<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HackerTarget.com : Online Security Vulnerability Assessment &#187; Site Updates</title>
	<atom:link href="http://hackertarget.com/category/site-updates/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackertarget.com</link>
	<description>Everyone is a target : Test your security now</description>
	<lastBuildDate>Wed, 09 Jun 2010 08:09:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Sqlmap 0.8 Released and Rolled out to HackerTarget.com servers</title>
		<link>http://hackertarget.com/2010/04/sqlmap-0-8-released-and-rolled-out-to-hackertarget-com-servers/</link>
		<comments>http://hackertarget.com/2010/04/sqlmap-0-8-released-and-rolled-out-to-hackertarget-com-servers/#comments</comments>
		<pubDate>Thu, 08 Apr 2010 00:41:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[sqlmap]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=457</guid>
		<description><![CDATA[After discovering the new release of the excellent SQL Injection tool sqlmap I have done some testing and rolled it out to the HackerTarget.com scanning servers.
If you are not familiar with the power of sqlmap head over to the sourceforge site for demo videos and some top notch documentation. Our scanning tools are configured to [...]]]></description>
			<content:encoded><![CDATA[<p>After discovering the new release of the excellent SQL Injection tool <a href="http://sqlmap.sourceforge.net">sqlmap</a> I have done some testing and rolled it out to the <a href="http://www.hackertarget.com">HackerTarget.com</a> scanning servers.</p>
<p>If you are not familiar with the power of sqlmap head over to the <a href="http://sqlmap.sourceforge.net">sourceforge site</a> for demo videos and some top notch <a href="http://sqlmap.sourceforge.net/doc/README.html">documentation</a>. Our scanning tools are configured to discover sql injection holes. However the full power of sqlmap allows you move into the exploitation phase and take over a server &#8211; an excellent tool for penetration testing and showing management how serious sql injection holes can be. New features include integration with <a href="http://www.metasploit.com">Metasploit</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2010/04/sqlmap-0-8-released-and-rolled-out-to-hackertarget-com-servers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Scanner Comparison</title>
		<link>http://hackertarget.com/2010/02/web-scanner-comparison/</link>
		<comments>http://hackertarget.com/2010/02/web-scanner-comparison/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 01:41:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=435</guid>
		<description><![CDATA[An interesting report has been released that takes a sample of web application security testing applications and puts them up against each other.
The most notably thing is how much the results vary, and how many vulnerabilities most scanners miss. Clearly using more than one scanner is necessary to be able to compare the results, and [...]]]></description>
			<content:encoded><![CDATA[<p>An interesting <a href="http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf" target="_blank">report</a> has been released that takes a sample of web application security testing applications and puts them up against each other.</p>
<p>The most notably thing is how much the results vary, and how many vulnerabilities most scanners miss. Clearly using more than one scanner is necessary to be able to compare the results, and nothing can beat testing by skilled security professionals.</p>
<blockquote><p>NTOSpider by NT Objectives came out in the lead with the best overall score of the application scanners tested (which included Acunetix, Appscan, Burp Suite Pro, Hailstorm, WebInspect, and NTOSpider). He also measured things like how long the various scanners take to configure, support and so on &#8211; all important things for companies about to make the big investment. This isn’t all scanners everywhere (notably WhiteHat is missing as is the newest player to the field, NetSparker who incidentally took it upon themselves to add themselves into the report after the fact, and other free web assessment tools, like Nikto etc…), but it’s a great start to a long future of heavily debated research, I’m sure. Love him, or hate him, Larry’s always got interesting research to share!</p></blockquote>
<p><a href="http://ha.ckers.org/blog/20100203/accuracy-and-time-costs-of-web-application-security-scanner-report/" target="_blank">Accuracy and Time Costs of Web Application Security Scanner Report</a></p>
<p>I guess now would be a good time to point out that even if you cough up the money for a commercial scanner or perhaps an online scanning service such as <a href="http://www.qualys.com/" target="_blank">Qualys</a> or <a href="https://www.controlscan.com/index.php" target="_blank">ControlScan</a> getting a second opinion from a service such as ours here at <a href="http://www.hackertarget.com">HackerTarget.com</a> is an excellent way to get a second option.</p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2010/02/web-scanner-comparison/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nikto 2.1.0 released and rolled out</title>
		<link>http://hackertarget.com/2010/01/nikto-2-1-0-released-and-rolled-out/</link>
		<comments>http://hackertarget.com/2010/01/nikto-2-1-0-released-and-rolled-out/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:29:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[nikto]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=419</guid>
		<description><![CDATA[The latest version of Nikto has been rolled out to our web scanning servers.
