<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Context Security &#187; penetration testing</title>
	<atom:link href="http://www.contextsecurity.com/tag/penetration-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.contextsecurity.com</link>
	<description>Bringing information security into context.</description>
	<lastBuildDate>Wed, 16 Jun 2010 18:18:03 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>w3af Technical Segment on PaulDotCom Tonight</title>
		<link>http://www.contextsecurity.com/2009/03/12/w3af-technical-segment-on-pauldotcom-tonight/</link>
		<comments>http://www.contextsecurity.com/2009/03/12/w3af-technical-segment-on-pauldotcom-tonight/#comments</comments>
		<pubDate>Thu, 12 Mar 2009 18:55:15 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[pauldotcom]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[seth misenar]]></category>
		<category><![CDATA[w3af]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=90</guid>
		<description><![CDATA[Just wanted to let you all know that I will be a guest on the PaulDotcom Security Weekly podcast tonight.  I will be leading a technical segment on w3af, which is a very nifty free/open source tool for web application scanning/exploitation.  Should be loads of fun!
The live stream should go up around 1845 EDT with [...]]]></description>
			<content:encoded><![CDATA[<p>Just wanted to let you all know that I will be a guest on the PaulDotcom Security Weekly podcast tonight.  I will be leading a technical segment on w3af, which is a very nifty free/open source tool for web application scanning/exploitation.  Should be loads of fun!</p>
<p>The live stream should go up around 1845 EDT with the show starting around 1900EDT.  Further details can be found here: <a href="http://pauldotcom.com/security-weekly/" target="_blank">http://pauldotcom.com/security-weekly/</a></p>
<p>Hope to see you there.</p>
<p>Seth Misenar</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/03/12/w3af-technical-segment-on-pauldotcom-tonight/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SANS 542 Webcast: Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit</title>
		<link>http://www.contextsecurity.com/2009/02/27/sans-542-webcast-build-your-own-army-of-darkness-xss-frameworks-for-zombies-and-profit/</link>
		<comments>http://www.contextsecurity.com/2009/02/27/sans-542-webcast-build-your-own-army-of-darkness-xss-frameworks-for-zombies-and-profit/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 21:54:50 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS Teaching]]></category>
		<category><![CDATA[542]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=82</guid>
		<description><![CDATA[Below is information regarding a webcast I will be leading for SANS on 03/18/2009 at 10 AM EST.  Should be fun.
Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit
Featuring: Seth Misenar
In this preview to the newly updated SEC542 Web Application Penetration Testing course being offered in Amsterdam, you will learn how build [...]]]></description>
			<content:encoded><![CDATA[<p>Below is information regarding a webcast I will be leading for SANS on 03/18/2009 at 10 AM EST.  Should be fun.</p>
<h5>Build Your Own Army of Darkness: XSS Frameworks for Zombies and Profit</h5>
<h6>Featuring: Seth Misenar</h6>
<p>In this preview to the newly updated SEC542 Web Application Penetration Testing course being offered in Amsterdam, you will learn how build and control your very own zombie battalion/Army of Darkness.  The discussion will start with a whizz|bang overview of the new 6 day version of SEC542, and quickly move to XSS Frameworks and, of course, zombies galore. Whether you are excited or petrified by the prospect of zombies, join Seth Misenar for this hour long webcast.  As Bruce Campbell/Ash of Evil Dead fame would say, &#8220;Groovy&#8221;.</p>
<h5>Speaker Bios:</h5>
<p><strong>Seth Misenar:</strong></p>
