<?xml version="1.0" encoding="utf-8"?>
<!-- generator="wordpress/1.5.1-alpha" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
>

<channel>
	<title>thrtcl spr-mstrbtn!</title>
	<link>http://negative.blogsome.com</link>
	<description>Mstrbtn tchnqs shld b ncrgd nd tght n the pblc schl systms!</description>
	<pubDate>Sat, 22 Oct 2005 23:32:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=1.5.1-alpha</generator>
	<language>en</language>

		<item>
		<title>Bye</title>
		<link>http://negative.blogsome.com/2005/04/07/bye/</link>
		<comments>http://negative.blogsome.com/2005/04/07/bye/#comments</comments>
		<pubDate>Thu, 07 Apr 2005 16:18:37 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/04/07/bye/</guid>
		<description><![CDATA[	I&#8217;m done with this blog. The archive will stay here for other purpose.
	It doesn&#8217;t mean that I hate blog. I just don&#8217;t like the way it handles my articles. Wiki is good to fill my needs.
	Will redirect you to my other page in 5 seconds. Or&#8230; just go to http://jim.geovedi.com/
]]></description>
			<content:encoded><![CDATA[	<p>I&#8217;m done with this blog. The archive will stay here for other purpose.</p>
	<p>It doesn&#8217;t mean that I hate blog. I just don&#8217;t like the way it handles my articles. Wiki is good to fill my needs.</p>
	<p>Will redirect you to my other page in 5 seconds. Or&#8230; just go to <a href="http://jim.geovedi.com/">http://jim.geovedi.com/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/04/07/bye/feed/</wfw:commentRss>
	</item>
		<item>
		<title>awexpl strikes</title>
		<link>http://negative.blogsome.com/2005/02/14/awexpl-strikes/</link>
		<comments>http://negative.blogsome.com/2005/02/14/awexpl-strikes/#comments</comments>
		<pubDate>Mon, 14 Feb 2005 06:53:17 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/02/14/awexpl-strikes/</guid>
		<description><![CDATA[	Just came back from holiday and reviewed apache logfile on my homeserver, I noticed that there are some wacky lines in access_log:
	200.217.***.*** - - [11/Feb/2005:15:47:15 +0700]
"GET /cgi-bin/awstats.pl?configdir=|echo%20;
echo%20;id;echo%20;echo| HTTP/1.0" 404 287
200.217.***.*** - - [11/Feb/2005:15:47:45 +0700]
"GET /awstats/awstats.pl?configdir=|echo%20;
echo%20;id;echo%20;echo| HTTP/1.0" 404 287
	After 2 minutes googling, I found a reference to the AWSTATS exploit. Looks like versions of awstats 6.2 [...]]]></description>
			<content:encoded><![CDATA[	<p>Just came back from holiday and reviewed apache logfile on my homeserver, I noticed that there are some wacky lines in <tt>access_log</tt>:</p>
	<p><code>200.217.***.*** - - [11/Feb/2005:15:47:15 +0700]<br />
"GET /cgi-bin/awstats.pl?configdir=|echo%20;<br />
echo%20;id;echo%20;echo| HTTP/1.0" 404 287</code><br />
<code>200.217.***.*** - - [11/Feb/2005:15:47:45 +0700]<br />
"GET /awstats/awstats.pl?configdir=|echo%20;<br />
echo%20;id;echo%20;echo| HTTP/1.0" 404 287</code></p>
	<p>After 2 minutes <a href="http://www.google.com/search?hl=en&#038;lr=&#038;client=firefox-a&#038;rls=org.mozilla%3Aen-US%3Aofficial&#038;q=inurl%3A+awstats.pl%3Fconfigdir%3D&#038;btnG=Search">googling</a>, I found a reference to the <a href="http://www.k-otik.com/exploits/20050124.awexpl.c.php">AWSTATS exploit</a>. Looks like versions of awstats 6.2 and lower are vulnerable, version 6.3 has the fix.</p>
	<p>More googling results mention that <a href="http://zone-h.org/en/defacements/filter/filter_defacer=Infektion+Group/">Infecktion Group</a> claimed credit for many web defacements related to this awstats vulnerability and has reported over <a href="http://www.internetnews.com/security/article.php/3467571">400 such defacements</a>, though it is unclear how many and whether the same attack vector was utilized.</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/02/14/awexpl-strikes/feed/</wfw:commentRss>
	</item>
		<item>
		<title>Google getting smarter</title>
		<link>http://negative.blogsome.com/2005/02/05/google_smart/</link>
		<comments>http://negative.blogsome.com/2005/02/05/google_smart/#comments</comments>
		<pubDate>Sat, 05 Feb 2005 04:16:50 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/02/05/google_smart/</guid>
		<description><![CDATA[	Probably due to Santy worm, Google filtering some keywords.
