<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Testing Tools Blog - Testertools &#187; Security Testing</title>
	<atom:link href="http://www.testertools.com/blog/category/security-testing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.testertools.com/blog</link>
	<description>The latest news and blog information from testertools.com</description>
	<lastBuildDate>Fri, 03 Feb 2012 11:24:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>GUI Tool Reveals SQL Injection Vulnerabilities</title>
		<link>http://www.testertools.com/blog/gui-tool-reveals-sql-injection-vulnerabilities/</link>
		<comments>http://www.testertools.com/blog/gui-tool-reveals-sql-injection-vulnerabilities/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 12:46:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Dan Kuykendall]]></category>
		<category><![CDATA[NT OBJECTives.]]></category>
		<category><![CDATA[NTO SQL Invader]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2326</guid>
		<description><![CDATA[<br/>A free utility that you can use to demonstrate SQL injection vulnerabilities in web apps has been released by web security  specialists, NT OBJECTives.
NTO SQL Invader is interesting because it isn&#8217;t designed to find the  vulnerability; instead, the aim is to give you a way to show how the  vulnerability could be ]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://ww1.prweb.com/prfiles/2011/10/10/9023695/gI_60000_NTOlogo.jpg"><img class="alignleft" src="http://ww1.prweb.com/prfiles/2011/10/10/9023695/gI_60000_NTOlogo.jpg" alt="" width="250" height="250" /></a>A free utility that you can use to demonstrate<strong> SQL injection</strong> vulnerabilities in web apps has been released by web security  specialists, <strong><a href="http://www.ntobjectives.com/">NT OBJECTives</a>.</strong></p>
<p><strong>NTO SQL Invader</strong> is interesting because it isn&#8217;t designed to find the  vulnerability; instead, the aim is to give you a way to show how the  vulnerability could be exploited.</p>
<p>NTO SQL Invader Provides Pen Testers and Developers the Ability to Quickly and Easily Exploit and Demonstrate SQL Injection Vulnerabilities in Web Applications<br />
NT OBJECTives, a provider of automated, comprehensive and accurate Web Application security software, services and SaaS, today announced the availability of NTO SQL Invader, a free tool which provides pen testers and developers the ability to quickly and easily exploit and demonstrate SQL Injection vulnerabilities in Web applications.</p>
<p>Most organizations understand that SQL Injection vulnerabilities put their sensitive data at risk and it has been the dominant method used in this year’s high-profile web application attacks; with millions of sites attacked in 2011.</p>
<p>Despite the fact that SQL Injection is well documented and there are tools to discover the vulnerabilities, it has been very difficult to determine if the vulnerability can actually be exploited because most existing SQL Injection testing tools are executed from a command line, lack an intuitive user interface or are no longer supported. Without the ability to clearly demonstrate the exploitability of a vulnerability, remediation efforts are often delayed and friction between security and development teams surfaces. NTO SQL Invader allows pen testers and developers to quickly and easily leverage a vulnerability to view the list of records, tables and user accounts on the back-end database.</p>
<p>With a few simple clicks in NTO SQL Invader, a user can exploit a web application vulnerability that was discovered manually or from a Dynamic Application Security Testing (DAST) tool like NTOSpider. NTO SQL Invader works as a stand-alone tool and also includes integration with NTOSpider’s reporting technology to assist pen testers and developers in quickly identifying and validating discovered vulnerabilities. While reviewing and confirming results from NTOSpider, users can leverage NTO SQL Invader to provide a polished, real-world proof-of-concept for the discovered SQL Injection vulnerabilities.<br />
&#8220;Accurate vulnerability identification is a crucial and challenging task but it is only half the battle,” says<strong> Dan Kuykendall</strong>, co-CEO and Chief Technology Officer of NT OBJECTives. “We wanted to support organizations in their analysis and remediation efforts by providing an easy to use tool that enables penetration testers to demonstrate how these vulnerabilities can be exploited. We felt it was important to provide a free and useful tool to our customers and to the entire community.”</p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/gui-tool-reveals-sql-injection-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Euro countries announce plans to ban hacking and pen testing tools</title>
		<link>http://www.testertools.com/blog/euro-countries-announce-plans-to-ban-hacking-and-pen-testing-tools/</link>
		<comments>http://www.testertools.com/blog/euro-countries-announce-plans-to-ban-hacking-and-pen-testing-tools/#comments</comments>
		<pubDate>Mon, 20 Jun 2011 17:00:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Performance Testing]]></category>
		<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[penetration testing tools]]></category>
		<category><![CDATA[techworld.com]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2225</guid>
		<description><![CDATA[<br/>According to a report in techworld.com European countries have announced plans to ban hacking and penetration testing tools
Justice Ministers across Europe want to make the creation of &#8220;hacking  tools&#8221; a criminal offence, but critics have hit back at the plans,  saying that they are unworkable.
