<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Angels of security &#187; software</title>
	<atom:link href="http://angelsofsecurity.com/blog/category/software/feed/" rel="self" type="application/rss+xml" />
	<link>http://angelsofsecurity.com/blog</link>
	<description>Musings of an infosec renegade</description>
	<lastBuildDate>Tue, 02 Aug 2011 19:01:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>cool tool of the moment</title>
		<link>http://angelsofsecurity.com/blog/2010/10/06/cool-tool-of-the-moment/</link>
		<comments>http://angelsofsecurity.com/blog/2010/10/06/cool-tool-of-the-moment/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 02:51:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[mojopac]]></category>
		<category><![CDATA[OS]]></category>
		<category><![CDATA[vm]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/?p=650</guid>
		<description><![CDATA[I just came across a tool called mojopac which I&#8217;d actually never seen or heard of before. Basically you can take a current windows OS and move the entire OS onto a USB drive. Take that USB drive to any other computer and it will launch your system as a VM. They claim (although I [...]]]></description>
			<content:encoded><![CDATA[<p>I just came across a tool called <a href="http://www.mojopac.com">mojopac</a> which I&#8217;d actually never seen or heard of before. Basically you can take a current windows OS and move the entire OS onto a  USB drive. Take that USB drive to any other computer and it will launch your system as a VM. They claim (although I haven&#8217;t  seen it verified) that the USB based system and the host system will not  interfere with each other. Basically it seems to be like a &#8220;build your  own knoppix&#8221; tool but for Windows. It also turns any computer into a super portable laptop &#8211; just install your system with all your configs, apps, etc. onto a USB stick. You don&#8217;t need to take any hardware with you when you travel &#8211; just plug your USB into whatever computer is convenient.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2010/10/06/cool-tool-of-the-moment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>new web app scanner</title>
		<link>http://angelsofsecurity.com/blog/2010/03/22/new-web-app-scanner/</link>
		<comments>http://angelsofsecurity.com/blog/2010/03/22/new-web-app-scanner/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 16:30:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[application security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[skipfish]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/?p=566</guid>
		<description><![CDATA[A friend of mine dropped me a note to point out that Google has released an open source web application security scanner called skipfish. I haven&#8217;t used it yet (installing as I type), and will hopefully have some thought on it soon.]]></description>
			<content:encoded><![CDATA[<p>A friend of mine dropped me a note to point out that Google has released an open source web application security scanner called <a href="http://code.google.com/p/skipfish/">skipfish</a>. I haven&#8217;t used it yet (installing as I type), and will hopefully have some thought on it soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2010/03/22/new-web-app-scanner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP war dialing</title>
		<link>http://angelsofsecurity.com/blog/2009/03/04/voip-war-dialing/</link>
		<comments>http://angelsofsecurity.com/blog/2009/03/04/voip-war-dialing/#comments</comments>
		<pubDate>Wed, 04 Mar 2009 21:35:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[war dialing]]></category>
		<category><![CDATA[warvox]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/03/04/voip-war-dialing/</guid>
		<description><![CDATA[It&#8217;s about time someone made this tool. Warvox uses a VoIP connection to do it&#8217;s war dialing. Because it uses VoIP, it can dial multiple numbers on parallel. It also has some good built in analysis features to find things like voicemail.]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s about time someone made this tool. <a href="http://warvox.org/">Warvox </a>uses a VoIP connection to do it&#8217;s war dialing. Because it uses VoIP, it can dial multiple numbers on parallel. It also has some good built in analysis features to find things like voicemail.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/03/04/voip-war-dialing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>alternate data streams and IIS</title>
		<link>http://angelsofsecurity.com/blog/2009/02/23/alternate-data-streams-and-iis/</link>
		<comments>http://angelsofsecurity.com/blog/2009/02/23/alternate-data-streams-and-iis/#comments</comments>
		<pubDate>Mon, 23 Feb 2009 15:50:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[alternate data streams]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[iis]]></category>
