<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[RootCamp Forum]]></title>
	<link rel="self" href="http://rootcamp.co.kr/forum/extern.php?action=feed&amp;type=atom"/>
	<updated>2009-12-28T07:08:07Z</updated>
	<generator>PunBB</generator>
	<id>http://rootcamp.co.kr/forum/index.php</id>
		<entry>
			<title type="html"><![CDATA[Windows Audit]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=45&amp;action=new"/>
			<summary type="html"><![CDATA[<p><a href="http://windowsaudit.com/winscanx/">http://windowsaudit.com/winscanx/</a></p><p>윈도우 감사 툴입니다.</p><p>많은 양의 컴터를 감사할때 편하겠군요..</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-12-28T07:08:07Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=45&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Cloud Security and Privacy]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=44&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://ecx.images-amazon.com/images/I/51%2Bt392z0jL._BO2,204,203,200_PIsitb-sticker-arrow-click,TopRight,35,-76_AA240_SH20_OU01_.jpg" alt="http://ecx.images-amazon.com/images/I/51%2Bt392z0jL._BO2,204,203,200_PIsitb-sticker-arrow-click,TopRight,35,-76_AA240_SH20_OU01_.jpg" /></span></p><p><a href="http://www.amazon.com/exec/obidos/ASIN/0596802765/helpnetsecuri-20">http://www.amazon.com/exec/obidos/ASIN/ &#133; tsecuri-20</a></p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-12-18T08:45:39Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=44&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Perl Best Practices]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=43&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://ecx.images-amazon.com/images/I/41sTMs-txCL._BO2,204,203,200_PIsitb-sticker-arrow-click,TopRight,35,-76_AA240_SH20_OU01_.jpg" alt="http://ecx.images-amazon.com/images/I/41sTMs-txCL._BO2,204,203,200_PIsitb-sticker-arrow-click,TopRight,35,-76_AA240_SH20_OU01_.jpg" /></span></p><p><a href="http://www.amazon.com/Perl-Best-Practices-Damian-Conway/dp/0596001738">http://www.amazon.com/Perl-Best-Practic &#133; 0596001738</a></p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-12-04T00:52:59Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=43&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Building Social Web Applications]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=42&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://www.net-security.org/images/articles/socialwebapps.jpg" alt="http://www.net-security.org/images/articles/socialwebapps.jpg" /></span></p><br /><p><a href="http://www.amazon.com/exec/obidos/ASIN/0596518757/helpnetsecuri-20">http://www.amazon.com/exec/obidos/ASIN/ &#133; tsecuri-20</a></p><br /><p>시간나면 읽어봐야 겠군</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-20T01:29:05Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=42&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Mac OS X Snow Leopard Pocket Guide]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=41&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://www.net-security.org/images/articles/snowleopardguide.jpg" alt="http://www.net-security.org/images/articles/snowleopardguide.jpg" /></span></p><br /><p><a href="http://www.amazon.com/exec/obidos/ASIN/0596802722/helpnetsecuri-20#noop">http://www.amazon.com/exec/obidos/ASIN/ &#133; ri-20#noop</a></p><br /><p>스노우 레오파드의 가이드 북<br />이번에 업그레이드 했는데...</p><p>점점 맥이 좋아질라고 하네...ㅎㅎㅎ</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-20T01:27:37Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=41&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Modsecurity Handbook]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=40&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="https://www.feistyduck.com/images/modsecurity-handbook-cover.gif" alt="https://www.feistyduck.com/images/modsecurity-handbook-cover.gif" /></span></p><br /><p><a href="https://www.feistyduck.com/">https://www.feistyduck.com/</a></p><br /><br /><p>다들 알고 계시는 모드시큐리티 핸드북입니다.</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-20T01:25:22Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=40&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Report: Windows 7 security]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=39&amp;action=new"/>
