<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The FYRM Blog &#187; ShmooCon</title>
	<atom:link href="http://blog.fyrmassociates.com/category/shmoocon/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fyrmassociates.com</link>
	<description></description>
	<lastBuildDate>Tue, 10 Aug 2010 14:50:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.fyrmassociates.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/29bd7a6974e2b2222578faa640e336b0?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>The FYRM Blog &#187; ShmooCon</title>
		<link>http://blog.fyrmassociates.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.fyrmassociates.com/osd.xml" title="The FYRM Blog" />
	<atom:link rel='hub' href='http://blog.fyrmassociates.com/?pushpress=hub'/>
		<item>
		<title>GuestStealer Wrapup</title>
		<link>http://blog.fyrmassociates.com/2010/03/01/gueststealer-wrapup/</link>
		<comments>http://blog.fyrmassociates.com/2010/03/01/gueststealer-wrapup/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 02:30:03 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[GuestStealer]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=183</guid>
		<description><![CDATA[In addition to the previously mentioned Nmap script, GuestStealer has now made its way into a Nessus plugin and a Metasploit module. Nessus Plugin 44646 was released by Tenable a few weeks ago and the Metasploit module was pushed up to the trunk last week. GuestStealer has been mentioned in several articles and blog posts recently, including DarkReading &#8211; Tech [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=183&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In addition to the previously mentioned Nmap script, GuestStealer has now made its way into a <a title="Nessus Plugin 44646" href="http://www.nessus.org/plugins/index.php?view=single&amp;id=44646" target="_blank">Nessus plugin</a> and a <a title="Metasploit Module" href="http://www.metasploit.com/modules/auxiliary/scanner/http/vmware_server_dir_trav" target="_blank">Metasploit module</a>. Nessus Plugin 44646 was released by Tenable a few weeks ago and the Metasploit module <a title="Metasploit" href="http://carnal0wnage.attackresearch.com/node/406" target="_blank">was pushed up to the trunk last week</a>.</p>
<p>GuestStealer has been mentioned in several articles and blog posts recently, including <a title="Dark Reading - Tech Insight: Securing The Virtualized Server Environment" href="http://www.darkreading.com/vulnerability_management/security/management/showArticle.jhtml?articleID=222900286" target="_blank">DarkReading &#8211; Tech Insight: Securing The Virtualized Server Environment</a> and <a title="The Hacker News Network" href="http://www.hackernews.com/2010/02/15/gueststealer-released-for-cve-2009-3373/" target="_blank">The Hacker News Network</a>. While most have been accurate, several early blogs stated that GuestStealer used a cross site scripting attack to steal the guests. So to clarify and avoid any confusion, GuestStealer exploits the directory traversal vulnerability described in <a title="CVE-2009-3733" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3733" target="_blank">CVE-2009-3733</a>. For further information, check out the <a title="Stealing Guests...The VMware Way Slides" href="http://www.slideshare.net/mascasa/shmoocon-2010-stealing-guests-the-vmware-way" target="_blank">presentation slides</a> or <a href="http://www.shmoocon.org/2010/videos/GuestStealing-Morehouse.m4v" target="_blank">presentation video</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/183/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/183/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/183/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=183&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/03/01/gueststealer-wrapup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.shmoocon.org/2010/videos/GuestStealing-Morehouse.m4v" length="0" type="video/mp4" />
<enclosure url="http://www.shmoocon.org/2010/videos/GuestStealing-Morehouse.m4v" length="0" type="video/mp4" />
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
		<item>
		<title>GuestStealer 1.1 and PaulDotCom Webcast</title>
		<link>http://blog.fyrmassociates.com/2010/02/18/gueststealer-1-1-and-smart-grid-book-updates/</link>
		<comments>http://blog.fyrmassociates.com/2010/02/18/gueststealer-1-1-and-smart-grid-book-updates/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 00:11:59 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[GuestStealer]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Virtualization Security]]></category>
		<category><![CDATA[Vulnerability Assessment]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=177</guid>
		<description><![CDATA[Justin and I will be on the PaulDotCom podcast tonight to discuss the latest developments with GuestStealer and the Smart Grid book. For more information, check out tonight&#8217;s episode guide and join the live discussion tonight. Also, GuestStealer v1.1 is now available for download. This is a bug fix release that improves the error handling [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=177&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Justin and I will be on the <a title="PaulDotCom Podcast" href="http://pauldotcom.com/live" target="_blank">PaulDotCom</a> podcast tonight to discuss the latest developments with GuestStealer and the Smart Grid book. For more information, check out tonight&#8217;s <a title="PaulDotCom Episode 187" href="http://pauldotcom.com/wiki/index.php/Episode187#Guest_Interview:_Justin_Morehouse_and_Tony_Flick" target="_blank">episode guide</a> and join the live discussion tonight.</p>
<p>Also, GuestStealer v1.1 is now available for download. This is a bug fix release that improves the error handling and prevention of downloading the same vmdk file twice (when that vmdk self-references itself). Thanks to the efforts by Ron at <a title="SkullSecurity" href="http://www.skullsecurity.org/blog/" target="_blank">Skull Security</a>, the new version is available on the <a title="FYRM Tools" href="http://www.fyrmassociates.com/tools.html" target="_blank">tools page</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/177/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/177/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/177/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=177&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/02/18/gueststealer-1-1-and-smart-grid-book-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
