5 swag. Submit your 4-bits at <a href="http://www.hak5.org/nibble" target="_blank">hak5.org/nibble</a></p>
<p>If you&#8217;re into Hak5 you&#8217;ll love our new show by hosts Darren Kitchen and Shannon Morse. Check out <a href="http://www.revision3.com/haktip">HakTip</a>!</p>
<p>Whether you&#8217;re a beginner or a pro, <a href="http://www.revision3.com/haktip">HakTip</a> is essential viewing for current and aspiring hackers, computer enthusiasts, and IT professionals. With a how-to approach to all things Information Technology, HakTip breaks down the core concepts, tools, and techniques of Linux, Wireless Networks, Systems Administration, and more</p>
<p>And let&#8217;s not forget to mention that you can follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> and <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>, <a href="http://revision3.com/hak5/subscribe" target="_blank">Subscribe</a> to the show and get all your Hak5 goodies, including the infamous <a href="http://hakshop.com/collections/frontpage/products/wifi-pineapple" target="_blank">WiFi Pineapple</a> over at <a href="http://hakshop.com/" target="_blank">HakShop.com</a>. If you have any questions or suggestions please feel free to contact us at <a href="mailto:feedback@hak5.org">feedback@hak5.org</a>.</p>
<p>If you’re an IT or software consultant, you’re always looking to compete with the big guys. Problem is you may be a one man show! You need a remote support tool &#8211; and the best is Go To Assist Express. The faster you can connect to a customer, the faster you can move on to the next challenge! Reduce your travel time and increase revenue by handling more support requests. Brought to you by Citrix, you KNOW Go To Assist Express is easy and secure. Try GoToAssist Express FREE for 30 Days. For this special offer visit <a href="http://www.gotoassist.com/hak5" target="_blank">GoToAssist.com/Hak5</a>.</p>
<p>If you want to build a video site or if your website has a play button, I recommend getting a dot TV domain. A dot TV website lets you showcase your original content and create a unique site, not just another YouTube channel.<br />
Just go to <a href="http://www.domain.com" target="_blank">domain.com</a> and search for the perfect dot TV domain for your new idea. Then use coupon code Hak5 at checkout to save an extra 15%.<br />
If you need to host your dot TV website, don’t forget about Domain.com’s web hosting plans. They’re less than six bucks a month and have everything you need to build, maintain, and promote your site.<br />
Remember – when you think domain names, think <a href="http://www.domain.com" target="_blank">domain.com</a>.<br />
Got a great idea? It all starts with a great domain. <a href="http://www.domain.com" target="_blank">domain.com</a></p>
<p>Audible.com is the leading provider of downloadable digital audiobooks and spoken word entertainment. Audible has over 75,000 titles to choose from, to be downloaded to your iPod/MP3 player and played back anywhere, anytime. Choose from books in every genre, science fiction, thrillers, drama, comedy, business, history and more. Go to audiblepodcast.com/ hak5 to get a FREE audiobook-download of your choice when you sign up today. Again go to <a href="http://www.audiblepodcast.com/hak5" target="_blank">Audiblepodcast.com/hak5</a> for your Free Audiobook!</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/hak5-922/feed</wfw:commentRss>
		<slash:comments>17</slash:comments>
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0922/hak5--0922--britishthemesong--hd720p30.h264.mp4" length="389400238" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0922/hak5--0922--britishthemesong--large.h264.mp4" length="212963283" type="video/mp4" />
<enclosure url="http://videos.revision3.com/revision3/web/hak5/0922/hak5--0922--britishthemesong--large.wmv9.wmv" length="361105975" type="video/asf" />
		</item>
		<item>
		<title>Setting up Qnext Communication System.</title>
		<link>http://Hak5.org/geek/setting-up-qnext-communication-system</link>
		<comments>http://Hak5.org/geek/setting-up-qnext-communication-system#comments</comments>
		<pubDate>Sun, 12 Sep 2010 23:15:27 +0000</pubDate>
		<dc:creator>paul</dc:creator>
				<category><![CDATA[Geek]]></category>
		<category><![CDATA[AIM]]></category>
		<category><![CDATA[file sharing]]></category>
		<category><![CDATA[IM]]></category>
		<category><![CDATA[remote access]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=3130</guid>
		<description><![CDATA[
			
				
			
		
Shannon is all about combining instant messaging, file sharing and remote access with Qnext.



Shannon shows how to setup Qnext and use it for all her online communication.
