<?xml version="1.0" encoding="utf-8"?><!-- generator="wordpress/1.5.1-alpha" -->
<rss version="0.92">
<channel>
	<title>thrtcl spr-mstrbtn!</title>
	<link>http://negative.blogsome.com</link>
	<description>Mstrbtn tchnqs shld b ncrgd nd tght n the pblc schl systms!</description>
	<lastBuildDate>Sat, 22 Oct 2005 23:32:22 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>

	<item>
		<title>Bye</title>
		<description>	I&#8217;m done with this blog. The archive will stay here for other purpose.
	It doesn&#8217;t mean that I hate blog. I just don&#8217;t like the way it handles my articles. Wiki is good to fill my needs.
	Will redirect you to my other page in 5 seconds. Or&#8230; just go to http://jim.geovedi.com/
 </description>
		<link>http://negative.blogsome.com/2005/04/07/bye/</link>
	</item>
	<item>
		<title>awexpl strikes</title>
		<description>	Just came back from holiday and reviewed apache logfile on my homeserver, I noticed that there are some wacky lines in access_log:
	200.217.***.*** - - [11/Feb/2005:15:47:15 +0700]
"GET /cgi-bin/awstats.pl?configdir=|echo%20;
echo%20;id;echo%20;echo| HTTP/1.0" 404 287
200.217.***.*** - - [11/Feb/2005:15:47:45 +0700]
"GET /awstats/awstats.pl?configdir=|echo%20;
echo%20;id;echo%20;echo| HTTP/1.0" 404 287
	After 2 minutes googling, I found a reference to the AWSTATS exploit. Looks ...</description>
		<link>http://negative.blogsome.com/2005/02/14/awexpl-strikes/</link>
	</item>
	<item>
		<title>Google getting smarter</title>
		<description>	Probably due to Santy worm, Google filtering some keywords.
	
	But, it seems that Google guys are just searching for predefined strings&#8230;not so smart!  inurl: admin.php [Blocked], inurl: admin.PHP [Pass], inurl:&#8221;admin php&#8221; [Pass], anything different than .php (for example: .pHp) will work..

 </description>
		<link>http://negative.blogsome.com/2005/02/05/google_smart/</link>
	</item>
	<item>
		<title>German court rules email blocking &#8216;illegal&#8217;</title>
		<description>	The Higher Regional Court now has ruled that blocking email by content is unlawful as it is considered confidential in German law. Blocking is only allowed when, say, a viral attack is imminent. The implications of the ruling aren&#8217;t yet fully clear. Whether the Higher Regional Court has unintentionally legalised ...</description>
		<link>http://negative.blogsome.com/2005/01/20/german_email_blocking/</link>
	</item>
	<item>
		<title>Valdis Kletnieks: Writing Secure Code</title>
		<description>	
On Tue, 18 Jan 2005 14:31:39 EST, &#8220;Sigmon Cheri Y Civ 82 CSS/SCPD :: Software Dev&#8221; said:
	Item: The &#8220;ongoing&#8221; debate among choices of open source vs. proprietary (all companies&#8217;) solutions, not just the major players in the industry. 
	I&#8217;m certain you&#8217;ve seen similar situations&#8230; where there are groups of people ...</description>
		<link>http://negative.blogsome.com/2005/01/20/writing_secure_code/</link>
	</item>
	<item>
		<title>Honey, Where&#8217;s My Jump Bag?</title>
		<description>	[Sidebar: Fill Your Jump Bag]
	A &#8220;jump bag&#8221; is a collection of critical items you might need during crisis response when an attacker invades your network. It should contain these items:
	
Tape recorder or minidisk

	Backup media
	Binary backup software
	CDs with statically linked binaries of critical OS executables
	Forensic software
	Windows NT and 2000 resource kits
	Bootable ...</description>
		<link>http://negative.blogsome.com/2005/01/20/jump_bag/</link>
	</item>
	<item>
		<title>NUKIDO: Various Local Vulnerabilities in Mac OS X  10.3.x</title>
		<description>	Several kernel level bounds checking vulnerabilities were found during an audit performed by Immunity team on the recent Darwin kernel xnu­517.7.7.  These vulnerabilities are mostly in user to kernel memory copy operations and also allocation of kernel memory driven by user supplied size value(s). 
	Well, they also put the ...</description>
		<link>http://negative.blogsome.com/2005/01/19/nukido/</link>
	</item>
	<item>
		<title>BS7799 Lead Auditor Course</title>
		<description>	Starting today until January 14, 2005, I&#8217;ll be in BS7799 Lead Auditor Course organized by Bellua &#8212; in association with Bureau Veritas, at Gran Melia Hotel, Jakarta. The course is intended for all those who wish to undertake and eventually lead audits of Information Security Management Systems. It is also ...</description>
		<link>http://negative.blogsome.com/2005/01/10/bs7799_course/</link>
	</item>
	<item>
		<title>Honeynet Project Report: Trend Analysis</title>
		<description>	Honeynet Project just released a report about the security of Linux. The life expectancy of Linux has lengthened dramatically since 2001 and 2002, the project said, from a mere 72 hours two and three years ago to an average of three months today. 
	Why? There are several explanations for that:

Default ...</description>
		<link>http://negative.blogsome.com/2005/01/07/honeynet_trend_analysis/</link>
	</item>
	<item>
		<title>Tsunami email scams</title>
		<description>	The FBI is warning that fraudsters are using internet scams in the aftermath of the Asian tsunami disaster. The agency is warning of phishing websites claiming to be for relief charities, and emails offering to find victims for a fee or requesting that money be deposited in overseas accounts. Perhaps ...</description>
		<link>http://negative.blogsome.com/2005/01/07/tsunami-email-scams/</link>
	</item>
</channel>
</rss>