Ministers from all 27 countries of the European Union ]]></description>
			<content:encoded><![CDATA[<br/><p><strong><a href="http://flagspot.net/images/e/eu-eun.gif"><img class="alignleft" src="http://flagspot.net/images/e/eu-eun.gif" alt="" width="324" height="216" /></a></strong>According to a report in <a href="http://techworld.com" target="_blank">techworld.com</a> European countries have announced plans to ban <strong>hacking </strong>and <strong>penetration testing tools</strong></p>
<blockquote><p><strong>Justice Ministers</strong> across Europe want to make the creation of &#8220;hacking  tools&#8221; a criminal offence, but critics have hit back at the plans,  saying that they are unworkable.</p>
<p>Ministers from all 27 countries of the European Union met on June 9  to discuss European Commission proposals for a directive on attacks  against information systems. But in addition to approving the  Commission&#8217;s text, the ministers extended the draft to include &#8220;the  production and making available of tools for committing offences&#8221;.</p>
<p>This is problematic, as much legal and legitimate software could be  put to criminal use by hackers. The draft mentions &#8220;malicious software  designed to create botnets or unrightfully obtained computer passwords,&#8221;  but goes no further in attempting to clarify what &#8220;tools&#8221; might be  subject to criminal sanctions.</p></blockquote>
<p>To read the full article read <a href="http://news.techworld.com/security/3286274/european-countries-want-to-ban-hacking-and-penetration-testing-tools/">European countries want to ban hacking and penetration testing tools</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/euro-countries-announce-plans-to-ban-hacking-and-pen-testing-tools/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon EC2 Used to Crack Password Encryption on Wireless Networks</title>
		<link>http://www.testertools.com/blog/amazon-ec2-used-to-crack-password-encryption-on-wireless-networks/</link>
		<comments>http://www.testertools.com/blog/amazon-ec2-used-to-crack-password-encryption-on-wireless-networks/#comments</comments>
		<pubDate>Tue, 11 Jan 2011 09:03:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[Black Hat DC]]></category>
		<category><![CDATA[Thomas Roth]]></category>
		<category><![CDATA[WPA-PSK]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2108</guid>
		<description><![CDATA[<br/>According to a report in eweek &#8211; A security researcher will reveal at Black Hat DC how he deployed   password-testing software on Amazon EC2 to break into a secured wireless   network using WPA-PSK.
Titled &#8216;Amazon EC2 Used to Crack Password Encryption on Wireless Networks&#8217;  the hack took only 20 Minutes to complete:
Specialized ]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://www.eweek.com/images/zde/eweek-logo.gif"><img class="alignleft" src="http://www.eweek.com/images/zde/eweek-logo.gif" alt="" width="227" height="47" /></a>According to a report in eweek &#8211; A security researcher will reveal at <strong>Black Hat DC </strong>how he deployed   password-testing software on <strong>Amazon EC2</strong> to break into a secured wireless   network using <strong>WPA-PSK</strong>.</p>
<p>Titled &#8216;Amazon EC2 Used to Crack Password Encryption on Wireless Networks&#8217;  the hack took only 20 Minutes to complete:</p>
<blockquote><p>Specialized software running over Amazon&#8217;s cloud services can be used to crack passwords on wireless networks, said a German security researcher on Jan. 7.<strong>Thomas Roth</strong>, a security and software engineering consultant at Lanworks AG, in Cologne, Germany, will be publicizing his research at the Black Hat conference in Washington, D.C., Jan. 16-17.</p></blockquote>
<p>To read the full article read <a href="http://www.eweek.com/c/a/Security/Amazon-EC2-Used-to-Crack-Password-Encryption-on-Wireless-Networks-490541/">Amazon EC2 Used to Crack Password Encryption on Wireless Networks</a>.</p>
<blockquote></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/amazon-ec2-used-to-crack-password-encryption-on-wireless-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title></title>
		<link>http://www.testertools.com/blog/2091/</link>
		<comments>http://www.testertools.com/blog/2091/#comments</comments>
		<pubDate>Mon, 27 Dec 2010 23:43:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Core Impact Pro]]></category>
		<category><![CDATA[Core Insight Enterprise]]></category>
		<category><![CDATA[Mark Hatton]]></category>
		<category><![CDATA[Robert Westervelt]]></category>
		<category><![CDATA[SearchSecurity.com]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2091</guid>
		<description><![CDATA[<br/>SearchSecurity.com have featured an article on a new Penetration Testing Software Release.
