<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Root777 &#187; Pen Testing</title>
	<atom:link href="http://www.root777.com/category/pen-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.root777.com</link>
	<description>Computer Security &#38; Technology</description>
	<lastBuildDate>Mon, 31 Oct 2011 01:36:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<image>
  <link>http://www.root777.com</link>
  <url>http://www.root777.com/favicon.ico</url>
  <title>Root777</title>
</image>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>The Most Popular Usernames and Passwords, a Visual Representation</title>
		<link>http://www.root777.com/pen-testing/the-most-popular-usernames-and-passwords-a-visual-representation/</link>
		<comments>http://www.root777.com/pen-testing/the-most-popular-usernames-and-passwords-a-visual-representation/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 23:55:03 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[RockYou]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[usernames]]></category>

		<guid isPermaLink="false">http://www.root777.com/?p=205</guid>
		<description><![CDATA[Dragon Research Group has compiled a list of the most popular usernames and passwords that are prevalent by SSH scanners/brute forcer attackers. It does not relate to popular account credentials such as the RockYou password research. Popular SSH Usernames Popular SSH Passwords]]></description>
			<content:encoded><![CDATA[<p><a title="Dragon Research" href="http://www.dragonresearchgroup.org/" target="_blank">Dragon Research Group</a> has compiled a list of the most popular usernames and passwords that are prevalent by SSH scanners/brute forcer attackers. It does not relate to popular account credentials such as the <a title="RockYou password research" href="http://www.nytimes.com/2010/01/21/technology/21password.html" target="_blank">RockYou password research</a>.</p>
<p><strong>Popular SSH Usernames</strong></p>
<p><strong><img class="alignleft" title="Popular SSH Usernames" src="http://farm5.static.flickr.com/4086/4994630300_3a1acaa80e_d.jpg" alt="Popular SSH Usernames" width="500" height="222" /><br />
</strong></p>
<p><strong>Popular SSH Passwords</strong></p>
<p><strong><img class="alignleft" title="Popular SSH passwords" src="http://farm5.static.flickr.com/4088/4994630294_6dc6644f23_d.jpg" alt="Popular SSH passwords" width="500" height="249" /><br />
</strong></p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=205&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/pen-testing/the-most-popular-usernames-and-passwords-a-visual-representation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ethical Hacker Network Challenge : Miracle on Thirty &#8211; Hack Street</title>
		<link>http://www.root777.com/pen-testing/ethical-hacker-network-challenge-miracle-on-thirty-hack-street/</link>
		<comments>http://www.root777.com/pen-testing/ethical-hacker-network-challenge-miracle-on-thirty-hack-street/#comments</comments>
		<pubDate>Sun, 08 Aug 2010 12:52:23 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[challenge]]></category>
		<category><![CDATA[EthicalHacker]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.root777.com/?p=202</guid>
		<description><![CDATA[The results for the Ethical Hacker Network Challenge &#8211; Miracle on Thirty Hack Street are finally in and I won a Technical Honorable Mention! The challenge was pretty good and was focussed on Facebook security or insecurity rather. Before I list my answers to the challenge, make sure to check out my blog post on [...]]]></description>
			<content:encoded><![CDATA[<p>The results for the Ethical Hacker Network Challenge &#8211; <a title="Hacker Network Challenge" href="http://www.ethicalhacker.net/content/view/285/2/" target="_blank">Miracle on Thirty Hack Street</a> are finally in and I won a <a title="Winners of Ethical Hacker Network Challenge" href="http://www.ethicalhacker.net/content/view/305/2/" target="_blank">Technical Honorable Mention</a>!</p>
