<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-20075889</id><updated>2008-04-28T09:52:55.926-05:00</updated><title type='text'>Plan B: Security, Technology, and the Law</title><link rel='alternate' type='text/html' href='http://www.planb-security.net/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default?start-index=26&amp;max-results=25'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.planb-security.net/atom.xml'/><author><name>todb</name></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>77</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-20075889.post-1393973892275780812</id><published>2008-04-10T18:03:00.006-05:00</published><updated>2008-04-11T10:31:25.982-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='downgrade'/><category scheme='http://www.blogger.com/atom/ns#' term='flash'/><category scheme='http://www.blogger.com/atom/ns#' term='cross-domain policy'/><title type='text'>Older is Better: Flash player plugin for Linux</title><summary type='text'>Here's a link to solve your new Flash woes if you upgraded and suddenly your favorite Flash site doesn't work any more:
Download old-libflashplayer.so

I just uploaded a known working (pre-April 9, 2008) version of the Flash player plugin for Firefox for Linux to the above link at FileCrunch.

Directions: Download the Flash player plugin somewhere, like your Desktop. Then run these commands in a </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2008/04/older-is-better-flash-player-plugin-for.html' title='Older is Better: Flash player plugin for Linux'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=1393973892275780812' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/1393973892275780812'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/1393973892275780812'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-5548664496483164001</id><published>2008-03-23T20:51:00.003-05:00</published><updated>2008-03-23T20:58:16.997-05:00</updated><title type='text'>Teaching Kids to Program</title><summary type='text'>HacketyHack is a Ruby sandbox designed to teach kids how to program in a way that emphasizes speed and fun. Since I'm attempting to devour anything I can find about Ruby these days, this popped up while surfing around the various "Ruby lifestyle" sites.

Since I have a few kids of my own, I'm hopeful this will come in handy. Maybe I can get my four year old to implement a Ruby TNS listener for me.</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2008/03/teaching-kids-to-program.html' title='Teaching Kids to Program'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=5548664496483164001' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5548664496483164001'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5548664496483164001'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-590702867118946498</id><published>2008-03-05T15:27:00.003-06:00</published><updated>2008-03-05T15:41:33.837-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='chinese spies'/><category scheme='http://www.blogger.com/atom/ns#' term='breakingpoint'/><category scheme='http://www.blogger.com/atom/ns#' term='me'/><category scheme='http://www.blogger.com/atom/ns#' term='3com'/><title type='text'>New Job For Me</title><summary type='text'>So, I've finally caught my breath.

In the last month, I've a) bought a new house, b) rented out my old house, c) moved my family 7 miles, d) suffered (with said family) some horrible bronchial infection and e) got a new position at BreakingPoint Systems, where I've been doing nothing but brush up on my practical Ruby and XML, and learn various protocol specs so that I can actually perform the </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2008/03/new-job-for-me.html' title='New Job For Me'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=590702867118946498' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/590702867118946498'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/590702867118946498'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-1818902352974264732</id><published>2008-02-04T15:23:00.000-06:00</published><updated>2008-02-04T15:31:51.008-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='document authenticity'/><category scheme='http://www.blogger.com/atom/ns#' term='beaurocracy'/><title type='text'>Document-based authentication failures</title><summary type='text'>So, if you don't have an insurance card handy for when it's time to re-register your vehicle, it's permissible to just make one with your favorite document editor and your favored insurance company logo at the top. The logo seems to be key -- the county worker's eyes went straight to it, and she didn't bother to really read the rest of the surrogate card I produced (so she didn't notice that I </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2008/02/document-based-authentication-failures.html' title='Document-based authentication failures'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=1818902352974264732' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/1818902352974264732'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/1818902352974264732'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-2922793470039673418</id><published>2008-01-08T07:58:00.000-06:00</published><updated>2008-01-09T08:28:49.111-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cvc'/><category scheme='http://www.blogger.com/atom/ns#' term='scan alert'/><category scheme='http://www.blogger.com/atom/ns#' term='mcafee'/><title type='text'>Hacker Safe Compromised</title><summary type='text'>At least, it was according to Ryan's new blog. Which seems a little embarrassing to their new owners, McAfee. Oops. According to the report, credit card numbers and CVCs may have been stolen -- which means that Scan Alert, just like most people, were probably storing CVCs along with CC#'s in an unencrypted format. Nice.

