<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Yasser&#039;s Security Blog</title>
	<atom:link href="http://seek4sec.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://seek4sec.wordpress.com</link>
	<description>Because only the insecure strive for security!</description>
	<lastBuildDate>Fri, 25 Mar 2011 16:31:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='seek4sec.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/1e5c4b56e140b36c1e53e3f23adf2dae?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Yasser&#039;s Security Blog</title>
		<link>http://seek4sec.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://seek4sec.wordpress.com/osd.xml" title="Yasser&#039;s Security Blog" />
	<atom:link rel='hub' href='http://seek4sec.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Cryptography for Penetration Testers</title>
		<link>http://seek4sec.wordpress.com/2011/03/25/cryptography-for-penetration-testers/</link>
		<comments>http://seek4sec.wordpress.com/2011/03/25/cryptography-for-penetration-testers/#comments</comments>
		<pubDate>Fri, 25 Mar 2011 16:31:11 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[PenTest]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[owasp]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=79</guid>
		<description><![CDATA[I wanna share with you this interesting presentation about some cryptography  issues  related to the pentest. That&#8217;s not a theoretical one but it gives practical aspects and case studies. Nice reading<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=79&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wanna share with you this interesting presentation about some cryptography  issues  related to the pentest. That&#8217;s not a theoretical one but it gives practical aspects and case studies.</p>
<p>Nice reading <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<iframe src='http://www.slideshare.net/slideshow/embed_code/620347' width='490' height='402'></iframe>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/79/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/79/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/79/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=79&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2011/03/25/cryptography-for-penetration-testers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>
	</item>
		<item>
		<title>SaaS: audit du WPA dans un nuage</title>
		<link>http://seek4sec.wordpress.com/2011/03/19/saas_audit_nuage_securite/</link>
		<comments>http://seek4sec.wordpress.com/2011/03/19/saas_audit_nuage_securite/#comments</comments>
		<pubDate>Sat, 19 Mar 2011 05:56:13 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=74</guid>
		<description><![CDATA[Bonjour! J&#8217;aimerais bien parler dans cet article d&#8217;un service illustrant une figure de SaaS: Security as a Service. En fait, il s&#8217;agit d&#8217;un WPA Cracker. Ce service est supposé être utilisé par des testeurs d&#8217;intrusion et des auditeurs de sécurité des réseaux afin d&#8217;auditer la sécurité des réseaux sans fil protégés par une WPA-PSK. Ce [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=74&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://seek4sec.files.wordpress.com/2011/03/wpa_05.png"><img class="aligncenter size-full wp-image-75" title="wpa_cracker" src="http://seek4sec.files.wordpress.com/2011/03/wpa_05.png?w=490" alt="wpa cracker"   /></a></p>
<p>Bonjour!</p>
<p>J&#8217;aimerais bien parler dans cet article d&#8217;un service illustrant une figure de SaaS: Security as a Service. En fait, il s&#8217;agit d&#8217;un <strong>WPA Cracker. </strong>Ce service est supposé être utilisé par des testeurs d&#8217;intrusion et des auditeurs de sécurité des réseaux afin d&#8217;auditer la sécurité des réseaux sans fil protégés par une WPA-PSK.</p>
<p>Ce service est basé sur un nuage (cloud) formé de cluster de 400CPU qui essaierons  un total de 135 millions mots de dictionnaire   créés spécialement pour casser les mots de passe WPA.</p>
<p>Selon les fournisseurs du service, tandis que le processus de cassage de ce type de clés prend en moyen 5 jours sur un PC dual-core, la même opération prend cependant sur leur cluster à peu près 20 minutes pour un prix $17.</p>
<p>Un autre service pour l&#8217;audit des fichiers ZIP est offert et les responsables invitent les visiteurs de proposés d&#8217;autres types de fichiers susceptibles intéressés une large gamme de testeurs potentiels.</p>
<p>A mon avis, les créateurs du système WPA Cracker ont bien profité de la nouvelle tendance du cloud computing, l&#8217;ont combinée par un savoir-faire en matière de sécurité des réseaux sans fil pour en tirer profit en créant un service payant.</p>
<p>Lien du projet: <a title="http://www.wpacracker.com/" href="http://www.wpacracker.com/" target="_blank">http://www.wpacracker.com/</a></p>
