<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>EnableSecurity</title>
	<atom:link href="http://enablesecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://enablesecurity.com</link>
	<description>Security Consultancy, Research and Development</description>
	<lastBuildDate>Tue, 01 Jun 2010 11:10:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='enablesecurity.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/277c71575ac661f2e6c6c304e5db39a3?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>EnableSecurity</title>
		<link>http://enablesecurity.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://enablesecurity.com/osd.xml" title="EnableSecurity" />
	<atom:link rel='hub' href='http://enablesecurity.com/?pushpress=hub'/>
		<item>
		<title>Using XSS to switch off dotDefender 4.0</title>
		<link>http://enablesecurity.com/2010/06/01/using-xss-to-switch-off-dotdefender-4-0/</link>
		<comments>http://enablesecurity.com/2010/06/01/using-xss-to-switch-off-dotdefender-4-0/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 11:10:43 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=409</guid>
		<description><![CDATA[AppliCure&#8217;s dotDefender version 4.0 had a security flaw in the log viewing feature of the administrative interface. We just published an advisory for this vulnerability. Here&#8217;s the interesting part: &#8220;The log viewer facility in dotDefender does not properly htmlencode user supplied input. This leads to a cross site scripting vulnerability when the log viewer displays [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=409&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>AppliCure&#8217;s dotDefender version 4.0 had a security flaw in the log viewing feature of the administrative interface. We just <a href="http://resources.enablesecurity.com/advisories/ES-20100601-dotdefender4.txt" target="_blank">published an advisory</a> for this vulnerability. Here&#8217;s the interesting part:</p>
<blockquote><p><em>&#8220;The log viewer facility in dotDefender does not properly htmlencode user supplied input. This leads to a cross site scripting vulnerability when the log viewer displays HTTP headers.&#8221;</em></p></blockquote>
<p>The following video shows how an attacker can make use of cross site scripting to get the system administrator to automatically switch off dotDefender. This effectively disables the WAF, leaving the web application exposed to any attacks that said WAF was supposed to protect against.</p>
<p>Advisory: <a href="http://resources.enablesecurity.com/advisories/ES-20100601-dotdefender4.txt" target="_blank">ES-20100601</a></p>
<p>Video demo: <a href="http://vimeo.com/12132622" target="_blank">http://vimeo.com/12132622</a></p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=12132622&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=12132622&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
	<param name="wmode" value="opaque" />
</object>
</span></p>
<p><strong>FAQ</strong></p>
<p><em>But doesn&#8217;t the attacker need to reach the administrator  interface?</em></p>
<p>Nope &#8211; its the administrator&#8217;s authenticated web browser that disables the WAF due to the injected javascript.  Therefore the attacker just needs to reach the website protected by the  WAF.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/409/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/409/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/409/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=409&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2010/06/01/using-xss-to-switch-off-dotdefender-4-0/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>VOIPPACK update for February 2010 brings faster VoIP cracking and destruction</title>
		<link>http://enablesecurity.com/2010/02/16/voippack-update-for-february-2010-brings-faster-voip-cracking-and-destruction/</link>
		<comments>http://enablesecurity.com/2010/02/16/voippack-update-for-february-2010-brings-faster-voip-cracking-and-destruction/#comments</comments>
		<pubDate>Tue, 16 Feb 2010 13:30:40 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=383</guid>
		<description><![CDATA[So it&#8217;s time to issue an update to VOIPPACK, with some new goodies! This update includes two new tools called &#8220;bypassalwaysreject&#8221; and &#8220;sipopenrelay&#8221; DoS exploits for Asterisk PBX called &#8220;asteriskdiscomfort&#8221;, &#8220;asterisksscanfdos&#8221; and &#8220;iax2resourceexhaust&#8221; Generic DoS exploit &#8220;sipinviteflood&#8221; Optimizations for the SIP Digest leak tool &#8220;sipdigestleak&#8221; and the SIP digest cracker What does &#8220;bypassalwaysreject&#8221; do? Asterisk [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=383&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>So it&#8217;s time to issue an update to VOIPPACK, with some new goodies!</p>
<p>This update includes</p>
<ul>
<li> two new tools called &#8220;bypassalwaysreject&#8221; and &#8220;sipopenrelay&#8221;</li>
<li>DoS exploits for Asterisk PBX called &#8220;asteriskdiscomfort&#8221;, &#8220;asterisksscanfdos&#8221; and &#8220;iax2resourceexhaust&#8221;</li>
<li>Generic DoS exploit &#8220;sipinviteflood&#8221;</li>
