<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CUICQngyeyp7ImA9WxBbEkQ.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188</id><updated>2010-03-11T08:46:03.693+01:00</updated><title>Security4all - Dedicated to digital security, enterprise 2.0 and presentation skills</title><subtitle type="html">My Blog's main focus is to have a place to keep an overview on recent and useful information security news combined with a small interest in presentation skills, productivity and other random thoughts.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://blog.security4all.be/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://blog.security4all.be/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>1258</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Security4all" /><feedburner:info uri="security4all" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by-nc-sa/3.0/" /><logo>http://bp1.blogger.com/_hKfJbfbBxMU/SDnjCBFeBhI/AAAAAAAABNc/NDpT-OWXMc8/S1600-R/header+copy.jpg</logo><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecurity4all" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecurity4all" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecurity4all" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/Security4all" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecurity4all" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FSecurity4all" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FSecurity4all" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><entry gd:etag="W/&quot;AkQHSXs6eSp7ImA9WxBbEk0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-1453391610955543386</id><published>2010-03-10T08:43:00.004+01:00</published><updated>2010-03-10T09:05:38.511+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-10T09:05:38.511+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="application vulnerabilities" /><category scheme="http://www.blogger.com/atom/ns#" term="targeted attacks" /><title>IE6 &amp; IE7 zero day published in Microsoft Security Advisory 981374</title><content type="html">Another 0-day in Internet Explorer is being exploited as reported by Microsoft in &lt;a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"&gt;Security Advisory 981374 &lt;/a&gt; yesterday. IE  versions 6 and 7 are affected and according to reports, it's only being used in targeted attacks. Which makes it even more dangerous if you are a potential target since IDS and AV signatures might not be available at this point.&lt;br /&gt;&lt;br /&gt;No patch is available. User are recommended to upgrade to IE8 or use alternative browsers like Firefox with an add-on  that blocks script by default like Noscript. Allowing Flash and Java by default nowadays is not a safe practice anymore.&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2010/03/some-great-whitepapers-on-aurora.html"&gt;Some  great whitepapers on the Aurora attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/isps-in-trouble-ddos-and-targeted.html"&gt;ISPs   in trouble, DDoS and Targeted Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/10/isaca-event-changing-threat-targeted.html"&gt;ISACA   Event: The changing threat: Targeted Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/07/office-word-2002-sp3-zero-day-revealed.html"&gt;Office   Word 2002 SP3 Zero day revealed&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/05/united-tax-spearphishing-attack-and.html"&gt;United   Tax Spearphishing attack and a little Belgian twist&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/05/ceos-of-large-companies-targeted-in-new.html"&gt;CEOs   of large companies targeted in new whaling wave&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/this-is-how-good-targeted-attacks-are.html"&gt;This   is how good the targeted attacks are getting&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/which-non-executables-files-are.html"&gt;Which   non-executables files are targeted the most?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/03/securitynl-maarten-social-engineering.html"&gt;Security.nl,   Maarten, social engineering and targeted attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/social-engineering-put-to-test-how.html"&gt;Social   engineering put to the test. How would your employee score?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/03/social-engineering-pentesting-against.html"&gt;Social   engineering pentesting against your employees&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/03/do-we-need-user-education.html"&gt;Do   we need user education?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2007/06/spear-phishing-and-whaling.html"&gt;Spear   Phishing and Whaling&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-1453391610955543386?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YVngQR-0qDo:0oDRK0aVNeA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=YVngQR-0qDo:0oDRK0aVNeA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YVngQR-0qDo:0oDRK0aVNeA:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YVngQR-0qDo:0oDRK0aVNeA:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YVngQR-0qDo:0oDRK0aVNeA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YVngQR-0qDo:0oDRK0aVNeA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=YVngQR-0qDo:0oDRK0aVNeA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YVngQR-0qDo:0oDRK0aVNeA:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/YVngQR-0qDo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/1453391610955543386/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=1453391610955543386" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1453391610955543386?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1453391610955543386?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/YVngQR-0qDo/ie6-ie7-zero-day-published-in-microsoft.html" title="IE6 &amp; IE7 zero day published in Microsoft Security Advisory 981374" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/03/ie6-ie7-zero-day-published-in-microsoft.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ENQHw4cCp7ImA9WxBbEk0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-7832023452330522575</id><published>2010-03-10T07:47:00.003+01:00</published><updated>2010-03-10T08:21:31.238+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-10T08:21:31.238+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="targeted attacks" /><title>Some great whitepapers on the Aurora attacks</title><content type="html">While the Aurora attacks were a good user awareness situation, it has become a lot of hype and three letter acronyms about something that has been happening for a longer period of time.&lt;br /&gt;&lt;br /&gt;A few whitepapers have appeared that give us some juicy details about the dropper and backdoor and domain names used in the attacks. As well as the information they were after. Although ending with some vendor pitches, some are interesting read.&lt;br /&gt;&lt;br /&gt;1. The first one is a report from HBGary which you can download &lt;a href="http://www.hbgary.com/wp-content/themes/blackhat/images/hbgthreatreport_aurora.pdf"&gt;here&lt;/a&gt;. It contains some good technical information about the dropper and malware used.&lt;br /&gt;&lt;br /&gt;2. Then there is this McAfee whitepaper which has a lot more marketing fluff and more suited for CISA/Auditors (personal information will be asked for downloading but is not verified). A few good points but less technical details. It's mainly about the SCM they targeted.&lt;br /&gt;&lt;p style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;Specifically, we have concluded that, in several cases, the attackers  executed precision strikes to gain access to &lt;a href="http://en.wikipedia.org/wiki/Revision_control" onclick="javascript:pageTracker._trackPageview('/outbound/article/en.wikipedia.org');"&gt;source  code configuration management systems&lt;/a&gt; (SCMs) at targeted companies.  SCMs are used by software engineers to manage their projects and are  used to store source code, the crown jewels of any tech company.&lt;/span&gt;&lt;/p&gt; &lt;p style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;In our analysis of the attacks we found that the perpetrators went  through several hoops to ultimately compromise the systems of the SCM  users at the targeted organizations. This means that the attackers now  had access to the SCM system and could siphon out source code or, worse,  modify and add code. (Source: &lt;a href="http://siblog.mcafee.com/cto/source-code-repositories-targeted-in-operation-aurora/"&gt;McAfee&lt;/a&gt;)&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;Link to &lt;a href="http://resources.mcafee.com/forms/Aurora_VDTRG_WP"&gt;whitepaper&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;It might also be worth mentioning that there is&lt;a href="http://www.linkedin.com/groups?gid=2677290&amp;amp;trk=myg_ugrp_ovr"&gt; a LinkedIN group&lt;/a&gt; were articles and information about Aurora is being shared.&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/isps-in-trouble-ddos-and-targeted.html"&gt;ISPs  in trouble, DDoS and Targeted Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/10/isaca-event-changing-threat-targeted.html"&gt;ISACA  Event: The changing threat: Targeted Attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/07/office-word-2002-sp3-zero-day-revealed.html"&gt;Office  Word 2002 SP3 Zero day revealed&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/05/united-tax-spearphishing-attack-and.html"&gt;United  Tax Spearphishing attack and a little Belgian twist&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/05/ceos-of-large-companies-targeted-in-new.html"&gt;CEOs  of large companies targeted in new whaling wave&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/this-is-how-good-targeted-attacks-are.html"&gt;This  is how good the targeted attacks are getting&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/which-non-executables-files-are.html"&gt;Which  non-executables files are targeted the most?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/03/securitynl-maarten-social-engineering.html"&gt;Security.nl,  Maarten, social engineering and targeted attacks&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/social-engineering-put-to-test-how.html"&gt;Social  engineering put to the test. How would your employee score?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/03/social-engineering-pentesting-against.html"&gt;Social  engineering pentesting against your employees&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/03/do-we-need-user-education.html"&gt;Do  we need user education?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2007/06/spear-phishing-and-whaling.html"&gt;Spear  Phishing and Whaling&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-7832023452330522575?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=XGUDn9kE008:Qnq3bAPhfCM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=XGUDn9kE008:Qnq3bAPhfCM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=XGUDn9kE008:Qnq3bAPhfCM:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=XGUDn9kE008:Qnq3bAPhfCM:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=XGUDn9kE008:Qnq3bAPhfCM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=XGUDn9kE008:Qnq3bAPhfCM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=XGUDn9kE008:Qnq3bAPhfCM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=XGUDn9kE008:Qnq3bAPhfCM:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/XGUDn9kE008" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/7832023452330522575/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=7832023452330522575" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7832023452330522575?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7832023452330522575?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/XGUDn9kE008/some-great-whitepapers-on-aurora.html" title="Some great whitepapers on the Aurora attacks" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/03/some-great-whitepapers-on-aurora.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YBRXYyfCp7ImA9WxBbEUo.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-1180133817616331202</id><published>2010-03-09T22:24:00.005+01:00</published><updated>2010-03-09T22:45:54.894+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-09T22:45:54.894+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="patch" /><category scheme="http://www.blogger.com/atom/ns#" term="application vulnerabilities" /><title>Time to step up your Acrobat Reader patching. Attacks are on the rise.</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hKfJbfbBxMU/S5a_dQIz-BI/AAAAAAAACxY/VIVwl39_QVk/s1600-h/3909511118_7f54ce8aa8.jpg"&gt;&lt;img style="cursor: pointer; width: 251px; height: 378px;" src="http://1.bp.blogspot.com/_hKfJbfbBxMU/S5a_dQIz-BI/AAAAAAAACxY/VIVwl39_QVk/s400/3909511118_7f54ce8aa8.jpg" alt="" id="BLOGGER_PHOTO_ID_5446751308620232722" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you haven't patched the latest Acrobat Reader from two weeks ago, it might be time to step up the pace. If you look at &lt;a href="http://www.f-secure.com/weblog/archives/00001903.html"&gt;this blogpost&lt;/a&gt; from F-secure, you'll see that the PDF format has become the choice for targeted attacks. Within the security community, it's being nicknamed Penetration Document Format.