<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Netsoc</title>
	<atom:link href="http://www.netsoc.dit.ie/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.netsoc.dit.ie</link>
	<description>Netsoc DIT</description>
	<lastBuildDate>Tue, 17 Apr 2012 17:59:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Getting that Job in Ethical Hacking Talk &#8211; IBM</title>
		<link>http://www.netsoc.dit.ie/2012/04/getting-that-job-in-ethical-hacking-talk-ibm/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=getting-that-job-in-ethical-hacking-talk-ibm</link>
		<comments>http://www.netsoc.dit.ie/2012/04/getting-that-job-in-ethical-hacking-talk-ibm/#comments</comments>
		<pubDate>Tue, 17 Apr 2012 17:58:02 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[talk]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=618</guid>
		<description><![CDATA[I was just forwarded this by Fred Mtenzi. There&#8217;ll be a talk this thursday on ethical hacking Getting that Job Ethical Hacking Promoting yourself in a Highly Competitive Environment by Juan Galiana Lara, Paul McCann &#38; Martin Mitchell Thursday 19th &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/04/getting-that-job-in-ethical-hacking-talk-ibm/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>I was just forwarded this by Fred Mtenzi. There&#8217;ll be a talk this thursday on ethical hacking<br />
Getting that Job Ethical Hacking</p>
<p>Promoting yourself in a Highly Competitive Environment<br />
by Juan Galiana Lara, Paul McCann &amp; Martin Mitchell</p>
<p>Thursday 19th April 2012 .4pm DIT Bolton Street Room 281</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/04/getting-that-job-in-ethical-hacking-talk-ibm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Building Secure Web Applications</title>
		<link>http://www.netsoc.dit.ie/2012/03/building-secure-web-applications/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=building-secure-web-applications</link>
		<comments>http://www.netsoc.dit.ie/2012/03/building-secure-web-applications/#comments</comments>
		<pubDate>Fri, 23 Mar 2012 00:05:11 +0000</pubDate>
		<dc:creator>Michael Loughran loughran</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=613</guid>
		<description><![CDATA[Hey Everyone, When: Tuesday 27th, 6pm Where: KA G 026 Ground floor Annex building, Kevin St My name is Michael Loughran. I am a final year project student in DT228 and I will being a brief talk on some of the security &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/building-secure-web-applications/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hey Everyone,</p>
<p>When: Tuesday 27th, 6pm<br />
Where: KA G 026 Ground floor Annex building, Kevin St</p>
<p>My name is Michael Loughran. I am a final year project student in DT228 and I will being a brief talk on some of the security issues I encountered over the development of my project. The projects goal was to create a space MMO game that could be played in a web browser. It was developed in PHP and used mysql for the database. In this talk we will cover</p>
<ul>
<li>sql injection</li>
<li>cross site scripting</li>
<li>input validation</li>
</ul>
<p>We will show some sample applications that have been developed and show how each of these issues can affect them. This talk will demonstrate how to not only perform the above attacks but also how to secure web applications against them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/building-secure-web-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Events postponed</title>
		<link>http://www.netsoc.dit.ie/2012/03/events-postponed/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=events-postponed</link>
		<comments>http://www.netsoc.dit.ie/2012/03/events-postponed/#comments</comments>
		<pubDate>Wed, 21 Mar 2012 18:16:34 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=598</guid>
		<description><![CDATA[I&#8217;m afraid we (and most likely a good few of you) are pretty busy with assignments at the moment. There won&#8217;t be anything on Thursday and most likely not Monday either. Have a look at http://147.252.127.43/collegedemo2 though, it&#8217;s an sql &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/events-postponed/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m afraid we (and most likely a good few of you) are pretty busy with assignments at the moment. There won&#8217;t be anything on Thursday and most likely not Monday either.</p>
<p>Have a look at <a href="http://147.252.127.43/collegedemo2">http://147.252.127.43/collegedemo2</a> though, it&#8217;s an sql injection tutorial thing. Some parts don&#8217;t work (like most of level 4 and all of the &#8220;500&#8243; challenges) as I wrote it up really roughly and in a hurry. When the assignments are over I might rewrite it.</p>
<p>In the mean time, good luck with assignments and keep an eye out for when we start back up events, possibly next week or the week after!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/events-postponed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Intersocs IRC server now peered!</title>
		<link>http://www.netsoc.dit.ie/2012/03/intersocs-irc-server-now-peered/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=intersocs-irc-server-now-peered</link>
		<comments>http://www.netsoc.dit.ie/2012/03/intersocs-irc-server-now-peered/#comments</comments>
