<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for tag penetration testing</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/tag/40-penetration-testing" rel="self"/>
    <description>Latest security documents RSS feed for tag penetration testing</description>
    <language>en-us</language>
    <item>
      <title>[Video] Google Hacking for Penetration Testers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/371-johnny-long"&gt;Johnny Long&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/102-defcon-13"&gt;DEFCON 13&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 26 Feb 2012 12:20:53 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4965-google-hacking-for-penetration-testers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4965-google-hacking-for-penetration-testers</guid>
    </item>
    <item>
      <title>[Audio] Google Hacking for Penetration Testers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/371-johnny-long"&gt;Johnny Long&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/102-defcon-13"&gt;DEFCON 13&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 26 Feb 2012 11:58:24 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4964-google-hacking-for-penetration-testers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4964-google-hacking-for-penetration-testers</guid>
    </item>
    <item>
      <title>[Slides] Kautilya: Teensy Beyond Shell</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1565-nikhil-mittal"&gt;Nikhil Mittal&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: As hackers, we have been exploiting the inherent trust by Operating System on Human Interface Devices for some time now. Teensy is a USB Micro-controller; a device which can act as a Human Interface Device when connected to a computer and is able to do the job pre-programmed in it.  Many interesting things have been done using Teensy as a keyboard. We have mostly seen shells, many types of them. It is time we start looking at Teensy as a pentesting device capable of doing much more than popping shells. Introducing Kautilya, a toolkit which can be used to perform various pre-exploitation and post-exploitation activities. Kautilya aims on easing the use of attack vectors which traditionally require human intervention but can be automated using Teensy. Kautilya contains some nice customizable payloads which may be used for enumeration, info gathering, disabling countermeasures, keylogging and using Operating System against itself for much more. The talk will be full of live demonstrations.</description>
      <pubDate>Sun, 05 Feb 2012 12:04:14 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4859-kautilya-teensy-beyond-shell</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4859-kautilya-teensy-beyond-shell</guid>
    </item>
    <item>
      <title>[Paper] Kautilya: Teensy Beyond Shell</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1565-nikhil-mittal"&gt;Nikhil Mittal&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/100-black-hat-abu-dhabi-2011"&gt;Black Hat Abu Dhabi 2011&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: As hackers, we have been exploiting the inherent trust by Operating System on Human Interface Devices for some time now. Teensy is a USB Micro-controller; a device which can act as a Human Interface Device when connected to a computer and is able to do the job pre-programmed in it.  Many interesting things have been done using Teensy as a keyboard. We have mostly seen shells, many types of them. It is time we start looking at Teensy as a pentesting device capable of doing much more than popping shells. Introducing Kautilya, a toolkit which can be used to perform various pre-exploitation and post-exploitation activities. Kautilya aims on easing the use of attack vectors which traditionally require human intervention but can be automated using Teensy. Kautilya contains some nice customizable payloads which may be used for enumeration, info gathering, disabling countermeasures, keylogging and using Operating System against itself for much more. The talk will be full of live demonstrations.</description>
      <pubDate>Sun, 05 Feb 2012 12:02:59 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4858-kautilya-teensy-beyond-shell</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4858-kautilya-teensy-beyond-shell</guid>
    </item>
    <item>
      <title>[Slides] Pentesting J2EE</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/254-marc-schoenefeld"&gt;Marc Schoenefeld&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/97-black-hat-federal-2006"&gt;Black Hat Federal 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 19 Jan 2012 06:49:24 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4767-pentesting-j2ee</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4767-pentesting-j2ee</guid>
    </item>
    <item>
      <title>[Slides] Client Side Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1378-max-caceres"&gt;Max Caceres&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 17 Jan 2012 06:33:38 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4753-client-side-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4753-client-side-penetration-testing</guid>
    </item>
    <item>