]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fgeek%2Fsetting-up-qnext-communication-system"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fgeek%2Fsetting-up-qnext-communication-system&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Shannon is all about combining instant messaging, file sharing and remote access with Qnext.</p>
<div style="clear:both;"></div>
<p><span id="more-3130"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/so2966a29do?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0&amp;start=943" /><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube.com/v/so2966a29do?version=3&amp;hl=en_US&amp;fs=1&amp;hd=1&amp;showinfo=0&amp;rel=0&amp;showsearch=0&amp;start=943" wmode="transparent" allowfullscreen="true" allowscriptaccess="always"></embed></object></p>
<p>Shannon shows how to setup Qnext and use it for all her online communication.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/geek/setting-up-qnext-communication-system/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Episode 722 – Virtual Private Networks using your Google account and chipset woes</title>
		<link>http://Hak5.org/episodes/episode-722</link>
		<comments>http://Hak5.org/episodes/episode-722#comments</comments>
		<pubDate>Wed, 14 Jul 2010 08:35:42 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 7]]></category>
		<category><![CDATA[chipset]]></category>
		<category><![CDATA[darren kitchen]]></category>
		<category><![CDATA[gbridge]]></category>
		<category><![CDATA[i7]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[shannon morse]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.Hak5.org/?p=2229</guid>
		<description><![CDATA[<object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/koDFZWJ-Jck&#038;hl=en_US&#038;fs=1&#038;hd=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/koDFZWJ-Jck&#038;hl=en_US&#038;fs=1&#038;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-722"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-722&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This week Shannon has a great Snubs Report on setting up a Virtual Private Network using your Google account, and Darren shares some lessons learned in Linux wireless chipset compatibility and motherboard selection in a segment that can only be dubbed &#8220;How I walked in for a USB dongle and left with an i7 rig&#8221;</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-2229"></span></p>
<p><object width="555" height="312"><param name="movie" value="http://www.youtube.com/v/koDFZWJ-Jck&#038;hl=en_US&#038;fs=1&#038;hd=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/koDFZWJ-Jck&#038;hl=en_US&#038;fs=1&#038;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="555" height="312" wmode="transparent"></embed></object></p>
<p><strong>Linux wireless chipset compatibility, or, how I ended up with an i7</strong></p>
<p>Darren shares some lessons learned in Linux wireless chipset compatibility, motherboard selection and why following up on forum threads is important.</p>
<p>Next week we&#8217;ll continue with water cooling and home built wireless access points</p>
<p><b>Domain.com</b></p>
<p>I like <a href="http://www.domain.com" target="_blank">Domain.com</a>’s Deluxe web hosting plan that’s only $8.75/mo. One click install of all the popular open source programs like WordPress, Joomla, and Drupal, and more! Unlimited traffic</p>
<p>Free website builder with unlimited pages, Easy and affordable to get your sites online with <a href="http://www.domain.com" target="_blank">Domain.com</a>. <a href="http://www.domain.com" target="_blank">Domain.com</a> offers blistering fast DNS and hosting infrastructure, the lowest prices on the web AND the highest quality. Thanks to Hak5 fans, <a href="http://www.domain.com" target="_blank">Domain.com</a> is one of the fastest growing domain and hosting companies in the world. Got a great idea? It all starts with a great domain.  <a href="http://www.domain.com" target="_blank">Domain.com</a>! Don’t forget to use coupon code HAK5 at checkout to get 15% off your order. </p>
<p><strong>Setting up a simple Virtual Private Network using Google</strong></p>
<p><a href="http://www.gbridge.com/" target="_blank">Gbridge</a> is a free software-only solution available for all versions of Windows and uses your Google Account for authentication. It is an extension of Google&#8217;s gtalk service and lets you remotely control PCs, sync folders, share files, and chat securely and easily. You can share your desktop with your designated friend from anywhere in the world and automatically traverses firewalls and NATting routers without the need for configuration! Gbridge allows you to securely share and access files and let friends view photos instantly remotely with no download needed. Transfer and sync large files and folders to and from anywhere with no size restrictions, then use AutoSync to auto-schedule, auto-resume, and do incremental transfers as well as set up and auto-backup of your important folder to a local or remote PC.</p>
<p>I connected to a box on our Hak5 Cloud Lab with GoToAssist Express to show you how to easily connect Gbridge and start sharing files.</p>
<p>Click on the download link to go to the download page on Gbridge.com.<br />
Start the download and click yes a couple of times.<br />
A popup will say it needs to install the VPN driver so click ok, then wait for the install to finish. Click allow if Windows tells you any warnings about downloading and installing.<br />
Click finished once it&#8217;s done installing.<br />
Start Gbridge and it&#8217;ll ask you for your gmail info. </p>
<p>You can also create a new gmail account or google apps account if you dont want to use your regular one.<br />
The first thing I see is my friends list. It automatically includes my chat friends, none of which are online right now.</p>
