<?xml version="1.0" encoding="UTF-8"?>
<!--Generated by Squarespace Site Server v5.9.2 (http://www.squarespace.com/) on Thu, 11 Mar 2010 17:56:35 GMT--><rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:rss="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:cc="http://web.resource.org/cc/"><rss:channel rdf:about="http://www.penetrationtester.com/blog/"><rss:title>Blog</rss:title><rss:link>http://www.penetrationtester.com/blog/</rss:link><rss:description></rss:description><dc:language>en-US</dc:language><dc:date>2010-03-11T17:56:35Z</dc:date><admin:generatorAgent rdf:resource="http://www.squarespace.com/">Squarespace Site Server v5.9.2 (http://www.squarespace.com/)</admin:generatorAgent><rss:items><rdf:Seq><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2010/2/2/7-tips-for-small-business-it-security.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2009/6/2/onwards.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2009/4/30/nmap-scanning-past-watchguard-firewalls.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/11/3/risky-business-podcast-85.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/9/30/cisco-ip-phone-7936-default-passwords.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/8/31/being-an-infosec-professional-and-having-pci-knowledge-is-so.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/7/18/telstras-crap-customer-service-for-the-iphone.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/7/18/loosing-faith-in-pci-enforcement.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/7/18/now-a-pci-dss-qsa.html"/><rdf:li rdf:resource="http://www.penetrationtester.com/blog/2008/7/1/finding-credit-card-data-for-pci-compliance-work.html"/></rdf:Seq></rss:items></rss:channel><rss:item rdf:about="http://www.penetrationtester.com/blog/2010/2/2/7-tips-for-small-business-it-security.html"><rss:title>7 Tips for Small Business IT Security</rss:title><rss:link>http://www.penetrationtester.com/blog/2010/2/2/7-tips-for-small-business-it-security.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2010-02-02T20:33:52Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>As on ABC Radio when I was interviewed along with <a href="http://www.suretegroup.com.au">Alastair MacGibbon</a>&nbsp;on IT Security, I mentioned several resources and key tasks to ensure you maintain a good level of security for your organisation or family PC. Here is a quick summary and a list of resources.</p>
<ul>
<li>Passwords   
<ul>
<li>Weak password selection by users is still the most common way to compromise and organisation. Choose a phrase and use the first letter from each word as your password. And add symbol at the end i.e @yourpasswordvaluehere!</li>
</ul>
</li>
</ul>
<ul>
<li>Protecting your system from Malware;    
<ul>
<li>There are several good solutions some are even free my preferences are my pick of the free is <a href="http://free.avg.com/au-en/download-avg-anti-virus-free">AVG</a> offering.</li>
<li>The commercial offerings are always battling it out it the reviews and some shine above others. <a href="http://www.sophos.com">Sophos</a> is something I often see in the field doing a good job IMHO.</li>
<li>When selecting an antivirus or these days malware protection look for something that protects all of your online activity&nbsp; (Email, Web Browsing and Social Media)</li>
</ul>
</li>
</ul>
<ul>
<li>Patch your software;   
<ul>
<li>Windows users are often compromised due to lack of updating your software. The windows OS makes use of the built in software update process which should be set to Automatic.</li>
<li>Third party software also needs to be regularly updated not sure if your it's up to date? Try using <a href="http://secunia.com/vulnerability_scanning/personal/">a free online tool from Secunia</a> to check if there are any vulnerabilities for the software on your machine.</li>
</ul>
</li>
</ul>
<ul>
<li>Data Encryption    
<ul>
<li>Windows Encryption tools are very effective against casual attackers. There has been encryption in windows for many years all seamless to the enduser. Windows 7 and Vista have the Bitlocker tool which is simple to very simple to enable.</li>
</ul>
</li>
</ul>
<ul>
<li>Firewalls   
<ul>
<li>Are you concerned you might have some services exposed to the internet perform a quick free scan at the <a href="https://www.grc.com/x/ne.dll?bh0bkyd2">Shields up</a> website and discover which ports are open.</li>
<li>If your organisation is starting to look at something more than just a ADSL modem between you and the internet or you need more control on activities your employees are performing online then an entry level firewall will assist. They often do many if not all of the tasks of the corporate big boys without the need for costly staff or $$$. My recommendation for ease of use and features is the <a href="http://www.watchguard.com/">Watchguard</a> range of systems.</li>
