<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.9.2 (http://www.squarespace.com/) on Fri, 12 Mar 2010 19:03:29 GMT--><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>Mubix Links</title><link>http://www.room362.com/mubixlinks/</link><description></description><lastBuildDate>Fri, 05 Mar 2010 20:18:25 +0000</lastBuildDate><copyright></copyright><language>en-US</language><generator>Squarespace Site Server v5.9.2 (http://www.squarespace.com/)</generator><item><title>HD Moore at 17</title><dc:creator>Rob Fuller</dc:creator><pubDate>Fri, 05 Mar 2010 20:16:13 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/3/5/hd-moore-at-17.html</link><guid isPermaLink="false">438411:4906714:6918766</guid><description><![CDATA[<p>had to save this for posterity. ;-)</p>
<p><object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/m6JyIUyRi4U&hl=en_US&fs=1&color1=0x3a3a3a&color2=0x999999"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/m6JyIUyRi4U&hl=en_US&fs=1&color1=0x3a3a3a&color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed></object></p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6918766.xml</wfw:commentRss></item><item><title>CSPP</title><dc:creator>Rob Fuller</dc:creator><pubDate>Thu, 04 Mar 2010 17:22:36 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/3/4/cspp.html</link><guid isPermaLink="false">438411:4906714:6906690</guid><description><![CDATA[<p>Connection String Parameter Pollution:</p>
<p><a href="http://www.informatica64.com/csppScanner.aspx">http://www.informatica64.com/csppScanner.aspx</a></p>
<p>more info here:</p>
<p>[Whitepaper &ndash; PDF] <a title="http://www.blackhat.com/presentations/bh-dc-10/Alonso_Chema/Blackhat-DC-2010-Alonso-Connection-String-Parameter-Pollution-wp.pdf" href="http://www.blackhat.com/presentations/bh-dc-10/Alonso_Chema/Blackhat-DC-2010-Alonso-Connection-String-Parameter-Pollution-wp.pdf">http://www.blackhat.com/presentations/bh-dc-10/Alonso_Chema/Blackhat-DC-2010-Alonso-Connection-String-Parameter-Pollution-wp.pdf</a></p>
<p>and</p>
<p>[Slides] <a title="http://www.slideshare.net/chemai64/connection-string-parameter-pollution-attacks-3057114" href="http://www.slideshare.net/chemai64/connection-string-parameter-pollution-attacks-3057114">http://www.slideshare.net/chemai64/connection-string-parameter-pollution-attacks-3057114</a></p>
<p>and</p>
<p>[Report] <a title="http://www.darkreading.com/database_security/security/vulnerabilities/showArticle.jhtml?articleID=222600894" href="http://www.darkreading.com/database_security/security/vulnerabilities/showArticle.jhtml?articleID=222600894">http://www.darkreading.com/database_security/security/vulnerabilities/showArticle.jhtml?articleID=222600894</a></p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6906690.xml</wfw:commentRss></item><item><title>Mini Metasploit</title><dc:creator>Rob Fuller</dc:creator><pubDate>Thu, 18 Feb 2010 19:21:39 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/2/18/mini-metasploit.html</link><guid isPermaLink="false">438411:4906714:6742515</guid><description><![CDATA[<p>So a bunch of you have emailed and/or asked for the mini installer from my “<a href="http://www.room362.com/blog/2009/6/26/metasploit-framework-as-a-payload.html">Metasploit Framework as a Payload</a>” post. I got permission to post it up on my site. HOWEVER, new builds of both mini and the larger installer will be coming soon, so keep checking back for updates on <a href="http://metasploit.com">Metasploit.com</a> for updates on that.</p>  <p>Here are the links to the files:</p>  <p><a href="http://www.room362.com/scripts-and-programs/metasploit/mini-3.3-dev.exe">mini-3.3-dev.exe</a> (5.9M)</p>  <p><a href="http://www.room362.com/scripts-and-programs/metasploit/framework-3.3-dev-mini.exe">framework-3.3-dev-mini.exe</a> (11.5 M)</p>  <p><a href="http://www.room362.com/scripts-and-programs/metasploit/framework-3.3-dev.exe">framework-3.3-dev.exe</a> (20.8M)</p>  <p>The two mini’s have a different amount of code taken out of them, so find what works best for you and your needs.</p>  <p>Also, you can download the <a href="http://www.room362.com/scripts-and-programs/metasploit/deploymsf.rb">deploymsf.rb</a> and more on my <a href="http://www.room362.com/scripts-and-programs/">Scripts and Programs</a> tab as well as the link.</p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6742515.xml</wfw:commentRss></item><item><title>Web App Sec Pro's Daily Crossword</title><dc:creator>Rob Fuller</dc:creator><pubDate>Wed, 17 Feb 2010 17:00:03 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/2/17/web-app-sec-pros-daily-crossword.html</link><guid isPermaLink="false">438411:4906714:6721219</guid><description><![CDATA[<p>So here is the basic jist, you got a blob of code, you have to find the vulnerable part. And the next post explains where it and why it is the way it is. The technical&nbsp;equivalent&nbsp;to a daily crossword.</p>
<p><a href="http://spotthevuln.com/">http://spotthevuln.com/</a></p>
