<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6027147</id><updated>2011-08-03T09:21:05.604-07:00</updated><title type='text'>Security musings (reflectorium)</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default?start-index=101&amp;max-results=100'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>288</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6027147.post-2691452142121842076</id><published>2010-06-02T00:35:00.000-07:00</published><updated>2010-06-02T00:36:09.343-07:00</updated><title type='text'>Malware analysis</title><content type='html'>Very nice article&lt;br /&gt;links to&lt;br /&gt;wepawet&lt;br /&gt;malzilla&lt;br /&gt;jsunpack&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-2691452142121842076?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.heise.de/security/artikel/Java-Decompiler-940637.html' title='Malware analysis'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2691452142121842076'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2691452142121842076'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2010/06/malware-analysis.html' title='Malware analysis'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-6317488293615827312</id><published>2010-02-26T05:40:00.000-08:00</published><updated>2010-02-26T05:41:35.616-08:00</updated><title type='text'>Overcoming problems in BT4 with apt-get install scapy2</title><content type='html'>#cd /var/cache/apt/archives/&lt;br /&gt;#dpkg --force-all -i libssh2_1.2.2-bt0_all.deb&lt;br /&gt;#dpkg --force-all -i scapy2_2.1-bt1_all.deb&lt;br /&gt;(as root)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-6317488293615827312?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/6317488293615827312/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=6317488293615827312' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/6317488293615827312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/6317488293615827312'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2010/02/overcoming-problems-in-bt4-with-apt-get.html' title='Overcoming problems in BT4 with apt-get install scapy2'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-4396323365794325544</id><published>2010-02-25T23:13:00.000-08:00</published><updated>2010-02-25T23:14:01.437-08:00</updated><title type='text'>Web Security Dojo v1.0 release</title><content type='html'>http://www.webappsec.org/lists/websecurity/archive/2010-02/msg00069.html&lt;br /&gt;&lt;br /&gt;"For a quick start grab the VM from http://dojo.mavensecurity.com and&lt;br /&gt;read the included Readme file and/or watch the intro video at&lt;br /&gt;http://www.youtube.com/watch?v=lum6bSsyJ38."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-4396323365794325544?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/4396323365794325544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=4396323365794325544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4396323365794325544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4396323365794325544'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2010/02/web-security-dojo-v10-release.html' title='Web Security Dojo v1.0 release'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-3518208811023786714</id><published>2010-02-24T23:55:00.000-08:00</published><updated>2010-02-25T23:13:07.218-08:00</updated><title type='text'>tweets du jour</title><content type='html'>dragosr  &lt;br /&gt;Hak5 has DHCP exhaustion and DNS MITM via metasploit module vid http://bit.ly/dpRr9b (&gt;HDMoore)&lt;br /&gt;&lt;br /&gt;TEDchris&lt;br /&gt;Here's what Sergey Brin told me at #TED about Google's cyber-attack in China and "Don't Be Evil" http://on.ted.com/8A6D&lt;br /&gt;&lt;br /&gt;dragosr&lt;br /&gt;good sans passthehash toolkit comparison paper http://bit.ly/cAlhmq&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-3518208811023786714?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/3518208811023786714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=3518208811023786714' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3518208811023786714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3518208811023786714'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2010/02/tweets-du-jour.html' title='tweets du jour'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-4599686560418336022</id><published>2010-01-07T12:55:00.001-08:00</published><updated>2010-01-07T12:55:44.963-08:00</updated><title type='text'>SED one liners</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-4599686560418336022?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://sed.sourceforge.net/sed1line.txt' title='SED one liners'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/4599686560418336022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=4599686560418336022' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4599686560418336022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4599686560418336022'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2010/01/sed-one-liners.html' title='SED one liners'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-5598390194691070179</id><published>2010-01-06T01:28:00.000-08:00</published><updated>2010-01-06T01:29:21.807-08:00</updated><title type='text'>Analysis of Java Exploit kit</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-5598390194691070179?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.inreverse.net/?p=804' title='Analysis of Java Exploit kit'/><link rel='enclosure' type='' href='http://www.inreverse.net/?p=804' length='0'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/5598390194691070179/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=5598390194691070179' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5598390194691070179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5598390194691070179'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2010/01/analysis-of-java-exploit-kit.html' title='Analysis of Java Exploit kit'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-7125565117138945765</id><published>2009-11-24T08:18:00.000-08:00</published><updated>2009-11-24T08:19:03.290-08:00</updated><title type='text'>Yersinia overview</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-7125565117138945765?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.networkworld.com/community/node/42439' title='Yersinia overview'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/7125565117138945765/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=7125565117138945765' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/7125565117138945765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/7125565117138945765'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/11/yersinia-overview.html' title='Yersinia overview'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-5845228171290950510</id><published>2009-11-24T08:13:00.001-08:00</published><updated>2009-11-24T08:13:51.607-08:00</updated><title type='text'>Monitor sidewiki entries on whole domains</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-5845228171290950510?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://auroracommsblog.com/monitor-sidewikis-on-your-whole-domain-phew/' title='Monitor sidewiki entries on whole domains'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/5845228171290950510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=5845228171290950510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5845228171290950510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5845228171290950510'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/11/monitor-sidewiki-entries-on-whole.html' title='Monitor sidewiki entries on whole domains'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-6593612379539983857</id><published>2009-09-11T04:12:00.001-07:00</published><updated>2009-09-11T04:12:42.706-07:00</updated><title type='text'>Google Chart API</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-6593612379539983857?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://code.google.com/intl/de-DE/apis/chart/types.html#maps' title='Google Chart API'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/6593612379539983857/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=6593612379539983857' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/6593612379539983857'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/6593612379539983857'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/09/google-chart-api.html' title='Google Chart API'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-5924001680382994156</id><published>2009-09-11T02:41:00.001-07:00</published><updated>2009-09-11T02:41:45.954-07:00</updated><title type='text'>Modern approaches to data viz</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-5924001680382994156?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.smashingmagazine.com/2007/08/02/data-visualization-modern-approaches/' title='Modern approaches to data viz'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5924001680382994156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5924001680382994156'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/09/modern-approaches-to-data-viz.html' title='Modern approaches to data viz'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-7226738000710875111</id><published>2009-09-09T23:51:00.001-07:00</published><updated>2009-09-09T23:52:21.648-07:00</updated><title type='text'>Visualising IP Geolocation in HILBERT space</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-7226738000710875111?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.hatfulofhollow.com/posts/code/hilbert/explorer/index.html' title='Visualising IP Geolocation in HILBERT space'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/7226738000710875111/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=7226738000710875111' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/7226738000710875111'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/7226738000710875111'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/09/visualising-ip-geolocation-in-hilbert.html' title='Visualising IP Geolocation in HILBERT space'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-8830047485666258802</id><published>2009-09-09T23:50:00.001-07:00</published><updated>2009-09-09T23:50:47.942-07:00</updated><title type='text'>Free geo database of all IP addresses</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-8830047485666258802?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.wipmania.com/en/base/' title='Free geo database of all IP addresses'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/8830047485666258802/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=8830047485666258802' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/8830047485666258802'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/8830047485666258802'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/09/free-geo-database-of-all-ip-addresses.html' title='Free geo database of all IP addresses'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-739319804341508026</id><published>2009-03-09T07:27:00.000-07:00</published><updated>2009-03-09T07:28:00.300-07:00</updated><title type='text'>Building Security In Maturity Model</title><content type='html'>http://bsi-mm.com/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-739319804341508026?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://bsi-mm.com/' title='Building Security In Maturity Model'/><link rel='enclosure' type='' href='http://bsi-mm.com/' length='0'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/739319804341508026/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=739319804341508026' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/739319804341508026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/739319804341508026'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2009/03/building-security-in-maturity-model.html' title='Building Security In Maturity Model'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-3580294645941337780</id><published>2008-10-20T11:16:00.001-07:00</published><updated>2008-10-20T11:16:34.824-07:00</updated><title type='text'>http://dnsbl.abuse.ch/</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-3580294645941337780?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://dnsbl.abuse.ch/' title='http://dnsbl.abuse.ch/'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/3580294645941337780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=3580294645941337780' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3580294645941337780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3580294645941337780'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2008/10/httpdnsblabusech.html' title='http://dnsbl.abuse.ch/'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-5211170494562945099</id><published>2008-10-17T13:17:00.001-07:00</published><updated>2008-10-17T13:17:45.043-07:00</updated><title type='text'></title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-5211170494562945099?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.edge-security.com/proxystrike.php' title=''/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/5211170494562945099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=5211170494562945099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5211170494562945099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5211170494562945099'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2008/10/blog-post.html' title=''/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-3346060050985157274</id><published>2008-09-26T02:26:00.000-07:00</published><updated>2008-09-26T02:27:02.306-07:00</updated><title type='text'>Breakpoint Clickjacking Speculations</title><content type='html'>http://www.breakingpointsystems.com/community/blog/clickjacking&lt;br /&gt;&lt;br /&gt;and of course&lt;br /&gt;http://blogs.zdnet.com/security/?p=1973&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-3346060050985157274?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3346060050985157274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3346060050985157274'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2008/09/breakpoint-clickjacking-speculations.html' title='Breakpoint Clickjacking Speculations'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-2520033917798862955</id><published>2008-09-18T00:10:00.000-07:00</published><updated>2008-09-18T00:13:47.609-07:00</updated><title type='text'>Links of the day</title><content type='html'>http://www.sensepost.com/research/squeeza/&lt;br /&gt;http://www.sensepost.com/research/reDuh/&lt;br /&gt;http://carnal0wnage.blogspot.com/2008/09/passing-hash-with-gsecdump-and-msvctl.html&lt;br /&gt;http://carnal0wnage.blogspot.com/2008/08/owning-client-without-and-exploit.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-2520033917798862955?