<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>EnableSecurity</title>
	<link>http://enablesecurity.com</link>
	<description>Security Consultancy, Research and Development</description>
	<lastBuildDate>Tue, 01 Jun 2010 11:10:43 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress.com" -->

	<item>
		<title>Using XSS to switch off dotDefender 4.0</title>
		<description><![CDATA[AppliCure&#8217;s dotDefender version 4.0 had a security flaw in the log viewing feature of the administrative interface. We just published an advisory for this vulnerability. Here&#8217;s the interesting part: &#8220;The log viewer facility in dotDefender does not properly htmlencode user supplied input. This leads to a cross site scripting vulnerability when the log viewer displays [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=409&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2010/06/01/using-xss-to-switch-off-dotdefender-4-0/</link>
			</item>
	<item>
		<title>VOIPPACK update for February 2010 brings faster VoIP cracking and destruction</title>
		<description><![CDATA[So it&#8217;s time to issue an update to VOIPPACK, with some new goodies! This update includes two new tools called &#8220;bypassalwaysreject&#8221; and &#8220;sipopenrelay&#8221; DoS exploits for Asterisk PBX called &#8220;asteriskdiscomfort&#8221;, &#8220;asterisksscanfdos&#8221; and &#8220;iax2resourceexhaust&#8221; Generic DoS exploit &#8220;sipinviteflood&#8221; Optimizations for the SIP Digest leak tool &#8220;sipdigestleak&#8221; and the SIP digest cracker What does &#8220;bypassalwaysreject&#8221; do? Asterisk [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=383&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2010/02/16/voippack-update-for-february-2010-brings-faster-voip-cracking-and-destruction/</link>
			</item>
	<item>
		<title>What I&#8217;ve been working on&#8230;</title>
		<description><![CDATA[Lots of links included: SEC-T in Sweden where I presented on VoIP security and the Internet .. proof that there&#8217;s lots of VoIP devices being exposed on the &#8216;net, and the sharks are there to profit by abusing them Updated SIPVicious to support new features used for the SEC-T presentation BruCON VoIP Auditing Workshop, which [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=381&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/09/17/what-ive-been-working-on/</link>
			</item>
	<item>
		<title>HAR2009: Talks of interest</title>
		<description><![CDATA[After a long wait, HAR is finally with us. There&#8217;s a large number of talks and events and I thought I&#8217;d make a list of the ones that I hope to attend today: &#8220;Teh Internetz are pwned&#8221; by Scott McIntyre: all the internet threats and issues from the point of view of an Internet Service [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=375&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/08/13/har2009-talks-of-interest/</link>
			</item>
	<item>
		<title>VOIPSCANNER.com &#8211; SaaS VoIP security auditing</title>
		<description><![CDATA[One thing that I&#8217;ve been working on is making it easy for organizations and consultants to check their IP PBX for security issues. Toll fraud, or theft of service (phone calls) is becoming quite a problem for organizations that expose their PBX on the Internet. VOIPSCANNER.com aims to make it easier to find out how [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=372&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/07/17/voipscanner-com-saas-voip-security-auditing/</link>
			</item>
	<item>
		<title>WAF research media coverage and a response to Imperva</title>
		<description><![CDATA[Our presentation at OWASP Europe in Krakow on Web Application Firewall shortcomings was featured on Darkreading, and Wendel was quoted in the article. Other sites and blogs (such as Heise) also mentioned the presentation. Imperva&#8217;s (which happens to be a WAF vendor) blog had some comments about the presentation as well, and in this post [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=359&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/05/20/waf-research-media-coverage-and-a-response-to-imperva/</link>
			</item>
	<item>
		<title>Web Application Firewalls and VoIP on the intertubes</title>
		<description><![CDATA[So the OWASP at Krakow (which was a great experience!) came to an end. The conference was a mixture of technical and non-technical presentations; I liked the w3af presentation and thought it was well delivered, and I heard that the &#8220;HTTP Parameter Pollution&#8221; was particularly interesting. It seems that the Web Applications Firewall talk that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=352&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/05/15/web-application-firewalls-and-voip-on-the-intertubes/</link>
			</item>
	<item>
		<title>The state of Web Application Security and their Firewalls</title>
		<description><![CDATA[Back from Troopers09 in Munich after presenting our (Wendel Guglielmetti Henrique from Trustwave  and yourstruly) research on Web Application Firewalls. Troopers was great and the organizers (Enno Rey and co) made a great job out of the conference. Kudos to them!  During the presentation we demonstrated some tools that will help security analysts and penetration [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=345&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/04/26/the-state-of-web-application-security-and-their-firewalls/</link>
			</item>
	<item>
		<title>VOIPPACK for April adds Asterisk scanning, leaking phones and Troopers09</title>
		<description><![CDATA[Announcing the VOIPPACK April edition supporting IAX2 and can now scan Asterisk servers. Because the feedback for sipautohack was great, we included a similar tool for the Asterisk protocol called iax2autohack in the April edition of VOIPPACK. The following are the new tools avialable in this update: iax2enumerate which like sipenumerate, tries to guess extensions [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=334&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/04/15/voippack-for-april-adds-asterisk-scanning/</link>
			</item>
	<item>
		<title>Introducing VOIPSCANNER.com &#8211; SaaS VoIP security scanner</title>
		<description><![CDATA[One of the projects that we&#8217;ve been busy with is VOIPSCANNER.com. I am now pleased to announce that it is (semi-)public beta. During beta stage the service will be free but we shall be approving each application individually. Apply for a beta code now. What is VOIPSCANNER.com? VOIPSCANNER.COM makes scanning your public facing IP PBX [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&amp;blog=3438158&amp;post=329&amp;subd=enablesecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<link>http://enablesecurity.com/2009/04/07/introducing-voipscannercom-saas-voip-security-scanner/</link>
			</item>
</channel>
</rss>