Update 2008-01-09: The compromised site in question here is Geeks.com, not </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2008/01/hacker-safe-compromised.html' title='Hacker Safe Compromised'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=2922793470039673418' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2922793470039673418'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2922793470039673418'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-4554248547536547800</id><published>2008-01-04T13:24:00.001-06:00</published><updated>2008-01-04T13:28:57.447-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social networking'/><category scheme='http://www.blogger.com/atom/ns#' term='pirates'/><category scheme='http://www.blogger.com/atom/ns#' term='zdnet'/><title type='text'>More about how Facebook/Myspace is the devil</title><summary type='text'>A cursory blurb over on ZDNet has dubbed social networking sites as the next hacker frontier. To which i say, "Avast!" since I like piratical metaphors for hax0ring more than cowboy metaphors.</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2008/01/more-about-how-facebookmyspace-is-devil.html' title='More about how Facebook/Myspace is the devil'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=4554248547536547800' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/4554248547536547800'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/4554248547536547800'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-3305695177963703434</id><published>2007-12-24T13:41:00.000-06:00</published><updated>2007-12-24T13:46:38.362-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='greasemonkey'/><category scheme='http://www.blogger.com/atom/ns#' term='https'/><title type='text'>NonHTTPS.user.js</title><summary type='text'>I find it maddening that when Firefox fetches a web page via SSL, it will also incorporate non-SSL items without explicitly telling you /which/ elements were transmitted in the clear. I've whined about this before. Now, it came up again when I started using HTTPS-ified iGoogle. So, instead of actually working on Xmas eve, I wrote a Greasemonkey Script to try to make these this kind of thing more </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/12/nonhttpsuserjs.html' title='NonHTTPS.user.js'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=3305695177963703434' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/3305695177963703434'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/3305695177963703434'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-5154009980537442755</id><published>2007-11-09T15:55:00.000-06:00</published><updated>2007-11-09T16:08:44.584-06:00</updated><title type='text'>Oracle: Unbreakable (YMMV)</title><summary type='text'>Oracle's latest CPU mentions, Oracle will proactively create patches only for platform/version combinations that, based on historical data, customers are likely to download for the next Critical Patch Update. We create patches for historically inactive platform/version combinations of the Oracle Database and Oracle Application Server only if requested by customers.

So, it reads like, if you're </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/11/oracle-unbreakable-ymmv.html' title='Oracle: Unbreakable (YMMV)'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=5154009980537442755' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5154009980537442755'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5154009980537442755'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-5088772165190796673</id><published>2007-10-27T08:08:00.000-05:00</published><updated>2007-10-27T08:15:15.027-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='evasions'/><category scheme='http://www.blogger.com/atom/ns#' term='worms'/><title type='text'>Gozi Trojan Antispam String</title><summary type='text'>I posted to my work blog a little ditty about detecting the Gozi stuff circulating now, after noticing that only one variation of the PDF was hitting a more general detection mechanism, over and over again. This is further proof, at least to me, that the run-of-the-mill mass attacker still doesn't give a whit about evasion -- they're after people with no security mechanisms in place, so having </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/10/gozi-trojan-antispam-string.html' title='Gozi Trojan Antispam String'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=5088772165190796673' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5088772165190796673'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5088772165190796673'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-377899577635826127</id><published>2007-10-19T12:41:00.000-05:00</published><updated>2007-10-19T12:50:10.137-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='buzzwords'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>SpaMP3: The latest in cutesy buzzwords for spam</title><summary type='text'>Information Week is running a story on MP3-based spam, which they're calling SpaMP3. Oldtime readers know I am completely ga-ga over new names for old problems, so I'm totally in love with this story.

