<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The FYRM Blog &#187; GuestStealer</title>
	<atom:link href="http://blog.fyrmassociates.com/category/gueststealer/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fyrmassociates.com</link>
	<description></description>
	<lastBuildDate>Tue, 10 Aug 2010 14:50:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.fyrmassociates.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>The FYRM Blog &#187; GuestStealer</title>
		<link>http://blog.fyrmassociates.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.fyrmassociates.com/osd.xml" title="The FYRM Blog" />
	<atom:link rel='hub' href='http://blog.fyrmassociates.com/?pushpress=hub'/>
		<item>
		<title>GuestStealer Wrapup</title>
		<link>http://blog.fyrmassociates.com/2010/03/01/gueststealer-wrapup/</link>
		<comments>http://blog.fyrmassociates.com/2010/03/01/gueststealer-wrapup/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 02:30:03 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[GuestStealer]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=183</guid>
		<description><![CDATA[In addition to the previously mentioned Nmap script, GuestStealer has now made its way into a Nessus plugin and a Metasploit module. Nessus Plugin 44646 was released by Tenable a few weeks ago and the Metasploit module was pushed up to the trunk last week. GuestStealer has been mentioned in several articles and blog posts recently, including DarkReading &#8211; Tech [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=183&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In addition to the previously mentioned Nmap script, GuestStealer has now made its way into a <a title="Nessus Plugin 44646" href="http://www.nessus.org/plugins/index.php?view=single&amp;id=44646" target="_blank">Nessus plugin</a> and a <a title="Metasploit Module" href="http://www.metasploit.com/modules/auxiliary/scanner/http/vmware_server_dir_trav" target="_blank">Metasploit module</a>. Nessus Plugin 44646 was released by Tenable a few weeks ago and the Metasploit module <a title="Metasploit" href="http://carnal0wnage.attackresearch.com/node/406" target="_blank">was pushed up to the trunk last week</a>.</p>
<p>GuestStealer has been mentioned in several articles and blog posts recently, including <a title="Dark Reading - Tech Insight: Securing The Virtualized Server Environment" href="http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=222900286" target="_blank">DarkReading &#8211; Tech Insight: Securing The Virtualized Server Environment</a> and <a title="The Hacker News Network" href="http://www.hackernews.com/2010/02/15/gueststealer-released-for-cve-2009-3373/" target="_blank">The Hacker News Network</a>. While most have been accurate, several early blogs stated that GuestStealer used a cross site scripting attack to steal the guests. So to clarify and avoid any confusion, GuestStealer exploits the directory traversal vulnerability described in <a title="CVE-2009-3733" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3733" target="_blank">CVE-2009-3733</a>. For further information, check out the <a title="Stealing Guests...The VMware Way Slides" href="http://www.slideshare.net/mascasa/shmoocon-2010-stealing-guests-the-vmware-way" target="_blank">presentation slides</a> or <a href="http://www.shmoocon.org/2010/videos/GuestStealing-Morehouse.m4v" target="_blank">presentation video</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/183/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=183&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/03/01/gueststealer-wrapup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.shmoocon.org/2010/videos/GuestStealing-Morehouse.m4v" length="0" type="video/mp4" />
<enclosure url="http://www.shmoocon.org/2010/videos/GuestStealing-Morehouse.m4v" length="0" type="video/mp4" />
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
		<item>
		<title>GuestStealer 1.1 and PaulDotCom Webcast</title>
		<link>http://blog.fyrmassociates.com/2010/02/18/gueststealer-1-1-and-smart-grid-book-updates/</link>
		<comments>http://blog.fyrmassociates.com/2010/02/18/gueststealer-1-1-and-smart-grid-book-updates/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 00:11:59 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[GuestStealer]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=177</guid>
		<description><![CDATA[Justin and I will be on the PaulDotCom podcast tonight to discuss the latest developments with GuestStealer and the Smart Grid book. For more information, check out tonight&#8217;s episode guide and join the live discussion tonight. Also, GuestStealer v1.1 is now available for download. This is a bug fix release that improves the error handling [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=177&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Justin and I will be on the <a title="PaulDotCom Podcast" href="http://pauldotcom.com/live" target="_blank">PaulDotCom</a> podcast tonight to discuss the latest developments with GuestStealer and the Smart Grid book. For more information, check out tonight&#8217;s <a title="PaulDotCom Episode 187" href="http://pauldotcom.com/wiki/index.php/Episode187#Guest_Interview:_Justin_Morehouse_and_Tony_Flick" target="_blank">episode guide</a> and join the live discussion tonight.</p>
<p>Also, GuestStealer v1.1 is now available for download. This is a bug fix release that improves the error handling and prevention of downloading the same vmdk file twice (when that vmdk self-references itself). Thanks to the efforts by Ron at <a title="SkullSecurity" href="http://www.skullsecurity.org/blog/" target="_blank">Skull Security</a>, the new version is available on the <a title="FYRM Tools" href="http://www.fyrmassociates.com/tools.html" target="_blank">tools page</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/177/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=177&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/02/18/gueststealer-1-1-and-smart-grid-book-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
	</channel>
</rss>