Enjoy the web scanning from the leading open source web scanning tool.
Head over to Cirt.net for full details.
]]></description>
			<content:encoded><![CDATA[<p>The latest version of Nikto has been rolled out to our <a href="http://www.hackertarget.com/website-scan">web scanning servers</a>.</p>
<p>Enjoy the web scanning from the leading open source web scanning tool.</p>
<p>Head over to <a href="http://www.cirt.net" target="_blank">Cirt.net</a> for full details.</p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2010/01/nikto-2-1-0-released-and-rolled-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nmap 5.21 released and rolled out</title>
		<link>http://hackertarget.com/2010/01/nmap-5-21-released-and-rolled-out/</link>
		<comments>http://hackertarget.com/2010/01/nmap-5-21-released-and-rolled-out/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 03:14:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[firewall test]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[port scanner]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=417</guid>
		<description><![CDATA[A new year, and new updates. We have rolled out the latest version of Nmap to all our scan servers. Happy scanning in 2010.
Latest version includes performance improvements, new OS finger printing and a new traceroute engine.
]]></description>
			<content:encoded><![CDATA[<p>A new year, and new updates. We have rolled out the latest version of <a href="http://www.nmap.org" target="_blank">Nmap</a> to all our scan servers. Happy <a href="http://hackertarget.com/nmap-scan">scanning</a> in 2010.</p>
<p>Latest version includes performance improvements, new OS finger printing and a new traceroute engine.</p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2010/01/nmap-5-21-released-and-rolled-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Service Week</title>
		<link>http://hackertarget.com/2009/08/mozilla-service-week/</link>
		<comments>http://hackertarget.com/2009/08/mozilla-service-week/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 21:15:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=382</guid>
		<description><![CDATA[An online volunteering initiative by the Mozilla foundation is a great initiative intending to bring online volunteering together with organisations and individuals requiring assistance.
We believe the Internet should make life better. Join us the week of September 14-21, 2009, as we take action to make a difference in our communities, our world, our Web.
At HackerTarget.com [...]]]></description>
			<content:encoded><![CDATA[<p><a href='http://www.mozillaservice.org/?from=sfx&amp;uid=0&amp;t=472'><img src='http://sfx-images.mozilla.org/msw/110x32_red.png' align="right" alt='Spread Firefox Affiliate Button' border='0' /></a>An <a href="http://mozillaservice.org/">online volunteering initiative</a> by the <a href="http://www.mozilla.com/">Mozilla</a> foundation is a great initiative intending to bring online volunteering together with organisations and individuals requiring assistance.</p>
<blockquote><p>We believe the Internet should make life better. Join us the week of September 14-21, 2009, as we take action to make a difference in our communities, our world, our Web.</p></blockquote>
<p>At <a href="www.hackertarget.com">HackerTarget.com</a> we have pledged our support and are willing to provide <a href="http://hackertarget.com/nonprofit-and-ngo/">non-profit organisations and NGO&#8217;s</a> with free full security vulnerability assessments. Information Security is important to any organisation and we intend to assist specific organisations and raise awareness of the need for a good security process.</p>
<p><a href="http://mozillaservice.org/">Mozilla Service Week</a></p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2009/08/mozilla-service-week/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Whitepaper Released &#8211; Security Scanning Tools Overview</title>
		<link>http://hackertarget.com/2009/08/new-whitepaper-released-security-scanning-tools-overview/</link>
		<comments>http://hackertarget.com/2009/08/new-whitepaper-released-security-scanning-tools-overview/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 07:25:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=364</guid>
		<description><![CDATA[HackerTarget.com has now performed well over 10&#8242;000 free vulnerability scans, we now have a tool box of 6 different scanning options and each provides a different type of security test.