<p>When not watching zombie films, Seth Misenar serves as Founder/Lead Consultant for Context Security, which provides information security though leadership, independent research, security training, and security consulting services. His background includes network and web application penetration testing, vulnerability assessment, regulatory compliance efforts, security architecture design, as well as general security consulting. He has previously served as both a physical and network security consultant for Fortune 100 companies as well as the HIPAA and Information Security Officer for a state government agency.</p>
<p>In his former life, Seth received a B.S. in Philosophy from Millsaps College where he was twice selected for a Ford Teaching Fellowship. Also, Seth is no stranger to certifications and thus far has achieved credentials which include, but are not limited to, the following: CISSP, GSEC, GCIA, GCIH, GCWN, GCFA, GHTQ, GWAS, and MCSE credentials. He has previously taught numerous SANS classes including SEC401: Security Essentials, SEC504: Hacker Techniques, and SEC542: Web Application Penetration Testing. In addition to serving SANS in an teaching capacity, Seth also serves as both Virtual Mentor and Technical Director for SANS OnDemand.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/02/27/sans-542-webcast-build-your-own-army-of-darkness-xss-frameworks-for-zombies-and-profit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CeWL for Pen Testers</title>
		<link>http://www.contextsecurity.com/2009/01/08/cewl-for-pen-testers/</link>
		<comments>http://www.contextsecurity.com/2009/01/08/cewl-for-pen-testers/#comments</comments>
		<pubDate>Fri, 09 Jan 2009 01:50:07 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Ed Skoudis]]></category>
		<category><![CDATA[pauldotcom]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Robin Wood]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=63</guid>
		<description><![CDATA[Shortly after flipping through Ed&#8217;s slide deck for Secrets of America&#8217;s Top Pen Testers yesterday, I noticed a fortuitous tool annoucement come across the SANS GIAC Alumni mailing list.  Robin Wood emailed to announce the release of a tool called CeWL: Custom Wordlist Generator (which is of course pronounced &#8216;cool&#8217;).
http://www.digininja.org/cewl.php
CeWL &#8220;spiders a given url to [...]]]></description>
			<content:encoded><![CDATA[<p>Shortly after flipping through Ed&#8217;s slide deck for <em>Secrets of America&#8217;s Top Pen Testers</em> yesterday, I noticed a fortuitous tool annoucement come across the SANS GIAC Alumni mailing list.  Robin Wood emailed to announce the release of a tool called CeWL: Custom Wordlist Generator (which is of course pronounced &#8216;cool&#8217;).</p>
<p>http://www.digininja.org/cewl.php</p>
<blockquote><p>CeWL &#8220;spiders a given url to a specified depth, optionally following external links, and returns a list of words which can then be used for password crackers such as <a href="http://www.openwall.com/john/">John the Ripper</a>&#8221; (from the website).</p></blockquote>
<p>Very nice. This tool dovetails nicely with Ed&#8217;s first tip from <em>SATPT</em>, &#8220;Build Password Guessing and Cracking Dictionaries&#8221;.  In fact, it turns out that the tool was based on a PaulDotCom discussion, <a href="http://pauldotcom.com/2008/11/creating-custom-wordlists-for.html" target="_blank">http://pauldotcom.com/2008/11/creating-custom-wordlists-for.html</a>, which was in turn based upon content provided in Ed&#8217;s SEC560: Network Penetration Testing, which I will be teaching in Atlanta in February, <a href="https://www.sans.org/atlanta09_cs/description.php?tid=1717" target="_blank">https://www.sans.org/atlanta09_cs/description.php?tid=1717</a>.</p>
<p>Wshew&#8230;did you follow all that.  Regardless of its origins, CeWL definitely looks like something I will be adding to my tool arsenal.  Check it out.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/01/08/cewl-for-pen-testers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ed Skoudis&#8217; &#8220;Secrets of America&#8217;s Top Pen Testers&#8221;</title>
		<link>http://www.contextsecurity.com/2009/01/08/ed-skoudis-secrets-of-americas-top-pentesters/</link>
		<comments>http://www.contextsecurity.com/2009/01/08/ed-skoudis-secrets-of-americas-top-pentesters/#comments</comments>