      <title>[Slides] Stopping Automated Application Attack Tools</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/17-gunter-ollmann"&gt;Gunter Ollmann&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 16 Jan 2012 06:31:21 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4744-stopping-automated-application-attack-tools</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4744-stopping-automated-application-attack-tools</guid>
    </item>
    <item>
      <title>[Slides] IBM iSeries For Penetration Testers: Bypass Restrictions and Take Over Server</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1535-shalom-carmel"&gt;Shalom Carmel&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/96-black-hat-eu-2006"&gt;Black Hat EU 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 13 Jan 2012 06:34:03 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4729-ibm-iseries-for-penetration-testers-bypass-restrictions-and-take-over-server</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4729-ibm-iseries-for-penetration-testers-bypass-restrictions-and-take-over-server</guid>
    </item>
    <item>
      <title>[Slides] MatriXay&#8212;When WebApp&amp;Database Security Pen-Test/Audit Is a Joy</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/653-xiao-rong"&gt;Xiao Rong&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/652-yuan-fan"&gt;Yuan Fan&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/95-black-hat-usa-2006"&gt;Black Hat USA 2006&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 06 Jan 2012 13:08:59 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4681-matrixay%E2%80%94when-webappdatabase-security-pen-testaudit-is-a-joy</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4681-matrixay%E2%80%94when-webappdatabase-security-pen-testaudit-is-a-joy</guid>
    </item>
    <item>
      <title>[Slides] Google Hacking for Penetration Testers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/371-johnny-long"&gt;Johnny Long&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/93-black-hat-eu-2005"&gt;Black Hat EU 2005&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 30 Dec 2011 06:53:48 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4643-google-hacking-for-penetration-testers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4643-google-hacking-for-penetration-testers</guid>
    </item>
    <item>
      <title>[Slides] Google Attacks</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1450-patrick-chambet"&gt;Patrick Chambet&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/88-black-hat-usa-2004"&gt;Black Hat USA 2004&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 04 Dec 2011 06:28:33 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4489-google-attacks</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4489-google-attacks</guid>
    </item>
    <item>
      <title>[Slides] Automated Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/25-ivan-arce"&gt;Ivan Arce&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1378-max-caceres"&gt;Max Caceres&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/81-black-hat-usa-2001"&gt;Black Hat USA 2001&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 02 Nov 2011 06:52:23 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4281-automated-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4281-automated-penetration-testing</guid>
    </item>
    <item>
      <title>[Audio] SHODAN for Penetration Testers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/429-michael-schearer"&gt;Michael Schearer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 22 Mar 2011 05:25:06 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3598-shodan-for-penetration-testers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3598-shodan-for-penetration-testers</guid>
    </item>
    <item>
      <title>[Slides] SHODAN for Penetration Testers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/429-michael-schearer"&gt;Michael Schearer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 22 Mar 2011 05:25:06 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3599-shodan-for-penetration-testers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3599-shodan-for-penetration-testers</guid>
    </item>
    <item>
      <title>[Video] SHODAN for Penetration Testers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/429-michael-schearer"&gt;Michael Schearer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 22 Mar 2011 05:25:06 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3600-shodan-for-penetration-testers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3600-shodan-for-penetration-testers</guid>
    </item>
    <item>
      <title>[Video] Programmable HID USB Keystroke Dongle: Using the Teensy as a pen testing device</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1032-adrian-crenshaw"&gt;Adrian Crenshaw&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 31 Jan 2011 05:25:11 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3359-programmable-hid-usb-keystroke-dongle-using-the-teensy-as-a-pen-testing-device</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3359-programmable-hid-usb-keystroke-dongle-using-the-teensy-as-a-pen-testing-device</guid>
    </item>
    <item>
      <title>[Audio] Programmable HID USB Keystroke Dongle: Using the Teensy as a pen testing device</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1032-adrian-crenshaw"&gt;Adrian Crenshaw&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 31 Jan 2011 05:25:10 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3358-programmable-hid-usb-keystroke-dongle-using-the-teensy-as-a-pen-testing-device</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3358-programmable-hid-usb-keystroke-dongle-using-the-teensy-as-a-pen-testing-device</guid>