		<pubDate>Mon, 19 Mar 2012 20:39:15 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=590</guid>
		<description><![CDATA[We have intersocs irc connectivity! This is a private network of irc servers from all the various technical societies around Ireland such as redbrick, skynet, netsoc tcd etc. I&#8217;ve setup a script and some template configs/plugins for irssi, an irc client. Log &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/intersocs-irc-server-now-peered/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p><strong>We have intersocs irc connectivity!</strong> This is a private network of irc servers from all the various technical societies around Ireland such as redbrick, skynet, netsoc tcd etc.</p>
<p>I&#8217;ve setup a script and some template configs/plugins for irssi, an irc client.</p>
<p>Log into our server, login.netsoc.dit.ie in the usual way, run byobu or screen so you don&#8217;t loose your connection when you logout and run &#8220;setupirc&#8221;. After this is complete, it will prompt you to run irssi.</p>
<p>The script sets irssi to auto connect to irc.netsoc.dit.ie and join #dit channel. Check out #intersocs (main channel where all the different society people are) as well by typing /join #intersocs</p>
<p>&nbsp;</p>
<p><strong>Why did it take us so long to connect?</strong></p>
<p>Why didn&#8217;t we connected sooner? Well we tried, but there was a strange error</p>
<p>&#8220;Connect: Host irc.netsoc.tcd.ie not listed in ircd.conf&#8221;. Basically the issue was that the debian build of ircd-hybrid removes the ssl connectivity. That combined with the fact that unfortunately if ircd-hybrid never gave any errors about the ssl options. Simply put, if the ssl options were left in, it would just silently skip over the connect block and not show it even existed. Was just by chance that i commented out the rsa private file and crypto link and gave it a wack that I realised the problem went away.<br />
Simple build instructions for debian.  This doesn’t work with lenny due a bug in building with libssl. I&#8217;m sure you could change which library it compiles with to get it to work, http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=482630</p>
<pre>
apt-get -y install libssl-dev fakeroot
apt-get -y build-dep ircd-hybrid

mkdir ircd-build
cd ircd-build
apt-get source ircd-hybrid
cd ircd-hybrid-7*
sed -i 's/NICKLEN = 15/NICKLEN = 9/g' debian/rules
USE_OPENSSL=1 fakeroot debian/rules binary
cd ..
dpkg -i ircd-hybrid*.deb
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/intersocs-irc-server-now-peered/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cracking the Campuscon CTF Hacking challenge</title>
		<link>http://www.netsoc.dit.ie/2012/03/cracking-the-campuscon-ctf-hacking-challenge/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cracking-the-campuscon-ctf-hacking-challenge</link>
		<comments>http://www.netsoc.dit.ie/2012/03/cracking-the-campuscon-ctf-hacking-challenge/#comments</comments>
		<pubDate>Sun, 18 Mar 2012 02:36:35 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=580</guid>
		<description><![CDATA[Remember this? http://www.netsoc.dit.ie/2012/01/trip-to-campuscon-wit-form/ Forgot to mention, two of us headed down from netsoc DIT and won! Myself (Mark Cunningham) and Declan Curran. Here&#8217;s a quick write up on what the challenge was and how we cracked it. A big thank WIT Hacking &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/cracking-the-campuscon-ctf-hacking-challenge/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Remember this? <a href="http://www.netsoc.dit.ie/2012/01/trip-to-campuscon-wit-form/">http://www.netsoc.dit.ie/2012/01/trip-to-campuscon-wit-form/</a> Forgot to mention, two of us headed down from netsoc DIT and won! Myself (Mark Cunningham) and Declan Curran.</p>
<p>Here&#8217;s a quick write up on what the challenge was and how we cracked it. A big thank WIT Hacking society for putting on the conference and Seán Ó Briain (<a href="https://twitter.com/SeanOBriain">@SeanOBriain</a>) for creating the challenge. It was a lot of fun.</p>
<p><strong>Introduction</strong></p>
<p>The story behind the challenge was that a bomb is ticking down and we have to crack through the challenges and disarm the bomb before it blew up (there was obviously no real bomb just to clarify). The challenge consisted of 3 parts where at the end of each one, you were able to enter your team name. Our team name was &#8220;Club Mate.&#8221; (not a well chosen name I admit, especially as I think the stuff takes like crap)</p>
<p><strong>Cracking the challenge</strong></p>
<p>Initially we were given 2 ip addresses and told which one to start with.</p>
<p>The first server was called WOPR (<a href="http://www.imdb.com/title/tt0086567/">wargames</a> reference &#8211; great movie) running ubuntu. We port scanned it and found a http and ssh server running.</p>
<p>The web server consisted of a range of games. Series of urls had urls with parameters included (such as ?game=bla). These urls were vulnerable to sql injection.</p>