Written by Robert Westervelt, Core Security launches CISO-level pen testing software the article dicusses the release of a new tool and its features.
Core Security Technologies is introducing new pen testing software that, according to the company, has robust reporting capabilities,  enabling CIOs, CISOs ]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://SearchSecurity.com"><a href="http://media.techtarget.com/searchSecurity/images/header_logo2.gif"><img class="alignleft" src="http://media.techtarget.com/searchSecurity/images/header_logo2.gif" alt="" width="291" height="51" /></a>SearchSecurity.com</a> have featured an article on a new Penetration Testing Software Release.</p>
<p>Written by <strong>Robert Westervelt</strong>, <strong>Core Security launches CISO-level pen testing software </strong>the article dicusses the release of a new tool and its features.</p>
<blockquote><p>Core Security Technologies is introducing new <a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1380106,00.html">pen testing software</a> that, according to the company, has robust reporting capabilities,  enabling CIOs, CISOs and other executives to gauge risk to internal  systems and gain greater visibility into the progress of ongoing  security initiatives.</p>
<p>The Boston-based penetration testing firm, best known for its <strong>Core  Impact Pro</strong> software for pen testers, launched <strong>Core Insight Enterprise</strong> on  Monday.  The new tool can be programmed to view critical systems and  their connection points and then can be set to conduct multiple,  automated pen tests in an attempt to find a way into the company&#8217;s most  critical assets, said <strong>Mark Hatton</strong>, CEO of Core Security Technologies  Inc.</p></blockquote>
<p>To read more <a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1525167,00.html">click here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/2091/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Veracode offers channel “zero touch” SaaS</title>
		<link>http://www.testertools.com/blog/veracode-offers-channel-%e2%80%9czero-touch%e2%80%9d-saas/</link>
		<comments>http://www.testertools.com/blog/veracode-offers-channel-%e2%80%9czero-touch%e2%80%9d-saas/#comments</comments>
		<pubDate>Thu, 16 Dec 2010 20:40:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Performance Testing]]></category>
		<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[EMEA]]></category>
		<category><![CDATA[Global Partner Programme]]></category>
		<category><![CDATA[Matt Peachey]]></category>
		<category><![CDATA[Nebulas]]></category>
		<category><![CDATA[Peachey]]></category>
		<category><![CDATA[Pentura]]></category>
		<category><![CDATA[SecurityReview]]></category>
		<category><![CDATA[Veracode]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2073</guid>
		<description><![CDATA[<br/>Veracode is actively recruiting channel partners for a new cloud-based platform that allows partners and users to verify application security independently in both internally developed and third-party software without requiring source code or expensive in-house tools.