		<item>
		<title>ShmooCon 2010 Stealing Guests&#8230; Slides Online</title>
		<link>http://blog.fyrmassociates.com/2010/02/10/shmoocon-2010-stealing-guests-slides-online/</link>
		<comments>http://blog.fyrmassociates.com/2010/02/10/shmoocon-2010-stealing-guests-slides-online/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 04:51:31 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[ShmooCon]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[Virtualization Security]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=169</guid>
		<description><![CDATA[Luckily I was able to escape Washington DC&#8217;s 3rd round of snow to enjoy the tropical 40 degree weather here in Tampa today and write this post. Despite the blizzard and its many names, the ShmooCon faithful came out in full force to make another great conference. As usual, ShmooCon featured interesting presentations, shenanigans, and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=169&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Luckily I was able to escape Washington DC&#8217;s 3rd round of snow to enjoy the tropical 40 degree weather here in Tampa today and write this post. Despite the blizzard and its many names, the ShmooCon faithful came out in full force to make another great conference. As usual, ShmooCon featured interesting presentations, shenanigans, and a chance to hang out with those friends you usually only see at Cons.</p>
<p>I want to thank everyone who attended the <a title="Stealing Guests...The VMware Way" href="http://www.shmoocon.org/presentations-all.html#stealingguests" target="_blank">Stealing Guests&#8230;The VMware Way</a> talk, especially since no one threw shmooballs at us. For those of you who haven&#8217;t done so yet, head on over to the <a title="FYRM Associates Tools" href="http://fyrmassociates.com/tools.html" target="_blank">Tools</a> section of the Web site to grab GuestStealer and try it out yourself. Also, Ron over at Skull Security created an Nmap script to identify vulnerable VMware systems. Visit his <a title="Skull Security Nmap VMware Blog" href="http://www.skullsecurity.org/blog/?p=436" target="_blank">blog</a> to download the script and view instructions for installing the script.</p>
<p>For those of you who were unable to attend the talk&#8230;or find a video, here are the <a title="ShmooCon 2010 Presentation Slides" href="http://www.slideshare.net/mascasa/shmoocon-2010-stealing-guests-the-vmware-way" target="_blank">slides</a>.</p>
<p>I would also like to thank everyone who came up to the FYRM booth and talked to Matt and I. The security bug killing/reaction time testing flash game appeared to be a big hit, which drew many contestants&#8230;some more determined than others. For those of you that didn&#8217;t win this time, check back often to find out details for round 2!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/169/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/169/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/169/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/169/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/169/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/169/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/169/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/169/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=169&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/02/10/shmoocon-2010-stealing-guests-slides-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
		<item>
		<title>Stealing Guests&#8230;For a Free Hard Drive</title>
		<link>http://blog.fyrmassociates.com/2010/02/02/stealing-guests-for-a-free-hard-drive/</link>
		<comments>http://blog.fyrmassociates.com/2010/02/02/stealing-guests-for-a-free-hard-drive/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 06:15:56 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[ShmooCon]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=163</guid>
		<description><![CDATA[During the Stealing Guests&#8230;The VMware Way presentation at ShmooCon this weekend, FYRM will be holding a contest to give away an external hard drive. The first person to exploit the discussed vulnerability on the target virtual machine and yell out the hidden phrase will win the hard drive. In the presentation, a Perl script will be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=163&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>During the <a title="Stealing Guests...The VMware Way" href="http://shmoocon.org/presentations-all.html#stealingguests" target="_blank">Stealing Guests&#8230;The VMware Way</a> presentation at ShmooCon this weekend, FYRM will be holding a contest to give away an external hard drive. The first person to exploit the discussed vulnerability on the target virtual machine and yell out the hidden phrase will win the hard drive.</p>
<p>In the presentation, a Perl script will be released to easily exploit the vulnerability. The to-be-released tool runs on Mac OS X (with MacPorts) and most Linux distros. Currently, the tool requires the following Perl dependencies:</p>
<ul>
<li>LWP::Simple</li>
<li>XML::Simple</li>
<li>Data::Dumper</li>
<li>Crypt::SSLeay</li>
</ul>
<p>Bring your laptops and netbooks to the presentation to try the tool and win the hard drive. Check back often for any updates.</p>
<ul></ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/163/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/163/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/163/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/163/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/163/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/163/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/163/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/163/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=163&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/02/02/stealing-guests-for-a-free-hard-drive/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
	</channel>
</rss>