<p>If you have OpenDNS or some other DNS resolving service, it may keep Gbridge from functioning properly, so you will either need to configure your service with a VPN exception rule for gbridge.net or just raise the Gbridge virtual adapters binding order. (which can be changed back anytime you want.)<br />
Now at the top, you can log off, Invite friends by typing their email or add friends from your list of contacts. You can also create new shares:<br />
To do so, click on the volume you wish to share, then add any friends you want to share this folder with. I&#8217;m going to add Darren, then password the volume.<br />
Darren is currently on my list of friends but not included in my list of friends that I share with, so I&#8217;m going to allow him, and there we go! My SecureShare is now created.<br />
I can go into the SecureShares tab to make changes to my shared folders, and on my friends list, I can make changes to friends or chat with them.<br />
To backup your folder onto the main machine or another machine, click the Add EasyBackup icon, choose the SecureShare, choose which machine to put the backup on, and let the backup begin.<br />
To use desktop share, click on the icon, choose Configure, and change settings.<br />
All in all, Gbridge is lightweight, easy, and free. All good in my book!</p>
<p>It won&#8217;t replace a proper PPTP or IPsec VPN but it will be up and running in minutes giving you the majority of what you need.<br />
Email me what you think at <a href="mailto: feedback@hak5.org">feedback@hak5.org</a><br />
Thanks to Go To Assist Express for this weeks Snubs Report.</p>
<p><b>GoToAssist Express</b><br />
If you’re in technical support&#8230; I want to tell you about an easy way to save time&#8230; money &#8211; AND make you look like a HERO to clients and colleagues.<br />
<a href="http://www.gotoassist.com/hak5" target="_blank">GoToAssist Express</a> – bought to you by our friends at Citrix is an EASY and SECURE remote support solution! With GoToAssist Express, you can SEE and SOLVE the problem WITHOUT being there in person! GoToAssist Express is specifically designed for small businesses and professionals to support clients and the best part is that with GoToAssist you don’t have to pre-install software to on your customers’ machines so you can instantly start supporting them online. Try Go To Assist Express FREE for 30 days! For this special offer, you must visit <a href="http://www.gotoassist.com/hak5" target="_blank">gotoassist.com/Hak5</a>. That’s <a href="http://www.gotoassist.com/hak5" target="_blank">gotoassist.com/Hak5</a> for a FREE trial.</p>
<p><strong>Trivia</strong></p>
<p>This 90&#8242;s era IDE and interpreter came with four pre-written<br />
example programs, including<br />
&#8220;Nibbles&#8221; and &#8220;Gorillas&#8221;
</p>
<p>Be sure to submit your answer at <a href="http://www.hak5.org/trivia/" target="_blank">Hak5.org/Trivia</a> for your chance to win some awesome Hak5 swag.</p>
<p><b>United States Air Force</b><br />
A Special thanks to the sponsor of today’s episode, The United States Air Force</p>
<p>If you want to know the latest on Hak5 be sure to follow us on <a href="http://www.twitter.com/hak5/" target="_blank">Twitter</a> or <a href="http://www.facebook.com/technolust/" target="_blank">Facebook</a>.</p>
<p>Also, now is also a great time to grab some swag from the <a href="http://www.hak5.org/shop/" target="_blank">HakShop</a> &#8211; including the new airport friendly <a href="http://www.hak5.org/store/wifi-pineapple-version-2" target="_blank">WiFi Pineapple</a> with free world-wide shipping.</p>
<p>And finally if you&#8217;d like to suggest a topic for a future show feel free to hit up <a href="mailto:feedback@hak5.org">feedback@hak5.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-722/feed</wfw:commentRss>
		<slash:comments>17</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--hd720p30.h264.mp4" length="214" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--large.h264.mp4" length="211" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--large.xvid.avi" length="211" type="video/avi" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0722/hak5--0722--lessonslearned--large.wmv9.wmv" length="211" type="video/asf" />
		</item>
		<item>
		<title>Episode 621 – MiTM Javascript Keylogger, Social Engineering Toolkit and more</title>
		<link>http://Hak5.org/episodes/episode-621</link>
		<comments>http://Hak5.org/episodes/episode-621#comments</comments>
		<pubDate>Tue, 05 Jan 2010 15:24:41 +0000</pubDate>
		<dc:creator>Jason</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[address spoofing]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[backtrack4]]></category>
		<category><![CDATA[bt3]]></category>
		<category><![CDATA[bt4]]></category>
		<category><![CDATA[cross platform]]></category>
		<category><![CDATA[cryptsetup]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[finland]]></category>
		<category><![CDATA[inguardians]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Irongeek]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[javascript keylogger]]></category>
		<category><![CDATA[jay beale]]></category>
		<category><![CDATA[Keylogger]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[linux encryption]]></category>
		<category><![CDATA[mac address]]></category>
		<category><![CDATA[mac address spoofing]]></category>
		<category><![CDATA[mac changer]]></category>
		<category><![CDATA[mac spoofing]]></category>
		<category><![CDATA[macchanger]]></category>
		<category><![CDATA[mad macs]]></category>
		<category><![CDATA[madmacs]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[middler]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[mubix]]></category>
		<category><![CDATA[Nokia]]></category>
		<category><![CDATA[phish]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[Rob Fuller]]></category>
		<category><![CDATA[room362]]></category>
		<category><![CDATA[samurai]]></category>
		<category><![CDATA[samurai-wtf]]></category>
