<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Penetration Testing Lab</title>
	<atom:link href="http://pentestlab.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://pentestlab.wordpress.com</link>
	<description>Explore the lab...maybe you will find some interesting things...</description>
	<lastBuildDate>Mon, 20 May 2013 12:19:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Credential Harvester Attack Method by BlackByte</title>
		<link>http://pentestlab.wordpress.com/2012/02/24/credential-harvester-attack-method/#comment-5446</link>
		<dc:creator><![CDATA[BlackByte]]></dc:creator>
		<pubDate>Mon, 20 May 2013 12:19:48 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=136#comment-5446</guid>
		<description><![CDATA[Wow, thanks for the tutorial. I use no-ip on my router but how i can configure the SET of backtrack to the auto_detect mode off?
Thanks!]]></description>
		<content:encoded><![CDATA[<p>Wow, thanks for the tutorial. I use no-ip on my router but how i can configure the SET of backtrack to the auto_detect mode off?<br />
Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by Security News #0x3F &#124; CyberOperations</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5344</link>
		<dc:creator><![CDATA[Security News #0x3F &#124; CyberOperations]]></dc:creator>
		<pubDate>Sun, 12 May 2013 00:50:17 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5344</guid>
		<description><![CDATA[[&#8230;] folks at PenTestLab have an article about a tool called FindMyHash. That tool is a Python script that sends your [&#8230;]]]></description>
		<content:encoded><![CDATA[<p>[&#8230;] folks at PenTestLab have an article about a tool called FindMyHash. That tool is a Python script that sends your [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on QRCode Attack Vector by Matt</title>
		<link>http://pentestlab.wordpress.com/2012/04/17/qrcode-attack-vector/#comment-5328</link>
		<dc:creator><![CDATA[Matt]]></dc:creator>
		<pubDate>Fri, 10 May 2013 20:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=847#comment-5328</guid>
		<description><![CDATA[How do I open a terminal that shows the submitted credentials (like the one it the final picture in the post)?]]></description>
		<content:encoded><![CDATA[<p>How do I open a terminal that shows the submitted credentials (like the one it the final picture in the post)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by apentester</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5302</link>
		<dc:creator><![CDATA[apentester]]></dc:creator>
		<pubDate>Thu, 09 May 2013 08:16:15 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5302</guid>
		<description><![CDATA[Key thing to remember, the hash is the clients data. You should be under NDA when conducting a pentest, the client must authorise the release of this data to a third party.

Whether or not you believe the risk to minimal is irrelevant.]]></description>
		<content:encoded><![CDATA[<p>Key thing to remember, the hash is the clients data. You should be under NDA when conducting a pentest, the client must authorise the release of this data to a third party.</p>
<p>Whether or not you believe the risk to minimal is irrelevant.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by Der_Stift</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5297</link>
		<dc:creator><![CDATA[Der_Stift]]></dc:creator>
		<pubDate>Thu, 09 May 2013 06:51:47 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5297</guid>
		<description><![CDATA[I agree with apentester, because it is quite a bit risky to use this script. Because even the hashes could include company details. 
But on the other hand: It is good when you make sure that nobody can get to your IP. Even if this is not the company IP ;) And if you have no other choice to crack that system. 

So I would say it depence on the case, if you use it or not. :)]]></description>
		<content:encoded><![CDATA[<p>I agree with apentester, because it is quite a bit risky to use this script. Because even the hashes could include company details.<br />
But on the other hand: It is good when you make sure that nobody can get to your IP. Even if this is not the company IP <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  And if you have no other choice to crack that system. </p>
<p>So I would say it depence on the case, if you use it or not. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by anonymous</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5272</link>
		<dc:creator><![CDATA[anonymous]]></dc:creator>
		<pubDate>Wed, 08 May 2013 16:40:14 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5272</guid>
		<description><![CDATA[what if hashes reveal the organisation names in different probabilities and combinations? Posting it to the public databases is highly risky in my opionion.

A good alternative could be having nice wordlists with you on external drive or somethign and you can automate jtr/hash cat to come up with some passwords fast. Or add a rule to john to check different combinations of the client organisation name or frequently used string that you think is likely to be part of a password.]]></description>
		<content:encoded><![CDATA[<p>what if hashes reveal the organisation names in different probabilities and combinations? Posting it to the public databases is highly risky in my opionion.</p>
<p>A good alternative could be having nice wordlists with you on external drive or somethign and you can automate jtr/hash cat to come up with some passwords fast. Or add a rule to john to check different combinations of the client organisation name or frequently used string that you think is likely to be part of a password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by netbiosX</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5253</link>
		<dc:creator><![CDATA[netbiosX]]></dc:creator>
		<pubDate>Tue, 07 May 2013 20:49:05 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5253</guid>
		<description><![CDATA[@apentester I slightly disagree with you even though your reasons are valid. I will share my thoughts on this script and why I think that it is useful. 