What they fail to mention is how creepy it the low bitrate/low sample rate actually sounds. Click here to download and hear it yourself -- note AV scanners may block, though there doesn't look to </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/10/spamp3-latest-in-cutesy-buzzwords-for.html' title='SpaMP3: The latest in cutesy buzzwords for spam'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=377899577635826127' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/377899577635826127'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/377899577635826127'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-3901250162474882943</id><published>2007-10-18T13:09:00.000-05:00</published><updated>2007-10-18T13:13:55.015-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='living in the future'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberpunk'/><category scheme='http://www.blogger.com/atom/ns#' term='worms'/><title type='text'>Storm Bandwidth Resale</title><summary type='text'>CNET is running a surprisingly insightful article about the current state of the global malware/spam delivery system known as the Storm Worm Botnet. I don't want to spoil the ending or anything, but the Storm network is really pretty advanced. If you haven't read Shockwave Rider by now, you probably ought to in order to appreciate what the global network is going to look like when Storm and its </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/10/storm-bandwidth-resale.html' title='Storm Bandwidth Resale'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=3901250162474882943' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/3901250162474882943'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/3901250162474882943'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-2048435679549638472</id><published>2007-10-17T16:56:00.000-05:00</published><updated>2007-10-17T17:02:57.232-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='non-news'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>Reuters Runs Non-Story About Google</title><summary type='text'>This story is the silliest fluff piece about the Internet I've seen since the breathless piece on Twitter.

It's a list of keywords sorted by country. Okay. The implication is that America is way more interested in burritos and Iraq than, oh, Sweden is.

Shrug.

I can only assume that they had this pretty cool picture of Google-colored glasses, but no actual story to go with it.</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/10/reuters-runs-non-story-about-google.html' title='Reuters Runs Non-Story About Google'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=2048435679549638472' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2048435679549638472'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2048435679549638472'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-4296908584435084760</id><published>2007-10-11T12:26:00.001-05:00</published><updated>2007-10-11T12:39:04.461-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social networking'/><category scheme='http://www.blogger.com/atom/ns#' term='myspace'/><title type='text'>Okay, so Linkin, Myspace, and Facebook really aren't THAT bad...</title><summary type='text'>...but they have the potential for badness, like a chainsaw or strong encryption.

See my interview about social networking on Dark Reading. It's not earth shattering 0days that make these sites a liability, but the casual trust that users invest in them. Oh, and the 0days -- which are sometimes there by design.</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/10/okay-so-linkin-myspace-and-facebook.html' title='Okay, so Linkin, Myspace, and Facebook really aren&apos;t THAT bad...'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=4296908584435084760' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/4296908584435084760'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/4296908584435084760'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-3356600359090460777</id><published>2007-09-28T15:44:00.000-05:00</published><updated>2007-09-28T15:47:33.692-05:00</updated><title type='text'>All About My Money</title><summary type='text'>What a day.

This morning, I read an announcement that my employer, 3Com, is going to be taken private, bought up for 2.2 billion samoleans. It's even on TechCrunch, and while it's not a done deal, it's pretty close enough. Rad.

This afternoon, I go to log into my primary bank. Oops, it's gone. What the hell. It's even on the FDIC press page. Not so rad.

I guess if I had been paying attention </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/09/all-about-my-money.html' title='All About My Money'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=3356600359090460777' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/3356600359090460777'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/3356600359090460777'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-4200548255564724664</id><published>2007-07-11T10:16:00.000-05:00</published><updated>2007-07-11T10:28:27.644-05:00</updated><title type='text'>Firefox URL Extensions</title><summary type='text'>Just a quick note -- after reading about thor's IE-to-FF 0day, I noticed a neato extension that has nothing to do with this -- the Locationbar2 extension, which does some nifty highlighting and clickability transformations on the Location bar. It's included in CyberNotes' Top 10 list of Firefox URL extensions. I often lament that browsers don't do a very good job of making the "current" window </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/07/firefox-url-extensions.html' title='Firefox URL Extensions'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=4200548255564724664' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/4200548255564724664'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/4200548255564724664'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-6051975385415834722</id><published>2007-06-19T11:00:00.000-05:00</published><updated>2007-06-19T11:02:38.444-05:00</updated><title type='text'>No Hacking!</title><summary type='text'>Nothing inspires panic in the hearts of web application hax0rs quite like a retiree rent-a-cop.