			<summary type="html"><![CDATA[<p><a href="https://secure.sophos.com/security/whitepapers/index.html">https://secure.sophos.com/security/whit &#133; index.html</a></p><br /><br /><p><a href="https://secure.sophos.com/security/whitepapers/sophos-windows-7-security-wpna">https://secure.sophos.com/security/whit &#133; urity-wpna</a></p><p> <img src="http://rootcamp.co.kr/forum/img/smilies/neutral.png" width="19" height="19" alt="neutral" /></p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-10T06:21:08Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=39&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[13회 해킹방지워크샵]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=38&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://concert.or.kr/suf2009/img/m_img01.jpg" alt="http://concert.or.kr/suf2009/img/m_img01.jpg" /></span></p><p><a href="http://concert.or.kr/suf2009/">http://concert.or.kr/suf2009/</a></p><p>이런 유료군요..에궁</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-10T01:21:02Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=38&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Microsoft Web Sandbox]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=37&amp;action=new"/>
			<summary type="html"><![CDATA[<p><a href="http://websandbox.livelabs.com/Default.aspx">http://websandbox.livelabs.com/Default.aspx</a></p><p>The Web Sandbox explores how to advance the Web Platform to improve security, isolation, and quality of service protections for your web site and users.</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-04T06:56:52Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=37&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Microsoft Security Intelligence Report volume 7]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=36&amp;action=new"/>
			<summary type="html"><![CDATA[<p><a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=037f3771-330e-4457-a52c-5b085dc0a4cd&amp;displaylang=en">http://www.microsoft.com/downloads/deta &#133; laylang=en</a></p><p>MS에서 이런 보고서도 만드나 보네요</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-11-03T08:56:30Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=36&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Detecting Malice]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=35&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://www.detectmalice.com/2D_Cover2-med.png" alt="http://www.detectmalice.com/2D_Cover2-med.png" /></span></p><br /><p><a href="http://www.detectmalice.com/">http://www.detectmalice.com/</a></p><p>Robert Hansen (aka RSnake)가 쓴 300페이지에 달하는 기술서적 이라고 하네요<br />웹 어플리케이션 보안서적 같음</p><br /><p>목차<br />Detecting Malice: Preface<br />&nbsp; &nbsp; User Disposition<br />&nbsp; &nbsp; Deducing Without Knowing<br />&nbsp; &nbsp; Book Overview<br />&nbsp; &nbsp; Who Should Read This Book?<br />&nbsp; &nbsp; Why Now?<br />&nbsp; &nbsp; A Note on Style<br />&nbsp; &nbsp; Working Without a Silver Bullet<br />&nbsp; &nbsp; Special Thanks<br />&nbsp; Chapter 1 - DNS and TCP: The Foundations of Application Security<br />&nbsp; &nbsp; In the Beginning Was DNS<br />&nbsp; &nbsp; Same-Origin Policy and DNS Rebinding<br />&nbsp; &nbsp; DNS Zone Transfers and Updates<br />&nbsp; &nbsp; DNS Enumeration<br />&nbsp; &nbsp; TCP/IP<br />&nbsp; &nbsp; Spoofing and the Three-Way Handshake<br />&nbsp; &nbsp; Passive OS Fingerprinting with pOf<br />&nbsp; &nbsp; TCP Timing Analysis<br />&nbsp; &nbsp; Network DoS and DDoS Attacks<br />&nbsp; &nbsp; Attacks Against DNS<br />&nbsp; &nbsp; TCP DoS<br />&nbsp; &nbsp; Low Bandwidth DoS<br />&nbsp; &nbsp; Using DoS As Self-Defense<br />&nbsp; &nbsp; Motives for DoS Attacks<br />&nbsp; &nbsp; DoS Conspiracies<br />&nbsp; &nbsp; Port Scanning<br />&nbsp; &nbsp; With That Out of the Way...