<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Strategic Cyber LLC</title>
	<atom:link href="http://blog.strategiccyber.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.strategiccyber.com</link>
	<description>A blog about Armitage, Cobalt Strike, and Red Teaming</description>
	<lastBuildDate>Mon, 22 Apr 2013 13:42:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on PSA: A Safety Lesson about Team Servers by rsmudge</title>
		<link>http://blog.strategiccyber.com/2013/04/21/psa-a-safety-lesson-about-team-servers/#comment-986</link>
		<dc:creator><![CDATA[rsmudge]]></dc:creator>
		<pubDate>Mon, 22 Apr 2013 13:42:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=2035#comment-986</guid>
		<description><![CDATA[This blog post was written because it was a funny side effect and I really wanted to show a different side of the exercise red team. I strongly disagree with your statement about safety features in the Metasploit Framework. It&#039;s like asking for a child safety lock on a tank.

We do not need a forgiving way to destroy systems. We only destroy systems in an exercise environment. We destroy them because it is funny. We do not want you to recover them.

Penetration testers do not destroy systems during their engagements.

I appreciate your speculation about all of the things that could go wrong, but I really feel it&#039;s misplaced. Please, take this blog post for what it was meant to be &quot;haha, the (National CCDC) red team got a taste of their own medicine&quot;.]]></description>
		<content:encoded><![CDATA[<p>This blog post was written because it was a funny side effect and I really wanted to show a different side of the exercise red team. I strongly disagree with your statement about safety features in the Metasploit Framework. It&#8217;s like asking for a child safety lock on a tank.</p>
<p>We do not need a forgiving way to destroy systems. We only destroy systems in an exercise environment. We destroy them because it is funny. We do not want you to recover them.</p>
<p>Penetration testers do not destroy systems during their engagements.</p>
<p>I appreciate your speculation about all of the things that could go wrong, but I really feel it&#8217;s misplaced. Please, take this blog post for what it was meant to be &#8220;haha, the (National CCDC) red team got a taste of their own medicine&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on PSA: A Safety Lesson about Team Servers by sapling</title>
		<link>http://blog.strategiccyber.com/2013/04/21/psa-a-safety-lesson-about-team-servers/#comment-985</link>
		<dc:creator><![CDATA[sapling]]></dc:creator>
		<pubDate>Mon, 22 Apr 2013 12:51:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=2035#comment-985</guid>
		<description><![CDATA[Glad to hear you didn&#039;t have anything major destroyed and yet I have to say perhaps its time for metasploit to institute some additional protection measures. I mean what if you were at a client site mounted a remote file system of theres after hacking in and then that command was issued. Well I bet your never working for that company again. 
Regardless tell the team members next time the faster way and more forgiving way is to use fdisk. That way if he realizes his mistake before he runs a reboot the system isn&#039;t completely screwed. And if i am not mistaken because its just the partition table it should still be recoverable with a boot disk allowing you to recover the system.]]></description>
		<content:encoded><![CDATA[<p>Glad to hear you didn&#8217;t have anything major destroyed and yet I have to say perhaps its time for metasploit to institute some additional protection measures. I mean what if you were at a client site mounted a remote file system of theres after hacking in and then that command was issued. Well I bet your never working for that company again.<br />
Regardless tell the team members next time the faster way and more forgiving way is to use fdisk. That way if he realizes his mistake before he runs a reboot the system isn&#8217;t completely screwed. And if i am not mistaken because its just the partition table it should still be recoverable with a boot disk allowing you to recover the system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Metasploit 4.6 &#8211; Now with less Open Source GUI by Simon Earl</title>
		<link>http://blog.strategiccyber.com/2013/04/11/metasploit-4-6-now-with-less-open-source-gui/#comment-962</link>
		<dc:creator><![CDATA[Simon Earl]]></dc:creator>
		<pubDate>Mon, 15 Apr 2013 18:50:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1953#comment-962</guid>
		<description><![CDATA[When are you going to let the UK people have a play with Cobalt Strike ?]]></description>
		<content:encoded><![CDATA[<p>When are you going to let the UK people have a play with Cobalt Strike ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Missing in Action: Armitage on Kali Linux by rsmudge</title>
		<link>http://blog.strategiccyber.com/2013/03/13/missing-in-action-armitage-on-kali-linux/#comment-951</link>
		<dc:creator><![CDATA[rsmudge]]></dc:creator>
		<pubDate>Sat, 13 Apr 2013 03:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1741#comment-951</guid>
		<description><![CDATA[service metasploit start is necessary once and only once. It also starts the commercial stuff that Armitage doesn&#039;t use. You&#039;re just wasting memory and CPU letting it run. Armitage is capable of starting msfrpcd, to its specifications, for you. I really recommend letting it do so.]]></description>
		<content:encoded><![CDATA[<p>service metasploit start is necessary once and only once. It also starts the commercial stuff that Armitage doesn&#8217;t use. You&#8217;re just wasting memory and CPU letting it run. Armitage is capable of starting msfrpcd, to its specifications, for you. I really recommend letting it do so.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Missing in Action: Armitage on Kali Linux by Tralala</title>
		<link>http://blog.strategiccyber.com/2013/03/13/missing-in-action-armitage-on-kali-linux/#comment-950</link>
		<dc:creator><![CDATA[Tralala]]></dc:creator>
		<pubDate>Sat, 13 Apr 2013 02:54:15 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1741#comment-950</guid>
		<description><![CDATA[It not work for me

