<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Introducing Jikto</title>
	<link>http://www.metafilter.com/59820/Introducing-Jikto/</link>
	<description>Comments on MetaFilter post Introducing Jikto</description>
	<pubDate>Wed, 28 Mar 2007 13:54:34 -0800</pubDate>
	<lastBuildDate>Wed, 28 Mar 2007 13:54:34 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Introducing Jikto</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto</link>	
		<description>&lt;a href="http://news.com.com/Tool+turns+unsuspecting+surfers+into+hacking+help/2100-1002_3-6169034.html?tag=nefd.lede"&gt;Klaatu barada...Jikto?&lt;/a&gt; First there was &lt;a href=&quot;http://www.cirt.net/code/nikto.shtml&quot;&gt;Nikto&lt;/a&gt;.  Then along came &lt;a href=&quot;http://www.sensepost.com/research/wikto/&quot;&gt;Wikto&lt;/a&gt;. Last Saturday at &lt;a href=&quot;http://www.shmoocon.org/&quot;&gt;Shmoocon&lt;/a&gt; &lt;a href=&quot;http://portal.spidynamics.com/blogs/spilabs/archive/2007/03/22/Speaking-at-Shmoo.aspx&quot;&gt;Billy Hoffman&lt;/a&gt; &lt;a href=&quot;http://www.nytimes.com/cnet/CNET_2100-1002_3-6170223.html?_r=1&amp;oref=slogin&quot;&gt;introduced&lt;/a&gt; the world to &lt;a href=&quot;http://news.com.com/Tool+turns+unsuspecting+surfers+into+hacking+help/2100-1002_3-6169034.html?tag=nefd.lede&quot;&gt;Jitko&lt;/a&gt;, a client-side vulnerability scanner that exploits your browser &amp;amp; turns your PC into a platform for finding holes in computers across the Internet (or behind your firewall).  &lt;a href=&quot;http://www.memestreams.net/thread/bid29678/&quot;&gt;Reactions were mixed&lt;/a&gt;.  &lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2007/03/jikto-crossing-line.html&quot;&gt;Does Jikto go too far?&lt;/a&gt;</description>
		<guid isPermaLink="false">post:www.metafilter.com,2007:site.59820</guid>
		<pubDate>Wed, 28 Mar 2007 13:40:05 -0800</pubDate>
		<dc:creator>scalefree</dc:creator>		<category>computer</category>		<category>security</category>		<category>pentest</category>		<category>hacking</category>		<category>javascript</category>		<category>client-side</category>		<category>application</category>		<category>vulnerability</category>		<category>ajax</category>		<category>xss</category>		<category>scanner</category>
	</item>	<item>
		<title>By: chrominance</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635716</link>	
		<description>The last link argues that Hoffman would have gone too far had he actually released the code for Nikto, as the author originally believed. But Hoffman does not intend to release Nikto into the wild, thus there&apos;s no real danger beyond showing people a potential vector for exploitation (but not exactly how to do it). In other words, we&apos;re back to the basic issue of publishing security vulnerabilities publicly versus privately.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635716</guid>
		<pubDate>Wed, 28 Mar 2007 13:54:34 -0800</pubDate>
		<dc:creator>chrominance</dc:creator>
	</item>	<item>
		<title>By: scalefree</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635718</link>	
		<description>Yeah I meant to mention that he didn&apos;t actually release the code, just demoed it.  But still, it&apos;ll be interesting to see how long it takes for either the program itself to find its way into the wild or for someone to write an equivalent tool &amp;amp; release it now that the idea has been planted in people&apos;s heads.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635718</guid>
		<pubDate>Wed, 28 Mar 2007 14:05:55 -0800</pubDate>
		<dc:creator>scalefree</dc:creator>
	</item>	<item>
		<title>By: peewinkle</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635741</link>	
		<description>YIKES!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635741</guid>
		<pubDate>Wed, 28 Mar 2007 14:46:20 -0800</pubDate>
		<dc:creator>peewinkle</dc:creator>
	</item>	<item>
		<title>By: Jairus</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635756</link>	
		<description>aaaahahahaaahahaa</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635756</guid>
		<pubDate>Wed, 28 Mar 2007 15:16:37 -0800</pubDate>
		<dc:creator>Jairus</dc:creator>
	</item>	<item>
		<title>By: amberglow</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635774</link>	
		<description>This actually is good, if it forces businesses and other site owners to actually get serious about security. 