The launch of its Global Partner Programme will certify partners to sell its SecurityReview security verification solution delivered as software-as-a-service. ]]></description>
			<content:encoded><![CDATA[<br/><p><strong><a href="http://www.406ventures.com/images/companies/16/0x45/1/logo_image-veracode.png"><img class="alignleft" src="http://www.406ventures.com/images/companies/16/0x45/1/logo_image-veracode.png" alt="" width="245" height="38" /></a>Veracode </strong>is actively recruiting channel partners for a new cloud-based platform that allows partners and users to verify application security independently in both internally developed and third-party software without requiring source code or expensive in-house tools.</p>
<p>The launch of its <strong>Global Partner Programme</strong> will certify partners to sell its <strong>SecurityReview</strong> security verification solution delivered as software-as-a-service. Registered partners can manage the application scan process for clients without any upfront investment and receive a comprehensive report of application weaknesses in respect to compliance drivers such as PCI and OWASP.</p>
<p>According to <strong>Matt Peachey</strong>, VP for<strong> EMEA </strong>at Veracode, the arrival of web 2.0 has moved the security perimeter with new applications on mobile devices and in browsers becoming potential security risks. “It’s an increasing problem due to the nature of modern software development,; [Veracode] give partners the opportunity to solve many of these issues,” he says.</p>
<p>The service accepts binary files into its secure hosted environment which analyses each file for weaknesses using a combination of remote tools and technical specialists before returning a detailed report highlighting potential problems.</p>
<p>Peachey, who joins the firm following stints at IronPort, NetApp and Sun, is leading the drive to build a credible European channel. Part of the push by Veracode is in response to its rival Fortify being purchased by HP in August. Although the firms have different technology, they both offer to help developers secure code and avoid potential security issues.</p>
<p>For partners looking at offering the service, a typical scan can cost from several hundred to thousands of pounds depending on the complexity and size of the application. With margins of around 20 percent, the service offers a healthy profit without upfront commitment or technical training.</p>
<p>The vendor has already signed up a number of partners including <strong>Nebulas</strong> and <strong>Pentura,</strong> and <strong>Peachey</strong> points out that even individual consultants can use its SaaS as a “white label” tool to augment code reviews or security testing services.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/veracode-offers-channel-%e2%80%9czero-touch%e2%80%9d-saas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Warfare Communications Effects Solution for Training Environments Announced</title>
		<link>http://www.testertools.com/blog/cyber-warfare-communications-effects-solution-for-training-environments-announced/</link>
		<comments>http://www.testertools.com/blog/cyber-warfare-communications-effects-solution-for-training-environments-announced/#comments</comments>
		<pubDate>Wed, 15 Dec 2010 15:13:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Network Testing]]></category>
		<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[computer network attacks (CNA)#]]></category>
		<category><![CDATA[Inc.]]></category>
		<category><![CDATA[Live Virtual Constructive (LVC)]]></category>
		<category><![CDATA[Scalable Network Technologies]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2053</guid>
		<description><![CDATA[<br/>Scalable Network Technologies, Inc. (SNT),  the leader in wireless network modeling and simulation, announced that  the company has developed a software capability that enables integration  of realistic cyber warfare communication effects into a Live Virtual  Constructive (LVC) environment. The result is an advanced system that  provides more realistic training and ]]></description>
			<content:encoded><![CDATA[<br/><p><strong><a href="http://www.scalable-networks.com/wp-content/themes/snt/images/snt_logo.gif"><img class="alignleft" src="http://www.scalable-networks.com/wp-content/themes/snt/images/snt_logo.gif" alt="" width="285" height="65" /></a>Scalable Network Technologies, Inc.</strong> (<a href="http://www.scalable-networks.com/" target="_blank">SNT</a>),  the leader in <strong>wireless network modeling</strong> and <strong>simulation</strong>, announced that  the company has developed a software capability that enables integration  of realistic cyber warfare communication effects into a<strong> Live Virtual  Constructive (LVC)</strong> environment. The result is an advanced system that  provides more realistic training and improved analysis capabilities to  counter the increasing vulnerability of military systems to <strong>computer  network attacks (CNA)</strong>.</p>
<p>Although  current generation computer-based battlefield simulations deliver  experiential realism in force positioning, troop movement, supply  routing, enemy force detection/engagement, and damage calculation &#8211; next  generation net-centric systems open up a new domain of cyber  vulnerability that today&#8217;s war gaming systems don&#8217;t encompass.  Without  the inclusion of cyber warfare communications effects, battlefield  modeling and simulation can be overly optimistic, risking and/or  perpetuating negative training. By integrating high fidelity  communication models that incorporate network attack/defense, as well as  performance aberrations caused by various environmental factors &#8211; the  ability to analyze and train for the impact of cyber warfare on mission  outcome is dramatically improved.</p>
<p><strong>Integration Into Battlefield Simulation </strong></p>