&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;&lt;span class="rss:item"&gt;Because we're now seeing the vulnerability (CVE-2010-0188) being exploited in targeted attacks (&lt;a href="http://blogs.technet.com/mmpc/archive/2010/03/08/cve-2010-0188-patched-adobe-reader-vulnerability-is-actively-exploited-in-the-wild.aspx"&gt;Microsoft also&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Our sample was submitted by a European financial organization and the file name includes a reference to the &lt;a href="http://en.wikipedia.org/wiki/G-20_major_economies"&gt;G20&lt;/a&gt;. The exploit drops a downloader and attempts to make a connection to tiantian.ninth.biz. We detect this attack as Exploit:W32/PDFExploit.G. (source: &lt;a href="http://www.f-secure.com/weblog/archives/00001903.html"&gt;fsecure&lt;/a&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;If patches/upgrades are not possible, think about using the usual workaround like disabling javascript or installing alternative clients.&lt;br /&gt;&lt;br /&gt;PDFs can easily be used for info stealing purposed that evades AV, HIDS, etc... the victim doesn't event have to have admin privileges. Have a look at&lt;a href="http://blog.didierstevens.com/2010/03/08/pdf-info-stealer-poc/"&gt; this explanation&lt;/a&gt; from security expert Didier Stevens on how such an attack is performed. Didier has written numerous analyses of PDF malware in the past and is a known researcher in this field.&lt;br /&gt;&lt;br /&gt;On a small side note, Didier is going to give a malware analysis workshop at the &lt;a href="http://2010.brucon.org/"&gt;BruCON conference&lt;/a&gt;. This is the occasion to learn some PDF malware analysis techniques from him!!&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/0-day-in-adobe-flash-also-executable.html"&gt;0-Day in Adobe Flash, also executable from Acrobat Reader (updated)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/03/adobe-pushes-out-fix-for-reader-and.html"&gt;Adobe pushes out fix for Reader and Acrobat zero-day, one day ahead of schedule.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/03/sweet-irony-foxit-pdf-reader-releases.html"&gt;The sweet irony: Foxit PDF reader releases JBIG2 security patch&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/03/pdf-exploit-poc-without-any-user.html"&gt;PDF Exploit PoC without any user interaction&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/03/acrobat-reader-exploit-works-without.html"&gt;Acrobat reader exploit works without opening pdf&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/02/pdf-attacks-are-becoming-more.html"&gt;PDF attacks are becoming more widespread using ads&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/02/acrobat-reader-exploits-in-wild.html"&gt;Acrobat Reader exploits in the wild (updated)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from&lt;a href="http://www.flickr.com/photos/ludmila_tavares/" class="currentContextLink" id="contextLink_stream11751322@N02" name="Context Title"&gt; Ludmila Tavares' photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-1180133817616331202?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YhkrzGEcgN0:yvHzR2Zk5VY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=YhkrzGEcgN0:yvHzR2Zk5VY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YhkrzGEcgN0:yvHzR2Zk5VY:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YhkrzGEcgN0:yvHzR2Zk5VY:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YhkrzGEcgN0:yvHzR2Zk5VY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YhkrzGEcgN0:yvHzR2Zk5VY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=YhkrzGEcgN0:yvHzR2Zk5VY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=YhkrzGEcgN0:yvHzR2Zk5VY:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/YhkrzGEcgN0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/1180133817616331202/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=1180133817616331202" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1180133817616331202?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1180133817616331202?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/YhkrzGEcgN0/time-to-step-up-your-acrobat-reader.html" title="Time to step up your Acrobat Reader patching. Attacks are on the rise." /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_hKfJbfbBxMU/S5a_dQIz-BI/AAAAAAAACxY/VIVwl39_QVk/s72-c/3909511118_7f54ce8aa8.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/03/time-to-step-up-your-acrobat-reader.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0AMRXc7eip7ImA9WxBbEE0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-3676108835943232360</id><published>2010-03-08T00:30:00.004+01:00</published><updated>2010-03-08T00:49:44.902+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-08T00:49:44.902+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="community" /><category scheme="http://www.blogger.com/atom/ns#" term="belgian" /><category scheme="http://www.blogger.com/atom/ns#" term="hacking" /><title>Hackerspace Ghent (Whitespace or 0x20) will have their Open weekend on 19 - 21 March</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hKfJbfbBxMU/S5Q7VnfUv-I/AAAAAAAACxQ/bhbf24KrZuM/s1600-h/4010119736_18999fb993.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 300px;" src="http://1.bp.blogspot.com/_hKfJbfbBxMU/S5Q7VnfUv-I/AAAAAAAACxQ/bhbf24KrZuM/s400/4010119736_18999fb993.jpg" alt="" id="BLOGGER_PHOTO_ID_5446043091961429986" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I was happy to see that a second Hackerspace was starting in Belgium after the one in Brussels. And now after finding a location, they are ready to open their doors.&lt;br /&gt;&lt;br /&gt;More info at&lt;br /&gt;&lt;a href="http://hsg.bn2vs.com/Opening_Weekend"&gt;http://hsg.bn2vs.com/Opening_Weekend &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There will be presentations or workshops on topics like openWRT and IPv6. Let's not forget the opening drink (pssttt, they have Club Mate). Since it's a complete weekend, you don't have any excuse and have to drop by!!!&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2010/02/hackerspace-antwerp-in-bootstrap-mode.html"&gt;Hackerspace Antwerp in bootstrap mode&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2010/01/date-for-hackerspace-antwerp-startup.html"&gt;The date for the Hackerspace Antwerp Startup Meeting&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/12/discussing-about-hackerspace-antwerp.html"&gt;Discussing about Hackerspace Antwerp&lt;/a&gt;&lt;/li&gt;&lt;li&gt; &lt;div class="post hentry"&gt; &lt;a name="2020654797735972754"&gt;&lt;/a&gt;  &lt;a href="http://blog.security4all.be/2009/02/what-is-hackerspace.html"&gt;What is a hackerspace?&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/01/what-does-hackerspace-looks-like.html"&gt;What does a hackerspace look like? And the next Hackerspace Brussels meetup.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from&lt;a href="http://www.flickr.com/photos/laughingsquid/" class="currentContextLink" id="contextLink_stream27403767@N00" name="Context Title"&gt; Laughing Squid's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-3676108835943232360?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Wi_oMooISrY:CBGhx73MNDE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=Wi_oMooISrY:CBGhx73MNDE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Wi_oMooISrY:CBGhx73MNDE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Wi_oMooISrY:CBGhx73MNDE:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Wi_oMooISrY:CBGhx73MNDE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Wi_oMooISrY:CBGhx73MNDE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=Wi_oMooISrY:CBGhx73MNDE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Wi_oMooISrY:CBGhx73MNDE:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/Wi_oMooISrY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/3676108835943232360/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=3676108835943232360" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/3676108835943232360?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/3676108835943232360?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/Wi_oMooISrY/hackerspace-ghent-whitespace-or-0x20.html" title="Hackerspace Ghent (Whitespace or 0x20) will have their Open weekend on 19 - 21 March" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_hKfJbfbBxMU/S5Q7VnfUv-I/AAAAAAAACxQ/bhbf24KrZuM/s72-c/4010119736_18999fb993.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/03/hackerspace-ghent-whitespace-or-0x20.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUBRXoyeCp7ImA9WxBbEE0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-3635534316553427235</id><published>2010-03-08T00:13:00.003+01:00</published><updated>2010-03-08T00:24:14.490+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-03-08T00:24:14.490+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="censorship" /><category scheme="http://www.blogger.com/atom/ns#" term="cyberlaw" /><title>The Icelandic Modern Media Initiative addresses the key issues for free expression in the digital age</title><content type="html">&lt;object width="640" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/ZbGiPjIE1pE&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/ZbGiPjIE1pE&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;The goal of the IMMI proposal is to task the government with finding ways to strengthen freedom of expression around world and in Iceland, as well as providing strong protections for sources and whistleblowers. To this end the legal environment should be explored in such a way that the goals can be defined, and changes to law or new law proposals can be prepared. The legal environments of other countries should be considered, with the purpose of assembling the best laws to make Iceland a leader of freedoms of expression and information. We also feel it is high time to establish the first Icelandic international prize: The Icelandic Freedom of Expression Award.&lt;/span&gt;&lt;/blockquote&gt;More info can be found on &lt;a href="http://immi.is/"&gt;http://immi.is/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Have a look at this video. It's interesting to see what Wikileaks has inspired and this could mean a lot to free expression in the digital age and a good step towards fighting censorship.&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/10/ways-to-bypass-big-belgian-firewall.html"&gt;Ways to bypass the Big Belgian firewall&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/10/automated-social-networking.html"&gt;Automated Social Networking Surveillance Systems&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/according-to-child-support-groups-net.html"&gt;According to Child Support groups, Net filtering is a waste of money&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/big-brother-2009-has-rebellion-started.html"&gt;Big Brother 2009: Has the rebellion started?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/01/police-hacking-laws-moving-from-germany.html"&gt;Police hacking laws moving from Germany to the rest of Europe. Do as I say, not as I do.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/privacy-matters-movie-by-xs4all-to.html"&gt;Privacy matters: A movie by XS4ALL to raise user awareness to data surveillance&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-3635534316553427235?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mCw_Szpk4VI:V-1k9ku6j6E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=mCw_Szpk4VI:V-1k9ku6j6E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mCw_Szpk4VI:V-1k9ku6j6E:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mCw_Szpk4VI:V-1k9ku6j6E:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mCw_Szpk4VI:V-1k9ku6j6E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mCw_Szpk4VI:V-1k9ku6j6E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=mCw_Szpk4VI:V-1k9ku6j6E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mCw_Szpk4VI:V-1k9ku6j6E:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/mCw_Szpk4VI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/3635534316553427235/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=3635534316553427235" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/3635534316553427235?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/3635534316553427235?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/mCw_Szpk4VI/icelandic-modern-media-initiative.html" title="The Icelandic Modern Media Initiative addresses the key issues for free expression in the digital age" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/03/icelandic-modern-media-initiative.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0INRHs6fip7ImA9WxBVE08.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-8110982592451986540</id><published>2010-02-16T12:43:00.005+01:00</published><updated>2010-02-16T12:59:55.516+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-16T12:59:55.516+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="community" /><title>Call for Papers: BruCON 2010, 24-25 September</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hKfJbfbBxMU/S3qIGp2y9PI/AAAAAAAACxI/pR1oSBi-yWw/s1600-h/3933227435_1d1523d9e7.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 266px;" src="http://1.bp.blogspot.com/_hKfJbfbBxMU/S3qIGp2y9PI/AAAAAAAACxI/pR1oSBi-yWw/s400/3933227435_1d1523d9e7.jpg" alt="" id="BLOGGER_PHOTO_ID_5438809147899573490" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;2009 was the first edition of BruCON, a non-profit conference meant to unite all the people in and around Belgium interested in discussing computer security, privacy and computer technology related topics. It was a great first edition thanks to all the help of our partners and volunteers in the community.&lt;br /&gt;&lt;br /&gt;I'm happy that this event is moving towards a yearly gathering of like-minded people. Do you have an interesting topic to present or a cool workshop? Have a look at the full Call of Papers below.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.brucon.org/2010/02/brucon-2010-call-for-papers.html"&gt;http://blog.brucon.org/2010/02/brucon-2010-call-for-papers.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I hope to see you in September, if only to taste some Belgian beer or chocolate together. By preference not in combination! Although I heard of the existence of chocolate beer. ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-8110982592451986540?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yH4-Iap6Aws:0Xv13Twu_-E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=yH4-Iap6Aws:0Xv13Twu_-E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yH4-Iap6Aws:0Xv13Twu_-E:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yH4-Iap6Aws:0Xv13Twu_-E:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yH4-Iap6Aws:0Xv13Twu_-E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yH4-Iap6Aws:0Xv13Twu_-E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=yH4-Iap6Aws:0Xv13Twu_-E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yH4-Iap6Aws:0Xv13Twu_-E:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/yH4-Iap6Aws" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/8110982592451986540/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=8110982592451986540" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/8110982592451986540?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/8110982592451986540?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/yH4-Iap6Aws/call-for-papers-brucon-2010-24-25.html" title="Call for Papers: BruCON 2010, 24-25 September" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_hKfJbfbBxMU/S3qIGp2y9PI/AAAAAAAACxI/pR1oSBi-yWw/s72-c/3933227435_1d1523d9e7.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/02/call-for-papers-brucon-2010-24-25.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MMRXg4eip7ImA9WxBVEkk.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-7693267570047990929</id><published>2010-02-15T14:31:00.003+01:00</published><updated>2010-02-15T14:44:44.632+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-15T14:44:44.632+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="hackerspaces" /><title>Hackerspace Antwerp in bootstrap mode</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_hKfJbfbBxMU/S3lPLjI8E-I/AAAAAAAACw4/_oQ05fG0o_Y/s1600-h/IMG_0503%5B1%5D.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://2.bp.blogspot.com/_hKfJbfbBxMU/S3lPLjI8E-I/AAAAAAAACw4/_oQ05fG0o_Y/s320/IMG_0503%5B1%5D.jpg" alt="" id="BLOGGER_PHOTO_ID_5438465084856472546" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It seems that Hackerspace Antwerp is taking on form. We don't have a final name yet but we found a possible location to begin. It needs some work but it has loads of possibilities.&lt;br /&gt;&lt;br /&gt;Since my last post, we have a wiki and a mailinglist. Weekly meetings are now on Wednesday to keep things going. You'll find all the information on our wiki. Feel free to join us next Wednesday to help (&amp;amp; clean our new space). ;-)&lt;br /&gt;&lt;br /&gt;Wiki&lt;br /&gt;&lt;a href="http://antwerp.hackerspace.be/mw/index.php?title=Main_Page"&gt;http://antwerp.hackerspace.be/mw/index.php?title=Main_Page&lt;br /&gt;&lt;/a&gt;Mailinglist&lt;br /&gt;&lt;a href="http://discuss.hackerspaces.be/listinfo.cgi/antwerp-hackerspaces.be"&gt;http://discuss.hackerspaces.be/listinfo.cgi/antwerp-hackerspaces.be&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-7693267570047990929?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yZW90mOwAH4:JTg8ULdsW6w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=yZW90mOwAH4:JTg8ULdsW6w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yZW90mOwAH4:JTg8ULdsW6w:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yZW90mOwAH4:JTg8ULdsW6w:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yZW90mOwAH4:JTg8ULdsW6w:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yZW90mOwAH4:JTg8ULdsW6w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=yZW90mOwAH4:JTg8ULdsW6w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=yZW90mOwAH4:JTg8ULdsW6w:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/yZW90mOwAH4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/7693267570047990929/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=7693267570047990929" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7693267570047990929?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7693267570047990929?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/yZW90mOwAH4/hackerspace-antwerp-in-bootstrap-mode.html" title="Hackerspace Antwerp in bootstrap mode" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_hKfJbfbBxMU/S3lPLjI8E-I/AAAAAAAACw4/_oQ05fG0o_Y/s72-c/IMG_0503%5B1%5D.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/02/hackerspace-antwerp-in-bootstrap-mode.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYMSXo-fip7ImA9WxBRF0w.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-7057740602140657220</id><published>2010-01-05T13:54:00.004+01:00</published><updated>2010-01-05T20:03:08.456+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-05T20:03:08.456+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="antwerp" /><category scheme="http://www.blogger.com/atom/ns#" term="hackerspaces" /><title>The date for the Hackerspace Antwerp Startup Meeting</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hKfJbfbBxMU/S0OM0VgUecI/AAAAAAAACww/VzXTnSMYwDg/s1600-h/4010120394_b82269261a_b.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_hKfJbfbBxMU/S0OM0VgUecI/AAAAAAAACww/VzXTnSMYwDg/s320/4010120394_b82269261a_b.jpg" alt="" id="BLOGGER_PHOTO_ID_5423333207037999554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A lot of people responded for a startup meeting in Antwerp and are really divided over two possible dates. So I decided I will be there on both dates, although I can't stay very late.&lt;br /&gt;&lt;br /&gt;So on Saturday the 9th or Friday the 15th, please join us. Here is the original doodle: &lt;a href="http://doodle.com/pci5yiksm5nwimg6" target="_blank"&gt;http://&lt;span class="il"&gt;doodle&lt;/span&gt;.com/&lt;wbr&gt;pci5yiksm5nwimg6&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Feel free to comment and to share the link to others!!!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from "Scott Beale / &lt;a href="http://laughingsquid.com/"&gt;Laughing Squid&lt;/a&gt;") &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-7057740602140657220?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=SqQNy823SQs:kwDwSUFyBYQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=SqQNy823SQs:kwDwSUFyBYQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=SqQNy823SQs:kwDwSUFyBYQ:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=SqQNy823SQs:kwDwSUFyBYQ:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=SqQNy823SQs:kwDwSUFyBYQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=SqQNy823SQs:kwDwSUFyBYQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=SqQNy823SQs:kwDwSUFyBYQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=SqQNy823SQs:kwDwSUFyBYQ:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/SqQNy823SQs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/7057740602140657220/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=7057740602140657220" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7057740602140657220?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7057740602140657220?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/SqQNy823SQs/date-for-hackerspace-antwerp-startup.html" title="The date for the Hackerspace Antwerp Startup Meeting" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_hKfJbfbBxMU/S0OM0VgUecI/AAAAAAAACww/VzXTnSMYwDg/s72-c/4010120394_b82269261a_b.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/01/date-for-hackerspace-antwerp-startup.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04MQno7cCp7ImA9WxBVEkk.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-6117576471533258901</id><published>2010-01-04T01:09:00.005+01:00</published><updated>2010-02-15T14:53:03.408+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-15T14:53:03.408+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="community" /><category scheme="http://www.blogger.com/atom/ns#" term="26c3" /><title>Download the #26C3 videos and bonus material</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hKfJbfbBxMU/S0EyoY4k5ZI/AAAAAAAACwg/bThF354DVrs/s1600-h/53511162.jpg"&gt;&lt;img style="cursor: pointer; width: 240px; height: 320px;" src="http://1.bp.blogspot.com/_hKfJbfbBxMU/S0EyoY4k5ZI/AAAAAAAACwg/bThF354DVrs/s320/53511162.jpg" alt="" id="BLOGGER_PHOTO_ID_5422671095786694034" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So the 26th Chaos Communication Congress is over and it was a blast. For those that missed some talks (like me) or couldn't watch the live streams, you can download the video of almost all presentations.&lt;br /&gt;&lt;br /&gt;Best location to find the lastest videos is:&lt;br /&gt;&lt;a href="ftp://mirror.fem-net.de/CCC/26C3/"&gt;ftp://mirror.fem-net.de/CCC/26C3/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There you will find the videos in mp4-format, in mp3 or ogg audio files or mp4-ipod formatted videos.&lt;br /&gt;&lt;br /&gt;You can also watch the videos online thanks to &lt;a href="http://media.ccc.de/browse/congress/2009/index_1.html"&gt;CCC-TV&lt;/a&gt;. No need to download everything.&lt;br /&gt;&lt;br /&gt;I made some recordings of some the things happening around the conference. Check my &lt;a href="http://www.ustream.tv/channel/security4all"&gt;Ustream&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2010/01/date-for-hackerspace-antwerp-startup.html"&gt;The  date for the Hackerspace Antwerp Startup Meeting&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/02/what-is-hackerspace.html"&gt;What  is a hackerspace?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/01/what-does-hackerspace-looks-like.html"&gt;What  does a hackerspace looks like? And the next Hackerspace Brussels  meetup.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/12/hacker-space-brussels-wifi-workshop.html"&gt;Hacker  Space Brussels - Wifi Workshop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/new-hackerspace-brussels.html"&gt;New  hackerspace @ Brussels&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-6117576471533258901?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mjD2rdUU1Ug:iJ3Ock_yhxE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=mjD2rdUU1Ug:iJ3Ock_yhxE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mjD2rdUU1Ug:iJ3Ock_yhxE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mjD2rdUU1Ug:iJ3Ock_yhxE:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mjD2rdUU1Ug:iJ3Ock_yhxE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mjD2rdUU1Ug:iJ3Ock_yhxE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=mjD2rdUU1Ug:iJ3Ock_yhxE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=mjD2rdUU1Ug:iJ3Ock_yhxE:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/mjD2rdUU1Ug" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/6117576471533258901/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=6117576471533258901" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6117576471533258901?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6117576471533258901?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/mjD2rdUU1Ug/download-26c3-videos-and-bonus-material.html" title="Download the #26C3 videos and bonus material" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_hKfJbfbBxMU/S0EyoY4k5ZI/AAAAAAAACwg/bThF354DVrs/s72-c/53511162.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2010/01/download-26c3-videos-and-bonus-material.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04DSHk5fCp7ImA9WxBSFk0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-1609644380587382240</id><published>2009-12-23T22:27:00.003+01:00</published><updated>2009-12-23T23:06:19.724+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-23T23:06:19.724+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="antwerp" /><category scheme="http://www.blogger.com/atom/ns#" term="hackerspaces" /><title>Discussing about Hackerspace Antwerp</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hKfJbfbBxMU/SzKUUg0FE7I/AAAAAAAACwY/HVB1JRF0aqg/s1600-h/2684771440_07065859b6.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://4.bp.blogspot.com/_hKfJbfbBxMU/SzKUUg0FE7I/AAAAAAAACwY/HVB1JRF0aqg/s320/2684771440_07065859b6.jpg" alt="" id="BLOGGER_PHOTO_ID_5418556381806793650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some people have been thinking aloud about also starting a hackerspace in Antwerp. I decided to gather all these people and have a beer. Let's see if there are enough people to set the first step. If you know people that could be interested, please let them know.&lt;br /&gt;&lt;br /&gt;If you want to join us, have a look at &lt;a href="http://doodle.com/participation.html?pollId=pci5yiksm5nwimg6&amp;amp;0"&gt;http://doodle.com/participation.html?pollId=pci5yiksm5nwimg6&amp;amp;0&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;A &lt;span style="font-weight: bold;"&gt;hackerspace&lt;/span&gt; is an interdisciplinary community for learning, teaching, and creating. Instead of starting with a defined range of projects or programming, a hackerspace is driven by its members. It is a place where members have the infrastructure and resources to work on projects that interest them. Hackerspaces promote people to be hackers in the broadest sense: to learn all they can about the fields that interest them, explore their bounds, and create new and interesting ways to apply that knowledge.