Analysis of our scan history shows many of our users do not fully understand the role of each different tool. So we have released a new [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hackertarget.com">HackerTarget.com</a> has now performed well over 10&#8242;000 free vulnerability scans, we now have a tool box of 6 different scanning options and each provides a different type of security test.</p>
<p>Analysis of our scan history shows many of our users do not fully understand the role of each different tool. So we have <a href="http://hackertarget.com/whitepapers/HackerTarget.com-Security-Tools-Overview.pdf">released a new paper</a> that summarises each tool and provides links to the full documentation of each of these tools.</p>
<p>Includes details and sample output from each of our scan options; including the online nmap port scan, the OpenVas Vulnerability Scanner, Fierce dns scanner, Nikto Web Scanner, SQL Injection scanning option and the Joomla site scanner.</p>
<p><a href="http://hackertarget.com/whitepapers/HackerTarget.com-Security-Tools-Overview.pdf">HackerTarget.com Security Scanning Tools Overview</a></p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2009/08/new-whitepaper-released-security-scanning-tools-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Uservoice &#8211; Make a suggestion</title>
		<link>http://hackertarget.com/2009/08/uservoice-make-a-suggestion/</link>
		<comments>http://hackertarget.com/2009/08/uservoice-make-a-suggestion/#comments</comments>
		<pubDate>Sun, 16 Aug 2009 08:46:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=358</guid>
		<description><![CDATA[Would you like to suggest improvements to the HackerTarget.com scanning suite or services? We have setup an an account at the new uservoice.com site.
Head on over and let us know your ideas, add your votes to the ones you like.
]]></description>
			<content:encoded><![CDATA[<p>Would you like to suggest improvements to the <a href="http://hackertarget.com">HackerTarget.com</a> scanning suite or services? We have setup an <a href="http://hackertarget.uservoice.com">an account at the new uservoice.com site.</a></p>
<p>Head on over and let us know your ideas, add your votes to the ones you like.</p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2009/08/uservoice-make-a-suggestion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nmap 5.00 added to HackerTarget.com Scanning Suite</title>
		<link>http://hackertarget.com/2009/07/nmap-500-added-to-hackertargetcom-scanning-suite/</link>
		<comments>http://hackertarget.com/2009/07/nmap-500-added-to-hackertargetcom-scanning-suite/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 22:25:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=301</guid>
		<description><![CDATA[Hot off the forges of Fyodor comes the latest release of the worlds leading port scanner. Nmap 5.00 has been released, and we have immediately implemented it here at HackerTarget.com.
Keep an eye out as we explore some of the new features, we will be sure to implement them here, keeping HackerTarget.com the number one stop [...]]]></description>
			<content:encoded><![CDATA[<p>Hot off the <a href="http://www.insecure.org">forges of Fyodor</a> comes the latest release of the worlds leading port scanner. Nmap 5.00 has been released, and we have immediately implemented it here at <a href="http://www.hackertarget.com/nmap-scan">HackerTarget.com</a>.</p>
<p>Keep an eye out as we explore some of the new features, we will be sure to implement them here, keeping HackerTarget.com the number one stop for all your online vulnerability scanning solutions.</p>
<blockquote><p>Before we go into the detailed changes, here are the top 5 improvements in Nmap 5:</p>
<p>   1.      The new Ncat tool aims to be your Swiss Army Knife for data transfer, redirection, and debugging. We released a whole users&#8217; guide detailing security testing and network administration tasks made easy with Ncat.<br />
   2.      The addition of the Ndiff scan comparison tool completes Nmap&#8217;s growth into a whole suite of applications which work together to serve network administrators and security practitioners. Ndiff makes it easy to automatically scan your network daily and report on any changes (systems coming up or going down or changes to the software services they are running). The other two tools now packaged with Nmap itself are Ncat and the much improved Zenmap GUI and results viewer.<br />
   3.      Nmap performance has improved dramatically. We spent last summer scanning much of the Internet and merging that data with internal enterprise scan logs to determine the most commonly open ports. This allows Nmap to scan fewer ports by default while finding more open ports. We also added a fixed-rate scan engine so you can bypass Nmap&#8217;s congestion control algorithms and scan at exactly the rate (packets per second) you specify.<br />