<li>Optimizations for the SIP Digest leak tool &#8220;sipdigestleak&#8221; and the SIP digest cracker</li>
</ul>
<p><strong>What does &#8220;bypassalwaysreject&#8221; do?</strong></p>
<p>Asterisk PBX had introduced a new option &#8220;alwaysauthreject&#8221; which disables traditional enumeration of extensions. This tool makes use of an undisclosed method of enumerating extensions which works on Asterisk as of at least Asterisk 1.6.2.1 (and possibly the latest version too).</p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=9398873&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=9398873&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
	<param name="wmode" value="opaque" />
</object>
</span></p>
<p><strong>What does &#8220;sipopenrelay&#8221; do?</strong></p>
<p>This new tool tries to find misconfigured dialplans or ACLs by calling (sending INVITE messages) a specific phone number with different prefixes. This emulates current attack trends on the SIP front as described in <a href="http://blog.sipvicious.org/2010/02/rtp-traffic-to-1111.html" target="_blank">various</a> blog <a href="http://www.usken.no/2010/02/sip-scanning-causes-ddos-on-ip-1-1-1-1/" target="_blank">posts</a>.The result would be free calls which indicate the possibility of toll fraud.</p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=9408508&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=9408508&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
	<param name="wmode" value="opaque" />
</object>
</span></p>
<p><strong>What about the new DoS tools?</strong></p>
<p>Asterisk Discomfort exploits a DoS vulnerability that was fixed in AST-2009-010. The vulnerability lies in parsing of RTP comfort noise stream. The result is that Asterisk PBX crashes.</p>
<p>Asterisk SSCANF DoS exploits AST-2009-005 which has the result of crashing Asterisk PBX.</p>
<p>Invite Flood tool exploits a DoS found in various endpoints and PBX servers. It sends a large number of INVITE messages, initiating lots of calls and eventually causing either a crash or the application to hang.</p>
<p>IAX2 Resource exhaust is a DoS vulnerability that was fixed in AST-2009-006 and exploited a design flaw in the IAX2 protocol, in some ways similar to INVITE flood DoS. The result is that Asterisk starts taking too much resources, becoming unresponsive. Sometimes it crashes.</p>
<p><strong>And the enhancements?</strong></p>
<p>SIP Digest Leak tool and it&#8217;s sister Digest cracker have both been updated to support two new features.</p>
<ol>
<li>Zerolen SDP option in SIP Digest Leak means that when some SIP endpoints pick up the call, they send a hangup immediately. This cuts the waiting time for the attacker and immediately gives him/her the challenge response.</li>
<li>Support for using <a href="http://www.openwall.com/john/" target="_blank">John the Ripper</a> as an external tool to crack Digest passwords. The jumbo patch needs to be applied to John the ripper &#8211; I&#8217;ll be posting on how to do this later on.</li>
</ol>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=9390043&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=9390043&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
	<param name="wmode" value="opaque" />
</object>
</span></p>
<p>That is all for now, hope you enjoy the update. For more information about VOIPPACK take a look at the <a href="http://enablesecurity.com/products">products page</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/383/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/383/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/383/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/383/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/383/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/383/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/383/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/383/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=383&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2010/02/16/voippack-update-for-february-2010-brings-faster-voip-cracking-and-destruction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>What I&#8217;ve been working on&#8230;</title>
		<link>http://enablesecurity.com/2009/09/17/what-ive-been-working-on/</link>
		<comments>http://enablesecurity.com/2009/09/17/what-ive-been-working-on/#comments</comments>
		<pubDate>Thu, 17 Sep 2009 11:02:25 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=381</guid>
		<description><![CDATA[Lots of links included: SEC-T in Sweden where I presented on VoIP security and the Internet .. proof that there&#8217;s lots of VoIP devices being exposed on the &#8216;net, and the sharks are there to profit by abusing them Updated SIPVicious to support new features used for the SEC-T presentation BruCON VoIP Auditing Workshop, which [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=381&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Lots of links included:</p>
<ul>
<li>SEC-T in Sweden where I presented on <a href="http://www.sec-t.org/2009/Speakers.html#sandro" target="_blank">VoIP security and the Internet</a> .. proof that there&#8217;s lots of VoIP devices being exposed on the &#8216;net, and the sharks are there to profit by abusing them</li>