&lt;/span&gt;&lt;/span&gt; &lt;p style="font-style: italic;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;The people in a hackerspace also share their knowledge with others who share their interests, through classes, working groups, or day-to-day discussion while working on projects. That is where the fascinating educational potential of the hackerspace lies: there is no finite list of the skills that can be taught and exchanged. People share what they know with members and the community at large, and it results in more people having the knowledge to make something new and tangible out of their ideas and interests. (source: &lt;/span&gt;&lt;a style="font-style: italic;" href="http://pumpingstationone.org/2009/02/what-is-a-hackerspace/"&gt;pumping station one&lt;/a&gt;&lt;span style="font-style: italic;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/02/what-is-hackerspace.html"&gt;What is a hackerspace?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/01/what-does-hackerspace-looks-like.html"&gt;What does a hackerspace looks like? And the next Hackerspace Brussels meetup.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/12/hacker-space-brussels-wifi-workshop.html"&gt;Hacker Space Brussels - Wifi Workshop&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/new-hackerspace-brussels.html"&gt;New hackerspace @ Brussels&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from&lt;a href="http://www.flickr.com/photos/mightyohm/" class="currentContextLink" id="contextLink_stream28042570@N08"&gt; mightyohm's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-1609644380587382240?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=uGa-oaAAUmg:lfwSIZ68nY8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=uGa-oaAAUmg:lfwSIZ68nY8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=uGa-oaAAUmg:lfwSIZ68nY8:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=uGa-oaAAUmg:lfwSIZ68nY8:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=uGa-oaAAUmg:lfwSIZ68nY8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=uGa-oaAAUmg:lfwSIZ68nY8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=uGa-oaAAUmg:lfwSIZ68nY8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=uGa-oaAAUmg:lfwSIZ68nY8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/uGa-oaAAUmg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/1609644380587382240/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=1609644380587382240" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1609644380587382240?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1609644380587382240?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/uGa-oaAAUmg/discussing-about-hackerspace-antwerp.html" title="Discussing about Hackerspace Antwerp" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_hKfJbfbBxMU/SzKUUg0FE7I/AAAAAAAACwY/HVB1JRF0aqg/s72-c/2684771440_07065859b6.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/12/discussing-about-hackerspace-antwerp.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UMQ3gzfSp7ImA9WxBSE0w.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-1089843871640118380</id><published>2009-12-19T23:30:00.005+01:00</published><updated>2009-12-20T15:28:02.685+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-20T15:28:02.685+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><category scheme="http://www.blogger.com/atom/ns#" term="hacking" /><title>#26C3 Mobile Schedule for Android and iPhone</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hKfJbfbBxMU/Sy1bjRlD59I/AAAAAAAACwQ/8u1g5lk1y-o/s1600-h/2628869994_087a85722c_b.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 214px;" src="http://4.bp.blogspot.com/_hKfJbfbBxMU/Sy1bjRlD59I/AAAAAAAACwQ/8u1g5lk1y-o/s320/2628869994_087a85722c_b.jpg" alt="" id="BLOGGER_PHOTO_ID_5417086588368971730" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In less then a week, it will be time for the biggest hackerconference in Europe: The Chaos Communication Congress (which I will be visiting). I will be covering the event and documenting some tips.  Let's start with a few good ones.&lt;br /&gt;&lt;br /&gt;For your convenience, two applications were made with the 26C3: Here be Dragons Schedule (Fahrplan), &lt;a href="http://uk.androlib.com/android.screenshot.app.xnpx-xjim.u.aspx"&gt;one for Android&lt;/a&gt; and &lt;a href="http://j.mp/8Oj4Em"&gt;one for the iPhone&lt;/a&gt; (iTunes link). Kudos for the people who made them.&lt;br /&gt;&lt;br /&gt;If you don't have PDA/Smartphone but are bringing a DECT phone: &lt;span id="msgtxt6658665344" class="msgtxt en"&gt;Call Voicebarf on DECT#7666 to know the upcoming talks at that moment.&lt;br /&gt;&lt;br /&gt;There will also schedules displayed throughout the conference center so don't print them and save some trees.&lt;br /&gt;&lt;br /&gt;If you can't make it to the conference, several locations around the world will be displaying the live video streams. Go out and meet some new people. Check "&lt;a href="http://events.ccc.de/congress/2009/wiki/Dragons_everywhere"&gt;Dragons everywhere&lt;/a&gt;" for locations.&lt;br /&gt;&lt;br /&gt;If it's your first time to this conference, have a look at:&lt;a href="http://blog.security4all.be/2009/07/preparing-your-laptop-or-iphone-for.html"&gt; Preparing your laptop (or iPhone) for a security/hacker conference&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For all other matters, read through the &lt;a href="http://events.ccc.de/congress/2009/wiki/Main_Page"&gt;26C3 wiki&lt;/a&gt; and their &lt;a href="http://events.ccc.de/congress/2009/wiki/FrequentlyAskedQuestions"&gt;FAQ&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Follow &lt;a href="http://twitter.com/security4all/"&gt;@security4all&lt;/a&gt; on Twitter for live tweets about the conference or follow the #26c3 hashtag in general. Some clients like tweetdeck support following hashtags or you can use http://search.twitter.com. Either online or through an &lt;a href="http://search.twitter.com/search.atom?lang=en&amp;amp;q=%2326c3"&gt;RSS feed&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;If you want a free &lt;a href="http://www.brucon.org/"&gt;BruCON&lt;/a&gt; sticker, find me at the conference. ;-)&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/08/get-defcon-17-cd-archive.html"&gt;Get the #DEFCON 17 CD Archive (updated x2)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/day-2-collection-of-blackhat-articles.html"&gt;Day 2: A collection of #Blackhat articles: keeping remote track of the event&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/blackhat-slides-available-and-first.html"&gt;BlackHat slides available and first blogposts&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/how-to-follow-blackhatdefcon-without.html"&gt;How to follow Blackhat/Defcon without being there&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/preparing-your-laptop-or-iphone-for.html"&gt;Preparing your laptop (or iPhone) for a security/hacker conference&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from&lt;a href="http://www.flickr.com/photos/wili/" class="currentContextLink" id="contextLink_stream62223880@N00"&gt; wili_hybrid's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-1089843871640118380?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=M-_3IrFz-so:qL8VttPf5cc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=M-_3IrFz-so:qL8VttPf5cc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=M-_3IrFz-so:qL8VttPf5cc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=M-_3IrFz-so:qL8VttPf5cc:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=M-_3IrFz-so:qL8VttPf5cc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=M-_3IrFz-so:qL8VttPf5cc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=M-_3IrFz-so:qL8VttPf5cc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=M-_3IrFz-so:qL8VttPf5cc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/M-_3IrFz-so" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/1089843871640118380/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=1089843871640118380" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1089843871640118380?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1089843871640118380?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/M-_3IrFz-so/26c3-mobile-schedule-for-android-and.html" title="#26C3 Mobile Schedule for Android and iPhone" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_hKfJbfbBxMU/Sy1bjRlD59I/AAAAAAAACwQ/8u1g5lk1y-o/s72-c/2628869994_087a85722c_b.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://blog.security4all.be/2009/12/26c3-mobile-schedule-for-android-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YMQH48fip7ImA9WxNUEEw.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-6249293786646793554</id><published>2009-10-31T19:53:00.000+01:00</published><updated>2009-10-31T19:53:01.076+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-31T19:53:01.076+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="censorship" /><category scheme="http://www.blogger.com/atom/ns#" term="belgian" /><title>Ways to bypass the Big Belgian firewall</title><content type="html">Yes, the Belgian government can decide which websites we visit and which we don't. The first step on a road that will lead us to situations like we have seen in Australia (&lt;a href="http://blog.security4all.be/2009/07/according-to-child-support-groups-net.html"&gt;According to Child Support groups, Net filtering is a waste of money)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here is the best Belgian article I have read to date about this issue which covers all aspects :&lt;a href="http://www.zdnet.be/news/105509/zwarte-lijst-voor-belgische-surfers-omstreden/"&gt; "zwarte lijst voor belgische surfers omstreden" by &lt;span class="smalltext"&gt;Els Bellens&lt;/span&gt;&lt;/a&gt; (Zdnet.be)&lt;br /&gt;&lt;br /&gt;Like Tim Berners-Lee, inventor of the WWW stated, the internet was designed to be used without limitations. The main argument of government officials to start with this blacklist, is that "average users won't be able to stumble upon these bad websites anymore. It's for their own protection. "&lt;br /&gt;&lt;br /&gt;And in a typical Belgian fashion, (luckily for us), it's implemented in the least efficient manner: a DNS blacklist.&lt;br /&gt;&lt;br /&gt;And as expected, a lot of internet users (e.g. &lt;a href="http://www.blogologie.be/2009/04/acht-manieren-om-de-belgische-internet-censuur-te-omzeilen-op-rijm.html"&gt;blogologie&lt;/a&gt;,  &lt;a href="http://lvb.net/item/6976"&gt;lvb.net&lt;/a&gt;, &lt;a href="http://www.belgiancowboys.be/online/595"&gt;belgiancowboys.be&lt;/a&gt;, &lt;a href="http://www.tik.be/forum/viewtopic.php?f=21&amp;amp;t=10971&amp;amp;p=143842"&gt;tik vzw&lt;/a&gt;)  have started listing ways to bypass this filter just as a matter of principle (like the Streisand effect).&lt;br /&gt;&lt;br /&gt;So let's hope that this blacklist will go away and the government will stop throwing away money on an inefficient systems that will never work.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-6249293786646793554?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=5NTt-z66yzg:7UFgQRLzrlo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=5NTt-z66yzg:7UFgQRLzrlo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=5NTt-z66yzg:7UFgQRLzrlo:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=5NTt-z66yzg:7UFgQRLzrlo:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=5NTt-z66yzg:7UFgQRLzrlo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=5NTt-z66yzg:7UFgQRLzrlo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=5NTt-z66yzg:7UFgQRLzrlo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=5NTt-z66yzg:7UFgQRLzrlo:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/5NTt-z66yzg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/6249293786646793554/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=6249293786646793554" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6249293786646793554?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6249293786646793554?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/5NTt-z66yzg/ways-to-bypass-big-belgian-firewall.html" title="Ways to bypass the Big Belgian firewall" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.security4all.be/2009/10/ways-to-bypass-big-belgian-firewall.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ENRH88cCp7ImA9WxNVF0g.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-1611250454532730901</id><published>2009-10-28T19:42:00.004+01:00</published><updated>2009-10-28T19:48:15.178+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-28T19:48:15.178+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="surveillance projects" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Sign against Dataretention - bewaarjeprivacy.be</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hKfJbfbBxMU/SuiR5NCFNVI/AAAAAAAACvQ/MYMoneeikA4/s1600-h/acquia_marina_logo.gif"&gt;&lt;img style="cursor: pointer; width: 320px; height: 127px;" src="http://4.bp.blogspot.com/_hKfJbfbBxMU/SuiR5NCFNVI/AAAAAAAACvQ/MYMoneeikA4/s320/acquia_marina_logo.gif" alt="" id="BLOGGER_PHOTO_ID_5397724565340501330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Finally something in Belgium to be proud of. Several organizations in Belgium representing internet users, lawyers, journalists, etc.... have started a petition against the Belgian adaptation of the EU Dataretention law.&lt;br /&gt;&lt;br /&gt;Why should you sign this petition?&lt;br /&gt;&lt;ul&gt;&lt;li&gt;It's an invasion on your privacy&lt;/li&gt;&lt;li&gt;It makes 10 million Belgians potential suspects&lt;/li&gt;&lt;li&gt;It invades the professional confidentiality between lawyers and their clients, journalists and their sources etc....&lt;/li&gt;&lt;li&gt;The necessity of Dataretention has yet to be proven&lt;/li&gt;&lt;li&gt;Dataretention provides no guarantee against terrorism or crime&lt;/li&gt;&lt;li&gt;It will result in a high price that consumers will have to pay....&lt;/li&gt;&lt;/ul&gt;So go to http://bewaarjeprivacy.be/ and sign the petition.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-1611250454532730901?