<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-20189612</id><updated>2011-11-26T22:37:57.094-08:00</updated><title type='text'>Ignorance is the root of all evil ... ;-)</title><subtitle type='html'>Exposing Digital In-security</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>98</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-20189612.post-2725714051158266353</id><published>2011-10-16T15:40:00.000-07:00</published><updated>2011-10-16T15:45:30.055-07:00</updated><title type='text'>How I got back a returning customer</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="color: #e69138;"&gt;&lt;u&gt;Background&lt;/u&gt;&lt;/div&gt;A little background information for you folks... who don't understand what I do... I expose the ways in which your network, server, host, web application, website or any other system maybe vulnerable to real attacks. We are not talking about some obscure bug that can't be exploited. We are talking about DNS here...&lt;br /&gt;&lt;br /&gt;Now DNS is not exactly rocket science, right? You think so? The customer whom I spoke to doesn't really concur with me on that point. He thinks it is rocket science, since he does not have enough technical knowledge to figure it out. I give him a demonstration of how to tunnel SSH over DNS (Ozyman) and SSH over HTTP :))&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #e69138;"&gt;&lt;u&gt;Show time (DNS Tunneling)&lt;/u&gt;&lt;/div&gt;Once I do that, his auditor freaks out and tells me how I am doing bad things. What is my job again? I expose vulnerabilities and real threats to the customer, I don't perform simple scans and tell the customer to patch some bug without taking business productivity and impact in to consideration. In layman terms, tunneling a protocol over another like discussed above can cause the network to think SSH is just DNS traffic. Truth is some rogue hacker may get a reverse shell running through that port and hide in plain sight.&lt;br /&gt;&lt;br /&gt;The customer and his new found "auditor" (read: CISSP / CISA holder, with no grasp of protocols). I had to show documentation, research and a tool. To top it off, I showed a live demo and used Wireshark to show the DNS traffic. I did my job and I did it so well, that the customer becomes scared, confused and everything else, but convinced. The customer does not want to understand the impact, or go with a quality security tester like me.&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #e69138;"&gt;&lt;u&gt;My mistake&lt;/u&gt;&lt;/div&gt;I told them, I will test the environment without any bias and will not support their certification (compliance) efforts, if they fail to co-operate and patch all the important vulnerabilities. This causes a real stir and the next time, the customer (who happened to be a return customer - more than 4 engagements)... fails to choose ME for the 5th time.&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #e69138;"&gt;&lt;u&gt;Business 101&lt;/u&gt;&lt;/div&gt;Guess why they didn't want me? I argued and I failed to co-operate with them for their namesake compliance... OK, from a business point of view I totally understand their hatred towards me. There's an old saying in sales, If You Win the Argument, You Lose the Sale (The auditor played a good part in convincing them, that I am not the right person for the job). When it comes to security and technical aspects, I put my money where my mouth was... and showed them a real demonstration.&lt;br /&gt;&lt;br /&gt;&lt;div style="color: #e69138;"&gt;&lt;u&gt;Better Late Than Never&lt;/u&gt;&lt;/div&gt;What did I learn? Be co-operative... or lose the sale. I'd rather have it my way or the highway... and a customer who can not appreciate quality is always going to end up in my bad books. I am a person that believes in quality over everything else.&lt;br /&gt;&lt;br /&gt;What did they learn? The customer's network got hacked exactly 90 days, after they achieved compliance. The customer didn't hesitate to call me. The manager at their firm said some thing I am very proud of... He said, "We are calling you because you scared us just like that hacker..."&lt;br /&gt;&lt;div style="color: #e69138;"&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/div&gt;&lt;u style="color: #e69138;"&gt;For a few dollars more&lt;/u&gt;&lt;br /&gt;After the post mortem and forensic analysis, I helped them to set up an incident response plan. The customer now engages me for security testing and over all maintenance of their network. I have gained a returning customer, after losing them once. Selling is all about second chances ;))&lt;br /&gt;&lt;br /&gt;P.S: This is NOT the First Time, I am getting a call from a customer that disagreed with me and got hacked!&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2725714051158266353?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2725714051158266353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2725714051158266353' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2725714051158266353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2725714051158266353'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/10/how-i-got-back-returning-customer.html' title='How I got back a returning customer'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-9203802050513247212</id><published>2011-10-06T03:35:00.000-07:00</published><updated>2011-10-06T11:47:23.542-07:00</updated><title type='text'>Wow, Goodbye Steve?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;Is it that time of the century for an inventor to be gone? Gee, that sucks... Goodbye Steve :(&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-l9om6e3ogs8/To2EUA_bm7I/AAAAAAAAAbg/Z7Nc14HN9qw/s1600/steve_jobs_and_wozniak.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="381" src="http://1.bp.blogspot.com/-l9om6e3ogs8/To2EUA_bm7I/AAAAAAAAAbg/Z7Nc14HN9qw/s400/steve_jobs_and_wozniak.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Steve is an inspiration at best and he braved - being born to unmarried parents, thrown to be adopted by his mother... Then he drops out of college, founder of apple, founder of pixar, rejoins apple - a revolution happens with iPhone, iPad, iPod and owning an Apple product doesn't make you exclusive anymore, they've turned from being a niche company to a mainstream company with nearly $350 Billion USD in stocks... The only company that makes more money than Apple is Exxon Mobil and they do it from oil, not from ideas !&lt;br /&gt;&lt;br /&gt;R.I.P Steve, also R.I.P A.C Nielsen... Peace !&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-9203802050513247212?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/9203802050513247212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=9203802050513247212' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/9203802050513247212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/9203802050513247212'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/10/wow-goodbye-steve.html' title='Wow, Goodbye Steve?'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-l9om6e3ogs8/To2EUA_bm7I/AAAAAAAAAbg/Z7Nc14HN9qw/s72-c/steve_jobs_and_wozniak.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-8700841770892864652</id><published>2011-08-27T05:59:00.000-07:00</published><updated>2011-08-27T05:59:46.574-07:00</updated><title type='text'>iQuit... Steve job quits apple, what again?</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;I have stopped counting the number of times, he's quit and come back to Apple...&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-anLr5DD8yEU/TljpTcJx6fI/AAAAAAAAAbU/Opbzx8bLDbU/s1600/byesteve.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="265" src="http://1.bp.blogspot.com/-anLr5DD8yEU/TljpTcJx6fI/AAAAAAAAAbU/Opbzx8bLDbU/s320/byesteve.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Really would be a relief, if he let M$ stay on top and generate serious revenue compared to Apple. Personally, I'd like to see iPhone and a lot of i Apps / i Hardware(s) to stop... The world becomes restricted to bullshit software provided by apple... and their updates, well you've got to pay for it? WTF?&lt;br /&gt;&lt;br /&gt;A lot of apple fans are pissed because the software, drm and whole pay for your updates BS - what if, they introduce bugs just to push more updates... That is not happening now, but some thing like that isn't impossible... ;)&lt;br /&gt;&lt;br /&gt;It would be ironic to have such ridiculous stuff going on, amidst their already high number of vulnerabilities. iHate - Apple... All that aside, Steve Jobs is a great guy (business strategy, promotion, ideas and inspiring), Good luck to him !&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-8700841770892864652?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/8700841770892864652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=8700841770892864652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8700841770892864652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8700841770892864652'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/08/iquit-steve-job-quits-apple-what-again.html' title='iQuit... Steve job quits apple, what again?'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-anLr5DD8yEU/TljpTcJx6fI/AAAAAAAAAbU/Opbzx8bLDbU/s72-c/byesteve.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-7801454913012598610</id><published>2011-07-09T12:32:00.001-07:00</published><updated>2011-07-09T12:33:49.735-07:00</updated><title type='text'>Love Letters...</title><content type='html'>I just love this, love this mail, especially the part about monies... hahaha !&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-bCxCcRRgANM/ThitDti2P3I/AAAAAAAAAaM/YJrjL6dPsAM/s1600/lovemail.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 147px;" src="http://3.bp.blogspot.com/-bCxCcRRgANM/ThitDti2P3I/AAAAAAAAAaM/YJrjL6dPsAM/s400/lovemail.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5627438013676404594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thank you for the Love letters :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-7801454913012598610?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/7801454913012598610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=7801454913012598610' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7801454913012598610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7801454913012598610'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/07/love-letters.html' title='Love Letters...'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-bCxCcRRgANM/ThitDti2P3I/AAAAAAAAAaM/YJrjL6dPsAM/s72-c/lovemail.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-7539994379915377613</id><published>2011-06-06T04:47:00.000-07:00</published><updated>2011-06-06T05:02:09.270-07:00</updated><title type='text'>Note: Top 5 Database Breaches in 2011</title><content type='html'>&lt;blockquote&gt;1. Victim: HBGary Federal&lt;br /&gt;Assets Stolen/Affected: 60,000 confidential emails, executive social media accounts, and customer information. &lt;br /&gt;&lt;br /&gt;2. Victim: RSA&lt;br /&gt;Assets Stolen/Affected: Proprietary information about RSA's SecurID authentication tokens.&lt;br /&gt;&lt;br /&gt;3. Victim: Epsilon&lt;br /&gt;Assets Stolen: E-mail databases from 2 percent of the firm's 2,500 corporate clients.&lt;br /&gt;&lt;br /&gt;4. Victim: Sony&lt;br /&gt;Assets Stolen: More than 100 million customer account details and 12 million unencrypted credit card numbers. &lt;br /&gt;&lt;br /&gt;5. Victim: Texas Comptroller's Office&lt;br /&gt;Assets Stolen: The names, Social Security numbers, and mailing addresses of 3.5 million individuals, plus dates of birth and driver's license numbers of some. &lt;/blockquote&gt;&lt;br /&gt;Note for reference... :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-7539994379915377613?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/7539994379915377613/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=7539994379915377613' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7539994379915377613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7539994379915377613'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/06/note-top-5-database-breaches-in-2011.html' title='Note: Top 5 Database Breaches in 2011'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2294425729516941712</id><published>2011-04-28T10:29:00.000-07:00</published><updated>2011-05-05T18:43:12.806-07:00</updated><title type='text'>And you thought online booking is safe</title><content type='html'>INOX Movies features - A lesson in "designing secure web pages"&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-q4NqYuYgOk0/TbmlFCz7KFI/AAAAAAAAAZ4/mJyJ8BMAtMc/s1600/SQLi_INOX.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 270px;" src="http://3.bp.blogspot.com/-q4NqYuYgOk0/TbmlFCz7KFI/AAAAAAAAAZ4/mJyJ8BMAtMc/s400/SQLi_INOX.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5600689117684508754" /&gt;&lt;/a&gt;&lt;br /&gt;Vulnerable URL: hxxp://www.inoxmovies.com/seatlayout.aspx&lt;br /&gt;&lt;br /&gt;Incase you don't understand what will be the bug, it will be a SQL Injection!&lt;br /&gt;&lt;br /&gt;INOX Movies is "Safe"... Come on, it uses "http"... it's unbreakable! :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2294425729516941712?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2294425729516941712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2294425729516941712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2294425729516941712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2294425729516941712'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/04/and-you-thought-online-booking-is-safe.html' title='And you thought online booking is safe'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-q4NqYuYgOk0/TbmlFCz7KFI/AAAAAAAAAZ4/mJyJ8BMAtMc/s72-c/SQLi_INOX.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-991927117933889452</id><published>2011-04-17T02:35:00.001-07:00</published><updated>2011-04-17T02:52:46.986-07:00</updated><title type='text'>APNIC runs out of IPv4 Address</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-k_QXja_N3xU/Taq1JJgYUXI/AAAAAAAAAZo/oeyII8ZCBmo/s1600/IPv4SlowEnd.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 225px;" src="http://1.bp.blogspot.com/-k_QXja_N3xU/Taq1JJgYUXI/AAAAAAAAAZo/oeyII8ZCBmo/s400/IPv4SlowEnd.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5596484655736443250" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;blockquote&gt;http://www.apnic.net/publications/news/2011/final-8&lt;/blockquote&gt;&lt;br /&gt;If you haven't read this announcement, read it and act on IPv6... deployment for your enterprise environment.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-991927117933889452?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/991927117933889452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=991927117933889452' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/991927117933889452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/991927117933889452'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/04/apnic-runs-out-of-ipv4-address.html' title='APNIC runs out of IPv4 Address'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-k_QXja_N3xU/Taq1JJgYUXI/AAAAAAAAAZo/oeyII8ZCBmo/s72-c/IPv4SlowEnd.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-7505992596994017232</id><published>2011-02-12T10:59:00.000-08:00</published><updated>2011-02-12T12:12:45.834-08:00</updated><title type='text'>Ignorance is "THE" root of all evil</title><content type='html'>Example? HBGary's latest pwnage by Anonymous group... Can't understand why they don't maintain good passwords, different passwords for their account, some user awareness and why they can't get pro-active website maintenance and testing. They have so much capital and as the last line in the JPG says... "not expertly secured" ... Epic FAIL.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-MncF7GqMEGY/TVbZXA3vuyI/AAAAAAAAAZA/XWQrsgGqE2Q/s1600/hbgary-pwned.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 313px;" src="http://4.bp.blogspot.com/-MncF7GqMEGY/TVbZXA3vuyI/AAAAAAAAAZA/XWQrsgGqE2Q/s320/hbgary-pwned.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5572880578311600930" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;BTW, I had and still have respect for Greg Hoglund from HBGary. All in all, they lost clients and will have bad PR for the next month or so... please work on your security "before" you get hacked.&lt;br /&gt;&lt;br /&gt;For all the guys, who insist on "no DoS, no stress testing, no client side testing and no social engineering" - [04:18] &lt;&amp;Sabu&gt; greg, a 16 year old girl social engineered your admin jussi and got root to rootkit.com&lt;br /&gt;&lt;br /&gt;Yes, that's straight from a IRC chat log involving Greg(HBGary), Penny (HBGary) and the anonymous group... I read the full log for the LOLs :D&lt;br /&gt;&lt;br /&gt;Peace !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-7505992596994017232?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/7505992596994017232/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=7505992596994017232' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7505992596994017232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7505992596994017232'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2011/02/ignorance-is-root-of-all-evil.html' title='Ignorance is &quot;THE&quot; root of all evil'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-MncF7GqMEGY/TVbZXA3vuyI/AAAAAAAAAZA/XWQrsgGqE2Q/s72-c/hbgary-pwned.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-4867958029640223255</id><published>2010-12-18T23:17:00.000-08:00</published><updated>2010-12-18T23:30:49.976-08:00</updated><title type='text'>Back... To Security Testing</title><content type='html'>After a recent flood of investigative, forensic and legal support requests... We are back ON-Track to security testing... Always great to have the 'hacker' tag :D&lt;br /&gt;&lt;br /&gt;I certainly appreciate my clients who entrusted their resources to me for investigations and forensic work, but nothing like our bread-and-butter, haha.&lt;br /&gt;&lt;br /&gt;The headlines from ArsTechnica read "MSE 2.0 arrives with heuristic scanning, network traffic inspection" &amp; "December 2010 Patch Tuesday will come with most bulletins ever"... and ZDNet's headlines include "Microsoft delivers patches for IE, font driver; Puts Stuxnet to bed" &amp; "Apple plugs 15 gaping security holes in QuickTime" &lt;br /&gt;&lt;br /&gt;Some surprise that MSE 2.0 has been successful, because it was released earlier for as a pilot - and failed in 1.0 before they learned their lessons and launched 2.0 ;)&lt;br /&gt;&lt;br /&gt;Same surprise about Windows Patch Tuesday - I love MS, they help us survive and stay in business... No Wonder, with tools like Metasploit and CANVAS around :D&lt;br /&gt;&lt;br /&gt;Stuxnet has been put to bed and that is indeed good news... &lt;br /&gt;&lt;br /&gt;We are going to have a blast, 3 pen-tests already lined up :))&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-4867958029640223255?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/4867958029640223255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=4867958029640223255' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4867958029640223255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4867958029640223255'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/12/back-to-security-testing.html' title='Back... To Security Testing'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-4436235634102646717</id><published>2010-08-01T13:15:00.000-07:00</published><updated>2010-08-01T14:06:49.686-07:00</updated><title type='text'>UIDAI Scheme - Or - Compromising my privacy?</title><content type='html'>What we know / heard from a few sources?&lt;br /&gt;&lt;br /&gt;Basic Information:&lt;br /&gt;The UID itself will collect only standard attributes such as name, date of birth, gender, father/mother/spouse/guardians name, address and a photograph. The only unique information is the biometrics (10 fingerprints and both IRIS scans).&lt;br /&gt;&lt;br /&gt;Who / Why / Usage&lt;br /&gt;The UID will be given to all residents who are in India and avail services and not just citizens.&lt;br /&gt;&lt;br /&gt;The information in the database will be used only for authentication purposes and will not be shared or transmitted. Anyone seeking to authenticate the identity of another person using the UID database – will only get a response in YES or NO.&lt;br /&gt;&lt;br /&gt;About working / operations:&lt;br /&gt;The UIDAI is working on a partnership model with a variety of agencies and service providers ( both government and private sector) to enroll residents for UID Numbers and verify their identity. For e.g. Insurance companies, LPG marketing companies, RSBY, MG-NREGA etc. The UIDAI will also engage with Outreach Groups (essentially CSOs) to target, the homeless, urban poor, tribals, differently-abled population of the country etc.&lt;br /&gt;&lt;br /&gt;About security:&lt;br /&gt;The UID database will be guarded both physically and electronically by a few select individuals with high clearance. It will not be available even for many members of the UID staff and will be secured through encryption, and in a highly secure data vault.