<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>InfoSecPodcast.com &#187; Security Tools</title>
	<atom:link href="http://www.infosecpodcast.com/category/security/security-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecpodcast.com</link>
	<description>Information Security related news, opinions and ramblings</description>
	<pubDate>Thu, 03 Jul 2008 13:35:55 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Record IM video on the network?</title>
		<link>http://www.infosecpodcast.com/2008/07/record-im-video-on-the-network/</link>
		<comments>http://www.infosecpodcast.com/2008/07/record-im-video-on-the-network/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 15:23:03 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>

		<category><![CDATA[AIM video]]></category>

		<category><![CDATA[MSN Messenger]]></category>

		<category><![CDATA[record]]></category>
<category>AIM video</category><category>MSN Messenger</category><category>record</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/?p=183</guid>
		<description><![CDATA[A friend of mine is works in the financial services market. His company has a need to record Instant Messenger video sessions (think AOL and MSN webcam ) and archive them. They need to do this on the network as opposed to having client software do it locally on the desktop. This is due to [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Record+IM+video+on+the+network%3F&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2008%2F07%2Frecord-im-video-on-the-network%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>A friend of mine is works in the financial services market. His company has a need to record Instant Messenger video sessions (think AOL and MSN webcam ) and archive them. They need to do this on the network as opposed to having client software do it locally on the desktop. This is due to the varied desktop systems, only half are Windows based.</p>
<p>Anyone know of a commercial solution or open source libraries that could do this? I know many IPS&#8217; can detect IM video but he needs to record. Is IM video even encrypted? Before you start with the privacy concerns this is done with full knowledge of both parties who are also employees of the same company. It is a pilot program at this point.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/AIM+video" rel="tag"> AIM video</a>, <a href="http://technorati.com/tag/record" rel="tag"> record</a>, <a href="http://technorati.com/tag/MSN+Messenger" rel="tag"> MSN Messenger </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2008/07/record-im-video-on-the-network/feed/</wfw:commentRss>
		</item>
		<item>
		<title>RFP for PenTesting</title>
		<link>http://www.infosecpodcast.com/2007/07/rfp-for-pentesting/</link>
		<comments>http://www.infosecpodcast.com/2007/07/rfp-for-pentesting/#comments</comments>
		<pubDate>Wed, 11 Jul 2007 13:53:26 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2007/07/rfp-for-pentesting/</guid>
		<description><![CDATA[eWeek has a decent RFP template you can use when selecting a company to provide PenTest services. It&#8217;s not perfect but it is a great start if you have nothing. The RFP is on page 44 of the July9th issue.
If you happen to be looking for those services check out NMI InfoSecurity Solutions. They produce [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=RFP+for+PenTesting&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2007%2F07%2Frfp-for-pentesting%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.eweek.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.eweek.com');">eWeek</a> has a decent RFP template you can use when selecting a company to provide PenTest services. It&#8217;s not perfect but it is a great start if you have nothing. The RFP is on page 44 of the July9th issue.</p>
<p>If you happen to be looking for those services check out <a href="http://www.nmi.net" onclick="javascript:pageTracker._trackPageview ('/outbound/www.nmi.net');">NMI InfoSecurity Solutions</a>. They produce the best reports I have ever seen from a security services company. They also have a risk metric system (<a href="http://www.nmi.net/rsk.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.nmi.net');">RSK</a>) that makes it easy to track changes in your security risk level.</p>
<p>**Disclaimer**  Yes, I used to work for NMI and no I did not receive compensation for this plug <img src='http://www.infosecpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/eweek" rel="tag"> eweek</a>, <a href="http://technorati.com/tag/pentest" rel="tag"> pentest</a>, <a href="http://technorati.com/tag/rfp" rel="tag"> rfp</a>, <a href="http://technorati.com/tag/NMI" rel="tag"> NMI </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2007/07/rfp-for-pentesting/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Declassified window film stops wireless / cell signals</title>
		<link>http://www.infosecpodcast.com/2007/07/declassified-window-film-stops-wireless-cell-signals/</link>
		<comments>http://www.infosecpodcast.com/2007/07/declassified-window-film-stops-wireless-cell-signals/#comments</comments>
		<pubDate>Fri, 06 Jul 2007 14:50:16 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>