<br />&nbsp; Chapter 2 - IP Address Forensics<br />&nbsp; &nbsp; What Can an IP Address Tell You?<br />&nbsp; &nbsp; Reverse DNS Resolution<br />&nbsp; &nbsp; WHOIS Database<br />&nbsp; &nbsp; Geolocation<br />&nbsp; &nbsp; Real-Time Block Lists and IP Address Reputation<br />&nbsp; &nbsp; Related IP Addresses<br />&nbsp; &nbsp; When IP Address Is A Server<br />&nbsp; &nbsp; Web Servers as Clients<br />&nbsp; &nbsp; Dealing with Virtual Hosts<br />&nbsp; &nbsp; Proxies and Their Impact on IP Address Forensics<br />&nbsp; &nbsp; Network-Level Proxies<br />&nbsp; &nbsp; HTTP Proxies<br />&nbsp; &nbsp; AOL Proxies<br />&nbsp; &nbsp; Anonymization Services<br />&nbsp; &nbsp; Tor Onion Routing<br />&nbsp; &nbsp; Obscure Ways to Hide IP Address<br />&nbsp; &nbsp; IP Address Forensics<br />&nbsp; &nbsp; To Block or Not?<br />&nbsp; Chapter 3 - Time<br />&nbsp; &nbsp; Traffic Patterns<br />&nbsp; &nbsp; Event Correlation<br />&nbsp; &nbsp; Daylight Savings<br />&nbsp; &nbsp; Forensics and Time Synchronization<br />&nbsp; &nbsp; Humans and Physical Limitations<br />&nbsp; &nbsp; Gold Farming<br />&nbsp; &nbsp; CAPTCHA Breaking<br />&nbsp; &nbsp; Holidays and Prime Time<br />&nbsp; &nbsp; Risk Mitigation Using Time Locks<br />&nbsp; &nbsp; The Future is a Fog<br />&nbsp; Chapter 4 - Request Methods and HTTP Protocols<br />&nbsp; &nbsp; Request Methods<br />&nbsp; &nbsp; GET<br />&nbsp; &nbsp; POST<br />&nbsp; &nbsp; PUT and DELETE<br />&nbsp; &nbsp; OPTIONS<br />&nbsp; &nbsp; CONNECT<br />&nbsp; &nbsp; HEAD<br />&nbsp; &nbsp; TRACE<br />&nbsp; &nbsp; Invalid Request Methods<br />&nbsp; &nbsp; Random Binary Request Methods<br />&nbsp; &nbsp; Lowercase Method Names<br />&nbsp; &nbsp; Extraneous White Space on the Request Line<br />&nbsp; &nbsp; HTTP Protocols<br />&nbsp; &nbsp; Missing Protocol Information<br />&nbsp; &nbsp; HTTP 1.0 vs. HTTP 1.1<br />&nbsp; &nbsp; Invalid Protocols and Version Numbers<br />&nbsp; &nbsp; Newlines and Carriage Returns<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 5 - Referring URL<br />&nbsp; &nbsp; Referer Header<br />&nbsp; &nbsp; Information Leakage through Referer<br />&nbsp; &nbsp; Disclosing Too Much<br />&nbsp; &nbsp; Spot the Phony Referring URL<br />&nbsp; &nbsp; Third-Party Content Referring URL Disclosure<br />&nbsp; &nbsp; What Lurks in Your Logs<br />&nbsp; &nbsp; Referer and Search Engines<br />&nbsp; &nbsp; Language, Location, and the Politics That Comes With It<br />&nbsp; &nbsp; Google Dorks<br />&nbsp; &nbsp; Natural Search Strings<br />&nbsp; &nbsp; Vanity Search<br />&nbsp; &nbsp; Black Hat Search Engine Marketing and Optimization<br />&nbsp; &nbsp; Referring URL Availability<br />&nbsp; &nbsp; Direct Page Access<br />&nbsp; &nbsp; Meta Refresh<br />&nbsp; &nbsp; Links from SSL/TLS Sites<br />&nbsp; &nbsp; Links from Local Pages<br />&nbsp; &nbsp; Users&#039; Privacy Concerns<br />&nbsp; &nbsp; Determining Why Referer Isn&#039;t There<br />&nbsp; &nbsp; Referer Reliability<br />&nbsp; &nbsp; Redirection<br />&nbsp; &nbsp; Impact of Cross-Site Request Forgery<br />&nbsp; &nbsp; Is the Referring URL a Fake?<br />&nbsp; &nbsp; Referral Spam<br />&nbsp; &nbsp; Last thoughts<br />&nbsp; Chapter 6 - Request URL<br />&nbsp; &nbsp; What Does A Typical HTTP Request Look Like?