<li>Updated SIPVicious to <a href="http://sipvicious.org/blog/2009/09/sec-t-in-sweden-and-sipvicious-update.html">support new features</a> used for the SEC-T presentation</li>
<li><a href="http://www.brucon.org/index.php/Workshops#Auditing_VOIP" target="_blank">BruCON VoIP Auditing Workshop</a>, which will be held tomorrow and the next day .. attendees will get to build their own tools and demonstrate security issues in popular PBX servers and SIP phones (more details on <a href="http://sipvicious.org/blog/2009/09/voip-security-workshop-at-brucon-2009.html" target="_blank">sipvicious.org</a>)</li>
<li>Upcoming research in the following topics: Opensource PBX server security, SIP Digest leakage (some details <a href="https://resources.enablesecurity.com/resources/sipdigestleak-tut.pdf" target="_blank">here</a>)</li>
<li><a href="http://www.voipscanner.com/">VOIPSCANNER.com</a> is another project that is being upgraded</li>
<li><a href="http://enablesecurity.com/products">VOIPPACK</a> updates, more details on this soon</li>
<li>And in between there&#8217;s <strong>real</strong> work too :-)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/381/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/381/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/381/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=381&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/09/17/what-ive-been-working-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>HAR2009: Talks of interest</title>
		<link>http://enablesecurity.com/2009/08/13/har2009-talks-of-interest/</link>
		<comments>http://enablesecurity.com/2009/08/13/har2009-talks-of-interest/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 14:23:46 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=375</guid>
		<description><![CDATA[After a long wait, HAR is finally with us. There&#8217;s a large number of talks and events and I thought I&#8217;d make a list of the ones that I hope to attend today: &#8220;Teh Internetz are pwned&#8221; by Scott McIntyre: all the internet threats and issues from the point of view of an Internet Service [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=375&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>After a long wait, HAR is finally with us. There&#8217;s a large number of talks and events and I thought I&#8217;d make a list of the ones that I hope to attend today:</p>
<ul>
<li><strong>&#8220;Teh Internetz are pwned&#8221;</strong> by Scott McIntyre: all the internet threats and issues from the point of view of an Internet Service provider.. might be illuminating ;-)</li>
<li><strong>&#8220;Rootkits are awesome&#8221;</strong> by Mike Kemp, will be an update talk about his research into DLP (data loss prevention) and I hear that he&#8217;ll be picking on more products</li>
<li><strong>&#8220;Countering behavior based malware analysis&#8221;</strong> by Nomenumbra</li>
<li><strong>&#8220;Advanced MySQL Exploitation&#8221;</strong> by Muhaimin Dzulfakar, the author of MySqloit</li>
<li><strong>&#8220;Securing networks from an ISP perspective&#8221;</strong> by Bradley Freeman, seems to be along the lines of the talk by Scott McIntyre but from the point of view of a research &amp; education network perspective, JANET</li>
</ul>
<p>Then there&#8217;s the workshops (and beer) which appear to be worth visiting in between the talks. Busy times indeed, but if you&#8217;re around <a href="mailto:sandro@enablesecurity.com">email me</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/375/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=375&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/08/13/har2009-talks-of-interest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>VOIPSCANNER.com &#8211; SaaS VoIP security auditing</title>
		<link>http://enablesecurity.com/2009/07/17/voipscanner-com-saas-voip-security-auditing/</link>
		<comments>http://enablesecurity.com/2009/07/17/voipscanner-com-saas-voip-security-auditing/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 08:35:27 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>
		<category><![CDATA[voipscanner]]></category>
		<category><![CDATA[saas security]]></category>
		<category><![CDATA[saas voip]]></category>
		<category><![CDATA[sipvicious 2.0]]></category>
		<category><![CDATA[sipvicious-ng]]></category>
		<category><![CDATA[voip security report]]></category>
		<category><![CDATA[voip report]]></category>
		<category><![CDATA[sip security]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=372</guid>
		<description><![CDATA[One thing that I&#8217;ve been working on is making it easy for organizations and consultants to check their IP PBX for security issues. Toll fraud, or theft of service (phone calls) is becoming quite a problem for organizations that expose their PBX on the Internet. VOIPSCANNER.com aims to make it easier to find out how [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=372&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>One thing that I&#8217;ve been working on is making it easy for organizations and consultants to check their IP PBX for security issues. Toll fraud, or theft of service (phone calls) is becoming quite a problem for organizations that expose their PBX on the Internet. VOIPSCANNER.com aims to make it easier to find out how easy it is for attackers out there to gain access to your PBX.</p>