<category>cell phone</category><category>electromagnetic pulse</category><category>electronic communications</category><category>transmissions</category><category>us government</category><category>window film</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2007/07/declassified-window-film-stops-wireless-cell-signals/</guid>
		<description><![CDATA[I saw this one on Slashdot the other day  science.slashdot.org/article.pl?sid=07/07/03/0228246&#38;from=rss
Quote from article:
&#8220;Once manufactured under an exclusive contract with the US government, this  recently declassified window film is now available to the public. But don&#8217;t  expect to see it on store shelves anytime soon. Currently, it&#8217;s only available  directly from the manufacturer, [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Declassified+window+film+stops+wireless+%2F+cell+signals&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2007%2F07%2Fdeclassified-window-film-stops-wireless-cell-signals%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>I saw this one on Slashdot the other day  <a href="http://science.slashdot.org/article.pl?sid=07/07/03/0228246&amp;from=rss" title="http://science.slashdot.org/article.pl?sid=07/07/03/0228246&amp;from=rss" target="_blank">science.slashdot.org/article.pl?sid=07/07/03/0228246&amp;from=rss</a></p>
<p>Quote from article:</p>
<p><em>&#8220;Once manufactured under an exclusive contract with the US government, this  recently declassified window film is now available to the public. But don&#8217;t  expect to see it on store shelves anytime soon. Currently, it&#8217;s only available  directly from the manufacturer, and at prices that will likely make it  prohibitive for all but the wealthiest home owners. The two-millimeter-thick  coating can block Wi-Fi signals, cell phone transmissions, even the  near-infrared, yet is almost transparent&#8230; It can keep signals in (preventing  attempts to spy on electronic communications) or out, minimizing radio  interference and even the fabled electronics-destroying electromagnetic pulse  generated by a nuclear blast.&#8221; </em></p>
<p>Think of the applications. How much do you think that stuff costs per foot???</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/window+film" rel="tag"> window film</a>, <a href="http://technorati.com/tag/declassified" rel="tag"> declassified</a>, <a href="http://technorati.com/tag/wireless" rel="tag"> wireless</a>, <a href="http://technorati.com/tag/cellular" rel="tag"> cellular </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2007/07/declassified-window-film-stops-wireless-cell-signals/feed/</wfw:commentRss>
		</item>
		<item>
		<title>List of Malware Analysis tool from SANS</title>
		<link>http://www.infosecpodcast.com/2006/11/list-of-malware-analysis-tool-from-sans/</link>
		<comments>http://www.infosecpodcast.com/2006/11/list-of-malware-analysis-tool-from-sans/#comments</comments>
		<pubDate>Sat, 04 Nov 2006 03:07:23 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>
<category>analysis tools</category><category>malware</category><category>storm center</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/11/list-of-malware-analysis-tool-from-sans/</guid>
		<description><![CDATA[The Internet Storm Center at SANS has a post with a list of Malware Analysis tools submitted mostly by readers. If you are thinking about dissecting that piece of malware you just found, take a look at this list of helpers. Unless you do this a lot you&#8217;ve probably never heard of most of these [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=List+of+Malware+Analysis+tool+from+SANS&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F11%2Flist-of-malware-analysis-tool-from-sans%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://isc.sans.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/isc.sans.org');">The Internet Storm Center</a> at SANS has a post with a <a href="http://isc.sans.org/diary.php?storyid=1801" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/isc.sans.org');">list of Malware Analysis tools</a> submitted mostly by readers. If you are thinking about dissecting that piece of malware you just found, take a look at this list of helpers. Unless you do this a lot you&#8217;ve probably never heard of most of these tools.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/SANS" rel="tag"> SANS</a>, <a href="http://technorati.com/tag/Malware" rel="tag"> Malware</a>, <a href="http://technorati.com/tag/Internet+Storm+Center" rel="tag"> Internet Storm Center </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/11/list-of-malware-analysis-tool-from-sans/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Malware Analyzing Sandbox</title>
		<link>http://www.infosecpodcast.com/2006/11/malware-analyzing-sandbox/</link>
		<comments>http://www.infosecpodcast.com/2006/11/malware-analyzing-sandbox/#comments</comments>
		<pubDate>Sat, 04 Nov 2006 02:47:44 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/11/malware-analyzing-sandbox/</guid>