<p>Using one of these injection points, we pulled out two interesting tables. A &#8220;users&#8221; table and an &#8220;ssh-users&#8221; table. The users table contained an md5 hash. We cracked it with john the ripper and used the login to enter our our team name into the website. (The md5 hash wasn&#8217;t salted so we could have just googled it however we hadn&#8217;t got internet hooked up at the time as there was no need. Using the wordlist from john the ripper, we cracked it in fairly little time)</p>
<p>The ssh-users table contained a login/password to allow us to ssh into the machine. There we found a mail log that contained a conversation. This contained login details for a website running on the second server.</p>
<p>The second server was running ubuntu and was named GIBSON (yes we did hack the gibson). It was also running an unknown service that when we telneted to it, we found a prompt asking us for a passphrase to disable the bomb. None of the credentails worked at this point so we moved on.</p>
<p>We got a .htaccess type password prompt which we used the credentials we gleaned from the mail file to login. The website had a file upload feature. We attempted to upload a php shell however there was content filtering. Using burp, we changed the type of the file to plain/text and uploaded one of our php shell scripts. This allowed us to run system commands similar to terminal access.</p>
<p>Once we had terminal access, we poked around the files to see what we could find and discovered one of the users in the /home directory had their directory as world readable. inside was an interesting file (i think the word &#8220;key&#8221; was in the filename) containing a random stream of characters. We submitted that key to the service prompting us for the bomb deactivation code however it was denied. We backtracked and tried various other usernames/passwords. Finally realised the string was all base64 characters, decoded it and entered the code to deactivate the bomb.</p>
<p>Was an enjoyable set of challenges and from what we heard aftewards, we weren&#8217;t alone in thinking that. Hope to head out next year for more challenges and again, thanks to wit hacking society and Seán Ó Briain for creating the challenge for us!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/cracking-the-campuscon-ctf-hacking-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mini Wargame &#8211; Security challenge</title>
		<link>http://www.netsoc.dit.ie/2012/03/mini-wargame-security-challenge/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mini-wargame-security-challenge</link>
		<comments>http://www.netsoc.dit.ie/2012/03/mini-wargame-security-challenge/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 00:47:17 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=543</guid>
		<description><![CDATA[Hey Folks When: Thursday 15th, 6pm Where: KA-1-16 This thursday, we will be hosting a mini wargame. I say mini because I didn&#8217;t have the time to touch it up to quite the level i&#8217;d like. There will be some &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/mini-wargame-security-challenge/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hey Folks</p>
<p>When: Thursday 15th, 6pm<br />
Where: KA-1-16</p>
<p>This thursday, we will be hosting a mini wargame. I say mini because I didn&#8217;t have the time to touch it up to quite the level i&#8217;d like.</p>
<p>There will be some purposely vulnerable machines setup for everyone to try hack. This will be similar to the setups we have guided people through with the workshops/tutorials. Hope to see you all there!</p>
<p><strong>Workshop:</strong></p>
<p>You&#8217;ll need:<br />
Linux/ubuntu live cd (recommended). We&#8217;ll push this out via torrents at the start of class<br />
firefox (again, preferred but not required)<br />
Burpsuite<br />
john the ripper<br />
wordlist (<a href="http://download.openwall.net/pub/passwords/wordlists/">http://download.openwall.net/pub/passwords/wordlists/</a>), we&#8217;ll pass this around via torrents as well as their mirror is quite slow.</p>
<p><span style="text-decoration: underline;">Setup:</span><br />
On your LAB PC:</p>
<p>First: Check if ubuntu iso is on the E:\ drive. If it is, you may skip the following.</p>
<p>==================================================================<br />
Download: http://portableapps.com/apps/internet/utorrent_portable, Install to the E:\ drive.<br />
Run utorrent portable.<br />
Navigate to the server address &#8212;&#8212;&#8212;&#8211;(I haven&#8217;t got the server online yet, please wait untill the workshop starts)<br />
Download the torrents on the page using utorrent portable and save the data to the E:\ drive (NOT YOUR U:\ drive)<br />
==================================================================<br />
Once you&#8217;ve downloaded ubuntu, vmware as shown in this pdf &#8211; <a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/03/setupvmware.pdf">setupvmware</a>.</p>
<p>You&#8217;ll probably need to change your dns servers you can do so by typing:</p>
<p>echo &#8220;nameserver 8.8.8.8&#8243; | sudo tee /etc/resolv.conf</p>
<p>Then you&#8217;ll need to install libssl-dev , sudo apt-get install libssl-dev to have the proper libraries to compile john.<br />
You&#8217;re now ready to start hacking at the first server. Setup burp suite and firefox as shown before and aim your browser at: http://147.252.234.230</p>
<p>You will need to crack some passwords at some stage in the challenge, this is how you compile john the ripper ( a password cracker)</p>