		<category><![CDATA[lads]]></category>
		<category><![CDATA[ntfs]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/02/23/alternate-data-streams-and-iis/</guid>
		<description><![CDATA[I&#8217;ve been doing some fooling around with alternate data streams lately. I&#8217;ve found two interesting things which haven&#8217;t really been given a lot of attention before. The first  is just how ADS aware IIS is. IIS will serve up an ADS as a file. So for example, if you have a file called boring.html, which [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been doing some fooling around with <a href="http://www.windowsecurity.com/articles/Alternate_Data_Streams.html">alternate data streams</a> lately. I&#8217;ve found two interesting things which haven&#8217;t really been given a lot of attention before.</p>
<p>The first  is just how ADS aware IIS is. IIS will <a href="http://www.irongeek.com/i.php?page=security/altds">serve up an ADS</a> as a file. So for example, if you have a file called boring.html, which has an ADS called interesting.jpg, you can access the ADS by entering http://somedomain.com/boring.html:interesting.jpg as your URL. (I&#8217;m sorry I can&#8217;t provide an example here as I&#8217;m not using Windows to host this domain). If instead of a jpeg the ADS is server side code (like php), IIS will even execute the php code as you would expect. I suspect this is a great way for hackers to silently leak data from inside a network to the outside. All of that aside though, if you download a file from a web server which has ADS, IIS will not send the ADS along with the file &#8211; it will only send the main part of the file.</p>
<p><a href="http://angelsofsecurity.com/blog/wp-content/uploads/2009/02/surerun.JPG" title="surerun.jpg"><img src="http://angelsofsecurity.com/blog/wp-content/uploads/2009/02/surerun.thumbnail.JPG" alt="surerun.jpg" vspace="3" align="right" hspace="3" /></a>The second thing I&#8217;ve come to realize is that a lot of applications use ADS for &#8220;legitimate&#8221; reasons. The most common one is Internet explorer. Every file you download using IE has an ADS called &#8220;Zone.Identifier&#8221; attached to it. This ADS contains a ZoneID, which is a number from 0-4. The number indicates which zone the file was downloaded from. If the file was downloaded from the internet (zone 3) Windows XP SP2 and newer bring up the dialog box you see on the right, prompting the user to ensure they really want to run the app. If you want to disable this behavior, you can follow instructions found on the <a href="http://support.microsoft.com/kb/883260/">Microsoft website</a>.</p>
<p>On a related note, I just want to quickly put in a plug for <a href="http://www.heysoft.de/nt/ep-lads.htm">LADS &#8211; List Alternate Data Streams</a> &#8211; it is a very good, simple, easy to use, quality program. Also, it&#8217;s free.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/02/23/alternate-data-streams-and-iis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows resource editors</title>
		<link>http://angelsofsecurity.com/blog/2009/02/18/windows-resource-editors/</link>
		<comments>http://angelsofsecurity.com/blog/2009/02/18/windows-resource-editors/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 15:05:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[resource editor]]></category>
		<category><![CDATA[Resource Hacker]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2009/02/18/windows-resource-editors/</guid>
		<description><![CDATA[I recently borrowed a copy of Hacking Windows XP from a friend. (I was under the impression that it would be about, well, hacking). It&#8217;s really all about customizations that you can do to your system, through changes to the system files and registry. One useful thing it did have was a link to a [...]]]></description>
			<content:encoded><![CDATA[<p>I recently borrowed a copy of <a href="http://www.amazon.com/Hacking-Windows-ExtremeTech-Steve-Sinchak/dp/0764569295">Hacking Windows XP</a> from a friend. (I was under the impression that it would be about, well, hacking). It&#8217;s really all about customizations that you can do to your system, through changes to the system files and registry. One useful thing it did have was a link to a very good resource editor called <a href="http://angusj.com/resourcehacker/">Resource Hacker</a>. It&#8217;s been years since I&#8217;ve used a Windows resource editor, and I&#8217;m starting to remember how fun (and utterly time consuming) it can be to mess around with the look and feel of your Windows apps and OS. In short, Resource Hacker lets you open up an executable or library file (exe, dll, ocx, scr, or cpl), and see that various resources within it &#8211; things like text string and icons &#8211; and lets you change them. Say you don&#8217;t like an error message, just find that text string and change it. Don&#8217;t like the way an app looks? Just change the icons. Don&#8217;t like the fact that the start button says start? Change it. (It&#8217;s just a text string after all). I know someone will point out that a hex editor can do many of the same things, however a resource editor organizes the data for you making it easier to find that string you want to change (or just browse), and it should (in theory at least) keep you away from the executable code which could break the app. It also let&#8217;s you see and edit graphics. If you ever want to find a fun way to kill a lazy Sunday afternoon, I highly recommend it.