&lt;br /&gt;&lt;span style="font-style:italic;"&gt;&lt;br /&gt;Is your security up to the mark ? What is that secure data vault thing? Please don't use such terms, a layman maybe fooled into thinking "ultra secure" when in reality, you're storing it in the most haphazard manner.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Why do they (government) want a person's mother's name, father's name, and their respective UID numbers ? &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/TFXZJx3hLAI/AAAAAAAAATE/lZa-MP3vA74/s1600/UIDAI.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 210px;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/TFXZJx3hLAI/AAAAAAAAATE/lZa-MP3vA74/s320/UIDAI.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5500541281931176962" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Check this out ... the picture shows what info they are going to collect for the card. Add the present/permanent address thing to this mix, you can have one of our residing addresses, you are the government, you either choose permanent or present address, because parting with "everything" or too much of my private information to you - from me, a hacker's perspective... looks like asking to be stabbed !&lt;br /&gt;&lt;br /&gt;All I'm saying is ... basically, devil knows who's got access to this DB once it is implemented. That's not all, they do say there may be an option for a person to escape their identity theft mechanisms and create a completely false identity and obtain a UID, d'uh !&lt;br /&gt;&lt;br /&gt;Murphy's law folks, if you missed it ... "If anything can go wrong, it will"&lt;br /&gt;&lt;br /&gt;Security Model for UIDAI Scheme&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/TFXcjl6WOcI/AAAAAAAAATU/wNQGUY6Fa8k/s1600/security-uidai.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 174px;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/TFXcjl6WOcI/AAAAAAAAATU/wNQGUY6Fa8k/s320/security-uidai.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5500545023933299138" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Always be prepared for the worst case scenarios, stop deducing cyber crime with just audit trails for a change.&lt;br /&gt;&lt;br /&gt;Offences under UIDAI Act - Check out the screenshot&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/TFXa9rV1NtI/AAAAAAAAATM/ZGHTp_LtgJA/s1600/Offences-Under-UIDAI.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 176px;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/TFXa9rV1NtI/AAAAAAAAATM/ZGHTp_LtgJA/s320/Offences-Under-UIDAI.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5500543273044096722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Addition about the IT Act 2000, and consequences if you compromise their DB,"All offences under the Information Technology Act shall be deemed to be offences under the UIDAI if directed against the UIDAI or its database."&lt;br /&gt;&lt;br /&gt;Small FAQ I built for the readers,&lt;br /&gt;&lt;br /&gt;Q. How will they (government) manage and secure 1.20 billion people's information ?&lt;br /&gt;A. They wish to encrypt information and store it in a centralized DB... &lt;br /&gt;&lt;br /&gt;Q. What security design will be implemented for Server and the Network/Client?&lt;br /&gt;A. We have Firewall, IDS, IPS - alphabet soup basically, and Encryption with PKI.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Oh, my! the traditional defense-in-depth approach - Lauds the government. What about being proactive and conducting tests regularly? (Pen test, code review, DB security, red teaming, and compliance for the supporting infrastructure)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Q. Will my information be secure in the database?&lt;br /&gt;A. Well, it depends... lol !&lt;br /&gt; "The UID database will be susceptible to attacks and leaks at various levels. The UIDAI must have enough teeth to be able to address and deal with these issues effectively." &lt;br /&gt;&lt;br /&gt;Q. What will the basic information and biometrics be integrated with?&lt;br /&gt;A. Banks, Ration shop, Income Tax Dept, Passports, Credit Card/Debit Card, Online accounts. Precisely, enough sensitive data will be integrated with so-cal best practices to leave you stabbed from a lot of angles.&lt;br /&gt;&lt;br /&gt;People who define security should not use the abbreviation for et-cetera (etc). Define and then write a document, because you are dealing with national security and a billion plus populous here. Don't be so naive and clueless by mentioning stuff like "Network, Client Security – Encryption, PKI etc"&lt;br /&gt;&lt;br /&gt;From the looks of it, The way in which the government is dealing with our information is haphazard, to say the least.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-4436235634102646717?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/4436235634102646717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=4436235634102646717' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4436235634102646717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4436235634102646717'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/08/uidai-scheme-or-compromising-my-privacy.html' title='UIDAI Scheme - Or - Compromising my privacy?'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/TFXZJx3hLAI/AAAAAAAAATE/lZa-MP3vA74/s72-c/UIDAI.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-3534671051213935023</id><published>2010-07-23T23:55:00.001-07:00</published><updated>2010-07-24T00:23:06.784-07:00</updated><title type='text'>Xchanging URLs now ;))</title><content type='html'>The vulnerable page is still there, and there is no fix... but hey, the web developers sure learned to redirect the vulnerable page to home.html... ironic ;))&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/TEqUJx8IWwI/AAAAAAAAAS8/pSNIjGZEbF0/s1600/xchanging_url.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 156px;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/TEqUJx8IWwI/AAAAAAAAAS8/pSNIjGZEbF0/s320/xchanging_url.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5497369190904388354" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Web development and Security @ Xchanging - EPIC FAIL... sorry folks... Try harder next time... If you want to contact me for a penetration test, here's my mail: kishfellow at yahoo dot com&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-3534671051213935023?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/3534671051213935023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=3534671051213935023' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/3534671051213935023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/3534671051213935023'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/07/xchanging-urls-now.html' title='Xchanging URLs now ;))'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/TEqUJx8IWwI/AAAAAAAAAS8/pSNIjGZEbF0/s72-c/xchanging_url.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-6217813117095538227</id><published>2010-07-21T05:51:00.000-07:00</published><updated>2010-07-21T05:53:20.662-07:00</updated><title type='text'>Xchanging SQL Injections with you...</title><content type='html'>Xchanging - Xchanging plc (LSE: XCH) is a business processing company, with a wide range of multinational customers in 42 countries and employing over 8,000 people worldwide. It is listed on the London Stock Exchange and is in the FTSE 250 Index. Xchanging is also a member of the FTSE4Good index.&lt;br /&gt;&lt;br /&gt;They have a potential SQL injection here, well... someone needs a pen-test?&lt;br /&gt;http://selfservice.xchanging.com/serviceportal/default.aspx?offset=&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-6217813117095538227?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/6217813117095538227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=6217813117095538227' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/6217813117095538227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/6217813117095538227'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/07/xchanging-sql-injections-with-you.html' title='Xchanging SQL Injections with you...'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-264540373658604340</id><published>2010-07-06T06:07:00.000-07:00</published><updated>2010-07-06T06:44:54.234-07:00</updated><title type='text'>Linux migration SNAFU</title><content type='html'>Disclaimer: The author is not against windows, the author is not against linux, the author is against "stupid" practices and communication gap while migrating from one OS to another. The author is an ardent Linux and BSD Fan, and supports FOSS/OSS movements.&lt;br /&gt;&lt;br /&gt;The inspiration for this post comes from a REAL company whose employees were not so happy and almost resigned their posts owing to a bad migration. &lt;br /&gt;&lt;br /&gt;Here is a story of a simple Linux migration gone-all-wrong.&lt;br /&gt;&lt;br /&gt;The last thing any employee wants at the office on Monday morning is to turn on their workstation to find Linux instead of their beloved Windows operating system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How NOT TO MIGRATE from Windows to Linux&lt;/span&gt;&lt;br /&gt;- For Lower TCO, access to source code,&lt;br /&gt;- For Economic benefit,  Ethical Benefit,&lt;br /&gt;- For Access to Source code,&lt;br /&gt;- For whatever-else-you-deem-fit to trigger a migration&lt;br /&gt;&lt;br /&gt;You certainly have to communicate to your employee formally - written as a memo circulated throughout the ranks, or a simple e-mail to all employees notifying the change.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Analysis : Why it went wrong ?&lt;/span&gt;&lt;br /&gt;Things that made this particular migration go wrong...&lt;br /&gt;1) The employees were not informed prior to the migration&lt;br /&gt;2) Backup was not in place, only last minute backup was available&lt;br /&gt;3) There was no Linux101, Command Line usage or any induction towards the new operating system at their disposal.&lt;br /&gt;4) No clear planning, and deployment - Old versions of Ubuntu were deployed.&lt;br /&gt;5) There was no consultant or subject matter expert to assist the migration.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;How TO MIGRATE from Windows to Linux&lt;/span&gt;&lt;br /&gt;- Prior to the transition from one OS to another - inform your employees formally&lt;br /&gt;- Get them involved in the planning and ask for their views &amp; suggestions&lt;br /&gt;- After giving the heads-up, arrange for a backup (through System Administrator)&lt;br /&gt;- To make the transition smooth decide who needs a Linux desktop and how many Windows systems can be retained (to reduce training budget)&lt;br /&gt;- Choose a Linux distribution based on - User competence, prior experience, and business goal (why linux?)&lt;br /&gt;- Engage an external consultant or subject matter expert&lt;br /&gt;- Plan the switch with software used currently and alternate software available for linux&lt;br /&gt;HINT: ptth://www.osalt.com&lt;br /&gt;- Deploy a test bed and introduce the operating system functionality&lt;br /&gt;- Arrange for a formal induction (hands-on) with the consultant&lt;br /&gt;- Clarify doubts and exchange ideas, get tips and tricks and further reading&lt;br /&gt;- Arrange for a dinner (makes employees happy to eat and learn, than just learning)&lt;br /&gt;- Use linux philosophy from time to time - for motivation, increasing productivity, and squeezing employees to the max, hehe !&lt;br /&gt;&lt;span style="font-style:italic;"&gt;&lt;br /&gt;"The only thing worse than training good employees and losing them is NOT training your employees and keeping them."&lt;br /&gt;- Zig ziglar&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Point to be taken from this post: Next time you migrate to any linux distribution, make sure you Communicate the change, engage a subject matter expert, plan, test, and then deploy.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;br /&gt;&lt;br /&gt;PS: We offer Linux migration services, and Open Source consulting of the best quality at very nominal pricing. Contact me for more information.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-264540373658604340?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/264540373658604340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=264540373658604340' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/264540373658604340'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/264540373658604340'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/07/linux-migration-snafu.html' title='Linux migration SNAFU'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-175755838256389419</id><published>2010-05-31T03:02:00.001-07:00</published><updated>2010-05-31T03:06:14.107-07:00</updated><title type='text'>U Socket - USB Charging directly from plug points</title><content type='html'>Quoting from their website, &lt;br /&gt;"U-Socket is a duplex AC receptacle with built-in USB ports that can power any device that is capable of being charged via a 5V power adapter, but without the need for the power adapter! When a U-Socket replaces a traditional 3-prong AC wall socket, you can eliminate the clutter of AC Adapters that stick out &amp; take up space in your home or office. Everything stays neat &amp; organized. In additional, U-Socket's energy efficient design only outputs power through the USB port if something is connected to it. This can save you up to $25 per year in reduced energy costs. Good for you, good for the environment and with our great prices, good for your wallet too!"&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/TAOJ6P-AABI/AAAAAAAAAS0/3rn4TB1m99Y/s1600/usock.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 168px; height: 240px;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/TAOJ6P-AABI/AAAAAAAAAS0/3rn4TB1m99Y/s320/usock.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5477373205624651794" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Neat little addition to your desk to charge your devices like iPad or mp3 players :)&lt;br /&gt;&lt;br /&gt;For more information, &lt;a href="http://fastmac.com/usocket.php"&gt;click here&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-175755838256389419?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/175755838256389419/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=175755838256389419' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/175755838256389419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/175755838256389419'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/05/u-socket-usb-charging-directly-from.html' title='U Socket - USB Charging directly from plug points'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_0mC8VRRkEdE/TAOJ6P-AABI/AAAAAAAAAS0/3rn4TB1m99Y/s72-c/usock.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2013191145719509754</id><published>2010-02-07T03:11:00.000-08:00</published><updated>2010-02-07T03:12:37.171-08:00</updated><title type='text'>No pun intended</title><content type='html'>Pen tester1: I have have very less issues related to security compared to my windows laptop&lt;br /&gt;Kish: probably, because people own macs silently ;)&lt;br /&gt;Pen tester1: ...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2013191145719509754?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2013191145719509754/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2013191145719509754' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2013191145719509754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2013191145719509754'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2010/02/no-pun-intended.html' title='No pun intended'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-7821354928234970542</id><published>2009-10-17T23:14:00.000-07:00</published><updated>2009-10-17T23:25:06.792-07:00</updated><title type='text'>Evil Maid - Pwnie for Overhyped bug</title><content type='html'>&lt;meta equiv="Content-Type" content="text/html; charset=utf-8"&gt;&lt;meta name="ProgId" content="Word.Document"&gt;&lt;meta name="Generator" content="Microsoft Word 12"&gt;&lt;meta name="Originator" content="Microsoft Word 12"&gt;&lt;link rel="File-List" href="file:///C:%5CDOCUME%7E1%5CKINGPH%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_filelist.xml"&gt;&lt;link rel="themeData" href="file:///C:%5CDOCUME%7E1%5CKINGPH%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_themedata.thmx"&gt;&lt;link rel="colorSchemeMapping" href="file:///C:%5CDOCUME%7E1%5CKINGPH%7E1%5CLOCALS%7E1%5CTemp%5Cmsohtmlclip1%5C01%5Cclip_colorschememapping.xml"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="--"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:10.0pt; 	margin-left:0in; 	line-height:115%; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-bidi-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt; 	mso-ascii-font-family:Calibri; 	mso-fareast-font-family:Calibri; 	mso-hansi-font-family:Calibri;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:11.0pt; 	font-family:"Calibri","sans-serif"; 	mso-ascii-font-family:Calibri; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:"Times New Roman"; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Calibri; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Hey dudes, and dudettes, Happy Diwali to y’all !&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Today’s post is about &lt;a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html"&gt;the Evil maid&lt;/a&gt;'s exploits on an unsuspecting computer user...&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Scenario&lt;/u&gt;&lt;br /&gt;Full disk encryption with Truecrypt in this case...&lt;br /&gt;&lt;span style="color: rgb(255, 102, 102);"&gt;&lt;br /&gt;The author mentions PGP whole disk encryption but never mentions about testing it on the humor-me FAQ, LOL! :D&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Attack&lt;/u&gt;&lt;br /&gt;Joanna of Invisible things has come up with an attack (social engineering + physical access + usb drive?!) - WTF I say... If a person has physical access to your box, it is pretty much a goner... what difference does it make if I boot from a live-cd and use a keylogger or do the same thing from an USB drive?&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Solution &lt;/u&gt;&lt;br /&gt;Disable USB boot from BIOS options (this ain't nothing new to talk about, building a custom USB drive with a small kernel and a simple keylogger is NOT new)&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 102, 102);"&gt; If you know your way around in Linux, and you use it as a base for your penetration testing laptop. Try modprobe -r usb_storage and blacklist in your conf file, if you are paranoid.&lt;/span&gt;&lt;br /&gt; &lt;br /&gt;&lt;span style="color: rgb(255, 102, 102);"&gt; You can easily convert the install/remove commands into a shell-script. Alternately, USB devices can be disabled at the kernel level via GRUB or any other boot loader by editing menu.lst / grub.conf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;There is also a &lt;span style="color: rgb(255, 102, 102);"&gt;humor-me FAQ&lt;/span&gt; that says...&lt;br /&gt;&lt;span style="color: rgb(255, 102, 102);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;i style=""&gt;Q: Is this Evil Maid Attack some l33t new h4ck?&lt;br /&gt;Nope, the concept behind the Evil Maid Attack is neither new, nor l33t in any way.&lt;br /&gt;&lt;br /&gt;Q: So, why did you write it?&lt;br /&gt;Because we believe it demonstrates an important problem, and we would like more attention to be paid in the industry to solving it.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;As if nobody has covered these hardware based and/or social engineering attacks in the past?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;i style=""&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Q: I've disabled boot from USB in BIOS and my BIOS is password protected, am I protected against EM?&lt;br /&gt;No. Taking out your HDD, hooking it up to a USB enclosure case and later installing it back to your laptop increases the attack time by some 5-15 minutes at most. A maid has to carry her own laptop to do this though.&lt;/span&gt;&lt;/i&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;&lt;br /&gt;&lt;br /&gt;I loved this part... Every maid knows how to pull apart a laptop and remove the hard-drive enclosure without damaging the drive... Do all maids have prior training in corporate espionage, and basic computer/laptop hardware and operations? LOL!&lt;br /&gt;&lt;br /&gt;&lt;i style=""&gt;Q: Why did you choose TrueCrypt and not some other product? Because we believe TrueCrypt is a great product, we use it often in our lab, and we would love to see it getting some better protection against such attacks.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Encryption must protect against physical attacks? Since when did that become a pre-requisite for a fool-proof encryption system/software... since the day "Evil maid was coded" I guess... ;))&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Their solutions: Protect your laptop (wow, you discovered something here…), TPM (aka snake oil), Disk Hasher (oh, hashing is a “reasonable” solution even though it is broken) &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Let me get this straight, you invent a problem out of nothing and you suggest YOUR own solution, roflmao!