	
	But, it seems that Google guys are just searching for predefined strings&#8230;not so smart!  inurl: admin.php [Blocked], inurl: admin.PHP [Pass], inurl:&#8221;admin php&#8221; [Pass], anything different than .php (for example: .pHp) will work..

]]></description>
			<content:encoded><![CDATA[	<p>Probably due to <a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PERL_SANTY.D">Santy worm</a>, Google filtering some keywords.</p>
	<p><a href="http://negative.blogsome.com/uploads/negative/google_403.png"><img src="http://negative.blogsome.com/uploads/negative/google_403.png" alt="Google getting smarter" width="400"/></a></p>
	<p>But, it seems that Google guys are just searching for predefined strings&#8230;not so smart!  <a href="http://www.google.com/search?q=inurl%3A+admin.php">inurl: admin.php</a> <b>[Blocked]</b>, <a href="http://www.google.com/search?q=inurl%3A+admin.php">inurl: admin.PHP</a> <b>[Pass]</b>, <a href="http://www.google.com/search?q=inurl%3A+%22admin+php%22">inurl:&#8221;admin php&#8221;</a> <b>[Pass]</b>, anything different than .php (for example: .pHp) will work..
</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/02/05/google_smart/feed/</wfw:commentRss>
<enclosure url='http://negative.blogsome.com/uploads/negative/google_403.png' length='24164' type='image/png'/>
<enclosure url='http://negative.blogsome.com/uploads/negative/google_403.png' length='24164' type='image/png'/>
	</item>
		<item>
		<title>German court rules email blocking &#8216;illegal&#8217;</title>
		<link>http://negative.blogsome.com/2005/01/20/german_email_blocking/</link>
		<comments>http://negative.blogsome.com/2005/01/20/german_email_blocking/#comments</comments>
		<pubDate>Thu, 20 Jan 2005 11:13:10 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/20/german_email_blocking/</guid>
		<description><![CDATA[	The Higher Regional Court now has ruled that blocking email by content is unlawful as it is considered confidential in German law. Blocking is only allowed when, say, a viral attack is imminent. The implications of the ruling aren&#8217;t yet fully clear. Whether the Higher Regional Court has unintentionally legalised spam (which frequently is filtered [...]]]></description>
			<content:encoded><![CDATA[	<p>The Higher Regional Court now has <a href="http://www.olg-karlsruhe.de/html/presse/2005/ausfiltern%20von%20e-mails%20ist%20strafbar.htm">ruled</a> that blocking email by content is unlawful as it is considered confidential in German law. Blocking is only allowed when, say, a viral attack is imminent. The implications of the ruling aren&#8217;t yet fully clear. Whether the Higher Regional Court has unintentionally legalised spam (which frequently is filtered by content) remains to be seen.
</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/20/german_email_blocking/feed/</wfw:commentRss>
	</item>
		<item>
		<title>Valdis Kletnieks: Writing Secure Code</title>
		<link>http://negative.blogsome.com/2005/01/20/writing_secure_code/</link>
		<comments>http://negative.blogsome.com/2005/01/20/writing_secure_code/#comments</comments>
		<pubDate>Thu, 20 Jan 2005 10:35:14 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/20/writing_secure_code/</guid>
		<description><![CDATA[	
On Tue, 18 Jan 2005 14:31:39 EST, &#8220;Sigmon Cheri Y Civ 82 CSS/SCPD :: Software Dev&#8221; said:
	Item: The &#8220;ongoing&#8221; debate among choices of open source vs. proprietary (all companies&#8217;) solutions, not just the major players in the industry. 