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/2520033917798862955/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=2520033917798862955' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2520033917798862955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2520033917798862955'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2008/09/links-of-day.html' title='Links of the day'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-3969282277603469914</id><published>2008-09-08T23:12:00.000-07:00</published><updated>2008-09-08T23:15:20.728-07:00</updated><title type='text'>WASS statistics</title><content type='html'>WASS Weba Application Security Statistics 2007 gives some really nice insights, e.g. % of type of vulnerabilty on average site *and* how likely they are detected by automated scans vs. penetration testing. Automated scans are good at finding low and medium ones. Penetration test are good at finding high findings.&lt;br /&gt;http://packetstormsecurity.org/papers/general/wasc_wass_2007.pdf&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-3969282277603469914?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='enclosure' type='' href='http://packetstormsecurity.org/papers/general/wasc_wass_2007.pdf' length='0'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/3969282277603469914/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=3969282277603469914' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3969282277603469914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3969282277603469914'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2008/09/wass-statistics.html' title='WASS statistics'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-356917285447349538</id><published>2008-02-26T05:07:00.000-08:00</published><updated>2008-02-26T05:08:59.240-08:00</updated><title type='text'>local links</title><content type='html'>&lt;a href="file://c:"&gt;file://c:&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-356917285447349538?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/356917285447349538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=356917285447349538' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/356917285447349538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/356917285447349538'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2008/02/local-links.html' title='local links'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-1992579846976939323</id><published>2007-12-18T23:09:00.000-08:00</published><updated>2007-12-18T23:10:06.890-08:00</updated><title type='text'>Wireless Auditing Live CD</title><content type='html'>Russix&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-1992579846976939323?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.russix.com/index.htm' title='Wireless Auditing Live CD'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/1992579846976939323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=1992579846976939323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/1992579846976939323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/1992579846976939323'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/12/wireless-auditing-live-cd.html' title='Wireless Auditing Live CD'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-349812529042286845</id><published>2007-11-29T12:18:00.000-08:00</published><updated>2007-11-29T12:38:28.554-08:00</updated><title type='text'>Automated web testing</title><content type='html'>&lt;a href="http://wwwsearch.sourceforge.net/bits/GeneralFAQ.html"&gt;http://wwwsearch.sourceforge.net/bits/GeneralFAQ.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.opensourcetesting.org/functional.php"&gt;http://www.opensourcetesting.org/functional.php&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pamie.sourceforge.net/"&gt;http://pamie.sourceforge.net/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;http://search.cpan.org/~prashant/Win32-IEAutomation-0.5/lib/Win32/IEAutomation.pm&lt;a href="http://search.cpan.org/~prashant/Win32-IEAutomation-0.5/lib/Win32/IEAutomation.pm"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://search.cpan.org/dist/WWW-Mechanize/lib/WWW/Mechanize/Examples.pod"&gt;http://search.cpan.org/dist/WWW-Mechanize/lib/WWW/Mechanize/Examples.pod&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-349812529042286845?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/349812529042286845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=349812529042286845' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/349812529042286845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/349812529042286845'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/11/automated-web-testing_29.html' title='Automated web testing'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-5889980011513594696</id><published>2007-11-29T12:11:00.000-08:00</published><updated>2007-11-29T12:12:11.806-08:00</updated><title type='text'>Automated web testing</title><content type='html'>Selenium&lt;br /&gt;&lt;a href="http://www.openqa.org/selenium-rc/tutorial.html"&gt;http://www.openqa.org/selenium-rc/tutorial.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-5889980011513594696?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/5889980011513594696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=5889980011513594696' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5889980011513594696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/5889980011513594696'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/11/automated-web-testing.html' title='Automated web testing'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-4159311851033574064</id><published>2007-11-28T02:18:00.000-08:00</published><updated>2007-11-28T02:19:06.644-08:00</updated><title type='text'>http://www.trustedsource.org/</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-4159311851033574064?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.trustedsource.org/' title='http://www.trustedsource.org/'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/4159311851033574064/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=4159311851033574064' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4159311851033574064'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4159311851033574064'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/11/httpwwwtrustedsourceorg.html' title='http://www.trustedsource.org/'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-956438235746776097</id><published>2007-11-14T08:34:00.000-08:00</published><updated>2007-11-14T08:35:08.000-08:00</updated><title type='text'>When laptop is unlocked..</title><content type='html'>download and wallpaper. ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-956438235746776097?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.fpsmagazine.com/blog/uploaded_images/brain-hypnovision-754647.jpg' title='When laptop is unlocked..'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/956438235746776097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=956438235746776097' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/956438235746776097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/956438235746776097'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/11/when-laptop-is-unlocked.html' title='When laptop is unlocked..'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-4664657232694264853</id><published>2007-10-23T06:27:00.000-07:00</published><updated>2007-10-23T06:30:57.795-07:00</updated><title type='text'>Unicode Reverse Character .. for the fun of it..</title><content type='html'>The mirroring character is within the braces &lt;br /&gt;&lt;pre&gt;(&amp;#8238;&amp;#8238;( &lt;/pre&gt;&lt;br /&gt; Just copy it somewhere&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-4664657232694264853?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/4664657232694264853/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=4664657232694264853' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4664657232694264853'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4664657232694264853'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/10/unicode-reverse-character-for-fun-of-it.html' title='Unicode Reverse Character .. for the fun of it..'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-414961481794226788</id><published>2007-10-20T07:23:00.000-07:00</published><updated>2007-10-20T07:24:01.005-07:00</updated><title type='text'>Testing and exploiting flash</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-414961481794226788?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='https://www.flashsec.org/wiki/Main_Page' title='Testing and exploiting flash'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/414961481794226788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=414961481794226788' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/414961481794226788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/414961481794226788'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/10/testing-and-exploiting-flash.html' title='Testing and exploiting flash'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-475021862798295167</id><published>2007-10-09T00:47:00.000-07:00</published><updated>2007-10-09T00:48:10.963-07:00</updated><title type='text'>Interesting XSS site</title><content type='html'>http://www.xssed.com/&lt;br /&gt;- Interesting site on cross-site scripting.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-475021862798295167?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/475021862798295167/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=475021862798295167' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/475021862798295167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/475021862798295167'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/10/interesting-xss-site.html' title='Interesting XSS site'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-7335458611164965154</id><published>2007-08-15T01:50:00.001-07:00</published><updated>2007-08-15T01:51:01.500-07:00</updated><title type='text'>Wikiscanner</title><content type='html'>Nice tool that matches IP addresses, etc. to Wikipedia edits&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-7335458611164965154?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://wikiscanner.virgil.gr/' title='Wikiscanner'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/7335458611164965154/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=7335458611164965154' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/7335458611164965154'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/7335458611164965154'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/08/wikiscanner.html' title='Wikiscanner'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-4984356348738011075</id><published>2007-08-15T00:46:00.000-07:00</published><updated>2007-08-15T00:47:05.227-07:00</updated><title type='text'>Dan K on Youtube</title><content type='html'>or rather.. Dan K's own Youtube movies.. &lt;br /&gt;=)&lt;br /&gt;&lt;a href="http://www.youtube.com/user/effugas"&gt;http://www.youtube.com/user/effugas&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-4984356348738011075?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.youtube.com/user/effugas' title='Dan K on Youtube'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/4984356348738011075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=4984356348738011075' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4984356348738011075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/4984356348738011075'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/08/dan-k-on-youtube.html' title='Dan K on Youtube'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-3693363476972590636</id><published>2007-07-11T01:17:00.002-07:00</published><updated>2007-07-11T01:18:09.723-07:00</updated><title type='text'>XSS tunneling</title><content type='html'>XSS Tunneling Paper:&lt;br /&gt;http://www.portcullis-security.com/uplds/whitepapers/XSSTunnelling.pdf&lt;br /&gt;&lt;br /&gt;XSS Shell, XSS Tunnel Binary Releases and Source Code: &lt;br /&gt;http://www.portcullis-security.com/16.php&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-3693363476972590636?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/3693363476972590636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=3693363476972590636' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3693363476972590636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3693363476972590636'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/07/xss-tunneling.html' title='XSS tunneling'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-3294082929724075119</id><published>2007-07-11T01:17:00.001-07:00</published><updated>2007-07-11T01:17:22.900-07:00</updated><title type='text'>SQL Cheat sheet</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-3294082929724075119?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://ferruh.mavituna.com/makale/sql-injection-cheatsheet/' title='SQL Cheat sheet'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/3294082929724075119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=3294082929724075119' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3294082929724075119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/3294082929724075119'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/07/sql-cheat-sheet.html' title='SQL Cheat sheet'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-9032722083681354951</id><published>2007-05-23T22:13:00.000-07:00</published><updated>2007-05-23T22:14:25.606-07:00</updated><title type='text'>Top 15 free SQL injection scanners</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-9032722083681354951?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.security-hacks.com/2007/05/18/top-15-free-sql-injection-scanners' title='Top 15 free SQL injection scanners'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/9032722083681354951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=9032722083681354951' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/9032722083681354951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/9032722083681354951'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/05/top-15-free-sql-injection-scanners.html' title='Top 15 free SQL injection scanners'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-6419546670436417590</id><published>2007-05-15T13:51:00.000-07:00</published><updated>2007-05-15T13:52:12.251-07:00</updated><title type='text'>Some eyecandy..</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-6419546670436417590?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://mashable.com/2007/05/15/16-awesome-data-visualization-tools/' title='Some eyecandy..'