&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Bottom-line&lt;/u&gt;&lt;br /&gt;General unsuspecting public will leave a laptop like this fine lady here suggests. If a person identifies himself/herself a hacker, they are NOT supposed to leave their laptops in a hostile environment... When you leave like that, don't identify yourself as a hacker.&lt;br /&gt;&lt;br /&gt;&lt;i style=""&gt;Acknowledgments&lt;br /&gt;Thanks to the ennead@truecrypt.org for all the polemics we had which allowed me to better gather my thoughts on the topic. The same thanks to Alex and Rafal, for all the polemics I have had with them (it's customary for ITL to spend a lot of time finding bugs in each other's reasoning).&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The person demonstrating such a GREAT attack will go to any extent to prove that an attack is possible, but will not think one bit as to whether it is practical??&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Truecrypt clearly mentions about physical attacks in their documentation, which means they are not addressing the issue, and they want you to find something more serious and interesting to work on and if you don’t have a lot of ideas, ping &lt;a href="http://addxorrol.blogspot.com/"&gt;Halvar Flake&lt;/a&gt; – He’s a smart guy with a lot of ideas which are innovative. Stop rehashing old attacks and building small Linux kernels with a simple keylogger and write a humor-me FAQ with “we want more attention” (you want the industry to pay attention to the attack or you?)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;i&gt;Truecrypt Dev: My answer was a good safety case or strongbox with a good lock. If you use it, then you will notice that the attacker has accessed your notebook inside (as the case or strongbox will be damaged and it cannot be replaced because you had the correct key with you). If the safety case or strongbox can be opened without getting damaged &amp;amp; unusable, then it's not a good safety case or strongbox. ;-)&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;Well, what can I say, except … he pwned you!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;I nominate “the Evil Maid” for the Pwnie Awards 2010 - Most Overhyped bug… perhaps someone can beat Joanna to the race… Let’s see… hehe!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size: 12pt; line-height: 115%; color: rgb(255, 102, 102);"&gt;Errr...Where's all the rum gone?&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-7821354928234970542?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/7821354928234970542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=7821354928234970542' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7821354928234970542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7821354928234970542'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/10/evil-maid-pwnie-for-overhyped-bug.html' title='Evil Maid - Pwnie for Overhyped bug'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-7463015373356907924</id><published>2009-07-30T09:55:00.000-07:00</published><updated>2009-07-30T10:21:59.087-07:00</updated><title type='text'>R.I.P - Fravia, the master</title><content type='html'>Fravia (Fjalar Ravia) from Germany is amongst one of the most finest and brave human beings on this planet. He was an ardent reverse-engineer and a master at what he did. In early 2005/06 he gravitated on to search related stuff. He's a good friend and a great guy personally... I didn't know he was dead until I was talking to a friend on RCE.&lt;br /&gt;&lt;br /&gt;Without your teachings, emails and your website, I will not be where I am today.&lt;br /&gt;&lt;br /&gt;R.I.P Fravia, the brave may not live forever, but the cautious don't live at all !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-7463015373356907924?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/7463015373356907924/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=7463015373356907924' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7463015373356907924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7463015373356907924'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/07/rip-fravia-master.html' title='R.I.P - Fravia, the master'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-478857997450085247</id><published>2009-05-04T02:27:00.000-07:00</published><updated>2009-05-04T02:37:33.459-07:00</updated><title type='text'>Warning: Don't be conned</title><content type='html'>Warning: Don't be conned&lt;br /&gt;&lt;br /&gt;This POST is about an exceptionally serious issue, so don't be conned, or fall prey to impostors, and bad guys...&lt;br /&gt;&lt;br /&gt;Message:&lt;br /&gt;&lt;br /&gt;Don't dial 90# or 09#, #09 or any other combination requested by any technician / serviceman CLAIMING TO BE from your subscriber, on Nokia, and Motorola mobiles these codes are used by telephone service men to test line connectivity, these codes can also steal your number, and enable the caller to use your mobile to make calls, and bill it on your number.&lt;br /&gt;&lt;br /&gt;Technically,the caller can SPOOF HIS NUMBER to make calls, which will be routed through and billed on your number so stay alert, terrorists have used these type of conning tricks in the past,and use it now so be careful, and spread the word ...&lt;br /&gt;&lt;br /&gt;The information has been confirmed, by Nokia, Motorola, and CNN websites.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-478857997450085247?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/478857997450085247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=478857997450085247' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/478857997450085247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/478857997450085247'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/05/warning-dont-be-conned.html' title='Warning: Don&apos;t be conned'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2429365819209822052</id><published>2009-04-25T22:03:00.000-07:00</published><updated>2009-04-25T22:17:14.131-07:00</updated><title type='text'>Getting passwords with P2P</title><content type='html'>Getting passwords with p2p softwares&lt;br /&gt;(Limewire/Bearshare/Kazaa/Shareaza/emule)&lt;br /&gt;&lt;br /&gt;1. First you need to get any p2p software,download it with the crack.&lt;br /&gt;2. When you get bearshare and have set it up, click the Search button.&lt;br /&gt;3. Click on 'Documents' in the search section, and type anything like: My Passwords,Yahoo Passwords, Ebay Passwords, My Passes, Rapidshare Pass,XXX Pass, your best bet is My Passwords.txt&lt;br /&gt;4. Now the syntax : &lt;string&gt; Passwords or pass , you can include txt extension if required.&lt;br /&gt;5. Search and download the files and you can see clear text passwords.&lt;br /&gt;&lt;br /&gt;How is this possible?&lt;br /&gt;Simple answer, most p2p are illegal, they share your whole hd even if you set restrictions to prevent the sharing of entire hd or ur best collections.&lt;br /&gt;&lt;br /&gt;Wrote this a while ago, in some forum (this is from my 2006 scribbling), the funny thing is&lt;br /&gt;"it still works!"&lt;br /&gt;&lt;br /&gt;/Quit&lt;/string&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2429365819209822052?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2429365819209822052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2429365819209822052' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2429365819209822052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2429365819209822052'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/04/getting-passwords-with-p2p.html' title='Getting passwords with P2P'/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-8565091703778318940</id><published>2009-04-23T22:35:00.000-07:00</published><updated>2009-04-23T22:43:44.651-07:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/SfFQ8Tx6vBI/AAAAAAAAANo/hGdn4sP9FGo/s1600-h/recession.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 213px;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/SfFQ8Tx6vBI/AAAAAAAAANo/hGdn4sP9FGo/s320/recession.jpg" alt="" id="BLOGGER_PHOTO_ID_5328128831188024338" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Recession ? Okay, but still cigarettes, gutkha, and beers cost the same amount ... ;)&lt;br /&gt;&lt;br /&gt;Recession isn't something amazing, it's just another rough patch ... Get over it already!&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-8565091703778318940?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/8565091703778318940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=8565091703778318940' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8565091703778318940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8565091703778318940'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/04/recession-okay-but-still-cigarettes.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_0mC8VRRkEdE/SfFQ8Tx6vBI/AAAAAAAAANo/hGdn4sP9FGo/s72-c/recession.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2292007662475221637</id><published>2009-03-07T14:31:00.000-08:00</published><updated>2009-03-07T14:54:59.497-08:00</updated><title type='text'></title><content type='html'>How to get Examworx dumps for FREE, with a specially crafted URL (similar to my &lt;a href="http://kishfellow.blogspot.com/2007/07/actual-tests-website-bug-specially.html"&gt;Actualtests bug&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Example PoC: http://www.examworx.com/qadownsession365/BE-100W.exe&lt;br /&gt;&lt;br /&gt;URL syntax: http://www.examworx.com/qadownsession365/&lt;exam-code&gt;exam-code.exe&lt;br /&gt;&lt;br /&gt;Demos are hosted within the demo directory, as for the earlier example:&lt;br /&gt;http://www.examworx.com/qadownsession365/demo\BE-100W.exe&lt;br /&gt;&lt;br /&gt;Screenshot&lt;br /&gt;&lt;br /&gt;&lt;/exam-code&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/SbL7IIwIPbI/AAAAAAAAAMk/PM7pEkQMmZ0/s1600-h/examworx_bug.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 182px;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/SbL7IIwIPbI/AAAAAAAAAMk/PM7pEkQMmZ0/s320/examworx_bug.png" alt="" id="BLOGGER_PHOTO_ID_5310583027830111666" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;exam-code&gt;&lt;br /&gt;Examworx is usually, a Pass4sure clone, but no guarantees !&lt;br /&gt;Why pay for the dumps, when you can practically download them for FREE ;)&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;/exam-code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2292007662475221637?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2292007662475221637/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2292007662475221637' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2292007662475221637'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2292007662475221637'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/03/how-to-get-examworx-dumps-for-free-with.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_0mC8VRRkEdE/SbL7IIwIPbI/AAAAAAAAAMk/PM7pEkQMmZ0/s72-c/examworx_bug.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2529035977797861365</id><published>2009-02-27T08:54:00.001-08:00</published><updated>2009-02-27T08:58:09.110-08:00</updated><title type='text'></title><content type='html'>My good friend and fellow hacker, Digi from Crimemachine has been chosen to as &lt;a href="http://www.vmware.com/communities/vexpert/"&gt;VMWare vExpert&lt;/a&gt;. Only 300 people in the world have made it to the list... John Troyer of VMWare will publish the list sooner or later, on the website, and there's exclusive access to VMworld materials, and more in a private community just for these vetted list of vExperts.&lt;br /&gt;&lt;br /&gt;I sincerely wish him, the best of luck to succeed in more of his endeavors with VMware and his consulting projects !&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2529035977797861365?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2529035977797861365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2529035977797861365' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2529035977797861365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2529035977797861365'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2009/02/my-good-friend-and-fellow-hacker-digi.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-7977015182979627448</id><published>2008-10-10T19:57:00.000-07:00</published><updated>2008-10-14T19:22:33.204-07:00</updated><title type='text'></title><content type='html'>Worked @ _some company_&lt;some&gt; for 15 months, it was quite an experience ;)&lt;br /&gt;&lt;br /&gt;Now Iam back to normal ... or what's normal for me, to freelance, and consult in security just like old times. These days Iam consulting on Open Source, Linux, Virtualization, Network Monitoring/Analysis, Digital Security (not limited to Network Security) but also includes services like Forensics (Host, and Network), Incident Response, Web Security (App, Server, Services) ...&lt;br /&gt;&lt;br /&gt;We also provide value added services, and sell security advisories, industry grade exploits, and malware signatures for your IDS/IPS. We also provide malware "source code" if you want in bulk or any specific sample that you require.&lt;br /&gt;&lt;br /&gt;If you're looking out for any of these services, shoot me an email !&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;/some&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-7977015182979627448?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/7977015182979627448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=7977015182979627448' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7977015182979627448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/7977015182979627448'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2008/10/worked-for-15-months-now-iam-back-to.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-8478310180349468990</id><published>2008-10-02T04:36:00.000-07:00</published><updated>2008-10-02T04:38:13.904-07:00</updated><title type='text'></title><content type='html'>As many people think Iam dead ... I just want to remind you guys that I'm still up and running ...&lt;br /&gt;&lt;br /&gt;This blog is not dead, will try and post content from time to time ...&lt;br /&gt;But life these days has a lot more to do than with computers, security, and blogging ...&lt;br /&gt;&lt;br /&gt;Thanks to the anonymous friend, who asked if I'm still here ... The answer is YES :)&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-8478310180349468990?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/8478310180349468990/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=8478310180349468990' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8478310180349468990'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8478310180349468990'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2008/10/as-many-people-think-iam-dead.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2736001111761264277</id><published>2008-01-31T00:11:00.000-08:00</published><updated>2008-01-31T00:21:58.471-08:00</updated><title type='text'></title><content type='html'>Just nitpicked a small xss, which could've been spotted by anybody.&lt;br /&gt;&lt;br /&gt;Code quality: Worse&lt;br /&gt;Bug class: XSS&lt;br /&gt;Exploitable: Yes&lt;br /&gt;&lt;a href="http://sitelife.us.reuters.com/ver1.0/Direct/Process?jsonRequest=%7B%22UniqueId%22%3A0%2C%22Requests%22%3A%5B%7B%22UpdateArticleAction%22%3A%7B%22UpdateArticle%22%3A%7B%22ArticleKey%22%3A%7B%22Key%22%3A%22USL2733740320080127%22%7D%7D%2C%22OnPageUrl%22%3A%22http%3A%2F%2Fwww.reuters.com%2Farticle%2FousivMolt%2FidUSL2733740320080127%22%2C%22OnPageTitle%22%3A%22FACTBOX%3A+Rise+and+fall+of+the+SocGen+rogue+trader%22%2C%22Section%22%3A%7B%22Section%22%3A%7B%22Name%22%3A%22Main_US%22%7D%7D%2C%22Categories%22%3A%5B%7B%22Category%22%3A%7B%22Name%22%3A%22ousivMolt%22%7D%7D%5D%7D%7D%2C%7B%22ArticleKey%22%3A%7B%22Key%22%3A%22USL2733740320080127%22%7D%7D%5D%7D "&gt;&lt;br /&gt;Here is the Original URL&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.reuters.com/article/ousivMolt/idUSL2733740320080127?sp=true"&gt;XSS URL which "could" be malicious, this one's absolutely not, so don't worry &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You know, it's been too long since I posted here. I have three blogs...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.offensivecomputing.net/?q=blog/663"&gt;Offensive Computing&lt;/a&gt;: I have a small blog there&lt;br /&gt;&lt;a href="http://youdailydose.blogspot.com"&gt;Your Daily Dose of Jokes&lt;/a&gt; : Oh, Yeah, I know about humor too...&lt;br /&gt;&lt;br /&gt;Last but not least, &lt;a href="http://kishfellow.blogspot.com"&gt;my own web log&lt;/a&gt;, which is primary place for posting stuff.&lt;br /&gt;&lt;br /&gt;These days Iam left with a lot less spare time than 6 months back, when I was freelancing... I'll just hope to stay up and post something from time to time here.&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2736001111761264277?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2736001111761264277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2736001111761264277' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2736001111761264277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2736001111761264277'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2008/01/just-nitpicked-small-xss-which-couldve.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-221426567882526769</id><published>2008-01-30T22:42:00.000-08:00</published><updated>2008-01-30T22:56:20.596-08:00</updated><title type='text'></title><content type='html'>"Hacker Safe" Site Hacked, Data Stolen - Or not so hacker safe&lt;br /&gt;http://www.cioinsight.com/article2/0,1540,2246925,00.asp&lt;br /&gt;&lt;br /&gt;New skype vulnerability with PoC&lt;br /&gt;http://www.critical.lt/?opinions/show/1470&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-221426567882526769?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/221426567882526769/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=221426567882526769' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/221426567882526769'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/221426567882526769'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2008/01/hacker-safe-site-hacked-data-stolen-or.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2092304715855997432</id><published>2007-11-27T22:31:00.000-08:00</published><updated>2007-11-27T22:44:54.048-08:00</updated><title type='text'></title><content type='html'>Few good links that can help you unbrick your iPhone.&lt;br /&gt;&lt;br /&gt;Nice facts here, &lt;a href="http://www.tuaw.com/2007/09/28/5-things-you-need-to-know-about-the-iphone-1-1-1-update/"&gt;5 things you need to know about the iPhone&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;My 5 steps to unbrick the iPhone would be to ...&lt;br /&gt;&lt;a href="http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/061-3823.20070821.vormd/iPhone1,1_1.0.2_1C28_Restore.ipsw"&gt;Download the 1.0.2 image&lt;/a&gt; from Apple's website&lt;br /&gt;Use home + power button to get to the restore screen&lt;br /&gt;&lt;a href="http://iphone.fiveforty.net/wiki/index.php/Downgrade_from_1.1.1_to_1.0.2"&gt;Restore your phone's firmware&lt;/a&gt; image from updated version to 1.0.2&lt;br /&gt;Then add a contact with the jailbreak and upload anySIM to your iPhone as shown &lt;a href="http://www.winandmac.com/mobile/iphone/win-ultimate-guide-to-unlock-iphone-111-for-free/"&gt; &gt;&gt; here &lt;&lt; &lt;/a&gt;&lt;br /&gt;Last but not least, take sometime to read &lt;a href="http://iphone.fiveforty.net/wiki/index.php/Main_Page"&gt;the iPhone wiki&lt;/a&gt; which as plethora of information that will come in handy down the road.&lt;br /&gt;&lt;br /&gt;Files that you'd require for the process can be found &lt;a href="http://dc.shade.sh/iphone/"&gt; &gt;&gt; here &lt;&lt; &lt;/a&gt;, arranged neatly.&lt;br /&gt;&lt;br /&gt;Have fun hackin your phone.&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2092304715855997432?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2092304715855997432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2092304715855997432' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2092304715855997432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2092304715855997432'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/11/few-good-links-that-can-help-you.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2683026725177755711</id><published>2007-10-31T23:08:00.000-07:00</published><updated>2009-03-07T14:38:11.280-08:00</updated><title type='text'></title><content type='html'>It's XSS snack time of the day...&lt;br /&gt;&lt;br /&gt;Paypal is secure, you can use it for all transactions... Recommended by HackerSafe seal&lt;br /&gt;&lt;blockquote&gt;https://mobile.paypal.com/cgi-bin/wapapp?cmd=_wapapp-static&amp;amp;page=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E &lt;/blockquote&gt;&lt;br /&gt;While I was messing with the website, I came across this XSS bug in Paypal, which can be used with Javascript to steal passwords ;))&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2683026725177755711?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2683026725177755711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2683026725177755711' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2683026725177755711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2683026725177755711'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/10/new-paypal-xss.