<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>DC412 Forums</title>
    <link>http://dc412.org/forums/index.php</link>
    <description><![CDATA[]]></description>
    <language>EN</language>
    <pubDate>Tue, 31 Jan 2012 05:17:19 -0800</pubDate>
    <lastBuildDate>Tue, 31 Jan 2012 05:17:19 -0800</lastBuildDate>
    <category>DC412 Forums</category>
    <generator>Phorum 5.1.22</generator>
    <ttl>600</ttl>
    <item>
      <title>[DC412 Main Forum] Re: East Pittsburgh</title>
      <link>http://dc412.org/forums/read.php?2,28,39#msg-39</link>
      <author>ScottMcFall</author>
      <description><![CDATA[Hi Brian,

I live in Murrysville and my office is in Monroeville &amp; Turtle Creek.  Give me a ping, we'd love to participate. 

Scott
ProTech]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,28,39#msg-39</guid>
      <pubDate>Tue, 31 Jan 2012 05:17:19 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Upcoming Events</title>
      <link>http://dc412.org/forums/read.php?2,37,38#msg-38</link>
      <author>BrianWGray</author>
      <description><![CDATA[Pittsburgh BSides officially announced and accepting registration.

http://www.securitybsides.com/w/page/38914998/BSidesPittsburgh]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,37,38#msg-38</guid>
      <pubDate>Thu, 14 Apr 2011 12:47:34 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Upcoming Events</title>
      <link>http://dc412.org/forums/read.php?2,37,37#msg-37</link>
      <author>BrianWGray</author>
      <description><![CDATA[So far I'm planning on definitely hitting Bsides Pittsburgh and Derbycon for 2011. 

What events outside of Defcon are you looking forward to this year?]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,37,37#msg-37</guid>
      <pubDate>Fri, 01 Apr 2011 06:49:36 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Is there any one out there..?</title>
      <link>http://dc412.org/forums/read.php?2,33,36#msg-36</link>
      <author>BrianWGray</author>
      <description><![CDATA[If there is interest in pumping some life into DC412, I'm game.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,33,36#msg-36</guid>
      <pubDate>Sun, 13 Mar 2011 12:10:35 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Is there any one out there..?</title>
      <link>http://dc412.org/forums/read.php?2,33,35#msg-35</link>
      <author>pfriedma</author>
      <description><![CDATA[DC412 should be HUPd]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,33,35#msg-35</guid>
      <pubDate>Wed, 09 Mar 2011 13:47:39 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Is there any one out there..?</title>
      <link>http://dc412.org/forums/read.php?2,33,34#msg-34</link>
      <author>BrianWGray</author>
      <description><![CDATA[I would have to say that DC412 is dead. There are other groups in the area depending on where your interests are focused.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,33,34#msg-34</guid>
      <pubDate>Wed, 16 Feb 2011 10:34:16 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Is there any one out there..?</title>
      <link>http://dc412.org/forums/read.php?2,33,33#msg-33</link>
      <author>bish0p.greyhat</author>
      <description><![CDATA[I can't help but notice that there hasn't been a post in a few months... Have i finally found a semi local group (i'm from younstown ohio and a PTI graduate to boot), or should i continue on my lonely journey of learning how to code by myself? (i'm in the process of learning python at the moment)]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,33,33#msg-33</guid>
      <pubDate>Thu, 27 Jan 2011 10:08:18 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Reading Suggestions</title>
      <link>http://dc412.org/forums/read.php?2,13,32#msg-32</link>
      <author>BrianWGray</author>
      <description><![CDATA[I completely forgot about this thread but I still think it's a good idea.

The &quot;Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research written by: James Foster&quot; book was horrible and to be honest now is so outdated that most of the documentation on how the framework did work isn't relevant any longer.

&quot;Fuzzing - Brute Force vulnerability Discovery&quot; by Michael Sutton, Adam Greene, and Pedram Amini.  Is still a good intro to the basics of fuzzing however frameworks like sully etc. have made life more simple the testing methods etc. within the book are still well explained and useful.

Adding to the list:

Ajax Security, written by Billy Hoffman and Bryan Sullivan ISBN-13:978-0-321-49193-0 is a good overview of common programming errors in ajax application implementation.