<p><span style="text-decoration: underline;">Compile john</span><br />
Google &#8220;john the ripper&#8221; and download the latest <em>community-enhanced</em> version. It&#8217;ll probably appear in /home/ubuntu/Downloads/. You&#8217;ll need to extract it, tar -zxvf the-file-name-here<br />
cd into the directory it extracted and into src and type make to see all the options. You will most likely want to type<br />
make linux-X86-any. Once this has completed, you&#8217;ll find the program in the run directory (cd ../run)</p>
<p><strong>Mitigation:</strong></p>
<p>I&#8217;ll update this post about how we can secure the holes for the different parts of the challenge that have been solved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/mini-wargame-security-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System administration workshop Monday 12th March</title>
		<link>http://www.netsoc.dit.ie/2012/03/system-administration-workshop-monday-12th-march/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=system-administration-workshop-monday-12th-march</link>
		<comments>http://www.netsoc.dit.ie/2012/03/system-administration-workshop-monday-12th-march/#comments</comments>
		<pubDate>Sun, 11 Mar 2012 19:30:15 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=537</guid>
		<description><![CDATA[Hey Folks As per usual, this will be in KA-3-05 from 6pm. We will be doing a system administration workshop this Monday for installing and configuring services on a linux server. This will be hands on using vmware player on &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/system-administration-workshop-monday-12th-march/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hey Folks</p>
<p>As per usual, this will be in KA-3-05 from 6pm.</p>
<p>We will be doing a system administration workshop this Monday for installing and configuring services on a linux server. This will be hands on using vmware player on the lab machines.</p>
<p>We will be covering the basics such as</p>
<ul>
<li><span style="line-height: 22px;">Installing daemons/services</span></li>
<li><span style="line-height: 22px;">configuring services</span></li>
<li><span style="line-height: 22px;">adding users</span></li>
<li><span style="line-height: 22px;">Analysing logfiles</span></li>
<li><span style="line-height: 22px;">configuring network settings</span></li>
<li><span style="line-height: 22px;">Setting up firewalls</span></li>
</ul>
<p>Workshop notes, please download a torrent program such as utorrent portable.</p>
<p>Navigate to http://147.252.234.51 and download &#8220;ubuntu-11.10-desktop &#8221; etc torrent and open it and start downloading</p>
<p>&nbsp;</p>
<p>Once you have the iso downloaded, please read this file on how to set up vmware with the image <a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/03/setupvmware.pdf">setupvmware</a></p>
<p>To clarify for anyone who&#8217;s not using vmware, the setup should be a &#8220;bridge network connection&#8221; and we will be running a live cd not installing it</p>
<p>&nbsp;</p>
<p>Once vmware and ubuntu is setup, please boot up and select &#8220;TRY UBUNTU&#8221;</p>
<p><strong>Update:</strong> Great turn out, hope everyone found this as enjoyable as I did. Here are some photos of the event</p>
<p><iframe src="http://www.flickr.com/slideShow/index.gne?group_id=&amp;user_id=&amp;set_id=72157629572372749" frameborder="0" scrolling="no" align="center" width="500" height="500"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/system-administration-workshop-monday-12th-march/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP &#8211; Web application security workshops</title>
		<link>http://www.netsoc.dit.ie/2012/03/owasp-web-application-security-workshops/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=owasp-web-application-security-workshops</link>
		<comments>http://www.netsoc.dit.ie/2012/03/owasp-web-application-security-workshops/#comments</comments>
		<pubDate>Sun, 11 Mar 2012 19:12:30 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=534</guid>
		<description><![CDATA[Hey Folks, for anyone who hasn&#8217;t seen it, this is the email sent to the owasp Ireland mailing list. It&#8217;s free but you need to signup in advance. DATE: 30th March at 17:00 Dear all, We have the great pleasure &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/owasp-web-application-security-workshops/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Hey Folks, for anyone who hasn&#8217;t seen it, this is the email sent to the owasp Ireland mailing list. It&#8217;s free but you need to signup in advance.</p>
<p>DATE: 30th March at 17:00</p>
<p><em>Dear all,</em></p>
<p><em>We have the great pleasure to invite you to the upcoming OWASP Dublin event next Friday 30th March at 17:00 (registration opens at 16:30) in Google Ireland Engineering offices at One Grand Canal Plaza Building (located on Grand Canal Street Upper, beside the junction of Warrington Place and Barrow Street).</em></p>
<p><em>You could find a placemark for the building on this map : http://goo.gl/ZGASA</em></p>
<p><em>This event is free and open to EVERYONE but registration is mandatory. In this occasion, we have two great speakers from the UK coming only to deliver these talks.</em></p>
<p><em>Workshop #1 Details &#8211; Application Hacking: Beyond the OWASP Top 10</em></p>
