<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: My first pentest on a friend&#8217;s network	</title>
	<atom:link href="/my-first-pentest-on-a-friends-network/feed/" rel="self" type="application/rss+xml" />
	<link>/my-first-pentest-on-a-friends-network/</link>
	<description>A place for my thoughts when I was starting to break into the information security feild</description>
	<lastBuildDate>Wed, 30 Oct 2024 17:15:23 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.2</generator>
	<item>
		<title>
		By: Graeme Robinson		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-4025271</link>

		<dc:creator><![CDATA[Graeme Robinson]]></dc:creator>
		<pubDate>Fri, 20 Mar 2015 16:01:42 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-4025271</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/my-first-pentest-on-a-friends-network/#comment-3772195&quot;&gt;mike&lt;/a&gt;.

That&#039;s a great idea, nice one. Unfortunately he&#039;s tightened up his security and removed most of the attack surface that I used, so I&#039;d have to start all over.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/my-first-pentest-on-a-friends-network/#comment-3772195">mike</a>.</p>
<p>That&#8217;s a great idea, nice one. Unfortunately he&#8217;s tightened up his security and removed most of the attack surface that I used, so I&#8217;d have to start all over.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: mike		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-3772195</link>

		<dc:creator><![CDATA[mike]]></dc:creator>
		<pubDate>Tue, 03 Mar 2015 21:05:43 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-3772195</guid>

					<description><![CDATA[Hey. Just wondering -- what about sniffing the UnRAID credentials? You said that it&#039;s running over basic access authentication, which is only base64 encoded. Maybe that interface is running over HTTPS, but you now have root so you can get the certificate for that, start sniffing traffic, and then have your friend log into UnRAID. You could even sabotage UnRAID to force him to login and fix it if asking him to log in is not realistic.]]></description>
			<content:encoded><![CDATA[<p>Hey. Just wondering &#8212; what about sniffing the UnRAID credentials? You said that it&#8217;s running over basic access authentication, which is only base64 encoded. Maybe that interface is running over HTTPS, but you now have root so you can get the certificate for that, start sniffing traffic, and then have your friend log into UnRAID. You could even sabotage UnRAID to force him to login and fix it if asking him to log in is not realistic.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Graeme Robinson		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-174276</link>

		<dc:creator><![CDATA[Graeme Robinson]]></dc:creator>
		<pubDate>Tue, 02 Sep 2014 12:41:51 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-174276</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/my-first-pentest-on-a-friends-network/#comment-174266&quot;&gt;Ariel Barnatan&lt;/a&gt;.

I&#039;m not sure as I don&#039;t have an UnRAID box myself, but I can&#039;t see why not. I know someone who uses UnRAID and probably also uses transmission so I can ask them if you&#039;d like?

Update: Oh - this person used both, though transmission wasn&#039;t running on his UnRAID sever. I&#039;ll ask them if they moved transmission over to the UnRAID]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/my-first-pentest-on-a-friends-network/#comment-174266">Ariel Barnatan</a>.</p>
<p>I&#8217;m not sure as I don&#8217;t have an UnRAID box myself, but I can&#8217;t see why not. I know someone who uses UnRAID and probably also uses transmission so I can ask them if you&#8217;d like?</p>
<p>Update: Oh &#8211; this person used both, though transmission wasn&#8217;t running on his UnRAID sever. I&#8217;ll ask them if they moved transmission over to the UnRAID</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Ariel Barnatan		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-174266</link>

		<dc:creator><![CDATA[Ariel Barnatan]]></dc:creator>
		<pubDate>Tue, 02 Sep 2014 12:05:45 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-174266</guid>

					<description><![CDATA[hi Graeme, very interesting article. i wonder if you know - is it possible to password-protect the transmission webgui under UNRAID?]]></description>
			<content:encoded><![CDATA[<p>hi Graeme, very interesting article. i wonder if you know &#8211; is it possible to password-protect the transmission webgui under UNRAID?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: stejkenzie		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-158</link>

		<dc:creator><![CDATA[stejkenzie]]></dc:creator>
		<pubDate>Tue, 14 May 2013 15:55:57 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-158</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/my-first-pentest-on-a-friends-network/#comment-157&quot;&gt;Graeme Robinson&lt;/a&gt;.

I think I love you! Thank you very much :D]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/my-first-pentest-on-a-friends-network/#comment-157">Graeme Robinson</a>.</p>
<p>I think I love you! Thank you very much 😀</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Graeme Robinson		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-157</link>

		<dc:creator><![CDATA[Graeme Robinson]]></dc:creator>
		<pubDate>Tue, 14 May 2013 14:51:05 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-157</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/my-first-pentest-on-a-friends-network/#comment-156&quot;&gt;stejkenzie&lt;/a&gt;.

Done, check the top of the column on the right just under the beans!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/my-first-pentest-on-a-friends-network/#comment-156">stejkenzie</a>.</p>
<p>Done, check the top of the column on the right just under the beans!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: stejkenzie		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-156</link>

		<dc:creator><![CDATA[stejkenzie]]></dc:creator>
		<pubDate>Mon, 13 May 2013 16:49:51 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-156</guid>

					<description><![CDATA[Well, I would like to subscibe to your blog. Frequency of updates doesn&#039;t matter, at least you won&#039;t spam my RSS reader ;) But of course, that depends on you, I never set up RSS feed before so I have no idea how much trouble it is.]]></description>
			<content:encoded><![CDATA[<p>Well, I would like to subscibe to your blog. Frequency of updates doesn&#8217;t matter, at least you won&#8217;t spam my RSS reader 😉 But of course, that depends on you, I never set up RSS feed before so I have no idea how much trouble it is.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Graeme Robinson		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-155</link>

		<dc:creator><![CDATA[Graeme Robinson]]></dc:creator>
		<pubDate>Mon, 13 May 2013 13:43:51 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-155</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/my-first-pentest-on-a-friends-network/#comment-154&quot;&gt;stejkenzie&lt;/a&gt;.

Hi Martin,

Thanks for the comment. To be honest I didn&#039;t think I would update this blog often enough that anyone would want to subscribe to an RSS feed, but if you&#039;d like I can probably set that up?]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/my-first-pentest-on-a-friends-network/#comment-154">stejkenzie</a>.</p>
<p>Hi Martin,</p>
<p>Thanks for the comment. To be honest I didn&#8217;t think I would update this blog often enough that anyone would want to subscribe to an RSS feed, but if you&#8217;d like I can probably set that up?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: stejkenzie		</title>
		<link>/my-first-pentest-on-a-friends-network/#comment-154</link>

		<dc:creator><![CDATA[stejkenzie]]></dc:creator>
		<pubDate>Mon, 13 May 2013 13:32:44 +0000</pubDate>
		<guid isPermaLink="false">/?p=227#comment-154</guid>

					<description><![CDATA[I didn&#039;t believe those skills from hackthissite/nebula could be of any use, but you proved me wrong! Nice job man, I love this article. Just one consideration for you: how about creating RSS feed for your website? :)]]></description>
			<content:encoded><![CDATA[<p>I didn&#8217;t believe those skills from hackthissite/nebula could be of any use, but you proved me wrong! Nice job man, I love this article. Just one consideration for you: how about creating RSS feed for your website? 🙂</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