		<description><![CDATA[The clever folks over at Sunbelt Software have created a great free service to analyze malware samples called CWSandbox. How it works is you upload your suspected malware sample to their site. The CWSandbox then runs the malware and gives you a detailed report of what it did, it&#8217;s name if known, and a bunch [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Malware+Analyzing+Sandbox&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F11%2Fmalware-analyzing-sandbox%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>The clever folks over at <a href="http://www.sunbelt-software.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.sunbelt-software.com');">Sunbelt Software</a> have created a great free service to analyze malware samples called <a href="http://www.sunbelt-software.com/Sunbelt-CWSandbox.cfm" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.sunbelt-software.com');">CWSandbox</a>. How it works is you upload your suspected malware sample to their site. The CWSandbox then runs the malware and gives you a detailed report of what it did, it&#8217;s name if known, and a bunch of other cool information.</p>
<p>I found a post on <a href="http://blog.ncircle.com/archives/2006/10/cwsandbox_revie.htm" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/blog.ncircle.com');">nCircle&#8217;s blog</a> that has a pretty detailed description of this tool. The next time you have a strange ZIP attachment upload it and see what CWSandbox says.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/CWSandbox" rel="tag"> CWSandbox</a>, <a href="http://technorati.com/tag/Malware" rel="tag"> Malware</a>, <a href="http://technorati.com/tag/Sunbelt+Software" rel="tag"> Sunbelt Software</a>, <a href="http://technorati.com/tag/nCircle" rel="tag"> nCircle </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/11/malware-analyzing-sandbox/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Free Windows Honeypot from NetVigilance</title>
		<link>http://www.infosecpodcast.com/2006/11/free-windows-honeypot-from-netvigilance/</link>
		<comments>http://www.infosecpodcast.com/2006/11/free-windows-honeypot-from-netvigilance/#comments</comments>
		<pubDate>Thu, 02 Nov 2006 18:12:21 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/11/free-windows-honeypot-from-netvigilance/</guid>
		<description><![CDATA[VA provider NetVigilance has released a free Honeypot for Windows called WinHoneyd. It is a low-interaction (it simulates services such as RPC, HTTP, FTP, etc.) honeypot based on the Open Source honeyd software written by Niels Provos. Instructions, sample configs and FAQ&#8217;s can be found on the NetVigilance site.
&#8211;Chris
Technorati Tags:  WinHoneyd,  honeypot,  [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Free+Windows+Honeypot+from+NetVigilance&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F11%2Ffree-windows-honeypot-from-netvigilance%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>VA provider <a href="http://www.netvigilance.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.netvigilance.com');">NetVigilance</a> has released a free Honeypot for Windows called <a href="http://www.netvigilance.com/winhoneyd" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.netvigilance.com');">WinHoneyd</a>. It is a low-interaction (it simulates services such as RPC, HTTP, FTP, etc.) honeypot based on the Open Source <a href="http://www.honeyd.org/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.honeyd.org');">honeyd</a> software written by Niels Provos. Instructions, sample configs and FAQ&#8217;s can be found on the NetVigilance site.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/WinHoneyd" rel="tag"> WinHoneyd</a>, <a href="http://technorati.com/tag/honeypot" rel="tag"> honeypot</a>, <a href="http://technorati.com/tag/netvigilance" rel="tag"> netvigilance</a>, <a href="http://technorati.com/tag/Niels+Provos" rel="tag"> Niels Provos</a>, <a href="http://technorati.com/tag/honeyd" rel="tag"> honeyd </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/11/free-windows-honeypot-from-netvigilance/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ajax based port scanner</title>
		<link>http://www.infosecpodcast.com/2006/10/ajax-based-port-scanner/</link>
		<comments>http://www.infosecpodcast.com/2006/10/ajax-based-port-scanner/#comments</comments>
		<pubDate>Fri, 27 Oct 2006 14:41:39 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>
<category>acl</category><category>ajax</category><category>firewall</category><category>nmap</category><category>port scanner</category><category>security tools</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/10/ajax-based-port-scanner/</guid>
		<description><![CDATA[In the &#8220;WEB 2.0&#8243; world we live in it was a matter of time before Ajax security tools showed up. Ener OPScanner, an Ajax based port scanner. I definitely wouldn&#8217;t start making plans to replace NMAP with it. It&#8217;s more a novelty and a useful way to can yourself when making basic firewall or ACL [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Ajax+based+port+scanner&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F10%2Fajax-based-port-scanner%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>In the &#8220;WEB 2.0&#8243; world we live in it was a matter of time before Ajax security tools showed up. Ener<a href="http://labs.programming-designs.com/portscanner/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/labs.programming-designs.com');"> OPScanner</a>, an Ajax based port scanner. I definitely wouldn&#8217;t start making plans to replace NMAP with it. It&#8217;s more a novelty and a useful way to can yourself when making basic firewall or ACL changes.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/Ajax" rel="tag"> Ajax</a>, <a href="http://technorati.com/tag/port+scanner" rel="tag"> port scanner</a>, <a href="http://technorati.com/tag/security" rel="tag"> security </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/10/ajax-based-port-scanner/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Web based VMX file creator</title>