<p><em>Whilst many guides, tools and methodologies stress the importance and expand the ubiquity of the OWASP Top 10, many of the more interesting vulnerabilities are those which are not. In this talk, MDSec present some results from our assessments which defy even the broad classification of the OWASP Top 10.</em></p>
<p><em>Guest Speaker: Marcus Pinto</em><br />
<em>Twitter: @mdseclabs</em></p>
<p><em>With nine years’ experience, Marcus Pinto is an industry thought leader in Information Security, having authored the Web Application Hacker’s Handbook Series, and delivered numerous private training courses, conference training, seminars and awareness days on technical subjects worldwide. Marcus has managed end-user security, consultancy and internal penetration testing teams for government and financial sector organisations.</em></p>
<p><em>Workshop #2 Details: iOS Application (In)Security</em></p>
<p><em>The mobile application market has exploded in the last few years. With Apple holding a majority market share in the consumer market and a growing foothold in the enterprise, iOS application security has never been so important. In this talk, MDSec will present some of the lessons learned from evaluating iOS applications covering the platform security features, blackbox app assessment and the security relevant APIs.</em></p>
<p><em>Guest Speaker: Dominic Chell</em><br />
<em>Twitter: @deadbeefuk</em></p>
<p><em>Dominic is a director of MDSec, a UK based security consultancy specialising in a range of technical security assessment services including Mobile security. As a researcher, Dominic has been publicly acknowledged by numerous vendors, including Apple, for vulnerability disclosure.</em></p>
<p><em>Registration: http://www.regonline.com/beyondtop10</em></p>
<p><em>Any questions, please let me know.</em></p>
<p><em>Thanks,</em><br />
<em>Fabio</em></p>
<p><em>_______________________________________________</em><br />
<em>Owasp-ireland mailing list</em><br />
<em>Owasp-ireland@lists.owasp.org</em><br />
<em>https://lists.owasp.org/mailman/listinfo/owasp-ireland</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/owasp-web-application-security-workshops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web application security training workshop Monday with Mark Denihan</title>
		<link>http://www.netsoc.dit.ie/2012/03/web-application-training-workshop-monday-with-mark-denihan/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=web-application-training-workshop-monday-with-mark-denihan</link>
		<comments>http://www.netsoc.dit.ie/2012/03/web-application-training-workshop-monday-with-mark-denihan/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 21:22:30 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=498</guid>
		<description><![CDATA[Looking to get into security more? Want to learn how systems are really compromised or just plain want to learn how to hack? Come along to the security workshop training on Monday for a workshop by guest, Mark Denihan When: &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/web-application-training-workshop-monday-with-mark-denihan/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Looking to get into security more? Want to learn how systems are really compromised or just plain want to learn how to hack? Come along to the security workshop training on Monday for a workshop by guest, Mark Denihan</p>
<p>When: Monday- 5th March 6pm<br />
Where: KA-305 in Kevin st Annex building</p>
<p>Here&#8217;s what he has to say about the workshop<br />
<a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/03/mark-security-header.png"><img class="wp-image-518 alignleft" title="mark-security-header" src="/wp-content/uploads/2012/03/mark-security-header.png" alt="" width="700" height="173" /></a></p>
<p>&nbsp;</p>
<div><em>It is widely accepted now among researchers and practitioners in computing that there is no application or service on the internet that is immune from security attacks or threats. These security threats can result in attacks that diminish customers&#8217; trust with an organisation, damage it&#8217;s reputation, as well as subjecting the organisation to an array of costly law suits.</em></div>
<div></div>
<div><em>This workshop aims to establish a security mind with participants by enabling them to learn, practice and demonstrate how common security vulnerabilities can impact a system. This workshop will cater for those with no hacking experience to those that casually win wargames every other weekend.</em></div>
<div><em><br />
</em></div>
<div></div>
<div></div>
<div><img class="alignright size-full wp-image-501" style="border-style: initial; border-color: initial; border-width: initial;" title="mark-denihan" src="/wp-content/uploads/2012/03/mark-denihan1.jpg" alt="" width="162" height="277" /></div>
<div>Mark Denihan is currently a fourth year student working on a system called &#8220;Security Shephard,&#8221; a training enviroment who&#8217;s purpose is to train people about web application. He will be demoing it as part of the workshop Monday.</div>
<div>
<div>While not working on this project, Mark works part time as part of his</div>
<div>internship in the ethical hacking team at IBM.</div>
<div><span style="color: #4a630f;"><em><br />
</em></span><em><a style="color: #4a630f; text-decoration: none;" href="http://www.netsoc.dit.ie/wp-content/uploads/2012/03/mark-denihan1.jpg"><br />
