<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jonathan Arbib &#187; Exploits</title>
	<atom:link href="http://arbib.it/category/tech-junk/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://arbib.it</link>
	<description>A bit of my work, life, and experiences.</description>
	<lastBuildDate>Wed, 18 Aug 2010 17:45:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>WPA2 broken?</title>
		<link>http://arbib.it/2010/07/29/wpa2-broken/</link>
		<comments>http://arbib.it/2010/07/29/wpa2-broken/#comments</comments>
		<pubDate>Thu, 29 Jul 2010 17:24:33 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tech Junk]]></category>
		<category><![CDATA[is wpa2 broken?]]></category>
		<category><![CDATA[wpa]]></category>
		<category><![CDATA[wpa 2]]></category>
		<category><![CDATA[wpa 2 broken]]></category>
		<category><![CDATA[wpa borken]]></category>
		<category><![CDATA[wpa2]]></category>
		<category><![CDATA[wpa2 broken]]></category>

		<guid isPermaLink="false">http://arbib.it/?p=721</guid>
		<description><![CDATA[Source: http://www.airtightnetworks.com/WPA2-Hole196 WPA2 Hole196 Vulnerability WPA2, perceived as the most solid Wi-Fi security protocol, is widely used by enterprises for securing their Wi-Fi networks. But security researchers at AirTight have uncovered a vulnerability called &#8220;Hole196&#8243; in the WPA2 security protocol that exposes WPA2-secured Wi-Fi networks to malicious insiders. Exploiting the vulnerability, an insider can bypass [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-medium wp-image-722 alignleft" title="wifi_laptop" src="http://arbib.it/wp-content/uploads/2010/07/wifi_laptop-300x218.png" alt="" width="300" height="218" />Source: <a href="http://www.airtightnetworks.com/WPA2-Hole196" target="_blank">http://www.airtightnetworks.com/WPA2-Hole196</a></p>
<p>WPA2 Hole196 Vulnerability</p>
<p>WPA2, perceived as the most solid Wi-Fi security protocol, is widely used by enterprises for securing their Wi-Fi networks. But security researchers at AirTight have uncovered a vulnerability called &#8220;Hole196&#8243; in the WPA2 security protocol that exposes WPA2-secured Wi-Fi networks to malicious insiders. Exploiting the vulnerability, an insider can bypass WPA2 private key encryption and authentication to sniff and decrypt data from other authorized users as well as scan their Wi-Fi devices for vulnerabilities, install malware and possibly compromise those Wi-Fi devices. AirTight researcher, Md. Sohail Ahmad, will be demonstrating this vulnerability at the Black Hat Arsenal and at DEFCON18  in a presentation entitled &#8220;WPA Too?!&#8221; in Las Vegas on July 29th and July 31th respectively.</p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2010/07/29/wpa2-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Generate a INVISIBLE window to boost pages</title>
		<link>http://arbib.it/2010/07/27/how-to-generate-a-invisible-window-to-boost-pages/</link>
		<comments>http://arbib.it/2010/07/27/how-to-generate-a-invisible-window-to-boost-pages/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 15:16:43 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tech Junk]]></category>
		<category><![CDATA[Tutorials]]></category>

		<guid isPermaLink="false">http://arbib.it/?p=715</guid>
		<description><![CDATA[Interesting article here: http://www.thedomz.com/2010/05/generate-invisible-window-boost-pages/]]></description>
			<content:encoded><![CDATA[<p>Interesting article here:</p>
<p><a href="http://www.thedomz.com/2010/05/generate-invisible-window-boost-pages/" target="_blank">http://www.thedomz.com/2010/05/generate-invisible-window-boost-pages/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2010/07/27/how-to-generate-a-invisible-window-to-boost-pages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MITM Attack on Smartphones whitepaper</title>
		<link>http://arbib.it/2009/11/06/mitm-attack-on-smartphones-whitepaper/</link>
		<comments>http://arbib.it/2009/11/06/mitm-attack-on-smartphones-whitepaper/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 02:38:49 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[a5.1]]></category>
		<category><![CDATA[a5/1]]></category>
		<category><![CDATA[gsm]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=262</guid>
		<description><![CDATA[From Daily Dave Mailing List SMobile has released a detailed report on research indicating that smartphone users are just as susceptible to man-in-the-middle (MITM) attacks as PC users. This report details the results of attempts to produce MITM attacks to determine whether it is possible to intercept SSL encrypted communications between various smartphone devices and [...]]]></description>
			<content:encoded><![CDATA[<p>From Daily Dave Mailing List</p>
<p>SMobile has released a detailed report on research indicating that smartphone users are just as susceptible to man-in-the-middle (MITM) attacks as PC users. This report details the results of attempts to produce MITM attacks to determine whether it is possible to intercept SSL encrypted communications between various smartphone devices and servers. Of the devices that were tested, each of the major smartphone operating systems appeared to lack the ability to natively detect and defend against MITM attacks, allowing the testing team to intercept sensitive information that should have been encrypted via SSL.</p>