    </item>
    <item>
      <title>[Slides] Programmable HID USB Keystroke Dongle: Using the Teensy as a pen testing device</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1032-adrian-crenshaw"&gt;Adrian Crenshaw&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/65-defcon-18"&gt;DEFCON 18&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 30 Jan 2011 14:43:59 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3357-programmable-hid-usb-keystroke-dongle-using-the-teensy-as-a-pen-testing-device</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3357-programmable-hid-usb-keystroke-dongle-using-the-teensy-as-a-pen-testing-device</guid>
    </item>
    <item>
      <title>[Slides] No More of the Same Bad Security: Why the OSSTMM 3 is Threatening Modern Security Practices</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/421-pete-herzog"&gt;Pete Herzog&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/64-hashdays-2010"&gt;Hashdays 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Modern security has become just a dance-off between jargon and products. Enterprises are doing what their being told by compliance requirements, books, and blogs and it's not working or it's not scaling. The problem is we are being taught to build defenses like consumers and it fails us again and again. Then most of us learn to late however that it's failed because the verification methods and security metrics provided are biased or indirect and therefore point out unmanageable and imaginary cause/effect relationships. That's why ISECOM took a different direction with the OSSTMM 3. This short seminar will explain how and why the OSSTMM 3 is nothing like security that you know. There's no Risk analysis, no threat analysis, no patching, and no security awareness yet it works efficiently and economically. The operational security metrics and trust metrics you will see in action are realistic and allow for immediate and accurate defensive changes in your tactics and overall strategy. The OSSTMM 3 will challenge what you think you know about security. Be prepared to be amazed.</description>
      <pubDate>Thu, 13 Jan 2011 19:03:41 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3289-no-more-of-the-same-bad-security-why-the-osstmm-3-is-threatening-modern-security-practices</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3289-no-more-of-the-same-bad-security-why-the-osstmm-3-is-threatening-modern-security-practices</guid>
    </item>
    <item>
      <title>[Slides] Red Teaming</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1086-michael-jordon"&gt;Michael Jordon&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/63-ruxcon-2010"&gt;Ruxcon 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 26 Dec 2010 05:25:14 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3266-red-teaming</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3266-red-teaming</guid>
    </item>
    <item>
      <title>[Slides] No Holds Barred&#8217; Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1082-jarrod-loidl"&gt;Jarrod Loidl&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/63-ruxcon-2010"&gt;Ruxcon 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: This presentation aims to explain why security consultancies are losing the war in providing meaningful value to clients in Australia and what the security industry must do to affect positive change. Conversely, this talk will also cater to potential clients who wish to commission penetration tests what they need to do in order to gain the greatest value from them by creating an environment that is accepting of the problems and a willingness to properly remediate findings.  This talk is not intended to pinpoint blame but rather provide an industry update with some context. While the conclusions can be debated, the evidence presented will be irrefutable that changes are needed.  This presentation will be delivered by someone who has walked both sides of the fence - the client's side having hired multiple professional penetration testing teams and driven remediation efforts, to the consulting side and seeing the commercial realities facing consultancies and the pain experienced by multiple clients.</description>
      <pubDate>Thu, 23 Dec 2010 05:25:16 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3259-no-holds-barred%E2%80%99-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3259-no-holds-barred%E2%80%99-penetration-testing</guid>
    </item>
    <item>
      <title>[Video] Metasploit Pro - An HD Moore Production</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/386-hd-moore"&gt;H.D. Moore&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/62-sector-2010"&gt;SecTor 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 19 Dec 2010 05:25:15 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3251-metasploit-pro---an-hd-moore-production</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3251-metasploit-pro---an-hd-moore-production</guid>
    </item>
    <item>
