Tuesday, March 30, 2010

PenTBox – Penetration Testing Security Suite

PenTBox is a Security Suite that packs security and stability testing oriented tools for networks and systems. Programmed in Ruby and oriented to GNU/Linux systems, but compatible with Windows, MacOS and every systems where Ruby works.

It is free, licensed under GNU/GPLv3.

PenTBox Contains

Cryptography tools

  • Base64 Encoder & Decoder
  • Multi-Digest (MD5, SHA1, SHA256, SHA384, SHA512)
  • Hash Password Cracker (MD5, SHA1, SHA256, SHA384, SHA512)
  • Secure Password Generator
  • Files en/decryptor Rijndael (AES) 256 bits – GOST – ARC4

Network tools

  • TCP Flood DoSer
  • TCP Flood AutoDoSer
  • Spoofed SYN Flood DoSer [nmap - hping3]
  • Port scanner
  • Honeypot
  • PenTBox Secure Instant Messaging

Extra

  • L33t Sp3@k Converter
  • Fuzzer

An updated list of tools can be found here.

You can download PenTBox v1.3.2 here:

Windows version (Ruby included) – pentbox_1.3.2_win.zip
Linux version – pentbox_1.3.2.tar

Or read more here.

Post to Twitter

Post to Delicious

Post to Digg

Post to Facebook

Post to StumbleUpon

Maybe next year I can win Pwn2Own.

Posted via web from Will Rant For Food

Monday, March 29, 2010

Netflix for Wii: Mario Must be Happy

My family was one of the privileged few to receive an early copy of the Netflix for Wii disk.  Once you pop the disk in (yes, it is required each time you want to watch video from your instant queue) just authorize the disk using the special code (you only do this once on another computer via the Netflix site) and you're on your way.

Other than the fact you couldn't do a free text search for movies, I found the experience to be slick and well thought out.  You can browse your queue, sift through the various genres, or even pick up where you left off on your recently viewed items.

We watched Paul Blart: Mall Cop without any hiccups, and the audio and video quality were excellent even while using our wireless connection.

The product definitely did not feel like a beta release.  Now maybe they can work on allowing that free text search.

- Hutch

Posted via email from Will Rant For Food

Saturday, March 13, 2010

Google in The Onion in The Schneier-sphere

March 8, 2010

Google in The Onion

Funny:

MOUNTAIN VIEW, CA—Responding to recent public outcries over its handling of private data, search giant Google offered a wide-ranging and eerily well-informed apology to its millions of users Monday.

"We would like to extend our deepest apologies to each and every one of you," announced CEO Eric Schmidt, speaking from the company's Googleplex headquarters. "Clearly there have been some privacy concerns as of late, and judging by some of the search terms we've seen, along with the tens of thousands of personal e-mail exchanges and Google Chat conversations we've carefully examined, it looks as though it might be a while before we regain your trust."

Google expressed regret to some of its third-generation Irish-American users on Smithwood between Barlow and Lake.

Added Schmidt, "Whether you're Michael Paulson who lives at 3425 Longview Terrace and makes $86,400 a year, or Jessica Goldblatt from Lynnwood, WA, who already has well-established trust issues, we at Google would just like to say how very, truly sorry we are."

Posted on March 8, 2010 at 2:24 PM15 Comments

To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter.

If only this weren't true.

DISCLAIMER: Note to Indian and Chinese news organizations: The Onion is a "fake" news site and should not be used as a source for stories. Bruce Schneier is a serious security and cryptography expert and should not be used as a source for humor.

Posted via web from Will Rant For Food

Gordon Gecko for President - RE: Premium Prices at thebigquestions.com blog

Greed is good. Okay, maybe I'm overstating. Overwhelming desire for self-preservation and upward mobility is good. Boy, that's sure not as sexy, but it works.

Posted via web from Will Rant For Food

Privacy is Overrated - RE: De-Anonymizing Social Network Users

Ohm's summary of what's happened:

"Reidentification science disrupts the privacy policy landscape by undermining the faith that we have placed in anonymization. This is no small faith, for technologists rely on it to justify sharing data indiscriminately and storing data perpetually, all while promising their users (and the world) that they are protecting privacy. Advances in reidentification expose these promises as too often illusory. These advances should trigger a sea change in the law, because nearly every information privacy law or regulation grants a get-out-of-jail free card to those who anonymize their data....Yet reidentification science exposes the underlying promise made by these laws—that anonymization protects privacy—as an empty one, as broken as the technologists’ promises. At the very least, lawmakers must reexamine every privacy law, asking whether the power of reidentification and fragility of anonymization have thwarted their original designs.

