<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="2.0">
  <channel>
    <title>Dionach Information Security Blog</title>
    <link>http://www.dionach.com/blog/</link>
    <description>Dionach is an information security consultancy specialising in penetration testing and security auditing. ISO 27001 certified and PCI ASV. This is Dionach's blog on information security, penetration testing and auditing.</description>
    <language>en-gb</language>
    <lastBuildDate>18 May 12 00:00:00 GMT</lastBuildDate>
    <ttl>60</ttl>

        <item>
          <title>Gambling Commission ISO 27001 Security Requirements and Penetration Testing</title>
          <link>http://www.dionach.com/blog/Gambling-Commission-ISO-27001-Security-Requirements-and-Penetration-Testing.asp</link>
          <description>&lt;b&gt;Blog by Bil on 30 January&lt;/b&gt;&lt;br /&gt;The Gambling Commission requires that remote gambling licence holders get annual ISO 27001 security audits done. This needs to cover a specific subset of ISO 27001 controls ...</description>
          <datePosted>30 Jan 12 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Configuring Metasploit for Client Side Attacks</title>
          <link>http://www.dionach.com/blog/Configuring-Metasploit-for-Client-Side-Attacks.asp</link>
          <description>&lt;b&gt;Blog by Michele on 22 November&lt;/b&gt;&lt;br /&gt;During a client side test, several areas need to be setup for a successful attack. In this short article I will describe how to configure Metasploit by making use of the features in the latest release ...</description>
          <datePosted>22 Nov 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Virtual Security Management</title>
          <link>http://www.dionach.com/blog/Virtual-Security-Management.asp</link>
          <description>&lt;b&gt;Blog by Dave on 18 October&lt;/b&gt;&lt;br /&gt;First of all, in the interests of fairness, I should point out that I think virtualisation is amazing. I love the idea that my laptop can run several different, largely independent operating systems ...</description>
          <datePosted>18 Oct 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>An Effective Internal Penetration Test</title>
          <link>http://www.dionach.com/blog/An-Effective-Internal-Penetration-Test.asp</link>
          <description>&lt;b&gt;Blog by Dave on 19 September&lt;/b&gt;&lt;br /&gt;&quot;My servers are all fully patched, and we've fixed the weak administrator password that the last guys found. So I don't really expect you to find anything!&quot;
The previous statement, paraphrased slightly ...</description>
          <datePosted>19 Sep 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Security is a Process, not a Product</title>
          <link>http://www.dionach.com/blog/Security-is-a-Process-not-a-Product.asp</link>
          <description>&lt;b&gt;Blog by Michele on 5 September&lt;/b&gt;&lt;br /&gt;It’s not a novelty to say that the market is often regulated by the strong business brand and it is no exception for IT security. Companies will often use a single commercial product to try to achieve ...</description>
          <datePosted>5 Sep 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Custom Access Control</title>
          <link>http://www.dionach.com/blog/Custom-Access-Control.asp</link>
          <description>&lt;b&gt;Blog by Dave on 6 July&lt;/b&gt;&lt;br /&gt;As penetration testers we have a tendency to get caught up in the latest exploit, or the most intricate piece of SQL injection or cross-site scripting ...</description>
          <datePosted>6 Jul 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Reviewing Your Security After Sony, RSA and IMF Breaches</title>
          <link>http://www.dionach.com/blog/Reviewing-Your-Security-After-Sony-RSA-and-IMF-Breaches.asp</link>
          <description>&lt;b&gt;Blog by Bil on 13 June&lt;/b&gt;&lt;br /&gt;The various publicised data and network breaches (or &quot;hacks&quot;) this year seem to fall into two camps...</description>
          <datePosted>13 Jun 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Vulnerability: Grapecity DataDynamics Report Library Cross-Site Scripting</title>
          <link>http://www.dionach.com/blog/Vulnerability-Grapecity-DataDynamics-Report-Library-Cross-Site-Scripting.asp</link>
          <description>&lt;b&gt;Blog by Dave on 13 May&lt;/b&gt;&lt;br /&gt;Grapecity's DataDynamics Report Library is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data ...</description>
          <datePosted>13 May 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Vulnerability: Kodak InSite Troubleshooting Cross-Site Scripting</title>
          <link>http://www.dionach.com/blog/Vulnerability-Kodak-InSite-Troubleshooting-Cross-Site-Scripting.asp</link>
          <description>&lt;b&gt;Blog by Dave on 13 May&lt;/b&gt;&lt;br /&gt;Kodak InSite is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data ...</description>
          <datePosted>13 May 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Vulnerability: Domino Sametime Server 'stconf' Reflected Cross-Site Scripting</title>
          <link>http://www.dionach.com/blog/Vulnerability-Domino-Sametime-Server-stconf-Reflected-Cross-Site-Scripting.asp</link>
          <description>&lt;b&gt;Blog by Dave on 13 May&lt;/b&gt;&lt;br /&gt;Domino Sametime is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data ...</description>
          <datePosted>13 May 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Vulnerabilities in Web Content Management Systems</title>
          <link>http://www.dionach.com/blog/Vulnerabilities-in-Web-Content-Management-Systems.asp</link>
          <description>&lt;b&gt;Blog by Tassi on 21 February&lt;/b&gt;&lt;br /&gt;During my time as a penetration tester I have come across a series of Web Content Management Systems (WCMS) including both Free Open Source Software (FOSS) and Commercial Off The Shelf (COTS) software ...</description>
          <datePosted>21 Feb 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>The Security Value of the Robots.txt file</title>
          <link>http://www.dionach.com/blog/The-Security-Value-of-the-Robots.txt-file.asp</link>
          <description>&lt;b&gt;Blog by Mithun on 10 February&lt;/b&gt;&lt;br /&gt;This is my view on the use of robots.txt as a security control and the problems of not having one. From my penetration testing experience ...</description>
          <datePosted>10 Feb 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Penetration Testing Is Not Vulnerability Scanning</title>
          <link>http://www.dionach.com/blog/Penetration-Testing-Is-Not-Vulnerability-Scanning.asp</link>
          <description>&lt;b&gt;Blog by Dave on 3 February&lt;/b&gt;&lt;br /&gt;I recently received the go-ahead for an external penetration test which referred to the test as &quot;a scan&quot;. This is not the first time I have seen penetration testing and vulnerability scanning confused ...</description>
          <datePosted>3 Feb 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Update to ISO 27001 Planned for 2013</title>
          <link>http://www.dionach.com/blog/Update-to-ISO-27001-Planned-for-2013.asp</link>
          <description>&lt;b&gt;Blog by Bil on 25 January&lt;/b&gt;&lt;br /&gt;I went to the UK User Group Consultation at BSI on 25th January. This provided the attendees to get an overview of the changes and comment on them. The update for ISO 27001 is currently on the 4th working draft ...</description>
          <datePosted>25 Jan 11 00:00:00 GMT</datePosted>
        </item>
        
        <item>
          <title>Web Services Blind SQL Injection</title>
          <link>http://www.dionach.com/blog/Web-Services-Blind-SQL-Injection.asp</link>
          <description>&lt;b&gt;Blog by Bil on 18 January&lt;/b&gt;&lt;br /&gt;There is plenty of documentation for using blind SQL injection in penetration tests. This code demonstrates exploiting blind SQL injection in a web service using Python...</description>
          <datePosted>18 Jan 11 00:00:00 GMT</datePosted>
        </item>
        
  </channel>
</rss>