If this thread or forum ever takes off I have dozens of reading suggestions and I would love to see suggestions from others.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,13,32#msg-32</guid>
      <pubDate>Fri, 23 Apr 2010 12:41:38 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] CTF event</title>
      <link>http://dc412.org/forums/read.php?2,31,31#msg-31</link>
      <author>BrianWGray</author>
      <description><![CDATA[The Pittsburgh Security User Group is looking to hold another Capture the Flag event. 
Check out PittSUG.org for more info.

[quote]
Submitted by can0beans on Fri, 04/16/2010 - 14:31
Just wanted to let everyone know that another PittSUG Capture the Flag event is planned for Saturday June 12th. Blow the dust off your Ninja suit, download the latest copy of Pentoo or pull out that bottle of BackTrack PwnSauce because it's hackin' time.

More details to follow this weekend!
[/quote]
http://pittsug.org/content/another-pittsug-capture-flag-coming-soon]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,31,31#msg-31</guid>
      <pubDate>Fri, 23 Apr 2010 12:18:15 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: For those that got to attend...</title>
      <link>http://dc412.org/forums/read.php?2,20,30#msg-30</link>
      <author>BrianWGray</author>
      <description><![CDATA[Company cutbacks killed all conferences for me this year. Anyone go, and what was your favorite speaker / event?]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,20,30#msg-30</guid>
      <pubDate>Sun, 23 Aug 2009 08:53:28 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: For those that got to attend...</title>
      <link>http://dc412.org/forums/read.php?2,20,29#msg-29</link>
      <author>BrianWGray</author>
      <description><![CDATA[That's great to hear. I had some other conferences that sucked up my $$ to go this past year but hopefully I'll have it in the budget to hit up both defcon and shmoocon next year.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,20,29#msg-29</guid>
      <pubDate>Fri, 27 Feb 2009 11:03:11 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] East Pittsburgh</title>
      <link>http://dc412.org/forums/read.php?2,28,28#msg-28</link>
      <author>BrianWGray</author>
      <description><![CDATA[I moved to Tarentum, Pa this past year and I am looking for people in the general area that are interested in working on some projects. If you're interested feel free to contact me.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,28,28#msg-28</guid>
      <pubDate>Fri, 27 Feb 2009 11:00:54 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: For those that got to attend...</title>
      <link>http://dc412.org/forums/read.php?2,20,27#msg-27</link>
      <author>NeoN</author>
      <description><![CDATA[Yeah Bohack and I went... I liked DefCon 15 better, but it's always informational and fun! I can't wait for Defcon 17!]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,20,27#msg-27</guid>
      <pubDate>Wed, 21 Jan 2009 11:50:32 -0800</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: For those that got to attend...</title>
      <link>http://dc412.org/forums/read.php?2,20,26#msg-26</link>
      <author>BrianWGray</author>
      <description><![CDATA[sooo, anyone go this year?]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,20,26#msg-26</guid>
      <pubDate>Tue, 02 Sep 2008 13:01:03 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: For those that got to attend...</title>
      <link>http://dc412.org/forums/read.php?2,20,25#msg-25</link>
      <author>BrianWGray</author>
      <description><![CDATA[sounds exciting...]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,20,25#msg-25</guid>
      <pubDate>Thu, 01 Nov 2007 07:18:05 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Defcon 15 on google video</title>
      <link>http://dc412.org/forums/read.php?2,24,24#msg-24</link>
      <author>BrianWGray</author>
      <description><![CDATA[http://video.google.com/videoplay?docid=-6149767674745536409&amp;q=%22defcon+15+-%22+site%3Avideo.google.com&amp;total=122&amp;start=100&amp;num=10&amp;so=1&amp;type=search&amp;plindex=4]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,24,24#msg-24</guid>
      <pubDate>Wed, 12 Sep 2007 14:01:48 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: An idea....</title>
      <link>http://dc412.org/forums/read.php?2,22,23#msg-23</link>
      <author>BrianWGray</author>
      <description><![CDATA[I suppose the real question is what can be gained from doing it. If the scanners are simply a ticket verification / tally system for attendance counts or if it's linked to anything more important. I have a friend that has been involved in cabling a few ball parks I'll see if they have any incites.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,22,23#msg-23</guid>
      <pubDate>Thu, 30 Aug 2007 08:35:19 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] An idea....</title>
      <link>http://dc412.org/forums/read.php?2,22,22#msg-22</link>
      <author>NeoN</author>
      <description><![CDATA[You go to some event that you bought tickets for, Pirates game, concert, or something like that. The person at the gate has a PDA with a bar code scanner which scans your tickets. Almost every time I look at the PDA, they are using some Internet Explorer web based app. It also refreshes so quickly that it most likely is on an intranet using 802.11 rather then using 1X or some other means of wireless communication. My question is if this is hackable. I'm half tempted to sit outside the gates of some venue and see what I can find.