The power of reidentification also transforms the public policy debate over information privacy. Today, this debate centers almost entirely on squabbles over magical phrases like “personally identifiable information” (PII) or “personal data.” Advances in reidentification expose how thoroughly these phrases miss the point. Although it is true that a malicious adversary can use PII like a name or social security number to link data to identity, as it turns out, the adversary can do the same thing using information that nobody would classify as personally identifiable.... These studies [Sweeny, Netflix study, etc.] and others like them sound the death knell for the idea that we protect privacy when we remove PII from our databases. This idea, which has served as the central focus of information privacy law for almost forty years, is a fallacy that has run its course and must now yield to something else."

So, you think you should be able to keep your e-mail, phone number, photos quarantined to just you and a few selected friends? Come on, we all live in public now. Get over it...oh, what's my number? Hey, mind your own business.

Posted via web from Will Rant For Food

Run Your Own Free Proxy Through the Google App Engine - Google Apps - Lifehacker

Privacy, schmivacy. If you don't do anything wrong on the Internet you have nothing to fear. Right?

Posted via web from Will Rant For Food

Run a Total Background Check on Yourself with Free Online Tools - Consumer Protection - Lifehacker

I'm afraid I might find out who I am

Posted via web from Will Rant For Food

U.S. Declassifies Part of Secret Cybersecurity Plan

And the plan is...more planning!

Posted via web from Will Rant For Food

Sologig.com - Fraud and Deception Find Work

There are a million sordid tales in the wired city. This is one of them.

With the new tech bubble about to expand, I’ve recently had reason to revamp the ol’ résumé and begin looking at various job boards and other online job search tools. While I wish I had better news to report, here’s the basic lowdown: these online tools are still far behind the technology curve. However, that review will have to wait for another day. Today I need to expose the fraudulent practices of one SoloGig.com.

SoloGig bills itself as an online repository of tech jobs for the freelance technology professional, but it is actually an insidious way of getting your hard earned cash out of your wallet and into SoloGig’s pocket. First off, who’s behind SoloGig.com? Well, believe it or not, it’s non other than CareerBuilder.com. My local paper uses CareerBuilder as its sole online source for displaying job-related classifieds, and I have been very pleased with CareerBuilder’s content and services. But free is only nice if it actually delivers, and CareerBuilder has seemed to do that for me. Imagine, then, my surprise as I find out that they’re the ones foisting SoloGig's fraud upon unsuspecting tech pros.

I was looking for some solo gigs and therefore thought SoloGig.com would be a great fit. I signed up and paid for the premium service—yes, paid cold, hard cash. While no one can promise you job listings down the street, or even in your own hometown, I expected to find something in the greater Southern Puget Sound region, and was sorely disappointed. Instead, what I noted was that few, if any, of the listings on SoloGig were actually freelance or contract jobs. Most were retreads of online jobs I’d seen elsewhere, and most of these were pretty old to boot. But as I took a look at these listings, and asked the engine to sort them by their posting date, I noted another anomaly: postings were supposedly taking place mere tenths of a second apart. This was true not just of one or two individual postings, but entire web pages full of listings. How was it possible that job listings I’d seen over a week or two ago elsewhere were supposedly fresh leads posted mere moments before on SoloGig? My contention, and one that was never denied in my correspondence with SoloGig.com, was that someone (or more properly a SQL script of some kind) was freshening the listings to make it look like SoloGig had all kinds of new postings.

Because SoloGig is owned by CareerBuilder, I found it odd that they would lag so far behind them in re-posting this data if they were simply sharing it. I decided it was time to Google SoloGig and see what complaints were out there (something I should have done in the beginning). Lo and behold, others had noticed similar issues, and most reported problems with billing and refunds. Well, eventually I had had enough of my time with SoloGig and asked for a refund. I was ready to duke it out with the billing department, but, to my great relief, my refund was posted within 24-hours of receiving my cancellation notice.

While I never expected SoloGig to be responsible for getting me a job, I did expect them to be honest with their data--especially when you pay them to do so.

Though my tale ends somewhat happily (after all I didn't lose my money), it is still a cautionary tale in the murky ways of the web.

EDITOR'S NOTE: Originally published on my tech blog in 2005, this continues to be the most popular rant I've written to date and continues to garner comments.  In starting this new blog I thought it appropriate to begin with something successful from the past.

Posted via web from Will Rant For Food