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/6419546670436417590/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=6419546670436417590' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/6419546670436417590'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/6419546670436417590'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/05/some-eyecandy.html' title='Some eyecandy..'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-2758346889598688109</id><published>2007-05-07T22:56:00.001-07:00</published><updated>2007-05-07T22:56:19.380-07:00</updated><title type='text'>Wfuzz</title><content type='html'>A web application fuzzer with dictionnaries.&lt;br /&gt;&lt;a href="http://www.edge-security.com/wfuzz.php"&gt;http://www.edge-security.com/wfuzz.php&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-2758346889598688109?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/2758346889598688109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=2758346889598688109' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2758346889598688109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2758346889598688109'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/05/wfuzz.html' title='Wfuzz'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-2724730788491467995</id><published>2007-05-07T22:49:00.000-07:00</published><updated>2007-05-07T22:50:41.520-07:00</updated><title type='text'>Secret behind Canadian Spy Coins revealed</title><content type='html'>.. just multicolor standard coins.. just too unfamiliar too US military contractors.. (Weia!)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-2724730788491467995?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.cbc.ca/technology/story/2007/05/07/tech-poppy-quarter.html' title='Secret behind Canadian Spy Coins revealed'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/2724730788491467995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=2724730788491467995' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2724730788491467995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/2724730788491467995'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/05/secret-behind-canadian-spy-coins.html' title='Secret behind Canadian Spy Coins revealed'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-1502008008581046634</id><published>2007-03-22T03:29:00.001-07:00</published><updated>2007-03-22T03:29:46.041-07:00</updated><title type='text'>SQL injection sheet</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-1502008008581046634?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://ha.ckers.org/blog/20070315/sql-injection-cheat-sheet/' title='SQL injection sheet'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/1502008008581046634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=1502008008581046634' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/1502008008581046634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/1502008008581046634'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2007/03/sql-injection-sheet.html' title='SQL injection sheet'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-116643328937138631</id><published>2006-12-18T01:14:00.000-08:00</published><updated>2006-12-18T01:14:49.393-08:00</updated><title type='text'>Top 10 Web Hacks 2006</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-116643328937138631?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://jeremiahgrossman.blogspot.com/2006/12/top-10-web-hacks-of-2006.html' title='Top 10 Web Hacks 2006'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/116643328937138631/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=116643328937138631' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116643328937138631'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116643328937138631'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/12/top-10-web-hacks-2006.html' title='Top 10 Web Hacks 2006'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-116617367591911191</id><published>2006-12-15T01:07:00.000-08:00</published><updated>2006-12-15T01:07:55.933-08:00</updated><title type='text'>Backdooring image files</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-116617367591911191?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.gnucitizen.org/blog/backdooring-images' title='Backdooring image files'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/116617367591911191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=116617367591911191' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116617367591911191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116617367591911191'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/12/backdooring-image-files.html' title='Backdooring image files'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-116599353724565359</id><published>2006-12-12T23:04:00.000-08:00</published><updated>2006-12-13T11:44:49.346-08:00</updated><title type='text'>The mirroring character in Unicode (which is &amp; #8238;&amp; #8238; without the blanks)</title><content type='html'>&amp;#8238;&amp;#8238; Interesting blog entry on the Unicode mirroring character..&lt;br /&gt;&lt;a href="http://digitalpbk.blogspot.com/2006/11/fun-with-unicode-and-mirroring.html"&gt;http://digitalpbk.blogspot.com/2006/11/fun-with-unicode-and-mirroring.html &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.reflectorium.de/?/moc.elgoog.www//:ptth"&gt;http://www.reflectorium.de/?/moc.elgoog.www//:ptth&lt;/a&gt;&lt;br /&gt;of course is misleading..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-116599353724565359?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://digitalpbk.blogspot.com/2006/11/fun-with-unicode-and-mirroring.html' title='The mirroring character in Unicode (which is &amp; #8238;&amp; #8238; without the blanks)'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/116599353724565359/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=116599353724565359' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116599353724565359'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116599353724565359'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/12/mirroring-character-in-unicode-which.html' title='The mirroring character in Unicode (which is &amp; #8238;&amp; #8238; without the blanks)'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-116560399586632078</id><published>2006-12-08T10:52:00.000-08:00</published><updated>2006-12-08T10:53:15.890-08:00</updated><title type='text'>Earthquake Information Europe</title><content type='html'>Really good website&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-116560399586632078?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.emsc-csem.org/' title='Earthquake Information Europe'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/116560399586632078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=116560399586632078' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116560399586632078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/116560399586632078'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/12/earthquake-information-europe.html' title='Earthquake Information Europe'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-115858481039461117</id><published>2006-09-18T06:06:00.000-07:00</published><updated>2006-09-18T06:06:50.416-07:00</updated><title type='text'>Javascript attackapi</title><content type='html'>&lt;a href="http://www.gnucitizen.org/projects/attackapi/"&gt;http://www.gnucitizen.org/projects/attackapi/ &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-115858481039461117?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/115858481039461117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=115858481039461117' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/115858481039461117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/115858481039461117'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/09/javascript-attackapi.html' title='Javascript attackapi'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-115511225518383052</id><published>2006-08-09T01:29:00.000-07:00</published><updated>2006-08-09T01:31:33.410-07:00</updated><title type='text'>Spyware and Malware</title><content type='html'>These web sites seem to have some repositories and tools to that end:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.mwcollect.org/"&gt;http://www.mwcollect.org/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.offensivecomputing.net/"&gt;http://www.offensivecomputing.net/ &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-115511225518383052?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/115511225518383052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=115511225518383052' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/115511225518383052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/115511225518383052'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/08/spyware-and-malware.html' title='Spyware and Malware'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-115080302237202568</id><published>2006-06-20T04:29:00.000-07:00</published><updated>2006-06-20T04:30:22.400-07:00</updated><title type='text'>Coldfusion Security Checklist</title><content type='html'>&lt;a href="http://ray.camdenfamily.com/coldfusionsecuritychecklist.cfm%20http://ray.camdenfamily.com/coldfusionsecuritychecklist.cfm"&gt;http://ray.camdenfamily.com/coldfusionsecuritychecklist.cfm &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-115080302237202568?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/115080302237202568/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=115080302237202568' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/115080302237202568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/115080302237202568'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/06/coldfusion-security-checklist.html' title='Coldfusion Security Checklist'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-114375379890893502</id><published>2006-03-30T13:03:00.000-08:00</published><updated>2006-03-30T13:24:00.520-08:00</updated><title type='text'>Jerry A. Taylor of Tuttle, OK</title><content type='html'>Thanks to TheRegister probably all know what "pulling a Tuttle" means by now.&lt;br /&gt;See:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.theregister.co.uk/2006/03/24/tuttle_centos/"&gt;http://www.theregister.co.uk/2006/03/24/tuttle_centos/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.theregister.co.uk/2006/03/27/tuttle_email/"&gt;http://www.theregister.co.uk/2006/03/27/tuttle_email/ &lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;As a result, a few folks probably started to wonder what 22 years experience in IT really means nowadays. (As Mr. Taylor was still unable to tell a standard default install page..)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://72.14.203.104/search?q=cache:eqsOBCMbxYAJ:www.tuttletimes.com/viewarticle.php%3Fid%3D744+%22jerry+a.+taylor%22+tuttle&amp;hl=de&amp;amp;amp;gl=de&amp;ct=clnk&amp;amp;cd=10"&gt;This article in the Tuttletimes&lt;/a&gt; (courtesy of Google's cache) gives some details that might explain some of the background:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Mr. Taylor worked 22 years with E Systems as a program manager. The majority of the time on a  classified government program.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;He has also had his own computer business and worked for the Choctaw Electric Cooperative as their internet technologies manager.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;It appears that Mr. Taylor had originally great plans for the city website when he started his job:&lt;br /&gt;a user-friendly automated system, information about city officials, agenda and minutes of meetings, a place to read ordinances, bill payments and building permit applications.&lt;br /&gt;- Which probably means that there's still a lot of work waiting for him, considering the current state of &lt;a href="http://www.tuttle-ok.gov/"&gt;http://www.tuttle-ok.gov/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;He had already build the city of Harrah’s website before at &lt;a href="http://www.harrah.net/"&gt;http://www.harrah.net/&lt;/a&gt;. Currently it gives you a one-word-page.&lt;br /&gt;Fortunately, it has been archived for posterity at archive.org:&lt;br /&gt;&lt;a href="http://web.archive.org/web/*/http://www.harrah.net/"&gt;http://web.archive.org/web/*/http://www.harrah.net/&lt;/a&gt;&lt;br /&gt;(Also see &lt;a href="http://www.greateroklahomacity.com/page.asp?atomid=461"&gt;this&lt;/a&gt;)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;So all in all, it seems that he should have had all the skills. (Of course, you never know what classified programms are all about.) - Something must have stopped him from reaching the goals that he had laid out for himself.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-114375379890893502?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/114375379890893502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=114375379890893502' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/114375379890893502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/114375379890893502'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/03/jerry-taylor-of-tuttle-ok.html' title='Jerry A. Taylor of Tuttle, OK'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-113981518582890329</id><published>2006-02-12T23:17:00.000-08:00</published><updated>2006-02-12T23:19:45.836-08:00</updated><title type='text'>EFF warning on new Google Desktop Search</title><content type='html'>It stores your files on the Google servers if "search across computers" is enabled. - Which of course is a major item of concern..&lt;br /&gt;&lt;a href="http://www.eff.org/news/archives/2006_02.php#004400"&gt;http://www.eff.org/news/archives/2006_02.php#004400&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-113981518582890329?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/113981518582890329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=113981518582890329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/113981518582890329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/113981518582890329'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/02/eff-warning-on-new-google-desktop.html' title='EFF warning on new Google Desktop Search'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-113808619198542292</id><published>2006-01-23T23:00:00.000-08:00</published><updated>2006-01-23T23:03:11.986-08:00</updated><title type='text'>Bruce Schneier and RFID passports (again)</title><content type='html'>A not so great piece by Schneier on RFID-enabled passports.&lt;br /&gt;- Surprise:  There are several sorts and ranges for RFIDs (and tricks!).&lt;br /&gt;.. what are the problems that US people have with passports? (mystery)&lt;br /&gt;&lt;a href="http://www.schneier.com/blog/archives/2006/01/reading_rfid_ca.html"&gt;http://www.schneier.com/blog/archives/2006/01/reading_rfid_ca.