<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PhishMe &#187; Tools</title>
	<atom:link href="http://blog.phishme.com/category/tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.phishme.com</link>
	<description>Posts about innovative phishing ploys, social engineering techniques, and the latest hacks.  PhishMe is your one stop blog for the latest in anti-phishing and security news.</description>
	<lastBuildDate>Thu, 17 Nov 2011 14:10:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>How do you trust?</title>
		<link>http://blog.phishme.com/2009/01/how-do-you-trust/</link>
		<comments>http://blog.phishme.com/2009/01/how-do-you-trust/#comments</comments>
		<pubDate>Thu, 15 Jan 2009 16:16:59 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[pki]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/?p=131</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2009/01/how-do-you-trust/]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2009/01/how-do-you-trust/">http://intrepidusgroup.com/insight/2009/01/how-do-you-trust/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2009/01/how-do-you-trust/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Peer Guardian for Internal Penetration Tests</title>
		<link>http://blog.phishme.com/2008/05/peer-guardian-for-internal-penetration-tests/</link>
		<comments>http://blog.phishme.com/2008/05/peer-guardian-for-internal-penetration-tests/#comments</comments>
		<pubDate>Mon, 05 May 2008 17:04:51 +0000</pubDate>
		<dc:creator>Aaron</dc:creator>
				<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2008/05/peer-guardian-for-internal-penetration-tests/</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2008/05/peer-guardian-for-internal-penetration-tests/]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2008/05/peer-guardian-for-internal-penetration-tests/">http://intrepidusgroup.com/insight/2008/05/peer-guardian-for-internal-penetration-tests/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2008/05/peer-guardian-for-internal-penetration-tests/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MITM TCP Tools</title>
		<link>http://blog.phishme.com/2008/04/mitm-tcp-tools/</link>
		<comments>http://blog.phishme.com/2008/04/mitm-tcp-tools/#comments</comments>
		<pubDate>Mon, 14 Apr 2008 14:24:58 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[MITM]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tcp]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2008/04/mitm-tcp-tools/</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2008/04/mitm-tcp-tools/ but really, just use mallory. Post is outdated. Cheers]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2008/04/mitm-tcp-tools/">http://intrepidusgroup.com/insight/2008/04/mitm-tcp-tools/</a></p>
<p>but really, just use mallory. Post is outdated. Cheers</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2008/04/mitm-tcp-tools/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>pwn3d by the TS@!</title>
		<link>http://blog.phishme.com/2008/04/pwn3d-by-the-ts/</link>
		<comments>http://blog.phishme.com/2008/04/pwn3d-by-the-ts/#comments</comments>
		<pubDate>Mon, 07 Apr 2008 21:41:53 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Humor]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Web Apps]]></category>
		<category><![CDATA[flying]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2008/04/pwn3d-by-the-ts/</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2008/04/pwn3d-by-the-ts/]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2008/04/pwn3d-by-the-ts/">http://intrepidusgroup.com/insight/2008/04/pwn3d-by-the-ts/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2008/04/pwn3d-by-the-ts/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Shmoocon 2008 wrap-up: The Non-Moose Stuff</title>
		<link>http://blog.phishme.com/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/</link>
		<comments>http://blog.phishme.com/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 19:29:14 +0000</pubDate>
		<dc:creator>Corey</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/">http://intrepidusgroup.com/insight/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2008/02/shmoocon-2008-wrap-up-the-non-moose-stuff/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Phishing with Encoded IP Addresses</title>
		<link>http://blog.phishme.com/2008/01/phishing-with-encoded-ip-addresses/</link>
		<comments>http://blog.phishme.com/2008/01/phishing-with-encoded-ip-addresses/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 15:45:23 +0000</pubDate>
		<dc:creator>Corey</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2008/01/phishing-with-encoded-ip-addresses/</guid>
		<description><![CDATA[I was adding a little special sauce to Phishme.com this past week and thought this might be fun to share. We have a few different ways a user can craft their phishing links. If he/she chooses the IP address option, then there is also the choice of encoding options. This lets you mask the IP [...]]]></description>