</a></em></div>
</div>
<p><iframe src="http://www.youtube-nocookie.com/embed/19ROp3qik6s" frameborder="0" width="560" height="315"></iframe></p>
<p><iframe src="http://www.flickr.com/slideShow/index.gne?group_id=&amp;user_id=&amp;set_id=72157629158026302" frameborder="0" scrolling="no" align="center" width="500" height="500"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/web-application-training-workshop-monday-with-mark-denihan/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>BitTorrent deployment of software across a lab</title>
		<link>http://www.netsoc.dit.ie/2012/03/bittorrent-deployment-of-software-across-a-lab/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=bittorrent-deployment-of-software-across-a-lab</link>
		<comments>http://www.netsoc.dit.ie/2012/03/bittorrent-deployment-of-software-across-a-lab/#comments</comments>
		<pubDate>Fri, 02 Mar 2012 21:19:11 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=507</guid>
		<description><![CDATA[Situation: This semster vmware player is on the lab pcs. I wanted to host workshops using ubuntu + vulnerable vms for security/system administraiton. This collection includes around 10 gigs of vms, isos and tools. Problem: Even with 100Mb connections, downloading from &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/03/bittorrent-deployment-of-software-across-a-lab/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Situation: This semster vmware player is on the lab pcs. I wanted to host workshops using ubuntu + vulnerable vms for security/system administraiton. This collection includes around 10 gigs of vms, isos and tools.</p>
<p>Problem: Even with 100Mb connections, downloading from one location (Be it the internet or the M drive etc), would saturate the downlink with 30/40 labs (ontop of everyone elses traffic). Usbs are slow and even sharing between lab pcs would be hectic.</p>
<p>Solution: I remember twitter using bittorrent for server deployment. (<a href="http://torrentfreak.com/twitter-uses-bittorrent-for-server-deployment-100210/">http://torrentfreak.com/twitter-uses-bittorrent-for-server-deployment-100210/</a>). So this evening, when the labs emptied out for this weekend, I setup a torrent tracker &#8211; RivetTracker  -<a href="http://sourceforge.net/projects/rivettracker/">http://sourceforge.net/projects/rivettracker/</a>, which was quite easy. All you need is a mysql username + password and some php server space. It has a similar setup to wordpress the first time. You&#8217;re given a username + password you can use to upload new torrents to it.</p>
<p>I was expecting it to be more difficult than it turned out to be but we just grabbed some torrent clients, logged onto all the lab PCs, set them all up to download the torrent. Was quite cool watching all the lab pcs max out upload/download speeds. We didn&#8217;t time the process unfortunately but it was quite fast.</p>
<p>Funny enough, this process turned out to be faster than transferring the collection to usb and transfering across to a shared smb drive. So one of the labs now has a nice collection of 10 gigs of security research tools on the E: drive (tempdata) although this is liable to be wiped after a certain period of time. Fred Mtenzi (security lecturer) has kindly given permission for this collection to be stored on the M drive under &#8220;netsoc&#8221; directory so even if this collection is lost, you can download it again from here without hunting around too much.</p>
<p>Final Notes: This isn&#8217;t of the usual importance that usually makes it to a website post however I did think it worked REALLY smoothly and worked surprisingly well. While the implementation is trivial and nothing new, It would be well worth a look for deploying tools in the lab. After I had it all done, I considered that a multicast solution might have worked better since they were all on the local network. Ah well, always next time!</p>
<p><strong>Update</strong>: People were asking me to upload a screenshot of my setup.  Unfortunately I don&#8217;t have a screenshot of when all the clients were connected, but this is the aftermath. An announcement recent about rivettracker highlights a LOT of security vulnerabilities. Specificly, sql injection. The code looks horrific and the latest version off sourceforge is still vulnerable. A bit of google-fu also shows there&#8217;s a lot of servers out there running this&#8230; dangerous. This seems like a semi-easy target we may try exploit in a workshop. Here&#8217;s the report here <a href="http://packetstormsecurity.org/files/110416/rivettracker-sql.txt">http://packetstormsecurity.org/files/110416/rivettracker-sql.txt</a></p>
<p>Also quick note, we have patched the version we use in the labs each week however you&#8217;re welcome to verify it yourself!</p>
<p><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/03/rivettracker-netsoc.png"><img title="rivettracker-netsoc" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/03/rivettracker-netsoc.png" alt="" width="1267" height="654" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/03/bittorrent-deployment-of-software-across-a-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>System Administration Talk with Debian</title>