	I&#8217;m certain you&#8217;ve seen similar situations&#8230; where there are groups of people who are very opinionated one [...]]]></description>
			<content:encoded><![CDATA[	<blockquote><p>
<b>On Tue, 18 Jan 2005 14:31:39 EST, &#8220;Sigmon Cheri Y Civ 82 CSS/SCPD :: Software Dev&#8221; said:</b></p>
	<p>Item: The &#8220;ongoing&#8221; debate among choices of open source vs. proprietary (all companies&#8217;) solutions, not just the major players in the industry. </p>
	<p>I&#8217;m certain you&#8217;ve seen similar situations&#8230; where there are groups of people who are very opinionated one way or the other. My concern is the best solution(s) security-wise, regardless of the source. Any comments?  From a broad-brush perspective?
</p></blockquote>
	<p>Define &#8220;best&#8221;.</p>
	<p>Most secure, no matter *how* hard it is to use?  There&#8217;s some pretty bad-ass MLS systems available - and they&#8217;re often a royal pain to *do* anything (because you keep finding you can&#8217;t easily get around some compartmentalization feature that&#8217;s intentionally getting in your way).  This one&#8217;s easy. Turn it off, encase it in a large concrete block, and dump it into the Marianas Trench.  Quite secure, but not very useful. (Apply some thermite along the way if you&#8217;re *really* paranoid).<br />
.<br />
:<br />
Remember that security is a process, and a balancing act.  Let&#8217;s say your security budget is S, the cost of an incident is C, and the likelyhood of an incident is P.  If you can make S = C*P, you have perfect security (if S is greater, you&#8217;re spending too much, and if S is lower, you could still save money by increasing S).  Those of you who want to model multiple events and costs can generalize it to a summation across all C(sub n)*P(sub n).  </p>
	<p>The really mathematically astute will realize that (a) if you&#8217;re bothering with the summation, the function quite possibly has multiple local maximums and minimums, and (b) the exact location and value of said inflection points of the curve depend on coefficients that are basically non-measurable, and you&#8217;re left making educated guesses (&#8221;What&#8217;s the % chance per year of compromise of a fully patched Windows box with an idiot user, and the %chance for a box that&#8217;s missing some patches, but has a user who doesn&#8217;t click on every &#8220;ooh shiny?&#8221; and the ever-favorite &#8220;What&#8217;s the least costly (money, people time, political brownie points) way to convince a particular Very Important Butthead to buy in to a specific proposal, or should we just punt and do things some way that V. Butthead will go along with?&#8221;)<br />
.<br />
:<br />
Read more at <a href="http://www.securityfocus.com/archive/98/387715/2005-01-17/2005-01-23/0">SecProg@SecurityFocus.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/20/writing_secure_code/feed/</wfw:commentRss>
	</item>
		<item>
		<title>Honey, Where&#8217;s My Jump Bag?</title>
		<link>http://negative.blogsome.com/2005/01/20/jump_bag/</link>
		<comments>http://negative.blogsome.com/2005/01/20/jump_bag/#comments</comments>
		<pubDate>Thu, 20 Jan 2005 07:19:19 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/20/jump_bag/</guid>
		<description><![CDATA[	[Sidebar: Fill Your Jump Bag]
	A &#8220;jump bag&#8221; is a collection of critical items you might need during crisis response when an attacker invades your network. It should contain these items:
	
Tape recorder or minidisk

	Backup media
	Binary backup software
	CDs with statically linked binaries of critical OS executables
	Forensic software
	Windows NT and 2000 resource kits
	Bootable CD-ROMs
	USB token memory device
	External hard [...]]]></description>
			<content:encoded><![CDATA[	<p>[<a href="http://www.computerworld.com/securitytopics/security/story/0,10801,98913,00.html">Sidebar: Fill Your Jump Bag</a>]</p>
	<p>A &#8220;jump bag&#8221; is a collection of critical items you might need during crisis response when an attacker invades your network. It should contain these items:</p>
	<ul>
<li>Tape recorder or minidisk
</li>
	<li>Backup media</li>
	<li>Binary backup software</li>
	<li>CDs with statically linked binaries of critical OS executables</li>
	<li>Forensic software</li>
	<li>Windows NT and 2000 resource kits</li>
	<li>Bootable CD-ROMs</li>
	<li>USB token memory device</li>
	<li>External hard drive</li>
	<li>Small hub</li>
	<li>Patch cables</li>
	<li>Laptop with dual operating system capability</li>
	<li>Call list and cell phone</li>
	<li>Plastic baggies for handling evidence</li>
	<li>Extra notebooks for taking notes</li>
</ul>
	<p>A jump bag is not only needed when an attacker invades my network but for any critical situation &#8212; for example, when one partition in my fiance&#8217;s hard drive crashed few days ago and she has many imporant data for almost 18GB. </p>
	<p>At that time, I have no tools in hand, so approx. I took 3 hours to recovery the data (~45 minutes spent to search the proper recovery software). After that incident, I realize how important having a jump bag and thinking to have one near future.