<p>So head over to <a href="http://voipscanner.com" target="_blank">VOIPSCANNER.com</a> and create an account!</p>
<p>Using this tool consists of the following steps:</p>
<ol>
<li><a href="http://beta.voipscanner.com/voipscanner/default/apply">Register an account</a> and buy credit (or use the time limited promo <strong>ENABLESEC</strong> to get some for free)</li>
<li>Enter the IP address of your PBX server and scan away</li>
<li>Receive a report by email that shows the findings</li>
</ol>
<p><span style="font-weight:bold;">How does it work really?</span><br />
VoIPScanner.com is making use of the next generation of SIPVicious (2.0) in the background and right now it does the following automatically:</p>
<ol>
<li>Checks if an IP PBX is listening on the given address</li>
<li>Does extension enumeration, just like svwar in SIPVicious</li>
<li>For each extension found it starts a password cracking attack</li>
<li>Generate a PDF report such as <a href="http://beta.voipscanner.com/voipscanner/static/samplereport.pdf">this one</a></li>
</ol>
<p>Any feedback or affiliate requests, <a href="mailto:sandro@enablesecurity.com">contact me</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/372/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=372&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/07/17/voipscanner-com-saas-voip-security-auditing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>WAF research media coverage and a response to Imperva</title>
		<link>http://enablesecurity.com/2009/05/20/waf-research-media-coverage-and-a-response-to-imperva/</link>
		<comments>http://enablesecurity.com/2009/05/20/waf-research-media-coverage-and-a-response-to-imperva/#comments</comments>
		<pubDate>Wed, 20 May 2009 13:00:08 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[rant]]></category>
		<category><![CDATA[appseceu09]]></category>
		<category><![CDATA[imperva]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[sandro]]></category>
		<category><![CDATA[securesphere]]></category>
		<category><![CDATA[waf security]]></category>
		<category><![CDATA[wendel]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=359</guid>
		<description><![CDATA[Our presentation at OWASP Europe in Krakow on Web Application Firewall shortcomings was featured on Darkreading, and Wendel was quoted in the article. Other sites and blogs (such as Heise) also mentioned the presentation. Imperva&#8217;s (which happens to be a WAF vendor) blog had some comments about the presentation as well, and in this post [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=359&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-360" title="the-3-monkeys" src="http://enablesecurity.files.wordpress.com/2009/05/the-3-monkeys.jpg?w=400&#038;h=300" alt="the-3-monkeys" width="400" height="300" /></p>
<p>Our presentation at <a href="http://www.owasp.org/index.php/AppSecEU09" target="_blank">OWASP Europe</a> in Krakow on Web Application Firewall shortcomings was featured on <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=217400819" target="_blank">Darkreading</a>, and Wendel was quoted in the article. Other sites and blogs (such as <a href="http://www.heise.de/developer/OWASP-Konferenz-Web-Hacking-und-Abwehr--/news/meldung/137934">Heise</a>) also mentioned the presentation. Imperva&#8217;s (which happens to be a WAF vendor) <a href="http://blog.imperva.com/2009/05/owasp-appsec-eu2009-day-1.html" target="_blank">blog</a> had some comments about the presentation as well, and in this post I hope to answer some of the claims.</p>
<blockquote><p>&#8220;What Wendel (TrustWave) and Sandro (EnabledSecurity) basically showed is that they can figure out if a WAF is deployed to protect a web application and two techniques that can allegedly &#8220;bypass&#8221; WAFs.&#8221;</p></blockquote>
<p>Unfortunately we had a couple of technical issues that meant that our presentation did not start on time and some of the live demos could not be shown. We had just 30 minutes to present which was not enough. We did perform the demos the next day anyway to a number of people who had some interesting feedback (more on that later). Either way, we mentioned more than two techniques that can lead to a bypass in some of the Web Application Firewalls.</p>
<blockquote><p>&#8220;The two speakers described WAFs basically as a combination of black lists and white lists while missing the entire point in WAFs that learn the web application interfaces and usage patterns using dynamic profiling mechanisms and express complex security rules through advanced correlation engines. Actually, WAFs were developed to overcome the disadvantages in purely signature based products like IDSs.&#8221;</p></blockquote>
<p>I do not currently have access to Imperva&#8217;s SecureSphere, but aren&#8217;t &#8220;dynamic profiling and express complex security rules&#8221; there to <em>automatically</em> create whitelists? That is what the <a href="http://www.imperva.com/docs/DS_SecureSphere_Web_Application_Firewall.pdf" target="_self">SecureSphere datasheet</a> and the <a href="http://www.imperva.com/products/waf_se.html" target="_blank">specifications page</a> implies. If not, can you explain how this works (and also explain express complex security rules)?</p>
