Home Projects Pictures Books About PGP Key

Finding PANs with Open Source Tools

February 27th, 2008 Anthony Towry

Recently the idea hit me to look into what it would take to locate personal account numbers (PAN)s that had been unknowingly filed away by applications or server logs.  I quickly found three open source tools to enlist.

Listen to find out which one I liked and which ones are fit for /dev/null.  Enjoy the show!

  • Cornell Spider (windows version)
  • Cornell Spider 4.0 (Perl) this wasn't tested, but apparently doesn't suck. 
  • Find_ssn, credit cards actually expire before this is finished scanning
  • Senf from the University of Texas is awesome!
 
icon for podpress  Finding PANs With Open Source Tools [24:58m]: Play Now | Play in Popup | Download (59)

Posted in Podcast | No Comments »

PCI DSS

November 11th, 2007 Anthony Towry

Lately I've been looking a little further into the Payment Card Industry's Data Security Standard. Unfortunately, you could look for weeks and still find out new "fun facts". So as usual, I've put together a crash course on what I know about the PCI DSS and a little bit about what it might mean to the average credit card accepting merchant.

Show notes:

  • Here you can find the DSS, FAQs and the Self Assessment Questionnaire https://www.pcisecuritystandards.org
  • Some information on what an acquiring bank does.
  • Criticism of PCI at DarkReading.com and some interesting points by Martin McKeay
  • Interview with Robert Preatoni regarding his BlueHat talk.
  • The WabiSabiLabi marketplace , just in case you want to give someone an 0-day for Christmas this year. Santa still hasn't brought me one.

As always, if I've left something out, or you've got something good to add, let me know.

 
icon for podpress  The PCI DSS Episode [46:15m]: Play Now | Play in Popup | Download (71)

Posted in Podcast | No Comments »

  • Recent Posts

    • New ProCheckUp ValidateRequest Bypass
    • Samurai Web Test Framework 0.1
    • Altering the Mac OS X Login Access Window Text
    • Summary on the State of Nmap
    • Android Security Team Says Hi
  • Archives

    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
    • July 2007
  • Categories

    • Art
    • Books
    • Community
    • conferences
    • Hardware
    • Management
    • Operating Systems
    • Podcast
    • Programming
    • Projects
    • Security
    • Site News
    • Software
    • Testing
    • Uncategorized
    • Web development
  • Blogroll

    • Defcon 405
    • ha.ckers.org
    • Halvar Flake
    • OSVDB Blog
    • phed.org
    • Scott Berkun’s Blog
  • Tags

    .Net ASP.NET Beta Books browser buffer overflow C Community Compliance Concept conferences Credit Cards dc405 defcon Development exploit Future fuzzing hacking Linux malware Management Metasploit Microsoft oklahoma Open Source osvdb OS X Patterns PCI Perl Podcast Programming protocols Ruby secure coding Security Silverlight SQL Server Testing tools vulnerabilities vulnerability WordPress xss

Calculated Decision has Joomla! under the hood!

Podcast Powered by podPress (v8.8)