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-113808619198542292?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/113808619198542292/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=113808619198542292' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/113808619198542292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/113808619198542292'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/01/bruce-schneier-and-rfid-passports.html' title='Bruce Schneier and RFID passports (again)'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-113808597193927149</id><published>2006-01-23T22:56:00.000-08:00</published><updated>2006-01-23T22:59:31.950-08:00</updated><title type='text'>US customs opening international mail (routinely?)</title><content type='html'>Bruce Schneier links to a Reuter article on US customes opening international snail mail. Legally.&lt;br /&gt;&lt;a href="http://www.schneier.com/blog/archives/2006/01/us_customs_open.html"&gt;http://www.schneier.com/blog/archives/2006/01/us_customs_open.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-113808597193927149?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/113808597193927149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=113808597193927149' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/113808597193927149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/113808597193927149'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2006/01/us-customs-opening-international-mail.html' title='US customs opening international mail (routinely?)'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-112240406181497412</id><published>2005-07-26T11:53:00.000-07:00</published><updated>2005-07-26T11:54:21.820-07:00</updated><title type='text'>Johnny Long published book on Google hacking</title><content type='html'>&lt;a href="http://books.slashdot.org/article.pl?sid=05/07/25/200221&amp;amp;from=rss"&gt;Review at Slashdot&lt;/a&gt; (danke Timo!)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-112240406181497412?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/112240406181497412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=112240406181497412' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/112240406181497412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/112240406181497412'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/07/johnny-long-published-book-on-google.html' title='Johnny Long published book on Google hacking'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-111839274856686637</id><published>2005-06-10T01:38:00.000-07:00</published><updated>2005-06-10T01:39:08.570-07:00</updated><title type='text'>The DoD Information Assurance Portal</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-111839274856686637?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://iase.disa.mil/' title='The DoD Information Assurance Portal'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/111839274856686637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=111839274856686637' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111839274856686637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111839274856686637'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/06/dod-information-assurance-portal.html' title='The DoD Information Assurance Portal'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-111780198620646623</id><published>2005-06-03T05:30:00.000-07:00</published><updated>2005-06-03T05:33:06.213-07:00</updated><title type='text'>Guerilla Threat Modelling</title><content type='html'>&lt;br /&gt;Microsoft's Peter Torr has an excellent article on Threat Modelling (the Microsoft way..)&lt;br /&gt;at &lt;a href="http://blogs.msdn.com/ptorr/archive/2005/02/22/GuerillaThreatModelling.aspx"&gt;&lt;span style="text-decoration: underline;"&gt;right here&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-111780198620646623?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blogs.msdn.com/ptorr/archive/2005/02/22/GuerillaThreatModelling.aspx' title='Guerilla Threat Modelling'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/111780198620646623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=111780198620646623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111780198620646623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111780198620646623'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/06/guerilla-threat-modelling.html' title='Guerilla Threat Modelling'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-111641308506285008</id><published>2005-05-18T03:43:00.000-07:00</published><updated>2005-05-18T03:48:40.190-07:00</updated><title type='text'>Illustrative Security Risks</title><content type='html'>&lt;br /&gt; Illustrative Risks to the Public in the Use of Computer Systems and Related Technology by Peter G. Neumann&lt;br /&gt;&lt;a href="http://www.csl.sri.com/users/neumann/illustrative.html"&gt;http://www.csl.sri.com/users/neumann/illustrative.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-111641308506285008?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/111641308506285008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=111641308506285008' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111641308506285008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111641308506285008'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/05/illustrative-security-risks.html' title='Illustrative Security Risks'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-111399531643079393</id><published>2005-04-20T04:06:00.000-07:00</published><updated>2005-04-20T04:08:36.430-07:00</updated><title type='text'>OpenSSH key management</title><content type='html'>&lt;br /&gt;&lt;a href="http://www-106.ibm.com/developerworks/library/l-keyc.html"&gt;http://www-106.ibm.com/developerworks/library/l-keyc.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www-106.ibm.com/developerworks/library/l-keyc2/"&gt;http://www-106.ibm.com/developerworks/library/l-keyc2/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www-106.ibm.com/developerworks/library/l-keyc3/"&gt;http://www-106.ibm.com/developerworks/library/l-keyc3/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-111399531643079393?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/111399531643079393/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=111399531643079393' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111399531643079393'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111399531643079393'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/04/openssh-key-management.html' title='OpenSSH key management'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-111337954675898090</id><published>2005-04-13T00:58:00.000-07:00</published><updated>2005-04-13T01:05:46.760-07:00</updated><title type='text'>Whoppix LiveCD for Penetration Testing</title><content type='html'>Based on Knoppix, heavily modded for pen testing&lt;br /&gt;&lt;a href="http://www.whoppix.net/"&gt;http://www.whoppix.net/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-111337954675898090?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/111337954675898090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=111337954675898090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111337954675898090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111337954675898090'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/04/whoppix-livecd-for-penetration-testing.html' title='Whoppix LiveCD for Penetration Testing'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-111080094488247700</id><published>2005-03-14T03:47:00.000-08:00</published><updated>2005-03-14T03:49:04.883-08:00</updated><title type='text'>Using honeynets to learn more about Bots</title><content type='html'>&lt;br /&gt;There's an interesting write-up at &lt;a href="http://www.honeynet.org/papers/bots/"&gt;http://www.honeynet.org/papers/bots/&lt;/a&gt;&lt;br /&gt;- one of my big to-do's once my gear is up and running again.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-111080094488247700?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/111080094488247700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=111080094488247700' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111080094488247700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/111080094488247700'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/03/using-honeynets-to-learn-more-about.html' title='Using honeynets to learn more about Bots'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110976859858252007</id><published>2005-03-02T05:02:00.000-08:00</published><updated>2005-03-02T05:03:47.783-08:00</updated><title type='text'>The Insecure Indexing Vulnerability</title><content type='html'>&lt;br /&gt;&lt;strong&gt;&lt;a style="font-weight: normal;" href="http://www.webappsec.org/articles/022805-plain.html"&gt;Attacks Against Local Search Engines&lt;/a&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/strong&gt;interesting paper by Amit Klein on how internal documents could be accessed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110976859858252007?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.webappsec.org/articles/022805-plain.html' title='The Insecure Indexing Vulnerability'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110976859858252007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110976859858252007' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110976859858252007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110976859858252007'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/03/insecure-indexing-vulnerability.html' title='The Insecure Indexing Vulnerability'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110976729636809116</id><published>2005-03-02T04:39:00.000-08:00</published><updated>2005-03-02T04:51:41.976-08:00</updated><title type='text'>Andreas Bogk comments on SHA-1</title><content type='html'>&lt;br /&gt;..in German. While I like Bruce Schneier's comments, I think we should also listen to the other folks out there. (as in: just re-quoting cryptogram is a *bad thing*). - Andreas did some very original things in the past.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110976729636809116?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='https://www.openbc.com/cgi-bin/forum.fpl?op=showarticles&amp;id=327941&amp;articleid=347816#347816' title='Andreas Bogk comments on SHA-1'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110976729636809116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110976729636809116' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110976729636809116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110976729636809116'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/03/andreas-bogk-comments-on-sha-1.html' title='Andreas Bogk comments on SHA-1'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110967098201920862</id><published>2005-03-01T01:54:00.000-08:00</published><updated>2005-03-01T01:57:41.990-08:00</updated><title type='text'>Send-Safe - a look at a professional spamming tool</title><content type='html'>&lt;br /&gt;&lt;br /&gt;The folks at F-Secure did a fascinating article  on "Send Safe", one of the tools used by spammers.&lt;br /&gt;This tool even has builtin support for using infected PCs to send the spam. Very interesting screen shot!&lt;br /&gt;&lt;a href="http://www.f-secure.com/weblog/#00000485"&gt;http://www.f-secure.com/weblog/#00000485&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110967098201920862?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.f-secure.com/weblog/#00000485' title='Send-Safe - a look at a professional spamming tool'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110967098201920862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110967098201920862' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110967098201920862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110967098201920862'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/03/send-safe-look-at-professional.html' title='Send-Safe - a look at a professional spamming tool'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110917589168253523</id><published>2005-02-23T08:23:00.000-08:00</published><updated>2005-02-23T08:24:51.683-08:00</updated><title type='text'>Guerilla Threat Modelling</title><content type='html'>Peter Torr (of Microsoft) on Threat Modelling again:&lt;br /&gt;&lt;a href="http://blogs.msdn.com/ptorr/archive/2005/02/22/378510.aspx"&gt;Guerilla Threat Modelling&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110917589168253523?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blogs.msdn.com/ptorr/archive/2005/02/22/378510.aspx' title='Guerilla Threat Modelling'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110917589168253523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110917589168253523' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110917589168253523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110917589168253523'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/02/guerilla-threat-modelling.html' title='Guerilla Threat Modelling'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110802531528824307</id><published>2005-02-10T01:47:00.000-08:00</published><updated>2005-02-10T00:51:29.666-08:00</updated><title type='text'>Packetstormsecurity RSS-feeds</title><content type='html'>&lt;a href="http://www.packetstormsecurity.org/whatsnew100.xml"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110802531528824307?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.packetstormsecurity.org/whatsnew100.xml' title='Packetstormsecurity RSS-feeds'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110802531528824307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110802531528824307' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110802531528824307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110802531528824307'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/02/packetstormsecurity-rss-feeds.html' title='Packetstormsecurity RSS-feeds'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110795172932468879</id><published>2005-02-09T04:21:00.000-08:00</published><updated>2005-02-09T04:22:09.323-08:00</updated><title type='text'>Enterprise Architecture Alignment Heuristics</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110795172932468879?