<p>Most WAFs by default support blacklist approach and on large complex sites the positive model is not easy to setup or maintain. Making use of learning features of various WAF products is definitely going to help, but does not solve issues such as maintenance. A good question is &#8220;what sort of traffic do you use to train your WAF&#8221;? A large number of WAFs are configured to make use of the blacklist approach most of the times, even though the positive / whitelist model is supported by the WAF product.</p>
<blockquote><p>&#8220;Presenting the ability to detect WAFs deployed in front of a web application as a major security risk is just biased&#8221;</p></blockquote>
<p>Detection of the WAF is not a major security issue within itself, but is just another step in the reconnaissance stage of an attack.</p>
<p>As for the feedback that we received at OWASP, many of the participants who had first hand experience with Web Application Firewalls agreed that positive model Web Application Firewalls are a pain to maintain. Everyone came to the conclusion that you  need dedicated personnel to maintain a large web application protected by a WAF. That is hardly something that the vendors want you to know.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/359/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/359/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/359/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/359/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/359/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/359/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/359/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/359/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=359&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/05/20/waf-research-media-coverage-and-a-response-to-imperva/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2009/05/the-3-monkeys.jpg" medium="image">
			<media:title type="html">the-3-monkeys</media:title>
		</media:content>
	</item>
		<item>
		<title>Web Application Firewalls and VoIP on the intertubes</title>
		<link>http://enablesecurity.com/2009/05/15/web-application-firewalls-and-voip-on-the-intertubes/</link>
		<comments>http://enablesecurity.com/2009/05/15/web-application-firewalls-and-voip-on-the-intertubes/#comments</comments>
		<pubDate>Fri, 15 May 2009 20:09:18 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>
		<category><![CDATA[web application firewall]]></category>
		<category><![CDATA[waf]]></category>
		<category><![CDATA[voip]]></category>
		<category><![CDATA[confidence]]></category>
		<category><![CDATA[krakow]]></category>
		<category><![CDATA[darkreading]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=352</guid>
		<description><![CDATA[So the OWASP at Krakow (which was a great experience!) came to an end. The conference was a mixture of technical and non-technical presentations; I liked the w3af presentation and thought it was well delivered, and I heard that the &#8220;HTTP Parameter Pollution&#8221; was particularly interesting. It seems that the Web Applications Firewall talk that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=352&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>So the <a href="http://www.owasp.org/index.php/AppSecEU09" target="_blank">OWASP at Krakow</a> (which was a great experience!) came to an end. The conference was a mixture of technical and non-technical presentations; I liked the w3af presentation and thought it was well delivered, and I heard that the &#8220;HTTP Parameter Pollution&#8221; was particularly interesting. It seems that the Web Applications Firewall talk that we gave steered the attention of various <a href="http://www.acunetix.com/blog/websecuritynews/implementing-a-web-application-firewall-only-is-not-enough-to-secure-web-applications/" target="_blank">organizations</a>, <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=217400819" target="_blank">media</a> (DarkReading) and <a href="http://search.twitter.com/search?q=waf" target="_blank">people</a> (Twitter). The presentation went a big bonkers and Murphey&#8217;s Law kicked in. However we got the chance to demonstrate the missed content after the conference for an audience that provided a lot of good feedback.</p>
<p>I&#8217;ll also be presenting a session on VoIP scanning on the internet at<strong> <a href="http://2009.confidence.org.pl/" target="_blank">CONFidence</a> tomorrow.</strong> Most other presentations and research seems to focus on VoIP (in)security + layer 2 issues, such as sniffing clear text VoIP. In contrast to this, my session will be more focused on what attackers coming Internet (can) do to your SIP PBX and endpoints. The focus is on demonstrating using both live demos and recorded videos and destribing some interesting (rather new) attacks that apply to VoIP on the Internet.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/352/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=352&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/05/15/web-application-firewalls-and-voip-on-the-intertubes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>The state of Web Application Security and their Firewalls</title>