		<category><![CDATA[SET]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[social engineering toolkit]]></category>
		<category><![CDATA[spoofing]]></category>
		<category><![CDATA[spotify]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[the middler]]></category>
		<category><![CDATA[trucrypt]]></category>
		<category><![CDATA[truecrypt]]></category>
		<category><![CDATA[tunnel]]></category>
		<category><![CDATA[ubuntu encryption]]></category>
		<category><![CDATA[virtual appliance]]></category>
		<category><![CDATA[virtual box]]></category>
		<category><![CDATA[virtualbox]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[wtf]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1922</guid>
		<description><![CDATA[<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="555" height="312" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube-nocookie.com/v/NtcKH9yRyJM&#38;hl=en_US&#38;fs=1&#38;rel=0&#38;hd=1" /><param name="wmode" value="transparent" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube-nocookie.com/v/NtcKH9yRyJM&#38;hl=en_US&#38;fs=1&#38;rel=0&#38;hd=1" wmode="transparent" allowscriptaccess="always" allowfullscreen="true"></embed></object>]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-621"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-621&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>This week Darren is joined by <a href="http://www.room362.com" target="_blank">Rob Ruller</a>, aka <a href="http://www.room362.com" target="_blank">Mubix</a> for a little fun with Man-in-the-middle javascript keylogger using <a href="http://code.google.com/p/middler/" target="_blank">the Middler</a>, and pwning with the <a href="http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_(SET)" target="_blank">Social Engineering Toolkit</a>. Plus using <a href="http://www.spotify.com" target="_blank">Spotify</a> in the US without a <a href="http://www.hak5.org/hack/bypass-filters-with-your-own-web-proxy" target="_blank">proxy</a>, Mac Address spoofing in <a href="http://www.alobbs.com/macchanger/" target="_blank">Linux</a> or <a href="http://www.irongeek.com/i.php?page=security/madmacs-mac-spoofer" target="_blank">Windows</a>, <a href="http://virtualboximages.com" target="_blank">Virtual Appliances</a> for <a href="http://www.virtualbox.org/" target="_blank">VirtualBox</a>, and much more! Take an hour lunch and prepare to feed your technolust!</p>
<div style="clear:both;"></div>
<p><a href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0621/hak5--0621--setoolkit--hd720p30.h264.mp4">Download HD</a> <a href="http://www.podtrac.com/pts/redirect.mp4/videos.revision3.com/revision3/web/hak5/0621/hak5--0621--setoolkit--large.h264.mp4">Download MP4</a> <a href="http://www.podtrac.com/pts/redirect.avi/videos.revision3.com/revision3/web/hak5/0621/hak5--0621--setoolkit--large.xvid.avi">Download XviD</a> <a href="http://www.podtrac.com/pts/redirect.wmv/videos.revision3.com/revision3/web/hak5/0621/hak5--0621--setoolkit--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1922"></span><br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="555" height="312" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube-nocookie.com/v/NtcKH9yRyJM&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" /><param name="wmode" value="transparent" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="555" height="312" src="http://www.youtube-nocookie.com/v/NtcKH9yRyJM&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" wmode="transparent" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p><strong>Cross Platform Encryption</strong></p>
<p>Mahmoud, as well as many others, wrote in to ask about the cross-platform compatability of the encryption set setup on <a href="http://www.hak5.org/episodes/episode-620" target="_blank">Hak5 episode 620</a> using cryptsetup.</p>
<p>The short answer is, no, it&#8217;s just for Linux. If you&#8217;re looking for something both open source and cross platform look no further than <a href="http://www.truecrypt.org/" target="_blank">Truecrypt</a></p>
<p><strong>Spotify in the United States without a proxy</strong></p>
<p><strong> </strong>Following up on last week&#8217;s question about IP spoofing so users in the US can try out <a href="http://www.spotify.com" target="_blank">Spotify</a>, we&#8217;ve got just the trick without a proxy. Ok, well sorta. If you happen to have a beta invite and a friend, perhapse on <a href="http://hak5.org/forums/index.php?showtopic=14847" target="_blank">IRC</a>, in an allowed country it&#8217;s just a matter of having them sign up for you. The only limitation is that you&#8217;ll need to have your account signed into from your &#8220;home country&#8221; every 14 days. On the other hand if you decide to spring for the €9,99/mo premium account you, supposedly, don&#8217;t have such limitations. Thanks to Jouni in Finland for hooking me up. I&#8217;ll be sad when its game over in two weeks. Or will it?</p>
<p><strong>Virtual Appliances for VirtualBox</strong></p>
<p>If you&#8217;re a fan of <a href="http://www.virtualbox.org" target="_blank">VirtualBox</a> then you&#8217;ll love <a href="http://virtualboximages.com/" target="_blank">VirtualBoxImages.com</a>. They&#8217;ve got pre-packaged VirtualBox VDI&#8217;s ready for your enjoyment.</p>
<p><strong>Javascript Keylogger via Man-in-the-Middle Attack</strong></p>
<p>When it comes to man-in-the-middle attacks just about anything is possible. In this segment Darren explores <a href="http://www.inguardians.com/" target="_blank">InGuardians</a> tool <a href="http://code.google.com/p/middler/" target="_blank">the Middler</a>. Using a plugin architecture for manipulating (among others) http traffic, we attempt to get the infamous javascript onKeyPress keylogger going. Without much success in that department Darren goes on to demonstrate iframe injection and ponders ways to make the <a href="http://code.google.com/p/middler/source/browse/tags/0.95r1/middlerlib/plugins/plugin-keylogger-INGUARDIANS-ONLY.py" target="_blank">borked plugin</a> behave.</p>
