<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for SkullSecurity</title>
	<atom:link href="http://www.skullsecurity.org/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.skullsecurity.org/blog</link>
	<description>Just another security weblog</description>
	<lastBuildDate>Thu, 22 Dec 2011 09:58:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>Comment on WebDAV Detection, Vulnerability Checking and Exploitation by micr0</title>
		<link>http://www.skullsecurity.org/blog/2009/webdav-detection-vulnerability-checking-and-exploitation/comment-page-1#comment-8336</link>
		<dc:creator>micr0</dc:creator>
		<pubDate>Thu, 22 Dec 2011 09:58:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=285#comment-8336</guid>
		<description>thank you man :)</description>
		<content:encoded><![CDATA[<p>thank you man :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by m_101</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8335</link>
		<dc:creator>m_101</dc:creator>
		<pubDate>Wed, 21 Dec 2011 14:49:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8335</guid>
		<description>Nice analysis :).</description>
		<content:encoded><![CDATA[<p>Nice analysis :).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by Ron Bowes</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8334</link>
		<dc:creator>Ron Bowes</dc:creator>
		<pubDate>Wed, 21 Dec 2011 03:21:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8334</guid>
		<description>@blowcheck - Yeah, I didn&#039;t even think to mention why I was doing it without a pcap. Thanks for asking!</description>
		<content:encoded><![CDATA[<p>@blowcheck - Yeah, I didn't even think to mention why I was doing it without a pcap. Thanks for asking!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by blowcheck</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8333</link>
		<dc:creator>blowcheck</dc:creator>
		<pubDate>Tue, 20 Dec 2011 21:36:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8333</guid>
		<description>it was just a personal consideration.., so congratz is still useful, a well done static and dinamic analysis, i love them, thanks i wait the next one.</description>
		<content:encoded><![CDATA[<p>it was just a personal consideration.., so congratz is still useful, a well done static and dinamic analysis, i love them, thanks i wait the next one.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by Ron Bowes</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8332</link>
		<dc:creator>Ron Bowes</dc:creator>
		<pubDate>Tue, 20 Dec 2011 21:28:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8332</guid>
		<description>@blowcheck - yes, but I couldn&#039;t get the server working so I didn&#039;t have the ability to packet capture the communication. 

@Steve - thank you sir!</description>
		<content:encoded><![CDATA[<p>@blowcheck - yes, but I couldn't get the server working so I didn't have the ability to packet capture the communication. </p>
<p>@Steve - thank you sir!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by blowcheck</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8331</link>
		<dc:creator>blowcheck</dc:creator>
		<pubDate>Tue, 20 Dec 2011 21:16:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8331</guid>
		<description>Personally the first analysis part: 

&quot;&quot;&quot;Client connects to server
Client sends server a null-terminated port number
Server connects back to client on that port&quot;&quot;&quot; 

would be much more easy dumping the communication between client-server.
Do you agree?
blow</description>
		<content:encoded><![CDATA[<p>Personally the first analysis part: </p>
<p>"""Client connects to server<br />
Client sends server a null-terminated port number<br />
Server connects back to client on that port""" </p>
<p>would be much more easy dumping the communication between client-server.<br />
Do you agree?<br />
blow</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by Steve</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8330</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Tue, 20 Dec 2011 20:34:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8330</guid>
		<description>Awesome analysis. I found this VERY nice blog via reddit. 

I like your detailed description i learned a lot from this post ;-).</description>
		<content:encoded><![CDATA[<p>Awesome analysis. I found this VERY nice blog via reddit. </p>
<p>I like your detailed description i learned a lot from this post ;-).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Remote control manager FAIL by PoURaN</title>
		<link>http://www.skullsecurity.org/blog/2011/remote-control-manager-fail/comment-page-1#comment-8329</link>
		<dc:creator>PoURaN</dc:creator>
		<pubDate>Mon, 19 Dec 2011 23:14:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1197#comment-8329</guid>
		<description>Hello.. Just read your tweet and I really enjoyed your vuln analysis.. Cool man.. Waiting for more ;)</description>
		<content:encoded><![CDATA[<p>Hello.. Just read your tweet and I really enjoyed your vuln analysis.. Cool man.. Waiting for more ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Return of the Facebook Snatchers by researcher</title>
		<link>http://www.skullsecurity.org/blog/2010/return-of-the-facebook-snatchers/comment-page-3#comment-8323</link>
		<dc:creator>researcher</dc:creator>
		<pubDate>Tue, 29 Nov 2011 21:42:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=887#comment-8323</guid>
		<description>I am trying to see if I can get public users facebook status and all the replies for their status thats been publish. So far I haven&#039;t had luck with the facebook api. Do you have any suggestions?</description>
		<content:encoded><![CDATA[<p>I am trying to see if I can get public users facebook status and all the replies for their status thats been publish. So far I haven't had luck with the facebook api. Do you have any suggestions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on About me (Ron) by Josh</title>
		<link>http://www.skullsecurity.org/blog/about/comment-page-1#comment-8322</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Wed, 23 Nov 2011 17:00:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/wordpress/?page_id=2#comment-8322</guid>
		<description>Thank you Ron.
I am in my second year of a computer science degree and the assembly tutorial on your wiki is absolutely brilliant - you should stick it in a book and sell it.
If you do release it - even on kindle or free pdf or whatever - let me know :D</description>
		<content:encoded><![CDATA[<p>Thank you Ron.<br />
I am in my second year of a computer science degree and the assembly tutorial on your wiki is absolutely brilliant - you should stick it in a book and sell it.<br />
If you do release it - even on kindle or free pdf or whatever - let me know :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Followup to my Facebook research by Nightingale</title>
		<link>http://www.skullsecurity.org/blog/2010/followup-to-my-facebook-research/comment-page-1#comment-8320</link>
		<dc:creator>Nightingale</dc:creator>
		<pubDate>Fri, 11 Nov 2011 18:04:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=898#comment-8320</guid>
		<description>Hello Ron