<p>The challenge was pretty good and was focussed on Facebook security or insecurity rather. Before I list my answers to the challenge, make sure to check out my blog post on <a title="Facebook Privacy Settings Guide" href="http://www.root777.com/security/facebook-privacy-settings-guide/" target="_blank">Facebook privacy settings guide</a>.  The objective of this hacking challenge was to access a file on someone&#8217;s account. The way to access that person&#8217;s Facebook profile was to add that person&#8217;s friend to my friends list and then misuse the &#8220;share with friend of friends&#8221; privacy setting on Facebook.</p>
<p>Check out the <a title="Miracle on Thirty Hack Street" href="http://www.ethicalhacker.net/content/view/285/2/" target="_blank">challenge</a> first before scrolling down and see if you can solve it first.</p>
<p><span id="more-202"></span></p>
<div id="_mcePaste"><strong>Challenge Question # 1</strong>: What is the name of the following mathematical property? If a=b and b=c, then a=c.</div>
<div id="_mcePaste">The mathematical property is that of a Transitive relation</div>
<div></div>
<div id="_mcePaste"><strong>Challenge Question # 2</strong>: What FQL query or API call can be used to retrieve information about vacations from Kris Cringle’s (uid 100000565751882) Facebook account?</div>
<div id="_mcePaste"></div>
<div>fql.query is : SELECT content FROM note WHERE uid = “100000565751882”</div>
<div id="_mcePaste"><a title="FQL Query guide" href="http://wiki.developers.facebook.com/index.php/Note_(FQL)" target="_blank">http://wiki.developers.facebook.com/index.php/Note_(FQL)</a></div>
<div></div>
<div id="_mcePaste">The output</div>
<div></div>
<blockquote>
<div>While nothing can be as important to me as the night of the 24th, vacations with Mrs. Claus are a very close second! (Don&#8217;t let her know that.)</div>
<div></div>
<div>We have done many things over the years. disney was a blast. I will stay at the Swan and Dolphin again!</div>
<div></div>
<div>hawaii was tons of fun, even if Mary got a sun burn.</div>
<div></div>
<div>washington dc was impressive. I really liked the National Cryptographic Museum. The Enigma machine was cool.</div>
<div></div>
<div>norway was definitely the best though. Not only will I always remember that trip, but it will be part of my daily life from now on!</div>
<div></div>
<div>&lt;Photo 1&gt;&lt;Photo 2&gt;&lt;Photo 3&gt;&lt;Photo 4&gt;&lt;Photo 5&gt;&lt;Photo 6&gt;&lt;Photo 7&gt;</div>
</blockquote>
<div></div>
<div id="_mcePaste"><strong>Challenge Question # 3</strong>: What Facebook privacy setting allowed this data leakage? What is the default value of this setting?</div>
<div></div>
<div id="_mcePaste">The privacy setting is <strong>Posts by Me</strong> which controls privacy settings for status updates, links, notes, photos, and videos.</div>
<div id="_mcePaste"></div>
<div id="_mcePaste">The default privacy setting is not “Everyone” as a different account who is not a friend of Fred Gailey returns an empty string to the fql query from Question #2. This also rules out “Only Friends” option as well. The conclusion is “Friends of Friends” privacy setting. Santa needs to strengthen his Facebook security</div>
<div></div>
<div id="_mcePaste"><strong>Challenge Question # 4</strong>: What is the text from the decrypted message from the Judge?</div>
<div></div>
<div id="_mcePaste">The hints for the passphrase were the lowercase locations of disney, hawaii, washington and norway.</div>
<div id="_mcePaste">Trying them resulted in the secret passphrase being norway. The decrypted pdf file content:</div>
<div></div>
<blockquote>
<div id="_mcePaste" style="text-align: right;">December 9, 1901</div>
<div id="_mcePaste">Dear Mr.Santa,</div>
<div id="_mcePaste">My mom asked me to write you this letter with my Christmas wish list. I’ve always wanted a Righteous Bison Indivisible Particle Smasher for Christmas. I will use it for good – I promise!</div>
<div id="_mcePaste"></div>
<div>Here is a picture:</div>
<div id="_mcePaste"></div>
<div>&lt;attached picture&gt;</div>
<div id="_mcePaste"></div>
<div>I’ve tried to be a very good boy all year.</div>
<div id="_mcePaste" style="text-align: right;">Thank you,</div>
<div id="_mcePaste" style="text-align: right;">Henry X. Harper</div>
<div id="_mcePaste" style="text-align: right;">Age 10</div>