<p><strong>Social Engineering Toolkit</strong></p>
<p>Hacking isn&#8217;t just about remote code execution. Well, I mean, that&#8217;s fun and all but rather than exploiting the server, how about exploiting the Human OS. In this segment <a href="http://www.room362.com" target="_blank">Mubix</a> demonstrates David Kennedy (aka <a href="http://twitter.com/dave_rel1k" target="_blank">Rel1k</a>)&#8217;s tool, <a href="http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_(SET)" target="_blank">The Social Engineering Toolkit</a>. Despite some challenges with clients that werent setup with Java, Mubix successfully demonstrates meterpreter in conjunction with a cloned site.</p>
<p><strong>Mac Address Spoofing</strong></p>
<p><a href="http://www.twitter.com/Bluesmanchukk" target="_blank">@Bluesmanchukk</a> writes in to ask about Mac Address Spoofing. Darren and Rob discuss their favorite tools for the job: <a href="http://en.wikipedia.org/wiki/MAC_spoofing" target="_blank">ifconfig</a> (Linux), <a href="http://www.alobbs.com/macchanger/" target="_blank">GNU MAC Changer</a> (Linux), <a href="http://www.irongeek.com/i.php?page=security/madmacs-mac-spoofer" target="_blank">MadMACs</a> (Windows), <a href="http://wiki.hak5.org/wiki//MAC_Randomizer" target="_blank">Mac Randomizer</a> (Linux).</p>
<p><strong>Multi-Player Notepad</strong></p>
<p>Stoned33 wrote in to ask for our picks for simple online collaboration. Aside from the obvious Google Wave, Rob recommends the recently Google-Acquired yet still operating <a href="http://etherpad.com/" target="_blank">Etherpad</a>. This real-time document editor is like multi-player notepad on crack. Give it a shot.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-621/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hacking PPTP VPNs with ASLEAP</title>
		<link>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap</link>
		<comments>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap#comments</comments>
		<pubDate>Mon, 14 Dec 2009 07:58:05 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Hack]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[client handshake authentication protocol]]></category>
		<category><![CDATA[cowpatty]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[joshua wright]]></category>
		<category><![CDATA[l2tp]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[point to point tunneling protocol]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1627</guid>
		<description><![CDATA[
			
				
			
		
Darren demonstrates cracking Microsoft VPN tunnels using the MS-CHAPv2 authentication protocol using Joshua Wright&#8217;s tool ASLEAP and talks about the theory behind the attack.



Continuing on with our VPN series I find it important to highlight ...]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fhack%2Fhacking-pptp-vpns-with-asleap"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fhack%2Fhacking-pptp-vpns-with-asleap&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Darren demonstrates cracking Microsoft VPN tunnels using the MS-CHAPv2 authentication protocol using Joshua Wright&#8217;s tool ASLEAP and talks about the theory behind the attack.</p>
<div style="clear:both;"></div>
<p><span id="more-1627"></span></p>
<p><object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/IPPHJBp3bXU&#038;hl=en_US&#038;fs=1&#038;start=262"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/IPPHJBp3bXU&#038;hl=en_US&#038;fs=1&#038;start=262" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object></p>
<p>Continuing on with our VPN series I find it important to highlight the weaknesses in the protocols we have talked about thus far. In <a target="_blank" href="http://www.hak5.org/episodes/episode-610">my last segment</a> I highlighted a tool that allows an attacker to easily hijack an SSL session using a man-in-the-middle attack. Couple this with Adito (aka OpenVPN-ALS), <a target="_blank" href="http://www.hak5.org/episodes/episode-607">my favorite open-source SSL VPN server</a>, and you can see the problem.</p>
<p>But what about the basic <a target="_blank" href="http://www.hak5.org/episodes/episode-605">Microsoft VPN</a> we setup <a target="_blank" href="http://www.hak5.org/episodes/episode-605">a few weeks back?</a> The VPN servers that we setup on Windows XP and Server 2003 used either active directory or local windows accounts to authenticate users.</p>
<p>And looking back at <a target="_blank" href="http://www.hak5.org/episodes/episode-419">our discussions</a> on pwdump, rainbow tables and the like you&#8217;ll remember the inherent weaknesses in Windows account credentials.</p>
<p>There are two ways Windows stores a user&#8217;s account credentials, or password. <a target="_blank" href="http://en.wikipedia.org/wiki/LM_hash">LAN Manager</a> hashes which are comprised of watered-down weaksauce and <a target="_blank" href="http://en.wikipedia.org/wiki/NTLM">NTLM</a> which are succeptable to time-memory tradeoff attacks.</p>
<p>The default VPN server implemented in Windows XP and Server 2003&#8242;s Routing and Remote Access service uses Point-To-Point-Tunneling-Protocol. This is convenient because the Windows clients have supported Microsoft PPTP VPN connections natively since 2000, and in Windows 95/98 with <a target="_blank" href="http://support.microsoft.com/kb/191494">Dual Up Networking version 1.3</a>.</p>
<p>The modern authentication protocol of Microsoft&#8217;s PPTP is <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc739678(WS.10).aspx">MS-CHAPv2</a>. This <a target="_blank" href="http://en.wikipedia.org/wiki/Challenge-handshake_authentication_protocol">Challenge Handshake Authentication Protocol</a> suffers from inherent weaknesses.</p>