<p>&nbsp;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/74/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=74&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2011/03/19/saas_audit_nuage_securite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2011/03/wpa_05.png" medium="image">
			<media:title type="html">wpa_cracker</media:title>
		</media:content>
	</item>
		<item>
		<title>Journées Nationales de la Sécurité &#8211; Marrakech</title>
		<link>http://seek4sec.wordpress.com/2011/03/16/journees-nationales-de-la-securite-marrakech/</link>
		<comments>http://seek4sec.wordpress.com/2011/03/16/journees-nationales-de-la-securite-marrakech/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 03:39:16 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[AMAN]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[JNS]]></category>
		<category><![CDATA[Journées Nationales de la Sécurité]]></category>
		<category><![CDATA[Morocco]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=69</guid>
		<description><![CDATA[In this topic I&#8217;ll give a briefing  as an attendee and participant at &#8220;Journées Nationales de la Sécurité&#8221; (JNS). The First edition of National Journeys of  Security were a great opportunity to meet researchers and some professional actors of infosec in Morocco. The journeys took place in Marrakesh for 2 days:  march, 11-12, 2011. The [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=69&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In this topic I&#8217;ll give a briefing  as an attendee and participant at &#8220;<strong>Journées Nationales de la Sécurité&#8221;</strong> (JNS). The First edition of National Journeys of  Security were a great opportunity to meet researchers and some professional actors of infosec in Morocco. The journeys took place in <strong>Marrakesh</strong> for 2 days:  march, <span style="color:#000000;font-size:medium;">11-12, 2011.</span></p>
<p><span style="color:#000000;font-size:medium;"></p>
<div id="attachment_71" class="wp-caption aligncenter" style="width: 234px"><a href="http://seek4sec.files.wordpress.com/2011/03/250px-menara_gardenmoroccomarrakech.jpg"><img class="size-medium wp-image-71" title="Marrakech" src="http://seek4sec.files.wordpress.com/2011/03/250px-menara_gardenmoroccomarrakech.jpg?w=224&#038;h=300" alt="Marrakech" width="224" height="300" /></a><p class="wp-caption-text">Marrakech</p></div>
<p></span></p>
<p>The organization of the JNS aimed to strengthen links between researchers, industrialists, engineers, organizations, teachers, students and other actors of IT field, in Morocco or in  foreigns countries , in a common goal to work together, present and discuss their works, develop partnerships and projects, propose viable solutions and provide our country with strong skills in the field of  information, systems and network  security.</p>
<p>I want to thank Mr. <span style="color:#666666;"><span style="color:#000000;">Anas ABOU EL KALAM and all members of the organization&#8217;s comity, to accept our contribution to these days. In fact, we, as members of the <a href="http://inseclub.net" target="_blank">INSEC </a>club of ENSIAS,  had the opportunity to talk, during the presentations, a little bit about our initiative of creating a scholar club for IT Security and inform all attendees of our organization of the first edition of <a href="http://mcsc.inseclub.net" target="_blank">&#8220;Moroccan Cyber Security Challenge &#8211; Rabat, April, 16-17 &#8220;</a>.</span></span></p>
<p><span style="color:#666666;"><span style="color:#000000;">A the end, thier were a General Assembly of a new association named <strong>AMAN</strong></span><strong> </strong></span><strong><span style="color:#86202d;">(Association  				Marocaine de la confiAnce Numérique)</span></strong><span style="color:#666666;"><span style="color:#000000;">. Yet another good initiative in Morocco, good job founders!<br />
</span></span></p>
<p><span style="color:#666666;"><span style="color:#000000;">The event were well organized and the  attendees were pleased to meet experiences and research of all participants.</span></span></p>
<p><span style="color:#666666;"><span style="color:#000000;">I hope we&#8217;ll see more events like this in Morocco and I&#8217;m glad to be a part of this first edition.</span></span></p>
<p><span style="color:#666666;"><span style="color:#000000;">For more details about the past event, I invite you to see the Program of </span></span><a href="http://www.ensa.ac.ma/jns/programme.htm" target="_blank">Journées Nationales de la Sécurité</a>.</p>
<p>&nbsp;</p>
<p><span style="color:#666666;"><strong><br />
</strong></span></p>
<p><span style="color:#000000;font-size:medium;"><br />
</span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/69/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=69&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2011/03/16/journees-nationales-de-la-securite-marrakech/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2011/03/250px-menara_gardenmoroccomarrakech.jpg?w=224" medium="image">
