<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Seven Sisters on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/seven-sisters/</link>
    <description>Recent content in Seven Sisters on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 03 Mar 2012 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/seven-sisters/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Applying the ERNW Seven Sisters Approach to VoIP Networks</title>
      <link>https://insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks/</link>
      <pubDate>Sat, 03 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;if you’re following this blog regularly or if you’ve ever attended an &lt;a href=&#34;http://www.hmtrainingsolutions.com/&#34;&gt;ERNW-led workshop&lt;/a&gt; which included an “architecture section” you will certainly remember the “Seven Sisters of Infrastructure Security” stuff (used for example in &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;this post&lt;/a&gt;). These are a number of (well, more precisely, it’s seven ;-)) fundamental security principles which can be applied to any complex infrastructure, be that a network, a building, an airport or the like.&lt;/p&gt;&#xA;&lt;p&gt;As part of our upcoming &lt;a href=&#34;https://www.blackhat.com/html/bh-eu-12/bh-eu-12-briefings.html#rey&#34;&gt;Black Hat&lt;/a&gt; and &lt;a href=&#34;http://www.troopers.de/troopers12/agenda/protecting-voice-over-ip-in-2012/&#34;&gt;Troopers&lt;/a&gt; talks we will apply those principles to some VoIP networks we (security-) assessed and, given we won’t cover them in detail there, it might be helpful to perform a quick refresher of them, together with an initial application to VoIP deployments. Here we go; these are the “Seven Sisters of Infrastructure Security”:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sisters’ Act of MFD Security</title>
      <link>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</link>
      <pubDate>Thu, 07 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</guid>
      <description>&lt;p&gt;Recently Micele and I were researching for our talk about the current state of security of Multifunction Devices (MFDs). Since we’re both seasoned pentesters who are quite familar with MFDs, we were really surprised that very little new research is going on on the topic of MFD security. While diving deeper into the topic, we found a very simple explanation for this: As in 2002, it is still possible to download print or scan jobs using &lt;a href=&#34;http://h20000.www2.hp.com/bc/docs/support/SupportManual/bpl13208/bpl13208.pdf&#34;&gt;PJL&lt;/a&gt;, many devices still offer default FTP or Telnet access, and, of course, stored files can be recovered from MFD hard drives — on an enterprise wide scale. To even strengthen our impression of the current state of MFD security, most devices crashed or did go wild while performing some scans — and we do not talk about fuzzing here.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