<p>As far back at 1999 these weaknesses have been widely known. If you&#8217;re interested in reading more on the cryptanalysis of MS-CHAPv2 there&#8217;s a <a target="_blank" href="http://www.schneier.com/paper-pptpv2.html">nifty paper</a> written by Bruce Schneier and L0pht that I&#8217;ll link in the show notes.</p>
<p>And while other options exist such as <a target="_blank" href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx">Radius</a>, this is still the default option for PPTP authentication in Windows environments.</p>
<p><a target="_blank" href="http://www.willhackforsushi.com/?page_id=87">Joshua Wright</a>, author of <a target="_blank" href="http://www.willhackforsushi.com/?p=284">coWPAtty</a> (See <a target="_blank" href="http://www.hak5.org/episodes/episode-518">our segment here</a>), released in 2004 a proof of concept tool to demonstrate weaknesses in <a target="_blank" href="http://en.wikipedia.org/wiki/Lightweight_Extensible_Authentication_Protocol">LEAP</a> and PPTP protocols.</p>
<p>This tool, <a target="_blank" href="http://www.willhackforsushi.com/Asleap.html">ASLEAP</a>, was updated in 2007 to include an option to just crack MS-CHAP v2. Either by examining a packet capture that includes a MS-CHAP handshake ASLEAP or specifying an MS-CHAP challenge and response ASLEAP is able to deduce the username and last two bytes of the NT hash. Using this information, and a dictionary file, ASLEAP is able to brute-force the hash.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/hack/hacking-pptp-vpns-with-asleap/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Episode 614 &#8211; Firewall evasion, SSH and virtual appliances!</title>
		<link>http://Hak5.org/episodes/episode-614</link>
		<comments>http://Hak5.org/episodes/episode-614#comments</comments>
		<pubDate>Wed, 18 Nov 2009 14:49:32 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[asleap]]></category>
		<category><![CDATA[bypass filter]]></category>
		<category><![CDATA[bypass firewall]]></category>
		<category><![CDATA[bypass school filter]]></category>
		<category><![CDATA[convert virtualbox]]></category>
		<category><![CDATA[convert vmware]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[DimDim]]></category>
		<category><![CDATA[dropbear]]></category>
		<category><![CDATA[easy proxy]]></category>
		<category><![CDATA[eavesdrop]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[free proxies]]></category>
		<category><![CDATA[free proxy]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hack filter]]></category>
		<category><![CDATA[hack firewall]]></category>
		<category><![CDATA[hack school filter]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[hacking firewalls]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[internet proxy]]></category>
		<category><![CDATA[internet tunneling]]></category>
		<category><![CDATA[lanman]]></category>
		<category><![CDATA[LM]]></category>
		<category><![CDATA[local forward]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[mschap]]></category>
		<category><![CDATA[mschapv2]]></category>
		<category><![CDATA[network scan]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[office firewall]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[open ssh]]></category>
		<category><![CDATA[open wifi]]></category>
		<category><![CDATA[OpenSSH]]></category>
		<category><![CDATA[Packet Sniff]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php proxy]]></category>
		<category><![CDATA[phpproxy]]></category>
		<category><![CDATA[port forward]]></category>
		<category><![CDATA[port redirection]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[proxies]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[Putty]]></category>
		<category><![CDATA[quick proxy]]></category>
		<category><![CDATA[restrictions]]></category>
		<category><![CDATA[safe wifi]]></category>
		<category><![CDATA[school firewall]]></category>
		<category><![CDATA[secure irc]]></category>
		<category><![CDATA[secure network]]></category>
		<category><![CDATA[secure shell]]></category>
		<category><![CDATA[secure tunnel]]></category>
		<category><![CDATA[secure wifi]]></category>
		<category><![CDATA[shell]]></category>
		<category><![CDATA[shell account]]></category>
		<category><![CDATA[simply proxy]]></category>
		<category><![CDATA[sniffing]]></category>
		<category><![CDATA[socks]]></category>
		<category><![CDATA[socks proxy]]></category>
		<category><![CDATA[socks5]]></category>
		<category><![CDATA[SSH]]></category>
		<category><![CDATA[ssh client]]></category>
		<category><![CDATA[ssh forward]]></category>
		<category><![CDATA[ssh server]]></category>
		<category><![CDATA[ssh tunnel]]></category>
		<category><![CDATA[static ip]]></category>
		<category><![CDATA[traffic tunneling]]></category>
		<category><![CDATA[university firewall]]></category>
		<category><![CDATA[virtual appliance]]></category>
		<category><![CDATA[virtual appliance marketplace]]></category>
		<category><![CDATA[Virtual Machine]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[virtual private server]]></category>
		<category><![CDATA[virtualbox]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[vmdk]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vpn]]></category>
		<category><![CDATA[vps]]></category>
		<category><![CDATA[web proxy]]></category>
		<category><![CDATA[work firewall]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1457</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3869" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent" />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-614"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-614&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Got a restrictive firewall blocking sites at school or work? Evade &#8216;em easily with your own private web proxy. Want to securely tunnel any port through an SSH session? Darren&#8217;s got just the trick. Wondering how to properly use Asleap to crack MS-CHAPv2 PPTP VPN handshakes &#038; LM Hashes? Interested in trying out neat free enterprise applications but don&#8217;t feel like spending hours in a terminal? Try deploying a virtual appliance in minutes, the free and open source way.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1457"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3869" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312" wmode="transparent" /></p>
