<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.9.1" -->
<rss version="0.92">
<channel>
	<title>eleventh alliance</title>
	<link>http://www.11a.nu</link>
	<description></description>
	<lastBuildDate>Mon, 11 Dec 2006 04:12:00 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Screencast of WEP cracking posted</title>
		<description><![CDATA[A while back me and Johan Johari did a presentation on the topic of wireless security and OpenWRT. As part of the presentation we conducted a demo of WEP cracking, but due to problematic hardware and time restrictions we were unable to complete the WEP cracking demonstration. So here is, as promised, a AVI file [...]]]></description>
		<link>http://proxy.11a.nu/2006/12/11/screencast-of-wep-cracking-posted/</link>
			</item>
	<item>
		<title>SoHo Honeypot Update</title>
		<description><![CDATA[I thought we were well overdue for a status update on the Linksys honeypot project so here it is.
Project Goal:
Create custom firmware for cheap consumer router to give them honeypot/honeynet capabilities.
Sub projects:
Re-direction of &#8220;dropped&#8221; packets

Status: Planning stage
Details: At the first look it&#8217;s the easiest thing to do, but routing, VPN and TTL issues are not [...]]]></description>
		<link>http://proxy.11a.nu/2006/11/12/soho-honeypot-update/</link>
			</item>
	<item>
		<title>Software supported ISO27001:2005 certification process</title>
		<description><![CDATA[ Once in a while I get to sit down and talk to software vendors and distributors about their software offerings. Recently I got the chance to spend some time with Eric Lachapelle, CEO of Veridion, to look through the Proteus™ software application that helps you with your ISO27001:2005 certification. The software comes in 4 [...]]]></description>
		<link>http://proxy.11a.nu/2006/08/02/software-supported-iso270012005-certification-process/</link>
			</item>
	<item>
		<title>Securing SSH access with pam_captcha</title>
		<description><![CDATA[Anyone who runs their SSH service on the default port, and have it accessable to the world, should by now noticed the huge amount of mindless banging on the door in terms of automated attempts to gain access to your system by guessing the password for (possible) user accounts. This is not a danger in [...]]]></description>
		<link>http://proxy.11a.nu/2006/06/05/securing-ssh-access-with-pam_captcha/</link>
			</item>
	<item>
		<title>SguilCD 0.6.1 Development Started</title>
		<description><![CDATA[I&#8217;ve started to work on SguilCD 0.6.1 and I&#8217;ve uploaded several RPM&#8217;s to http://www.boseco.com/download/?get=/Sguil/BETA for you to test out. Please report any problems using the forum.
This is beta software, no official support will be given and they have only been tested so far as they compile cleanly. The RPMs are compiled for CentOS 4 (a [...]]]></description>
		<link>http://proxy.11a.nu/2006/04/13/sguilcd-061-development-started/</link>
			</item>
	<item>
		<title>Bejtlich / Bianco ShmooCon Video Online</title>
		<description><![CDATA[I&#8217;ve mirrored an excellent talk by Bejtlich / Bianco on the topic of Network Security Monitoring and Sguil which was presented at ShmooCon earlier this year.

]]></description>
		<link>http://proxy.11a.nu/2006/04/10/bejtlich-bianco-shmoocon-video-online/</link>
			</item>
	<item>
		<title>Audio of my talk at EUSecWest 06 posted</title>
		<description><![CDATA[I&#8217;ve finally moved over to another hosting provider that offers me the storage and bandwidth I require for my growing sites, and I can finally offer you the recording of my EUSecWest 06 presentation about Network Security Monitoring: Theory and Practice.
Just to note that Mr. Murphy was present at the conference, and the demo was [...]]]></description>
		<link>http://proxy.11a.nu/2006/03/30/audio-of-my-talk-at-eusecwest-06-posted/</link>
			</item>
	<item>
		<title>End of the Wordpress saga</title>
		<description><![CDATA[Matt has updated the Wordpress 2.0.2 release notification and properly given credit to my contribution to make Wordpress a more secure software.
As I understand it there was some lack of communication within the Wordpress team when Matt wrote the release advisory and was never informed about my contribution. I still hope that the Wordpress team [...]]]></description>
		<link>http://proxy.11a.nu/2006/03/20/end-of-the-wordpress-saga/</link>
			</item>
	<item>
		<title>Cross Site Scripting vulnerability in Wordpress 2.0.1</title>
		<description><![CDATA[This blog post was originally published on the 4th March 2006, but was removed until a patched version of Wordpress was released to give the Wordpress users out there a chance to update their installations.

Wordpress 2.0.1 has an reflected Cross Site Scripting vulnerability in /wp-admin/options-general.php. You need to be logged in to use it. The [...]]]></description>
		<link>http://proxy.11a.nu/2006/03/17/xss-in-wordpress-201/</link>
			</item>
	<item>
		<title>Responsible Disclosure of Security Vulnerabilities</title>
		<description><![CDATA[Recently I reported a Cross Site Scripting vulnerability in Wordpress to their security team, and complied with their every demand (and suggestion) - including unpublished my finding report on this website until a patched version is released and people have had a chance to upgrade. The problem is that they never gave me credit for [...]]]></description>
		<link>http://proxy.11a.nu/2006/03/13/responsible-disclosure-of-security-vulnerabilities/</link>
			</item>
</channel>
</rss>