But what i did go for /etc/rc.local
and add 
service postgresql start &amp;&amp; service metasploit start
and all start work for me.]]></description>
		<content:encoded><![CDATA[<p>It not work for me</p>
<p>But what i did go for /etc/rc.local<br />
and add<br />
service postgresql start &amp;&amp; service metasploit start<br />
and all start work for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Metasploit 4.6 &#8211; Now with less Open Source GUI by rsmudge</title>
		<link>http://blog.strategiccyber.com/2013/04/11/metasploit-4-6-now-with-less-open-source-gui/#comment-943</link>
		<dc:creator><![CDATA[rsmudge]]></dc:creator>
		<pubDate>Fri, 12 Apr 2013 03:14:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1953#comment-943</guid>
		<description><![CDATA[I wouldn&#039;t say these events are related. Kali is a new distro and the team there has been extremely responsive to requests to add tools that users suggest.]]></description>
		<content:encoded><![CDATA[<p>I wouldn&#8217;t say these events are related. Kali is a new distro and the team there has been extremely responsive to requests to add tools that users suggest.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Metasploit 4.6 &#8211; Now with less Open Source GUI by Mike Landeck</title>
		<link>http://blog.strategiccyber.com/2013/04/11/metasploit-4-6-now-with-less-open-source-gui/#comment-942</link>
		<dc:creator><![CDATA[Mike Landeck]]></dc:creator>
		<pubDate>Fri, 12 Apr 2013 03:06:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1953#comment-942</guid>
		<description><![CDATA[Interesting trend in front end GUI&#039;s being dropped. Besides armitage and msfgui being dropped from metasploit  I noticed that gerix, the GUI for the aircrack-ng suite is not included in the default kali distro.

Keep up the good work and great attitude.]]></description>
		<content:encoded><![CDATA[<p>Interesting trend in front end GUI&#8217;s being dropped. Besides armitage and msfgui being dropped from metasploit  I noticed that gerix, the GUI for the aircrack-ng suite is not included in the default kali distro.</p>
<p>Keep up the good work and great attitude.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Metasploit 4.6 &#8211; Now with less Open Source GUI by Todd Gustafson</title>
		<link>http://blog.strategiccyber.com/2013/04/11/metasploit-4-6-now-with-less-open-source-gui/#comment-939</link>
		<dc:creator><![CDATA[Todd Gustafson]]></dc:creator>
		<pubDate>Thu, 11 Apr 2013 22:23:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1953#comment-939</guid>
		<description><![CDATA[Thank you Mudge. Love your stuff

- T]]></description>
		<content:encoded><![CDATA[<p>Thank you Mudge. Love your stuff</p>
<p>- T</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Missing in Action: Armitage on Kali Linux by Zach</title>
		<link>http://blog.strategiccyber.com/2013/03/13/missing-in-action-armitage-on-kali-linux/#comment-915</link>
		<dc:creator><![CDATA[Zach]]></dc:creator>
		<pubDate>Fri, 05 Apr 2013 20:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1741#comment-915</guid>
		<description><![CDATA[Sorry I didn&#039;t check back from my post a few weeks ago.  I had all sorts of problems when initially downloading the iso of Kali.  After fixing small problem one after another I finally just gave up and downloaded the VM image and everything started working no problem.  

Thanks for the help]]></description>
		<content:encoded><![CDATA[<p>Sorry I didn&#8217;t check back from my post a few weeks ago.  I had all sorts of problems when initially downloading the iso of Kali.  After fixing small problem one after another I finally just gave up and downloaded the VM image and everything started working no problem.  </p>
<p>Thanks for the help</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pivoting through SSH by Darren Martyn</title>
		<link>http://blog.strategiccyber.com/2013/03/28/pivoting-through-ssh/#comment-900</link>
		<dc:creator><![CDATA[Darren Martyn]]></dc:creator>
		<pubDate>Mon, 01 Apr 2013 16:27:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.strategiccyber.com/?p=1756#comment-900</guid>
		<description><![CDATA[Is there any chance of support for forwarding a local port (the listener) through a pivot host like so?
ssh -R 0.0.0.0:4444:0.0.0.0:4444 root@pivot -p 22

And then setting the payload to connect back to port 4444 on pivot after forwarding localport 4444 to 4444 on pivot? I have tried this in the past with no luck so far, think it would be an interesting feature for getting around egress filtering after compromising a host on the &quot;edge&quot; of a network, for example, a router or firewall appliance.]]></description>
		<content:encoded><![CDATA[<p>Is there any chance of support for forwarding a local port (the listener) through a pivot host like so?<br />
ssh -R 0.0.0.0:4444:0.0.0.0:4444 root@pivot -p 22</p>
<p>And then setting the payload to connect back to port 4444 on pivot after forwarding localport 4444 to 4444 on pivot? I have tried this in the past with no luck so far, think it would be an interesting feature for getting around egress filtering after compromising a host on the &#8220;edge&#8221; of a network, for example, a router or firewall appliance.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
