<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; hdmoore</title>
	<atom:link href="http://hackaday.com/tag/hdmoore/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:34:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; hdmoore</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>DNS exploit in the wild</title>
		<link>http://hackaday.com/2008/07/23/dns-exploit-in-the-wild/</link>
		<comments>http://hackaday.com/2008/07/23/dns-exploit-in-the-wild/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 02:00:00 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[cache]]></category>
		<category><![CDATA[dankaminsky]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[druid]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hdmoore]]></category>
		<category><![CDATA[matasano]]></category>
		<category><![CDATA[metasploit]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/07/23/dns-exploit-in-the-wild/</guid>
		<description><![CDATA[We&#8217;ve been tracking Metasploit commits since Matasano&#8217;s premature publication of [Dan Kaminsky]&#8216;s DNS cache poisoning flaw on Monday knowing full well that a functional exploit would be coming soon. Only two hours ago [HD Moore] and [I)ruid] added a module to the Metasploit Project that will let anyone test the vulnerability (with comment: &#8220;ZOMG. What [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2329&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img width="450" vspace="4" hspace="4" height="110" border="0" src="http://hackadaycom.files.wordpress.com/2008/06/had_switch.jpg?w=450&#038;h=110" alt="" /><br />We&#8217;ve been tracking <a href="http://metasploit.com/">Metasploit</a> commits since Matasano&#8217;s <a href="http://blog.wired.com/27bstroke6/2008/07/details-of-dns.html">premature publication</a> of [Dan Kaminsky]&#8216;s DNS cache poisoning flaw on Monday knowing full well that a functional exploit would be coming soon. Only two hours ago [HD Moore] and [I)ruid] added a module to the Metasploit Project that will let anyone test the vulnerability (with comment: &#8220;<a href="http://metasploit.com/dev/trac/browser/framework3/trunk/modules/auxiliary/spoof/dns/baliwicked_host.rb?rev=5579">ZOMG. What is this? &gt;:-)</a>&#8220;). [HD] <a href="http://blog.wired.com/27bstroke6/2008/07/dns-exploit-in.html">told Threat Level</a> that it doesn&#8217;t work yet for domains that are already cached by the DNS server, but it will automatically wait for the cached entry to expire and then complete the attack. You can read more about the bailiwicked_host.rb module <a href="http://www.caughq.org/exploits/CAU-EX-2008-0002.txt">in CAU&#8217;s advisory</a>. For a more detailed description of how the attack works, see this <a href="http://beezari.livejournal.com/141796.html">mirror of Matason&#8217;s post</a>. You can check if the DNS server you are using is vulnerable by <a href="http://www.doxpara.com/">using the tool on [Dan]&#8216;s site</a>.</p>
<p>[photo: <a href="http://flickr.com/photos/dork/413073001/">mattdork</a>]</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/2329/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/2329/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/2329/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/2329/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/2329/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=2329&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/07/23/dns-exploit-in-the-wild/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_switch.jpg" medium="image" />
	</item>
		<item>
		<title>ARP poisoning is still a problem</title>
		<link>http://hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/</link>
		<comments>http://hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/#comments</comments>
		<pubDate>Thu, 05 Jun 2008 01:00:00 +0000</pubDate>
		<dc:creator>Juan Aguilar</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[arppoisoning]]></category>
		<category><![CDATA[arpspoofing]]></category>
		<category><![CDATA[hdmoore]]></category>
		<category><![CDATA[layer2]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[mitm]]></category>

		<guid isPermaLink="false">http://hackaday.iheartcashews.com:8181/2008/06/04/arp-poisoning-is-still-a-problem/</guid>
		<description><![CDATA[You&#8217;ve no doubt heard that the site hosting Metasploit, the exploit framework, was hacked earlier this week, but what you may not have heard is that it was done using a layer 2 attack. Though Metasploit.com was not actually cracked, a server on the same VLAN was compromised and used to ARP poison the gateway. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1925&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img vspace="4" hspace="4" border="0" src="http://hackadaycom.files.wordpress.com/2008/06/had-metasploit-hacked-1.jpg" alt="" /><br />You&#8217;ve no doubt heard that the site hosting Metasploit, the exploit framework, was <a href="http://seclists.org/fulldisclosure/2008/Jun/0011.html">hacked earlier this week</a>, but what you may not have heard is that it was done <a href="http://taosecurity.blogspot.com/2008/06/old-school-layer-2-hacking.html?showComment=1212545100000#c7102389871482079713">using a layer 2 attack</a>. Though <a href="http://metasploit.com/">Metasploit.com</a> was not actually cracked, a server on the same VLAN was compromised and used to ARP poison the gateway. <a href="http://en.wikipedia.org/wiki/ARP_poisoning">ARP poisoning</a> is a method of sniffing data by sending a false ARP message to an Ethernet router to associate the hacker&#8217;s MAC address with a valid IP address from a genuine network node. From there the hackers were able to mount their MITM attack and show the image above instead of Metasploit&#8217;s website. This problem could have been avoided if the ISP was using fixed ARP entries, which is what [HD Moore] had to do to get the site back online. [Richard Bejtlich] points out that even though most people have been focusing on application security lately, <a href="http://taosecurity.blogspot.com/2008/06/old-school-layer-2-hacking.html?showComment=1212545100000#c7102389871482079713">fundamental attacks like this still happen</a>. If you&#8217;re doing a good job protecting yourself, you can still be at the mercy of the security of 3rd parties when operating in shared hosting environments.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackadaycom.wordpress.com/1925/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackadaycom.wordpress.com/1925/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/1925/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/1925/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/1925/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=1925&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/06/04/arp-poisoning-is-still-a-problem/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">juanaguilar</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had-metasploit-hacked-1.jpg" medium="image" />
	</item>
	</channel>
</rss>