</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/20/jump_bag/feed/</wfw:commentRss>
	</item>
		<item>
		<title>NUKIDO: Various Local Vulnerabilities in Mac OS X  10.3.x</title>
		<link>http://negative.blogsome.com/2005/01/19/nukido/</link>
		<comments>http://negative.blogsome.com/2005/01/19/nukido/#comments</comments>
		<pubDate>Wed, 19 Jan 2005 04:20:33 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/19/nukido/</guid>
		<description><![CDATA[	Several kernel level bounds checking vulnerabilities were found during an audit performed by Immunity team on the recent Darwin kernel xnu­517.7.7.  These vulnerabilities are mostly in user to kernel memory copy operations and also allocation of kernel memory driven by user supplied size value(s). 
	Well, they also put the an interersting bug on at(1). [...]]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.immunitysec.com/downloads/nukido.pdf">Several kernel level bounds checking vulnerabilities</a> were found during an audit performed by <a href="http://www.immunitysec.com/">Immunity</a> team on the recent Darwin kernel xnu­517.7.7.  These vulnerabilities are mostly in user to kernel memory copy operations and also allocation of kernel memory driven by user supplied size value(s). </p>
	<p>Well, they also put the an interersting bug on <tt>at(1)</tt>. Actually, i still wondering how someone can use the advantage of <tt>/etc/master.passwd</tt> in multi-user mode. The  <tt>/etc/master.passwd</tt> is consulted when the system is running in single-user mode. At other times this information is handled by <tt>lookupd</tt>.  By default, <tt>lookupd</tt> gets information from <tt>NetInfo</tt>, so this file will not be consulted unless someone have changed <tt>lookupd</tt>&#8217;s configuration.</p>
	<p>BTW, Mac OS X 10.3.7 is still using buggy version of <a href="http://sudo.ws/">sudo</a>. Last week I received a mail reply from <a href="http://www.apple.com/support/security/">Apple Product Security Team</a>, they said my information has been passed along to their engineering team for further analysis.
</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/19/nukido/feed/</wfw:commentRss>
	</item>
		<item>
		<title>BS7799 Lead Auditor Course</title>
		<link>http://negative.blogsome.com/2005/01/10/bs7799_course/</link>
		<comments>http://negative.blogsome.com/2005/01/10/bs7799_course/#comments</comments>
		<pubDate>Mon, 10 Jan 2005 09:31:05 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/10/bs7799_course/</guid>
		<description><![CDATA[	Starting today until January 14, 2005, I&#8217;ll be in BS7799 Lead Auditor Course organized by Bellua &#8212; in association with Bureau Veritas, at Gran Melia Hotel, Jakarta. The course is intended for all those who wish to undertake and eventually lead audits of Information Security Management Systems. It is also useful for those interested in [...]]]></description>
			<content:encoded><![CDATA[	<p>Starting today until January 14, 2005, I&#8217;ll be in <a href="http://www.bellua.com/bcs2005/bs7799.index.html">BS7799 Lead Auditor Course</a> organized by <a href="http://www.bellua.com">Bellua</a> &#8212; in association with <a href="http://www.bureauveritas.com/">Bureau Veritas</a>, at <a href="http://www.granmeliajakarta.com/">Gran Melia Hotel</a>, Jakarta. The course is intended for all those who wish to undertake and eventually lead audits of Information Security Management Systems. It is also useful for those interested in implementation of BS7799. It is essential for those wishing to register with IRCA as an <acronym title"Information Security Management System">ISMS</acronym> Auditor.