<p>&nbsp;</p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6721219.xml</wfw:commentRss></item><item><title>Flash Hacking</title><dc:creator>Rob Fuller</dc:creator><pubDate>Thu, 11 Feb 2010 19:04:39 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/2/11/flash-hacking.html</link><guid isPermaLink="false">438411:4906714:6651850</guid><description><![CDATA[<p>Read this:</p>  <p><a href="http://code.google.com/p/doctype/wiki/ArticleFlashSecurity">http://code.google.com/p/doctype/wiki/ArticleFlashSecurity</a></p>  <p>Then this:</p>  <p><a href="http://www.ivizsecurity.com/blog/web-application-security/testing-flash-applications-pen-tester-guide/">http://www.ivizsecurity.com/blog/web-application-security/testing-flash-applications-pen-tester-guide/</a></p>  <p>Then this:</p>  <p><a href="http://carnal0wnage.blogspot.com/2009/11/decompiling-flash-files-with-swfscan.html">http://carnal0wnage.blogspot.com/2009/11/decompiling-flash-files-with-swfscan.html</a></p>  <p>Also, attend one of Kevin Johnson’s talk on the subject, not sure if his stuff is posted anywhere yet though.</p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6651850.xml</wfw:commentRss></item><item><title>Probabilistic Password Cracking</title><dc:creator>Rob Fuller</dc:creator><pubDate>Sat, 23 Jan 2010 17:00:19 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/1/23/probabilistic-password-cracking.html</link><guid isPermaLink="false">438411:4906714:6376629</guid><description><![CDATA[<p>Matt Weir from <a title="http://reusablesec.blogspot.com" href="http://reusablesec.blogspot.com">http://reusablesec.blogspot.com</a> created a program (well, continued where Bill had left off) that takes dictionary based password cracking to a whole new level</p>
<p>Read more and download the tool here:</p>
<p><a href="http://sites.google.com/site/reusablesec/Home/password-cracking-tools/probablistic_cracker">http://sites.google.com/site/reusablesec/Home/password-cracking-tools/probablistic_cracker</a></p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6376629.xml</wfw:commentRss></item><item><title>Security Podcasts Boxee App</title><dc:creator>Rob Fuller</dc:creator><pubDate>Fri, 22 Jan 2010 17:00:32 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/1/22/security-podcasts-boxee-app.html</link><guid isPermaLink="false">438411:4906714:6376290</guid><description><![CDATA[<p><a title="http://www.twitter.com/ethicalhack3r" href="http://www.twitter.com/ethicalhack3r">ethicalhack3r</a> from <a title="http://www.ethicalhack3r.co.uk/" href="http://www.ethicalhack3r.co.uk/">http://www.ethicalhack3r.co.uk/</a> created a repository of security podcasts that you an add to Boxee:</p>
<p><a href="http://www.ethicalhack3r.co.uk/2010/01/19/securitypodcasts-boxee-app/">http://www.ethicalhack3r.co.uk/2010/01/19/securitypodcasts-boxee-app/</a></p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6376290.xml</wfw:commentRss></item><item><title>DirChex</title><dc:creator>Rob Fuller</dc:creator><pubDate>Thu, 21 Jan 2010 17:00:01 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/1/21/dirchex.html</link><guid isPermaLink="false">438411:4906714:6376271</guid><description><![CDATA[<p>Web App assessors / auditors / pentesters would be good to know this tool. It takes a list of urls and slams it through a proxy, not waiting for a reply. Your intercepting proxy is what does the work after that.</p>
<p><a href="http://code.google.com/p/dirchex/">http://code.google.com/p/dirchex/</a></p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6376271.xml</wfw:commentRss></item><item><title>Prison Break &amp;ndash; The Metasploit Saga</title><dc:creator>Rob Fuller</dc:creator><pubDate>Thu, 21 Jan 2010 16:06:21 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/1/21/prison-break-ndash-the-metasploit-saga.html</link><guid isPermaLink="false">438411:4906714:6389995</guid><description><![CDATA[<p>A great video on using Metasploit and Meterpreter to beat the Prison Break challenge from EthicalHacker.net</p>  <p>Plus, check out his other great videos as well!</p>  <p>&#160;<object width="400" height="300"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=6830384&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=6830384&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"></embed></object></p>  <p><a href="http://vimeo.com/6830384">Metasploit meterpreter Windump/Winpcap sniffer</a> from <a href="http://vimeo.com/siles">siles</a> on <a href="http://vimeo.com">Vimeo</a>.</p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6389995.xml</wfw:commentRss></item><item><title>Winquisitor</title><dc:creator>Rob Fuller</dc:creator><pubDate>Wed, 20 Jan 2010 15:13:37 +0000</pubDate><link>http://www.room362.com/mubixlinks/2010/1/20/winquisitor.html</link><guid isPermaLink="false">438411:4906714:6376608</guid><description><![CDATA[<p>A pretty pimp tool that is written in vb script (IOW: great for meterpreter scripting &lt;/evillaugh&gt;)</p>  <p>The paper on it by it’s author can be found at:</p>  <p><a href="http://www.sans.org/reading_room/whitepapers/incident/rss/winquisitor_windows_information_gathering_tool_33258">SANS Reading Room: Whitepaper by Mike Cardosa</a></p>  <p>and you can download the tool here:</p>  <p><a href="http://www.winquisitor.org/download/">http://www.winquisitor.org/download/</a></p>]]></description><wfw:commentRss>http://www.room362.com/mubixlinks/rss-comments-entry-6376608.xml</wfw:commentRss></item></channel></rss>