			<content:encoded><![CDATA[<p><img border="1" vspace="4" width="399" src="http://blog.phishme.com/wp-content/uploads/2008/01/phishmelinkjs.png" hspace="4" alt="Phishme Phishing Links" height="145" style="width: 399px; height: 145px" title="Phishme Phishing Links" /></p>
<p>I was adding a little special sauce to <a href="http://phishme.com" target="_blank">Phishme.com</a> this past week and thought this might be fun to share. We have a few different ways a user can craft their phishing links. If he/she chooses the IP address option, then there is also the choice of encoding options. This lets you mask the IP address in an attempt to trick the user into thinking part of the sub directory is perhaps the host name. Or as in the case with my mom&#8230; she thinks it is just the phone number so the computer knows where to call.  And it&#8217;s hard to blame her when you see a decimal encoded IP address.</p>
<p>http://2130706433/somecompany.com</p>
<p>The team over at Marshal has put together a <a href="http://www.marshal.com/kb/article.aspx?id=10537" target="_blank">good walk through</a> of the encoding so you can follow along. If you would like to view the javascript, you can find it <a href="http://blog.phishme.com/phishinglink.js" target="_blank">here</a>. This may not work on all browsers, but it holds up pretty well on your corporate windows boxes with IE or Firefox. Want to test it out? Just put in an IP address below and click on the link it generates.</p>
<p>-b3nn</p>
<form>
<input name="ip" id="ip" onkeyup="UpdateRealtimeURL();"/>
<select name="IPEncoding" onchange="UpdateRealtimeURL();" id="IPEncoding">
<option value="Decimal">Decimal</option>
<option value="Octal">Octal</option>
<option value="Hex">Hex</option>
<option value="Hex with Dot">Hex with Dot</option>
</select></form>
<p>
<b>
<div id="divRealtimeURL" align="bottom" style="color: #B51017"></div>
<p></b></p>
<p><script type="text/javascript" src="http://blog.phishme.com/phishinglink.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2008/01/phishing-with-encoded-ip-addresses/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Baiting the Hook, Sneak Peek at PhishMe.com</title>
		<link>http://blog.phishme.com/2007/10/baiting-the-hook-sneak-peak-at-phishmecom/</link>
		<comments>http://blog.phishme.com/2007/10/baiting-the-hook-sneak-peak-at-phishmecom/#comments</comments>
		<pubDate>Wed, 10 Oct 2007 17:22:52 +0000</pubDate>
		<dc:creator>Corey</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2007/10/baiting-the-hook-sneak-peak-at-phishmecom/</guid>
		<description><![CDATA[If you&#8217;ve been noticing a little silence on the blog recently, it&#8217;s been because a lot of the ranting has been going into developing what we think is a great anti-phishing user awareness tool. Take a peek at our main site at www.PhishMe.com Conducting ethical phishing attacks has never been easier. User awareness will be [...]]]></description>
			<content:encoded><![CDATA[<p><img border="0" align="right" width="285" src="http://phishme.com/images/whatis-scenario.jpg" hspace="5" alt="PhishMe" height="189" style="width: 285px; height: 189px" title="PhishMe" />If you&#8217;ve been noticing a little silence on the blog recently, it&#8217;s been because a lot of the ranting has been going into developing what we think is a great anti-phishing user awareness tool. Take a peek at our main site at <a href="http://www.phishme.com/">www.PhishMe.com</a></p>
<p>Conducting ethical phishing attacks has never been easier. User awareness will be improved, enforced, and for the first time for many users, easy to measure and trend over time. You can sign up for the mailing list right now that will let you know when the full blown service is launched. We will be offering free trial accounts that will allow you to get a taste of the features and test out if a few of your users will bite.</p>
<p>Another key feature of PhishMe is the built in templates to make your job of crafting phishing attacks simple yet effective and modern. How do you think your employees would respond to a message about a &#8220;virus outbreak&#8221;. Will they just follow the instruction in an email without verifying any of the information? What about a message to update their HealthCare information on a new third party site? The number of people that fall victim to these types of attacks will make you wonder why hackers even bother with anything that isn&#8217;t social engineering.</p>
<p>There is more to come in the future but for now, check out <a href="http://www.phishme.com/">www.PhishMe.com</a></p>
<p>-b3nn</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2007/10/baiting-the-hook-sneak-peak-at-phishmecom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vasco, an alternative to RSA SecurID hardware tokens</title>
		<link>http://blog.phishme.com/2007/08/vasco-an-alternative-to-rsa-securid-hardware-tokens/</link>
