<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Episode 513 &#8211; Extract Windows Executables from Packet Captures, PHP Gmail Badges, Winning the Easter Egg Hunt, and special guest Eighty of DualCore</title>
	<atom:link href="http://www.hak5.org/episodes/episode-513/feed" rel="self" type="application/rss+xml" />
	<link>http://www.hak5.org/episodes/episode-513</link>
	<description></description>
	<lastBuildDate>Sat, 20 Mar 2010 21:00:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Usedtire</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-36137</link>
		<dc:creator>Usedtire</dc:creator>
		<pubDate>Fri, 12 Jun 2009 11:50:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-36137</guid>
		<description>The best you could find was DualCore?  That guy programs everything in Visual Basic.  ;)  

Now being serious DualCore&#039;s music is awesome and int eighty knows his stuff.  He needs to be on the show moer often.  Great episode.  I learned a lot.  Now I just need to get int eighty to explain it all to me.</description>
		<content:encoded><![CDATA[<p>The best you could find was DualCore?  That guy programs everything in Visual Basic.  <img src='http://www.hak5.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />   </p>
<p>Now being serious DualCore&#8217;s music is awesome and int eighty knows his stuff.  He needs to be on the show moer often.  Great episode.  I learned a lot.  Now I just need to get int eighty to explain it all to me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ross</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35415</link>
		<dc:creator>Ross</dc:creator>
		<pubDate>Tue, 19 May 2009 00:21:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35415</guid>
		<description></description>
		<content:encoded><![CDATA[<p>Shannon,</p>
<p>Theres a brand new hack for the wii that lets you put the homebrew channel on wii menu 4.0! Heres the link for it: <a href="http://wiibrew.org/wiki/BaNNeRBoMB" rel="nofollow">http://wiibrew.org/wiki/BaNNeRBoMB</a>. I’ve tested it, and it works, so definitely check it out</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35403</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Mon, 18 May 2009 06:28:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35403</guid>
		<description>Darren,

Nice... Let me know if you&#039;ve got some questions about NetworkMiner for the show!</description>
		<content:encoded><![CDATA[<p>Darren,</p>
<p>Nice&#8230; Let me know if you&#8217;ve got some questions about NetworkMiner for the show!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darren</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35391</link>
		<dc:creator>Darren</dc:creator>
		<pubDate>Sun, 17 May 2009 16:37:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35391</guid>
		<description>Erik,

It&#039;s funny you mention this. Stick around for next week&#039;s show. NetworkMiner, as well as a similar fuller featured application, is shown.</description>
		<content:encoded><![CDATA[<p>Erik,</p>
<p>It&#8217;s funny you mention this. Stick around for next week&#8217;s show. NetworkMiner, as well as a similar fuller featured application, is shown.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35388</link>
		<dc:creator>Erik</dc:creator>
		<pubDate>Sun, 17 May 2009 13:55:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35388</guid>
		<description>A tool that is better at extracting files from pcaps is &lt;a href=&quot;http://networkminer.sourceforge.net/&quot; title=&quot;Network Miner&quot; rel=&quot;nofollow&quot;&gt;NetworkMiner&lt;/a&gt;. NetworkMiner can extract files of all formats, not just jpeg and exe. The secret is that NetworkMiner does deep packet inspection rather than file carving (like tcpxtract). This also makes it possible to extract files from HTTP sessions that use chunked or compressed transferes.

Another cool thing with NetworkMiner is also that it can be used to sniff the traffic, so no need to sniff with one app and analyze with anoter anymore.

Check it out on sourceforge:
http://networkminer.sourceforge.net/</description>
		<content:encoded><![CDATA[<p>A tool that is better at extracting files from pcaps is <a href="http://networkminer.sourceforge.net/" title="Network Miner" rel="nofollow">NetworkMiner</a>. NetworkMiner can extract files of all formats, not just jpeg and exe. The secret is that NetworkMiner does deep packet inspection rather than file carving (like tcpxtract). This also makes it possible to extract files from HTTP sessions that use chunked or compressed transferes.</p>
<p>Another cool thing with NetworkMiner is also that it can be used to sniff the traffic, so no need to sniff with one app and analyze with anoter anymore.</p>
<p>Check it out on sourceforge:<br />
<a href="http://networkminer.sourceforge.net/" rel="nofollow">http://networkminer.sourceforge.net/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Darren</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35330</link>
		<dc:creator>Darren</dc:creator>
		<pubDate>Fri, 15 May 2009 15:54:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35330</guid>
		<description>IDA is a disassembler.
http://www.hex-rays.com/idapro/</description>
		<content:encoded><![CDATA[<p>IDA is a disassembler.<br />
<a href="http://www.hex-rays.com/idapro/" rel="nofollow">http://www.hex-rays.com/idapro/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: choekstr</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35328</link>
		<dc:creator>choekstr</dc:creator>
		<pubDate>Fri, 15 May 2009 14:53:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35328</guid>
		<description>Anyone know what tool int80 is talking about when he references &quot;ida&quot; (sp?) sandbox program?  I did some google searches but didn&#039;t come up with much.  I currently use sandboxie but find it a bit obtrusive to the system and I have had a malware infected keygen break out of it and don&#039;t trust it anymore.  An alternative sandbox would be nice to try out.