<p>This new  synthetic cyber warfare test bed is capable of realistically  representing a network-centric battlespace under cyber attack for  testing and training applications. The test bed is achieved by  integrating SNT&#8217;s EXata™/cyber with COTS Computer Generated Forces  (CGF). Cyber warfare models (jammer, eavesdropper, distributed denial of  service, network attack) are developed and implemented within  EXata/cyber. For the integration, both tools take advantage of an  Interface Control Document (ICD) that works via the HLA signal and data  interactions to facilitate communications modeling between HLA  federates.</p>
<p>Members of  SNT&#8217;s technical staff will deliver a paper titled &#8220;Introducing a Cyber  Warfare Communications Effect Model to Synthetic Environments&#8221; at <a href="http://www.iitsec.org/" target="_blank">I/ITSEC</a>, the world&#8217;s largest modeling, simulation &amp; training conference, on Tuesday, November 30, 2010 at 5:00 PM  in Room S320D. In the presentation the authors describe how they  integrated a cyber warfare communications model into a Live Virtual  Constructive (LVC) environment, and examine the impact of using the  cyber warfare model versus the limitations of simplified communication  models in synthetic environments.  The I/ITSEC Conference is being held  at the Orange County Convention Center, Orlando, FL.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/cyber-warfare-communications-effects-solution-for-training-environments-announced/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Dyaptive Systems Wins Major Deal From World&#8217;s Largest Network Equipment Manufacturer</title>
		<link>http://www.testertools.com/blog/dyaptive-systems-wins-major-deal-from-worlds-largest-network-equipment-manufacturer/</link>
		<comments>http://www.testertools.com/blog/dyaptive-systems-wins-major-deal-from-worlds-largest-network-equipment-manufacturer/#comments</comments>
		<pubDate>Tue, 07 Dec 2010 20:43:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[3/4G networking]]></category>
		<category><![CDATA[Dyaptive]]></category>
		<category><![CDATA[Dyaptive Systems]]></category>
		<category><![CDATA[Joe Sutherland]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2076</guid>
		<description><![CDATA[<br/>The world&#8217;s largest network equipment manufacturer has awarded a  major supply contract to Dyaptive Systems for additional 3G/4G  subscriber simulation systems over a multi-year period. Dyaptive&#8217;s  end-to-end solution was selected, after extensive trials and  evaluations, to upgrade the primary test beds used to ensure robustness,  performance, scale and quality of ]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://www.ccnmatthews.com/logos2/Dyap.jpg"><img class="alignleft" src="http://www.ccnmatthews.com/logos2/Dyap.jpg" alt="" width="200" height="44" /></a>The world&#8217;s largest network equipment manufacturer has awarded a  major supply contract to <strong>Dyaptive Systems</strong> for additional 3G/4G  subscriber simulation systems over a multi-year period. Dyaptive&#8217;s  end-to-end solution was selected, after extensive trials and  evaluations, to upgrade the primary test beds used to ensure robustness,  performance, scale and quality of the company&#8217;s innovative 3G and 4G  network elements.</p>
<p><strong>Why is Stability and Robustness Testing Important?</strong></p>
<p>Stability and Robustness are crucial elements for today&#8217;s  live, 24/7 mobile networks, which are expected to run autonomously  without relying on human intervention. For example, Dyaptive&#8217;s solutions  &#8217;soak&#8217; the network with real-world traffic loads over long periods of  time in order to find defects that would otherwise only be discovered by  live customers, reducing their quality of experience. In Dyaptive&#8217;s  most recent contract, the manufacturer located numerous latent defects  that had previously eluded established testing methods. Both equipment  manufacturers and wireless operators derive high value from<strong> Dyaptive</strong>&#8217;s  end-to-end solutions, which feature realistic, complex traffic mixes  that are easy to create and execute. Other competitive tools on the  market provide traffic that is &#8220;synthetic&#8221; and hence fails to expose the  latent network defects that Dyaptive finds.</p>
<p>&#8220;The award of this contract is another indicator of the value  the Dyaptive DMTS brings to RAN vendors and operators in their quest to  ensure the utmost quality and performance in their 3G/4G products and  networks,&#8221; said <strong>Joe Sutherland</strong>, President and CEO, Dyaptive Systems Inc.  &#8220;Dyaptive&#8217;s platform is again proving to be the most cost effective,  flexible and easiest to use 3G/4G test solution for development,  verification and network engineers. We are very proud to have been  selected by the leader in <strong>3/4G networking </strong>to be their test partner for  their future needs.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/dyaptive-systems-wins-major-deal-from-worlds-largest-network-equipment-manufacturer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Help Net Security features Seven Deadliest Network Attacks Book Review</title>
		<link>http://www.testertools.com/blog/help-net-security-features-seven-deadliest-network-attacks-book-review/</link>
		<comments>http://www.testertools.com/blog/help-net-security-features-seven-deadliest-network-attacks-book-review/#comments</comments>
		<pubDate>Mon, 15 Nov 2010 16:36:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Mike Borkin]]></category>
		<category><![CDATA[Rob Kraus]]></category>
		<category><![CDATA[Seven Deadliest Network Attacks]]></category>
		<category><![CDATA[Stacy Prowell]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=2015</guid>
		<description><![CDATA[<br/>Help Net Security have featured a book review on network attacks.