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=hEES7AD3vrQ:6fdUMEOmbZE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=hEES7AD3vrQ:6fdUMEOmbZE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=hEES7AD3vrQ:6fdUMEOmbZE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=hEES7AD3vrQ:6fdUMEOmbZE:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=hEES7AD3vrQ:6fdUMEOmbZE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=hEES7AD3vrQ:6fdUMEOmbZE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=hEES7AD3vrQ:6fdUMEOmbZE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=hEES7AD3vrQ:6fdUMEOmbZE:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/hEES7AD3vrQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/1611250454532730901/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=1611250454532730901" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1611250454532730901?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1611250454532730901?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/hEES7AD3vrQ/sign-against-dataretention.html" title="Sign against Dataretention - bewaarjeprivacy.be" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_hKfJbfbBxMU/SuiR5NCFNVI/AAAAAAAACvQ/MYMoneeikA4/s72-c/acquia_marina_logo.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/10/sign-against-dataretention.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIFQ348fip7ImA9WxNVFko.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-1811965455852829578</id><published>2009-10-27T21:14:00.005+01:00</published><updated>2009-10-27T22:21:52.076+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-27T22:21:52.076+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="surveillance projects" /><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Automated Social Networking Surveillance Systems</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hKfJbfbBxMU/SudioJeZ8PI/AAAAAAAACvI/oQMSBJ5CIYE/s1600-h/3763967120_2bd063e61c.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 213px;" src="http://3.bp.blogspot.com/_hKfJbfbBxMU/SudioJeZ8PI/AAAAAAAACvI/oQMSBJ5CIYE/s320/3763967120_2bd063e61c.jpg" alt="" id="BLOGGER_PHOTO_ID_5397391120304566514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Last week, I noticed the existence of an EU surveillance project called "Intelligent information system supporting  observation, searching and detection for security of citizens in urban  environment" better known as "&lt;a href="http://www.indect-project.eu/"&gt;INDECT&lt;/a&gt;". You can have a look at their official website.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;According to &lt;/span&gt;&lt;em style="font-style: italic;"&gt;Wikileaks&lt;/em&gt;&lt;span style="font-style: italic;"&gt;, INDECT’s “Work package 4″ is designed “to comb web blogs, chat sites, news reports, and social-networking sites in order to build up automatic dossiers on individuals, organizations and their relationships.” Ponder that phrase again: “automatic dossiers.” (&lt;/span&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;&lt;a href="http://dissidentvoice.org/2009/10/mind-your-tweets-cia-and-european-union-building-social-networking-surveillance-system/"&gt;source&lt;/a&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;)&lt;/span&gt;&lt;/blockquote&gt;Automatic dossiers? Doesn't that give you a warm fuzzy feeling inside? There are a lot more reports and articles mentioned about similar projects (including network monitoring and data mining suites designed by Nokia Siemens, Ericsson and Verint) on &lt;a href="http://dissidentvoice.org/2009/10/mind-your-tweets-cia-and-european-union-building-social-networking-surveillance-system/"&gt;this website&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I enjoy and believe in the benefits of social networks as long as commons sense prevails about what you publish. But how many people are aware of the potential issues? Not that mass surveillance should be expected and allowed.&lt;br /&gt;Say a word online out of context and be labeled a potential 'problem' case. I don't believe in a technological magic wand who will correctly filter information. Too much possible false positives. Hasn't the world of IDS taught us that? Question is, who is making the alert filters for this systems? Who is going to watch the watchers?&lt;br /&gt;&lt;br /&gt;Some time ago, the &lt;a href="http://socialmediasecurity.com/"&gt;Social Media Security&lt;/a&gt; blog and podcast was founded. While I haven't really had time to spend some time on it, I highly advice to have a closer look at it.&lt;br /&gt;&lt;br /&gt;So apart from cybercriminals, must we also fear our governments?&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/09/international-action-day-freedom-not.html"&gt;International Action Day “Freedom not Fear 2009 – Stop the Surveillance Mania!” on 12th September 2009&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/according-to-child-support-groups-net.html"&gt;According to Child Support groups, Net filtering is a waste of money&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/big-brother-2009-has-rebellion-started.html"&gt;Big Brother 2009: Has the rebellion started?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/privacy-matters-movie-by-xs4all-to.html"&gt;Privacy matters: A movie by XS4ALL to raise user awareness to data surveillance&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/enisas-new-paper-inside-matrix-privacy.html"&gt;ENISA's New Paper: "Inside the matrix: Privacy &amp;amp; data protection challenges".&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2008/11/dress-good-google-streetview-driving.html"&gt;Dress good! Google Streetview driving around in Belgium.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/11/enisa-releases-paper-on-security-and.html"&gt;ENISA releases paper on Security and Privacy in online games and social and corporate virtual worlds&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/07/skype-backdoor-speculation-and-data.html"&gt;Skype backdoor speculation and Data surveillance of today&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2007/09/fbi-wiretapping-just-point-and-click.html"&gt;FBI Wiretapping: Just point and click&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/05/chinas-golden-shield-citizen-mass.html"&gt;China's golden shield, a citizen mass surveillance system&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/06/dangers-of-social-networking-and-some.html"&gt;The dangers of social networking and some countermeasures&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/06/german-id-card-wont-include.html"&gt;German ID card won't include fingerprints&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/05/billion-pound-uk-cctv-solves-3-of.html"&gt;Billion pound UK CCTV solves 3% of crimes. Efficient?&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/when-technology-takes-over-our-life.html"&gt;When technology takes over our life&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/04/airport-security-all-your-data-are.html"&gt;Airport Security: All your data are belong to us&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/02/dutch-government-wants-fingerprints-of.html"&gt;Dutch government wants fingerprints of every dutchman in national database&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/01/wikileaks-releases-details-on-german.html"&gt;Wikileaks releases details on German police Trojan&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://security4all.blogspot.com/2008/01/eu-might-decide-that-ip-is-personal.html"&gt;EU might decide that an IP is personal information&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from  &lt;a href="http://www.flickr.com/photos/matthileo/" class="currentContextLink" id="contextLink_stream38383999@N06"&gt;matthileo's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-1811965455852829578?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=34cUN0eS_jw:f2i9Uvgym0c:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=34cUN0eS_jw:f2i9Uvgym0c:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=34cUN0eS_jw:f2i9Uvgym0c:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=34cUN0eS_jw:f2i9Uvgym0c:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=34cUN0eS_jw:f2i9Uvgym0c:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=34cUN0eS_jw:f2i9Uvgym0c:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=34cUN0eS_jw:f2i9Uvgym0c:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=34cUN0eS_jw:f2i9Uvgym0c:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/34cUN0eS_jw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/1811965455852829578/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=1811965455852829578" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1811965455852829578?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/1811965455852829578?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/34cUN0eS_jw/automated-social-networking.html" title="Automated Social Networking Surveillance Systems" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_hKfJbfbBxMU/SudioJeZ8PI/AAAAAAAACvI/oQMSBJ5CIYE/s72-c/3763967120_2bd063e61c.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/10/automated-social-networking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IMQ308cSp7ImA9WxNVFkg.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-6385335515544270871</id><published>2009-10-27T14:10:00.004+01:00</published><updated>2009-10-27T14:53:02.379+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-27T14:53:02.379+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>Privacy and the 'Belgian Mobility Card' (BMC)</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_hKfJbfbBxMU/Sub5ezQXWiI/AAAAAAAACvA/aVFvPLiI7Ow/s1600-h/1228792871_b1c07016b5.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_hKfJbfbBxMU/Sub5ezQXWiI/AAAAAAAACvA/aVFvPLiI7Ow/s320/1228792871_b1c07016b5.jpg" alt="" id="BLOGGER_PHOTO_ID_5397275511000357410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It has been some while since we blogged about  the "&lt;a href="http://blog.security4all.be/2009/01/privacy-failure-in-belgian-rfid.html"&gt;Privacy failure in the Belgian RFID transport card&lt;/a&gt;", but the card will still be introduced nationally.&lt;br /&gt;&lt;br /&gt;See &lt;a href="http://www.datanews.be/nl/90-6-26725/article.html?cid=rss#90;6;26725"&gt;Chipkaarten De Lijn niet voor volgend jaar&lt;/a&gt; (datanews)&lt;br /&gt;&lt;br /&gt;Testing will occur in 2010 and the rollout will happen during 2011 and 2012. Time to go over some past facts.&lt;br /&gt;&lt;br /&gt;Some researchers of the UCL published a report about a privacy issue together with opensource tools that they used to test the card. On &lt;a href="http://www.uclouvain.be/sites/security/mobib.html"&gt;http://www.uclouvain.be/sites/security/mobib.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;But the details of the research were removed soon after, together with the tool. Why? Were they pressured in removing it? What would the benefit be in removing it? Don't people know that security by obscurity doesn't work? Sound a bit like a conspiracy, considering who owns the transport card company and who subsides the university. But we can't say for sure.&lt;br /&gt;&lt;br /&gt;Some details could still be found via google:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.uclouvain.be/sites/security/download/slides/Avoine-2009-iwrt-slides.pdf"&gt;http://www.uclouvain.be/sites/security/download/slides/Avoine-2009-iwrt-slides.pdf&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;From the PDF:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;Personal data are stored in the clear in the card.&lt;/span&gt; &lt;ul style="font-style: italic;"&gt;&lt;li&gt;Data stored in the card during its personalization: name of the holder, birthdate, zipcode, language, etc.&lt;/li&gt;&lt;/ul&gt;&lt;ul style="font-style: italic;"&gt;&lt;li&gt;Data recorded by the card when used for validations: last three validations (date, time, bus line, bus stop, subway station, etc.), and some additional technical data.&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;How can this not be an issue? This can totally be abused by stalkers with a good antenna and a laptop in their backpack, just to name one of the obvious abuses. Fathers, lock up your wife and your daughters.&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;So I hope that the MIVB/STIB, minister Hilde Crevits and other parties involving the Belgian Mobility Card (BMC) will do the right thing and NOT store this sensitive information in the clear before launching this card!!!&lt;br /&gt;&lt;br /&gt;Claiming that our national ID contains the same public information is true but it is not on a contactless card. Meaning I have to take it out of your wallet and physically put it in a reader. Comparing those two and claiming there is no issue with cleartext information on a wireless chip is a fantasy story.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;There is enough information and other tools available to read the info on the card. e.g.&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://rfidiot.org/"&gt;rfidiot.org&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://wiki.yobi.be/wiki/MOBIB"&gt;http://wiki.yobi.be/wiki/MOBIB&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a href="http://wiki.yobi.be/wiki/MOBIB"&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/a&gt;Other online articles mentioning the issue:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://pgzlog.wordpress.com/2009/01/12/met-mobib-op-het-openbaar-vervoer-in-brussel-uw-gegevens-te-grabbel/" rel="bookmark" title="Permanente verwijzing naar Met Mobib op het openbaar vervoer in Brussel: uw gegevens te grabbel?"&gt;Met Mobib op het openbaar vervoer in Brussel: uw gegevens te grabbel?