NeoN]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,22,22#msg-22</guid>
      <pubDate>Thu, 30 Aug 2007 05:59:29 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Reading Suggestions</title>
      <link>http://dc412.org/forums/read.php?2,13,21#msg-21</link>
      <author>BrianWGray</author>
      <description><![CDATA[Suggested Reading: &quot;Fuzzing - Brute Force vulnerability Discovery&quot; by Michael sutton, Adam Greene, and Pedram Amini.
ISBN-0-32-144611-9

Written to be easily understood and provides clear and useful background / instruction on learning fuzzing techniques.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,13,21#msg-21</guid>
      <pubDate>Wed, 22 Aug 2007 08:11:12 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] For those that got to attend...</title>
      <link>http://dc412.org/forums/read.php?2,20,20#msg-20</link>
      <author>BrianWGray</author>
      <description><![CDATA[I'm currious I haven't heard a word from the people that were able to attend defcon this year. Any thing expecialy exciting to share?]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,20,20#msg-20</guid>
      <pubDate>Wed, 22 Aug 2007 08:08:17 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Meeting Topics</title>
      <link>http://dc412.org/forums/read.php?2,19,19#msg-19</link>
      <author>BrianWGray</author>
      <description><![CDATA[Re: Next Meeting?? 
Posted by: NeoN (IP Logged)
Date: August 15, 2007 09:21AM


You know how sometimes if you search for something on Google and click on a result that they want you to pay for it? Well a cool thing that I found yesterday is that you can cloak Google's IP, referrers, browser agent and the like to get into those sites. Just another something cool to possibly present next meeting... 

Speaking of which... we need to set a date/time for the next one! I vote for Thursday, September 20th @ 7PM 

NeoN

Edited 1 time(s). Last edit at 08/15/2007 09:27AM by NeoN.


That reminds me of a couple years ago when sites were serving different pages to google bots than to regular visitors to increase their search ranking. There are still a bunch of firefox plugins that let you easily switch back and forth. For a while I had my home squid proxy set to re-write my agent headers to say that all the devices in the house were googlebots. Unfortunately that broke sites that do agent checks for &quot;compatibility.&quot;

Anyway, there is my rant for the afternoon.

Hmmm, meeting topics. I think I would like to give a presentation on Fuzzing windows apps with the Sulley framework. I'm not sure how many people would care about fuzzing though...]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,19,19#msg-19</guid>
      <pubDate>Wed, 15 Aug 2007 06:48:46 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Next Meeting??</title>
      <link>http://dc412.org/forums/read.php?2,8,18#msg-18</link>
      <author>NeoN</author>
      <description><![CDATA[You know how sometimes if you search for something on Google and click on a result that they want you to pay for it? Well a cool thing that I found yesterday is that you can cloak Google's IP, referrers, browser agent and the like to get into those sites. Just another something cool to possibly present next meeting...

Speaking of which... we need to set a date/time for the next one! I vote for Thursday, September 20th @ 7PM

NeoN]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,8,18#msg-18</guid>
      <pubDate>Wed, 15 Aug 2007 06:21:58 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Reading Suggestions</title>
      <link>http://dc412.org/forums/read.php?2,13,17#msg-17</link>
      <author>BrianWGray</author>
      <description><![CDATA[Suggested Reading: &quot;Reversing - Secrets of Reverse Engineering&quot; by Eldad Eilam
ISBN-10: 0-7645-7481-7
ISBN-13: 978-0-7645-7481-8

The book is a great introduction into the fundamentals of reversing x86 applications on the windows platform.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,13,17#msg-17</guid>
      <pubDate>Wed, 08 Aug 2007 11:27:14 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Next Meeting??</title>
      <link>http://dc412.org/forums/read.php?2,8,16#msg-16</link>
      <author>BrianWGray</author>
      <description><![CDATA[That's actually really cool. I see it's been around since 99 - 00 I hadn't heard about it.