		<link>http://www.infosecpodcast.com/2006/10/web-based-vmx-file-creator/</link>
		<comments>http://www.infosecpodcast.com/2006/10/web-based-vmx-file-creator/#comments</comments>
		<pubDate>Wed, 18 Oct 2006 11:35:20 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/10/web-based-vmx-file-creator/</guid>
		<description><![CDATA[If you do any sort of sandbox / Honyepot work like me you probably use VMWare Virtual Machines. When you create a VM the configuration settings are saved in a file with the .vmx extension. This file is a simple text file with name value pairs. Mike over at MikeTechShow.com posted a link to EasyVMX, [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Web+based+VMX+file+creator&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F10%2Fweb-based-vmx-file-creator%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>If you do any sort of sandbox / Honyepot work like me you probably use <a href="http://www.vmware.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.vmware.com');">VMWare</a> Virtual Machines. When you create a VM the configuration settings are saved in a file with the .vmx extension. This file is a simple text file with name value pairs. Mike over at <a href="http://www.miketechshow.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.miketechshow.com');">MikeTechShow.com</a> posted a link to <a href="http://www.easyvmx.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.easyvmx.com');">EasyVMX</a>, which is a web based vmx configuration file creator. If you are looking for something more than just the VMWare VM creation wizard you should check this out.</p>
<p>&#8211;Chris</p>
<div style="margin: 0px; padding: 0px; display: inline" id="0767317B-992E-4b12-91E0-4F059A8CECA8:2f206d02-baf8-4da9-bfe4-4d8d3bbd8c05" class="wlWriterSmartContent">Technorati tags: <a href="http://technorati.com/tags/VMWare" rel="tag" onclick="javascript:pageTracker._trackPageview ('/outbound/technorati.com');">VMWare</a>, <a href="http://technorati.com/tags/Miketechshow" rel="tag" onclick="javascript:pageTracker._trackPageview ('/outbound/technorati.com');">Miketechshow</a>, <a href="http://technorati.com/tags/easyvmx" rel="tag" onclick="javascript:pageTracker._trackPageview ('/outbound/technorati.com');">easyvmx</a>, <a href="http://technorati.com/tags/vmx" rel="tag" onclick="javascript:pageTracker._trackPageview ('/outbound/technorati.com');">vmx</a></div>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/10/web-based-vmx-file-creator/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bootable Linux security distros</title>
		<link>http://www.infosecpodcast.com/2006/09/bootable-linux-security-distros/</link>
		<comments>http://www.infosecpodcast.com/2006/09/bootable-linux-security-distros/#comments</comments>
		<pubDate>Wed, 27 Sep 2006 02:47:13 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>
<category>darknet</category><category>forensics</category><category>hard drive</category><category>knoppix</category><category>linux distributions</category><category>linux distro</category><category>nsm</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/09/bootable-linux-security-distros/</guid>
		<description><![CDATA[Darknet.org.uk has a pretty good list of Linux distributions that are geared to security tasks like pentesting, forensics and nsm. The good thing about this list is that these are Live CD&#8217;s. This means you can drop them into your CD a boot into a working Linux distro without affecting the currently installed operating system. [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Bootable+Linux+security+distros&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F09%2Fbootable-linux-security-distros%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://Darknet.org" title="http://Darknet.org" target="_blank">Darknet.org</a>.uk has a <a href="http://www.darknet.org.uk/2006/03/10-best-security-live-cd-distros-pen-test-forensics-recovery/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.darknet.org.uk');">pretty good list</a> of Linux distributions that are geared to security tasks like pentesting, forensics and nsm. The good thing about this list is that these are Live CD&#8217;s. This means you can drop them into your CD a boot into a working Linux distro without affecting the currently installed operating system. Most do have to option for a complete hard drive install should you wish.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/Darknet" rel="tag"> Darknet</a>, <a href="http://technorati.com/tag/Linux" rel="tag"> Linux</a>, <a href="http://technorati.com/tag/Live+CD" rel="tag"> Live CD</a>, <a href="http://technorati.com/tag/security" rel="tag"> security</a>, <a href="http://technorati.com/tag/whax" rel="tag"> whax</a>, <a href="http://technorati.com/tag/knoppix+std" rel="tag"> knoppix std</a>, <a href="http://technorati.com/tag/f.i.r.e" rel="tag"> f.i.r.e </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/09/bootable-linux-security-distros/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is that website safe?</title>