&lt;/a&gt; (Permanent Gecontroleerde Zones)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.brusselnieuws.be/artikels/stadsnieuws/gekraakte-mobib-kaart-doet-vragen-rijzen-naar-privacy"&gt;Gekraakte Mobib-kaart doet vragen rijzen naar privacy&lt;/a&gt; (Brussel Nieuws)&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from&lt;a href="http://www.flickr.com/photos/12098005@N06/" class="currentContextLink" id="contextLink_stream12098005@N06"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;Jools of Sweden's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-6385335515544270871?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=047cUKlUK6o:yhqeuVW0-bI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=047cUKlUK6o:yhqeuVW0-bI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=047cUKlUK6o:yhqeuVW0-bI:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=047cUKlUK6o:yhqeuVW0-bI:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=047cUKlUK6o:yhqeuVW0-bI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=047cUKlUK6o:yhqeuVW0-bI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=047cUKlUK6o:yhqeuVW0-bI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=047cUKlUK6o:yhqeuVW0-bI:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/047cUKlUK6o" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/6385335515544270871/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=6385335515544270871" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6385335515544270871?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6385335515544270871?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/047cUKlUK6o/privacy-and-belgian-mobility-card-bmc.html" title="Privacy and the 'Belgian Mobility Card' (BMC)" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_hKfJbfbBxMU/Sub5ezQXWiI/AAAAAAAACvA/aVFvPLiI7Ow/s72-c/1228792871_b1c07016b5.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/10/privacy-and-belgian-mobility-card-bmc.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cERH85eip7ImA9WxNWE0k.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-8553998482543750613</id><published>2009-10-12T12:41:00.003+02:00</published><updated>2009-10-12T12:56:45.122+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-12T12:56:45.122+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="user awareness" /><category scheme="http://www.blogger.com/atom/ns#" term="business continuity" /><title>Flu epidemic already announced in Belgium</title><content type="html">First of all, this is about the general flu epidemic which occurs every year. It's nothing H1N1 specific, which has been overhyped. Act normal and use common sense. But this is relevant information. Apply good hand hygiene, eat healthy and get enough sleep. Enough said.&lt;br /&gt;&lt;br /&gt;The Belgian center for Flu Control announced a flu epidemic in their &lt;a href="http://www.iph.fgov.be/flu/EN/Y2009-Influenza.pdf"&gt;latest week report&lt;/a&gt; (pdf) mentioned in their &lt;a href="http://www.iph.fgov.be/flu/NL/22NL.htm"&gt;weekly newsletter&lt;/a&gt;. Here is the interesting bit translated to English.&lt;br /&gt;&lt;br /&gt;Influenza Surveillance for week 40 (28 September tot 4 October)&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;The epidemic findings for week 40 are: The surveyed data show a heightened circulation of the Influenza virus and a moderate activity for the flu symptoms. According to the determined criteria, the flu epidemic has started.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The number of H1N1 cases have doubled compared to last week and was estimated at 4160 in week 39 with a cumulative total of 12678.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;Google search results and other online sources are also a good indicator and they do confirm the results of the Belgian flu center. Have a look at the B.V.L.G blog for &lt;a href="http://bvlg.blogspot.com/2009/10/griepepidemie.html"&gt;a detailed analysis&lt;/a&gt; (Dutch) with some nice graphs.&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/04/business-continuity-and-useful.html"&gt;Business continuity and useful resources about the N1H1 Swine Flu.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-8553998482543750613?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=fx0njBiqKpA:Q38pL6i3b10:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=fx0njBiqKpA:Q38pL6i3b10:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=fx0njBiqKpA:Q38pL6i3b10:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=fx0njBiqKpA:Q38pL6i3b10:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=fx0njBiqKpA:Q38pL6i3b10:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=fx0njBiqKpA:Q38pL6i3b10:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=fx0njBiqKpA:Q38pL6i3b10:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=fx0njBiqKpA:Q38pL6i3b10:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/fx0njBiqKpA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/8553998482543750613/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=8553998482543750613" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/8553998482543750613?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/8553998482543750613?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/fx0njBiqKpA/flu-epidemic-already-announced-in.html" title="Flu epidemic already announced in Belgium" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/10/flu-epidemic-already-announced-in.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQCQ3k5eSp7ImA9WxNXE0Q.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-3508727325200337376</id><published>2009-10-01T12:42:00.008+02:00</published><updated>2009-10-01T13:26:02.721+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-01T13:26:02.721+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="browser" /><title>Null character MITM Certificate released</title><content type="html">This year Dan Kaminsky and Moxie Marlinspike discovered that when requesting a certificate for example "Paypal.com\0.phishing.com" that some CAs would approve the request. What made it worse is that SSL client (and browsers) would ignore the characters after the null character, leading to an effective SSL Man in the Middle attack.&lt;br /&gt;&lt;br /&gt;Although it isn't possible to request these certificates anymore, Jacob Appelbaum &lt;a href="https://www.noisebridge.net/pipermail/noisebridge-discuss/2009-September/008400.html"&gt;released such a certificate&lt;/a&gt; yesterday together with the private key, stating that everybody had time enough to fix the issue. If you're a developer, you might want to look into this issue. For example &lt;a href="http://twitter.com/bug_bear/statuses/4497477845"&gt;Blackberries were still vulnerable to the attack&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Firefox patched the issue a few days after the initial presentation but other browsers like IE and Chrome rely on Microsoft's CryptoAPI to process the certificate and are still vulnerable.&lt;br /&gt;&lt;em&gt; &lt;blockquote&gt;&lt;a href="http://www.theregister.co.uk/2009/10/01/microsoft_crypto_ssl_bug/"&gt;&lt;span style="font-size:85%;"&gt;&lt;em&gt;"There are thousands of products on Windows right now that are still vulnerable to this SSL attack, and if someone were to publicly publish a targeted null prefix certificate, they'd be in trouble," said the white-hat hacker, who goes by the moniker Moxie Marlinspike. "Basically, everything that runs on Windows would be vulnerable with that one certificate."&lt;/em&gt;&lt;/span&gt;&lt;/a&gt; (source: &lt;a href="http://www.theregister.co.uk/2009/10/01/microsoft_crypto_ssl_bug/"&gt;Theregister.co.uk&lt;/a&gt;)&lt;a href="http://www.theregister.co.uk/2009/10/01/microsoft_crypto_ssl_bug/"&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;Note: The wildcard SSL certificate that Jacob Appelbaum released tricks older versions of the Network Security Services library into authenticating any website on the internet. But a lot of other applications using CryptoAPI might still be vulnerable to similar SSL MITM attacks. Time to patch the API like Firefox did. &lt;p&gt;Previous posts: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.brucon.org/2009/09/download-brucon-videos-and.html"&gt;Download the #brucon videos and presentations&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/08/collection-of-defcon-17-articles-videos.html"&gt;Collection of Defcon 17 articles, videos, pictures and podcasts&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/day-2-collection-of-blackhat-articles.html"&gt;Day 2: A collection of #Blackhat articles: keeping remote track of the event&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/blackhat-slides-available-and-first.html"&gt;BlackHat slides available and first blogposts&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-3508727325200337376?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=m3cDuSEwcls:jN4l6lKYQtw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=m3cDuSEwcls:jN4l6lKYQtw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=m3cDuSEwcls:jN4l6lKYQtw:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=m3cDuSEwcls:jN4l6lKYQtw:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=m3cDuSEwcls:jN4l6lKYQtw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=m3cDuSEwcls:jN4l6lKYQtw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=m3cDuSEwcls:jN4l6lKYQtw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=m3cDuSEwcls:jN4l6lKYQtw:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/m3cDuSEwcls" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/3508727325200337376/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=3508727325200337376" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/3508727325200337376?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/3508727325200337376?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/m3cDuSEwcls/null-character-mitm-certificate.html" title="Null character MITM Certificate released" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/10/null-character-mitm-certificate.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAGQ349fip7ImA9WxNXEkg.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-5652336950577367017</id><published>2009-09-29T21:52:00.004+02:00</published><updated>2009-09-29T22:38:42.066+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-29T22:38:42.066+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="community" /><category scheme="http://www.blogger.com/atom/ns#" term="networking" /><title>Security bloggers meetup London @ RSA</title><content type="html">Well, like last year us securitybloggers (-twits) are coming together for a drink and meet the people behind the avatars. It was a small but fun beginning last year and we hope to see even more people this year.&lt;br /&gt;&lt;br /&gt;Details on location etc... can be found on &lt;a href="http://blog.securityactive.co.uk/2009/09/29/rsa-security-bloggers-meet-up-09-3-weeks-away/"&gt;securityactive.co.uk&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-5652336950577367017?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=--obOhXuYi4:eBnXg-KCa5A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=--obOhXuYi4:eBnXg-KCa5A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=--obOhXuYi4:eBnXg-KCa5A:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=--obOhXuYi4:eBnXg-KCa5A:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=--obOhXuYi4:eBnXg-KCa5A:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=--obOhXuYi4:eBnXg-KCa5A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=--obOhXuYi4:eBnXg-KCa5A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=--obOhXuYi4:eBnXg-KCa5A:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/--obOhXuYi4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/5652336950577367017/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=5652336950577367017" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/5652336950577367017?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/5652336950577367017?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/--obOhXuYi4/security-bloggers-meetup-london-rsa.html" title="Security bloggers meetup London @ RSA" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/09/security-bloggers-meetup-london-rsa.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUUFRno4fCp7ImA9WxNXEk8.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-7705584596091042620</id><published>2009-09-29T12:56:00.004+02:00</published><updated>2009-09-29T13:20:17.434+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-29T13:20:17.434+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="vista" /><category scheme="http://www.blogger.com/atom/ns#" term="windows" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><title>SMBv2 exploit for Vista and Server 2008 released</title><content type="html">&lt;span id="articleBody"&gt;While I was too busy with BruCON, it seems that a SMBv2 vulnerability was published: &lt;a href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;Security Advisory 975497&lt;/a&gt;. While it affects Windows Vista and Server 2008, other versions are not vulnerable (including &lt;/span&gt;Windows 7 and Windows Server 2008 R2)&lt;span id="articleBody"&gt;.&lt;br /&gt;&lt;br /&gt;Port 445 needs to be open for the service to be exploited. Microsoft hasn't released an (out of band) patch since there was no working exploit code but promised to do so if the threat landscape changed. Blocking  ports 135 and 445 is one of the recommended countermeasures. You can also &lt;a href="http://www.microsoft.com/technet/security/advisory/975497.mspx"&gt;disable SMBv2 through a registry key&lt;/a&gt; if not needed.&lt;br /&gt;&lt;br /&gt;So far it was only possible to crash the service, but that changed today. &lt;a href="http://trac.metasploit.com/browser/framework3/trunk/modules/exploits/windows/smb/smb2_negotiate_func_index.rb"&gt;Working code&lt;/a&gt; has now been added to Metasploit. Although the code still needs improvement, it worked on several machines.