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://msdn.microsoft.com/architecture/default.aspx?pull=/library/en-us/dnmaj/html/heuristics.asp' title='Enterprise Architecture Alignment Heuristics'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110795172932468879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110795172932468879' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110795172932468879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110795172932468879'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/02/enterprise-architecture-alignment.html' title='Enterprise Architecture Alignment Heuristics'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110794057211077836</id><published>2005-02-09T01:13:00.000-08:00</published><updated>2005-02-09T01:21:35.693-08:00</updated><title type='text'>High-Level Threat Modelling </title><content type='html'>A nice synapsis on how the ideas in the Threat Modelling book by Window Snyder et al. might be put to use in practice. (As in: Hey Microsoft, cool idea - but just how to you do it in real life?)&lt;br /&gt;&lt;a href="http://weblogs.asp.net/ptorr/archive/2005/02/08/368881.aspx"&gt;http://weblogs.asp.net/ptorr/archive/2005/02/08/368881.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Not bad, but ends somewhat early.&lt;br /&gt;- I always thought that other key benefits to do threat modelling are, that you could&lt;br /&gt;a) show the morons that want to introduce insecurity later on in the project, what that will do to them easily and illustratively&lt;br /&gt;b) have a readily available, nice residual risk piece for final sign-off&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110794057211077836?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110794057211077836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110794057211077836' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110794057211077836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110794057211077836'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/02/high-level-threat-modelling.html' title='High-Level Threat Modelling '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110794017413789181</id><published>2005-02-09T01:05:00.000-08:00</published><updated>2005-02-09T01:09:34.136-08:00</updated><title type='text'>If you can get around it, people will.. </title><content type='html'>&lt;br /&gt;I found this on Larry Seltzer's &lt;a href="http://blog.ziffdavis.com/seltzer/archive/2005/02/07/5774.aspx"&gt;blog&lt;/a&gt;, who in turn found it on Bruce Schneier's.. :&lt;br /&gt;&lt;a href="http://www.syslog.com/%7Ejwilson/pics-i-like/kurios119.jpg"&gt;when physical security just doesn't make sense&lt;/a&gt;&lt;br /&gt;The  &lt;a href="http://www.livejournal.com/users/fantasygoat/"&gt;whole picture collection&lt;/a&gt; is also quite peculiar. (alas, off-topic)&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110794017413789181?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.syslog.com/~jwilson/pics-i-like/kurios119.jpg' title='If you can get around it, people will.. '/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110794017413789181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110794017413789181' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110794017413789181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110794017413789181'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/02/if-you-can-get-around-it-people-will.html' title='If you can get around it, people will.. '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110716163490844189</id><published>2005-01-31T01:49:00.000-08:00</published><updated>2005-01-31T01:23:19.060-08:00</updated><title type='text'>Microsoft: Mapping International Security Standards to MOF</title><content type='html'>About time that Microsoft came out with an other free tangible security management goodie.&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=b305cc14-de60-4fdb-93d0-4346492e375d&amp;displaylang=en"&gt;"Mapping International Security Standards to MOF&lt;/a&gt;" or - maybe more bluntly - How does Microsoft's interpretation of ITIL (called MOF) map to international security standards (such as ISO17799).&lt;br /&gt;By the way, the folks behind ITIL have a most excellent book on "ITIL security management", which happens to cover the ISO17799 mapping. So I wonder how much added-value Microsoft brings here. (Granted the ITIL book is expensive and this goodie is free..)&lt;br /&gt;--&lt;br /&gt;After a really hard glimpse at the Microsoft paper - it's really worth getting the original ITIL security management book. &lt;br /&gt;(The Microsoft paper is  somewhat thin, but nevertheless is a nice ISO17799 introduction...)&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110716163490844189?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110716163490844189/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110716163490844189' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110716163490844189'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110716163490844189'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/microsoft-mapping-international.html' title='Microsoft: Mapping International Security Standards to MOF'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110716092916503999</id><published>2005-01-31T01:40:00.000-08:00</published><updated>2005-01-31T00:42:09.166-08:00</updated><title type='text'>CopyScape - Web Plagiarism Search Engine </title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110716092916503999?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.copyscape.com/' title='CopyScape - Web Plagiarism Search Engine '/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110716092916503999/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110716092916503999' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110716092916503999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110716092916503999'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/copyscape-web-plagiarism-search-engine.html' title='CopyScape - Web Plagiarism Search Engine '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110704476147819586</id><published>2005-01-29T16:24:00.000-08:00</published><updated>2005-01-29T16:26:01.480-08:00</updated><title type='text'>Towards an Economic Analysis of Disclosure</title><content type='html'>A &lt;a href="http://www.emergentchaos.com/archives/000855.html"&gt;very interesting posting&lt;/a&gt; at Adam Shostack's blog (see below). - Also, have a look at the additional papers mentioned in the comments...&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110704476147819586?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110704476147819586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110704476147819586' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110704476147819586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110704476147819586'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/towards-economic-analysis-of.html' title='Towards an Economic Analysis of Disclosure'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110704441650763472</id><published>2005-01-29T16:18:00.000-08:00</published><updated>2005-01-29T16:24:26.980-08:00</updated><title type='text'>Emergent Chaos, blog by Adam Shostack</title><content type='html'>&lt;br /&gt;&lt;a href="http://www.emergentchaos.com/"&gt;http://www.emergentchaos.com/&lt;/a&gt;&lt;br /&gt;has some interesting thinking, .. now part of my daily blog diet..&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110704441650763472?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110704441650763472/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110704441650763472' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110704441650763472'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110704441650763472'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/emergent-chaos-blog-by-adam-shostack.html' title='Emergent Chaos, blog by Adam Shostack'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110692794919357080</id><published>2005-01-28T07:51:00.000-08:00</published><updated>2005-01-28T07:59:09.193-08:00</updated><title type='text'>Information Assurance Technical Framework Forum</title><content type='html'>&lt;br /&gt;&lt;br /&gt;"The &lt;a href="http://www.iatf.net/"&gt;Information Assurance Technical Framework Forum (IATFF) &lt;/a&gt;is a National Security&lt;br /&gt;Agency (NSA) sponsored outreach activity created to foster dialog amongst U.S.&lt;br /&gt;Government agencies, U.S. Industry, and U.S. Academia seeking to provide their&lt;br /&gt;customers solutions for information assurance problems."&lt;br /&gt;&lt;br /&gt;They have quite a few documents for download - although, on first glance, not totally cutting edge. (behind what you learnt to expect and love from folks like the NIST...)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.iatf.net/"&gt;http://www.iatf.net/&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110692794919357080?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110692794919357080/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110692794919357080' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110692794919357080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110692794919357080'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/information-assurance-technical.html' title='Information Assurance Technical Framework Forum'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110656299504187989</id><published>2005-01-24T02:34:00.000-08:00</published><updated>2005-01-24T03:11:40.680-08:00</updated><title type='text'>US: National security concerns over IBM notebook sale to China</title><content type='html'>According to this &lt;a href="http://www.spiegel.de/wirtschaft/0,1518,338269,00.html"&gt;article in German&lt;/a&gt; at SpiegelOnline, the CFIUS comitee in the USA is now voicing national security concerns of the sale of the IBM notebook business to a Chinese company. (I've been wondering about the implications of the Trusted Computing chip in the Thinkpads and China...)&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110656299504187989?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110656299504187989/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110656299504187989' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110656299504187989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110656299504187989'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/us-national-security-concerns-over-ibm.html' title='US: National security concerns over IBM notebook sale to China'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110631504471649046</id><published>2005-01-21T05:41:00.000-08:00</published><updated>2005-01-21T05:44:04.716-08:00</updated><title type='text'>FDA guidance</title><content type='html'>&lt;a href="http://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfGGP/Results.CFM?Doc_Type=1&amp;Doc_IsCur=1&amp;amp;Doc_OFFICE=OC&amp;amp;SORT_ORDER=DIVISION,Branch,DocName"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110631504471649046?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfGGP/Results.CFM?Doc_Type=1&amp;Doc_IsCur=1&amp;Doc_OFFICE=OC&amp;SORT_ORDER=DIVISION,Branch,DocName' title='FDA guidance'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110631504471649046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110631504471649046' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110631504471649046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110631504471649046'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/fda-guidance.html' title='FDA guidance'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110621045234908703</id><published>2005-01-20T01:38:00.000-08:00</published><updated>2005-01-20T00:40:52.350-08:00</updated><title type='text'>Defiling - anti-forensics on UNIX</title><content type='html'>HERT carries an article on "The Grugq" making a tour this year, talking about anti-forensics in UNIX. (Article also links to a presentation).&lt;br /&gt;&lt;a href="http://hert.org/story.php/58"&gt;http://hert.org/story.php/58&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here's a link to a Phrack article mentioned at link above. (old, 2002)&lt;br /&gt;&lt;a href="http://www.phrack.org/phrack/59/p59-0x06.txt"&gt;http://www.phrack.org/phrack/59/p59-0x06.txt&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110621045234908703?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110621045234908703/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110621045234908703' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110621045234908703'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110621045234908703'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/defiling-anti-forensics-on-unix.html' title='Defiling - anti-forensics on UNIX'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110594928046318756</id><published>2005-01-17T01:07:00.000-08:00</published><updated>2005-01-17T00:08:00.463-08:00</updated><title type='text'>New releases at metasploit</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110594928046318756?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://metasploit.com/' title='New releases at metasploit'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110594928046318756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110594928046318756' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110594928046318756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110594928046318756'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/new-releases-at-metasploit.html' title='New releases at metasploit'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110594919318011885</id><published>2005-01-17T01:02:00.000-08:00</published><updated>2005-01-17T06:13:45.066-08:00</updated><title type='text'>Locksmith rehash disclosure debate</title><content type='html'>Very interesting article on TaoSecurity Blog about a debate on a locksmith newsgroup that was kindled by a paper titled "safecracking for the computer scientist".&lt;br /&gt;&lt;br /&gt;Basically some locksmiths there are stuck in a 19th century mind set. - This is scary, to think that some of these folks still believe that selling insecure devices as secure is okay as long as noone tells about the insecurity in them - and we entrust them with real life valuables.. *yuck!*&lt;br /&gt;&lt;br /&gt;&lt;a href="http://taosecurity.blogspot.com/2005/01/locksmiths-rehash-disclosure-debate.html"&gt;Link to entry on taosecurity&lt;/a&gt;&lt;a href="http://taosecurity.blogspot.com/2005/01/locksmiths-rehash-disclosure-debate.html"&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110594919318011885?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110594919318011885/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110594919318011885' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110594919318011885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110594919318011885'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/locksmith-rehash-disclosure-debate.html' title='Locksmith rehash disclosure debate'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110485662948950027</id><published>2005-01-04T08:35:00.000-08:00</published><updated>2005-01-04T08:37:09.490-08:00</updated><title type='text'>BITS Kalculator: Key Risk Measurement Tool for Information Security Operational Risks </title><content type='html'>&lt;br /&gt;From the Bank of International Settlements (BIS):&lt;br /&gt;&lt;a href="http://www.bitsinfo.org/wp.html"&gt;http://www.bitsinfo.org/wp.