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-1449883865601861136</id><published>2007-10-29T04:35:00.001-07:00</published><updated>2007-10-29T04:35:46.310-07:00</updated><title type='text'></title><content type='html'>Google chat can be blocked, without blocking google.com on the whole.You must block chatenabled.mail.google.com with the ports 443 and 80 to talk.google.com.Linux users can use iptables to redirect the traffic to 127.0.0.1 (your local loopback address) You can also use the old fashioned /etc/hosts for the same...&lt;br /&gt;&lt;br /&gt;I had to write this post here, because there's been a lot of attention to blocking google's chat lately.&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-1449883865601861136?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/1449883865601861136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=1449883865601861136' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/1449883865601861136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/1449883865601861136'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/10/google-chat-can-be-blocked-without.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-8272754566145871487</id><published>2007-10-14T00:03:00.000-07:00</published><updated>2010-03-18T22:27:58.854-07:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/RxG_YIWUoUI/AAAAAAAAAGI/9fy7tmLcHhI/s1600-h/confinvite.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/RxG_YIWUoUI/AAAAAAAAAGI/9fy7tmLcHhI/s320/confinvite.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5121084672575840578" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I was invited to speak in LegionSec 07 conference, but due to professional engagements, Iam unable to deliver the talk as promised. The conference organizer has been informed about the glitch.&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-8272754566145871487?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/8272754566145871487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=8272754566145871487' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8272754566145871487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8272754566145871487'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/10/i-was-invited-to-speak-in-legionsec-07.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/RxG_YIWUoUI/AAAAAAAAAGI/9fy7tmLcHhI/s72-c/confinvite.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-8481564512997289306</id><published>2007-09-16T09:24:00.000-07:00</published><updated>2007-09-16T09:34:02.658-07:00</updated><title type='text'></title><content type='html'>THE website is back, yes, the one and only &lt;a href="http://www.crimemachine.com/aboutus.htm"&gt;CRIMEMACHINE&lt;/a&gt; !&lt;br /&gt;&lt;br /&gt;Refused by heaven, and feared by hell ... http://www.crimemachine.com&lt;br /&gt;&lt;br /&gt;Keep watching for a few or more updates to the site from time to time.&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-8481564512997289306?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/8481564512997289306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=8481564512997289306' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8481564512997289306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/8481564512997289306'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/09/website-is-back-yes-one-and-only.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-9197511174337862137</id><published>2007-09-08T11:10:00.000-07:00</published><updated>2008-12-10T01:43:36.774-08:00</updated><title type='text'></title><content type='html'>The code displayed below is from &lt;a href="http://www.borderware.com/products/mxtreme/"&gt;MXtreme firewall&lt;/a&gt;, and this is a perfect example how NOT to code a web page, especially for an appliance as critical as this... Possibly a 0day ;)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/RuLmPjxUrjI/AAAAAAAAAFk/xLtyBHJBkKA/s1600-h/0day-bug.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/RuLmPjxUrjI/AAAAAAAAAFk/xLtyBHJBkKA/s400/0day-bug.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5107898082366107186" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-9197511174337862137?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/9197511174337862137/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=9197511174337862137' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/9197511174337862137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/9197511174337862137'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/09/mxtreme-firewall-code-displayed-below.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_0mC8VRRkEdE/RuLmPjxUrjI/AAAAAAAAAFk/xLtyBHJBkKA/s72-c/0day-bug.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-4826300739014524971</id><published>2007-07-25T07:02:00.000-07:00</published><updated>2008-12-10T01:43:36.866-08:00</updated><title type='text'></title><content type='html'>A picture of the M927 warhead, containing 2.63 kg of TNT explosive filling.This cartridge is designed to be used with the Howitzers used by U.S. National Army guard's light artillery forces.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/RqdZH9VCcSI/AAAAAAAAAFc/n6FYhgXkf8s/s1600-h/m927_105mm.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/RqdZH9VCcSI/AAAAAAAAAFc/n6FYhgXkf8s/s400/m927_105mm.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5091135897022394658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This &lt;a href="http://www.theregister.co.uk/2007/07/23/mpack_developer_interview/"&gt;article talks about a web-exploitation toolkit&lt;/a&gt;, which is Mpack. The comments are really funny, it was a good read, the article is originally from Security Focus website.&lt;br /&gt;&lt;br /&gt;I personally feel the russian programmers, from DCT have come no close to this invention for destructive usage ;)&lt;br /&gt;&lt;br /&gt;PS: Iam not supporting them, it's just that the whole issue is funny.&lt;br /&gt;&lt;br /&gt;Then again it could be &lt;a href="http://www.theregister.co.uk/2007/06/18/hijacked_sites_install_malware/"&gt;equally destructive&lt;/a&gt; like the m927, ahem !&lt;br /&gt;&lt;br /&gt;As per one of the comments, from the article, &lt;br /&gt;"It's just software deal with it", and that is all there is to it, period. &lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-4826300739014524971?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/4826300739014524971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=4826300739014524971' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4826300739014524971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4826300739014524971'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/07/picture-of-m927-warhead-containing-2.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_0mC8VRRkEdE/RqdZH9VCcSI/AAAAAAAAAFc/n6FYhgXkf8s/s72-c/m927_105mm.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-21562996906076896</id><published>2007-07-20T09:04:00.000-07:00</published><updated>2008-12-10T01:43:37.408-08:00</updated><title type='text'></title><content type='html'>&lt;span style="font-weight:bold;"&gt;Actual tests website bug ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A specially crafted url can grab the "Exact" file from the site, &lt;br /&gt;that's sold, for FREE :D&lt;br /&gt;&lt;br /&gt;PoC CCNA : http://downloads.actualtests.com/Pdf-Down/uploads/640-801.zip&lt;br /&gt;&lt;br /&gt;hint: replace 640-801 with your favorite exam number, and get it for free &lt;br /&gt;&lt;br /&gt;BTW, with stuff like this why would people want to register for the Actual Tests Subscription that costs 99 USD... Then again, Iam not that smart ... hehe !&lt;br /&gt;&lt;br /&gt;Bug reported ... and screenshot attached below.&lt;br /&gt;&lt;br /&gt;Bug1 - Actual tests website, main&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDlFVh4n7I/AAAAAAAAAFE/zP74ZYtpHU4/s1600-h/bug1.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDlFVh4n7I/AAAAAAAAAFE/zP74ZYtpHU4/s400/bug1.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5089319458770034610" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Bug2 - Actual tests website, sub-domain&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDlTVh4n8I/AAAAAAAAAFM/YWAGDqYNJFA/s1600-h/bug2.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDlTVh4n8I/AAAAAAAAAFM/YWAGDqYNJFA/s400/bug2.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5089319699288203202" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;PS: We can offer ACTUAL TESTS a web penetration test if they're interested.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDmzVh4n9I/AAAAAAAAAFU/n_tdmpq0EnI/s1600-h/email1.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDmzVh4n9I/AAAAAAAAAFU/n_tdmpq0EnI/s400/email1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5089321348555644882" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-21562996906076896?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/21562996906076896/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=21562996906076896' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/21562996906076896'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/21562996906076896'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/07/actual-tests-website-bug-specially.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/RqDlFVh4n7I/AAAAAAAAAFE/zP74ZYtpHU4/s72-c/bug1.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-357216871181086653</id><published>2007-06-23T02:25:00.000-07:00</published><updated>2007-06-23T02:27:22.362-07:00</updated><title type='text'></title><content type='html'>A random line from my arsenal of quotes ...&lt;br /&gt;&lt;br /&gt;HE'S A PEOPLE SPECIALIST, THAT'S WHY HE GOT CONNED ! :))&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-357216871181086653?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/357216871181086653/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=357216871181086653' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/357216871181086653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/357216871181086653'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/06/random-line-from-my-arsenal-of-quotes.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-1806999086588691351</id><published>2007-05-28T10:56:00.000-07:00</published><updated>2008-12-10T01:43:37.513-08:00</updated><title type='text'></title><content type='html'>Time for serving today's pwnsauce (morning_wood* tm), hehe !&lt;br /&gt;&lt;br /&gt;Just to prove my re-phrasing right in the previous post, www.appinonline.com comes with a few or more XSS, SQL injection, and buffer overflow bugs ... lol !&lt;br /&gt;&lt;br /&gt;They got almost 45 patterns of XSS, 5 patterns of SQL injection, including numeric and string input/multiple input types ... They provide security for top companies, and here's a photograph of their great president, Mr.Rajat Khare ...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/Rlsg2fuzkHI/AAAAAAAAAE8/hPcUTp3rocc/s1600-h/appin_endorsedby_president.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/Rlsg2fuzkHI/AAAAAAAAAE8/hPcUTp3rocc/s400/appin_endorsedby_president.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5069681926138466418" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;PS: They provide WEB-SECURITY, AND APPLICATION SECURITY ... WOW !&lt;br /&gt;Wonder how good they're ?? Here's the proof &lt;br /&gt;&lt;br /&gt;PPS: It also proves my argument, that all graduates aren't intelligent, not even the ones from IIT.&lt;br /&gt;&lt;br /&gt;In the end, we see that, even today ... the cobbler still goes barefoot ;)&lt;br /&gt;&lt;br /&gt;This also goes to say, the security product / vendor / service providers themselves need some security to start with ... and who knows, time will tell if this company can survive the harsh lashes from the cruel media...&lt;br /&gt;&lt;br /&gt;Reported the stuff to him :)&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-1806999086588691351?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/1806999086588691351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=1806999086588691351' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/1806999086588691351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/1806999086588691351'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/05/time-for-serving-todays-pwnsauce.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_0mC8VRRkEdE/Rlsg2fuzkHI/AAAAAAAAAE8/hPcUTp3rocc/s72-c/appin_endorsedby_president.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-6367805519709132992</id><published>2007-05-25T07:06:00.000-07:00</published><updated>2007-05-25T07:23:13.135-07:00</updated><title type='text'></title><content type='html'>Quote from "For a few dollars more" , 1960 something ...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;In this world where life has no value, death sometimes has it's price...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I tried to rephrase this for Infosec, hehe ! :P&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;In this world where a computer's data has no value, a break-in sometimes has it's price.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;That's why the hackers sprung up ... &lt;br /&gt;&lt;br /&gt;The loss of customer/client/consumer, and bad public-relations ... lol, a news brief will be "almost mean the end" of a company in mainstream IT.&lt;br /&gt;&lt;br /&gt;/Quit, enough of blaming&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-6367805519709132992?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/6367805519709132992/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=6367805519709132992' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/6367805519709132992'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/6367805519709132992'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/05/in-this-world-where-life-has-no-value.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-4322628885128704682</id><published>2007-05-20T10:04:00.000-07:00</published><updated>2008-12-10T01:43:37.748-08:00</updated><title type='text'></title><content type='html'>We present to you ... www.usablesecurity.com !&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/RlCAhvuzkGI/AAAAAAAAAE0/n2mg6s0cM-A/s1600-h/usablesec.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/RlCAhvuzkGI/AAAAAAAAAE0/n2mg6s0cM-A/s400/usablesec.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5066690898028630114" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Security blog's XSS ;)&lt;br /&gt;&lt;br /&gt;Ironically their page has their last post on "phishing" and "Open ID"...&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-4322628885128704682?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/4322628885128704682/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=4322628885128704682' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4322628885128704682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4322628885128704682'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/05/we-present-to-you.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/RlCAhvuzkGI/AAAAAAAAAE0/n2mg6s0cM-A/s72-c/usablesec.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2908516514218658742</id><published>2007-05-20T09:14:00.002-07:00</published><updated>2008-12-10T01:43:38.156-08:00</updated><title type='text'></title><content type='html'>Presenting the XSS Trio ;)&lt;br /&gt;&lt;br /&gt;Site: www.googlefont.com, www.netscape.com, and www.mtv.com&lt;br /&gt;Multiple XSS bugs&lt;br /&gt;Risk: High&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/RlB6I_uzkDI/AAAAAAAAAEc/y61qTTkNDsQ/s1600-h/Googlefont_XSS.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/RlB6I_uzkDI/AAAAAAAAAEc/y61qTTkNDsQ/s400/Googlefont_XSS.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5066683875757101106" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Google font - XSS&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/RlB6S_uzkEI/AAAAAAAAAEk/0zrtOaHTtvE/s1600-h/netscape_xss.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/RlB6S_uzkEI/AAAAAAAAAEk/0zrtOaHTtvE/s400/netscape_xss.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5066684047555792962" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Netscape XSS&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/RlB6gPuzkFI/AAAAAAAAAEs/ODgsgd8uuwA/s1600-h/m-tv_xss.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/RlB6gPuzkFI/AAAAAAAAAEs/ODgsgd8uuwA/s400/m-tv_xss.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5066684275189059666" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Mtv.com - nice music channel !&lt;br /&gt;&lt;br /&gt;XSS is not an ordinary threat anymore which can just bring pop-ups, advanced and planned attacks, XSS worms like the myspace one, and nice shellcodes (like the ones showed by bill hoffman of SPI @ shmoocon are examples of ... sophistication in this area) And we can't forget XSS Proxy ... uauauauauauaua !&lt;br /&gt;&lt;br /&gt;/Ph33r to click ...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2908516514218658742?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2908516514218658742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2908516514218658742' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2908516514218658742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2908516514218658742'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/05/presenting-xss-trio-site-www_20.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_0mC8VRRkEdE/RlB6I_uzkDI/AAAAAAAAAEc/y61qTTkNDsQ/s72-c/Googlefont_XSS.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-137009684553098571</id><published>2007-05-08T04:54:00.000-07:00</published><updated>2007-05-08T05:02:44.072-07:00</updated><title type='text'></title><content type='html'>Hew Griffith, the ex-DoD council member, has been extradited to the USA for sentencing.&lt;br /&gt;Personally I feel he must have had his chances to serve time in Australia.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.theage.com.au/news/national/australia-hands-over-man-to-us-courts/2007/05/06/1178390140855.html"&gt;Read the full story here...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-137009684553098571?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/137009684553098571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=137009684553098571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/137009684553098571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/137009684553098571'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/05/hew-griffith-ex-dod-council-member-has.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-760360718946203114</id><published>2007-05-03T03:24:00.000-07:00</published><updated>2007-05-03T03:27:29.157-07:00</updated><title type='text'></title><content type='html'>Quoted from &lt;a href="http://arstechnica.com/news.ars/post/20070502-student-creates-counter-strike-map-gets-kicked-out-of-school.html"&gt;ArsTechnica&lt;/a&gt;, a kid got kicked outta school for creating a counter-strike map of the school... sounds funny, but logical as well, seems as though schools are on high alert, after the massacre at Virginia Tech...&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-760360718946203114?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/760360718946203114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=760360718946203114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/760360718946203114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/760360718946203114'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/05/quoted-from-arstechnica-kid-got-kicked.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-781996669041751812</id><published>2007-03-22T18:55:00.000-07:00</published><updated>2008-12-10T01:43:38.302-08:00</updated><title type='text'></title><content type='html'>Full headers of the phishing email ...&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;X-Apparently-To:  &lt;my_email&gt;@yahoo.com via 209.191.87.92; Thu, 22 Mar 2007 01:38:34 -0700&lt;br /&gt;X-YahooFilteredBulk: 64.151.53.220&lt;br /&gt;X-Originating-IP: [64.151.53.220]&lt;br /&gt;Return-Path: &lt;service@paypal.com&gt;&lt;br /&gt;Authentication-Results: mta222.mail.re3.yahoo.com from=paypal.com; domainkeys=neutral (no sig)&lt;br /&gt;Received: from 64.151.53.220 (HELO 192.168.1.252) (64.151.53.220) by mta222.mail.re3.yahoo.com with SMTP; Thu, 22 Mar 2007 01:38:34 -0700&lt;br /&gt;Received: from 60.76.174.246 by ; Thu, 22 Mar 2007 04:35:46 -0500&lt;br /&gt;Message-ID: &lt;FBHLUTXOJYHOOHCZYTQLPVSWE@aol.com&gt;&lt;br /&gt;From: "service@paypal.com" &lt;service@paypal.com&gt;&lt;br /&gt;Reply-to: "service@paypal.com" &lt;service@paypal.com&gt;&lt;br /&gt;To: &lt;my_email&gt;@yahoo.com&lt;br /&gt;Subject: Compromised PayPal Account&lt;br /&gt;Date: Thu, 22 Mar 2007 13:35:46 +0400&lt;br /&gt;X-Mailer: Microsoft Outlook Express 5.50.4522.1200&lt;br /&gt;MIME-Version: 1.0&lt;br /&gt;Content-Type: multipart/alternative; boundary="--202896902971285"&lt;br /&gt;X-Priority: 1&lt;br /&gt;X-MSMail-Priority: High&lt;br /&gt;Content-Length: 1308&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/RgM2zt0zwYI/AAAAAAAAADs/FvhHm7GrnZo/s1600-h/paypal_phishing1.