Now get the hell out of my food court.</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/06/no-hacking.html' title='No Hacking!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=6051975385415834722' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/6051975385415834722'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/6051975385415834722'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-9177191831120964601</id><published>2007-06-13T10:35:00.000-05:00</published><updated>2007-06-13T10:57:12.016-05:00</updated><title type='text'>Oh, good, another sucky browser for Windows</title><summary type='text'>After a pretty funny marketing salvo dissing Microsoft security, Apple went and released Safari for Windows. Trouble is, it's full of bugs.</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/06/oh-good-another-sucky-browser-for.html' title='Oh, good, another sucky browser for Windows'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=9177191831120964601' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/9177191831120964601'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/9177191831120964601'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-8275741117914624899</id><published>2007-05-31T08:33:00.000-05:00</published><updated>2007-05-31T12:09:23.725-05:00</updated><title type='text'>Etherbat: A useful application of ARP spoofing</title><summary type='text'>Today, Paweł Pokrywka announced the release of Etherbat, a Linux application for mapping local networks. The cool part is that it does its magic through ARP spoofing.

I have a soft spot for limited information network mapping and device identification, and this does both, which makes it cool++ in my book. I've long wondered what other practical effects you could achieve with ARP spoofing (aside </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/05/etherbat-useful-application-of-arp.html' title='Etherbat: A useful application of ARP spoofing'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=8275741117914624899' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/8275741117914624899'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/8275741117914624899'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-7328939500144503315</id><published>2007-05-21T10:20:00.000-05:00</published><updated>2007-05-21T15:20:06.842-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ssl firefox gmail'/><title type='text'>Partial Encryption on Gmail?</title><summary type='text'>This started popping up today (click to embiggen):



So, what is a normal user supposed to do with the warning that "parts of the page" were not encrypted? Seems that if you, the user, were counting on your Gmail contents being secret (maybe you're reading Gmail in the same room as Robert Graham), and you get this big red warning on your location bar, it's either a) too late to do anything about</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/05/partial-encryption-on-gmail.html' title='Partial Encryption on Gmail?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=7328939500144503315' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/7328939500144503315'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/7328939500144503315'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-2904436753766586855</id><published>2007-03-18T11:28:00.000-05:00</published><updated>2007-03-18T11:34:55.721-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='full disclosure'/><category scheme='http://www.blogger.com/atom/ns#' term='media whores'/><category scheme='http://www.blogger.com/atom/ns#' term='myspace'/><title type='text'>Myspace Hax0rs</title><summary type='text'>So, over the weekend, this popped up on the usual mailing lists: Month of MySpace Bugs, Yes!, or MOMBY.

Loyal readers will know I've poked at MySpace a time or two, and faithfully reported my findings to what I've guessed is the right place (security@myspace.com and abuse@myspace.com), to be met with indifference from News Corp and quizzical looks from peers as to why I'm even bothering.

So, </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/03/myspace-hax0rs.html' title='Myspace Hax0rs'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=2904436753766586855' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2904436753766586855'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2904436753766586855'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-348633203794393393</id><published>2007-03-15T11:50:00.000-05:00</published><updated>2007-03-15T12:01:58.457-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='crime'/><category scheme='http://www.blogger.com/atom/ns#' term='nginx'/><category scheme='http://www.blogger.com/atom/ns#' term='malicious'/><title type='text'>Nginx http server, possibly a criminal indicator?</title><summary type='text'>Just like using Linux doesn't automatically make you a criminal, I doubt that using Nginx (proncouned, "Engine-X") is necessarily a criminal act. But is it an indicator?