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110485662948950027?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110485662948950027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110485662948950027' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110485662948950027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110485662948950027'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/bits-kalculator-key-risk-measurement.html' title='BITS Kalculator: Key Risk Measurement Tool for Information Security Operational Risks '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110485027240923738</id><published>2005-01-04T06:45:00.000-08:00</published><updated>2005-01-04T06:51:36.833-08:00</updated><title type='text'>Defeating web-based content filtering on gateways...</title><content type='html'>&lt;br /&gt;Rory has some comments on proxies that obfuscate the communication at &lt;a href="http://raesene.dnsalias.net/archives/000156.html"&gt;http://raesene.dnsalias.net/archives/000156.html &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(Axel pointed me towards this via &lt;a href="http://balrog.de/security/archives/2005/01/04/55_security-is-not-a-product-once-again"&gt;http://balrog.de/security/archives/2005/01/04/55_security-is-not-a-product-once-again )&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Personally, I think one shouldn't focus on these cgi/php-based proxies too much. Isn't it far easier to use google's "translate that page" functionality? Or Anonymizer and Co?&lt;br /&gt;.. or - to the same end - a trusted SSL-based reverse proxy???&lt;br /&gt;&lt;br /&gt;Of course, the cgi/php-based proxies will give you&lt;br /&gt;+ clicks 'n hits on someone's web ads&lt;br /&gt;+ and a nice click/usage history somewhere&lt;br /&gt;&lt;br /&gt;Should be ideal for phising too.. (So please beware!)&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110485027240923738?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110485027240923738/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110485027240923738' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110485027240923738'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110485027240923738'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/defeating-web-based-content-filtering.html' title='Defeating web-based content filtering on gateways...'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110475823962951403</id><published>2005-01-03T05:14:00.000-08:00</published><updated>2005-01-03T05:17:19.630-08:00</updated><title type='text'>Notes from the 21C03 conference</title><content type='html'>&lt;br /&gt;&lt;br /&gt;Here are my notes from the 21C03 conference held by the German Chaos Communication Club (CCC) from Dec 27-29 2004 in Berlin.&lt;br /&gt;&lt;br /&gt;The official sites of the event are at&lt;br /&gt;&lt;a href="http://www.ccc.de/congress/2004/index.en.html"&gt;http://www.ccc.de/congress/2004/index.en.html&lt;/a&gt;&lt;br /&gt;&lt;a href="https://21c3.ccc.de/wiki/index.php/Main_Page"&gt;https://21c3.ccc.de/wiki/index.php/Main_Page&lt;/a&gt;&lt;br /&gt;&lt;a href="http://21c3.ccc.de/weblog/"&gt;http://21c3.ccc.de/weblog/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The CCC promised to make videos of most sessions available on the web. (Should be up in January 2005).&lt;br /&gt;&lt;br /&gt;The annual conference had a record participation (around 3,500 participants) and appeared much more professional than earlier events.&lt;br /&gt;The organisators had to choose from around 200 submissions to fill the session tracks. The trick was really which session to choose.&lt;br /&gt;&lt;br /&gt;__Things that really struck me__&lt;br /&gt;&lt;br /&gt;_Passive covert channels in the Linux kernel_&lt;br /&gt;- Very interesting talk focused on getting covert messages out as part of the Sequence number in packets. The speaker introduced a tool (nushu.c), which hides this communication. This could have various uses e.g. in bot networks and applications that "want to phone home" and hide additional data.&lt;br /&gt;See &lt;a href="http://www.invisiblethings.org/"&gt;http://www.invisiblethings.org/ &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;_Bluetooth vulnerabilities_&lt;br /&gt;- There was a full-disclosure presentation (incl. tools) on the bluetooth vulnerabilities mentioned in 2004 by trifinite.&lt;br /&gt;See&lt;a href="http://www.trifinite.org/"&gt; http://www.trifinite.org/&lt;/a&gt;&lt;br /&gt;- This is really bad. This is about reading and manipulating address books from afar. This is also - on some phones - about using someone else's phone to make phone calls and to redirect phones to someone else's phone to yours.&lt;br /&gt;- People need to get their vulnerable phones updated in a shop. (And most people probably won't.)&lt;br /&gt;&lt;br /&gt;_Security nightmares_&lt;br /&gt;- SSH will probably be exploited again in a big way in 2005. (Rumours of another upcoming exploit). -&gt; This makes me think that people should start to look at "port knocking" (or restricting access to certain IPs) to add a level of security for internet facing systems, i.e. you can only connect to your SSH server if you come from a pre-defined IP or after you did some magic ping/connection pattern.&lt;br /&gt;- There might be trouble with cars turning into mobile computers ahead. It appears that some car systems use RDS data (via the car radio) as input. There are rumours that the RDS parsers in some car radios might be exploitable.&lt;br /&gt;- People should really, really patch their mobile phones...&lt;br /&gt;&lt;br /&gt;_MD5 insecurities_&lt;br /&gt;- there are collisions in MD5. (Which also means that people should start to use other hash algorithms instead)&lt;br /&gt;- a Chinese researcher has released two proof of concept test vectors that cause a collision. (It is unclear how these vectors were found!)&lt;br /&gt;- these two test vectors can already be used to carry out attacks today&lt;br /&gt;- MD5 operates on blocks, i.e.  if you find  two files that MD5 to the same hash, an arbitrary payload can be applied to both files and they'll still have the same hash.&lt;br /&gt;(These two files could be e.g. the two test vectors above)&lt;br /&gt;- David Kaminsky's tool "stripwire" produces  two binary packages. Both contain an arbitrary payload, but the payload is encrypted with AES. Only one of the packages ("Fire") is decryptable and thus dangerous; the other ("Ice") shields its data behind AES. Both files share the same MD5 hash.&lt;br /&gt;- According to doxpara.com: "This is an excellent vector for malicious developers to get unsafe code past a group of auditors, perhaps to acquire a required third party signature. Alternatively, build tools themselves could be compromised to embed safe versions of dangerous payloads in each build. At some later point, the embedded payload could be safely "activated", without the MD5 changing. This has implications for Tripwire, DRM, and several package management architectures.[..] Very interesting possibilities open up once the full attack is made available -- among other things, we can create self-decrypting executables (fire.exe and ice.exe) that exhibit differential behavior based on their internal colliding payloads. They'll still have the same MD5 hash."&lt;br /&gt;- this also allows for covert channels&lt;br /&gt;- there's also a real hole posed by the MD5 variant used in KaZaa&lt;br /&gt;- -&gt; You can read it all at &lt;a href="http://www.doxpara.com"&gt;http://www.doxpara.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;_Instant Messaging security holes_&lt;br /&gt;- Apparently there were/are quite a few bugs in IM clients. This is bad as more and more people use them for "serious" communications.&lt;br /&gt;-&gt; &lt;a href="http://www.stonedcoder.org/"&gt;http://www.stonedcoder.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;_DNS_&lt;br /&gt;- nice talk on how one can use the DNS system with its mind-boggling number of servers to tunnel data and store data&lt;br /&gt;- this included a demonstration of SSH via DNS and webradio (caching)&lt;br /&gt;- NTSX old tool&lt;br /&gt;- droute new tool&lt;br /&gt;- also google for "grr", "nomede" and "miname"&lt;br /&gt;- -&gt; or read it all at &lt;a href="http://www.doxpara.com"&gt;http://www.doxpara.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;_physical security_&lt;br /&gt;- They explained how "bump keys" (999 keys) work. Apparently this allows you to pick even high-quality locks and advanced locks like the keso.&lt;br /&gt;The speaker gave a good demonstration by breaking a wide range of locks within mere minutes on stage (see below).Basically you cut the key with the deepest set of grooves possible (often by setting the key making machine to "9999.."). This bump key is then inserted and hit with a vibrating little hammer. This causes the bolts in the lock to shake quickly up and down, allowing for brief openings during which the key can be turned.&lt;br /&gt;See&lt;a href="http://www.gregandbeth.com/imagegallery/index.php?action=display&amp;imageID=222"&gt; http://www.gregandbeth.com/imagegallery/index.php?action=display&amp;amp;imageID=222&lt;/a&gt;&lt;br /&gt;The speaker also showed a (rather easy) attack against the Winckhaus Bluekey system. (Breaking a 250 euro lock with a 40 euro magnet).&lt;br /&gt;&lt;br /&gt;_SAP security_&lt;br /&gt;- As people want to be "on the safe side", there are often very insecure settings (i.e. chmod 777) on folders&lt;br /&gt;- look for cleartext passwords in scripts&lt;br /&gt;- look for NFS exports&lt;br /&gt;&lt;br /&gt;_phishing_&lt;br /&gt;- They showed an interesting technique that redirects the victim to the legitimate web site, but opens a pop-up window on top of that;&lt;br /&gt;the counteraction for the legitimate site owner is to open a pop-up window with the same name as the phisher's pop-up&lt;br /&gt;&lt;br /&gt;_code reviews_&lt;br /&gt;- They showed some source code from Cisco, Microsoft and MySQL that didn't look very secure. (Hard to fall asleep).&lt;br /&gt;&lt;br /&gt;_automated web site hacking (php worms)_&lt;br /&gt;- apparently quite a few people are interested in writing PHP worms that use Google now.&lt;br /&gt;- look at the tools RATS and nikto to find flaws&lt;br /&gt;&lt;br /&gt;_Sun Solaris 10_&lt;br /&gt;- Sun Solaris comes with a tool called "dtrace" that gives you a very deep view into the system. (and can allow you to read out passwords).&lt;br /&gt;- There's a new rootkit called SiNAR.&lt;br /&gt;&lt;br /&gt;__Various miscellaneous notes__&lt;br /&gt;&lt;br /&gt;Onion routing&lt;br /&gt;e.g. using TOR (&lt;a href="http://tor.eff.org/"&gt;http://tor.eff.org/&lt;/a&gt; )&lt;br /&gt;&lt;br /&gt;Infrared hacking&lt;br /&gt;look at &lt;a href="http://www.lirc.org/"&gt;http://www.lirc.org/&lt;/a&gt; and &lt;a href="http://www.irtrans.org/"&gt;http://www.irtrans.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Personal firewalls on Windows&lt;br /&gt;will always be breakable/insecure because of the low-level inter-process communication possible in Windows&lt;br /&gt;&lt;br /&gt;Fravia on searching the web&lt;br /&gt;-&gt; &lt;a href="http://www.searchlores.org/"&gt;http://www.searchlores.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;__Next major event in Europe_&lt;br /&gt;"What the hack?" - July 28-31st in the Netherlands.&lt;br /&gt;This it the bi-annual European Summer camp (HIP97, Heart-of-Gold (99), HAL2001, Fairy-Dust (03), now: WTF 05)&lt;br /&gt;&lt;a href="http://www.whatthehack.org/"&gt;http://www.whatthehack.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110475823962951403?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110475823962951403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110475823962951403' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110475823962951403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110475823962951403'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/notes-from-21c03-conference.html' title='Notes from the 21C03 conference'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110474195863809156</id><published>2005-01-03T01:45:00.000-08:00</published><updated>2005-01-03T00:45:58.636-08:00</updated><title type='text'>Secureme - a whacky new blog on the block..</title><content type='html'>I really enjoy this..&lt;br /&gt;&lt;a href="http://secureme.blogspot.com/"&gt;http://secureme.blogspot.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110474195863809156?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110474195863809156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110474195863809156' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110474195863809156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110474195863809156'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/secureme-whacky-new-blog-on-block.html' title='Secureme - a whacky new blog on the block..'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110474176850269550</id><published>2005-01-03T01:40:00.000-08:00</published><updated>2005-01-03T00:42:48.503-08:00</updated><title type='text'>OSSTMM - Open Source Security Testing Methodology Manual</title><content type='html'>&lt;br /&gt;Almost on the same topic:&lt;br /&gt;&lt;span style="font-family: arial;"&gt;ISECOM is working on the &lt;/span&gt;&lt;span style="font-family:Century Gothic;"&gt;&lt;span style="font-family: arial;"&gt;"&lt;/span&gt;&lt;a style="font-family: arial;" href="http://www.isecom.org/osstmm/"&gt;OSSTMM - Open Source Security Testing Methodology Manual&lt;/a&gt;&lt;span style="font-family: arial;"&gt;".&lt;/span&gt;&lt;br /&gt; &lt;span style="font-family: arial;"&gt;&lt;br /&gt;- A somewhat mixed bag of recipies. &lt;/span&gt;Good reading, gives insights.  But sometimes I think its labelling goes a bit over the top.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110474176850269550?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110474176850269550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110474176850269550' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110474176850269550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110474176850269550'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/osstmm-open-source-security-testing.html' title='OSSTMM - Open Source Security Testing Methodology Manual'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-110474154142282950</id><published>2005-01-03T01:35:00.000-08:00</published><updated>2005-01-03T00:39:01.423-08:00</updated><title type='text'>OISSG releases Information System Security Assessment Framework (ISSAF)</title><content type='html'>&lt;br /&gt; The &lt;a href="http://oissg.org/"&gt;OISSG&lt;/a&gt;  is working on a  &lt;span style="font-size:100%;"&gt;Information System Security Assessment Framework (ISSAF).