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/RgM2zt0zwYI/AAAAAAAAADs/FvhHm7GrnZo/s400/paypal_phishing1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5044936269687406978" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is a very bad way to send "scam" emails. Honestly no "smart" phisher would send his emails from AOL.com and using Outlook express... Why do all people want Paypal... ??&lt;br /&gt;&lt;br /&gt;LOL !&lt;br /&gt;&lt;br /&gt;How does this work ? &lt;br /&gt;The phisher redirects the user to his host pointed with the arrow, rather than paypal, and collects data for his "own profit"&lt;br /&gt;&lt;br /&gt;Reported to a &lt;a href="http://www.antiphishing.org"&gt;APWG&lt;/a&gt; &amp; &lt;a href="http://www.f-secure.com/weblog/"&gt;F-Secure&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;What can you do ? Don't click on the link blindly, take a minute to check the status bar, and copy/paste links on your browser, if you're suspicious of the person who sent this, then send it to reportphishing &gt;at&lt; antiphishing &gt;dot&lt; org&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-781996669041751812?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/781996669041751812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/781996669041751812'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/03/full-headers-of-phishing-email.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_0mC8VRRkEdE/RgM2zt0zwYI/AAAAAAAAADs/FvhHm7GrnZo/s72-c/paypal_phishing1.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-5732521410604322506</id><published>2007-03-10T20:07:00.000-08:00</published><updated>2007-03-11T01:09:28.313-08:00</updated><title type='text'></title><content type='html'>Update from jf -at- danglingpointers -dot- net.&lt;br /&gt;&lt;br /&gt;Seems the variable name was &lt;a href="http://www.google.com/search?hl=en&amp;q=intext%3A%22wgBreakFrames%22&amp;btnG=Google+Search"&gt;googled&lt;/a&gt; a bit, and apparently it was a considered a vulnerability, not just a bug... if the wiki was embedded in another frame, the by injecting javascript the attack can occur.So that's what was shown below in the code(see previous blog post).The Authors have anyhow disabled it by default in newer versions of the wiki software.&lt;br /&gt;&lt;br /&gt;My bit, is that I have just been digging code decently.We will conclude that I found a bug in OWASP website.(&lt;a href="http://www.conpec.com.br/wiki/RELEASE-NOTES"&gt;which was considered a vulnerability in the past&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-5732521410604322506?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/5732521410604322506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=5732521410604322506' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/5732521410604322506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/5732521410604322506'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/03/update-from-jf-at-danglingpointers-dot.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-3359312449403526652</id><published>2007-03-10T09:08:00.000-08:00</published><updated>2008-12-10T01:43:38.607-08:00</updated><title type='text'></title><content type='html'>Is OWASP vulnerable ?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/RfLn4hLUMgI/AAAAAAAAADU/Q-ocfi6jFCM/s1600-h/not-defined.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/RfLn4hLUMgI/AAAAAAAAADU/Q-ocfi6jFCM/s320/not-defined.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5040345891145527810" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Check this out, the code shown above has the variable wgBreakFrames as undefined.&lt;br /&gt;&lt;br /&gt;I expect some feedback on the same... Posted to full disclosure list.&lt;br /&gt;&lt;br /&gt;The wgBreakFrames variable is vulnerable to injection... &lt;br /&gt;It is confirmed just as a bug, with minimal impact,not a vulnerability.&lt;br /&gt;There could probably be attacks if we could inject javascript in the window.&lt;br /&gt;&lt;br /&gt;I would like to thank, jf -at- danglingpointers -dot- net &amp; andfarm -at- gmail -dot- com, for the assistance provided through the Full-disclosure list :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Full-Disclosure - We believe in it !&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;Kish&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-3359312449403526652?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/3359312449403526652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=3359312449403526652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/3359312449403526652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/3359312449403526652'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/03/is-owasp-vulnerable-check-this-out-code.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_0mC8VRRkEdE/RfLn4hLUMgI/AAAAAAAAADU/Q-ocfi6jFCM/s72-c/not-defined.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2725426490464922183</id><published>2007-03-04T21:19:00.000-08:00</published><updated>2008-12-10T01:43:38.992-08:00</updated><title type='text'></title><content type='html'>Site: www.techworks.in &lt;br /&gt;Multiple XSS bugs&lt;br /&gt;Risk: Medium-High&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/ReuqcbgmxwI/AAAAAAAAADE/dlybqmC54N4/s1600-h/xss.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/ReuqcbgmxwI/AAAAAAAAADE/dlybqmC54N4/s320/xss.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5038308013541607170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;They're ""Official EC-Council distributor, India""&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/Reur5rgmxxI/AAAAAAAAADM/6UX1Fgxm-g8/s1600-h/email.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/Reur5rgmxxI/AAAAAAAAADM/6UX1Fgxm-g8/s320/email.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5038309615564408594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Full-Disclosure - We believe in it ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2725426490464922183?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2725426490464922183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2725426490464922183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2725426490464922183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2725426490464922183'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/03/site-www.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_0mC8VRRkEdE/ReuqcbgmxwI/AAAAAAAAADE/dlybqmC54N4/s72-c/xss.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2384332088607675303</id><published>2007-03-01T20:25:00.000-08:00</published><updated>2007-03-02T03:23:49.025-08:00</updated><title type='text'></title><content type='html'>&lt;a href="http://www.computerdefense.org/?p=260"&gt;Originally posted &lt;/a&gt; on the 14th of Feb, Yeah, Iam sorry, late by 2 weeks. Still worth a laugh.&lt;br /&gt;&lt;br /&gt;Acunetix survey says : 70% of websites, out of it's 3200 scanned ones were &lt;a href="http://www.acunetix.com/news/security-audit-results.htm"&gt;vulnerable&lt;/a&gt; to attacks. &lt;br /&gt;&lt;br /&gt;Then, Network world and it's "go-to-guy" &lt;a href="http://www.opus1.com/jms"&gt;Joel Snyder&lt;/a&gt;, a.k.a Security expert,&lt;a href="http://www.networkworld.com/community/?q=node/11477"&gt; replies back &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thomas Ptacek, a guru at &lt;a href="http://www.matasano.com"&gt;Matasano&lt;/a&gt;, gives &lt;a href="http://www.matasano.com/log/700/joel-snyder-follows-up-matasano-provides-the-missing-subtext/"&gt;his take on the issue.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Acunetix gives back &lt;a href="http://www.acunetix.com/news/acunetix_reveals_data.htm"&gt;some statistics and it's report&lt;/a&gt;...&lt;br /&gt;&lt;br /&gt;I learnt to laugh like an Italian friend of mine, UAUAUAUAUAUAUAUAUAUAUAUAUA !!&lt;br /&gt;You must try it too ... it's fun to laugh, it's the best way to forget all your worries... &lt;br /&gt;&lt;br /&gt;Jokes apart, the truth is conveyed here humorously... You must note that somewhere in the context is mentioned, Acunetix's numbers are low ...&lt;br /&gt;&lt;br /&gt;/Ale vide&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2384332088607675303?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2384332088607675303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2384332088607675303' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2384332088607675303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2384332088607675303'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/03/originally-posted-here-on-14th-of-feb.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-2581453691914043647</id><published>2007-02-26T00:42:00.000-08:00</published><updated>2008-12-10T01:43:39.675-08:00</updated><title type='text'></title><content type='html'>Site: www.tcs.com (Tata Consultancy Services)&lt;br /&gt;Multiple SQL Injection/XSS bugs&lt;br /&gt;Risk: Medium-High&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/ReKiQO5vpPI/AAAAAAAAACQ/PHVNcWS8Ptc/s1600-h/pic2.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/ReKiQO5vpPI/AAAAAAAAACQ/PHVNcWS8Ptc/s320/pic2.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5035765733115536626" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The company which can't secure it's site is providing services on Security. WOW !!!&lt;br /&gt;http://www.tcs.com/esecurity =&gt; Check this out ;) &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/ReKh_O5vpOI/AAAAAAAAACI/GFsWFdCdw5Y/s1600-h/pic1.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/ReKh_O5vpOI/AAAAAAAAACI/GFsWFdCdw5Y/s320/pic1.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5035765441057760482" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;SQL Injection - Do you want me to be the DBA ;) ??&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/ReR-de5vpSI/AAAAAAAAAC4/uMQqI4wCSyE/s1600-h/pic4.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/ReR-de5vpSI/AAAAAAAAAC4/uMQqI4wCSyE/s320/pic4.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5036289328283624738" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cross Site Scripting - Do you see phishing coming your way ;) ??&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/ReKwdu5vpRI/AAAAAAAAACs/53FAm1b5ydk/s1600-h/pic3.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/ReKwdu5vpRI/AAAAAAAAACs/53FAm1b5ydk/s320/pic3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5035781358206559506" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I sent an email back in December 2006, they're so responsible not to fix their bugs even after 2 months. I sent the email to their Information Security Manager, Chennai, not to admin/webmaster/or any default address. No response until date (see picture)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Email sent to "Full-Disclosure - We believe in it ;)"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-2581453691914043647?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/2581453691914043647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=2581453691914043647' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2581453691914043647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/2581453691914043647'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/02/check-this-out-do-you-see-threat-tcs-i.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/ReKiQO5vpPI/AAAAAAAAACQ/PHVNcWS8Ptc/s72-c/pic2.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-5329828332962671056</id><published>2007-02-18T06:32:00.000-08:00</published><updated>2008-12-10T01:43:40.440-08:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/Rdhj38lC4RI/AAAAAAAAABo/1kX9Jis4ENQ/s1600-h/reply4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/Rdhj38lC4RI/AAAAAAAAABo/1kX9Jis4ENQ/s320/reply4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5032882396391989522" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Got a reply from them, they want to fix it now :)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/RdhjsMlC4QI/AAAAAAAAABg/dtzwbw_BM3c/s1600-h/reply3.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/RdhjsMlC4QI/AAAAAAAAABg/dtzwbw_BM3c/s320/reply3.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5032882194528526594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;My reply for their email. &lt;br /&gt;With this, Iam closing this issue. Seems they've come to terms with me :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Full-Disclosure - We believe in it ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-5329828332962671056?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/5329828332962671056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=5329828332962671056' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/5329828332962671056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/5329828332962671056'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/02/got-reply-from-them-they-want-to-fix-it.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/Rdhj38lC4RI/AAAAAAAAABo/1kX9Jis4ENQ/s72-c/reply4.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-3512938749922444014</id><published>2007-02-18T04:59:00.000-08:00</published><updated>2008-12-10T01:43:40.642-08:00</updated><title type='text'></title><content type='html'>Posted to Full-Disclosure list, copied to LegionSec&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_0mC8VRRkEdE/RdhOE8lC4PI/AAAAAAAAABU/nGQe6sOXjXg/s1600-h/fulldisc.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_0mC8VRRkEdE/RdhOE8lC4PI/AAAAAAAAABU/nGQe6sOXjXg/s320/fulldisc.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5032858430474477810" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Full-Disclosure - We believe in it&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://digg.com/security/Security_bugs_in_Security_conference_site"&gt;On a sidenote, this post got dugg !&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-3512938749922444014?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/3512938749922444014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=3512938749922444014' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/3512938749922444014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/3512938749922444014'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/02/posted-to-full-disclosure-list-copied.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_0mC8VRRkEdE/RdhOE8lC4PI/AAAAAAAAABU/nGQe6sOXjXg/s72-c/fulldisc.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-4856090516527779555</id><published>2007-02-17T19:47:00.000-08:00</published><updated>2008-12-10T01:43:40.857-08:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/RdfMcslC4NI/AAAAAAAAAA8/PhHcg7WVcmc/s1600-h/reply1.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/RdfMcslC4NI/AAAAAAAAAA8/PhHcg7WVcmc/s320/reply1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5032715901984760018" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I never expected them to reply but they did ! What a surprise ;)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0mC8VRRkEdE/RdfMp8lC4OI/AAAAAAAAABE/Rbhj4_k5Vpw/s1600-h/reply2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_0mC8VRRkEdE/RdfMp8lC4OI/AAAAAAAAABE/Rbhj4_k5Vpw/s320/reply2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5032716129618026722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So here's my reply... to them.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Full-Disclosure - We believe in it&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-4856090516527779555?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/4856090516527779555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=4856090516527779555' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4856090516527779555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/4856090516527779555'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/02/i-never-expected-them-to-reply-but-they.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_0mC8VRRkEdE/RdfMcslC4NI/AAAAAAAAAA8/PhHcg7WVcmc/s72-c/reply1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-9042415976840210216</id><published>2007-02-17T13:21:00.000-08:00</published><updated>2008-12-10T01:43:41.071-08:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0mC8VRRkEdE/Rdd_FslC4MI/AAAAAAAAAAw/DsDHIwOKb_M/s1600-h/fopen.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_0mC8VRRkEdE/Rdd_FslC4MI/AAAAAAAAAAw/DsDHIwOKb_M/s320/fopen.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5032630844452430018" /&gt;&lt;/a&gt;&lt;br /&gt;Update to my previous post :)&lt;br /&gt;&lt;br /&gt;Possibility to fetch files such as /etc/passwd&lt;br /&gt;http://www.flconferences.com/download.php?file=/legionsec_1/archive/LegionSec'06___Vicente.pdf =&gt; Example&lt;br /&gt;&lt;br /&gt;Click on the above link to see "Function.fopen"&lt;br /&gt;&lt;br /&gt;When it lists out "fopen(/hsphere/local/home/flconf/flconferences.com/user_conference/legionsec_1/archive/LegionSec\'06___Vicente.pdf"&lt;br /&gt;&lt;br /&gt;What amount of time will it take for an attacker, to manipulate this function and retrieve critical files as /etc/passwd or /etc/shadow&lt;br /&gt;&lt;br /&gt;With this kind of information in hand, the extent of damage that can be done is "maximum"&lt;br /&gt;&lt;br /&gt;Documentation for &lt;a href="http://in2.php.net/function.fopen"&gt;Function.fopen&lt;/a&gt; from PHP Website.&lt;br /&gt;&lt;span style="font-style:italic;"&gt;&lt;br /&gt;Full-Disclosure - We believe in it. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-9042415976840210216?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/9042415976840210216/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=9042415976840210216' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/9042415976840210216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/9042415976840210216'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/02/update-to-my-previous-post-possibility.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_0mC8VRRkEdE/Rdd_FslC4MI/AAAAAAAAAAw/DsDHIwOKb_M/s72-c/fopen.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-776723419545873902</id><published>2007-02-17T07:14:00.000-08:00</published><updated>2008-12-10T01:43:41.560-08:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/RddDiclC4LI/AAAAAAAAAAk/__1PizEtZx4/s1600-h/faq.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/RddDiclC4LI/AAAAAAAAAAk/__1PizEtZx4/s400/faq.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5032565367676002482" /&gt;&lt;/a&gt;&lt;br /&gt;Advisory by Kishfellow&lt;br /&gt;&lt;br /&gt;Site: www.flconferences.com (LegionSec)&lt;br /&gt;Multiple XSS vulnerabilities&lt;br /&gt;Risk: Medium-High&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0mC8VRRkEdE/RdcfYclC4KI/AAAAAAAAAAY/NnYfBvUdek8/s1600-h/email1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_0mC8VRRkEdE/RdcfYclC4KI/AAAAAAAAAAY/NnYfBvUdek8/s400/email1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5032525613458710690" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Picture says it all ...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;Full-Disclosure - We believe in it. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-776723419545873902?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/776723419545873902/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=776723419545873902' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/776723419545873902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/776723419545873902'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/02/picture-says-it-all.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_0mC8VRRkEdE/RddDiclC4LI/AAAAAAAAAAk/__1PizEtZx4/s72-c/faq.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116847305545724517</id><published>2007-01-10T15:47:00.000-08:00</published><updated>2007-02-14T12:07:23.224-08:00</updated><title type='text'></title><content type='html'>Whoa ! ... I just can't believe that I got myself a &lt;a href="http://www.boseindia.com/Product/PL117.jpg"&gt;BOSE headfone&lt;/a&gt; [considered to be really the best money can buy, for a headfone or any sound equipment]&lt;br /&gt;&lt;br /&gt;You have the "Right to laugh ;)" ... &lt;a href="http://www.bitquabit.com/2007/02/14/smart-guys-date-in-parallel/"&gt;&gt;&gt; See this post &lt;&lt;&lt;/a&gt;&lt;br /&gt;I don't believe that he is such a geek, he uses V=IR to describe parallel dating ;))&lt;br /&gt;~ Hats off to you bro ~&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116847305545724517?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116847305545724517/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116847305545724517' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116847305545724517'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116847305545724517'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/01/whoa.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116780730868264185</id><published>2007-01-02T22:45:00.000-08:00</published><updated>2007-01-02T22:55:08.703-08:00</updated><title type='text'></title><content type='html'>The new HD-DVD [High definition DVD] already cracked ?