First of all you can avoid sending the hash from the network of the client (if the test is internal). So this problem is solved as it will be impossible for anybody to match this hash to your client.

Secondly the majority of these websites are performing a check in their database to see if the hash is already cracked or not. In the above example the hash is well-known so in these scenarios it can save you time especially when it is impossible for them to associate the hash with your client. If the hash is already cracked by someone else and you discover it through this script then still you will mark the issue as weak password and you will report it. So in this situation the client still needs to change the password ( so the hash will change) so nobody will have nothing.

For me the only problem that I can think with the usage of this script is when a password is the name of the company. So in this situation yes all these third-party websites can associate the hash with the company. But someone can argue and say that if you don&#039;t check a system for default or weak credentials as a pen tester then definitely you are not doing something correctly.]]></description>
		<content:encoded><![CDATA[<p>@apentester I slightly disagree with you even though your reasons are valid. I will share my thoughts on this script and why I think that it is useful. </p>
<p>First of all you can avoid sending the hash from the network of the client (if the test is internal). So this problem is solved as it will be impossible for anybody to match this hash to your client.</p>
<p>Secondly the majority of these websites are performing a check in their database to see if the hash is already cracked or not. In the above example the hash is well-known so in these scenarios it can save you time especially when it is impossible for them to associate the hash with your client. If the hash is already cracked by someone else and you discover it through this script then still you will mark the issue as weak password and you will report it. So in this situation the client still needs to change the password ( so the hash will change) so nobody will have nothing.</p>
<p>For me the only problem that I can think with the usage of this script is when a password is the name of the company. So in this situation yes all these third-party websites can associate the hash with the company. But someone can argue and say that if you don&#8217;t check a system for default or weak credentials as a pen tester then definitely you are not doing something correctly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by Voyager</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5250</link>
		<dc:creator><![CDATA[Voyager]]></dc:creator>
		<pubDate>Tue, 07 May 2013 17:03:22 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5250</guid>
		<description><![CDATA[Cool tip, thx]]></description>
		<content:encoded><![CDATA[<p>Cool tip, thx</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on FindMyHash by apentester</title>
		<link>http://pentestlab.wordpress.com/2013/05/06/findmyhash/#comment-5248</link>
		<dc:creator><![CDATA[apentester]]></dc:creator>
		<pubDate>Tue, 07 May 2013 16:04:12 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=1942#comment-5248</guid>
		<description><![CDATA[I&#039;m not sure I agree with this - posting of hashes to a public site may not appropriate. Is the source IP attributable to the client - if so the owner of the site now knows password X is likely to belong to organisation Y?

Does the client approve of you posting sensitive password hashes to a website which cannot easily be verified?

Does the third-party website attempt to crack (and therefore compromise) unknown password hashes?

Most testers I know would stay clear of such sites (on a penetration test at least) for the above reasons....]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m not sure I agree with this &#8211; posting of hashes to a public site may not appropriate. Is the source IP attributable to the client &#8211; if so the owner of the site now knows password X is likely to belong to organisation Y?</p>
<p>Does the client approve of you posting sensitive password hashes to a website which cannot easily be verified?</p>
<p>Does the third-party website attempt to crack (and therefore compromise) unknown password hashes?</p>
<p>Most testers I know would stay clear of such sites (on a penetration test at least) for the above reasons&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Creating Wordlists With Crunch by Gesucht: Rar Bruteforce Programm - Nydus Underground</title>
		<link>http://pentestlab.wordpress.com/2012/07/12/creating-wordlists-with-crunch/#comment-5179</link>
		<dc:creator><![CDATA[Gesucht: Rar Bruteforce Programm - Nydus Underground]]></dc:creator>
		<pubDate>Fri, 03 May 2013 06:02:23 +0000</pubDate>
		<guid isPermaLink="false">http://pentestlab.wordpress.com/?p=958#comment-5179</guid>
		<description><![CDATA[[...]  [...]]]></description>
		<content:encoded><![CDATA[<p>[...]  [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