<p><b>Port Tunneling and Socks5 Proxies with a Secure Shell (SSH)</b></p>
<p>SSH Tunneling isn&#8217;t new to the show, we&#8217;ve done it <a href="http://www.hak5.org/episodes/episode-504">before over DNS</a> or in conjunction <a href="http://www.hak5.org/episodes/hak5-episode-7-released">with VNC</a>. Today we&#8217;re looking at two SSH tricks for tunneling just about any traffic.</p>
<p>First up, <i>ssh -D</i>. The <i>-D</i> option specified a local &quote;Dynamic&quote; application-level port forwarding. Any connection made to the specified port goes through the tunnel as a SOCKS4 or SOCKS5 proxy. Perfect for secure web browsing as demonstrated with Firefox in this segment.</p>
<p><u>Usage</u></p>
<blockquote><pre>ssh -D 8080 user@server</pre>
</blockquote>
<p>Second, <i>ssh -L</i>. The <i>-L</i> option enables port forwarding. Using this option tells the SSH client to listen to traffic on a specified port and forward it along through the tunnel. The server receives this data and points it to the specified destination, whether it be on the destination network or otherwise. In our example we use the <i>-L</i> option to securely connect to an open IRC server.</p>
<p><u>Usage</u></p>
<blockquote><pre>ssh user@server -L local-listen-port:destination-ip:destination-port</pre>
</blockquote>
<p>For more SSH-fu check out the <a href="http://unixhelp.ed.ac.uk/CGI/man-cgi?ssh+1">ssh man page</a> or Linux Journal&#8217;s interesting series on <a href="http://www.linuxjournal.com/article/4412">101 uses of openssh</a>.</p>
<p><b>Bypassing site-blocking firewalls with your own private web proxy</b></p>
<p>The age old scheme for bypassing restrictive firewalls, like those that block sites at school or work, has been to use a web proxy. Of course this is followed up by the network administrator blocking all mainstream proxies. But what if you could run your own? Well, you can and it&#8217;s really freaking easy. In this segment Darren demonstrates <a href="http://sourceforge.net/projects/poxy/">PHProxy</a></p>
<p><b>Cracking MS-CHAPv2 PPTP VPN handshakes &#038; LM Hashes Followup from 6&#215;12</b></p>
<p>On <a href="http://www.hak5.org/episodes/episode-612">episode 612</a> we demonstrated a tool, asleap, designed to crack MS-CHAPv2, the authentication protocol commonly found in Microsoft PPTP VPNs. The final demo was unsuccessful due to the encoding of the handshake and response sniffed by Wireshark. Viewer Sc00bz was kind enough to post a PHP script that accepts the challenge, response and username and provides you with the proper asleap command to run with the properly encoded byte sequences. Sc00bz has well documented the code, which lives now on this <a href="http://hak5.org/forums/index.php?showtopic=14755">Hak5 forum</a> thread. Thanks Sc00bz!</p>
<p><b>Deploying Virtual Appliances in minutes the open source way</b></p>
<p>A Virtual Appliance can be though of as a software image containing a supporting stack designed to run inside a virtual machine. A quick look at vmware&#8217;s <a href="http://www.vmware.com/appliances/">virtual appliance directory</a> shows that there are hundreds of applications that can be quickly and easily deployed. In this segment I take the <a href="http://www.dimdim.com/hak5">Dimdim</a> open source virtual appliance, designed for vmware, and deploy it with <a rhef="http://www.virtualbox.org">VirtualBox</a> (just becasue I can).</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-614/feed</wfw:commentRss>
		<slash:comments>38</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--hd720p30.h264.mp4" length="345088325" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.h264.mp4" length="225102421" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.xvid.avi" length="194242128" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0614/hak5--0614--tunnelingproxies--large.wmv9.wmv" length="180435644" type="video/x-ms-wmv" />
		</item>
		<item>
		<title>Episode 612 &#8211; Hacking PPTP VPNs with ASLEAP</title>
		<link>http://Hak5.org/episodes/episode-612</link>
		<comments>http://Hak5.org/episodes/episode-612#comments</comments>
		<pubDate>Wed, 04 Nov 2009 16:52:17 +0000</pubDate>
		<dc:creator>Darren Kitchen</dc:creator>
				<category><![CDATA[Episodes]]></category>
		<category><![CDATA[Season 6]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[Brute Force]]></category>
		<category><![CDATA[chap]]></category>
		<category><![CDATA[client handshake authentication protocol]]></category>
		<category><![CDATA[cowpatty]]></category>
		<category><![CDATA[crack]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hash]]></category>
		<category><![CDATA[ipsec]]></category>
		<category><![CDATA[joshua wright]]></category>
		<category><![CDATA[l2tp]]></category>
		<category><![CDATA[lan man]]></category>
		<category><![CDATA[ms-chap]]></category>
		<category><![CDATA[ms-chapv2]]></category>
		<category><![CDATA[ntlm]]></category>
		<category><![CDATA[offensive security]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[penetration test]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[point to point tunneling protocol]]></category>
		<category><![CDATA[pptp]]></category>
		<category><![CDATA[remote exploit]]></category>
		<category><![CDATA[routing and remote access]]></category>
		<category><![CDATA[rras]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[virtual private network]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.hak5.org/?p=1440</guid>