&lt;br /&gt;&lt;br /&gt;Rumors arose early on the new year that a hacker named muslix64 has compromised the encryption called AACS [both blu-ray &amp; hd-dvd use the same encryption]&lt;br /&gt;&lt;br /&gt;Read the news brief from three sources :)&lt;br /&gt;&lt;br /&gt;NewYork Times - &lt;a href="http://www.nytimes.com/2007/01/01/technology/01hack.html?ei=5088&amp;amp;en=38ddb2918d77f8a4&amp;ex=1325307600&amp;amp;partner=rssnyt&amp;emc=rss&amp;amp;pagewanted=print"&gt;&gt;&gt; Read more &lt;&lt;&lt;/a&gt;&lt;br /&gt;ComputerWorld - &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9006918&amp;amp;source=rss_topic17"&gt;&gt;&gt; Read more &lt;&lt;&lt;/a&gt;&lt;br /&gt;ZDnet - &lt;a href="http://news.zdnet.co.uk/security/0,1000000189,39285289,00.htm"&gt;&gt;&gt; Read more &lt;&lt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;On a side note, happy new year to all of you :)&lt;br /&gt;&lt;br /&gt;I heard from a friend of mine, that this year starts and ends with a monday, it has the most number of saturdays &amp;amp; sundays... and no public holidays fall on sunday. Hence, this is a new year with least working days according to the anonymous friend who informed me :)&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116780730868264185?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116780730868264185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116780730868264185' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116780730868264185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116780730868264185'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2007/01/new-hd-dvd-high-definition-dvd-already.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116737460385553671</id><published>2006-12-28T22:38:00.000-08:00</published><updated>2006-12-30T09:41:05.273-08:00</updated><title type='text'></title><content type='html'>Today as usual I booted in windows 2000 and inspected this "&lt;a href="http://www.sophos.com/virusinfo/analyses/trojerazera.html"&gt;strange&lt;/a&gt;" piece of malware [a trojan].&lt;br /&gt;&lt;br /&gt;I must really compliment the author of this malware, since he does a good job by deleting important files like mp3,mpeg,pr0n and other illegal stuff that people download off p2p software ;))&lt;br /&gt;&lt;br /&gt;Credits fly to you, whoever you are !!&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2006/05/17/killjoy_trojan/"&gt;&lt;br /&gt;Read more here ...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116737460385553671?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116737460385553671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116737460385553671' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116737460385553671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116737460385553671'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/12/today-as-usual-i-booted-in-windows.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116719116379170268</id><published>2006-12-26T19:41:00.000-08:00</published><updated>2006-12-26T19:49:15.026-08:00</updated><title type='text'></title><content type='html'>Santa gave me a lot of gifts for christmas of which two were very good,&lt;br /&gt;so Iam sharing with you people ;))&lt;br /&gt;&lt;br /&gt;Trust me, he gave me an oppurtunity to see the power of RainbowTables [ &lt;a href="http://rtables.blogspot.com/"&gt;&gt;&gt;Here &lt;&lt;&lt;/a&gt; ]&lt;br /&gt;&lt;br /&gt;Ofcourse, he gave me toys to play too ... &lt;a href="http://www.iss.net/evolvingthreat/game.html"&gt;Check this out&lt;/a&gt; ...&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116719116379170268?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116719116379170268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116719116379170268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116719116379170268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116719116379170268'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/12/santa-gave-me-lot-of-gifts-for.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116689906566134657</id><published>2006-12-23T10:24:00.000-08:00</published><updated>2006-12-23T10:37:45.673-08:00</updated><title type='text'></title><content type='html'>I was doing a bit of wifi-hacking recently... playing with toys ;-)&lt;br /&gt;&lt;br /&gt;Recommended reading =&gt; &lt;a href="http://www.blackhat.com/presentations/bh-usa-06/BH-US-06-Veyssett.pdf"&gt;Blackhat Slides&lt;/a&gt; [Laurent Butti and Franck Veysett]&lt;br /&gt;&lt;br /&gt;/me (Quit :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116689906566134657?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116689906566134657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116689906566134657' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116689906566134657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116689906566134657'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/12/i-was-doing-bit-of-wifi-hacking.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116664461339234860</id><published>2006-12-20T11:54:00.000-08:00</published><updated>2006-12-20T11:56:53.393-08:00</updated><title type='text'></title><content type='html'>I've not been with my computer for the last few days ... went out shopping, spotting and doing stuff that I don't do regularly ;)&lt;br /&gt;&lt;br /&gt;The surprising thing is I couldn't withstand touching my laptop everyday for emails. . .&lt;br /&gt;&lt;br /&gt;I just signed off the internet 8 days ago, and here Iam, back ... Back with a bang ?! Probably.&lt;br /&gt;&lt;br /&gt;I just re-energized myself and feels good to be ranting here :)&lt;br /&gt;&lt;br /&gt;/Pull D' Plug&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116664461339234860?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116664461339234860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116664461339234860' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116664461339234860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116664461339234860'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/12/ive-not-been-with-my-computer-for-last.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116532170615254095</id><published>2006-12-05T04:22:00.000-08:00</published><updated>2006-12-05T19:25:23.420-08:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger/2230/2018/1600/384755/M%26F_1-5.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger/2230/2018/320/119854/M%26F_1-5.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Muscles &amp; Fitness - Training system library is worth every penny you invest in it ...&lt;br /&gt;&lt;br /&gt;I just bought the 5 DVDs for 40 US Dollars, I think it's an incredible source for body building.&lt;br /&gt;&lt;br /&gt;I'll write more about this dvd shortly ...&lt;br /&gt;&lt;br /&gt;On a side note, weight that we gain is reversible ... Lots of things are "reversible" in life, and reversing comes naturally ;)&lt;br /&gt;&lt;br /&gt;GPS is having it's gcc toolkit ready. I have been examining the board for a while now, and coding the processor module for nintendo with the opcodes.&lt;br /&gt;&lt;br /&gt;If someone needs the opcodes for v831 processor, let me know through email.&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116532170615254095?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116532170615254095/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116532170615254095' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116532170615254095'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116532170615254095'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/12/muscles-gps-is-having-its-gcc-toolkit.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116288556455767729</id><published>2006-11-06T23:40:00.000-08:00</published><updated>2006-11-06T23:46:04.570-08:00</updated><title type='text'></title><content type='html'>http://www.videojug.com/film/how-to-fold-a-t-shirt-in-2-seconds&lt;br /&gt;&lt;br /&gt;Amazing piece of "work" ... I saw the comments section, and many people complaining about the video's speed. Use the pause button around 10-12 times in the 2 seconds when they show the folding ;)&lt;br /&gt;&lt;br /&gt;100% working, try it&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116288556455767729?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116288556455767729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116288556455767729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116288556455767729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116288556455767729'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/11/httpwww.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116252710566437533</id><published>2006-11-02T20:04:00.000-08:00</published><updated>2006-11-13T04:57:49.283-08:00</updated><title type='text'></title><content type='html'>Couple of neat pen-tests were done in the last month. This month I have a mighty big cake in my hand with over a thousand desktops and a few servers, from an organization. ;)&lt;br /&gt;&lt;br /&gt;Now about the new reverse-engg project at hand, the GPS unit. It runs on Nintendo processor.&lt;br /&gt;&lt;br /&gt;Manufacturer : NEC Corporation&lt;br /&gt;Processor Model : v831&lt;br /&gt;Addn Info: 32 bit Microprocessor&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/2230/2018/1600/NECv831.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/2230/2018/320/NECv831.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Iam still working on the details of this circuit's datasheet, as of now Iam building a GCC kit for this thingy.&lt;br /&gt;&lt;br /&gt;/Ale vide&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116252710566437533?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116252710566437533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116252710566437533' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116252710566437533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116252710566437533'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/11/couple-of-neat-pen-tests-were-done-in.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116214299335386625</id><published>2006-10-29T09:25:00.000-08:00</published><updated>2006-10-29T09:32:52.900-08:00</updated><title type='text'></title><content type='html'>Today , thoughts that traverse through my mind almost daily has come to a stop.&lt;br /&gt;Seems there is something I failed to realize ... Yes, I have realized "an important" thing&lt;br /&gt;about life. I slept the whole day and Iam blogging now. &lt;span style="font-style: italic; color: rgb(255, 102, 102);"&gt;The SL33P factor has been missing&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 102);"&gt;for the past few years of my life ... &lt;/span&gt;which I think has bothered me enough. So Iam planning&lt;br /&gt;to compensate for my misdoings now ;) ...&lt;br /&gt;&lt;br /&gt;/part&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116214299335386625?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116214299335386625/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116214299335386625' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116214299335386625'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116214299335386625'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/10/today-thoughts-that-traverse-through.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116140164827270925</id><published>2006-10-20T20:25:00.000-07:00</published><updated>2006-12-11T03:56:41.710-08:00</updated><title type='text'></title><content type='html'>News... warezov variants are making a lot of headlines in AV blogs.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 0);"&gt;Today being Diwali, here is a traditional way of saying happy diwali to all my friends here.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 0);"&gt;जलते जगमगाते रहे, हम आपको आप हमको याद आते रहे जब तक जिन्दगी है, दुआ है हमारी "आप चाँद की तरह जगमगाते रहे" दीपों के पर्व दीपावली की हार्दीक शुभकामनाएँ !!! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 0);"&gt;Ofcourse, I've got my English version too ... ;))&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; color: rgb(255, 102, 0);"&gt;I wish you all a very Happy Diwali and an even prosperous New Year&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Then I've got new toys coming my way for a fresh reverse-engineering challenge.&lt;br /&gt;&lt;br /&gt;GPS - &lt;a href="http://en.wikipedia.org/wiki/Gps"&gt;Global Positioning system&lt;/a&gt; , this time is my target. Seems there is some kinda DVD unit that won't play regular DVDs. After the car ecu and tv hacks, I've started to get a firm grasp on embedded stuff and hardware hacking.&lt;br /&gt;&lt;br /&gt;I think this project will go well ;)&lt;br /&gt;&lt;br /&gt;I will keep you all posted.&lt;br /&gt;&lt;br /&gt;Cheers :D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116140164827270925?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116140164827270925/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116140164827270925' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116140164827270925'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116140164827270925'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/10/news.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-116123411363460666</id><published>2006-10-18T22:00:00.000-07:00</published><updated>2006-10-18T22:01:53.646-07:00</updated><title type='text'></title><content type='html'>http://www.gizmodo.com/gadgets/gadgets/mcdonalds-im-lovin-malware-207639.php&lt;br /&gt;&lt;br /&gt;Story from Gizmodo on McDonald's malware ;))&lt;br /&gt;&lt;br /&gt;Iam loving it !!&lt;br /&gt;&lt;br /&gt;/Quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-116123411363460666?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/116123411363460666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=116123411363460666' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116123411363460666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/116123411363460666'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/10/httpwww.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-115924230322275951</id><published>2006-09-25T20:30:00.000-07:00</published><updated>2006-09-28T07:09:02.726-07:00</updated><title type='text'></title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/2230/2018/1600/hacking_trust.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/2230/2018/320/hacking_trust.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This picture was done by &lt;a href="http://www.bellua.net"&gt;Antony Zboralski&lt;/a&gt; (for his talk in HackInTheBox 2006.&lt;br /&gt;&lt;br /&gt;The people at HITBSec2006 were kind enough to provide Live webcast ;)&lt;br /&gt;&lt;br /&gt;I heard the second day's keynote and some talks which interested me in the 2 day conference.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.milw0rm.com/exploits/2425"&gt;VML Exploit&lt;/a&gt; from milw0rm receives a lot of attention as vendor patch hasn't come up yet&lt;br /&gt;&lt;br /&gt;The unofficial patch from &lt;a href="http://mwpbu.baylor.edu/zert/members.htm"&gt;ZERT&lt;/a&gt; is the temporary solution, and I think that team consists of the most elite and respected researchers in security industry.&lt;br /&gt;&lt;br /&gt;That's all I got in stock now, actually I have been staying away from my box for a while now ... Since I thought life has more to give / take except this machine ;)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Update: Official patch released out of the microsoft patch cycle, available at update website.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-115924230322275951?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/115924230322275951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=115924230322275951' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115924230322275951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115924230322275951'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/09/this-picture-was-done-by-antony.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-115783333314759945</id><published>2006-09-09T13:09:00.000-07:00</published><updated>2006-09-09T13:27:36.070-07:00</updated><title type='text'></title><content type='html'>Pshisssssss ... the hell out !&lt;br /&gt;Long time , no blog ... bah, I have been lazy, tht's one reason&lt;br /&gt;Second reason is I haven't done much except reporting and getting keen on phishing.&lt;br /&gt;Here is the &lt;a href="http://www.antiphishing.org/reports/apwg_report_june_2006.pdf"&gt;report&lt;/a&gt; from APWG (Anti-Phishing Working group) for June06.&lt;br /&gt;&lt;br /&gt;Oh, we can't forget &lt;a href="http://www.microsoft.com/technet/security/bulletin/advance.mspx"&gt;Patch Tuesday's advance bulletin&lt;/a&gt;&lt;br /&gt;Here is an interesting thread &lt;a href="http://seclists.org/pen-test/2006/Aug/0372.html"&gt;a new set of API's for Java&lt;/a&gt;&lt;br /&gt;That's it for now&lt;br /&gt;&lt;br /&gt;/quit :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-115783333314759945?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/115783333314759945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=115783333314759945' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115783333314759945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115783333314759945'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/09/pshisssssss.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-115471828815536862</id><published>2006-08-04T12:00:00.000-07:00</published><updated>2006-08-04T15:59:29.783-07:00</updated><title type='text'></title><content type='html'>Hierarchy of Piracy&lt;br /&gt;  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/2230/2018/1600/piracy_hierarchy.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/blogger/2230/2018/320/piracy_hierarchy.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The above diagram shows how software is pirated schematically ...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-115471828815536862?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/115471828815536862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=115471828815536862' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115471828815536862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115471828815536862'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/08/hierarchy-of-piracy-above-diagram.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-115304266183735587</id><published>2006-07-16T02:22:00.000-07:00</published><updated>2006-07-16T03:26:36.833-07:00</updated><title type='text'></title><content type='html'>Things I can think of now ...&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms06-Jul.mspx"&gt;Microsoft Bulletin&lt;/a&gt; (came out 4 days before ... already ppl will be diff'ing patches)&lt;br /&gt;Post on &lt;a href="http://metasploit.blogspot.com/2006/07/month-of-browser-bugs.html"&gt;browser bugs&lt;/a&gt; from hdm&lt;br /&gt;Then the Anti-Malware Team at Microsoft releasing &lt;a href="http://blogs.technet.com/antimalware/archive/2006/06/13/435670.aspx"&gt;a whitepaper&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blogs.technet.com/photos/antimalware/images/435661/500x375.aspx"&gt;Picture of the Anti-Malware Team&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ahh... I almost forgot &lt;a href="http://fifaworldcup.yahoo.com"&gt;Italy's World Cup victory over France&lt;/a&gt; and about the&lt;br /&gt;"disgusting" words spoken by Materazzi. &lt;a href="http://en.wikipedia.org/wiki/Zinedine_Zidane"&gt;Zidane's&lt;/a&gt; head butt had a lot of press&lt;br /&gt;attention. According to French Coach Raymond Domenech "To me&lt;br /&gt;Materazzi is the man.... He not only uttered those words and sent&lt;br /&gt;our best player packing, but also scored an extra goal and helped&lt;br /&gt;Italy win the world cup"&lt;br /&gt;&lt;br /&gt;Ye, we can understand why he said he scored the "extra-goal".&lt;br /&gt;At the near end of the match in the second period of extra-time the french&lt;br /&gt;players were really pushing it hard and almost scored a goal ...&lt;br /&gt;suddenly zidane's head butt and the rest is history ... it went to&lt;br /&gt;penalties and the italians won on penalties. For me this world cup was&lt;br /&gt;less convincing than the 2002 world cup for the sheer fact of the dives&lt;br /&gt;(all hail van bommel)/unfair play (do u remember a banner called "My play is fair play ??")&lt;br /&gt;/inconsistent referees(Portugal v Holland) and ofcourse the materazzi-zidane issue.&lt;br /&gt;&lt;br /&gt;I bought a new laptop with very nice specs. That's some good news :)&lt;br /&gt;&lt;br /&gt;/quit for now&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-115304266183735587?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/115304266183735587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=115304266183735587' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115304266183735587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115304266183735587'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/07/things-i-can-think-of-now.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-115000140290726060</id><published>2006-06-10T21:36:00.000-07:00</published><updated>2006-06-10T22:05:00.866-07:00</updated><title type='text'></title><content type='html'>Iam NOT the only one who cries over spilt milk.... ;'-(&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;I have got over what has been troubling me for almost a month or two.... I got over the fact that Iam not the only one who looks back at a good friend who is no more mine and I deserved it for sure.