&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;color:#000000;"&gt;A draft version of this framework is available at the OISSG website at:&lt;br /&gt;&lt;a href="http://oissg.org/issaf01/issaf0.1.zip" target="_blank"&gt;&lt;u&gt;&lt;span style="color:#0000ff;"&gt;http://oissg.org/issaf01/issaf0.1.zip&lt;/span&gt;&lt;/u&gt;&lt;/a&gt; (5.59 MB) or &lt;a href="http://oissg.org/issaf01/issaf0.1.pdf" target="_blank"&gt;&lt;u&gt;&lt;span style="color:#0000ff;"&gt;http://oissg.org/issaf01/issaf0.1.pdf&lt;/span&gt;&lt;/u&gt;&lt;/a&gt; (12.6 MB)&lt;br /&gt;&lt;br /&gt;- I had no chance to read it so far. YMMV&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-110474154142282950?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/110474154142282950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=110474154142282950' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110474154142282950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/110474154142282950'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2005/01/oissg-releases-information-system.html' title='OISSG releases Information System Security Assessment Framework (ISSAF)'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109906982833718544</id><published>2004-10-29T10:08:00.000-07:00</published><updated>2004-10-29T10:10:28.336-07:00</updated><title type='text'>Off topic: Eminem's Mosh (call to vote, not-Bush)</title><content type='html'>&lt;br /&gt;&lt;a href="http://www.gnn.tv/content/emosh_hi.html"&gt;Eminem's Mosh&lt;/a&gt; - clearly, he doesn't like Bush. =)&lt;br /&gt;Loosely related  &lt;a href="http://www.coxar.pwp.blueyonder.co.uk/"&gt;weapons of mass destruction&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109906982833718544?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109906982833718544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109906982833718544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109906982833718544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109906982833718544'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/off-topic-eminems-mosh-call-to-vote.html' title='Off topic: Eminem&apos;s Mosh (call to vote, not-Bush)'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109906355392963485</id><published>2004-10-29T08:22:00.000-07:00</published><updated>2004-10-29T08:25:53.930-07:00</updated><title type='text'>Competitive Hacking </title><content type='html'>&lt;br /&gt;Getloaded vs. Truckstop - tale of one company scraping data of another company's business portal site.&lt;br /&gt;Mostly by posing as a subscriber or re-using (userID, passwords)  pair.&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.theregister.co.uk/2004/10/26/competitive_hacking/"&gt;http://www.theregister.co.uk/2004/10/26/competitive_hacking/&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109906355392963485?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109906355392963485/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109906355392963485' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109906355392963485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109906355392963485'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/competitive-hacking.html' title='Competitive Hacking '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109888818215676101</id><published>2004-10-27T07:41:00.000-07:00</published><updated>2004-10-27T07:43:02.156-07:00</updated><title type='text'>Sardonix - source code auditing </title><content type='html'>&lt;br /&gt;Good site, good links, good stuff: &lt;a href="http://sardonix.org/Auditing_Resources.html"&gt;http://sardonix.org/Auditing_Resources.html&lt;/a&gt;&lt;br /&gt;And &lt;a href="http://www.cse.ogi.edu/%7Ecrispin/"&gt;Crispin Cowan&lt;/a&gt; is involved in it.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109888818215676101?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109888818215676101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109888818215676101' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109888818215676101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109888818215676101'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/sardonix-source-code-auditing.html' title='Sardonix - source code auditing '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109888808278305191</id><published>2004-10-27T07:38:00.000-07:00</published><updated>2004-10-27T07:41:22.783-07:00</updated><title type='text'>Criminals making money off DDoS threats</title><content type='html'>&lt;br /&gt;This &lt;a href="http://story.news.yahoo.com/news?tmpl=story&amp;cid=2026&amp;amp;ncid=2026&amp;e=4&amp;amp;u=/latimests/20041025/ts_latimes/deletingonlineextortion"&gt;article&lt;/a&gt; gives some detail on the actual extortions going on. Internet casinos and bookies are threatened by criminals operating bot nets. It also gives some idea on the money involved - and it has suspense, heros and  a good ending,&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109888808278305191?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109888808278305191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109888808278305191' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109888808278305191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109888808278305191'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/criminals-making-money-off-ddos.html' title='Criminals making money off DDoS threats'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109873954550481949</id><published>2004-10-25T14:23:00.000-07:00</published><updated>2004-10-25T14:27:32.806-07:00</updated><title type='text'>The World Bank Technology Risk Checklist</title><content type='html'>&lt;br /&gt;For what it's worth. From a cissp-forum posting by Gideon T. Rasmussen:&lt;br /&gt;&lt;br /&gt;"The World Bank Technology Risk Checklist is designed to provide Chief&lt;br /&gt;Information Security Officers (CISO), Chief Technology&lt;br /&gt;Officers (CTO), Chief Financial Officers (CFO), Directors, Risk Managers&lt;br /&gt;and Systems Administrators with a way of measuring and validating the&lt;br /&gt;level of security within a particular organization."&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.infragard.net/library/pdfs/technologyrisklist.pdf" target="_blank"&gt;&lt;br /&gt;http://www.infragard.net&lt;wbr&gt;/library/pdfs/technologyriskli&lt;wbr&gt;st.pdf&lt;/a&gt;&lt;a href="http://www.infragard.net/library/pdfs/technologyrisklist.pdf"&gt; &lt;/a&gt;(31 pages)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109873954550481949?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109873954550481949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109873954550481949' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109873954550481949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109873954550481949'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/world-bank-technology-risk-checklist.html' title='The World Bank Technology Risk Checklist'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109872737992564429</id><published>2004-10-25T10:55:00.000-07:00</published><updated>2004-10-25T11:02:59.926-07:00</updated><title type='text'>Linkedin - a social network service</title><content type='html'>Today I discovered Linkedin ( &lt;a href="http://www.linkedin.com/"&gt;http://www.linkedin.com/ &lt;/a&gt;). Similar to OpenBC, Orkut and Friendster it gives you a platform to network. - While I'm still convinced that it takes beer, wine or hardship to really get to know people, I think it's a good service to get to that point.&lt;br /&gt;(- Has anyone a free Orkut invite? =)  )&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109872737992564429?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109872737992564429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109872737992564429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109872737992564429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109872737992564429'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/linkedin-social-network-service.html' title='Linkedin - a social network service'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109825705811436623</id><published>2004-10-20T01:22:00.000-07:00</published><updated>2004-10-20T00:24:18.113-07:00</updated><title type='text'>Directory of Open Access Journals</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109825705811436623?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.doaj.org/' title='Directory of Open Access Journals'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109825705811436623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109825705811436623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109825705811436623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109825705811436623'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/directory-of-open-access-journals.html' title='Directory of Open Access Journals'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109808468537212056</id><published>2004-10-18T01:28:00.000-07:00</published><updated>2004-10-18T00:31:25.373-07:00</updated><title type='text'>FG SecMgt in the Gesellschaft für Informatik e.V.</title><content type='html'>&lt;br /&gt;I'm a member of the FG SecMgt in the FB Sicherheit of the German "Gesellschaft für Informatik e.V.". If your German is good, it's a good place to meet peers and enjoy fruitful discussions. The web site has also some good presentations from past events... (meets 2-3 times a year, low volume mailing list)&lt;br /&gt;&lt;a href="http://www.gi-fb-sicherheit.de/fg/secmgt/index.html"&gt;http://www.gi-fb-sicherheit.de/fg/secmgt/index.html&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109808468537212056?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109808468537212056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109808468537212056' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109808468537212056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109808468537212056'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/fg-secmgt-in-gesellschaft-fr.html' title='FG SecMgt in the Gesellschaft für Informatik e.V.'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109751357601858670</id><published>2004-10-11T09:49:00.000-07:00</published><updated>2004-10-11T09:52:56.020-07:00</updated><title type='text'>Unicornscan</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109751357601858670?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.dyadsecurity.com/s_unicornscan.html' title='Unicornscan'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109751357601858670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109751357601858670' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109751357601858670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109751357601858670'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/10/unicornscan.html' title='Unicornscan'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109558834378529099</id><published>2004-09-19T02:59:00.000-07:00</published><updated>2004-09-19T03:35:14.626-07:00</updated><title type='text'>Bassajew and costs of terror attacks</title><content type='html'>&lt;br /&gt;I heard on the car radio the other day that Bassajew gave numbers on how much the recent terror attacks in Russia and Beslan did cost him. I remember something like 9,600 USD for the Beslan terror attack (in which terrorists took pupils, teachers and parents hostage) and something like 7,000 USD and 4,000 USD for the suicide bombing in Moscow and the bombings of two Russian passenger planes.&lt;br /&gt;Here are some links:&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;&lt;a href="http://www.mosnews.com/news/2004/09/17/chechenrebel.shtml"&gt;http://www.mosnews.com/news/2004/09/17/chechenrebel.shtml&lt;/a&gt;&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.rferl.org/featuresarticle/2004/9/427B2C89-948D-4B8E-B9E7-15C3D7858C1D.html"&gt;an article on Radio Free Europe&lt;/a&gt;&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.nzherald.co.nz/storydisplay.cfm?storyID=3592536&amp;thesection=news&amp;amp;amp;amp;thesubsection=world"&gt;an article  from a site in New Zealand&lt;/a&gt; &lt;/li&gt; &lt;/ul&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109558834378529099?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109558834378529099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109558834378529099' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109558834378529099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109558834378529099'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/bassajew-and-costs-of-terror-attacks.html' title='Bassajew and costs of terror attacks'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109558512827959071</id><published>2004-09-19T02:10:00.000-07:00</published><updated>2004-09-19T02:12:08.280-07:00</updated><title type='text'>Nur allzuwahr.. IT-Sicherheitsbeauftragter im c't Kartoon..</title><content type='html'>&lt;br /&gt; in German  ;-) &lt;a href="http://www.heise.de/ct/schlagseite/04/20/"&gt;http://www.heise.de/ct/schlagseite/04/20/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109558512827959071?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109558512827959071/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109558512827959071' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109558512827959071'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109558512827959071'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/nur-allzuwahr-it-sicherheitsbeauftragt.html' title='Nur allzuwahr.. IT-Sicherheitsbeauftragter im c&apos;t Kartoon..'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109557735180935679</id><published>2004-09-18T23:57:00.000-07:00</published><updated>2004-09-19T02:16:52.720-07:00</updated><title type='text'>M$ Windows XP Professional Bugging Device?</title><content type='html'>&lt;br /&gt;Cccure has a list of 47 spots in Microsoft XP Professional that the anonymous author of that document thinks are cases of possible concern. (PARANOIA! on/off) - or maybe I'd say are "paranoia entry points"?&lt;br /&gt;&lt;a href="http://www.cccure.org/modules.php?name=News&amp;file=article&amp;amp;sid=591"&gt;http://www.cccure.org/modules.php?name=News&amp;file=article&amp;amp;sid=591&lt;/a&gt;&lt;br /&gt;- While I think that most of them are quite irrelevant, it's probably not bad to adjust/verify personal paranoia levels on a Sunday morning..&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109557735180935679?