Ian De Villiers

Wikto 2 Bugfix

A seasonal Wikto version was released on the 22nd (Version 2.0.2911-20215) which has an issue with the web spider funtionality. HTTPS requests are being made in plain text, and this obviously means that attempts to spider such sites will not work. A bug fix for this is available from www.sensepost.com Thanks to Mark Murdock for the heads up.

Wikto Updates

A new version of Wikto is also available, which provides a more reliable web spider and also includes some minor bugfixes. More details regarding Wikto are available at http://www.sensepost.com/research/wikto

Suru Version 2.0

We are pleased to announce the release of Suru version 2.0, our MITM proxy. Suru has now been rewritten to work with the .Net 2 runtime environment and includes all the features of the original 1.x stream, as well as numbers of enhancements and upgrades. Features which have been added since the last 1.1 stable release include the following: Upstream proxy support Response timing for timing-based attacks Highlighting of search terms in the request editor and the browser Neater and sortable request and fuzz list boxes Request interception There is currently a known bug when using Suru 2.0 with Mac OS/X and Parallels, but we hope to have the issue ironed out as soon as possible and will release a fix for this in the very near future.

FaceBook

’twas only a matter of time before various FaceBook developers started cashing in on the amount of personal info they can collect… http://www.theregister.co.uk/2007/09/12/facebook_compare_people/ This was something Marco and I chatted about a few weeks ago – not from the “financial gain” perspective, but rather from the large amounts of data one would be able to collect from Facebook by playing with the FaceBook API. Unfortunately, there has been no time for fun and games yet…