		<comments>http://blog.phishme.com/2007/08/vasco-an-alternative-to-rsa-securid-hardware-tokens/#comments</comments>
		<pubDate>Tue, 28 Aug 2007 15:17:10 +0000</pubDate>
		<dc:creator>Aaron</dc:creator>
				<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Techno]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2007/08/vasco-an-alternative-to-rsa-securid-hardware-tokens/</guid>
		<description><![CDATA[As a security consultant with exposure to many large enterprises I admit I’m biased to RSA SecurID tokens. During penetration tests, our company has cracked tens of thousands of passwords. When I’m standing in front of a customer explaining why their password policies failed, they want to believe that changing this policy will help them. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://blog.phishme.com/wp-content/uploads/2007/08/digipass-go3.jpg" alt="digipass-go3.jpg" title="digipass-go3.jpg" align="left" hspace="2" />As a security consultant with exposure to many large enterprises I admit I’m biased to <a href="http://www.rsa.com/node.aspx?id=1156" target="_blank">RSA SecurID</a> tokens. During penetration tests, our company has cracked tens of thousands of passwords. When I’m standing in front of a customer explaining why their password policies failed, they want to believe that changing this policy will help them. Secretly I know that humans will defeat the spirit of any password policy and that the best approach is to take the responsibility of password composition away from the end user. (When you stare at thousands of clear text passwords you develop a cynicism.)</p>
<p>August2007, you’ve been a good password, but it’s time I move on to owning enterprises with September2007.</p>
<p>The other day a friend asked me if there are any other products like SecurID he should be evaluating for his company as part of their plan to introduce <a href="http://en.wikipedia.org/wiki/Two-factor_authentication" target="_blank">two-factor authentication</a>. Apart from SecurID the only other device that left me thinking “Hey this thing works” is <a href="http://www.vasco.com/products/product.html?product=46" target="_blank">Vasco’s Digipass</a>. Any two factor system worth its weight in salt should provide authentication hooks to the popular services. If you plan to use the solution with custom web applications, you may need to dig a little deeper&#8230;maybe a lot deeper. Most solutions have hook-in APIs, but it takes some effort to piece it all together.</p>
<p>If you are evaluating two factor authentication devices make a list of the top services you need authentication for:</p>
<ul>
<li>Network devices</li>
<li>Windows authentication</li>
<li>Unix authentication</li>
<li>VPN users</li>
<li>Wireless user authentication</li>
</ul>
<p>If a solution can cover 80% of your authentication needs and is cost effective, go with it. 80% coverage is 80% better than letting humans pick passwords; chances are with a little effort and creativity you can put something together to rein in the residual 20%. If you don’t have a two-factor solution, evaluate <a href="http://www.vasco.com/" target="_blank">Vasco</a> with the others.</p>
<p>-higB</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2007/08/vasco-an-alternative-to-rsa-securid-hardware-tokens/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Wrapping Up the Cons: Best of BlackHat and Defcon 2007</title>
		<link>http://blog.phishme.com/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/</link>
		<comments>http://blog.phishme.com/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/#comments</comments>
		<pubDate>Wed, 08 Aug 2007 13:32:43 +0000</pubDate>
		<dc:creator>Corey</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/">http://intrepidusgroup.com/insight/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2007/08/wrapping-up-the-cons-best-of-blackhat-and-defcon-2007/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>EXIF Scrubbing: Hey, Harry! Know your Tool and Wash your Hands.</title>
		<link>http://blog.phishme.com/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/</link>
		<comments>http://blog.phishme.com/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/#comments</comments>
		<pubDate>Thu, 19 Jul 2007 19:00:49 +0000</pubDate>
		<dc:creator>Corey</dc:creator>
				<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://blog.phishme.com/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/</guid>
		<description><![CDATA[Post moved here: http://intrepidusgroup.com/insight/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/]]></description>
			<content:encoded><![CDATA[<p>Post moved here: <a href="http://intrepidusgroup.com/insight/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/">http://intrepidusgroup.com/insight/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.phishme.com/2007/07/exif-scrubbing-hey-harry-know-your-tool-and-wash-your-hands/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