</ul>
</li>
</ul>
<ul>
<li>Online/Social Media   
<ul>
<li>The benefits of using facebook, myspace, linkedin and other social media sites to promote your business or catch up with friends and family is wonderful. But as online criminals increase there attack vectors be conscious of what you post online. My advice is don't post anything online that you are not prepared to pin to your letter box at the front of you house.</li>
</ul>
</li>
</ul>
<ul>
<li>Outsource   
<ul>
<li>If you are about to set up online but don't have the time or money to buy the right equipment or hire staff of consultants (Like myself). Consider looking at <a href="http://www.rackspace.com">Rackspace</a> who provide online virtual servers which you can get full access to and consult there excellent support staff.</li>
</ul>
</li>
</ul>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2009/6/2/onwards.html"><rss:title>Onwards</rss:title><rss:link>http://www.penetrationtester.com/blog/2009/6/2/onwards.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2009-06-03T02:29:02Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p><span class="text">I left Pure Hacking yesterday after 2.5 years I had a great time but it is now onwards and upwards as the Director of <a href="http://www.hacklabs.com">HackLabs</a>. HackLabs is a new boutique <a href="http://www.hacklabs.com">penetration testing</a> company looking forward to making a significant impact on the industry.</span></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2009/4/30/nmap-scanning-past-watchguard-firewalls.html"><rss:title>Nmap Scanning past Watchguard Firewalls</rss:title><rss:link>http://www.penetrationtester.com/blog/2009/4/30/nmap-scanning-past-watchguard-firewalls.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2009-04-30T10:51:50Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>I come up against Watchguard Firewalls and these little guys and they are not bad little firewalls for the small to medium size organisations. This is mostly because they have quite a bit enabled by default. One of them is the port scan detection module which locks any IPs when it detects a port scan. One of the problems for pen testers is that it does not have a whitelist so for a client it's either on or off.</p><p>When you are performing an infrastructure penetration testing its important to get good reliable port scans. So often we ask customers to turn it off to ensure we capture every open port as often we don't have the luxury of time to allow us to run slow scans to bypass the detection rules. As clients who run Watchguard only have the option of on or off it will most often remain enabled and force the tester to do a slow scan.</p><p>After playing with a few different timings to get the best result I found against the default Watchguard settings was the following nmap command to get them done the quickest but without getting my IP blacklisted.</p><p><em>nmap -sS -iL targetlist.txt -P0 -sV -T4</em></p><p>When done with a full port range (-p1-65535) on four IP's it takes 1000 seconds to complete. The -T4 option is the time setting, T1 is the slowest.</p><p><em><br /></em></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/11/3/risky-business-podcast-85.html"><rss:title>Risky Business Podcast #85</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/11/3/risky-business-podcast-85.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-11-03T01:21:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>I was listening to the the Risky Business podcast this morning (by the way thanks Patrick you do a great job putting the show together). In episode 85 (http://itradio.com.au/?p=206) Patrick talks to one of his sponsors and legendary security expert Marcus Ranum. Old Marcus has some funny views on pen testing and I think they are slightly missing the mark.</p><br/><p>Marcus believes that tools such as CORE Impact and Metasploit are not a good idea as it makes a pen tester lazy (If I could generalise his comments to mean that). The things were left out which are an argument as to why tools such as the above are needed and why pen testing is still a valuable exercise are illustrated by the following points;</p><br/><p>1. A pen test is not just exploitation of devices ! A pen test is about using the technical access you gain to gather business sensitive information to highlight the risk of weak IT Security controls. It's not about just getting the access !!!! Whilst the tech's in the target organisation understand the impact. It's about highlighting the business impact should someone malicious exploit the same vulnerability and attempt to extract sensitive business information or disrupt operations, this is what senior management are interested in.