		<link>http://www.infosecpodcast.com/2006/09/is-that-website-safe/</link>
		<comments>http://www.infosecpodcast.com/2006/09/is-that-website-safe/#comments</comments>
		<pubDate>Tue, 12 Sep 2006 21:36:00 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Security Tools]]></category>
<category>firefox browser</category><category>google search</category><category>internet explorer</category><category>malicious content</category><category>malware</category><category>mcafee</category><category>vint cerf</category><category>vlan</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/security-tools/2006/09/is-that-website-safe/</guid>
		<description><![CDATA[When we click on a hyperlink we really have no idea if the site on the other end is safe. When I go there will I find spyware, a virus infected file, a browser exploit&#8230;who knows? I&#8217;m pretty paranoid when I &#8220;surf&#8221; the web. Anytime I go adventuring on the web I am doing it [...]<p><a href="http://sharethis.com/item?&#038;wp=2.6&#38;publisher=650110b1-7c6f-41ed-87c1-3d53bdd4b3de&#38;title=Is+that+website+safe%3F&#38;url=http%3A%2F%2Fwww.infosecpodcast.com%2F2006%2F09%2Fis-that-website-safe%2F">ShareThis</a></p>]]></description>
			<content:encoded><![CDATA[<p>When we click on a hyperlink we really have no idea if the site on the other end is safe. When I go there will I find spyware, a virus infected file, a browser exploit&#8230;who knows? I&#8217;m pretty paranoid when I &#8220;surf&#8221; the web. Anytime I go adventuring on the web I am doing it thru a Firefox browser running on a Link Virtual Machine. To take a step further, the VM is connected to an access point in it&#8217;s own VLAN. So if it does get p0wned it can&#8217;t do any damage on my internal network. Yes, this is my home network <img src='http://www.infosecpodcast.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>LinkScanner</strong><br />
I saw this <a href="http://blog.washingtonpost.com/securityfix/2006/09/scan_those_links_before_visiti.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/blog.washingtonpost.com');">post</a> by Brian Krebs who writes on Security for the Washington Post. If you don&#8217;t follow his column you should. Brian mentions a site called <a href="http://linkscanner.explabs.com/linkscanner/default.asp" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/linkscanner.explabs.com');">LinkScanner</a> from <a href="http://www.exploitlabs.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.exploitlabs.com');">Exploit Labs</a>. LinkScanner allows you to enter a URL and it will check to see if there are any nasty things hiding there. I&#8217;ve been using this site for a while and it has alerted me of a couple sites with malware.</p>
<p><strong>McAfee Site Advisor<br />
</strong>McAfee offers the <a href="http://www.siteadvisor.com/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.siteadvisor.com');">Site Advisor</a> service to determine if a website has malicious content. They use a Red / Yellow / Green color scheme to visualize if a site is Bad, Unknown, or Good.  If you happen to use Internet Explorer they have a plugin that will display the Site Advisor rating of the page you are on in the lower right of the browser. I&#8217;ve used SA quite a bit and it seems to be a solid tool.</p>
<p><strong>Dr. Web</strong><br />
The Russian AV company <a href="http://www.freedrweb.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.freedrweb.com');">Dr. Web</a> has released <a href="http://www.freedrweb.com/browser/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.freedrweb.com');">browser plugins</a> for Firefox, IE and Opera. These plugins allow you to scan a site for malware before visiting it. Right clicking on a link gives you the option to scan it for malware. I have not had a chance to use their tools yet so I can&#8217;t vouch for their quality.</p>
<p><strong>Google<br />
</strong>When you click on a link from a <a href="http://www.google.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.google.com');">Google</a> search (or cache I think?), a warning page will be displayed if the site is determinted to have malicious content. This is possble through a partnership with <a href="http://www.stopbadware.org" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.stopbadware.org');">www.stopbadware.org</a>.   Several prominent people including Vint Cerf and Ari Schwartz are involved with <a href="http://StopBadware.org" title="http://StopBadware.org" target="_blank">StopBadware.org</a>.</p>
<p>There are probably other I have missed. If you know of any please let me know and I will post them here.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/SiteScanner" rel="tag"> SiteScanner</a>, <a href="http://technorati.com/tag/Malware" rel="tag"> Malware</a>, <a href="http://technorati.com/tag/spyware" rel="tag"> spyware</a>, <a href="http://technorati.com/tag/Site+Advisor" rel="tag"> Site Advisor</a>, <a href="http://technorati.com/tag/Exploit+Labs" rel="tag"> Exploit Labs </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/09/is-that-website-safe/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.063 seconds -->