what do yu think today?
Have you change the mind of the
facebook User - to take better
passwords? Is it possible today,
or are the Users more sensible?

Have a nice day!</description>
		<content:encoded><![CDATA[<p>Hello Ron</p>
<p>what do yu think today?<br />
Have you change the mind of the<br />
facebook User - to take better<br />
passwords? Is it possible today,<br />
or are the Users more sensible?</p>
<p>Have a nice day!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Weaponizing dnscat with shellcode and Metasploit by Sean</title>
		<link>http://www.skullsecurity.org/blog/2010/weaponizing-dnscat-with-shellcode-and-metasploit/comment-page-1#comment-8318</link>
		<dc:creator>Sean</dc:creator>
		<pubDate>Thu, 10 Nov 2011 02:01:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=611#comment-8318</guid>
		<description>Nice work! Though repeatedly querying the same or very similar queries bespeaks a faulty resolver at best. Or perhaps I misunderstand your idea here? I personally prefer the transport to be ICMP echo request/response for various reasons. I recently posted a write up at informati.cc. I&#039;m interested in your comments.</description>
		<content:encoded><![CDATA[<p>Nice work! Though repeatedly querying the same or very similar queries bespeaks a faulty resolver at best. Or perhaps I misunderstand your idea here? I personally prefer the transport to be ICMP echo request/response for various reasons. I recently posted a write up at informati.cc. I'm interested in your comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on (Mostly) good password resets by MD5_is_faster</title>
		<link>http://www.skullsecurity.org/blog/2011/mostly-good-password-resets/comment-page-1#comment-8317</link>
		<dc:creator>MD5_is_faster</dc:creator>
		<pubDate>Thu, 03 Nov 2011 16:12:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1088#comment-8317</guid>
		<description>Adding to CrazyD&#039;s comment for the SMF estimates, I generally assume that MD5 can be guessed offline, today, at 45 billion guesses/sec*machine, not 5 million, per (http://hashcat.net/oclhashcat-lite/).
This takes your 23 CPU-year estimate down to 23 machine-hours for an exhaustive brute force search.</description>
		<content:encoded><![CDATA[<p>Adding to CrazyD's comment for the SMF estimates, I generally assume that MD5 can be guessed offline, today, at 45 billion guesses/sec*machine, not 5 million, per (<a href="http://hashcat.net/oclhashcat-lite/" rel="nofollow">http://hashcat.net/oclhashcat-lite/</a>).<br />
This takes your 23 CPU-year estimate down to 23 machine-hours for an exhaustive brute force search.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Return of the Facebook Snatchers by laughing so hard</title>
		<link>http://www.skullsecurity.org/blog/2010/return-of-the-facebook-snatchers/comment-page-3#comment-8316</link>
		<dc:creator>laughing so hard</dc:creator>
		<pubDate>Sun, 30 Oct 2011 01:33:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=887#comment-8316</guid>
		<description>this whole post is so hilarious!

people refuse to understand the importance of making vulnerabilities PUBLIC - an age-old discussion that should have been settled ages ago - as when vulns are public, there&#039;s a fire under the proverbial bottom of whoever&#039;s responsible (ie. FB) to fix it, and before it&#039;s public it&#039;s only accessible to the bad-guy. really people: imagine you have two bad-guys sitting in a room. if one of them started to make public his findings, would that be a good thing or a bad thing for the bad guys? OBVIOUSLY, it&#039;s a bad thing, as the hole will be patched sooner. any pentester will sabotage his evil twin by making public his findings! (as for making public instead of just telling the company in question in secret - well, i believe experience speaks for itself...ie. they never listen.)