Seven Deadliest Network Attacks written by Stacy Prowell, Rob Kraus and Mike Borkin and published by Syngress,  book introduces the reader to the anatomy of attacks aimed at networks:  DoS, MiTM, war dialing, penetration testing, protocol tunneling,  password replay and spanning tree ]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://ecx.images-amazon.com/images/I/41B5lSqELXL._SL500_AA300_.jpg"><img class="alignleft" src="http://ecx.images-amazon.com/images/I/41B5lSqELXL._SL500_AA300_.jpg" alt="" width="300" height="300" /></a><strong>Help Net Security</strong> have featured a book review on network attacks.</p>
<p><strong>Seven Deadliest Network Attacks </strong>written by Stacy Prowell, Rob Kraus and Mike Borkin and published by <a href="http://www.syngress.com/" target="_new">Syngress</a>,  book introduces the reader to the anatomy of attacks aimed at networks:  DoS, MiTM, war dialing, penetration testing, protocol tunneling,  password replay and spanning tree attacks.</p>
<p>Do you need to keep up with the latest hacks, attacks, and exploits  effecting social networks? Then you need Seven Deadliest Social Network  Attacks.</p>
<p>This book pinpoints the most dangerous hacks and exploits  specific to social networks like Facebook, Twitter, and MySpace, laying  out the anatomy of these attacks including how to make your system more  secure. You will discover the best ways to defend against these vicious  hacks with step-by-step instruction and learn techniques to make your  computer and network impenetrable.</p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;">Seven Deadliest Network Attacks</div>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/help-net-security-features-seven-deadliest-network-attacks-book-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rapid7 Introduces Metasploit Pro</title>
		<link>http://www.testertools.com/blog/rapid7-introduces-metasploit-pro/</link>
		<comments>http://www.testertools.com/blog/rapid7-introduces-metasploit-pro/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 22:49:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[Lol Meta-Tags Klauen Rofl]]></category>
		<category><![CDATA[Mike Tuchen]]></category>
		<category><![CDATA[Rapid7]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/rapid7-introduces-metasploit-pro/</guid>
		<description><![CDATA[<br/>Rapid7®, the leading provider of unified vulnerability management and penetration testing  solutions, today announced the availability of Metasploit Pro™, the new software for security professionals in enterprises, government agencies and consulting firms who need to make network security testing more efficient to reduce costs. Unlike alternative products, Metasploit Pro improves the efficiency of penetration ]]></description>
			<content:encoded><![CDATA[<br/><p>Rapid7®, the leading provider of unified vulnerability management and penetration testing  solutions, today announced the availability of Metasploit Pro™, the new software for security professionals in enterprises, government agencies and consulting firms who need to make network security testing more efficient to reduce costs. Unlike alternative products, Metasploit Pro improves the efficiency of penetration testers by providing unrestricted remote network access and enabling teams to collaborate efficiently. Metasploit Pro exceeds the functionality of Metasploit Express™ with support for security testing of custom Web applications, managing client-side campaigns against end-users and additional evasion features.</p>
<p>“Metasploit Pro completes our suite of penetration testing products and addresses the needs of the penetration testing expert who requires advanced features,” said Mike Tuchen, Rapid7 president and CEO. “We built Metasploit Pro with the same intuitive interface and efficient workflows of Metasploit Express and added advanced features that enable penetration testers to compromise networks deeper and faster. As a result, they can complete their security testing in less time, greatly reducing the overall impact on security budgets.”</p>
<p>The Metasploit® Framework is the most widely used and mature solution in the market with more than one million unique downloads in the past year and the world’s largest, public database for quality assured exploits. As organizations face increasing threats to complex, business-critical systems, the ability to simulate realistic attacks on their infrastructure in a fast and cost-effective manner is critical. Only Metasploit products are based on the Metasploit Framework, the gold standard for penetration testing, and are therefore best suited to emulate realistic attacks.</p>