		<link>http://enablesecurity.com/2009/04/26/the-state-of-web-application-security-and-their-firewalls/</link>
		<comments>http://enablesecurity.com/2009/04/26/the-state-of-web-application-security-and-their-firewalls/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 20:24:31 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>
		<category><![CDATA[interview]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[syrinx]]></category>
		<category><![CDATA[troopers09]]></category>
		<category><![CDATA[trustwave]]></category>
		<category><![CDATA[web application firewall]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=345</guid>
		<description><![CDATA[Back from Troopers09 in Munich after presenting our (Wendel Guglielmetti Henrique from Trustwave  and yourstruly) research on Web Application Firewalls. Troopers was great and the organizers (Enno Rey and co) made a great job out of the conference. Kudos to them!  During the presentation we demonstrated some tools that will help security analysts and penetration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=345&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Back from <a href="http://troopers09.org/">Troopers09</a> in Munich after presenting our (Wendel Guglielmetti Henrique from Trustwave  and yourstruly) research on Web Application Firewalls. Troopers was great and the organizers (<a href="http://www.ernw.de/" target="_blank">Enno Rey and co</a>) made a great job out of the conference. Kudos to them!  During the presentation we demonstrated some tools that will help security analysts and penetration testers to identify WAFs and fingerprint their rules.We hope to release these tools soon.. meanwhile if you would like to beta test, please send me a <a href="http://enablesecurity.com/contact">note</a>.</p>
<p>Last week Bryan Miller from <a href="http://www.syrinxtech.com/" target="_blank">Syrinx Technologies</a> interviewed me on Web Application Security and WAFs. You may listen to this podcast <a href="http://www.syrinxtech.com/podcasts/090421SYR.mp3" target="_blank">here</a> where I gave my views on web application security and an introduction to the presentation for Troopers. If you would like to keep updated with this podcast, you may subscribe using the <a href="http://www.syrinxtech.com/podcasts/rss.xml" target="_blank">RSS feed</a>.</p>
<p><object type='application/x-shockwave-flash' wmode='opaque' data='http://static.slideshare.net/swf/ssplayer2.swf?id=1344590&#038;doc=wendel-sandro-troopers09-1-090426151524-phpapp02' width='500' height='410'><param name='movie' value='http://static.slideshare.net/swf/ssplayer2.swf?id=1344590&#038;doc=wendel-sandro-troopers09-1-090426151524-phpapp02' /><param name='allowFullScreen' value='true' /><param name='allowScriptAccess' value='always' /></object></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/345/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/345/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/345/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/345/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/345/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/345/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/345/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/345/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=345&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/04/26/the-state-of-web-application-security-and-their-firewalls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.syrinxtech.com/podcasts/090421SYR.mp3" length="12716149" type="audio/mpeg" />
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>VOIPPACK for April adds Asterisk scanning, leaking phones and Troopers09</title>
		<link>http://enablesecurity.com/2009/04/15/voippack-for-april-adds-asterisk-scanning/</link>
		<comments>http://enablesecurity.com/2009/04/15/voippack-for-april-adds-asterisk-scanning/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 14:18:03 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>
		<category><![CDATA[voip security]]></category>
		<category><![CDATA[voippack]]></category>
		<category><![CDATA[canvas]]></category>
		<category><![CDATA[sipautohack]]></category>
		<category><![CDATA[iax2autohack]]></category>
		<category><![CDATA[iax2 security]]></category>
		<category><![CDATA[asterisk security]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=334</guid>
		<description><![CDATA[Announcing the VOIPPACK April edition supporting IAX2 and can now scan Asterisk servers. Because the feedback for sipautohack was great, we included a similar tool for the Asterisk protocol called iax2autohack in the April edition of VOIPPACK. The following are the new tools avialable in this update: iax2enumerate which like sipenumerate, tries to guess extensions [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=334&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Announcing the <a href="http://enablesecurity.com/products/voippack/">VOIPPACK April edition </a>supporting IAX2 and can now scan Asterisk servers. Because the feedback for sipautohack was great, we included a similar tool for the Asterisk protocol called iax2autohack in the April edition of VOIPPACK. The following are the new tools avialable in this update:</p>