I&apos;m all for it--almost all fixes and patches and security problems are exposed by people like the ones behind this stuff. It&apos;s astonishing how unsecure so many sites and servers and machines are.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635774</guid>
		<pubDate>Wed, 28 Mar 2007 15:46:16 -0800</pubDate>
		<dc:creator>amberglow</dc:creator>
	</item>	<item>
		<title>By: amberglow</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635775</link>	
		<description>(and all our personal computers too)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635775</guid>
		<pubDate>Wed, 28 Mar 2007 15:47:20 -0800</pubDate>
		<dc:creator>amberglow</dc:creator>
	</item>	<item>
		<title>By: phaedon</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635776</link>	
		<description>I&apos;ll wait for the movie to come out.  In the meantime:

&lt;i&gt;Gimme some sugar, baby.&lt;/i&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635776</guid>
		<pubDate>Wed, 28 Mar 2007 15:48:57 -0800</pubDate>
		<dc:creator>phaedon</dc:creator>
	</item>	<item>
		<title>By: inflatablekiwi</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635861</link>	
		<description>Although the code for this tool has not been released, there are plenty of code snippets out there for doing similar things (Javascript browser &lt;a href=&quot;http://events.ccc.de/congress/2006/Fahrplan/events/1602.en.html&quot;&gt;keystroke loggers&lt;/a&gt;, &lt;a href=&quot;http://www.gnucitizen.org/projects/javascript-port-scanner/&quot;&gt;port&lt;/a&gt; &lt;a href=&quot;http://www.securityfocus.com/bid/23082/exploit&quot;&gt;scanners &lt;/a&gt;etc).  It was only a matter of time until these individual tools and techniques were refined and made into a general purpose assessment tool like Jikto.  

Jeremiah Grossman (see the last link in scalefree&apos;s post) gave a good presentation on using browser code to hack internal networks using similar techniques (&lt;a href=&quot;http://jeremiahgrossman.blogspot.com/2006/09/video-hacking-intranet-websites-from.html&quot;&gt;video/slides and proof of concept code&lt;/a&gt;) at &lt;a href=&quot;http://www.blackhat.com&quot;&gt;BlackHat&lt;/a&gt; 2006.

If nothing else, another good example to show people how cross site scripting/inadequate data validation can come back to haunt you in weird and wonderful ways.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635861</guid>
		<pubDate>Wed, 28 Mar 2007 17:32:44 -0800</pubDate>
		<dc:creator>inflatablekiwi</dc:creator>
	</item>	<item>
		<title>By: b1tr0t</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1635899</link>	
		<description>port scanning by img url (first port scanner link) is simultaneously amusing and scary.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1635899</guid>
		<pubDate>Wed, 28 Mar 2007 18:42:19 -0800</pubDate>
		<dc:creator>b1tr0t</dc:creator>
	</item>	<item>
		<title>By: Twang</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1636790</link>	
		<description>Security ... it&apos;s such a &lt;a href=http://home.nycap.rr.com/cyclone/disney/sots/tarbaby.htm&quot; &quot;&gt;tarbaby&lt;/a&gt;.

Why doesn&apos;t someone think of a way to divide a computer into two parts: stuff that&apos;s visible/accessible/modifiable online, and stuff that&apos;s not, PERIOD. Can it *really* be so hard?

You can&apos;t &apos;net into a computer that&apos;s not connected to the net. SO ... you make part of the computer that way. The net part, and the non-net part.

Maybe that&apos;s a use for the new 8-core chips ... let them figure out how to pull it off. One chip is the COP.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1636790</guid>
		<pubDate>Fri, 30 Mar 2007 02:28:45 -0800</pubDate>
		<dc:creator>Twang</dc:creator>
	</item>	<item>
		<title>By: b1tr0t</title>
		<link>http://www.metafilter.com/59820/Introducing-Jikto#1636914</link>	
		<description>In theory, that is how most modern systems are designed. In practices, it is easier to bribe the cop on some systems than others.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2007:site.59820-1636914</guid>
		<pubDate>Fri, 30 Mar 2007 06:09:03 -0800</pubDate>
		<dc:creator>b1tr0t</dc:creator>
	</item>
	</channel>
</rss>