			<media:title type="html">Marrakech</media:title>
		</media:content>
	</item>
		<item>
		<title>Jarlsberg: a cheesy web app to secure</title>
		<link>http://seek4sec.wordpress.com/2010/07/10/jarlsberg-a-cheesy-web-app-to-secure/</link>
		<comments>http://seek4sec.wordpress.com/2010/07/10/jarlsberg-a-cheesy-web-app-to-secure/#comments</comments>
		<pubDate>Sat, 10 Jul 2010 03:40:57 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[PenTest]]></category>
		<category><![CDATA[google code]]></category>
		<category><![CDATA[Jarlsberg]]></category>
		<category><![CDATA[pyton]]></category>
		<category><![CDATA[web application]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=49</guid>
		<description><![CDATA[This topic is dedicated to another codelab that concerns Web Application Exploits and Defenses: This framework is coded by Bruce Leban, Mugdha Bendre, and Parisa Tabriz from Google Code. It&#8217;s written in Python, so some familiarity with Python can be helpful. However, the security vulnerabilities covered are not Python-specific and you can do most of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=49&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This topic is dedicated to another codelab that concerns Web Application Exploits and Defenses:</p>
<p><a href="http://seek4sec.files.wordpress.com/2010/07/gruyere-78.png"><img class="aligncenter size-full wp-image-61" title="gruyere-78" src="http://seek4sec.files.wordpress.com/2010/07/gruyere-78.png?w=490" alt="logo"   /></a></p>
<p>This framework is coded by <strong>Bruce Leban</strong>, <strong>Mugdha Bendre</strong>, and <strong>Parisa Tabriz</strong> from Google Code. It&#8217;s written in <strong><span style="color:#339966;">Python</span></strong>, so some familiarity with Python can be helpful. However, the security vulnerabilities covered are not Python-specific and you can do most of the lab without even looking at the code.</p>
<p>Jarlsberg, compared to a piece of cheese, has multiple security bugs ranging from XSS and XSRF, to information disclosure, DoS, and remote code execution. The goal of this codelab is to guide the tester through discovering some of these bugs and learning ways to fix them both in Jarlsberg and in general.</p>
<p style="text-align:center;"><a href="http://seek4sec.files.wordpress.com/2010/07/gruyere.png"><img class="aligncenter size-medium wp-image-59" title="gruyere" src="http://seek4sec.files.wordpress.com/2010/07/gruyere.png?w=300&#038;h=246" alt="gruyere" width="300" height="246" /></a><em>Jarlsberg Home Page</em></p>
<p>Challenges are tagged to indicate which techniques are required to solve them:  some of it can  be solved just by using black box techniques, others require that you look at the Jarlsberg source code and finally some challenges  require some specific knowledge of Jarlsberg that will be given in the first hint.</p>
<p>It&#8217;s really a great work and I&#8217;m enjoying time to time find some of the obvious vulns :p See the shots:</p>
<p><a href="http://seek4sec.files.wordpress.com/2010/07/xss1.png"><img class="aligncenter size-medium wp-image-50" title="XSS1" src="http://seek4sec.files.wordpress.com/2010/07/xss1.png?w=300&#038;h=126" alt="" width="300" height="126" /></a></p>
<p style="text-align:center;"><a href="http://seek4sec.files.wordpress.com/2010/07/xss2.png"><img class="aligncenter size-medium wp-image-51" title="xss2" src="http://seek4sec.files.wordpress.com/2010/07/xss2.png?w=300&#038;h=117" alt="" width="300" height="117" /></a><em>Oops! Don&#8217;t you smell a tasty cookie</em> ? :p</p>
<p style="text-align:center;">&nbsp;</p>
<h3 style="text-align:left;"><span style="color:#000000;">Have fun and secure it !</span></h3>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=49&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2010/07/10/jarlsberg-a-cheesy-web-app-to-secure/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2010/07/gruyere-78.png" medium="image">
			<media:title type="html">gruyere-78</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2010/07/gruyere.png?w=300" medium="image">
			<media:title type="html">gruyere</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2010/07/xss1.png?w=300" medium="image">
			<media:title type="html">XSS1</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2010/07/xss2.png?w=300" medium="image">
			<media:title type="html">xss2</media:title>
		</media:content>
	</item>
		<item>
		<title>Securing public services using Tariq!</title>
		<link>http://seek4sec.wordpress.com/2010/07/04/securing-public-services-using-tariq/</link>
		<comments>http://seek4sec.wordpress.com/2010/07/04/securing-public-services-using-tariq/#comments</comments>
