<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; nmap</title>
	<atom:link href="http://hackaday.com/tag/nmap/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 06:18:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; nmap</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Containing Conficker</title>
		<link>http://hackaday.com/2009/03/30/containing-conficker/</link>
		<comments>http://hackaday.com/2009/03/30/containing-conficker/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 00:22:01 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[honeynet project]]></category>
		<category><![CDATA[network scanner]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[rich mogull]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[svn]]></category>
		<category><![CDATA[whitepaper]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=9999</guid>
		<description><![CDATA[With all the noise about Conficker turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the HoneyNet Project have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-10000" title="conficker" src="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" alt="conficker" width="450" height="220" /></p>
<p>With <a title="The Internet Is Infected - CBS News Video" href="http://www.cbsnews.com/video/watch/?id=4901282n">all the noise</a> about <a title="Conficker - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Conficker">Conficker</a> turning your computer into liquid hot magma on April 1st, there&#8217;s actually some positive news. Researchers from the <a title="Honeynet Project Blog | The Honeynet Project" href="http://www.honeynet.org/">HoneyNet Project</a> have been following the worm since infections started in late 2008. They recently discovered an easy way to identify infected systems remotely. Conficker attempts to patch the MS08-067 vulnerability during infection. A flaw in the patch causes the machine to respond differently than both an unpatched system and an officially patched system. Using this knowledge, the team developed a proof of concept network scanner in python to find infected machines. You can find it in <a title="(Updated) Easily Detect Conficker Infections- Over the Network | securosis.com" href="http://securosis.com/2009/03/30/easily-detect-conficker-infections-over-the-network/">[Rich Mogull]&#8216;s initial post</a>. [Dan Kaminisky] has <a title="Tools, Tools, Tools : DoxPara Research" href="http://www.doxpara.com/?p=1291">packaged it as an EXE</a> and has instructions for how to build the SVN version of <a title="Nmap - Free Security Scanner For Network Exploration &amp; Security Audits." href="http://nmap.org/">Nmap</a>, which includes the new signature. Other network scanner vendors are adding the code as well.</p>
<p>In conjunction with this detection code, the team has also released the whitepaper <a title="Know Your Enemy: Containing Conficker | The Honeynet Project" href="http://www.honeynet.org/papers/conficker">Know Your Enemy: Containing Conficker</a>. It discusses ways to detect, contain, and remove Conficker. They&#8217;ve combined this with a <a title="Informatik IV: Containing Conficker" href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker/">tool release</a> that covers Conficker&#8217;s dynamic domain generation among other things.</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/9999/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/9999/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/9999/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=9999&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/03/30/containing-conficker/feed/</wfw:commentRss>
		<slash:comments>49</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/03/conficker.jpg" medium="image">
			<media:title type="html">conficker</media:title>
		</media:content>
	</item>
		<item>
		<title>Default password network scanning</title>
		<link>http://hackaday.com/2008/10/13/default-password-network-scanning/</link>
		<comments>http://hackaday.com/2008/10/13/default-password-network-scanning/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 22:57:40 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[default]]></category>
		<category><![CDATA[defaultpassword]]></category>
		<category><![CDATA[depant]]></category>
		<category><![CDATA[hydra]]></category>
		<category><![CDATA[midnightresearchlabs]]></category>
		<category><![CDATA[mrl]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[scan]]></category>
		<category><![CDATA[scanning]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=4756</guid>
		<description><![CDATA[Midnight Research Labs has just published a new tool. Depant will scan your network and check to see if services are using default passwords. It starts by performing an Nmap scan to discover available services on the network. It organizes these services by speed of response. Using Hydra it does brute force password checking of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=4756&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="trinity" src="http://hackadaycom.files.wordpress.com/2008/06/had_trinity.jpg?w=450&#038;h=110" alt="" width="450" height="110" /></p>