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2009/02/18/windows-resource-editors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Users testing for site security</title>
		<link>http://angelsofsecurity.com/blog/2008/08/15/users-testing-for-site-security/</link>
		<comments>http://angelsofsecurity.com/blog/2008/08/15/users-testing-for-site-security/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 13:38:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[browsers]]></category>
		<category><![CDATA[hackersafe]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[www]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/08/15/users-testing-for-site-security/</guid>
		<description><![CDATA[I think this isn&#8217;t a bad idea, but the implementation is inherently flawed: the company plans to release a toolbar for major browsers that will check visited Web sites for obvious security issues. The add-on software will check for twenty signs &#8212; such as the version numbers of the Web server and the content management [...]]]></description>
			<content:encoded><![CDATA[<p>I think <a href="http://www.securityfocus.com/brief/796">this</a> isn&#8217;t a bad idea, but the implementation is inherently flawed:</p>
<blockquote><p><span class="body">the company plans to release a toolbar for major browsers that will check visited Web sites for obvious security issues. The add-on software will check for twenty signs &#8212; such as the version numbers of the Web server and the content management system &#8212; to make sure that the site has no obvious flaws.</span></p></blockquote>
<p>As I said, it seems like a good idea. It&#8217;s non-invasive, and it alerts users (even non security savvy ones) that a site may be insecure. Ultimately it provides a very real and direct consequence of lax security to e-commerce sites &#8211; be secure or you may scare off customers. (And we all know that fear of affecting the bottom line is often the only thing that makes corporate entities act in favor of security). The problem is that without being invasive (think SQL injection), you can&#8217;t really tell if a site is secure. I&#8217;m afraid that this is going to turn into another one of those <a href="http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html">McAfee hackersafe</a> style logos &#8211; just a green light that makes you feel safe without actually doing anything.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/08/15/users-testing-for-site-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Race to zero</title>
		<link>http://angelsofsecurity.com/blog/2008/08/12/race-to-zero/</link>
		<comments>http://angelsofsecurity.com/blog/2008/08/12/race-to-zero/#comments</comments>
		<pubDate>Tue, 12 Aug 2008 13:49:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[race to zero]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/08/12/480/</guid>
		<description><![CDATA[The Race to Zero is a competition which recently wrapped up at Defcon. In it, teams of contestants are given ten known pieces of malware &#8211; viruses and exploits &#8211; and are tasked with obfuscating the malware in such a way that antivirus programs cannot detect the malware. The competition was ultimately won by Mandiant [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.racetozero.net/">Race to Zero</a> is a competition which recently wrapped up at <a href="https://www.defcon.org">Defcon</a>. In it, teams of contestants are given ten known pieces of malware &#8211; viruses and exploits &#8211; and are tasked with obfuscating the malware in such a way that antivirus programs cannot detect the malware. The competition was <a href="http://www.securityfocus.com/brief/795?ref=rss">ultimately won</a> by <a href="http://www.mandiant.com/">Mandiant</a> which completed the task in a little over six hours. (About 36 minutes per challenge). This contest simply serves to illustrate the point that signature based antivirus scanning is a failing proposition. As I&#8217;ve <a href="/blog/2008/06/26/more-malware-signatures-needed-than-before/">said before</a>, there are a virtually infinite number of possible malware signature out there, and trying to write an infinite number of signatures is an exercise in futility. It makes a lot more sense to enumerate good than to enumerate bad. We figured this out years ago when we started making firewalls use a default deny &#8211; we should be doing the same for antivirus.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/08/12/race-to-zero/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>compiling nmap</title>