</p>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/10/bs7799_course/feed/</wfw:commentRss>
	</item>
		<item>
		<title>Honeynet Project Report: Trend Analysis</title>
		<link>http://negative.blogsome.com/2005/01/07/honeynet_trend_analysis/</link>
		<comments>http://negative.blogsome.com/2005/01/07/honeynet_trend_analysis/#comments</comments>
		<pubDate>Fri, 07 Jan 2005 07:16:42 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/07/honeynet_trend_analysis/</guid>
		<description><![CDATA[	Honeynet Project just released a report about the security of Linux. The life expectancy of Linux has lengthened dramatically since 2001 and 2002, the project said, from a mere 72 hours two and three years ago to an average of three months today. 
	Why? There are several explanations for that:

Default installation of Linux distributions are [...]]]></description>
			<content:encoded><![CDATA[	<p><a href="http://www.honeynet.org/">Honeynet Project</a> just released a <a href="http://www.honeynet.org/papers/trends/life-linux.pdf">report</a> about the security of Linux. The life expectancy of Linux has lengthened dramatically since 2001 and 2002, the project said, from a mere 72 hours two and three years ago to an average of three months today. </p>
	<p>Why? There are several explanations for that:
<ol>
<li>Default installation of Linux distributions are becoming harder to compromise.</li>
	<li>The primary threat is changing from machine-focused to human-focused.</li>
	<li>Based purely on economies of scale, attackers are targeting Win32 based system and their users.</li>
	<li>Windows, through piracy and low-cost ditributions in developing countries (such as China), has increased market penetration.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/07/honeynet_trend_analysis/feed/</wfw:commentRss>
	</item>
		<item>
		<title>Tsunami email scams</title>
		<link>http://negative.blogsome.com/2005/01/07/tsunami-email-scams/</link>
		<comments>http://negative.blogsome.com/2005/01/07/tsunami-email-scams/#comments</comments>
		<pubDate>Fri, 07 Jan 2005 06:37:44 +0000</pubDate>
		<dc:creator>Administrator</dc:creator>
		
	<category>Security</category>
		<guid>http://negative.blogsome.com/2005/01/07/tsunami-email-scams/</guid>
		<description><![CDATA[	The FBI is warning that fraudsters are using internet scams in the aftermath of the Asian tsunami disaster. The agency is warning of phishing websites claiming to be for relief charities, and emails offering to find victims for a fee or requesting that money be deposited in overseas accounts. Perhaps most appalling, those who have [...]]]></description>
			<content:encoded><![CDATA[	<p>The <a href="http://www.fbi.gov/">FBI</a> is warning that fraudsters are using internet scams in the aftermath of the <a href="http://en.wikipedia.org/wiki/2004_Indian_Ocean_earthquake">Asian tsunami disaster</a>. The agency is warning of <a href="http://en.wikipedia.org/wiki/Phising">phishing</a> websites claiming to be for relief charities, and emails offering to find victims for a fee or requesting that money be deposited in overseas accounts. Perhaps most appalling, those who have appealed online for information about missing friends and relatives are being contacted via email by opportunists proposing to investigate, in exchange for a hefty retainer.</p>
	<p>Related stories:
<ul>
<li>The Register, <a href="http://www.theregister.co.uk/2005/01/06/tsunami_relief_attack/">Tsunami relief donors under cyber-attack, says FBI</a></li>
	<li><b>vnu</b>network, <a href="http://www.vnunet.com/news/1160318">FBI warns of tsunami email scams</a></li>
	<li><b>vnu</b>network, <a href="http://www.vnunet.com/news/1160274">Phishing attacks increase by 29 per cent</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://negative.blogsome.com/2005/01/07/tsunami-email-scams/feed/</wfw:commentRss>
	</item>
	</channel>
</rss>