&lt;br /&gt;&lt;br /&gt;So, will we see new worms coming our way? Although Conficker was well written, fortunately it wasn't really used to it's full potential. Will we be that lucky again?&lt;br /&gt;&lt;br /&gt;Discuss vulnerabilities instead of patches at your patch meetings, because only patching doesn't cut it. Have a look at &lt;a href="http://csrc.nist.gov/publications/nistpubs/800-40-Ver2/SP800-40v2.pdf"&gt;NIST's Creating a patch and vulnerability management program&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-7705584596091042620?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Qz_TJgmR6XY:wQLXB2MGFrQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=Qz_TJgmR6XY:wQLXB2MGFrQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Qz_TJgmR6XY:wQLXB2MGFrQ:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Qz_TJgmR6XY:wQLXB2MGFrQ:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Qz_TJgmR6XY:wQLXB2MGFrQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Qz_TJgmR6XY:wQLXB2MGFrQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=Qz_TJgmR6XY:wQLXB2MGFrQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Qz_TJgmR6XY:wQLXB2MGFrQ:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/Qz_TJgmR6XY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/7705584596091042620/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=7705584596091042620" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7705584596091042620?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7705584596091042620?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/Qz_TJgmR6XY/smbv2-exploit-for-vista-and-server-2008.html" title="SMBv2 exploit for Vista and Server 2008 released" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/09/smbv2-exploit-for-vista-and-server-2008.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUHSX0zcSp7ImA9WxNQGE4.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-7419607366722414600</id><published>2009-09-25T00:43:00.001+02:00</published><updated>2009-09-25T00:43:58.389+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-25T00:43:58.389+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="belgian" /><title>CERT.be is hiring</title><content type="html">As was told during &lt;a href="http://www.brucon.org/index.php/Presentations"&gt;BruCON&lt;/a&gt;, we can stop complaining about a missing CERT in Belgium. BELNET is looking for people to extend their team and the team should be up and running by January 2010. A big applause for their introduction!&lt;br /&gt;&lt;br /&gt;If you are interested, look at their website &lt;a href="https://www.cert.be/jobs"&gt;cert.be/jobs&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-7419607366722414600?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=V0F-5C-iilo:EwT6zhcPpTE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=V0F-5C-iilo:EwT6zhcPpTE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=V0F-5C-iilo:EwT6zhcPpTE:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=V0F-5C-iilo:EwT6zhcPpTE:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=V0F-5C-iilo:EwT6zhcPpTE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=V0F-5C-iilo:EwT6zhcPpTE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=V0F-5C-iilo:EwT6zhcPpTE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=V0F-5C-iilo:EwT6zhcPpTE:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/V0F-5C-iilo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/7419607366722414600/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=7419607366722414600" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7419607366722414600?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7419607366722414600?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/V0F-5C-iilo/certbe-is-hiring.html" title="CERT.be is hiring" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/09/certbe-is-hiring.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkUCRXg4fCp7ImA9WxNRFE8.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-6266281198757143949</id><published>2009-09-08T18:36:00.003+02:00</published><updated>2009-09-08T18:44:24.634+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-08T18:44:24.634+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="privacy" /><title>International Action Day “Freedom not Fear 2009 – Stop the Surveillance Mania!” on 12th September 2009</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_hKfJbfbBxMU/SqaJtii1dyI/AAAAAAAACuw/y3C8SErzAFU/s1600-h/1409483266_b2cdf2f841.jpg"&gt;&lt;img style="cursor: pointer; width: 240px; height: 320px;" src="http://4.bp.blogspot.com/_hKfJbfbBxMU/SqaJtii1dyI/AAAAAAAACuw/y3C8SErzAFU/s320/1409483266_b2cdf2f841.jpg" alt="" id="BLOGGER_PHOTO_ID_5379138220400670498" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I somehow completely missed any communication about this &lt;b&gt;International Action Day “Freedom not Fear 2009.&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Unfortunately, it seems that it is on the 12th of September already and that there is nothing planned in Brussels. Bad communication? Or is there nobody in Belgium at least a little bit interested in their privacy and civil rights?&lt;br /&gt;&lt;br /&gt;More info on &lt;a href="http://wiki.vorratsdatenspeicherung.de/Freedom_Not_Fear_2009"&gt;http://wiki.vorratsdatenspeicherung.de/Freedom_Not_Fear_2009&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from&lt;a href="http://www.flickr.com/photos/maha-online/" class="currentContextLink" id="contextLink_stream74203222@N00"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;maha-online's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-6266281198757143949?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=byaPi7-8-d0:dAzBbkJC3Xc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=byaPi7-8-d0:dAzBbkJC3Xc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=byaPi7-8-d0:dAzBbkJC3Xc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=byaPi7-8-d0:dAzBbkJC3Xc:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=byaPi7-8-d0:dAzBbkJC3Xc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=byaPi7-8-d0:dAzBbkJC3Xc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=byaPi7-8-d0:dAzBbkJC3Xc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=byaPi7-8-d0:dAzBbkJC3Xc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/byaPi7-8-d0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/6266281198757143949/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=6266281198757143949" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6266281198757143949?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6266281198757143949?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/byaPi7-8-d0/international-action-day-freedom-not.html" title="International Action Day “Freedom not Fear 2009 – Stop the Surveillance Mania!” on 12th September 2009" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_hKfJbfbBxMU/SqaJtii1dyI/AAAAAAAACuw/y3C8SErzAFU/s72-c/1409483266_b2cdf2f841.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/09/international-action-day-freedom-not.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8FRng8eyp7ImA9WxNSGE0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-6290826835852625153</id><published>2009-08-31T20:51:00.006+02:00</published><updated>2009-09-01T13:16:57.673+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-01T13:16:57.673+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="windows" /><category scheme="http://www.blogger.com/atom/ns#" term="application vulnerabilities" /><title>Possible 0-day in IIS5 and IIS6 FTP (updated x3)</title><content type="html">A &lt;a href="http://seclists.org/fulldisclosure/2009/Aug/0443.html"&gt;zero day for IIS5 &amp;amp; 6&lt;/a&gt; was posted today to the Full Disclosure mailinglist. Yes, we are talking shellcode. This seems to be real.&lt;br /&gt;&lt;br /&gt;According to Thierry Zoller, it doesn't work reliably for IIS6 but it's not impossible (source: &lt;a href="http://twitter.com/thierryzoller/statuses/3672647953"&gt;twitter&lt;/a&gt;) and confirmed by &lt;a href="http://seclists.org/fulldisclosure/2009/Aug/0449.html"&gt;this comment&lt;/a&gt; on the mailinglist. But it will crash the service on Windows2003 as such. Seems an issue in the MKDIR command.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.us-cert.gov/current/index.html#microsoft_internet_information_services_iis1"&gt;US CERT&lt;/a&gt; is advising:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-family:Arial,Geneva,Helvetica;font-size:85%;"  &gt;US-CERT encourages administrators to disable anonymous write access to the FTP server to help mitigate the vulnerability, although a proper impact analysis should be performed prior to taking defensive measures.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So the impact seems limited to servers that allow anonymous (write) access. Unless you don't trust authenticated users or fear they can be easily compromised. Stay tuned for updates.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UPDATE&lt;/span&gt;: Thanks to a &lt;a href="http://blog.rootshell.be/2009/09/01/detecting-vulnerable-iis-ftp-hosts-using-nmap/"&gt;NMAP script from Xavier&lt;/a&gt;, you can now scan you environment for vulnerable servers.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UPDATE 2&lt;/span&gt;: If you need a snort signature for the milw0rm IIS-FTP&lt;br /&gt;exploit. Emergent threats released signature tarballs and a history is available in CVS:&lt;br /&gt;&lt;a href="http://www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/EXPLOIT/EXPLOIT_IISFTP" target="_blank" style="color: rgb(42, 93, 176);"&gt;http://www.emergingthreats.&lt;wbr&gt;net/cgi-bin/cvsweb.cgi/sigs/&lt;wbr&gt;EXPLOIT/EXPLOIT_IISFTP&lt;/a&gt;&lt;br /&gt;Wiki: &lt;a href="http://doc.emergingthreats.net/bin/view/Main/2009828" target="_blank" style="color: rgb(42, 93, 176);"&gt;http://doc.emergingthreats.&lt;wbr&gt;net/bin/view/Main/2009828&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UPDATE 3&lt;/span&gt;: Developers of the Backtrack &lt;span style="text-decoration: underline;"&gt;played &lt;/span&gt;&lt;a href="http://www.offensive-security.com/blog/vulndev/microsoft-iis-ftp-5-0-remote-system-exploit/" rel="external"&gt;with the exploit&lt;/a&gt; and created an enhanced version that opens a listening port on a fully patched Windows 2000 system running IIS 5. They made a &lt;a href="http://www.offensive-security.com/videos/microsoft-ftp-server-remote-exploit/msftp.html" rel="external"&gt;video&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-6290826835852625153?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Ha7XPaegPko:3sYnhSVG-Xw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=Ha7XPaegPko:3sYnhSVG-Xw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Ha7XPaegPko:3sYnhSVG-Xw:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Ha7XPaegPko:3sYnhSVG-Xw:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Ha7XPaegPko:3sYnhSVG-Xw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Ha7XPaegPko:3sYnhSVG-Xw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=Ha7XPaegPko:3sYnhSVG-Xw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=Ha7XPaegPko:3sYnhSVG-Xw:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/Ha7XPaegPko" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/6290826835852625153/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=6290826835852625153" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6290826835852625153?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/6290826835852625153?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/Ha7XPaegPko/possible-0-day-in-iis5-and-iis6-ftp.html" title="Possible 0-day in IIS5 and IIS6 FTP (updated x3)" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/08/possible-0-day-in-iis5-and-iis6-ftp.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEEQHY7fip7ImA9WxNSFEw.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-886285887573388742</id><published>2009-08-28T00:09:00.003+02:00</published><updated>2009-08-28T02:16:41.806+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-28T02:16:41.806+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><title>HAR2009: where to get the presentation videos</title><content type="html">Well, HAR2009 was a blast. It was fun meeting a lot of other people, doing some workshops and some &lt;a href="http://www.flickr.com/photos/security4all/3845243590/"&gt;soldering&lt;/a&gt;.  I missed some of the talks I wanted to see but luckily there were recordings of the presentations. They are about 24GB and you can find them at:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://mirrors.dotsrc.org/HAR-Streamdumps/"&gt;dotsrc.org HTTP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="ftp://mirrors.dotsrc.org/HAR-Streamdumps/"&gt;dotsrc.org FTP&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://har2009.blinkenarea.org/HAR-Streamdumps/html"&gt;BlinkenArea HTTP (slow)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;These are raw, unedited videos. Some edited videos are available on &lt;a href="http://rehash.nl/"&gt;http://rehash.nl/&lt;/a&gt; by streaming. But I prefer to have my videos offline.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-886285887573388742?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JAkXrD5Ucj4:oYFpxapHHLA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=JAkXrD5Ucj4:oYFpxapHHLA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JAkXrD5Ucj4:oYFpxapHHLA:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JAkXrD5Ucj4:oYFpxapHHLA:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JAkXrD5Ucj4:oYFpxapHHLA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JAkXrD5Ucj4:oYFpxapHHLA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=JAkXrD5Ucj4:oYFpxapHHLA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JAkXrD5Ucj4:oYFpxapHHLA:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/JAkXrD5Ucj4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/886285887573388742/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=886285887573388742" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/886285887573388742?