<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for The Cover of Night</title>
	<atom:link href="http://www.thecoverofnight.com/blog/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://www.thecoverofnight.com/blog</link>
	<description>Exploiting and Explaining Security for the People</description>
	<lastBuildDate>Tue, 10 Aug 2010 21:31:43 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>Comment on The First Step of Rapid Tool Smithing by jcran</title>
		<link>http://www.thecoverofnight.com/blog/?p=319&#038;cpage=1#comment-4371</link>
		<dc:creator>jcran</dc:creator>
		<pubDate>Tue, 10 Aug 2010 21:31:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=319#comment-4371</guid>
		<description>great stream-of-consciousness description of what you&#039;re working on. can you do this for the other ~894 (hey, everybody works 14 hour days, right?) hours that you&#039;ve been doing this type research? ;)</description>
		<content:encoded><![CDATA[<p>great stream-of-consciousness description of what you&#8217;re working on. can you do this for the other ~894 (hey, everybody works 14 hour days, right?) hours that you&#8217;ve been doing this type research? <img src='http://www.thecoverofnight.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on TCP State Machine for Scapy, Alpha-ware by Ricky D</title>
		<link>http://www.thecoverofnight.com/blog/?p=190&#038;cpage=1#comment-2633</link>
		<dc:creator>Ricky D</dc:creator>
		<pubDate>Thu, 25 Mar 2010 00:35:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=190#comment-2633</guid>
		<description>How can I run this on windows?</description>
		<content:encoded><![CDATA[<p>How can I run this on windows?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Reversing the Plague Bot, will the Real Snipa Please Stand-up by apridgen</title>
		<link>http://www.thecoverofnight.com/blog/?p=214&#038;cpage=1#comment-2054</link>
		<dc:creator>apridgen</dc:creator>
		<pubDate>Thu, 04 Feb 2010 11:03:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=214#comment-2054</guid>
		<description>Ooops.  Sorry about that fixed now.</description>
		<content:encoded><![CDATA[<p>Ooops.  Sorry about that fixed now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Reversing the Plague Bot, will the Real Snipa Please Stand-up by Nicolai</title>
		<link>http://www.thecoverofnight.com/blog/?p=214&#038;cpage=1#comment-2052</link>
		<dc:creator>Nicolai</dc:creator>
		<pubDate>Thu, 04 Feb 2010 09:07:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=214#comment-2052</guid>
		<description>Hey Dude, Great article but the links to the idaypython and immunity scripts are broken.</description>
		<content:encoded><![CDATA[<p>Hey Dude, Great article but the links to the idaypython and immunity scripts are broken.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keeping Old School Tactics Current: Google, Telnet, and Echo FTW by Michael Jerris</title>
		<link>http://www.thecoverofnight.com/blog/?p=291&#038;cpage=1#comment-2042</link>
		<dc:creator>Michael Jerris</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:52:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=291#comment-2042</guid>
		<description>This is really no different than a default setup of postgresql or many other programs.  I just wanted to be clear that this is not a vulnerability due to default configuration, but a user explicitly enabling external access with weak authentication.  I would never suggest that event socket be allowed to be accessed off the box unless very tightly controlled with firewall to specific hosts and stronger passwords at the least, but more likely to be used over a more secure layer such as an ssh tunnel with keyed authentication.</description>
		<content:encoded><![CDATA[<p>This is really no different than a default setup of postgresql or many other programs.  I just wanted to be clear that this is not a vulnerability due to default configuration, but a user explicitly enabling external access with weak authentication.  I would never suggest that event socket be allowed to be accessed off the box unless very tightly controlled with firewall to specific hosts and stronger passwords at the least, but more likely to be used over a more secure layer such as an ssh tunnel with keyed authentication.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keeping Old School Tactics Current: Google, Telnet, and Echo FTW by apridgen</title>
		<link>http://www.thecoverofnight.com/blog/?p=291&#038;cpage=1#comment-2041</link>
		<dc:creator>apridgen</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:48:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=291#comment-2041</guid>
		<description>I live in Texas.  I don&#039;t blame the bullets or gun, but I do blame the hunter and the manufacturer.  Manufacturer for a broken safety and the hunter for not ensuring the safety actually works when the gun is loaded.  