		<pubDate>Sun, 04 Jul 2010 19:06:22 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[Arabic]]></category>
		<category><![CDATA[Port knoking]]></category>
		<category><![CDATA[Secure]]></category>
		<category><![CDATA[Tariq]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=38</guid>
		<description><![CDATA[This was the title of an interesting article in Hakin9 Magazine. It&#8217;s about a topic that threats what port-knocking is, the benefit of using it and how-to secure a public service such as SSH using Tariq. However this name &#8220;Tariq&#8221; didn&#8217;t refers to the Arabic language? Yep! Indeed, the developer of this technique is the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=38&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This was the title of an interesting article in <a title="Hakin9" href="www.hakin9.org" target="_blank">Hakin9 Magazine</a>. It&#8217;s about a topic that threats what port-knocking is, the benefit of using it and how-to secure a public service such as SSH using Tariq.</p>
<p><img class="aligncenter" title="Port knocking" src="http://www.thenetworkadministrator.com/portknocking.jpg" alt="Port knocking image" width="120" height="120" /></p>
<p>However this name <span style="color:#008080;"><em>&#8220;Tariq&#8221;</em></span> didn&#8217;t refers to the Arabic language? Yep! Indeed, the developer of this technique is the engineer <a title="Ali Al-Shemery" href="http://www.binary-zone.com/whoami/" target="_blank">Ali Al-Shemery</a> and the project was developed using python and scapy to fulfill his Ph.D. Research.</p>
<p>Here are brief notes of the project excerpt from <a title="Google code" href="http://code.google.com/p/tariq/" target="_blank">the official project&#8217;s page:</a><strong><a href="http://code.google.com/p/tariq/"></a></strong></p>
<blockquote>
<table cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td></td>
<td>&#8220;Tariq is a new hybrid port-knocking technique, which  uses Cryptography, Steganography, and Mutual Authentication to develop  another security layer in front of any service that needs to be accessed  from different locations around the globe. [...]. We had to use a new  methodology that can communicate in an unseen manner, making TCP Replay  Attacks hard to be issued against Tariq. We also wanted the  implementation to listen to no ports, or bind itself to no socket for  packets exchange, so that Tariq won&#8217;t be exposed himself to a remote  exploit. Tariq relies completely on Packet Crafting, as all packets sent  and received are crafted to suite our needs.&#8221;</td>
</tr>
</tbody>
</table>
</blockquote>
<p>The project has been also added to the <a title="Portkocking" href="http://www.portknocking.org" target="_blank">Portknoking</a> website among a wide variety of other implementations of port knocking!</p>
<p>It&#8217;s really honorable to see like these projects in our Arabic community ! Big up to you my bro <span style="color:#008080;"><strong>Ali Al-Shemery</strong></span> for your brilliant work and May Allah reward you for the good!</p>
<p>To download the magazine:  <a title="Hakin9" href="http://download.hakin9.org/en/hakin9_05_2010_EN.pdf" target="_blank">Hakin9 05 2010 EN.pdf</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/38/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/38/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/38/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=38&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2010/07/04/securing-public-services-using-tariq/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>

		<media:content url="http://www.thenetworkadministrator.com/portknocking.jpg" medium="image">
			<media:title type="html">Port knocking</media:title>
		</media:content>
	</item>
		<item>
		<title>Cluster under Ubuntu to crack passwords using BF method!</title>
		<link>http://seek4sec.wordpress.com/2010/07/04/cluster-under-ubuntu-to-crack-passwords-using-bf-method/</link>
		<comments>http://seek4sec.wordpress.com/2010/07/04/cluster-under-ubuntu-to-crack-passwords-using-bf-method/#comments</comments>
		<pubDate>Sun, 04 Jul 2010 16:36:25 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[cluster]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=30</guid>
		<description><![CDATA[In my earlier reading, I found this tutorial that explains who to mount a cluster under Ubuntu 10.04 in order to crack passwords using the Brute Force method. In this case, the famous tool is used: Johan the Ripper. But the guy, as he said, used this implementation when he found himself in a situation [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=30&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="Cluster running Linux" src="http://farm4.static.flickr.com/3149/2556707493_8a5a02e3f6.jpg" alt="High Performance Computing " width="500" height="478" /></p>