<br />&nbsp; &nbsp; Watching For Things That Don’t Belong<br />&nbsp; &nbsp; Domain Name in the Request Field<br />&nbsp; &nbsp; Proxy Access Attempts<br />&nbsp; &nbsp; Anchor Identifiers<br />&nbsp; &nbsp; Common Request URL Attacks<br />&nbsp; &nbsp; Remote File Inclusion<br />&nbsp; &nbsp; SQL Injection<br />&nbsp; &nbsp; HTTP Response Splitting<br />&nbsp; &nbsp; NUL Byte Injection<br />&nbsp; &nbsp; Pipes and System Command Execution<br />&nbsp; &nbsp; Cross-Site Scripting<br />&nbsp; &nbsp; Web Server Fingerprinting<br />&nbsp; &nbsp; Invalid URL Encoding<br />&nbsp; &nbsp; Well-Known Server Files<br />&nbsp; &nbsp; Easter Eggs<br />&nbsp; &nbsp; Admin Directories<br />&nbsp; &nbsp; Automated Application Discovery<br />&nbsp; &nbsp; Well-Known Files<br />&nbsp; &nbsp; Crossdomain.xml<br />&nbsp; &nbsp; Robots.txt<br />&nbsp; &nbsp; Google Sitemaps<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 7 - User-Agent Identification<br />&nbsp; &nbsp; What is in a User-Agent Header?<br />&nbsp; &nbsp; Malware and Plugin Indicators<br />&nbsp; &nbsp; Software Versions and Patch Levels<br />&nbsp; &nbsp; User-Agent Spoofing<br />&nbsp; &nbsp; Cross Checking User-Agent against Other Headers<br />&nbsp; &nbsp; User-Agent Spam<br />&nbsp; &nbsp; Indirect Access Services<br />&nbsp; &nbsp; Google Translate<br />&nbsp; &nbsp; Traces of Application Security Tools<br />&nbsp; &nbsp; Common User-Agent Attacks<br />&nbsp; &nbsp; Search Engine Impersonation<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 8 - Request Header Anomalies<br />&nbsp; &nbsp; Hostname<br />&nbsp; &nbsp; Requests Missing Host Header<br />&nbsp; &nbsp; Mixed-Case Hostnames in Host and Referring URL Headers<br />&nbsp; &nbsp; Cookies<br />&nbsp; &nbsp; Cookie Abuse<br />&nbsp; &nbsp; Cookie Fingerprinting<br />&nbsp; &nbsp; Cross Site Cooking<br />&nbsp; &nbsp; Assorted Request Header Anomalies<br />&nbsp; &nbsp; Expect Header XSS<br />&nbsp; &nbsp; Headers Sent by Application Vulnerability Scanners<br />&nbsp; &nbsp; Cache Control Headers<br />&nbsp; &nbsp; Accept CSRF Deterrent<br />&nbsp; &nbsp; Language and Character Set Headers<br />&nbsp; &nbsp; Dash Dash Dash<br />&nbsp; &nbsp; From Robot Identification<br />&nbsp; &nbsp; Content-Type Mistakes<br />&nbsp; &nbsp; Common Mobile Phone Request Headers<br />&nbsp; &nbsp; X-Moz Prefetching<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 9 - Embedded Content<br />&nbsp; &nbsp; Embedded Styles<br />&nbsp; &nbsp; Detecting Robots<br />&nbsp; &nbsp; Detecting CSRF Attacks<br />&nbsp; &nbsp; Embedded JavaScript<br />&nbsp; &nbsp; Embedded Objects<br />&nbsp; &nbsp; Request Order<br />&nbsp; &nbsp; Cookie Stuffing<br />&nbsp; &nbsp; Impact of Content Delivery Networks on Security<br />&nbsp; &nbsp; Asset File Name Versioning<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 10 - Attacks Against Site Functionality<br />&nbsp; &nbsp; Attacks Against Sign-In<br />&nbsp; &nbsp; Brute-Force Attacks Against Sign-In<br />&nbsp; &nbsp; Phishing Attacks<br />&nbsp; &nbsp; Registration<br />&nbsp; &nbsp; Username Choice<br />&nbsp; &nbsp; Brute Force Attacks Against Registration<br />&nbsp; &nbsp; Account Pharming<br />&nbsp; &nbsp; What to Learn from the Registration Data<br />&nbsp; &nbsp; Fun With Passwords<br />&nbsp; &nbsp; Forgot Password<br />&nbsp; &nbsp; Password DoS Attacks<br />&nbsp; &nbsp; Don’t Show Anyone Their Passwords<br />&nbsp; &nbsp; User to User Communication<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 11 - History<br />&nbsp; &nbsp; Our Past<br />&nbsp; &nbsp; History Repeats Itself<br />&nbsp; &nbsp; Cookies<br />&nbsp; &nbsp; JavaScript Database<br />&nbsp; &nbsp; Internet Explorer Persistence<br />&nbsp; &nbsp; Flash Cookies<br />&nbsp; &nbsp; CSS History<br />&nbsp; &nbsp; Refresh<br />&nbsp; &nbsp; Same Page, Same IP, Different Headers<br />&nbsp; &nbsp; Cache and Translation Services<br />&nbsp; &nbsp; Uniqueness<br />&nbsp; &nbsp; DNS Pinning Part Two<br />&nbsp; &nbsp; Biometrics<br />&nbsp; &nbsp; Breakout Fraud<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 12 - Denial of Service<br />&nbsp; &nbsp; What Are Denial Of Service Attacks?