<p>Midnight Research Labs has just published a new tool. <a href="http://midnightresearch.com/pages/depant-your-network/">Depant</a> will scan your network and check to see if services are using default passwords. It starts by performing an <a href="http://nmap.org/">Nmap</a> scan to discover available services on the network. It organizes these services by speed of response. Using <a href="http://freeworld.thc.org/thc-hydra/">Hydra</a> it does brute force password checking of these services with a <a href="http://www.phenoelit-us.org/dpl/dpl.html">default password list</a>. The user can supply an alternate list for the first phase or an additional list to be used in a followup check. Depant has many different options for configuring your scan and will certainly help you find that rogue piece of hardware on your network that someone failed to set up securely.</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/4756/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/4756/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/4756/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/4756/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/4756/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/4756/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/4756/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/4756/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=4756&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/10/13/default-password-network-scanning/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_trinity.jpg" medium="image">
			<media:title type="html">trinity</media:title>
		</media:content>
	</item>
		<item>
		<title>Avoiding OS fingerprinting in Windows</title>
		<link>http://hackaday.com/2008/10/04/avoiding-os-fingerprinting-in-windows/</link>
		<comments>http://hackaday.com/2008/10/04/avoiding-os-fingerprinting-in-windows/#comments</comments>
		<pubDate>Sun, 05 Oct 2008 00:00:26 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[ettercap]]></category>
		<category><![CDATA[fingerprint]]></category>
		<category><![CDATA[fingerprinting]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[obscurity]]></category>
		<category><![CDATA[os]]></category>
		<category><![CDATA[os fingerprinting]]></category>
		<category><![CDATA[p0f]]></category>
		<category><![CDATA[satori]]></category>
		<category><![CDATA[security cloak]]></category>
		<category><![CDATA[security through obscurity]]></category>
		<category><![CDATA[TCP]]></category>
		<category><![CDATA[tcpip]]></category>

		<guid isPermaLink="false">http://hackadaycom.wordpress.com/?p=4299</guid>
		<description><![CDATA[[Irongeek] has been working on changing the OS fingerprint of his Windows box. Common network tools like Nmap, P0f, Ettercap, and NetworkMiner can determine what operating system is being run by the behavior of the TCP/IP stack. By changing this behavior, you can make your system appear to be another OS. [Irongeek] started writing his [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=4299&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-4300" title="fingerprint" src="http://hackadaycom.files.wordpress.com/2008/10/fingerprint.jpg" alt="" width="450" height="96" /></p>
<p>[Irongeek] has been working on <a href="http://www.irongeek.com/i.php?page=security/osfuscate-change-your-windows-os-tcp-ip-fingerprint-to-confuse-p0f-networkminer-ettercap-nmap-and-other-os-detection-tools">changing the OS fingerprint of his Windows box</a>. Common network tools like <a href="http://nmap.org/">Nmap</a>, <a href="http://lcamtuf.coredump.cx/p0f.shtml">P0f</a>, <a href="http://ettercap.sourceforge.net/">Ettercap</a>, and <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner">NetworkMiner</a> can determine what operating system is being run by the behavior of the TCP/IP stack. By changing this behavior, you can make your system appear to be another OS. [Irongeek] started writing his own tool by checking the source of <a href="http://www.securiteam.com/tools/5MP052KI0A.html">Security Cloak</a> to find out what registry keys needed to be changed. His OSfuscate tool lets you define your own .os fingerprint file. You can pretend to be any number of different systems from IRIX to Dreamcast. Unfortunately this only works for TCP/IP. Other methods, like <a href="http://myweb.cableone.net/xnih/mortalx.htm">Satori</a>&#8216;s DHCP based fingerprinting, still work and need to be bypassed by other means. Yes, this is just &#8220;security through obscurity&#8221;, but it is something fun to play with.</p>
<br />Posted in downloads hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/4299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/4299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/4299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/4299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/4299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/4299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/4299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/4299/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=4299&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/10/04/avoiding-os-fingerprinting-in-windows/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/10/fingerprint.jpg" medium="image">
			<media:title type="html">fingerprint</media:title>
		</media:content>
	</item>
	</channel>
</rss>