<p>Paper can be downloaded here:<br />
<a style="color: #ed1c24;" href="http://threatcenter.smobilesystems.com/?page_id=1331" target="_blank">http://threatcenter.smobilesystems.com/?page_id=1331</a></p>
<p>thanks toÂ MAYANK</p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2009/11/06/mitm-attack-on-smartphones-whitepaper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RainbowCrack 1.4 is released</title>
		<link>http://arbib.it/2009/07/24/july-22-2009rainbowcrack-14-is-released/</link>
		<comments>http://arbib.it/2009/07/24/july-22-2009rainbowcrack-14-is-released/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 15:04:43 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[rainbow crack]]></category>
		<category><![CDATA[rainbow tables]]></category>
		<category><![CDATA[rainbowcrack]]></category>
		<category><![CDATA[rcrack]]></category>
		<category><![CDATA[rt]]></category>
		<category><![CDATA[rtc]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=181</guid>
		<description><![CDATA[From http://project-rainbowcrack.com/ This version focus on more effective rainbow table file format. New features: * New compact rainbow table file format (.rtc) reduce rainbow table size by 50% to 56.25% * New rt2rtc utility convert rainbow table from raw file format (.rt) to compact file format (.rtc) * New rtc2rt utility convert rainbow table from [...]]]></description>
			<content:encoded><![CDATA[<p>From http://project-rainbowcrack.com/</p>
<p>This version focus on more effective rainbow table file format. New features:</p>
<p>    * New compact rainbow table file format (.rtc) reduce rainbow table size by 50% to 56.25%<br />
    * New rt2rtc utility convert rainbow table from raw file format (.rt) to compact file format (.rtc)<br />
    * New rtc2rt utility convert rainbow table from compact file format (.rtc) to raw file format (.rt)<br />
    * The rcrack/rcrack_cuda program support both .rt and .rtc rainbow table file format<br />
    * Conversion from non-perfect to perfect rainbow table is supported by rt2rtc utility</p>
<p>Smaller rainbow table significantly improve table lookup performance!</p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2009/07/24/july-22-2009rainbowcrack-14-is-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>phpbb.com Hacked &#8211; A Thorough Description!</title>
		<link>http://arbib.it/2009/02/07/phpbbcom-hacked-a-thorough-description/</link>
		<comments>http://arbib.it/2009/02/07/phpbbcom-hacked-a-thorough-description/#comments</comments>
		<pubDate>Sat, 07 Feb 2009 12:40:48 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[Detailed Attack]]></category>
		<category><![CDATA[Detailed Attack on phpbb.com]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Password Frequency Analysis]]></category>
		<category><![CDATA[phpbb]]></category>
		<category><![CDATA[phpbb hacked]]></category>
		<category><![CDATA[phpbb.com attack]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=138</guid>
		<description><![CDATA[phpbb.com was hacked. Sites get &#8220;broken into&#8221; every day, but in this case a very thorough description was published here on how the attack was carried out. There is a lot to learn form there, even if techniques used are mostly straight forward. After the attack, someone else then ran the list of recovered passwords [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://phpbb.com" target="_blank">phpbb.com</a> was hacked. Sites get &#8220;broken into&#8221; every day, but in this case a very thorough description was published <a href="http://hackedphpbb.blogspot.com/" target="_blank">here </a>on how the attack was carried out. There is a lot to learn form there, even if techniques used are mostly straight forward. After the attack, someone else then ran the list of recovered passwords through an analysis program, and <a href="http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html" target="_blank">here</a> is what he came out with.</p>
<p>Links:</p>
<p><a href="http://phpbb.com" target="_blank">phpbb Home Page</a></p>
<p><a href="http://hackedphpbb.blogspot.com/" target="_blank">Details of Attack</a></p>
<p><a href="http://www.darkreading.com/blog/archives/2009/02/phpbb_password.html" target="_blank">Password Frequency Analysis</a></p>
<p>Happy Hacking!</p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2009/02/07/phpbbcom-hacked-a-thorough-description/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WPA PSK lookup tables: wpa_psk-h1kari_renderman</title>
		<link>http://arbib.it/2008/11/11/wpa-psk-lookup-tables-wpa_psk-h1kari_renderman/</link>
		<comments>http://arbib.it/2008/11/11/wpa-psk-lookup-tables-wpa_psk-h1kari_renderman/#comments</comments>
		<pubDate>Tue, 11 Nov 2008 19:53:22 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[Church of Wifi]]></category>
		<category><![CDATA[renderman]]></category>
		<category><![CDATA[wpa]]></category>
		<category><![CDATA[wpa password list]]></category>
		<category><![CDATA[wpa psk renderman]]></category>
		<category><![CDATA[wpa_psk-h1kari_renderman]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=65</guid>