<br />&nbsp; &nbsp; Distributed DoS Attacks<br />&nbsp; &nbsp; My First Denial of Service Lesson<br />&nbsp; &nbsp; Request Flooding<br />&nbsp; &nbsp; Identifying Reaction Strategies<br />&nbsp; &nbsp; Database DoS<br />&nbsp; &nbsp; Targeting Search Facilities<br />&nbsp; &nbsp; Unusual DoS Vectors<br />&nbsp; &nbsp; Banner Advertising DoS<br />&nbsp; &nbsp; Chargeback DoS<br />&nbsp; &nbsp; The Great Firewall of China<br />&nbsp; &nbsp; Email Blacklisting<br />&nbsp; &nbsp; Dealing With Denial Of Service Attacks<br />&nbsp; &nbsp; Detection<br />&nbsp; &nbsp; Mitigation<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 13 - Rate of Movement<br />&nbsp; &nbsp; Rates<br />&nbsp; &nbsp; Timing Differences<br />&nbsp; &nbsp; CAPTCHAs<br />&nbsp; &nbsp; Click Fraud<br />&nbsp; &nbsp; Warhol or Flash Worm<br />&nbsp; &nbsp; Samy Worm<br />&nbsp; &nbsp; Inverse Waterfall<br />&nbsp; &nbsp; Pornography Duration<br />&nbsp; &nbsp; Repetition<br />&nbsp; &nbsp; Scrapers<br />&nbsp; &nbsp; Spiderweb<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 14 - Ports, Services, APIs, Protocols and 3rd Parties<br />&nbsp; &nbsp; Ports, Services, APIs, Protocols, 3rd Parties, oh my…<br />&nbsp; &nbsp; SSL and Man in the middle Attacks<br />&nbsp; &nbsp; Performance<br />&nbsp; &nbsp; SSL/TLS Abuse<br />&nbsp; &nbsp; FTP<br />&nbsp; &nbsp; Webmail Compromise<br />&nbsp; &nbsp; Third Party APIs and Web Services<br />&nbsp; &nbsp; 2nd Factor Authentication and Federation<br />&nbsp; &nbsp; Other Ports and Services<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 15 - Browser Sniffing<br />&nbsp; &nbsp; Browser Detection<br />&nbsp; &nbsp; Black Dragon, Master Reconnaissance Tool and BeEF<br />&nbsp; &nbsp; Java Internal IP Address<br />&nbsp; &nbsp; MIME Encoding and MIME Sniffing<br />&nbsp; &nbsp; Windows Media Player “Super Cookie”<br />&nbsp; &nbsp; Virtual Machines, Machine Fingerprinting and Applications<br />&nbsp; &nbsp; Monkey See Browser Fingerprinting Software – Monkey Do Malware<br />&nbsp; &nbsp; Malware and Machine Fingerprinting Value<br />&nbsp; &nbsp; Unmasking Anonymous Users<br />&nbsp; &nbsp; Java Sockets<br />&nbsp; &nbsp; De-cloaking Techniques<br />&nbsp; &nbsp; Persistence, Cookies and Flash Cookies Redux<br />&nbsp; &nbsp; Additional Browser Fingerprinting Techniques<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 16 - Uploaded Content<br />&nbsp; &nbsp; Content<br />&nbsp; &nbsp; Images<br />&nbsp; &nbsp; Hashing<br />&nbsp; &nbsp; Image Watermarking<br />&nbsp; &nbsp; Image Stenography<br />&nbsp; &nbsp; EXIF Data In Images<br />&nbsp; &nbsp; GDI+ Exploit<br />&nbsp; &nbsp; Warez<br />&nbsp; &nbsp; Child Pornography<br />&nbsp; &nbsp; Copyrights and Nefarious Imagery<br />&nbsp; &nbsp; Sharm el Sheikh Case Study<br />&nbsp; &nbsp; Imagecrash<br />&nbsp; &nbsp; Text<br />&nbsp; &nbsp; Text Stenography<br />&nbsp; &nbsp; Blog and Comment Spam<br />&nbsp; &nbsp; Power of the Herd<br />&nbsp; &nbsp; Profane Language<br />&nbsp; &nbsp; Localization and Internationalization<br />&nbsp; &nbsp; HTML<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 17 - Loss Prevention<br />&nbsp; &nbsp; Lessons From The Offline World<br />&nbsp; &nbsp; Subliminal Imagery<br />&nbsp; &nbsp; Security Badges<br />&nbsp; &nbsp; Prevention Through Fuzzy Matching<br />&nbsp; &nbsp; Manual Fraud Analysis<br />&nbsp; &nbsp; Honeytokens<br />&nbsp; &nbsp; Summary<br />&nbsp; Chapter 18 - Wrapup<br />&nbsp; &nbsp; Mood Ring<br />&nbsp; &nbsp; Insanity<br />&nbsp; &nbsp; Blocking and the 4th Wall Problem<br />&nbsp; &nbsp; Booby Trapping Your Application<br />&nbsp; &nbsp; Heuristics Age<br />&nbsp; &nbsp; Know Thy Enemy<br />&nbsp; &nbsp; Race, Sex, Religion<br />&nbsp; &nbsp; Profiling<br />&nbsp; &nbsp; Ethnographic Landscape<br />&nbsp; &nbsp; Calculated Risks<br />&nbsp; &nbsp; Correlation and Causality<br />&nbsp; &nbsp; Conclusion<br />&nbsp; About Robert Hansen</p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-10-27T05:55:47Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=35&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Linux in a Nutshell, Sixth Edition]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=34&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://www.net-security.org/images/articles/Linuxinanutshell-cover.jpg" alt="http://www.net-security.org/images/articles/Linuxinanutshell-cover.jpg" /></span></p><p><a href="http://www.amazon.com/Linux-Nutshell-Ellen-Siever/dp/0596154488">http://www.amazon.com/Linux-Nutshell-El &#133; 0596154488</a></p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-10-22T01:57:04Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=34&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Professional Penetration Testing: Creating and Operating a Formal Hack]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=33&amp;action=new"/>
			<summary type="html"><![CDATA[<p><span class="postimg"><img src="http://ecx.images-amazon.com/images/I/417OHpozCJL._BO2,204,203,200_PIsitb-sticker-arrow-click,TopRight,35,-76_AA240_SH20_OU01_.jpg" alt="http://ecx.images-amazon.com/images/I/417OHpozCJL._BO2,204,203,200_PIsitb-sticker-arrow-click,TopRight,35,-76_AA240_SH20_OU01_.jpg" /></span></p><br /><p><a href="http://www.amazon.com/dp/1597494259?tag=thedigitalcon-20&amp;camp=14573&amp;creative=327641&amp;linkCode=as1&amp;creativeASIN=1597494259&amp;adid=0146GHM3FER1CFNJHBXA&amp;">http://www.amazon.com/dp/1597494259?tag &#133; JHBXA&amp;</a></p><p> <img src="http://rootcamp.co.kr/forum/img/smilies/big_smile.png" width="19" height="19" alt="big_smile" /></p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-10-13T08:09:55Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=33&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Netsparker: Web application security scanner]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=32&amp;action=new"/>
			<summary type="html"><![CDATA[<p><a href="http://www.mavitunasecurity.com/">http://www.mavitunasecurity.com/</a></p><p>웹 스캐너이네요..</p><p>Highlights from the latest version:<br /></p><ul><li><p>Better performance (less CPU usage, improved HTTP performance and less requests).<br />SQL injection coverage.<br />Improved Engines: LFI and Command Injection engines improved.<br />New test modules such as &quot;crossdomain.xml&quot;, &quot;Apache server-status, server-info&quot;, &quot;SVN disclosure&quot;, &quot;Find backup files&quot;, &quot;TRACE/TRACK check&quot; and some more stuff that you hate to check but have to check.</p></li></ul>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-10-12T08:36:25Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=32&amp;action=new</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Panda USB Vaccine - Version 1.0.1.4]]></title>
			<link rel="alternate" href="http://rootcamp.co.kr/forum/viewtopic.php?id=31&amp;action=new"/>
			<summary type="html"><![CDATA[<p><a href="http://research.pandasecurity.com/archive/Panda-USB-Vaccine-_2D00_-Version-1.0.1.4.aspx">http://research.pandasecurity.com/archi &#133; 0.1.4.aspx</a></p><p>판다 시큐리티에서 USB 백신을 만들었네요</p><p>다운로드<br /><a href="http://download.cnet.com/Panda-USB-Vaccine/3000-2239_4-10909938.html?part=dl-55967&amp;subj=dl&amp;tag=button">http://download.cnet.com/Panda-USB-Vacc &#133; tag=button</a></p>]]></summary>
			<author>
				<name><![CDATA[beatto]]></name>
				<uri>http://rootcamp.co.kr/forum/profile.php?id=2</uri>
			</author>
			<updated>2009-10-09T01:58:57Z</updated>
			<id>http://rootcamp.co.kr/forum/viewtopic.php?id=31&amp;action=new</id>
		</entry>
</feed>