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/886285887573388742?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/JAkXrD5Ucj4/har2009-where-to-get-presentation.html" title="HAR2009: where to get the presentation videos" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.security4all.be/2009/08/har2009-where-to-get-presentation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUFQX4_eCp7ImA9WxJaFE8.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-7214561701713896467</id><published>2009-08-05T00:02:00.003+02:00</published><updated>2009-08-05T00:50:10.040+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-05T00:50:10.040+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><title>Collection of Defcon 17 articles, videos, pictures and podcasts</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_hKfJbfbBxMU/Sni2hadh4AI/AAAAAAAACuo/1cL4XLlH-38/s1600-h/3788070684_c51b36772e.jpg"&gt;&lt;img style="cursor: pointer; width: 320px; height: 213px;" src="http://1.bp.blogspot.com/_hKfJbfbBxMU/Sni2hadh4AI/AAAAAAAACuo/1cL4XLlH-38/s320/3788070684_c51b36772e.jpg" alt="" id="BLOGGER_PHOTO_ID_5366239641167060994" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is a list of articles and other fun stuff that people were tweeting about in the last week. This list is of course not exhaustive but a nice place to start reviewing the things that happened at the conference.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Articles:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.uncommonsensesecurity.com/2009/08/announcing-warzone-project.html"&gt;Announcing the Warzone Project&lt;/a&gt; (uncommonsensesecurity.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://it.toolbox.com/blogs/securitymonkey/defcon-updates-33217?rss=1"&gt;DefCon Updates&lt;/a&gt; (A Day in the Life of an Information Security Investigator )&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.darkreading.com/insiderthreat/security/app-security/showArticle.jhtml?articleID=218900315&amp;amp;cid=RSSfeed"&gt;Defcon: New Hack Hijacks Application Updates Via WiFi&lt;/a&gt; (Darkreading)&lt;/li&gt;&lt;li&gt;&lt;a href="http://news.cnet.com/8301-27080_3-10301329-245.html?part=rss&amp;amp;tag=feed&amp;amp;subj=News-Security"&gt;Researchers offer tools for eavesdropping and video hijacking&lt;/a&gt; (CNet.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/9136182/Korean_journalists_booted_from_Defcon"&gt;Korean 'journalists' booted from Defcon&lt;/a&gt; (computerworld.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/9136179/Fake_ATM_doesn_t_last_long_at_hacker_meet"&gt;Fake ATM doesn't last long at hacker meet&lt;/a&gt; (Computerworld)&lt;/li&gt;&lt;li&gt;&lt;span class="blogInfo"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.wired.com/threatlevel/2009/08/electronic-locks-defeated/"&gt;Electronic High-Security Locks Easily Defeated at DefCon&lt;/a&gt; (Wired.com)&lt;span class="blogInfo"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blogs.zdnet.com/security/?p=3843"&gt;Fake ATM, skimmers found in Las Vegas hotels&lt;/a&gt; (Zero Day)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.engadget.com/2009/08/03/atm-scam-at-defcon-clearly-the-work-of-ironic-criminals/"&gt;ATM scam at DEFCON clearly the work of ironic criminals &lt;/a&gt;(engadget.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.fastcompany.com/blog/kit-eaton/technomix/defcon-computer-security-conference-scary-all-sorts-reasons"&gt;The Best (and Worst) Hacks of Defcon Computer Security Conference 2009 &lt;/a&gt;(fastcompany.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://blogs.zdnet.com/security/?p=3851"&gt;Hacker demos persistent Mac keyboard attack&lt;/a&gt; (Zero day)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.forbes.com/2009/08/03/security-defcon-hackers-technology-security-defcon.html"&gt;Hack-Proofing The Hackers&lt;/a&gt; (forbes.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://infosecevents.net/2009/08/03/defcon-17-badge-hackers/"&gt;DEFCON 17 Badge Hackers&lt;/a&gt; (infosecevents.net)&lt;/li&gt;&lt;li&gt;&lt;a href="http://deals.venturebeat.com/2009/08/01/defcon-hacker-excuse-me-while-i-change-your-aircrafts-flight-plan/"&gt;Defcon air traffic control hacker: Excuse me while I change your aircraft’s flight plan &lt;/a&gt;(deals.venturebeat.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://sirdarckcat.blogspot.com/2009/08/our-favorite-xss-filters-and-how-to.html"&gt;Our Favorite XSS Filters and how to Attack them&lt;/a&gt; (sirdarckcat.blogspot.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.wired.com/threatlevel/2009/08/fed-rfid/"&gt;Feds at DefCon Alarmed After RFIDs Scanned&lt;/a&gt; (wired.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/print/9136223/Opinion_Irresponsibility_runs_amok_at_Black_Hat_Defcon?taxonomyName=Security&amp;amp;taxonomyId=17"&gt;Opinion: Irresponsibility runs amok at Black Hat, Defcon&lt;/a&gt; (computerworld.com)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.h-i-r.net/2009/08/ax0ns-defcon-17-wrap-up.html"&gt;Ax0n's DefCon 17 Wrap-Up&lt;/a&gt; (www.h-i-r.net)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cupfighter.net/index.php/2009/08/defcon-0-day-adobe-jbig2decode-disclosure-debalce-steven-adair/"&gt;Defcon talk: 0-day, gh0stnet and the Adobe JBIG2Decode disclosure debalce – Steven Adair&lt;/a&gt; (cupfighter.net)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.offensivecomputing.net/?q=node/1316"&gt;Blackhat USA 2009: Reverse Engineering by Crayon&lt;/a&gt; (offensivecomputing.net)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.informationweek.com/news/internet/security/showArticle.jhtml?articleID=218900314"&gt;Black Hat: Social Networks Reveal, Betray, Help Users&lt;/a&gt; (informationweek.com)&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Video:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://stub.bz/sslrebinding/"&gt;SSL rebinding video&lt;/a&gt; (stub.bz)&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.youtube.com/watch?v=Dq9_JMtQDN8"&gt;#defcon podcast meetup&lt;/a&gt; (youtube)&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.youtube.com/watch?v=QlDeTADLJp4"&gt;Hacking The Defcon 2009 Badge&lt;/a&gt; (youtube)&lt;/li&gt;&lt;li&gt;&lt;a href="http://vimeo.com/channels/carnal0wnage"&gt;Metasploit Oracle videos&lt;/a&gt; (vimeo.com)&lt;/li&gt;&lt;li&gt;&lt;a href="http://venturebeat.com/2009/07/31/video-interview-with-iphone-hacker-charlie-miller/"&gt;Hacker Charlie Miller on how he compromised the iPhone&lt;/a&gt; (venturebeat.com)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Podcast:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.mckeay.net/2009/08/01/defcon-microcast-1-johnny-long-hackers-for-charity/"&gt;Defcon Microcast 1 – Johnny Long, Hackers for Charity&lt;/a&gt; (Network security)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mckeay.net/2009/08/01/defcon-microcast-2-dark-tangent/"&gt;Defcon Microcast 2 – Dark Tangent&lt;/a&gt; (Network security)&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mckeay.net/2009/08/02/defcon-microcast-3-saturday-wrapup/"&gt;Defcon Microcast 3 – Saturday Wrapup &lt;/a&gt;(Network security)&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Pictures:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.defconpics.org/"&gt;http://www.defconpics.org/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/08/get-defcon-17-cd-archive.html"&gt;Get the #DEFCON 17 CD Archive (updated x2)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/day-2-collection-of-blackhat-articles.html"&gt;Day 2: A collection of #Blackhat articles: keeping remote track of the event&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/blackhat-slides-available-and-first.html"&gt;BlackHat slides available and first blogposts&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/how-to-follow-blackhatdefcon-without.html"&gt;How to follow Blackhat/Defcon without being there&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/preparing-your-laptop-or-iphone-for.html"&gt;Preparing your laptop (or iPhone) for a security/hacker conference&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;(Photo under creative commons from &lt;a href="http://www.flickr.com/photos/ggee/" class="currentContextLink" id="contextLink_stream32565510@N00"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;ggee's photostream&lt;/a&gt;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-7214561701713896467?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JxxzdVYYffY:QAukL79Rvyc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=JxxzdVYYffY:QAukL79Rvyc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JxxzdVYYffY:QAukL79Rvyc:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JxxzdVYYffY:QAukL79Rvyc:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JxxzdVYYffY:QAukL79Rvyc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JxxzdVYYffY:QAukL79Rvyc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=JxxzdVYYffY:QAukL79Rvyc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=JxxzdVYYffY:QAukL79Rvyc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/JxxzdVYYffY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/7214561701713896467/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=7214561701713896467" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7214561701713896467?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/7214561701713896467?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/JxxzdVYYffY/collection-of-defcon-17-articles-videos.html" title="Collection of Defcon 17 articles, videos, pictures and podcasts" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_hKfJbfbBxMU/Sni2hadh4AI/AAAAAAAACuo/1cL4XLlH-38/s72-c/3788070684_c51b36772e.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://blog.security4all.be/2009/08/collection-of-defcon-17-articles-videos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEYHSHw5eSp7ImA9WxJaEk0.&quot;"><id>tag:blogger.com,1999:blog-6437907677349484188.post-8592931798448572612</id><published>2009-08-01T14:16:00.004+02:00</published><updated>2009-08-02T10:35:39.221+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-02T10:35:39.221+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="conference" /><title>Get the #DEFCON 17 CD Archive (updated x2)</title><content type="html">The Defcon 17 CD Archive is up. Get it at &lt;a href="https://media.defcon.org/dc-17/DEFCON-17-CD.rar"&gt;https://media.defcon.org/dc-17/DEFCON-17-CD.rar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update: &lt;/span&gt;The following file triggered some Antivirus engines&lt;br /&gt;&lt;br /&gt;"Extras/bin/crackmes/manifest.exe". (in Sean Taylor's Extras.zip) - Detects as TR/Crypt.ZPACK.Gen&lt;br /&gt;&lt;br /&gt;But&lt;a href="http://twitter.com/_defcon_/status/3079543747"&gt; it was confirmed by the Defcon team&lt;/a&gt; that it contained no trojan. Better be safe then sorry.&lt;br /&gt;&lt;br /&gt;Related posts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/day-2-collection-of-blackhat-articles.html"&gt;Day 2: A collection of #Blackhat articles: keeping remote track of the event&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/blackhat-slides-available-and-first.html"&gt;BlackHat USA2009 slides available and first blogposts&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/how-to-follow-blackhatdefcon-without.html"&gt;How to follow Blackhat/Defcon without being there&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://blog.security4all.be/2009/07/preparing-your-laptop-or-iphone-for.html"&gt;Preparing your laptop (or iPhone) for a security/hacker conference&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6437907677349484188-8592931798448572612?l=blog.security4all.be' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=8DYX6TkGZkI:0hAGQL-ABeo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=8DYX6TkGZkI:0hAGQL-ABeo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=8DYX6TkGZkI:0hAGQL-ABeo:I9og5sOYxJI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=I9og5sOYxJI" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=8DYX6TkGZkI:0hAGQL-ABeo:Jwdi1b3fU3Q"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=Jwdi1b3fU3Q" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=8DYX6TkGZkI:0hAGQL-ABeo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=8DYX6TkGZkI:0hAGQL-ABeo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?i=8DYX6TkGZkI:0hAGQL-ABeo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/Security4all?a=8DYX6TkGZkI:0hAGQL-ABeo:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/Security4all?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Security4all/~4/8DYX6TkGZkI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://blog.security4all.be/feeds/8592931798448572612/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=6437907677349484188&amp;postID=8592931798448572612" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/8592931798448572612?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6437907677349484188/posts/default/8592931798448572612?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Security4all/~3/8DYX6TkGZkI/get-defcon-17-cd-archive.html" title="Get the #DEFCON 17 CD Archive (updated x2)" /><author><name>Security4all</name><uri>http://www.blogger.com/profile/09433979568731690987</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="08763543169152489406" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://blog.security4all.be/2009/08/get-defcon-17-cd-archive.html</feedburner:origLink></entry></feed>