<div id="_mcePaste">P.S. My middle name is “X-mas”!</div>
<div id="_mcePaste"></div>
<div>P.P.S. Someday, I hope to be a judge when I grow up!</div>
<div id="_mcePaste"></div>
</blockquote>
<div><strong>Bonus Question</strong>: What other information can you pull from the Kris Cringle Facebook account (uid 100000565751882)?</div>
<div></div>
<div id="_mcePaste">1. Photo Albums and Profile Picture</div>
<div id="_mcePaste">http://www.facebook.com/photos.php?id=100000565751882</div>
<div id="_mcePaste">http://www.facebook.com/album.php?aid=-3&amp;id=100000565751882</div>
<div id="_mcePaste">fql query:</div>
<div id="_mcePaste">SELECT aid, cover_pid, owner, name, created, modified, description, location, link, size, visible FROM album WHERE owner=100000565751882 AND aid IN (aid)</div>
<div id="_mcePaste">Gives us the link to all the 18 photos and profile picture links. From there, we can navigate to the full four photo albums of Hawaii, Disney, Washington and Norway.</div>
<div id="_mcePaste"></div>
<div>2. Profile picture, profile last updated time, timezone, locale, notes count, note title</div>
<div id="_mcePaste">fql query:</div>
<div id="_mcePaste">SELECT name, pic, affiliations, profile_update_time, timezone, notes_count, locale FROM user WHERE uid=100000565751882</div>
<div id="_mcePaste">Profile picture: http://profile.ak.fbcdn.net/v22939/1987/118/s100000565751882_350.jpg</div>
<div id="_mcePaste">Profile updated: 1260040422 UNIX time or Sat 5 Dec 2009 at 7:13:42PM GMT</div>
<div id="_mcePaste">Timezone: GMT -5 or Eastern Standard Timezone</div>
<div id="_mcePaste">Notes Count &amp; Title: 1 note called Vacations</div>
<img src="http://www.root777.com/?ak_action=api_record_view&id=202&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/pen-testing/ethical-hacker-network-challenge-miracle-on-thirty-hack-street/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to crash Google Chrome</title>
		<link>http://www.root777.com/pen-testing/how-to-crash-google-chrome/</link>
		<comments>http://www.root777.com/pen-testing/how-to-crash-google-chrome/#comments</comments>
		<pubDate>Fri, 05 Sep 2008 01:25:16 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[crash]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Google chrome]]></category>

		<guid isPermaLink="false">http://www.root777.com/?p=31</guid>
		<description><![CDATA[Google claims that its browser Google Chrome is able to isolate events that may crash a browser, isolated within those individual tabs. However, an issue exists with how Google Chrome handles undefined handlers in chrome.dll version 0.2.149.27 which is the latest version of the browser. A crash can result without any user interaction. When a [...]]]></description>
			<content:encoded><![CDATA[<p>Google claims that its browser Google Chrome is able to isolate events that may crash a browser, isolated within those individual tabs. However, an issue exists with how Google Chrome handles undefined handlers in chrome.dll version 0.2.149.27 which is the latest version of the browser. A crash can result without any user interaction.</p>
<p>When a user visits a malicious link which has an undefined handler and followed by a special character, the browser crashes. You can also crash the browser by typing the characters <strong>:% </strong>in the Chrome URL bar. Google Chrome crashes with a message &#8221; Whoa! Google Chrome has crashed. Restart now?&#8221;</p>
<p><img style="vertical-align: middle;" src="http://farm4.static.flickr.com/3278/2836313558_368fc7008f_o.jpg" alt="Google Chrome crash" width="494" height="438" /></p>
<p><span id="more-31"></span></p>
<p>Tested on : Windows Vista SP1, Windows XP SP2, Windows XP SP3</p>
<p>Howto: Type :% in the Google Chrome URL bar</p>
<p>Google Chrome crashes with all Tabs</p>
<p>Proof of Concept:</p>
<p>Note: Do not hover over the link below if you are currently using Google Chrome and running something critical. Google Chrome actively links to any URL in any page. So, you don&#8217;t even have to click on the link below for Google Chrome to crash. A mere hover will do.</p>
<p><strong>PoC Working exploit to crash Google Chrome</strong>:<br />
