<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[blog.rayfoo] &#187; tools</title>
	<atom:link href="http://blog.rayfoo.info/tag/tools/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rayfoo.info</link>
	<description>Here&#039;s where I write stuff, and you read what I wrote.</description>
	<lastBuildDate>Fri, 30 Jul 2010 04:30:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Metasploitable!</title>
		<link>http://blog.rayfoo.info/2010/05/metasploitable</link>
		<comments>http://blog.rayfoo.info/2010/05/metasploitable#comments</comments>
		<pubDate>Fri, 21 May 2010 14:14:23 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[practice]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[Ubuntu]]></category>
		<category><![CDATA[virtual machine]]></category>
		<category><![CDATA[VMware]]></category>
		<category><![CDATA[vulnerable]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=559</guid>
		<description><![CDATA[Metasploit now has a utility to allow people to practise pentesting on a controlled environment.  Termed &#8220;Metasploitable&#8221;, I&#8217;m guessing it is because it is &#8220;pwnable&#8221; It&#8217;s basically an Ubuntu 8.04 server on a VMware 6.5 image, running plenty of old and vulnerable services.  Yummy! It is available to Metasploit Express customers from the Customer Center, [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/05/metasploitable/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weird outgoing IP accesses&#8230;</title>
		<link>http://blog.rayfoo.info/2010/04/weird-outgoing-ip-accesses</link>
		<comments>http://blog.rayfoo.info/2010/04/weird-outgoing-ip-accesses#comments</comments>
		<pubDate>Wed, 28 Apr 2010 16:44:00 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[investigation]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=547</guid>
		<description><![CDATA[Found out by accident (plenty of &#8220;accident&#8221;s happening with me recently) that one of the home computers has been connecting out to some weird China IP amongst others, all of which are blacklisted according to robtex&#8230; Starting to get quite concerned, since there was a lot of stuff that was previously installed, like those that [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/04/weird-outgoing-ip-accesses/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting additional (IP/network/location) info along with your Splunk searches</title>
		<link>http://blog.rayfoo.info/2010/04/getting-additional-ipnetworklocation-info-along-with-your-splunk-searches</link>
		<comments>http://blog.rayfoo.info/2010/04/getting-additional-ipnetworklocation-info-along-with-your-splunk-searches#comments</comments>
		<pubDate>Mon, 19 Apr 2010 17:57:07 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[commands]]></category>
		<category><![CDATA[geolocation]]></category>
		<category><![CDATA[HOWTO]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[Splunk]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=529</guid>
		<description><![CDATA[Chanced upon some of the info by accident (smack at the bottom of one part of the Splunk documentation&#8230;), but I can&#8217;t find it now.  Going to share here anyway Some (or probably most/all) of your searches might involve public IP addresses, and more often than not we would want to have additional info along [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/04/getting-additional-ipnetworklocation-info-along-with-your-splunk-searches/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Troubleshooting Splunk</title>
		<link>http://blog.rayfoo.info/2010/03/troubleshooting-splunk</link>
		<comments>http://blog.rayfoo.info/2010/03/troubleshooting-splunk#comments</comments>
		<pubDate>Mon, 08 Mar 2010 14:27:51 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[data mining]]></category>
		<category><![CDATA[log analysis]]></category>
		<category><![CDATA[log collection]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[Splunk]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=478</guid>
		<description><![CDATA[Have been fiddling around with Splunk lately.  Splunk&#8217;s a really good tool to use for log collection and analysis (and that&#8217;s oversimplifying it, I believe it can even do event correlation&#8230;), which really made my love for data mining go crazy of late:P  Best part is that it has a perpetual free license, nice! One [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/03/troubleshooting-splunk/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful Firefox Plugins</title>
		<link>http://blog.rayfoo.info/2010/03/useful-firefox-plugins</link>
		<comments>http://blog.rayfoo.info/2010/03/useful-firefox-plugins#comments</comments>
		<pubDate>Wed, 03 Mar 2010 15:46:23 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[web application]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=474</guid>
		<description><![CDATA[Sharing my list of favourite Firefox plugins.  Some are used more for only when doing web application penetration testing, whereas some are useful for everyday awareness/protection when surfing around the interwebs.  Do leave comments if this helps, or you have any complaints/suggestions to help improve the list Adblock Plus: you know what this is for&#8230; [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/03/useful-firefox-plugins/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Web Security Dojo v1.0 release</title>
		<link>http://blog.rayfoo.info/2010/02/web-security-dojo-v1-0-release</link>