Thanks for any insight,
choekstr</description>
		<content:encoded><![CDATA[<p>Anyone know what tool int80 is talking about when he references &#8220;ida&#8221; (sp?) sandbox program?  I did some google searches but didn&#8217;t come up with much.  I currently use sandboxie but find it a bit obtrusive to the system and I have had a malware infected keygen break out of it and don&#8217;t trust it anymore.  An alternative sandbox would be nice to try out.</p>
<p>Thanks for any insight,<br />
choekstr</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35313</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Thu, 14 May 2009 23:19:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35313</guid>
		<description>If you&#039;re going to be using debug to dump an EXE payload, wouldn&#039;t you be sending it via ASCII in assembly? Then it converts the assembly lang to an exe and it wouldn&#039;t have the binary header you&#039;re referring to. That&#039;s why it&#039;s called a &quot;bypass&quot;, correct? There&#039;s where the 64kb limit comes in -- you&#039;re limited to 64kb of plaintext (albeit asm) code. This is just from old memory -- been a while for me.</description>
		<content:encoded><![CDATA[<p>If you&#8217;re going to be using debug to dump an EXE payload, wouldn&#8217;t you be sending it via ASCII in assembly? Then it converts the assembly lang to an exe and it wouldn&#8217;t have the binary header you&#8217;re referring to. That&#8217;s why it&#8217;s called a &#8220;bypass&#8221;, correct? There&#8217;s where the 64kb limit comes in &#8212; you&#8217;re limited to 64kb of plaintext (albeit asm) code. This is just from old memory &#8212; been a while for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ioyou</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35309</link>
		<dc:creator>ioyou</dc:creator>
		<pubDate>Thu, 14 May 2009 22:19:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35309</guid>
		<description>@Shikata
I would have never thought that they would watch it during class.  Although i have lived in Germany and gone to school there, the only time people watch porn is usually during lunch or after school while nobody is around.
That is what happened at my school since it has a 1gb uplink and everyone in the school who bought a laptop could access the network.

But the sys admins got smart and decided to implement to implement new cisco switches which scan the packages.

so now they have resorted to ssh tunneling to get passed the packaged scanning lol

German students get resourceful lol.

@Snubs
You must show us how you can take so long lol</description>
		<content:encoded><![CDATA[<p>@Shikata<br />
I would have never thought that they would watch it during class.  Although i have lived in Germany and gone to school there, the only time people watch porn is usually during lunch or after school while nobody is around.<br />
That is what happened at my school since it has a 1gb uplink and everyone in the school who bought a laptop could access the network.</p>
<p>But the sys admins got smart and decided to implement to implement new cisco switches which scan the packages.</p>
<p>so now they have resorted to ssh tunneling to get passed the packaged scanning lol</p>
<p>German students get resourceful lol.</p>
<p>@Snubs<br />
You must show us how you can take so long lol</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Shikata</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35307</link>
		<dc:creator>Shikata</dc:creator>
		<pubDate>Thu, 14 May 2009 21:26:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35307</guid>
		<description>@ioyou
I work at an institution (that is not an invite to trace my IP guys) and everyone thinks it&#039;s their &quot;RIGHT&quot; to view what they want on the education network. It gets bad when they start doing it in class and it gets broadcasted to our electronic classrooms that are conferenced in 200+ miles away.

@Snubs
I was giving you the benefit of the doubt to explain yourself, but if you&#039;re just going to blame on the noobs I would like you to time yourself the next time you put your seat belt on. 

0-2s - You&#039;re ok
3-5s - You&#039;re getting old
6-10s - Drunk/Noob
11-15s - You&#039;re high and can&#039;t figure it out. 
15+ - You are autistic and/or have ADHD (or your name is Shannon)

Please give us the results. I also welcome anyone to adjust my descriptions to your liking.</description>
		<content:encoded><![CDATA[<p>@ioyou<br />
I work at an institution (that is not an invite to trace my IP guys) and everyone thinks it&#8217;s their &#8220;RIGHT&#8221; to view what they want on the education network. It gets bad when they start doing it in class and it gets broadcasted to our electronic classrooms that are conferenced in 200+ miles away.</p>
<p>@Snubs<br />
I was giving you the benefit of the doubt to explain yourself, but if you&#8217;re just going to blame on the noobs I would like you to time yourself the next time you put your seat belt on. </p>
<p>0-2s &#8211; You&#8217;re ok<br />
3-5s &#8211; You&#8217;re getting old<br />
6-10s &#8211; Drunk/Noob<br />
11-15s &#8211; You&#8217;re high and can&#8217;t figure it out.<br />
15+ &#8211; You are autistic and/or have ADHD (or your name is Shannon)</p>
<p>Please give us the results. I also welcome anyone to adjust my descriptions to your liking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ioyou</title>
		<link>http://www.hak5.org/episodes/episode-513/comment-page-1#comment-35305</link>
		<dc:creator>ioyou</dc:creator>
		<pubDate>Thu, 14 May 2009 20:26:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.hak5.org/?p=1118#comment-35305</guid>
		<description>@Shikata
Nice choice on monitoring your intranet.
I can&#039;t believe that someone decided to watch erotic videos during lol

@[3w`Sparky]
Ya that&#039;s a good idea with the levels. although i got pretty far. I had all the clues just didn&#039;t know that the password for the zip was the code of the last one.</description>
		<content:encoded><![CDATA[<p>@Shikata<br />
Nice choice on monitoring your intranet.<br />
I can&#8217;t believe that someone decided to watch erotic videos during lol</p>
<p>@[3w`Sparky]<br />
Ya that&#8217;s a good idea with the levels. although i got pretty far. I had all the clues just didn&#8217;t know that the password for the zip was the code of the last one.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