Click for a demo <a href="http://www.root777.com/wp-admin/root777:%">HERE</a></p>
<p>According to <a title="SecuriTeam on Google Chrome" href="http://http//www.securiteam.com/securitynews/5TP010UPFU.html" target="_blank">SecuriTeam</a>, it crashes on &#8220;int3&#8243; at 0x01002FF3 as an exception/trap, followed by &#8220;POP EBP&#8221; instruction when pointed out by the EIP register at 0x01002FF4</p>
<p>UPDATE (9/7/2008): Google has patched this vulnerability in Chrome. They released an update to the browser. Please make sure you update your current version to 0.2.149.29</p>
<p><img style="vertical-align: middle;" src="http://farm4.static.flickr.com/3071/2835502513_3f42cc2bca.jpg" alt="Latest version of Google Chrome" width="430" height="340" /></p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=31&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/pen-testing/how-to-crash-google-chrome/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Physical Security &amp; Information Gathering</title>
		<link>http://www.root777.com/pen-testing/physical-security-information-gathering/</link>
		<comments>http://www.root777.com/pen-testing/physical-security-information-gathering/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 22:12:52 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[johnny long]]></category>
		<category><![CDATA[physical security]]></category>
		<category><![CDATA[video]]></category>

		<guid isPermaLink="false">http://www.root777.com/security-video/physical-security-information-gathering/</guid>
		<description><![CDATA[This is a great presentation by Johnny Long at Defcon. He talks about how easy it is to gain access to secure locations without any &#8220;hacking&#8221; aka physical security.]]></description>
			<content:encoded><![CDATA[<p>This is a great presentation by Johnny Long at Defcon. He talks about how easy it is to gain access to secure locations without any &#8220;hacking&#8221; aka physical security.</p>
<p><a href="http://www.root777.com/pen-testing/physical-security-information-gathering/"><em>Click here to view the embedded video.</em></a></p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=24&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/pen-testing/physical-security-information-gathering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The History of Hacking</title>
		<link>http://www.root777.com/security/the-history-of-hacking/</link>
		<comments>http://www.root777.com/security/the-history-of-hacking/#comments</comments>
		<pubDate>Fri, 01 Feb 2008 03:36:07 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Pen Testing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[kevin mitnick]]></category>

		<guid isPermaLink="false">http://www.root777.com/hacking/the-history-of-hacking/</guid>
		<description><![CDATA[Discovery Channel played a very interesting documentary titled &#8220;The History of Hacking&#8221;. This goes into the whole history of hacking starting with phone phreaking and Blue boxes and to the present state of hacking. However, a significant portion of this documentary tackles Social Engineering especially the most famous or rather infamous social engineer of all, [...]]]></description>
			<content:encoded><![CDATA[<p>Discovery Channel played a very interesting documentary titled &#8220;The History of Hacking&#8221;. This goes into the whole history of hacking starting with phone phreaking and Blue boxes and to the present state of hacking.</p>
<p>However, a significant portion of this documentary tackles Social Engineering especially the most famous or rather infamous social engineer of all, Kevin Mitnick. Folks in Computer Security should definitely read up on Kevin Mitnick&#8217;s books , <strong>The Art of Deception</strong> and <strong>The Art of Intrusion</strong>, both very interesting reads.</p>
<p><a href="http://www.root777.com/security/the-history-of-hacking/"><em>Click here to view the embedded video.</em></a></p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=19&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/security/the-history-of-hacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