   4. We released Nmap Network Scanning, the official Nmap guide to network discovery and security scanning. From explaining port scanning basics for novices to detailing low-level packet crafting methods used by advanced hackers, this book suits all levels of security and networking professionals. A 42-page reference guide documents every Nmap feature and option, while the rest of the book demonstrates how to apply those features to quickly solve real-world tasks. More than half the book is available in the free online edition.<br />
   5.      The Nmap Scripting Engine (NSE) is one of Nmap&#8217;s most powerful and flexible features. It allows users to write (and share) simple scripts to automate a wide variety of networking tasks. Those scripts are then executed in parallel with the speed and efficiency you expect from Nmap. All existing scripts have been improved, and 32 new ones added. New scripts include a whole bunch of MSRPC/NetBIOS attacks, queries, and vulnerability probes; open proxy detection; whois and AS number lookup queries; brute force attack scripts against the SNMP and POP3 protocols; and many more. All NSE scripts and modules are described in the new NSE documentation portal. </p></blockquote>
<p><a href="http://nmap.org/5/#5changes">http://nmap.org/5/#5changes</a></p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2009/07/nmap-500-added-to-hackertargetcom-scanning-suite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSH failed logins for past month</title>
		<link>http://hackertarget.com/2009/06/ssh-failed-logins-for-past-month/</link>
		<comments>http://hackertarget.com/2009/06/ssh-failed-logins-for-past-month/#comments</comments>
		<pubDate>Tue, 23 Jun 2009 11:07:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=203</guid>
		<description><![CDATA[This graph shows the failed logins into one of our servers for the past month. As you can see they get hammered &#8211; just like most servers on the Internet.
I will look at doing some more with the stats to get more of a trend over time, perhaps full automating and building some graphical representations [...]]]></description>
			<content:encoded><![CDATA[<p>This graph shows the failed logins into one of our servers for the past month. As you can see they get hammered &#8211; just like most servers on the Internet.</p>
<p>I will look at doing some more with the stats to get more of a trend over time, perhaps full automating and building some graphical representations of the data over the months.</p>
<p><img src="http://www.hackertarget.com/ssh-failed-login-attempts.png" alt="ssh failed logins for month - source and number of attempts" /></p>
<p>As you can see 122.3.9.40 is a busy little server, whois reveals the system is based in the Philippines and a google of the IP shows it be on a number of lists of attacking systems, including one called botnet.txt. So as is likely for most the high scores in this list, they will no doubt be compromised machines used to launch attacks scanning whole ranges of IP&#8217;s for open or poorly passworded ssh servers.</p>
<p>So now might be a good time to reset all your accounts and make sure you have strong passwords. These ssh brute force attacks are not going away any time soon.</p>
<p>An excellent method of avoiding these attacks is to change your ssh listen port. Simple to do &#8211; just change the &#8220;Listen&#8221; directive in /etc/sshd/sshd_config.</p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2009/06/ssh-failed-logins-for-past-month/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQLmap added to our free sql injection service</title>
		<link>http://hackertarget.com/2009/06/sqlmap-added-to-our-free-sql-injection-service/</link>
		<comments>http://hackertarget.com/2009/06/sqlmap-added-to-our-free-sql-injection-service/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 11:23:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Site Updates]]></category>

		<guid isPermaLink="false">http://hackertarget.com/?p=197</guid>
		<description><![CDATA[HackerTarget.com are happy to announce a new addition to our free vulnerability scanning services. Sqlmap has recently been released in version 7.0RC1, this is one of the most powerful sql injection tools available with a wide array of functions for sql injection detection and exploitation.
We have added it to our basic sql injection tool that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://hackertarget.com">HackerTarget.com</a> are happy to announce a new addition to our free vulnerability scanning services. <a href="http://sqlmap.sourceforge.net">Sqlmap</a> has recently been released in version 7.0RC1, this is one of the most powerful sql injection tools available with a wide array of functions for sql injection detection and exploitation.</p>
<p>We have added it to our basic sql injection tool that allows you to enter a suspect url (that you own or have permission to scan) and have the url checked for sql injection points.</p>
<p><a href="/free-sql-scan">Click over here now to test it out</a></p>
]]></content:encoded>
			<wfw:commentRss>http://hackertarget.com/2009/06/sqlmap-added-to-our-free-sql-injection-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