		<comments>http://blog.rayfoo.info/2010/02/web-security-dojo-v1-0-release#comments</comments>
		<pubDate>Fri, 26 Feb 2010 16:19:48 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[web application]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=455</guid>
		<description><![CDATA[Web Security Dojo is a turnkey web application security lab with tools, targets, and training materials built into a Virtual Machine(VM). It is ideal for both self-instruction and training classes since everything is pre-configured and no external network connection is needed. All tools and targets are configured to use non-conflicting ports and a Firefox proxy [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/02/web-security-dojo-v1-0-release/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Want to learn learn about cryptography and cryptanalysis?</title>
		<link>http://blog.rayfoo.info/2009/10/want-to-learn-learn-about-cryptography-and-cryptanalysis</link>
		<comments>http://blog.rayfoo.info/2009/10/want-to-learn-learn-about-cryptography-and-cryptanalysis#comments</comments>
		<pubDate>Fri, 30 Oct 2009 10:16:56 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[cryptanalysis]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=321</guid>
		<description><![CDATA[CrypTool seems pretty impressive as a learning/teaching tool.  Do check it out! Runs in Windows only, though that&#8217;s not going to stop me from trying to run it under Wine.. heh. Related posts that you might be interested in...May 21, 2010 -- Metasploitable! (0)April 29, 2010 -- Weird outgoing IP accesses&#8230; (0)April 20, 2010 -- [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2009/10/want-to-learn-learn-about-cryptography-and-cryptanalysis/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verifying rkhunter file warnings</title>
		<link>http://blog.rayfoo.info/2009/10/verifying-rkhunter-file-warnings</link>
		<comments>http://blog.rayfoo.info/2009/10/verifying-rkhunter-file-warnings#comments</comments>
		<pubDate>Mon, 12 Oct 2009 06:46:26 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[detection]]></category>
		<category><![CDATA[Finnix]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[rkhunter]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[scripts]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server administration]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=250</guid>
		<description><![CDATA[I got this problem as my rkhunter installation detected changed files (due to updates), so I encountered this solution by steve as I was searching for a solution. Of course, as there could be a root kit/trojan/malicious stuff running in your system as rkhunter&#8217;s meant to detect, you should NOT fully trust anything running from [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2009/10/verifying-rkhunter-file-warnings/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Testing Slowloris against nginx</title>
		<link>http://blog.rayfoo.info/2009/10/testing-slowloris-against-nginx</link>
		<comments>http://blog.rayfoo.info/2009/10/testing-slowloris-against-nginx#comments</comments>
		<pubDate>Mon, 12 Oct 2009 05:59:24 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[RSnake]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Slowloris]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[web server]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=244</guid>
		<description><![CDATA[CCCCCCCCCCOOCCOOOOO888@8@8888OOOOCCOOO888888888@@@@@@@@@8@8@@@@888OOCooocccc:::: CCCCCCCCCCCCCCCOO888@888888OOOCCCOOOO888888888888@88888@@@@@@@888@8OOCCoococc::: CCCCCCCCCCCCCCOO88@@888888OOOOOOOOOO8888888O88888888O8O8OOO8888@88@@8OOCOOOCoc:: CCCCooooooCCCO88@@8@88@888OOOOOOO88888888888OOOOOOOOOOCCCCCOOOO888@8888OOOCc:::: CooCoCoooCCCO8@88@8888888OOO888888888888888888OOOOCCCooooooooCCOOO8888888Cocooc: ooooooCoCCC88@88888@888OO8888888888888888O8O8888OOCCCooooccccccCOOOO88@888OCoccc ooooCCOO8O888888888@88O8OO88888OO888O8888OOOO88888OCocoococ::ccooCOO8O888888Cooo oCCCCCCO8OOOCCCOO88@88OOOOOO8888O888OOOOOCOO88888O8OOOCooCocc:::coCOOO888888OOCC oCCCCCOOO88OCooCO88@8OOOOOO88O888888OOCCCCoCOOO8888OOOOOOOCoc::::coCOOOO888O88OC oCCCCOO88OOCCCCOO8@@8OOCOOOOO8888888OoocccccoCO8O8OO88OOOOOCc.:ccooCCOOOO88888OO CCCOOOO88OOCCOOO8@888OOCCoooCOO8888Ooc::...::coOO88888O888OOo:cocooCCCCOOOOOO88O CCCOO88888OOCOO8@@888OCcc:::cCOO888Oc..... ....cCOOOOOOOOOOOc.:cooooCCCOOOOOOOOO OOOOOO88888OOOO8@8@8Ooc:.:...cOO8O88c. . .coOOO888OOOOCoooooccoCOOOOOCOOOO OOOOO888@8@88888888Oo:. . ...cO888Oc.. .oOOOOOOOOOCCoocooCoCoCOOOOOOOO COOO888@88888888888Oo:. .O8888C: .oCOo. ...cCCCOOOoooooocccooooooooCCCOO CCCCOO888888O888888Oo. .o8Oo. .cO88Oo: :. .:..ccoCCCooCooccooccccoooooCCCC coooCCO8@88OO8O888Oo:::... .. :cO8Oc. . ..... :. .:ccCoooooccoooocccccooooCCC :ccooooCO888OOOO8OOc..:...::. .co8@8Coc::.. .... ..:cooCooooccccc::::ccooCCooC .:::coocccoO8OOOOOOC:..::....coCO8@8OOCCOc:... ....:ccoooocccc:::::::::cooooooC ....::::ccccoCCOOOOOCc......:oCO8@8@88OCCCoccccc::c::.:oCcc:::cccc:..::::coooooo .......::::::::cCCCCCCoocc:cO888@8888OOOOCOOOCoocc::.:cocc::cc:::...:::coocccccc ...........:::..:coCCCCCCCO88OOOO8OOOCCooCCCooccc::::ccc::::::.......:ccocccc:co .............::....:oCCoooooCOOCCOCCCoccococc:::::coc::::....... ...:::cccc:cooo ..... ............. .coocoooCCoco:::ccccccc:::ccc::.......... ....:::cc::::coC . . ... .... [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2009/10/testing-slowloris-against-nginx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