		<description><![CDATA[Since link was broken on the Church of wifi website I got a copy though tbhost.eu. Now their link is broken. Here is an http copy and a torrent file (Please use torrent where possible&#8230;) HTTP (not possible anymore due to high bandwidth usage) Torrent Credits: HTTP Download from here (Broken Links?) Church of Wifi [...]]]></description>
			<content:encoded><![CDATA[<p>Since link was broken on the <a href="http://www.churchofwifi.org/default.asp?PageLink=Project_Display.asp?PID=90">Church of wifi website</a> I got a copy though <a href="http://tbhost.eu/rt.php?rainbowtable=81">tbhost.eu</a>. Now their link is broken. Here is an http copy and a torrent file <strong>(Please use torrent where possible&#8230;)</strong></p>
<p>HTTP (not possible anymore due to high bandwidth usage)<a href="http://ac3bf1.org/files/wpa_psk-h1kari_renderman/"><br />
</a></p>
<p><a href="http://www.mininova.org/tor/2007403">Torrent</a></p>
<p>Credits:</p>
<p>HTTP Download from <a href="http://tbhost.eu/rt.php?rainbowtable=81">here</a> (Broken Links?)<br />
<a href="http://www.churchofwifi.org/default.asp?PageLink=Project_Display.asp?PID=90">Church of Wifi</a><br />
and <a href="http://www.shmoo.com/">The Shmoo Group</a> for the previous Hosting of the torrent.</p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2008/11/11/wpa-psk-lookup-tables-wpa_psk-h1kari_renderman/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting (possible) phishing for admins?</title>
		<link>http://arbib.it/2008/10/06/interesting-possible-fishing-for-admins/</link>
		<comments>http://arbib.it/2008/10/06/interesting-possible-fishing-for-admins/#comments</comments>
		<pubDate>Mon, 06 Oct 2008 07:55:46 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[admin]]></category>
		<category><![CDATA[fishing]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[ssh client]]></category>
		<category><![CDATA[ssh iphone client]]></category>
		<category><![CDATA[ssh server]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=29</guid>
		<description><![CDATA[Read the posts on this forum Then visit the site linked at the bottom of the page, or click here That looks like phishing to me&#8230; Very simple attempt&#8230; But could be effective if indeed it IS phishing&#8230; To test it out, someone could perhaps create a &#8220;super&#8221; jailed ssh account on a system to [...]]]></description>
			<content:encoded><![CDATA[<p><img title="phishing" src="http://arbib.it/wp-content/uploads/2008/10/phishing-300x260.jpg" alt="" width="152" height="131" align="left" />Read the posts on <a href="http://forums.ilounge.com/showthread.php?t=222719" target="_blank">this forum</a></p>
<p>Then visit the site linked at the bottom of the page, or <a href="http://churchturing.org/w/iphone-ssh/" target="_blank">click here</a></p>
<p>That looks like phishing to me&#8230; Very simple attempt&#8230;</p>
<p>But could be effective if indeed it IS phishing&#8230;</p>
<p>To test it out, someone could perhaps create a &#8220;super&#8221; jailed ssh account on a system to perhaps see if someone attempts to login using those parameters&#8230; Someone wants to attempt it, and report back?</p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2008/10/06/interesting-possible-fishing-for-admins/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Steve just had his USRP confiscated</title>
		<link>http://arbib.it/2008/04/17/steve-just-had-his-usrp-confiscated/</link>
		<comments>http://arbib.it/2008/04/17/steve-just-had-his-usrp-confiscated/#comments</comments>
		<pubDate>Thu, 17 Apr 2008 20:27:29 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=10</guid>
		<description><![CDATA[Shocking news&#8230; I wonder what they will do with an Open Source Device&#8230; GSM Researcher stopped at Heathrow Airport by UK government officials]]></description>
			<content:encoded><![CDATA[<h4 class="serendipity_title">Shocking news&#8230; I wonder what they will do with an Open Source Device&#8230;</h4>
<p><a href="http://blog.thc.org/index.php?/archives/1-GSM-Researcher-stopped-at-Heathrow-Airport-by-UK-government-officials.html" target="_blank">GSM Researcher stopped at Heathrow Airport by UK government officials</a></p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2008/04/17/steve-just-had-his-usrp-confiscated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CCCC 2007 GSM A5 Cracking Talk</title>
		<link>http://arbib.it/2007/08/15/cccc-2007-gsm-a5-cracking-talk/</link>
		<comments>http://arbib.it/2007/08/15/cccc-2007-gsm-a5-cracking-talk/#comments</comments>
		<pubDate>Wed, 15 Aug 2007 21:33:10 +0000</pubDate>
		<dc:creator>ac3bf1</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Tutorials]]></category>

		<guid isPermaLink="false">http://ac3bf1.org/?p=109</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p><embed id="VideoPlayback" src="http://video.google.com/googleplayer.swf?docid=8955054591690672567&#038;hl=en&#038;fs=true" style="width:400px;height:326px" allowFullScreen="true" allowScriptAccess="always" type="application/x-shockwave-flash"> </embed></p>
]]></content:encoded>
			<wfw:commentRss>http://arbib.it/2007/08/15/cccc-2007-gsm-a5-cracking-talk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