<ul>
<li><strong>iax2enumerate</strong> which like sipenumerate, tries to guess extensions present on the Asterisk box, and will inform you if the extension has any password set or not</li>
<li><strong>iax2cracker</strong> which given a known extension on the Asterisk box, will attempt to recover the password through an online bruteforce attack</li>
<li><strong>iax2autohack</strong> which finds out any Asterisk servers on the network, enumerates the extensions and launches a password cracking attack on each extension</li>
</ul>
<p>The following demo shows <a href="http://vimeo.com/4162693" target="_blank">iax2autohack in action</a>:</p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=4162693&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=4162693&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
	<param name="wmode" value="opaque" />
</object>
</span></p>
<p>For more information about VOIPPACK and our other offerings check out<a href="http://enablesecurity.com/products/"> the products page</a>.</p>
<p>Additionally we confirmed a few phones that are vulnerable to the <a href="http://www.net-security.org/secworld.php?id=7263" target="_blank">SIP Digest Leak vulnerability</a> (tools included in VOIPPACK) for the Cisco 7940, Grandstream, Fritzbox and more, thanks <a href="http://www.usken.no/" target="_blank">to Sjur</a> and another unnamed entity ;-) Will be working on further research and releasing a paper after <a href="http://troopers09.org/content/e3/e445/index_eng.html" target="_blank">Troopers09</a> where <a href="http://troopers09.org/content/e2/index_eng.html#e255" target="_blank">Wendel G Henrique</a> and I will be presenting our Web Application Firewall research and releasing new tools.</p>
<p>Watch <a href="http://twitter.com/sandrogauci" target="_blank">twitter</a> if you&#8217;re interested in what&#8217;s happening ;-)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/334/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/334/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/334/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/334/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/334/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/334/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/334/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/334/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=334&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/04/15/voippack-for-april-adds-asterisk-scanning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>Introducing VOIPSCANNER.com &#8211; SaaS VoIP security scanner</title>
		<link>http://enablesecurity.com/2009/04/07/introducing-voipscannercom-saas-voip-security-scanner/</link>
		<comments>http://enablesecurity.com/2009/04/07/introducing-voipscannercom-saas-voip-security-scanner/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 12:46:50 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
				<category><![CDATA[Site news]]></category>
		<category><![CDATA[sipautohack]]></category>
		<category><![CDATA[sipvicious]]></category>
		<category><![CDATA[voipscanner]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=329</guid>
		<description><![CDATA[One of the projects that we&#8217;ve been busy with is VOIPSCANNER.com. I am now pleased to announce that it is (semi-)public beta. During beta stage the service will be free but we shall be approving each application individually. Apply for a beta code now. What is VOIPSCANNER.com? VOIPSCANNER.COM makes scanning your public facing IP PBX [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=329&subd=enablesecurity&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>One of the projects that we&#8217;ve been busy with is <a href="http://www.voipscanner.com/">VOIPSCANNER.com</a>. I am now pleased to announce that it is (semi-)public beta. During beta stage the service will be free but we shall be approving each application individually. Apply for a <a href="http://beta.voipscanner.com/voipscanner/default/apply">beta code now</a>.</p>
<h3>What is VOIPSCANNER.com?</h3>
<p>VOIPSCANNER.COM makes scanning your public facing IP PBX for security holes easier than ever. No need for desktop applications or any software installation, just enter the IP address of your IP PBX and you will receive a report of what attackers out there might find about your IP PBX.</p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=3984952&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=3984952&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
	<param name="wmode" value="opaque" />
</object>
</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/enablesecurity.wordpress.com/329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/enablesecurity.wordpress.com/329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/329/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=329&subd=enablesecurity&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/04/07/introducing-voipscannercom-saas-voip-security-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
	</channel>
</rss>