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109557735180935679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109557735180935679' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109557735180935679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109557735180935679'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/m-windows-xp-professional-bugging.html' title='M$ Windows XP Professional Bugging Device?'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109552637467731146</id><published>2004-09-18T09:51:00.000-07:00</published><updated>2004-09-18T09:52:54.676-07:00</updated><title type='text'>(in Germany:) The legal obligations and the responsibilities in case</title><content type='html'>&lt;pre wrap=""&gt;&lt;br /&gt;From a posting by Bodo Hoffmann to cissp-ffm:&lt;br /&gt;(in German)&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.surfcontrol.com/general/guides/SurfControl_RechtlicherLeitfaden.pdf"&gt;http://www.surfcontrol.com/general/guides/SurfControl_RechtlicherLeitfaden.pdf&lt;/a&gt;&lt;/pre&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109552637467731146?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109552637467731146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109552637467731146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109552637467731146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109552637467731146'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/in-germany-legal-obligations-and.html' title='(in Germany:) The legal obligations and the responsibilities in case'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109540612990929356</id><published>2004-09-17T01:27:00.000-07:00</published><updated>2004-09-17T00:28:49.910-07:00</updated><title type='text'>A visual history of spam (and virus) email</title><content type='html'>&lt;br /&gt;..from the blog of Raymond Chen (who  has kept every single piece of spam and virus email since mid-1997). &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109540612990929356?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://weblogs.asp.net/oldnewthing/archive/2004/09/16/230388.aspx' title='A visual history of spam (and virus) email'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109540612990929356/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109540612990929356' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109540612990929356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109540612990929356'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/visual-history-of-spam-and-virus-email.html' title='A visual history of spam (and virus) email'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109540408882649546</id><published>2004-09-16T23:49:00.000-07:00</published><updated>2004-09-16T23:57:40.236-07:00</updated><title type='text'>German IT agency sets record straight on IE</title><content type='html'>&lt;br /&gt; There has been some noise after the &lt;a href="http://www.bsi.de/"&gt;German Information Security Agency&lt;/a&gt; (BSI) apparently hinted that using a non-Microsoft web browser might give you less security headaches. NetworkFusion is covering the current state (and some clarifications by the BSI) in an article called "&lt;a href="http://www.nwfusion.com/news/2004/0916germaitag.html?fsrc=rss-security"&gt;German IT agency sets record straight on IE&lt;/a&gt;".&lt;br /&gt;- As you could expect, the BSI is choosing some less harsh language.&lt;br /&gt;The most interesting quote from it is: "&lt;span style="color: rgb(0, 102, 0);"&gt;Microsoft has responded to the developments by offering discounts to the country's vast public sector and agreeing to provide special assistance with software security.&lt;/span&gt;"&lt;br /&gt;Now - if I were the IT security agency chief of any country, wouldn't I just copy&amp;amp;paste the original BSI statements?? (and gain a hefty discount plus MS security consultancy package for my people??)&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109540408882649546?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109540408882649546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109540408882649546' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109540408882649546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109540408882649546'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/german-it-agency-sets-record-straight.html' title='German IT agency sets record straight on IE'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109536695950995238</id><published>2004-09-16T13:33:00.000-07:00</published><updated>2004-09-16T13:35:59.510-07:00</updated><title type='text'>	Minimization of network services on Windows systems </title><content type='html'>&lt;br /&gt; Very interesting reading. - I found it at the &lt;a href="http://taosecurity.blogspot.com/2004_09_01_taosecurity_archive.html#109535984675962616"&gt;TAO security blog , that also has a nice summary&lt;/a&gt;.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109536695950995238?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.hsc.fr/ressources/breves/min_srv_res_win.en.html' title='&#x9;Minimization of network services on Windows systems '/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109536695950995238/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109536695950995238' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109536695950995238'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109536695950995238'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/minimization-of-network-services-on.html' title='&#x9;Minimization of network services on Windows systems '/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109531953603625323</id><published>2004-09-16T01:20:00.000-07:00</published><updated>2004-09-16T23:48:58.596-07:00</updated><title type='text'>The CISSP secret hand shake</title><content type='html'>&lt;br /&gt; For all who have wondered - there is indeed a secret handshake to recognize fellow CISSPs.&lt;br /&gt;From a post by Mark Lachniet to cissp-forum (a high profile, highly professional closed list):&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;"It's just like the gangster handshake&lt;br /&gt;- fist (above),&lt;br /&gt;fist (below),&lt;br /&gt;fist&lt;/span&gt;&lt;span style="color: rgb(0, 0, 153);"&gt; horizontal.&lt;br /&gt;Then you say "wondertwin powers activate - shape of a &lt;span id="st" name="st" class="st0"&gt;risk &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;&lt;span id="st" name="st" class="st0"&gt;assessment&lt;/span&gt; methodology"  and "shape of a properly configured and managed &lt;/span&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;IDS system"&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;From personal experience, you are supposed to order beers right after saying this...&lt;br /&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109531953603625323?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109531953603625323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109531953603625323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109531953603625323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109531953603625323'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/cissp-secret-hand-shake.html' title='The CISSP secret hand shake'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109526181877820615</id><published>2004-09-15T08:20:00.000-07:00</published><updated>2004-09-16T00:19:37.813-07:00</updated><title type='text'>"Gmail-is-too-creepy"</title><content type='html'>&lt;br /&gt;&lt;a href="http://gmail-is-too-creepy.com/"&gt; http://gmail-is-too-creepy.com/&lt;/a&gt;&lt;br /&gt;for what it's worth. I haven't checked the allegations made at the link above, so take them with a grain of salt.&lt;br /&gt;Also, &lt;a href="http://www.gmx.de/"&gt;http://www.gmx.de/&lt;/a&gt; has largely increased it's free webmail quota to 1 GB, see &lt;a href="http://www.gmx.net/de/produkte/mail/freemail/index.html"&gt;here&lt;/a&gt;.&lt;br /&gt;- Gmail is Google's mail service.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109526181877820615?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://gmail-is-too-creepy.com/' title='&quot;Gmail-is-too-creepy&quot;'/><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109526181877820615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109526181877820615' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109526181877820615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109526181877820615'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/gmail-is-too-creepy.html' title='&quot;Gmail-is-too-creepy&quot;'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109509642919913611</id><published>2004-09-13T10:14:00.000-07:00</published><updated>2004-09-13T10:27:09.200-07:00</updated><title type='text'>TAMU 1999 Bonfire Disaster - a management tale on why proactive risk management matters</title><content type='html'>&lt;br /&gt;&lt;a href="http://www.tamu.edu/"&gt;Texas A&amp;M&lt;/a&gt; - or "Aggieland" - is a rather well-known US university with a (military-style pre-) "school of cadets". It's home of the George Bush Presidential Library, very close to the Bush's family ranch and a somewhat peculiar place. I spent quite some time in and around campus in '93-'96.&lt;br /&gt;Texas A&amp;amp;M is well-known for its football team, its inherent despise for the Univerity of Texas (at Austin) and the "team spirit" of its students and honored traditions.&lt;br /&gt;Up to 1999 one of the key traditions was the annual Bonfire - which developed into a major three-story construction. - I always had the feeling that more wood was burned in that fire, than was used as paper at that place.&lt;br /&gt;&lt;br /&gt;In 1999, the bonfire collapsed killing several people. The university was pressured to launch an in-depth investigation, which came up with quite shocking findings.&lt;br /&gt;&lt;br /&gt;See: &lt;a href="http://www.tamu.edu/bonfire-commission/reports/"&gt;http://www.tamu.edu/bonfire-commission/reports/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I think this is a really good story that demonstrates just how important a pro-active risk management is.&lt;br /&gt;&lt;br /&gt;Some quotes from the&lt;a href="http://www.tamu.edu/bonfire-commission/reports/Final.pdf"&gt; final report&lt;/a&gt;:&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;Lack of a written Bonfire design or construction methodology is in the Commission’s view both an important barrier failure and very relevant to  the collapse. This deficiency has resulted in multiple design changes  year-to-year, no established process for design reviews, and no  documentation of critical design factors. This was clearly evidenced in  interviews with University officials and students. On numerous  occasions, interviewees described a world in which design decisions were  made with no written guidance, no formal reviews, and no knowledge of  critical design factors. &lt;/span&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109509642919913611?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109509642919913611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109509642919913611' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109509642919913611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109509642919913611'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/tamu-1999-bonfire-disaster-management.html' title='TAMU 1999 Bonfire Disaster - a management tale on why proactive risk management matters'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109489212798457464</id><published>2004-09-11T01:40:00.000-07:00</published><updated>2004-09-11T01:43:02.590-07:00</updated><title type='text'>Breach! Breach! - http://www.ratemynetworkdiagram.com</title><content type='html'>&lt;br /&gt;This is a strange site: &lt;a href="http://www.ratemynetworkdiagram.com/"&gt;http://www.ratemynetworkdiagram.com/&lt;/a&gt;&lt;br /&gt;I wonder just who's putting stuff up there - and what is it for?&lt;br /&gt;- A honeypot for the dim-witted?&lt;br /&gt;Or some dating site for nerds? =)))&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109489212798457464?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109489212798457464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109489212798457464' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109489212798457464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109489212798457464'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/09/breach-breach-httpwwwratemynetworkdiag.html' title='Breach! Breach! - http://www.ratemynetworkdiagram.com'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109370902534165310</id><published>2004-08-28T09:03:00.000-07:00</published><updated>2004-08-28T09:03:45.340-07:00</updated><title type='text'>DRAFT NIST Special Publication 800-72, Guidelines on PDA Forensics</title><content type='html'>&lt;br /&gt;&lt;br /&gt; Yep, NIST has now a draft guideline for PDA forensics.. =)&lt;br /&gt;&lt;a href="http://csrc.nist.gov/publications/drafts.html#sp800-72"&gt;http://csrc.nist.gov/publications/drafts.html#sp800-72&lt;/a&gt;&lt;br /&gt;- good  stuff, although points out the insecurities within Palm OS.. =((&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109370902534165310?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109370902534165310/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109370902534165310' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109370902534165310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109370902534165310'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/08/draft-nist-special-publication-800-72.html' title='DRAFT NIST Special Publication 800-72, Guidelines on PDA Forensics'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6027147.post-109370859363217437</id><published>2004-08-28T08:54:00.000-07:00</published><updated>2004-08-28T08:58:13.123-07:00</updated><title type='text'>Reverse (SSH) shells</title><content type='html'>&lt;br /&gt;I know that reverse shells are used by trojans for ages.&lt;br /&gt;&lt;a href="http://www.brandonhutchinson.com/ssh_tunnelling.html"&gt;http://www.brandonhutchinson.com/ssh_tunnelling.html &lt;/a&gt;&lt;br /&gt;has a handy description of this is configured with standard openSSH.&lt;br /&gt;READ: How do I get to log in on machine A from home with SSH, by making A connect to me (rather vice versa).&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6027147-109370859363217437?l=reflectorium.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://reflectorium.blogspot.com/feeds/109370859363217437/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6027147&amp;postID=109370859363217437' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109370859363217437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6027147/posts/default/109370859363217437'/><link rel='alternate' type='text/html' href='http://reflectorium.blogspot.com/2004/08/reverse-ssh-shells.html' title='Reverse (SSH) shells'/><author><name>Stefan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