		<link>http://www.netsoc.dit.ie/2012/02/system-administration-talk-with-debian/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=system-administration-talk-with-debian</link>
		<comments>http://www.netsoc.dit.ie/2012/02/system-administration-talk-with-debian/#comments</comments>
		<pubDate>Tue, 28 Feb 2012 00:20:03 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=468</guid>
		<description><![CDATA[We&#8217;ll be doing a system administration Talk on Tuesday 28th on system administration with the light being on debian. This will be a semi introduction to debian in general with a highlight on the system administration. Hope to see you &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/02/system-administration-talk-with-debian/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ll be doing a system administration Talk on Tuesday 28th on system administration with the light being on debian. This will be a semi introduction to debian in general with a highlight on the system administration. Hope to see you all there!</p>
<p>When: 6PM Tuesday 28th February<br />
Where: KA G 026</p>
<p>Topics will include but are not limited to</p>
<ul>
<li><span style="line-height: 22px;">Installing packages/services</span></li>
<li><span style="line-height: 22px;">How to configure services</span></li>
<li><span style="line-height: 22px;">Networking</span></li>
<li><span style="line-height: 22px;">Firewalls with iptables</span></li>
<li><span style="line-height: 22px;">Locking down the system</span></li>
<li><span style="line-height: 22px;">Libraries + development headers and compiling services from source</span></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/02/system-administration-talk-with-debian/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GIT Workshop Monday 27th Feb</title>
		<link>http://www.netsoc.dit.ie/2012/02/git-workshop/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=git-workshop</link>
		<comments>http://www.netsoc.dit.ie/2012/02/git-workshop/#comments</comments>
		<pubDate>Sun, 26 Feb 2012 20:41:58 +0000</pubDate>
		<dc:creator>Graham Hayes graham.hayes3</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=454</guid>
		<description><![CDATA[Git + Versioning software Workshop + Talk this Monday! When: 6-8pm Monday 27th February Where: KA-3-05 We will be doing a source control workshop and talk tomorrow. Covering a basic overview of how it works, and and why you should use &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/02/git-workshop/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Git + Versioning software Workshop + Talk this Monday!</p>
<p>When: 6-8pm Monday 27th February<br />
Where: KA-3-05</p>
<p>We will be doing a source control workshop and talk tomorrow. Covering a basic overview of how it works, and and why you should use it. We will then use git and git hub to show you how you can use it.</p>
<p>Versioning software is used to take snapshots of your code and collaborately integrate different snapshots that different people have worked on into one project. We highly recommend coming along if you&#8217;ll be doing programming at some stage and even if you&#8217;re not. We&#8217;ll be using git in future workshops/events so if you&#8217;re planning on coming to later workshops,</p>
<p><a href="https://github.com/"><img class="alignnone size-medium wp-image-458" title="Github logo" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/6a00d8341c767353ef016762f7c808970b-800wi-200x300.png" alt="" width="200" height="300" /></a></p>
<p><strong>Update:</strong><br />
Video of the workshop<br />
<iframe src="http://www.youtube.com/embed/MloY0dRyMro" frameborder="0" width="420" height="315"></iframe><br />
<iframe align="center" src="http://www.flickr.com/slideShow/index.gne?group_id=&#038;user_id=&#038;set_id=72157629470578543" frameBorder="0" width="500" height="500" scrolling="no"></iframe></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/02/git-workshop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What would you like to see first this semester?</title>
		<link>http://www.netsoc.dit.ie/2012/02/what-would-you-like-to-see-first-this-semester/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-would-you-like-to-see-first-this-semester</link>
		<comments>http://www.netsoc.dit.ie/2012/02/what-would-you-like-to-see-first-this-semester/#comments</comments>
		<pubDate>Sun, 19 Feb 2012 20:31:38 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=447</guid>
		<description><![CDATA[What sort of workshops / Talks would you like to see FIRST this semester? https://docs.google.com/a/socs.dit.ie/spreadsheet/viewform?formkey=dGI2SUxsbWFDM1p4a29YVDFIVWlVbmc6MQ]]></description>
			<content:encoded><![CDATA[<p>What sort of workshops / Talks would you like to see FIRST this semester?</p>
<p><a href="https://docs.google.com/a/socs.dit.ie/spreadsheet/viewform?formkey=dGI2SUxsbWFDM1p4a29YVDFIVWlVbmc6MQ">https://docs.google.com/a/socs.dit.ie/spreadsheet/viewform?formkey=dGI2SUxsbWFDM1p4a29YVDFIVWlVbmc6MQ</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/02/what-would-you-like-to-see-first-this-semester/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Minecraft server Launch + Project day</title>
		<link>http://www.netsoc.dit.ie/2012/02/minecraft-server-launch-project-day/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=minecraft-server-launch-project-day</link>