big score for education also! thanks a lot, great read ron &amp; al.
keep up the excellent work!</description>
		<content:encoded><![CDATA[<p>this whole post is so hilarious!</p>
<p>people refuse to understand the importance of making vulnerabilities PUBLIC - an age-old discussion that should have been settled ages ago - as when vulns are public, there's a fire under the proverbial bottom of whoever's responsible (ie. FB) to fix it, and before it's public it's only accessible to the bad-guy. really people: imagine you have two bad-guys sitting in a room. if one of them started to make public his findings, would that be a good thing or a bad thing for the bad guys? OBVIOUSLY, it's a bad thing, as the hole will be patched sooner. any pentester will sabotage his evil twin by making public his findings! (as for making public instead of just telling the company in question in secret - well, i believe experience speaks for itself...ie. they never listen.)</p>
<p>big score for education also! thanks a lot, great read ron &amp; al.<br />
keep up the excellent work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Return of the Facebook Snatchers by FacialX</title>
		<link>http://www.skullsecurity.org/blog/2010/return-of-the-facebook-snatchers/comment-page-3#comment-8315</link>
		<dc:creator>FacialX</dc:creator>
		<pubDate>Sat, 22 Oct 2011 18:50:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=887#comment-8315</guid>
		<description>YOu people are dreaming You   will be identified and tied to your accounts shortly
Thieves, burglars, offenders, scammers will be idententified to the cameras
You post BILLIONS of photos and show your faces everywhere. This is your number. Live RIght for your true colors will be exposed.</description>
		<content:encoded><![CDATA[<p>YOu people are dreaming You   will be identified and tied to your accounts shortly<br />
Thieves, burglars, offenders, scammers will be idententified to the cameras<br />
You post BILLIONS of photos and show your faces everywhere. This is your number. Live RIght for your true colors will be exposed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A deeper look at ms11-058 by Anonym</title>
		<link>http://www.skullsecurity.org/blog/2011/a-deeper-look-at-ms11-058/comment-page-1#comment-8312</link>
		<dc:creator>Anonym</dc:creator>
		<pubDate>Mon, 17 Oct 2011 04:33:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1158#comment-8312</guid>
		<description>Very good work man! You saved me</description>
		<content:encoded><![CDATA[<p>Very good work man! You saved me</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ms08-068 -- Preventing SMBRelay Attacks by Ron Bowes</title>
		<link>http://www.skullsecurity.org/blog/2008/ms08-068-preventing-smbrelay-attacks/comment-page-1#comment-8311</link>
		<dc:creator>Ron Bowes</dc:creator>
		<pubDate>Mon, 17 Oct 2011 03:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=110#comment-8311</guid>
		<description>No, it was fixed in ms08-068 and any operating system that&#039;s come out since.</description>
		<content:encoded><![CDATA[<p>No, it was fixed in ms08-068 and any operating system that's come out since.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How Pwdump6 works, and how Nmap can do it by Mile</title>
		<link>http://www.skullsecurity.org/blog/2009/how-pwdump6-works-and-how-nmap-can-do-it/comment-page-1#comment-8310</link>
		<dc:creator>Mile</dc:creator>
		<pubDate>Sun, 16 Oct 2011 23:07:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=154#comment-8310</guid>
		<description>same here ....


svn: File not found: revision 21298, path ‘/nmap-exp/ron/nmap-smb’</description>
		<content:encoded><![CDATA[<p>same here ....</p>
<p>svn: File not found: revision 21298, path ‘/nmap-exp/ron/nmap-smb’</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on ms08-068 -- Preventing SMBRelay Attacks by Tom</title>
		<link>http://www.skullsecurity.org/blog/2008/ms08-068-preventing-smbrelay-attacks/comment-page-1#comment-8308</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Sat, 15 Oct 2011 18:14:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=110#comment-8308</guid>
		<description>Hi Ron,
Just asking, Is SMB Relay/Reply attack still relevant in this Win7SP1/Win2008R2 era?

Thanks,</description>
		<content:encoded><![CDATA[<p>Hi Ron,<br />
Just asking, Is SMB Relay/Reply attack still relevant in this Win7SP1/Win2008R2 era?</p>
<p>Thanks,</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Locks that can re-key themselves? by Jonwally</title>
		<link>http://www.skullsecurity.org/blog/2011/locks-that-can-re-key-themselves/comment-page-1#comment-8307</link>
		<dc:creator>Jonwally</dc:creator>
		<pubDate>Fri, 14 Oct 2011 05:50:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.skullsecurity.org/blog/?p=1134#comment-8307</guid>
		<description>I have been wondering how those locks worked; great in the simplicity.</description>
		<content:encoded><![CDATA[<p>I have been wondering how those locks worked; great in the simplicity.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