<p>To efficiently ensure the highest possible security of their IT infrastructure, enterprises need to prioritize the mitigation of vulnerabilities. Metasploit is the world’s only penetration testing solution that directly launches NeXpose® vulnerability scans to verify vulnerabilities. Based on this enterprise risk scoring, organizations can make informed decisions about which vulnerabilities should be addressed first.</p>
<p>“We’ve been thrilled with all the capabilities of Metasploit Express and were excited to try the advanced features of the new Metasploit Pro, especially team collaboration,” says Jim O’Gorman, security systems specialist at Continuum Worldwide, a leading independent provider of business assurance solutions and a Rapid7 customer. “Enabling penetration testers to share findings and notes definitely helps keep everyone in synch and productivity moving. It’s also a great time saver at the end of an assignment because you can create a single report including everyone’s findings at the push of a button.”</p>
<p>Metasploit Pro:</p>
<p>    * Scans and exploits Web applications. Metasploit Pro enables you to scan and exploit both standard and custom Web applications, often the most publicly accessible server on the network. These can provide a pivot point into a database or further into the network.<br />
    * Runs social engineering campaigns. Metasploit Pro runs custom social engineering campaigns, including website cloning for phishing and emails with malicious attachments, to compromise end-user systems, providing additional attack vectors into the network.<br />
    * Achieves unprecedented network access. Metasploit Pro is the world’s only penetration testing solution to achieve unrestricted remote network access through a compromised host. Unlike alternative products, which provide proxy-based pivoting that is restricted to certain protocols, Metasploit Pro’s VPN pivoting evades firewall restrictions and provides encrypted access into networks at the Ethernet level, providing the same capabilities as a physical network tap. As a result, penetration testers can run any network discovery tool, such as the NeXpose vulnerability scanner, through a compromised host as if they were directly connected to the internal network.<br />
    * Enables unique team collaboration. Metasploit Pro is the world’s first penetration testing solution that supports team collaboration to coordinate concerted attacks. Team members can see and search each other’s actions, progress and notes to make team efforts more efficient. Known hosts, credentials and hashes are automatically leveraged by other team members.</p>
<p>“I firmly believe that Metasploit Pro combines best-of-breed tools in a sane, easy-to-use format, enabling us to do our job quickly and thoroughly,” says Joshua Brashars, senior security consultant at AppSec Consulting, an information security firm and a Rapid7 consulting partner. “With Metasploit Pro, my team can maximize the efficiency of our penetration tests while minimizing the number of tools we require. Metasploit Pro combines the power of the Metasploit Framework with a simple-to-use interface that allows us to hit the ground running.”</p>
<p>“With Metasploit Pro, we’ve delivered a solution for penetration testers who love the workflow of Metasploit Express but needed to go even further with their security assessments,” said HD Moore, Rapid7 CSO and Metasploit chief architect. “Rapid7 is uniquely positioned to offer a multi-tiered product that solves the real-world challenges of hundreds of thousands of security professionals and researchers. And, as a result of our success with commercial products, we’re able to drive higher quality, additional features and faster exploit development in the free, open-source framework, giving directly back to the community that sustains us.”<a href="http://www.rapid7.com/img/global/logo.png"><img alt="" src="http://www.rapid7.com/img/global/logo.png" class="alignleft" width="279" height="41" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/rapid7-introduces-metasploit-pro/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Athena Security Offers Free Configuration Debugger for Limited Time</title>
		<link>http://www.testertools.com/blog/athena-security-offers-free-configuration-debugger-for-limited-time/</link>
		<comments>http://www.testertools.com/blog/athena-security-offers-free-configuration-debugger-for-limited-time/#comments</comments>
		<pubDate>Mon, 18 Oct 2010 16:58:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Testing]]></category>
		<category><![CDATA[development tools]]></category>
		<category><![CDATA[Athena FirePAC]]></category>
		<category><![CDATA[Athena Security]]></category>

		<guid isPermaLink="false">http://www.testertools.com/blog/?p=1965</guid>
