<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Day 3: ITSM Vulnerability Assessment techniques</title>
	<link>http://www.tssci-security.com/archives/2008/01/09/day-3-itsm-vulnerability-assessment-techniques/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Fri, 08 Aug 2008 19:11:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: Marcin</title>
		<link>http://www.tssci-security.com/archives/2008/01/09/day-3-itsm-vulnerability-assessment-techniques/#comment-3593</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Wed, 09 Jan 2008 20:09:10 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/01/09/day-3-itsm-vulnerability-assessment-techniques/#comment-3593</guid>
		<description>Hey nblracer... Having a strong fundamental understanding of the protocols the tools are used for is necessary in knowing how to use the tool. For example, using an HTTP proxy to intercept requests and modify parts of the header, if you know rfc2616, you'll be able to get up and running with the tool no problem. Same goes for using a tool like ettercap and arspoof to perform a MITM attack and sniff traffic, where an understanding of routing and networking concepts and how ARP works is necessary to know how to use the tool effectively... Your comment has sparked an idea for us, in that we'll try to post use cases for the tools we discuss in between postings. Definitely take a look through our archives to get a better understanding of the kinds of research and work we do. More later, I'm inbetween flights.</description>
		<content:encoded><![CDATA[<p>Hey nblracer&#8230; Having a strong fundamental understanding of the protocols the tools are used for is necessary in knowing how to use the tool. For example, using an HTTP proxy to intercept requests and modify parts of the header, if you know rfc2616, you&#8217;ll be able to get up and running with the tool no problem. Same goes for using a tool like ettercap and arspoof to perform a MITM attack and sniff traffic, where an understanding of routing and networking concepts and how ARP works is necessary to know how to use the tool effectively&#8230; Your comment has sparked an idea for us, in that we&#8217;ll try to post use cases for the tools we discuss in between postings. Definitely take a look through our archives to get a better understanding of the kinds of research and work we do. More later, I&#8217;m inbetween flights.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nblracer</title>
		<link>http://www.tssci-security.com/archives/2008/01/09/day-3-itsm-vulnerability-assessment-techniques/#comment-3591</link>
		<dc:creator>nblracer</dc:creator>
		<pubDate>Wed, 09 Jan 2008 18:10:19 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2008/01/09/day-3-itsm-vulnerability-assessment-techniques/#comment-3591</guid>
		<description>I'm new to your blog; And not sure, or had time to dig though the archives, to see how things are done here. But i would like to see some walk though with these tools you mentioned. Just my two cents.</description>
		<content:encoded><![CDATA[<p>I&#8217;m new to your blog; And not sure, or had time to dig though the archives, to see how things are done here. But i would like to see some walk though with these tools you mentioned. Just my two cents.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.175 seconds -->