I am not saying FreeSWITCH is bad, but this post is to illustrate how I went about breaking in to a host using FreeSWITCH.  The previous post was to illustrate the misconfigurations I noted and how easy it was to overlook and accomplish that misconfiguration.  FreeSWITCH does not appear in any of the titles.  FreeSWITCH was a means to an end to get on the box.  The posts illustrate this point.  Rather than arguing the issue, take it as a lesson learned update the configurations to be in what you would consider a secure by default.  </description>
		<content:encoded><![CDATA[<p>I live in Texas.  I don&#8217;t blame the bullets or gun, but I do blame the hunter and the manufacturer.  Manufacturer for a broken safety and the hunter for not ensuring the safety actually works when the gun is loaded.  </p>
<p>I am not saying FreeSWITCH is bad, but this post is to illustrate how I went about breaking in to a host using FreeSWITCH.  The previous post was to illustrate the misconfigurations I noted and how easy it was to overlook and accomplish that misconfiguration.  FreeSWITCH does not appear in any of the titles.  FreeSWITCH was a means to an end to get on the box.  The posts illustrate this point.  Rather than arguing the issue, take it as a lesson learned update the configurations to be in what you would consider a secure by default.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keeping Old School Tactics Current: Google, Telnet, and Echo FTW by Rupa Schomaker</title>
		<link>http://www.thecoverofnight.com/blog/?p=291&#038;cpage=1#comment-2040</link>
		<dc:creator>Rupa Schomaker</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:48:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=291#comment-2040</guid>
		<description>Shouldn&#039;t &quot;the vendor&quot; be the subject of this blog and not FreeSWITCH?  I can (mis)configure any platform to open it up to attack.</description>
		<content:encoded><![CDATA[<p>Shouldn&#8217;t &#8220;the vendor&#8221; be the subject of this blog and not FreeSWITCH?  I can (mis)configure any platform to open it up to attack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keeping Old School Tactics Current: Google, Telnet, and Echo FTW by Brian West</title>
		<link>http://www.thecoverofnight.com/blog/?p=291&#038;cpage=1#comment-2039</link>
		<dc:creator>Brian West</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:44:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=291#comment-2039</guid>
		<description>I don&#039;t see how they could over look the password.  The password and ip address are sitting right next to each other in the config file.  Any vendor or admin worth his weight in gold would know to check these things.  I&#039;m pretty sure you&#039;re one that would blame the gun and bullets and not the user.

/b</description>
		<content:encoded><![CDATA[<p>I don&#8217;t see how they could over look the password.  The password and ip address are sitting right next to each other in the config file.  Any vendor or admin worth his weight in gold would know to check these things.  I&#8217;m pretty sure you&#8217;re one that would blame the gun and bullets and not the user.</p>
<p>/b</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keeping Old School Tactics Current: Google, Telnet, and Echo FTW by apridgen</title>
		<link>http://www.thecoverofnight.com/blog/?p=291&#038;cpage=1#comment-2038</link>
		<dc:creator>apridgen</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:35:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=291#comment-2038</guid>
		<description>The vendor changed the IP address to 0.0.0.0, and they probably did not give a second thought about changing the password.</description>
		<content:encoded><![CDATA[<p>The vendor changed the IP address to 0.0.0.0, and they probably did not give a second thought about changing the password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keeping Old School Tactics Current: Google, Telnet, and Echo FTW by Anthony Minessale</title>
		<link>http://www.thecoverofnight.com/blog/?p=291&#038;cpage=1#comment-2037</link>
		<dc:creator>Anthony Minessale</dc:creator>
		<pubDate>Wed, 03 Feb 2010 16:29:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thecoverofnight.com/blog/?p=291#comment-2037</guid>
		<description>1) FS does not need to run as root nobody asks you to run it as root, it even has command line args to drop privs.
2) event_socket is actually designed to run on loopback.  Once we support SSL we may change that.
3) If you do choose to run it on a real IP there are ACL lists.
4) It can be also configured to authenticate with a user and password leading to a restricted list of commands i.e. no system command.

FreeSWITCH is an open source code base and it&#039;s distributed intentionally so that the process can run in the background and the event socket client can give you a CLI interface from the loopback interface.
Yes I 100% agreee that you could open your box to attack in many ways all of which can be reduced by not running as root and not letting the user have access to the system command but even then the embedded scripting languages you can execute also unlock endless possibilities of exploit.  You could have just as easily done os.system from your LUA script.   I would not recommend running FreeSWITCH at all on a public machine where you also let untrusted users have shell access.

We are trying to work on adding SSL to the APR sockets we use, maybe you could help us with that instead of blogging about how much we suck.</description>
		<content:encoded><![CDATA[<p>1) FS does not need to run as root nobody asks you to run it as root, it even has command line args to drop privs.<br />
2) event_socket is actually designed to run on loopback.  Once we support SSL we may change that.<br />
3) If you do choose to run it on a real IP there are ACL lists.<br />
4) It can be also configured to authenticate with a user and password leading to a restricted list of commands i.e. no system command.</p>
<p>FreeSWITCH is an open source code base and it&#8217;s distributed intentionally so that the process can run in the background and the event socket client can give you a CLI interface from the loopback interface.<br />
Yes I 100% agreee that you could open your box to attack in many ways all of which can be reduced by not running as root and not letting the user have access to the system command but even then the embedded scripting languages you can execute also unlock endless possibilities of exploit.  You could have just as easily done os.system from your LUA script.   I would not recommend running FreeSWITCH at all on a public machine where you also let untrusted users have shell access.</p>
<p>We are trying to work on adding SSL to the APR sockets we use, maybe you could help us with that instead of blogging about how much we suck.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