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Okay what's new in the scene ... Let's see ...&lt;br /&gt;&lt;br /&gt;First off we've got the &lt;a href="http://www.dailytech.com/article.aspx?newsid=2773"&gt;FBI raiding underground servers&lt;/a&gt;&lt;br /&gt;Next we've got the usual &lt;a href="http://www.local6.com/news/9344212/detail.html"&gt;punkz at school doing their grades away !&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.pcworld.com/news/article/0,aid,126035,00.asp"&gt;Microsoft are releasing what seems to be like "12 ?!" patches&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I guess the folks at &lt;a href="http://www.ncircle.com"&gt;nCircle&lt;/a&gt; wouldn't be &lt;a href="http://blog.ncircle.com/archives/2006/06/dirty_dozen.htm"&gt;sad&lt;/a&gt; this time ;-))&lt;br /&gt;Just looking ahead to a busy patch tuesday for him and his team ... so...so day for the sys-admins as well&lt;br /&gt;&lt;br /&gt;/quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-115000140290726060?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/115000140290726060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=115000140290726060' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115000140290726060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/115000140290726060'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/06/iam-not-only-one-who-cries-over-spilt.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114924545925794204</id><published>2006-06-02T03:48:00.000-07:00</published><updated>2006-06-02T04:08:31.796-07:00</updated><title type='text'></title><content type='html'>Antivirus vendor Sophos has cracked the password for the &lt;a href="http://en.wikipedia.org/wiki/Ransomware"&gt;Ransomware&lt;/a&gt; Archivieus.&lt;br /&gt;&lt;br /&gt;Read the full story at &lt;a href="http://www.vnunet.com/vnunet/news/2157399/sophos-cracks-ransomware-code"&gt;Vnunet&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114924545925794204?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114924545925794204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114924545925794204' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114924545925794204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114924545925794204'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/06/antivirus-vendor-sophos-has-cracked.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114877411461671772</id><published>2006-05-27T16:43:00.000-07:00</published><updated>2006-05-27T16:55:14.633-07:00</updated><title type='text'></title><content type='html'>The Da Vinci code "&lt;a href="http://ww1.mid-day.com/news/city/2006/may/137895.htm"&gt;mobile-virus&lt;/a&gt;" ?  Still unsure of what's going on because I haven't seen anyone in Chennai report anything or maybe they do...If someone is infected, consider sending me a sample because I'd like to have it :-)) &lt;br /&gt;&lt;br /&gt;Courtesy: &lt;a href="http://ww1.mid-day.com"&gt;MiDDAY&lt;/a&gt; magazine.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114877411461671772?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114877411461671772/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114877411461671772' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114877411461671772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114877411461671772'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/05/da-vinci-code-mobile-virus-still.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114762075519561294</id><published>2006-05-14T08:17:00.000-07:00</published><updated>2006-05-14T09:38:30.540-07:00</updated><title type='text'></title><content type='html'>"Hardcore" Body building is what Iam going to be concentrating for a change side-tracking my security saga which has been going on for 5 yrs.&lt;br /&gt;&lt;br /&gt;I want a break and Iam finally working out and eating like a beast ...to be precise&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;Iam trying to become a HUNK :-))&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;6 meals a day and 3 protein shakes ... Am I crazy ?? No ... Iam serious abt building myself like a beast.&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 0);"&gt;Iam planning to gain say around 10 kilos in 3 months, ofcourse all this can't be done without a good protein intake. Iam using Creatine Monohydrate, and another supplement with L-Glutamine. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Oh, I almost forgot about WHEY ... hehe, I use that too... Hope I'd not die of renal failiure...lol&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114762075519561294?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114762075519561294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114762075519561294' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114762075519561294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114762075519561294'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/05/hardcore-body-building-is-what-iam.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114684251545756800</id><published>2006-05-05T08:19:00.000-07:00</published><updated>2006-05-05T08:21:55.473-07:00</updated><title type='text'></title><content type='html'>http://blog.ncircle.com/archives/2006/05/certifications.htm&lt;br /&gt;&lt;br /&gt;nCircle team's blog had this post and an e-week news-brief based on which this was written and it's makes for a good read if you're having ur tea in hand like me at midnight... lol&lt;br /&gt;&lt;br /&gt;Cheers :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114684251545756800?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114684251545756800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114684251545756800' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114684251545756800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114684251545756800'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/05/httpblog.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114642308416577792</id><published>2006-04-30T11:35:00.000-07:00</published><updated>2006-04-30T14:10:17.423-07:00</updated><title type='text'></title><content type='html'>TV cards people ... It's time for new action as I have gone chasing the card model from Nagra systems for TV.&lt;br /&gt;&lt;br /&gt;The card model is ST19XL18... I have figured out a new way of dumping the eprom. The card's memory is having several roms. (3 ROMs and 1 EEPROM) The whole thing is about DSS hacking. Sadly there's no DSS in Chennai, only cable TV&lt;br /&gt;&lt;br /&gt;I got lucky when I met a 24 yr old from Portugal who asked me for help and it's really cool to know that weak crypto algos like DES are still used in TV cards. The whole aim to do all this to see more/all channels for FREE&lt;br /&gt;&lt;br /&gt;We have finally made it ... he was happy and so am I... I learned something new and new hardware to play with.&lt;br /&gt;The best part was all this was done remotely with me just supervising about the hardware/cables/connectors and the binaries were sent to me by email. He co-operated with me a lot and Iam proud that we did all this within 1 week. Hehe ;-))&lt;br /&gt;&lt;br /&gt;Given below is a small working of our old 64-bit algo.&lt;br /&gt;&lt;a href="http://www.zone-h.org/files/33/des-algorithm-details.txt"&gt;&gt;&gt; A short write up on DES by the Matthew Fischer &lt;&lt; &lt;/a&gt;&lt;br /&gt;Courtesy: Zone-H.org&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Update: If anybody wants the ST-7 opcodes email me&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114642308416577792?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114642308416577792/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114642308416577792' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114642308416577792'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114642308416577792'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/04/tv-cards-people.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114552325507850197</id><published>2006-04-20T01:48:00.000-07:00</published><updated>2006-04-22T23:34:19.340-07:00</updated><title type='text'></title><content type='html'>Rediff website has introduced a service/page for searching the approximate air fare for cities inside India only. The service is still beta and it's named Faresearch.&lt;br /&gt;&lt;br /&gt;You can check out &lt;a href="http://in.rediff.com/r/r/ic7"&gt;&gt;&gt; the service here &lt;&lt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I found this while checking my mails in my almost extinct rediff a/c :))&lt;br /&gt;&lt;br /&gt;Cheers&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114552325507850197?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114552325507850197/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114552325507850197' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114552325507850197'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114552325507850197'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/04/rediff-website-has-introduced.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114541799279079822</id><published>2006-04-18T20:29:00.000-07:00</published><updated>2006-04-22T23:36:50.450-07:00</updated><title type='text'></title><content type='html'>Car engines are amazing and they can be more fun sometimes, but paining as well.&lt;br /&gt;&lt;br /&gt;To know their details can be fun, but to draw maps of their connections can really be a pain in the ... well , it's happening now and I accidentally sleep these days just too much unusually. So time is still one step ahead of me.&lt;br /&gt;&lt;br /&gt;Car and computers are inter-related and I knew how only from ... some kind ppl who told me the things written below :-)&lt;br /&gt;&lt;br /&gt;As technology advanced, so did the electronics that go into cars. The ECU in a modern automobile, together with advanced engine technology, makes it possible to control many aspects of the engine's operation, such as spark timing and fuel injection. The ECU may also control valve timing, boost control (in turbocharged engines), ABS, the automatic transmission, and the electronic stability control system. All western cars like Nissan/Volvo/BMW/Skoda/Renault that have been manufactured after 1996 have ECU in them. The first ECU was seen in early 1970 as per Wikipedia. ECU means Electronic control unit or sometimes, called Engine control unit.&lt;br /&gt;&lt;br /&gt;My Embedded RE project has something do with the ECU only :-))&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114541799279079822?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114541799279079822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114541799279079822' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114541799279079822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114541799279079822'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/04/car-engines-are-amazing-and-they-can.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114425160746653958</id><published>2006-04-05T08:34:00.000-07:00</published><updated>2006-04-05T08:40:07.486-07:00</updated><title type='text'></title><content type='html'>&lt;a href="http://www.securityfocus.com/infocus/1603"&gt;Twenty dont's for ASP developers&lt;/a&gt;&lt;span class="down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;br /&gt;The article is precise and exactly to the point , making it more easier to read and understand.&lt;br /&gt;It's a must read for all developers who use ASP.&lt;br /&gt;&lt;br /&gt;Courtesy of &lt;a href="http://www.securityfocus.com"&gt;Security Focus&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114425160746653958?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114425160746653958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114425160746653958' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114425160746653958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114425160746653958'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/04/twenty-donts-for-asp-developers.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114378906145487776</id><published>2006-03-30T23:05:00.000-08:00</published><updated>2006-03-30T23:11:01.466-08:00</updated><title type='text'></title><content type='html'>Okay, it's been almost a week or more since I blogged.&lt;br /&gt;&lt;br /&gt;Iam now in kolkata and Iam here for a kewl project.I like the city, I have been here for 3 days and to be very frank I like this place ;)&lt;br /&gt;&lt;br /&gt;I have mapped several ideas for working on the project and I have temporarily stopped analyzing malware because this project is really sophisticated than the former. It's an embedded RE project.&lt;br /&gt;&lt;br /&gt;I'll update what Iam doing periodically ... if I have time.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114378906145487776?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114378906145487776/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114378906145487776' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114378906145487776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114378906145487776'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/03/okay-its-been-almost-week-or-more.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114246489545543122</id><published>2006-03-15T15:16:00.000-08:00</published><updated>2006-03-15T15:21:35.466-08:00</updated><title type='text'></title><content type='html'>MS Malicious code removal tool update for march includes W32/Atak, W32/Zlob and W32/Torvil&lt;br /&gt;&lt;br /&gt;Get it &lt;a href="http://www.microsoft.com/security/malwareremove/default.mspx"&gt;here&lt;/a&gt; &lt;br /&gt;(note: this tool is not a continual defense product like anti-virus or firewall product,it can be run on-demand)&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114246489545543122?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114246489545543122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114246489545543122' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114246489545543122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114246489545543122'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/03/ms-malicious-code-removal-tool-update.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114220541829884542</id><published>2006-03-12T15:11:00.000-08:00</published><updated>2006-03-12T15:16:58.320-08:00</updated><title type='text'></title><content type='html'>&lt;span class="down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;The VM Rootkits : Next big threat to security ??&lt;br /&gt;&lt;br /&gt;MS Research team has come up with a rootkit which can defeat virtual machine technologies like vmware/ms-virtual pc. They seem to have tested the PoC code on a linux/vmware and a windows/ms-virtual pc. Get the &lt;a href="http://www.eweek.com/article2/0,1759,1936666,00.asp?kc=EWRSS03129TX1K0000614"&gt;full story here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Regards&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114220541829884542?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114220541829884542/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114220541829884542' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114220541829884542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114220541829884542'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/03/vm-rootkits-next-big-threat-to.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114133744435559023</id><published>2006-03-02T14:06:00.000-08:00</published><updated>2006-03-02T14:10:44.383-08:00</updated><title type='text'></title><content type='html'>&lt;a href="http://1984comic.com/pageArticle.php?action=read&amp;id=157"&gt; Is Google the next Big Brother ??&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The above mentioned article makes for an interesting read and it spits out the facts of why/how &lt;a href="http://www.google.com/intl/en"&gt;Google&lt;/a&gt; could be potentially dangerous in the future not only for &lt;a href="http://www.microsoft.com"&gt;Microsoft&lt;/a&gt; but also to the common internet user like me or you.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The invasion of email privacy is one key point to be noted by all Gmail fans out there. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I have no comments regarding this &lt;a href="http://gmail.google.com"&gt;Gmail&lt;/a&gt; issue because I use &lt;a href="http://mail.yahoo.com"&gt;Yahoo mail&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114133744435559023?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114133744435559023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114133744435559023' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114133744435559023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114133744435559023'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/03/is-google-next-big-brother-above.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114131268817684689</id><published>2006-03-02T07:07:00.000-08:00</published><updated>2006-03-02T07:53:49.200-08:00</updated><title type='text'></title><content type='html'>Regarding the OS X 86 Maxxuss has successfully ported the system long time back and is now producing patches in a race with Apple, I spotted that the issue of dual booting OS X / Win XP will soon be accomplished.&lt;br /&gt;More info about this can be had from &lt;a href="http://www.osx86project.org"&gt;this website&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Meanwhile we must not forget that still some computers in the world are infected with Nyxem.e which will activate its payload on the 3rd of every month. I heard from some sources near me indicating a meagre rate of infection still existing here.&lt;br /&gt;&lt;br /&gt;/quit&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114131268817684689?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114131268817684689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114131268817684689' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114131268817684689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114131268817684689'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/03/regarding-os-x-86-maxxuss-has.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114103078592907701</id><published>2006-02-27T00:41:00.000-08:00</published><updated>2006-02-27T01:09:22.893-08:00</updated><title type='text'></title><content type='html'>An Auditor from &lt;a href="http://www.deloitte.com"&gt;Deloitte &amp; Touche,USA&lt;/a&gt; has lost an unencrypted CD beleived to be containing important information of current and former &lt;a href="http://us.mcafee.com"&gt;McAfee&lt;/a&gt; Employees. Around 9000 employees' social security numbers, information of stock holdings and other important info has been lost.&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.deloitte.com"&gt;Deloitte&lt;/a&gt; representative confirmed this incident had taken place on Dec.15 and &lt;a href="http://us.mcafee.com"&gt;McAfee&lt;/a&gt; were informed on Jan.11 almost a month after the incident had occured.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computerworld.com.au/index.php/id;1800511809;fp;16;fpid;0"&gt;Read the full story here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114103078592907701?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114103078592907701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114103078592907701' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114103078592907701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114103078592907701'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/auditor-from-deloitte-toucheusa-has.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114099397203322183</id><published>2006-02-26T14:41:00.000-08:00</published><updated>2006-02-26T14:46:12.050-08:00</updated><title type='text'></title><content type='html'>Feels good to have gone bug-hunting after a long time. I found a couple of buffer overflows in a prominent software in just a matter of 2 hrs !!. The POC Code will not be released. I have contacted the vendor and prefer not to elaborate on the details of the same as malware authors are waiting to prey in such situations ;-))&lt;br /&gt;&lt;br /&gt;Life seems to be fast these days and time alwayz is one-step ahead of me ... I hope to change this situation soon.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114099397203322183?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114099397203322183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114099397203322183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114099397203322183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114099397203322183'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/feels-good-to-have-gone-bug-hunting.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114034240026384543</id><published>2006-02-19T01:39:00.000-08:00</published><updated>2006-02-19T01:46:40.280-08:00</updated><title type='text'></title><content type='html'>Apple proxy ?? Apple's site mac.com has a redirection facility which attackers "can" use to their advantage.&lt;br /&gt;&lt;br /&gt;Check this out : http://www.mac.com//redirect/http://www.hotmail.com&lt;br /&gt;&lt;br /&gt;The above crafted URL is just a example,instead of hotmail it could be "any" dangerous URL perhaps a scam.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114034240026384543?