My first reaction was well there's reason #2 to block TCP 53 (#1 being to mitigate zone transfers) Then as I looked at it further NSTX works around not having TCP and allows you to tunnel using only UDP. 

I think the DNS performance alerts would probably alert a heavily used tunnel but good Find!]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,8,16#msg-16</guid>
      <pubDate>Wed, 25 Jul 2007 14:24:33 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Next Meeting??</title>
      <link>http://dc412.org/forums/read.php?2,8,15#msg-15</link>
      <author>NeoN</author>
      <description><![CDATA[Getting back on topic...

I just stumbled across something really sweet! Tunneling traffic through DNS... yeah DNS! Actually sending all of your traffic via SSH over DNS. You can use this to bypass those tricky captive portals!

neon]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,8,15#msg-15</guid>
      <pubDate>Wed, 25 Jul 2007 13:29:37 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Reading Suggestions</title>
      <link>http://dc412.org/forums/read.php?2,13,14#msg-14</link>
      <author>BrianWGray</author>
      <description><![CDATA[Below is a decent collection of links for getting started with Metasploit.

http://www.darknet.org.uk/2007/07/learn-to-use-metasploit-tutorials-docs-videos/

I have also pre-ordered (September 07)

Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research written by: James Foster

I'll let you know what I think once I've read it, but this is a Syngress book and I feel that they normaly produce an excellent product.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,13,14#msg-14</guid>
      <pubDate>Tue, 24 Jul 2007 08:32:08 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Reading Suggestions</title>
      <link>http://dc412.org/forums/read.php?2,13,13#msg-13</link>
      <author>BrianWGray</author>
      <description><![CDATA[I thought that a thread with suggested reading that ranges from article links to books, and possibly quick reviews would be a useful addition.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,13,13#msg-13</guid>
      <pubDate>Tue, 24 Jul 2007 08:27:07 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Next Meeting??</title>
      <link>http://dc412.org/forums/read.php?2,8,12#msg-12</link>
      <author>NeoN</author>
      <description><![CDATA[LOL sweet!

I looked into it and they fixed it. We're running a newer version then 5.1.20 and I also checked the changelog on the version we're running and it's all good.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,8,12#msg-12</guid>
      <pubDate>Thu, 19 Jul 2007 12:56:41 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Next Meeting??</title>
      <link>http://dc412.org/forums/read.php?2,8,11#msg-11</link>
      <author>BrianWGray</author>
      <description><![CDATA[Speaking of which...

http://secunia.com/product/4144/?task=advisories_2007

Impact:  Cross Site Scripting
Where:  From remote
Solution Status:  Unpatched  

Description:
Hasadya Raed has discovered a vulnerability in Phorum, which can be exploited by malicious people to conduct cross-site scripting attacks.

Input passed via the URL to admin.php is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Successful exploitation requires that the user is running a browser that does not URL-encode the request (e.g. Internet Explorer).

The vulnerability is confirmed in version 5.1.19. Other versions may also be affected.]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,8,11#msg-11</guid>
      <pubDate>Thu, 19 Jul 2007 07:46:33 -0700</pubDate>
    </item>
    <item>
      <title>[DC412 Main Forum] Re: Next Meeting??</title>
      <link>http://dc412.org/forums/read.php?2,8,10#msg-10</link>
      <author>neon</author>
      <description><![CDATA[Geeze... what kind of language is that!?! :-P

if($meeting != 'friday &amp;&amp; $meeting != 'weekend') { echo &quot;I'm attending!&quot;; }


Yeah, but really, I agree with Brian. I think it will help with getting more people in. Also, maybe starting just a hair later? Traffic is a bitch for some people...

I would like to learn more about cross-site scripting so that could be a possibility for a future topic.

neon]]></description>
      <category>DC412 Main Forum</category>
      <guid isPermaLink="true">http://dc412.org/forums/read.php?2,8,10#msg-10</guid>
      <pubDate>Wed, 18 Jul 2007 13:34:03 -0700</pubDate>
    </item>
  </channel>
</rss>