<p>In my earlier reading, I found this tutorial that explains who to mount a cluster under <span style="text-decoration:underline;">Ubuntu 10.04</span> in order to crack passwords using the Brute Force method. In this case, the famous tool is used: Johan the Ripper. But the guy, as he said, used this implementation when he found himself in a situation where he had to break up an old password of his.</p>
<p>In the original post, the author explains that he managed to decrease the time required to crack password hashes at home  to a fraction (9% of the original time) using his 3 computers with this  setup.</p>
<p>To my mind this implementation will be owesome using Back|Track 4 since this later is based on Debian core and uses Ubuntu packages and the JTR tool is already setup in B|T4 !</p>
<p>This document, as you&#8217;ll discover, is a simple step-by-step tutorial which is for academic purposes but can be used for purposes other than hacking.</p>
<p><a title="PDF link" href="http://www.petur.eu/projects/John_the_Ripper_on_a_Ubuntu_10.04_MPI_Cluster.pdf" target="_blank">The PDF link!</a></p>
<p>Source:</p>
<p><a class="alignleft" title="http://www.petur.eu/blog" href="http://www.petur.eu/blog/?p=59" target="_blank">http://www.petur.eu/blog/?p=59</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/30/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/30/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/30/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=30&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2010/07/04/cluster-under-ubuntu-to-crack-passwords-using-bf-method/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3149/2556707493_8a5a02e3f6.jpg" medium="image">
			<media:title type="html">Cluster running Linux</media:title>
		</media:content>
	</item>
		<item>
		<title>Welcome to Seek4Sec!</title>
		<link>http://seek4sec.wordpress.com/2010/05/25/welcome/</link>
		<comments>http://seek4sec.wordpress.com/2010/05/25/welcome/#comments</comments>
		<pubDate>Tue, 25 May 2010 14:28:49 +0000</pubDate>
		<dc:creator>Yasser</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[general]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[welcome]]></category>

		<guid isPermaLink="false">http://seek4sec.wordpress.com/?p=1</guid>
		<description><![CDATA[Welcome to Seek4Sec ! This is my first post As you may understand from the blog&#8217;s name, it is mainly dedicated to issues related to IT Security: it&#8217;s a kind of a Seek for Security. I would like also share some of Computing Science topics, white hacking, engineering skills and why not my modest experiences [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=1&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://seek4sec.files.wordpress.com/2010/05/banner-security.jpg"><img class="aligncenter size-medium wp-image-18" title="banner-security" src="http://seek4sec.files.wordpress.com/2010/05/banner-security.jpg?w=300&#038;h=84" alt="security banner " width="300" height="84" /></a></p>
<p>Welcome to <span style="color:#800080;"><strong><a href="http://seek4sec.wordpress.com">Seek4Sec</a></strong></span> !</p>
<p>This is my first post  <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>As you may understand from the blog&#8217;s name, it is mainly dedicated to issues related to IT Security: it&#8217;s a kind of a Seek for Security. I would like also share some of Computing Science topics, white hacking, engineering skills and why not my modest experiences in this field <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Posts in this blog are for educational purpose only!</p>
<p>I hope you enjoy contents and  themes!</p>
<p>If you have something to say about or add to a blog post I’ve  written, please take a moment to post your thoughts in a comment on the  blog.</p>
<p>Thanks for stopping by.</p>
<p><strong><em><br />
</em></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/seek4sec.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/seek4sec.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/seek4sec.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/seek4sec.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/seek4sec.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/seek4sec.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/seek4sec.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/seek4sec.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=seek4sec.wordpress.com&amp;blog=13859094&amp;post=1&amp;subd=seek4sec&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://seek4sec.wordpress.com/2010/05/25/welcome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/068c7712c691c2274a204be646487387?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">seek4security</media:title>
		</media:content>

		<media:content url="http://seek4sec.files.wordpress.com/2010/05/banner-security.jpg?w=300" medium="image">
			<media:title type="html">banner-security</media:title>
		</media:content>
	</item>
	</channel>
</rss>