</p><br/><p>2. The tools that assist a penetration tester such as CORE Impact and Metasploit are only as good as the person driving them. CORE Impact whilst having a automated wizard is handy but the manual process is required to get complete coverage. The reason customers like this tool being used is that it has great logging and reporting of all actions taken. Also as a tester when you are finished all you have to do is select cleanup and it removes all the agents (control modules you have installed whilst you have been exploiting systems). Once again great to show compromised hosts but unless you link these to business risk it's not that good for the customer. (Disclosure: Pure Hacking are re-sellers for CORE Impact)</p><br/><p>3. Coverage - The old problem with any consulting job is time and with a pen test time is always limited. Customers might not want to dedicate much time to the assessment but still expect a tester to find all the holes ! That is obviously a tough job, with scanning tools at least you get coverage of the target environment and whilst it's working away you focus on the other manual tasks of the test.</p><br/><p>4. The win or Loose scenario for a pen testers. This is not something we are too concerned about it's great to compromise a customer network and illustrate a security attack vector that they had not though of. But we still get paid even if we don't find any security weaknesses. In saying that however there are always security controls that can be strengthened to help reduce the risk a environment is exposed to.</p><br/><p>5. Secondly both tools have very limited Web Application security support and the shift to Web Application security testing has been very significant in the last 3 years. Most pen testing I perform (70%) is now on Web Applications.</p><br/><p>Happy to hear constructive thoughts on my post.</p><p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/9/30/cisco-ip-phone-7936-default-passwords.html"><rss:title>Cisco IP Phone 7936 Default Passwords</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/9/30/cisco-ip-phone-7936-default-passwords.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-09-30T06:02:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>Found it hard to find some of this info so thought I'd mention it my blog for fellow hackers/ Pen testers.</p><br/><p>Passwords for the Cisco IP Phone 7936;</p><br/><p>User Level Access @ Web interface: 7936</p><br/><p>Admin Level Access @ Web Interface:**#</p><br/><p>No actual username is required ! and after doing a bit of research it turns out if you change the accounts the rightful owner has no mechanism to change them back. If you thought a re-flash might be the answer the device requires administrator access to perform that function! So there is no mechanism to reset to factory defaults without admin access! There are a few stories of bricked phones as a result !</p><p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/8/31/being-an-infosec-professional-and-having-pci-knowledge-is-so.html"><rss:title>Being an infosec professional and having PCI knowledge is sometimes a curse</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/8/31/being-an-infosec-professional-and-having-pci-knowledge-is-so.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-08-31T00:52:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>One of the curse's of being an infosec professional has always been a healthy dose of paranoia. However this is often compounded by knowing the rules that people have to follow. Today I noted two really bad practices.</p><p></p><p>1.) The privacy laws in Sydney one are crap and two are not really followed but today I saw a great example of something to be scared of. I was in Kings Cross (Shopping I might add accompanied by my wife before you ask). We entered the swans club and as we are out of the 5km radius which allows us to enter as visitors we just have to prove it with photo ID. This is something we are all accustomed with. But when my wife gave it to them before you could say boo they scanned it and printed a "visitor pass" wtf?</p><p></p><p>Did they just take an electronic copy of my wife's drivers license ? Where is that stored ? How long do they keep it ? what do they use it for ? How do they dispose of the data when at end of life ?</p><p></p><p>There was no point going into a conversation with the burly front guy about his data security management plan so another potential risk to us a family...</p><p></p><p>2.) Then after a nice meal and a few czech beers I went to pay. I payed by visa and went to sign for the goods she checked my signature (could not speak english) her boss a guy who looked liked he'd worked in the cross for about 50 years next to her. She then proceed to ask me where on my visa was my security code (CVV2) I explained there but why and she wen to write it down !! Whoa sorry not letting you write that down.