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114034240026384543/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114034240026384543' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114034240026384543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114034240026384543'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/apple-proxy-apples-site-mac.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-114012770830832845</id><published>2006-02-16T14:02:00.000-08:00</published><updated>2006-02-16T14:31:55.923-08:00</updated><title type='text'></title><content type='html'>OS/X Leap.a - First power pc malware found in the wild.&lt;br /&gt;&lt;br /&gt; &lt;a href="http://www.macrumors.com/pages/2006/02/20060216005401.shtml"&gt;Read more from the source&lt;read&gt;&lt;/read&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can get &lt;a href="http://www.f-secure.com"&gt;F-Secure&lt;/a&gt;'s analysis &lt;a href="http://www.f-secure.com/v-descs/leap_a.shtml"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Does this mean Mac is becoming more popular with the latest collaboration between Apple and Intel ???&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Yes,it's becoming prominent and malware authors are targetting it for a change ;-))&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-114012770830832845?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/114012770830832845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=114012770830832845' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114012770830832845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/114012770830832845'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/osx-leap.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113932476014199940</id><published>2006-02-07T06:48:00.000-08:00</published><updated>2006-02-08T00:09:06.280-08:00</updated><title type='text'></title><content type='html'>The muslims have once again started defacing websites, and posting political messages against denmark... More news on the issue can be had from &lt;a href="http://www.zone-h.org/en/news/read/id=205987/"&gt;here&lt;/a&gt; . It's strange why denmark had to say anything ...and why this new wave of cyberwar against the two had to arise..??&lt;br /&gt;&lt;br /&gt;It's just in it's budding stages, and more attacks are likely to be seen in the future. These things remind me of the all-famous Yaha worm and their variants which wreaked havoc in Pakistani ISP(s). Indians and pakistanis were dueling each other a while ago from 2001 or so and still it is continuiing ...for a reason called "Kashmir"&lt;br /&gt;&lt;br /&gt;IMHO a Cyberwar between any two countries on political grounds is un-necessary. This is not any good because true patriots know how to fight by conducting, campaigns / speeches etc instead of trying to attack one's digital possesion.&lt;br /&gt;&lt;br /&gt;Why try to mess with one's digital privacy when there are governments and other departments under them trying to bridge these issues smoothly.&lt;br /&gt;&lt;br /&gt;Regards&lt;br /&gt;&lt;br /&gt;---[Disclaimer]---&lt;br /&gt;This post is just my view and it's not meant to be Indian's view or pakistan's view or whatever. Iam against racial /communal feelings. Everybody is a human and they deserve what they actually do ... Neither me nor my host (blogger.com) can be held liable for any misconception of what is expressed in this post.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113932476014199940?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113932476014199940/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113932476014199940' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113932476014199940'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113932476014199940'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/muslims-have-once-again-started.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113900747146862044</id><published>2006-02-03T14:55:00.001-08:00</published><updated>2006-02-03T15:02:32.376-08:00</updated><title type='text'></title><content type='html'>We need to compete for knowledge and wisdom, not for grades. Knowledge is piling up facts, wisdom is simplifying it. One could have good grades and a degree without learning much. The most important thing one can learn is to "learn to learn." &lt;span style="font-weight: bold;"&gt;People confuse education with the ability to memorize facts.&lt;/span&gt; Education of the mind without morals creates a menace to society.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Who is really educated ??&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;In a nutshell, educated persons are those who can choose wisely and courageously under any circumstances. If they have the ability to choose between wisdom and foolishness, between good and &lt;/span&gt;&lt;span style="font-style: italic;"&gt;bad, between virtuousness and vulgarities, regardless of the academic degrees they have, then they are educated.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 102);"&gt;Expert ?? An expert is someone who knows all the answers if you ask the right questions.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Taken from Shiv Khera's book = You can win :-)&lt;br /&gt;&lt;br /&gt;Still reading the book ... More to come ...&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113900747146862044?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113900747146862044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113900747146862044' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113900747146862044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113900747146862044'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/we-need-to-compete-for-knowledge-and_03.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113900690332430831</id><published>2006-02-03T14:46:00.000-08:00</published><updated>2006-02-03T14:48:26.060-08:00</updated><title type='text'></title><content type='html'>&lt;span style="font-style: italic;"&gt;To give you an example of selective listening, let me share with you a story I heard about a medical doctor who was invited as a guest speaker to address a group of alcoholics. He wanted to make a demonstration that would be powerful enough to make people realize that alcohol was injurious to their health. He had two containers, one with pure distilled water and one with pure alcohol. He put an earthworm into the distilled water and it swam beautifully and came up to the top. He put another earthworm into the alcohol and it disintegrated in front of everyone's eyes. He wanted to prove that this was what alcohol did to the insides of our body. He asked the group what the moral of the story ??&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;And one person from behind said, "If you drink alcohol you won't have worms in your stomach."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 102);"&gt;Was that the message? Of course not. That was selective listening--we hear what we want to hear and not what is being said. Many of our blessings are hidden treasures--count your blessings and not your troubles.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Taken from Shiv Khera's book = You can win :-)&lt;br /&gt;&lt;br /&gt;Iam still glued to this piece of plethoric values ...&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113900690332430831?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113900690332430831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113900690332430831' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113900690332430831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113900690332430831'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/to-give-you-example-of-selective.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113900107070384348</id><published>2006-02-03T13:08:00.000-08:00</published><updated>2006-02-03T13:27:14.280-08:00</updated><title type='text'></title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;span style="font-style: italic;"&gt;There was a man who made a living selling balloons at a fair.&lt;br /&gt;He had all colors of &lt;/span&gt;&lt;span style="font-style: italic;"&gt;balloons, including red, yellow, blue, and green. Whenever business was slow, he would &lt;/span&gt;&lt;span style="font-style: italic;"&gt;release a helium-filled balloon into the air and when the children saw it go up, they all &lt;/span&gt;&lt;span style="font-style: italic;"&gt;wanted to buy one. They would come up to him, buy a balloon, and his sales would go up &lt;/span&gt;&lt;span style="font-style: italic;"&gt;again. He continued this process all day. One day, he felt someone tugging at his jacket. &lt;/span&gt;&lt;span style="font-style: italic;"&gt;He turned around and saw a little boy who asked, "If you release a black balloon, would &lt;/span&gt;&lt;span style="font-style: italic;"&gt;that also fly?" Moved by the boy's concern, the man replied with empathy, "Son, it is not &lt;/span&gt;&lt;span style="font-style: italic;"&gt;the color of the balloon, it is what is inside that makes it go up."&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 153, 102);"&gt;The author's insight: What's inside us matters,"the attitude" that makes the difference between losers and winners... &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Taken from Shiv Khera's Book = You can Win(best selling title) :)&lt;br /&gt;&lt;br /&gt;It also brings to mind the saying &lt;span style="font-style: italic;"&gt;"IT'S THE ATTITUDE,NOT THE APTITUDE THAT DETERMINES ONE'S ALTITUDE" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113900107070384348?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113900107070384348/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113900107070384348' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113900107070384348'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113900107070384348'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/02/there-was-man-who-made-living-selling.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113841881656439025</id><published>2006-01-27T19:23:00.000-08:00</published><updated>2006-02-01T21:54:24.526-08:00</updated><title type='text'></title><content type='html'>According to &lt;a href="http://www.securityfocus.com"&gt;Security Focus&lt;/a&gt; news Nyxem.e/Blackmal.e/MyWife.e is spreading rapidly in India,Turkey,Italy ...&lt;br /&gt;Read more about the news article &lt;a href="http://www.securityfocus.com/brief/120"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This came up shortly after I posted my views/rough analysis of the worm.&lt;br /&gt;&lt;br /&gt;Update: &lt;a href="http://www.f-secure.com"&gt;F-Secure&lt;/a&gt; has released a &lt;a href="http://www.f-secure.com/tools/f-force.zip"&gt;disinfection utility&lt;/a&gt; called F-Force for Nyxem.e&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113841881656439025?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113841881656439025/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113841881656439025' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113841881656439025'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113841881656439025'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/01/according-to-security-focus-news-nyxem.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113836221316721431</id><published>2006-01-27T03:31:00.000-08:00</published><updated>2006-01-27T04:11:42.963-08:00</updated><title type='text'></title><content type='html'>Nyxem.e is a mass mailing worm, it sends the attachment, with filetype bhx(which actually is the worm). I was not surprised when a institute where I had studied was infected with the worm. (No anti-virus installed either) So the possibility of infection was very high. I won't be wondering if the worm spread to all their students' email and inturn their friends / contacts.&lt;br /&gt;&lt;br /&gt;Some behavioral details&lt;br /&gt;&lt;br /&gt;1)Coded in Microsoft Visual Basic, it uses remote shares to spread itself&lt;br /&gt;2)Nasty payload: Deletes the file of the following filetype *.doc/*.xls/*.mdb/*.mde/*.ppt/*.pps/*.zip/*.rar/*.pdf/*.psd/*.dmp&lt;br /&gt;3)It poses to be a winzip file (which is more threatening)&lt;br /&gt;4)It escapes from anti-virus vendors as it's kinda mydoom's design by avoiding sending the emails to their domains.&lt;br /&gt;5)It also kills the following services(anti-viruses)&lt;br /&gt;SYMANTEC/SCAN/KASPERSKY/VIRUS/MCAFEE/TREND MICRO/NORTON/REMOVAL/FIX&lt;br /&gt;&lt;br /&gt;So even if the institute I mentioned had a Anti-virus, it might have only one of the leading av's and this makes the installation of anti-viruses futile.&lt;br /&gt;&lt;br /&gt;I was particularly interested in this one because it's payload was to delete almost all essential files on the harddisk on Feb 3 or 3rd day of any month.This is aided by the running of a exe called update.exe is loaded into memory.(update.exe is created by the worm)I haven't fully analysed the worm.&lt;br /&gt;&lt;br /&gt;I have just outlined some of the key features which make it deadly.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113836221316721431?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113836221316721431/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113836221316721431' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113836221316721431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113836221316721431'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/01/nyxem.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113817437591637274</id><published>2006-01-24T23:14:00.000-08:00</published><updated>2006-01-24T23:32:55.963-08:00</updated><title type='text'></title><content type='html'>Yo... I have been playing with some old samples recently.. Iam also linked with a upcoming security firm in my city,where I might secure a job for myself for good ;-)&lt;br /&gt;&lt;br /&gt;That's all I have in stock for now :-)&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113817437591637274?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113817437591637274/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113817437591637274' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113817437591637274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113817437591637274'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/01/yo.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113686740504156924</id><published>2006-01-09T20:23:00.000-08:00</published><updated>2006-01-09T20:33:57.130-08:00</updated><title type='text'></title><content type='html'>My primary 40gig hdd crashed and it was declared unusable by me as soon as I got a couple of Data Read/Write errors.(also accompanying these two was the CRC Error for the hdd). I still wanted to try to make it re-usable instead of throwing it ... Hoping to make something happen I installed Win2000 SP4 and a Vmware image. As soon as I started working ... I again get these bsod(errors as mentioned above). I finally format it again fully and I won't throw it ... but I will have it as a souvenir/my memoir or whatever I feel like calling it ... Iam planning to buy a 10-20gig hdd to get back the setup for working on vulns/malware.&lt;br /&gt;&lt;br /&gt;Pray for my new hdd's health...&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113686740504156924?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113686740504156924/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113686740504156924' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113686740504156924'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113686740504156924'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2006/01/my-primary-40gig-hdd-crashed-and-it.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113563381269660946</id><published>2005-12-26T13:43:00.000-08:00</published><updated>2005-12-26T14:00:04.523-08:00</updated><title type='text'></title><content type='html'>Ho!! Ho!! Ho!! ...0wning the Cisco IOS , BlackHat USA 2005 ;)&lt;br /&gt;&lt;br /&gt;Courtesy: Google.com,Schneier.com.&lt;br /&gt;&lt;br /&gt;---[News]---&lt;br /&gt;&lt;br /&gt;In his blog www.schneier.com/blog, Bruce schneier,a security guru gives his review on how cisco were/are harassing former ISS Security Researcher, Michael lynn. Mr.Lynn had quit his job to present the paper in Blackhat USA '05.&lt;br /&gt;&lt;br /&gt;Security Guru gives &lt;a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html"&gt;his clear view&lt;/a&gt; of what happened to Mike.&lt;br /&gt;&lt;br /&gt;---[Audio File]---&lt;br /&gt;&lt;br /&gt;Audio of a Press Conference at BlackHat USA 2005 over Cisco and Michael Lynn&lt;br /&gt;&lt;br /&gt;This press conference was held during BlackHat USA2005 on Jul 28 with Michael Lynn and Jeff Moss attended. All parties which involved were invited but Cisco and ISS didn't participate.&lt;br /&gt;&lt;br /&gt;Here's &lt;a href="http://metamemos.typepad.com/e/20050728_162006.mp3"&gt;MP3 audio&lt;/a&gt; of the press conference. 37 min.&lt;br /&gt;&lt;br /&gt;---[Video file]---&lt;br /&gt;"Someone" posted a video of BlackHat USA proceedings page ripping process by Cisco sent staff.&lt;br /&gt;Download the video &lt;a href="http://downloads.oreilly.com/make/cisco.mov"&gt;here&lt;/a&gt;(QuickTime format)&lt;br /&gt;&lt;br /&gt;---[Disclaimer]---&lt;br /&gt;I haven't uploaded any content mentioned above.Iam just giving pointers for other people to know what is really available in the Internet.Neither I nor my host(blogger.com) will be liable for any of the actions of the readers.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113563381269660946?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113563381269660946/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113563381269660946' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113563381269660946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113563381269660946'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2005/12/ho-ho-ho.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113563101967608149</id><published>2005-12-26T13:02:00.000-08:00</published><updated>2005-12-26T13:03:39.676-08:00</updated><title type='text'></title><content type='html'>Get my tut on &lt;a href="http://programmerstools.org/node/511"&gt;Circumventing CD-Checks&lt;/a&gt; from protools.cjb.net maintained by Kaparo.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113563101967608149?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113563101967608149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113563101967608149' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113563101967608149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113563101967608149'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2005/12/get-my-tut-on-circumventing-cd-checks.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113563066854954943</id><published>2005-12-26T12:37:00.000-08:00</published><updated>2005-12-26T12:57:48.576-08:00</updated><title type='text'></title><content type='html'>Get my &lt;a href="http://programmerstools.org/node/485"&gt;Basic Overview of Reverse engineering&lt;/a&gt; from protools.cjb.net maintained by Kaparo.&lt;br /&gt;&lt;br /&gt;Regards&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113563066854954943?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://kishfellow.blogspot.com/feeds/113563066854954943/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20189612&amp;postID=113563066854954943' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113563066854954943'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113563066854954943'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2005/12/get-my-basic-overview-of-reverse.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20189612.post-113559036016109962</id><published>2005-12-26T01:40:00.000-08:00</published><updated>2008-10-02T04:41:21.018-07:00</updated><title type='text'></title><content type='html'>Blog is mainly about reverse engineering/hacking/coding malware and countermeasures for the same. I will sometimes rant in a semi-conscious or rather an oblivious mood ... which is left to the reader to take it / ignore it ...&lt;br /&gt;&lt;br /&gt;---[Disclaimer]---&lt;br /&gt;The author of this blog / web-log is a Security enthusiast who is interested in Security,any form of digital security...Ranging from Wired/Wireless Network to mechanisms like Smart card systems/Game console Protection/Casino's Poker machine security, etc...The author is driven by the curiosity to explore the innards of anything/everything using any means possible...&lt;br /&gt;&lt;br /&gt;The author uses the term hacker throughout this blog from the view of a penetration tester/data mangler/you name it ... ;-)&lt;br /&gt;&lt;br /&gt;The views expressed on this blog are my own unless stated otherwise...&lt;br /&gt;&lt;br /&gt;Cheers :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20189612-113559036016109962?l=kishfellow.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113559036016109962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20189612/posts/default/113559036016109962'/><link rel='alternate' type='text/html' href='http://kishfellow.blogspot.com/2005/12/blog-is-mainly-about-reverse.html' title=''/><author><name>Scarlet Pimpernel</name><uri>http://www.blogger.com/profile/03456568444522595359</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