      <title>[Video] Beyond Exploits: Real World Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/386-hd-moore"&gt;H.D. Moore&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/62-sector-2010"&gt;SecTor 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 02 Dec 2010 19:59:10 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3201-beyond-exploits-real-world-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3201-beyond-exploits-real-world-penetration-testing</guid>
    </item>
    <item>
      <title>[Slides] Beyond Exploits: Real World Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/386-hd-moore"&gt;H.D. Moore&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/62-sector-2010"&gt;SecTor 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 02 Dec 2010 19:40:37 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3200-beyond-exploits-real-world-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3200-beyond-exploits-real-world-penetration-testing</guid>
    </item>
    <item>
      <title>[Video] Turn-Key Pen Test Labs</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/237-thomas-wilhelm"&gt;Thomas Wilhelm&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/61-phreaknic-11"&gt;PhreakNIC 11&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Currently, those interested in learning how to professionally conduct Information System Penetration Tests have very little options available to them - they can either illegally attack Internet-connected systems, or create their own PenTest Lab. For those who prefer to avoid legal complications, they really only have the last option - a lab. However, this can be a very complicated and expensive alternative. In addition, scenarios have to be created that actually represent real-world scenarios; for a beginner this is a Catch-22 since they don't yet have the experience to even know what these scenarios might look like, let alone design them in a challenging way. In order to provide a simply way for both beginners and experts to improve their skills in Penetration Testing, I have designed what is, in effect, a Turn-Key Pen Test Lab using LiveCDs and minimal equipment requirements. The LiveCDs each represent different scenarios that mimic real-world systems and services, which provide essential challenges to improve critical skills in the field of Pen Testing.</description>
      <pubDate>Sat, 20 Nov 2010 12:08:42 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3157-turn-key-pen-test-labs</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3157-turn-key-pen-test-labs</guid>
    </item>
    <item>
      <title>[Video] Malicious USB Devices: Is that an attack vector in your pocket or are you just happy to see me?</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1032-adrian-crenshaw"&gt;Adrian Crenshaw&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/59-phreaknic-14"&gt;PhreakNIC 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 14 Nov 2010 06:12:57 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3126-malicious-usb-devices-is-that-an-attack-vector-in-your-pocket-or-are-you-just-happy-to-see-me</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3126-malicious-usb-devices-is-that-an-attack-vector-in-your-pocket-or-are-you-just-happy-to-see-me</guid>
    </item>
    <item>
      <title>[Video] Physical Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1027-brian-martin"&gt;Brian Martin&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1026-keith-pachulski"&gt;Keith Pachulski&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/58-shoecon-2010"&gt;ShoeCon 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 13 Nov 2010 10:47:04 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3123-physical-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3123-physical-penetration-testing</guid>
    </item>
    <item>
      <title>[Video] Operating in the Shadows</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1031-carlos-perez"&gt;Carlos Perez&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/57-hack3rcon-2010"&gt;Hack3rCon 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Operating in the Shadows: The presentation covers what are the most common artifacts that are left during a pentest, how to reduce this number and operate in a way to make it harder to detect the presence of the pentester and reduce the amount of information left on the target host by using Meterpreter and it's capabilities.</description>
      <pubDate>Tue, 09 Nov 2010 21:24:25 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3112-operating-in-the-shadows</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3112-operating-in-the-shadows</guid>
    </item>
    <item>
      <title>[Video] Physical Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1027-brian-martin"&gt;Brian Martin&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/1026-keith-pachulski"&gt;Keith Pachulski&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/57-hack3rcon-2010"&gt;Hack3rCon 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 09 Nov 2010 13:42:04 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3108-physical-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3108-physical-penetration-testing</guid>
    </item>
    <item>
      <title>[Video] Exploit Me: Firefox Add-ons for PenTesting</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1007-dan-sinclair"&gt;Dan Sinclair&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/51-layerone-2008"&gt;LayerOne 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 25 Oct 2010 16:13:44 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3026-exploit-me-firefox-add-ons-for-pentesting</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3026-exploit-me-firefox-add-ons-for-pentesting</guid>