		<pubDate>Fri, 09 Jan 2009 01:26:58 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[560]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Skoudis]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=61</guid>
		<description><![CDATA[Ed Skoudis sent a tweet yesterday announcing the immediate availability of his presentation from SANS CDI: Secrets of America&#8217;s Top Pen Testers. Obviously you will not get the full effect without Ed&#8217;s contagious excitement, but the 38 slides do stand on their own well. He is quick to point out (via the subtitle) that he [...]]]></description>
			<content:encoded><![CDATA[<p>Ed Skoudis sent a tweet yesterday announcing the immediate availability of his presentation from SANS CDI: <em>Secrets of America&#8217;s Top Pen Testers</em>. Obviously you will not get the full effect without Ed&#8217;s contagious excitement, but the 38 slides do stand on their own well. He is quick to point out (via the subtitle) that he did not name the presentation&#8230;</p>
<p>10 nicely presented tips (with Ed&#8217;s signature black hat red screened goodnes) at no charge&#8230;</p>
<p><a title="Secrets of Americas Top Pentesters" href="http://www.inguardians.com/research/docs/Skoudis_pentestsecrets.pdf" target="_blank">http://www.inguardians.com/research/docs/Skoudis_pentestsecrets.pdf</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2009/01/08/ed-skoudis-secrets-of-americas-top-pentesters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS Phoenix 2009</title>
		<link>http://www.contextsecurity.com/2008/12/15/sans-phoenix-2009/</link>
		<comments>http://www.contextsecurity.com/2008/12/15/sans-phoenix-2009/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 03:19:23 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS Teaching]]></category>
		<category><![CDATA[401]]></category>
		<category><![CDATA[538]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[Security Essentials]]></category>
		<category><![CDATA[seth misenar]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=45</guid>
		<description><![CDATA[Seth Misenar will be teaching SANS 401: Security Essentials and 538: Web App Pen Testing Immersion at SANS Phoenix 2009.
SEC401: Security Essentials
3/23/2009-3/28/2009
SEC538: Web Application Pen Testing Immersion
3/29/2008-3/30/2009
]]></description>
			<content:encoded><![CDATA[<p>Seth Misenar will be teaching SANS 401: Security Essentials and 538: Web App Pen Testing Immersion at <a href="http://www.sans.org/phoenix09/">SANS Phoenix 2009</a>.</p>
<p>SEC401: Security Essentials<br />
3/23/2009-3/28/2009</p>
<p>SEC538: Web Application Pen Testing Immersion<br />
3/29/2008-3/30/2009</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2008/12/15/sans-phoenix-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS Secure Europe 2009 &#8211; Amsterdam</title>
		<link>http://www.contextsecurity.com/2008/12/15/sans-secure-europe-2009-amsterdam/</link>
		<comments>http://www.contextsecurity.com/2008/12/15/sans-secure-europe-2009-amsterdam/#comments</comments>
		<pubDate>Mon, 15 Dec 2008 21:31:00 +0000</pubDate>
		<dc:creator>seth</dc:creator>
				<category><![CDATA[SANS]]></category>
		<category><![CDATA[SANS Teaching]]></category>
		<category><![CDATA[542]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[seth misenar]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.contextsecurity.com/?p=34</guid>
		<description><![CDATA[Seth Misenar will be teaching SANS 542: Web Application Penetration Testing at SANS Secure Europe 2009 &#8211; Amsterdam 
SEC542: Web Application Penetration Testing
5/11/2009-5/16/2009
]]></description>
			<content:encoded><![CDATA[<p>Seth Misenar will be teaching SANS 542: Web Application Penetration Testing at <a href="http://www.sans.org/secureamsterdam09/">SANS Secure Europe 2009 &#8211; Amsterdam </a></p>
<p>SEC542: Web Application Penetration Testing<br />
5/11/2009-5/16/2009</p>
]]></content:encoded>
			<wfw:commentRss>http://www.contextsecurity.com/2008/12/15/sans-secure-europe-2009-amsterdam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