		<comments>http://www.netsoc.dit.ie/2012/02/minecraft-server-launch-project-day/#comments</comments>
		<pubDate>Mon, 13 Feb 2012 09:08:02 +0000</pubDate>
		<dc:creator>Mark Cunningham</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=429</guid>
		<description><![CDATA[Welcome back folks We&#8217;re doing a launch party on Monday 13th at 6pm in KA-1-17. You&#8217;ll need a full copy of minecraft for this event which you can get here http://www.minecraft.net/store . Declan, a member of the committee, has written a lua &#8230;<p class="read-more"><a href="http://www.netsoc.dit.ie/2012/02/minecraft-server-launch-project-day/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<p>Welcome back folks</p>
<p>We&#8217;re doing a launch party on <strong>Monday 13th at 6pm in KA-1-17</strong>. You&#8217;ll need a full copy of minecraft for this event which you can get here http://www.minecraft.net/store . Declan, a member of the committee, has written a lua wrapper script to extend the interaction between the server which we will be publishing to github soon. We hope to advance the scripting behind the server a lot more in the time to come.</p>
<p>If you keep an eye out, you may just see some creepers walking around DIT today. Here&#8217;s some pictures of a few creations from our server so far.</p>
<p><strong>Update:</strong></p>
<p>Thanks to all who showed up, had some great craic and I even hear some the creeper came to life at some stage in the snackery and scared the living crap out of some people. To whoever it was, would be interested in hearing how many people you got to scare <img src='http://www.netsoc.dit.ie/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/425058_347960768560439_100000395570958_1198409_424786756_n.jpg"><img class="alignnone size-medium wp-image-442" title="425058_347960768560439_100000395570958_1198409_424786756_n" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/425058_347960768560439_100000395570958_1198409_424786756_n-225x300.jpg" alt="" width="225" height="300" /></a></p>
<p><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_01.09.52.png"><img class="alignnone size-medium wp-image-419" title="2012-02-12_01.09.52" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_01.09.52-300x220.png" alt="" width="300" height="220" /></a><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_01.10.23.png"><img class="alignnone size-medium wp-image-420" title="2012-02-12_01.10.23" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_01.10.23-300x220.png" alt="" width="300" height="220" /></a><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-11_23.04.24.png"><img class="alignnone size-medium wp-image-428" title="2012-02-11_23.04.24" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-11_23.04.24-300x220.png" alt="" width="300" height="220" /></a><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_00.04.56.png"><img class="alignnone size-medium wp-image-427" title="2012-02-12_00.04.56" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_00.04.56-300x220.png" alt="" width="300" height="220" /></a><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_00.05.13.png"><img class="alignnone size-medium wp-image-426" title="2012-02-12_00.05.13" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_00.05.13-300x220.png" alt="" width="300" height="220" /></a><a href="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_00.12.49.png"><img class="alignnone size-medium wp-image-425" title="2012-02-12_00.12.49" src="http://www.netsoc.dit.ie/wp-content/uploads/2012/02/2012-02-12_00.12.49-300x220.png" alt="" width="300" height="220" /></a></p>
<h3>Project Night</h3>
<p>We&#8217;ll be hosting a project night on <strong>Thursday from 6-8 in KA-1-16</strong>. This Thursday the 16th Feburary, we&#8217;ll be giving the&#8221; webtimetables plus&#8221; project a crack. See <a href="http://www.netsoc.dit.ie/2012/01/webtimetables-plus-project-proposal/">http://www.netsoc.dit.ie/2012/01/webtimetables-plus-project-proposal/</a> for more details. This will be a group orientated meetups rather than the usual lecture/workshop style so expect more of an even contribution level from everyone rather than one of us standing up and teaching everyone.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/02/minecraft-server-launch-project-day/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Temporary network issues</title>
		<link>http://www.netsoc.dit.ie/2012/01/temporary-network-issues/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=temporary-network-issues</link>
		<comments>http://www.netsoc.dit.ie/2012/01/temporary-network-issues/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 16:21:11 +0000</pubDate>
		<dc:creator>Declan Curran</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.netsoc.dit.ie/?p=410</guid>
		<description><![CDATA[We are currently working on our servers, so there will be some unexpected network issues over the next half hour or so. Sorry for any inconveniences.]]></description>
			<content:encoded><![CDATA[<p>We are currently working on our servers, so there will be some unexpected network issues over the next half hour or so. Sorry for any inconveniences.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.netsoc.dit.ie/2012/01/temporary-network-issues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