    </item>
    <item>
      <title>[Slides] Exploit Me: Firefox Add-ons for PenTesting</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/1007-dan-sinclair"&gt;Dan Sinclair&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/51-layerone-2008"&gt;LayerOne 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 25 Oct 2010 16:13:13 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3025-exploit-me-firefox-add-ons-for-pentesting</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3025-exploit-me-firefox-add-ons-for-pentesting</guid>
    </item>
    <item>
      <title>[Slides] Virtually Pwned Pentesting VMware</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/310-claudio-criscione"&gt;Claudio Criscione&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/48-hack-in-the-box-2010-malaysia"&gt;Hack In The Box 2010 Malaysia&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 20 Oct 2010 12:13:52 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2977-virtually-pwned-pentesting-vmware</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2977-virtually-pwned-pentesting-vmware</guid>
    </item>
    <item>
      <title>[Slides] SAP Penetration Testing with Bizsploit</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/306-mariano-nunez-di-croce"&gt;Mariano Nunez Di Croce&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/46-hack-in-the-box-2010-dubai"&gt;Hack In The Box 2010 Dubai&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 05 Oct 2010 11:38:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2920-sap-penetration-testing-with-bizsploit</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2920-sap-penetration-testing-with-bizsploit</guid>
    </item>
    <item>
      <title>[Slides] Hacking from the restroom</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/934-bruno-goncalves"&gt;Bruno Goncalves&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/44-hack-in-the-box-2009-malaysia"&gt;Hack In The Box 2009 Malaysia&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 14 Sep 2010 10:32:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2879-hacking-from-the-restroom</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2879-hacking-from-the-restroom</guid>
    </item>
    <item>
      <title>[Slides] Penetration Testing versus Source Code</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/665-nikhil-wagholikar"&gt;Nikhil Wagholikar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/43-nullcon-2010"&gt;Nullcon 2010&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:40:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2855-penetration-testing-versus-source-code</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2855-penetration-testing-versus-source-code</guid>
    </item>
    <item>
      <title>[Audio] Hacking WITH the iPod Touch</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/237-thomas-wilhelm"&gt;Thomas Wilhelm&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 08 May 2010 18:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2443-hacking-with-the-ipod-touch</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2443-hacking-with-the-ipod-touch</guid>
    </item>
    <item>
      <title>[Slides] Hacking WITH the iPod Touch</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/237-thomas-wilhelm"&gt;Thomas Wilhelm&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 08 May 2010 18:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2444-hacking-with-the-ipod-touch</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2444-hacking-with-the-ipod-touch</guid>
    </item>
    <item>
      <title>[Video] Hacking WITH the iPod Touch</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/237-thomas-wilhelm"&gt;Thomas Wilhelm&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 08 May 2010 18:19:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2445-hacking-with-the-ipod-touch</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2445-hacking-with-the-ipod-touch</guid>
    </item>
    <item>
      <title>[Video] Advanced SQL Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/785-joseph-mccray"&gt;Joseph McCray&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 08 Apr 2010 06:01:28 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2306-advanced-sql-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2306-advanced-sql-injection</guid>
    </item>
    <item>
      <title>[Slides] Advanced SQL Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/785-joseph-mccray"&gt;Joseph McCray&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 08 Apr 2010 06:01:26 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2304-advanced-sql-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2304-advanced-sql-injection</guid>
    </item>
    <item>
      <title>[Audio] Advanced SQL Injection</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/785-joseph-mccray"&gt;Joseph McCray&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 08 Apr 2010 06:01:25 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2303-advanced-sql-injection</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2303-advanced-sql-injection</guid>