I noticed it today as part of a light analysis of a real world exploit of the Overlong RTSP link bug for Quicktime. This is a lightweight http server that is now associated with at least one case of network crime by serving up a</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/03/nginx-http-server-possibly-criminal.html' title='Nginx http server, possibly a criminal indicator?'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=348633203794393393' title='9 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/348633203794393393'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/348633203794393393'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-5404291590142569861</id><published>2007-03-06T13:10:00.000-06:00</published><updated>2007-03-06T13:15:14.422-06:00</updated><title type='text'>Let's do the Timewarp again!</title><summary type='text'>Weird little PoC popped up on milw0rm a few days back -- a buffer overflow in Netrek.

Just made me chuckle. I haven't played Netrek in maybe, what,  15 years? Besides, everyone knows that Nethack is the best game ever, and that's one I still play (though usually in its Slash'em incarnation).</summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/03/lets-do-timewarp-again.html' title='Let&apos;s do the Timewarp again!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=5404291590142569861' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5404291590142569861'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/5404291590142569861'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-2245814695940392987</id><published>2007-02-24T14:42:00.000-06:00</published><updated>2007-02-24T14:46:09.010-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wlan nic mini-PCI fry&apos;s retail'/><title type='text'>No Mini-PCI at Fry's. Bummer.</title><summary type='text'>Today, I discovered that Fry's Electronics, once a bastion of computer/network/electronics geekery, is now completely irrelevant. I was shopping for a new mini-PCI wireless NIC, since my Intel chipset whatever-its-called OEM NIC that came with my IBM/Legend ThinkPad has always been weird and flakey, and I finally got sick of it. So, I packed one of the kids up in the car and bopped over to Fry's </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/02/no-mini-pci-at-frys-bummer.html' title='No Mini-PCI at Fry&apos;s. Bummer.'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=2245814695940392987' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2245814695940392987'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/2245814695940392987'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-6161403717378076434</id><published>2007-02-11T09:13:00.000-06:00</published><updated>2007-02-11T09:47:19.238-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rsa'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='paypal'/><category scheme='http://www.blogger.com/atom/ns#' term='2fa'/><category scheme='http://www.blogger.com/atom/ns#' term='verisign'/><title type='text'>Paypal Introduces Security Fob</title><summary type='text'>Strikingly similar to the RSA SecurID, PayPal has rolled out their own two-factor authentication (2FA) dongle.

While it's easy to dismiss random number key fobs as susceptible to man-in-the-middle attacks, I do think that if such this device were required on all accounts, it would significantly impact the effectiveness of traditional phishing scams -- assuming the attacker is actually going for </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2007/02/paypal-introduces-security-fob.html' title='Paypal Introduces Security Fob'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=6161403717378076434' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/6161403717378076434'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/6161403717378076434'/><author><name>todb</name></author></entry><entry><id>tag:blogger.com,1999:blog-20075889.post-116587210183958934</id><published>2006-12-11T15:14:00.001-06:00</published><updated>2006-12-11T15:21:41.856-06:00</updated><title type='text'>e-gold privacy (or lack thereof)</title><summary type='text'>Like TOR, e-gold is one of those Internet institutions which enjoys an aegis of libertarian-style privacy and freedom surrounding it. In that light, this Wired article is a fascinating read. On the one hand, E-gold is constantly getting harassed by the U.S. government for catering to international criminals, and on the other, e-gold is actively monitoring transactions and building associative </summary><link rel='alternate' type='text/html' href='http://www.planb-security.net/2006/12/e-gold-privacy-or-lack-thereof_11.html' title='e-gold privacy (or lack thereof)'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20075889&amp;postID=116587210183958934' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.planb-security.net/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/116587210183958934'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20075889/posts/default/116587210183958934'/><author><name>todb</name></author></entry></feed>