		<description><![CDATA[<embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3867" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  wmode="transparent"  />]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-612"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2FHak5.org%2Fepisodes%2Fepisode-612&amp;source=Hak5&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Continuing with the VPN Series, Darren discusses the inherent weaknesses in Microsoft&#8217;s PPTP authentication protocol, MS-CHAPv2, and demos a Linux tool that exploits these weaknesses.</p>
<div style="clear:both;"></div>
<p><a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--hd720p30.h264.mp4">Download HD</a> <a class="mov" href="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.h264.mp4">Download MP4</a> <a class="xvid" href="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.xvid.avi">Download XviD</a> <a class="wmv" href="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.wmv9.wmv">Download WMV</a></p>
<p><span id="more-1440"></span></p>
<p><embed class="rev3PlayerEmbed" type="application/x-shockwave-flash" src="http://revision3.com/player-v3867" allowFullScreen="true" quality="high" allowScriptAccess="always" width="555" height="312"  wmode="transparent"  /></p>
<p>Continuing on with our VPN series I find it important to highlight the weaknesses in the protocols we have talked about thus far. In <a target="_blank" href="http://www.hak5.org/episodes/episode-610">my last segment</a> I highlighted a tool that allows an attacker to easily hijack an SSL session using a man-in-the-middle attack. Couple this with Adito (aka OpenVPN-ALS), <a target="_blank" href="http://www.hak5.org/episodes/episode-607">my favorite open-source SSL VPN server</a>, and you can see the problem.</p>
<p>But what about the basic <a target="_blank" href="http://www.hak5.org/episodes/episode-605">Microsoft VPN</a> we setup <a target="_blank" href="http://www.hak5.org/episodes/episode-605">a few weeks back?</a> The VPN servers that we setup on Windows XP and Server 2003 used either active directory or local windows accounts to authenticate users.</p>
<p>And looking back at <a target="_blank" href="http://www.hak5.org/episodes/episode-419">our discussions</a> on pwdump, rainbow tables and the like you&#8217;ll remember the inherent weaknesses in Windows account credentials.</p>
<p>There are two ways Windows stores a user&#8217;s account credentials, or password. <a target="_blank" href="http://en.wikipedia.org/wiki/LM_hash">LAN Manager</a> hashes which are comprised of watered-down weaksauce and <a target="_blank" href="http://en.wikipedia.org/wiki/NTLM">NTLM</a> which are succeptable to time-memory tradeoff attacks.</p>
<p>The default VPN server implemented in Windows XP and Server 2003&#8242;s Routing and Remote Access service uses Point-To-Point-Tunneling-Protocol. This is convenient because the Windows clients have supported Microsoft PPTP VPN connections natively since 2000, and in Windows 95/98 with <a target="_blank" href="http://support.microsoft.com/kb/191494">Dual Up Networking version 1.3</a>.</p>
<p>The modern authentication protocol of Microsoft&#8217;s PPTP is <a target="_blank" href="http://technet.microsoft.com/en-us/library/cc739678(WS.10).aspx">MS-CHAPv2</a>. This <a target="_blank" href="http://en.wikipedia.org/wiki/Challenge-handshake_authentication_protocol">Challenge Handshake Authentication Protocol</a> suffers from inherent weaknesses.</p>
<p>As far back at 1999 these weaknesses have been widely known. If you&#8217;re interested in reading more on the cryptanalysis of MS-CHAPv2 there&#8217;s a <a target="_blank" href="http://www.schneier.com/paper-pptpv2.html">nifty paper</a> written by Bruce Schneier and L0pht that I&#8217;ll link in the show notes.</p>
<p>And while other options exist such as <a target="_blank" href="http://blogs.technet.com/rrasblog/archive/2009/03/25/remote-access-deployment-part-2-configuring-rras-as-a-vpn-server.aspx">Radius</a>, this is still the default option for PPTP authentication in Windows environments.</p>
<p><a target="_blank" href="http://www.willhackforsushi.com/?page_id=87">Joshua Wright</a>, author of <a target="_blank" href="http://www.willhackforsushi.com/?p=284">coWPAtty</a> (See <a target="_blank" href="http://www.hak5.org/episodes/episode-518">our segment here</a>), released in 2004 a proof of concept tool to demonstrate weaknesses in <a target="_blank" href="http://en.wikipedia.org/wiki/Lightweight_Extensible_Authentication_Protocol">LEAP</a> and PPTP protocols.</p>
<p>This tool, <a target="_blank" href="http://www.willhackforsushi.com/Asleap.html">ASLEAP</a>, was updated in 2007 to include an option to just crack MS-CHAP v2. Either by examining a packet capture that includes a MS-CHAP handshake ASLEAP or specifying an MS-CHAP challenge and response ASLEAP is able to deduce the username and last two bytes of the NT hash. Using this information, and a dictionary file, ASLEAP is able to brute-force the hash.</p>
<p>PS: Check out <a href="http://www.player2rentals.com" target="_blank">Player2Rentals.com</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://Hak5.org/episodes/episode-612/feed</wfw:commentRss>
		<slash:comments>16</slash:comments>
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--hd720p30.h264.mp4" length="549041844" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.mp4/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.h264.mp4" length="358047282" type="video/mp4" />
<enclosure url="http://www.podtrac.com/pts/redirect.avi/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.xvid.avi" length="315159934" type="video/x-msvideo" />
<enclosure url="http://www.podtrac.com/pts/redirect.wmv/bitcast-a.bitgravity.com/revision3/web/hak5/0612/hak5--0612--asleap--large.wmv9.wmv" length="307796076" type="video/x-ms-wmv" />
		</item>
	</channel>
</rss>
<!-- This Quick Cache file was built for (  hak5.org/tag/vpn/feed ) in 1.27729 seconds, on May 23rd, 2012 at 10:41 pm UTC. -->
<!-- This Quick Cache file will automatically expire ( and be re-built automatically ) on May 23rd, 2012 at 11:41 pm UTC -->