    </item>
    <item>
      <title>[Video] Injectable Exploits: Two New Tools for Pwning Web Apps and Browsers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/738-justin-searle"&gt;Justin Searle&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/755-kevin-johnson"&gt;Kevin Johnson&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/767-frank-dimaggio"&gt;Frank DiMaggio&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 28 Mar 2010 06:00:18 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2251-injectable-exploits-two-new-tools-for-pwning-web-apps-and-browsers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2251-injectable-exploits-two-new-tools-for-pwning-web-apps-and-browsers</guid>
    </item>
    <item>
      <title>[Slides] Injectable Exploits: Two New Tools for Pwning Web Apps and Browsers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/738-justin-searle"&gt;Justin Searle&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/755-kevin-johnson"&gt;Kevin Johnson&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/767-frank-dimaggio"&gt;Frank DiMaggio&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 28 Mar 2010 06:00:17 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2250-injectable-exploits-two-new-tools-for-pwning-web-apps-and-browsers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2250-injectable-exploits-two-new-tools-for-pwning-web-apps-and-browsers</guid>
    </item>
    <item>
      <title>[Audio] Injectable Exploits: Two New Tools for Pwning Web Apps and Browsers</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/738-justin-searle"&gt;Justin Searle&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/755-kevin-johnson"&gt;Kevin Johnson&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/767-frank-dimaggio"&gt;Frank DiMaggio&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sun, 28 Mar 2010 06:00:15 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2249-injectable-exploits-two-new-tools-for-pwning-web-apps-and-browsers</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2249-injectable-exploits-two-new-tools-for-pwning-web-apps-and-browsers</guid>
    </item>
    <item>
      <title>[Video] Dradis Framework - Sharing Information will get you Root</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 11 Mar 2010 06:01:39 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2191-dradis-framework---sharing-information-will-get-you-root</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2191-dradis-framework---sharing-information-will-get-you-root</guid>
    </item>
    <item>
      <title>[Audio] Dradis Framework - Sharing Information will get you Root</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 11 Mar 2010 06:01:36 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2190-dradis-framework---sharing-information-will-get-you-root</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2190-dradis-framework---sharing-information-will-get-you-root</guid>
    </item>
    <item>
      <title>[Slides] Dradis Framework - Sharing Information will get you Root</title>
      <description>&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/39-defcon-17"&gt;DEFCON 17&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 11 Mar 2010 06:01:31 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2189-dradis-framework---sharing-information-will-get-you-root</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2189-dradis-framework---sharing-information-will-get-you-root</guid>
    </item>
    <item>
      <title>[Slides] Pen Testing the Web with Firefox</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/429-michael-schearer"&gt;Michael Schearer&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/38-confidence-2009-warszawa"&gt;Confidence 2009 Warszawa&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Thu, 18 Feb 2010 09:03:00 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2057-pen-testing-the-web-with-firefox</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2057-pen-testing-the-web-with-firefox</guid>
    </item>
    <item>
      <title>[Slides] Risk Based Penetration Testing</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/665-nikhil-wagholikar"&gt;Nikhil Wagholikar&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/35-clubhack2009"&gt;ClubHack2009&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 01 Jan 2010 06:11:22 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1815-risk-based-penetration-testing</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1815-risk-based-penetration-testing</guid>
    </item>
    <item>
      <title>[Video] MatriXay: When Web App &amp; Database Security Pen-Test/Audit Is a Joy</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/652-yuan-fan"&gt;Yuan Fan&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/653-xiao-rong"&gt;Xiao Rong&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/40-penetration-testing"&gt;penetration testing&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/34-defcon-14"&gt;DEFCON 14&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Mon, 28 Dec 2009 06:12:07 +0100</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1783-matrixay-when-web-app--database-security-pen-testaudit-is-a-joy</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1783-matrixay-when-web-app--database-security-pen-testaudit-is-a-joy</guid>
    </item>
  </channel>
</rss>