		<link>http://angelsofsecurity.com/blog/2008/06/27/compiling-nmap/</link>
		<comments>http://angelsofsecurity.com/blog/2008/06/27/compiling-nmap/#comments</comments>
		<pubDate>Fri, 27 Jun 2008 17:05:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/06/27/compiling-nmap/</guid>
		<description><![CDATA[I&#8217;m setting up a new Linux machine, and while compiling nmap, I noticed the following fly by: ( ) /\ _ ( \ &#124; ( \ ( \.( ) _____ \ \ \ ` ` ) \ ( ___ / _ \ (_` \+ . x ( .\ \/ \____-----------/ (o) \_ - .- \+ [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m setting up a new Linux machine, and while compiling nmap, I noticed the following fly by:</p>
<pre>   (  )   /\   _                 (
    \ |  (  \ ( \.(               )                      _____
  \  \ \  `  `   ) \             (  ___                 / _   \
 (_`    \+   . x  ( .\            \/   \____-----------/ (o)   \_
- .-               \+  ;          (  O                           \____
                          )        \_____________  `              \  /
(__                +- .( -'.- &lt;. - _  VVVVVVV VV V\                 \/
(_____            ._._: &lt;_ - &lt;- _  (--  _AAAAAAA__A_/                |
  .    /./.+-  . .- /  +--  - .     \______________//_              \_______
  (__ ' /x  / x _/ (                                  \___'          \     /
 , x / ( '  . / .  /                                      |           \   /
    /  /  _/ /    +                                      /              \/
   '  (__/                                             /                  \
             NMAP IS A POWERFUL TOOL -- USE CAREFULLY AND REPONSIBLY</pre>
<p>Somehow, I&#8217;ve never noticed this before, but I love it. (Well, except for the misspelling of the word responsibly).</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/06/27/compiling-nmap/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>more malware signatures needed than before</title>
		<link>http://angelsofsecurity.com/blog/2008/06/26/more-malware-signatures-needed-than-before/</link>
		<comments>http://angelsofsecurity.com/blog/2008/06/26/more-malware-signatures-needed-than-before/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 15:44:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[proactive security]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[whitelisting]]></category>

		<guid isPermaLink="false">http://angelsofsecurity.com/blog/2008/06/26/more-malware-signatures-needed-than-before/</guid>
		<description><![CDATA[In the &#8220;duh&#8221; reporting on the moment, securityfocus reports that: The number of signatures required to detect malicious code skyrocketed in the first half of 2008. While I may mock them (gently of course) for reporting something which is obvious, the growth curve is impressive: The data &#8212; part of the F-Secure&#8217;s IT Security Threat [...]]]></description>
			<content:encoded><![CDATA[<p>In the &#8220;duh&#8221; reporting on the moment, <a href="http://www.securityfocus.com/brief/763?ref=rss">securityfocus reports</a> that:</p>
<blockquote><p><span class="body"> The number of signatures required to detect malicious code skyrocketed in the first half of 2008.</span></p></blockquote>
<p>While I may mock them (gently of course) for reporting something which is obvious, the growth curve is impressive:</p>
<blockquote><p><span class="body"> The data &#8212; part of the F-Secure&#8217;s <a href="http://www.f-secure.com/2008/1/index.html" target="_blank">IT Security Threat Summary</a> &#8212; showed that the company currently requires nearly 900,000 different signatures, also referred to as &#8220;definitions&#8221; or &#8220;detections,&#8221; in its product to catch current threats, up from <a href="http://www.securityfocus.com/brief/655">500,000 signatures</a> at the end of 2007.</span></p></blockquote>
<p>The solution of course, is to stop writing signatures. There are a virtually infinite number of pieces of malware that can be written, and trying to write a signature for each and every one is an exercise in futility. We&#8217;ve seen it time and again &#8211; blacklisting does not work in the long run, it is not scalable, and is inherently reactive rather than proactive.</p>
]]></content:encoded>
			<wfw:commentRss>http://angelsofsecurity.com/blog/2008/06/26/more-malware-signatures-needed-than-before/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