</p><p></p><p>The boss gave me a steely scare as I explained that was not required and not a practice merchants needed to use. He said it was good for him ... I'm sure it was given the dodgy area but I was not going to let them so I whipped my card away. The stare from the ex-croatian war vet was very chilling best I leave my PCI speech / best practices speech on this guy for another day ;-).</p><p></p><p>It's tough being a infosec professional ...</p><p></p><p></p><p></p><p></p><p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/7/18/telstras-crap-customer-service-for-the-iphone.html"><rss:title>Telstra's crap customer service for the iPhone</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/7/18/telstras-crap-customer-service-for-the-iphone.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-07-18T04:13:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>A week of waiting, 10 calls, many hours on, hold still don't have my iphone unlocked! I bought it outright so i could use on any carrier and then rang the magic number to get it unlocked to any carrier 1800 782 489.</p><br/><p>Rang them on Monday no joy. Received a call Tuesday from customer service section saying that they were waiting on Apple. Now a week later and many calls to telstra today I got fobbed off by saying that I had to follow the instructions on the apple site and that my IMEI had been logged with Apple as being unlocked and that I would have to do something my end to complete it ?</p><br/><p>Wtf ? So I asked what that was and telstra customer support did not know and then the said look it up in the documentation supplied with the phone. Jeez so I doubled checked everything looked at the web site and left yet another message for the person dealing with my unlocking request.</p><br/><p>No answer once again. Waiting ..</p><br/><p></p><p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/7/18/loosing-faith-in-pci-enforcement.html"><rss:title>Loosing faith in PCI enforcement</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/7/18/loosing-faith-in-pci-enforcement.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-07-18T01:36:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>Whilst PCI-DSS is mandatory for compliance when an organisation processes, transmits and stores Credit Card data. It is up to the acquirer (the banks) to enforce the merchants (businesses taking CC transactions) to measure the compliance against PCI-DSS. This information is then passed on to the card brands as a report on the status of compliance of it's merchants against the standard.</p><br/><p>The reason I have lost some faith as it became known to me that one large organisation doing millions of CC transactions who are not PCI compliant choose to pay the fines instead of ensuring they comply with the standard as it was cheaper in the short term.</p><br/><p>What is the cost of non-compliance fine well don't forget the acquirer decides this but one customer is only fined $20,000 a year. Which for them is a very very small amount compared to the revenue they are making from taking CC transactions.</p><br/><p>Lets hope these fines increase to the point where security actually starts getting some real attention by C-Levels.</p><p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/7/18/now-a-pci-dss-qsa.html"><rss:title>Now a PCI-DSS QSA !</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/7/18/now-a-pci-dss-qsa.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-07-18T01:25:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>I did the exam and training two weeks ago and got the results of passing yesterday. Now I'm armed and dangerous ;-)</p><p></p>]]></content:encoded></rss:item><rss:item rdf:about="http://www.penetrationtester.com/blog/2008/7/1/finding-credit-card-data-for-pci-compliance-work.html"><rss:title>Finding Credit Card Data for PCI Compliance Work</rss:title><rss:link>http://www.penetrationtester.com/blog/2008/7/1/finding-credit-card-data-for-pci-compliance-work.html</rss:link><dc:creator>Chris Gatford</dc:creator><dc:date>2008-07-01T11:24:00Z</dc:date><dc:subject></dc:subject><content:encoded><![CDATA[<p>During a PCI Audit compliance piece of work, you are as a QSA required to verify that various types CC sensitive data are not stored period. Although some types are permitted i.e. PAN (CC Number) and the expiry date as long as they are "protected". Well as someone with audit experience you know you won't get a truthful or comprehensive answer from the customer being audited. Often they don't know the entire process or they know that there might be "grey"areas.</p><br/><p>So you have to test portions of the environment this is tricky at best. There are some tools however to help you find sensitive data in the environment;</p><br/><p>https://source.its.utexas.edu/groups/its-iso/projects/senf/</p><br/><p>http://www.hackaday.com/2008/06/20/finding-sensitive-data-with-freeware/</p><p></p>]]></content:encoded></rss:item></rdf:RDF>