		<description><![CDATA[<br/>Athena Security, the makers of Athena FirePAC, a comprehensive  enterprise firewall audit and operations tool, today announced that it  will make the company&#8217;s Configuration Debugger, the first and only  software solution that network engineers can use for offline  troubleshooting of service availability issues on Cisco, Check Point and  Netscreen firewalls, ]]></description>
			<content:encoded><![CDATA[<br/><p><strong><a href="http://media.marketwire.com/attachments/201010/651741_Athena_logo.gif"><img class="alignleft" src="http://media.marketwire.com/attachments/201010/651741_Athena_logo.gif" alt="" width="260" height="120" /></a>Athena Security</strong>, the makers of <strong>Athena FirePAC,</strong> a comprehensive  enterprise firewall audit and operations tool, today announced that it  will make the company&#8217;s Configuration Debugger, the first and only  software solution that network engineers can use for offline  troubleshooting of service availability issues on Cisco, Check Point and  Netscreen firewalls, available for a free download until Halloween.</p>
<p>The <a href="http://vega.athenasecurity.net/r.html?uid=1.8c.12sm.3sk.shonlecj9z">Athena&#8217;s Configuration Debugger</a> features all the tools and functionality for troubleshooting even the  most complicated features related to firewalls from Cisco, Check Point  and Juniper. It simulates the behavior of the firewall so line level  technicians can quickly determine how the firewall is configured to  allow or block traffic flows to reachable hosts or subnets.</p>
<p>&#8220;The Athena Configuration Debugger is a far more convenient alternative  to Cisco&#8217;s Packet Tracer for applying virtual packets to troubleshoot  dropped services,&#8221; said David Hurst, CTO, Athena Security. &#8220;Focused,  flexible and easy to use, firewall engineers can use this tool to  quickly get to the heart of the rules that cause great confusion.&#8221;</p>
<p>With the limited time free download, users can try the Athena  Configuration Debugger to examine the entire configuration in a matter  of minutes. Using virtual packets, users can get interactive results  that allow them to easily explore rule/object relationships to isolate  the specific location for fixes fast.</p>
<p>The Debugger is the only product in the marketplace to:</p>
<ul>
<li>Support a mixed environment including Cisco PIX, ASA, FWSM, Check  Point, and Juniper Netscreen firewalls. You can bring all of these  firewalls into Athena and isolate the ACLs, NATs and Routes that require  remediation.</li>
<li>Troubleshoot packets specified by IP ranges, and a number of services, or entire subnets.</li>
<li>Does not require any firewall connectivity to perform a trace.</li>
<li>Isolate all applicable interfaces based on routing and NATing</li>
</ul>
<p>Troubleshooting service availability issues often requires a complete  examination of the configuration and an accurate mapping of how policies  relate to the structural and order dependencies between all of the  ACLs, NATs and Routes. This is a time consuming process. The Athena  Configuration Debugger is the industry&#8217;s only tool to make these rule  relationships explicitly clear, allowing engineers to target exact areas  in the firewall configuration where critical services are being blocked  so they can be restored quickly.</p>
<p>Users can actually specify the traffic they are trying to debug using a  single IP address, a number of services, or a subnet. The Debugger will  perform a reachability analysis to automatically determine access lists  or zone-to-zone policies, and evaluates how they respond to the user&#8217;s  actions and produces the results organized by rules and by packets. The  Debugger examines any settings or implied rules that could affect the  resulting traffic flows.</p>
<p>The Debugger also provides advanced comparison capabilities where it  links each rule and object change to its impact on added or deleted  traffic flows. This enables the ability to identify what specific  changes are responsible for a service disruption.</p>
<p>To get the Athena Configuration Debugger, IT managers can select any  Cisco, CheckPoint, or Netscreen firewall, even the most complex, and  send an email to Athena Security at <a href="mailto:sales@athenasecurity.net">sales@athenasecurity.net</a> with the message subject: Free Configuration Debugger. In the body of  the email, include the IP address of the firewall and an Athena  representative will provide the free license. The free license is good  for one year from the date of installation and the offer is available  until October 31, 2010.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.testertools.com/blog/athena-security-offers-free-configuration-debugger-for-limited-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

