<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5750556</id><updated>2011-04-22T09:15:24.558+05:30</updated><title type='text'>Thoughts From The Fringe Of The Web</title><subtitle type='html'>your main() source for information security news, abuse and other general ramblings</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://tftfotw.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>33</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5750556.post-109445553849431311</id><published>2004-09-06T11:54:00.000+05:30</published><updated>2004-09-06T12:55:38.493+05:30</updated><title type='text'>Complete rewrite of nmap (version 3.70)</title><content type='html'>Rush to your friendly neightbourhood &lt;a href="http://www.insecure.org"&gt; insecure.org&lt;/a&gt; and pick up a copy of the new nmap 3.70. As fyodor himself puts it:&lt;br /&gt;"This release includes dozens of major changes, and all users are advised to update.  "&lt;br /&gt;&lt;br /&gt;nmap is now much faster and supports parallel scanning of hosts ! This allows you to distribute a scan better, and is lighter on the target systems as well. There is also a fix for using it on systems with Windows SP2 (which &lt;a href="http://www.interact-sw.co.uk/iangblog/2004/08/12/norawsockets"&gt;broke raw sockets&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;From whatever testing I've done with the new version, it seems really good. The increase in speed is really awesome. This has all happened because the main port scanning engine has been rewritten from scratch.&lt;br /&gt;&lt;br /&gt;Go ahead and &lt;a href="http://www.insecure.org/nmap/nmap_download.html"&gt;download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-109445553849431311?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/109445553849431311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/109445553849431311'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_09_01_archive.html#109445553849431311' title='Complete rewrite of nmap (version 3.70)'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-109165232482617964</id><published>2004-08-05T02:09:00.000+05:30</published><updated>2004-08-05T02:15:24.826+05:30</updated><title type='text'>The New Job.....</title><content type='html'>Well, about that work related scenario.. I'm now working for &lt;a href="http://www.mielesecurity.com"&gt;MIEL e-Security Pvt Ltd.&lt;/a&gt; I'm working as a penetration-tester (what they call 'Attack &amp; Penetration').&lt;br /&gt;&lt;br /&gt;The blog updates have slowed down temporarily as I've been over-burdened with a whole lot of stuff. However here's the good news. The portknocking code will be up very shortly, as will another tool I've written to discover systems with common hostnames.. very useful when you don't get an AXFR from a DNS server. Pops up some interesting results ;)&lt;br /&gt;&lt;br /&gt;I'm back in action at &lt;a href="http://www.firewall.cx"&gt;firewall.cx&lt;/a&gt; again, so get in touch with me there.&lt;br /&gt;&lt;br /&gt;If any of the guys from the training in Mauritius are reading this, drop me a private message there and we can discuss some of the training topics etc.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-109165232482617964?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/109165232482617964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/109165232482617964'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_08_01_archive.html#109165232482617964' title='The New Job.....'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-108482187999842208</id><published>2004-05-18T00:38:00.000+05:30</published><updated>2004-05-18T00:54:39.996+05:30</updated><title type='text'>Back From The Dead</title><content type='html'>Yes I know its been awhile.. I've been busy appearing on the front page of newspapers (ok so only one newspaper.. the &lt;a href="http://www.mid-day.com"&gt;Mid-Day&lt;/a&gt;). The article covered the work I'm doing at the Mumbai Police &lt;a href="http://www.mumbaicyberlab.org"&gt;Cyber Lab&lt;/a&gt; (the website is incomplete) and was rather spiced up IMHO. Anyway, scans of that will come up later once I figure out how to make myself look like less of a hardened criminal in the photograph.&lt;br /&gt;&lt;br /&gt;So the &lt;a href="http://www.eweek.com/article2/0,1759,1593870,00.asp"&gt;Cisco IOS 12.3 source&lt;/a&gt; has been stolen. Coming after Microsoft's &lt;a href="http://www.microsoft.com/presspass/press/2004/Feb04/02-12windowssource.asp"&gt;great Win2k source expose&lt;/a&gt;, this is giving the term 'open source' a new meaning ;). Still you've gotta feel for Cisco, they make the best damn hardware bar none (the fact that I'm a proud card carrying member of the CCNA family does not make me biased !).&lt;br /&gt;&lt;br /&gt;Watched an incredible biography on &lt;a href="http://w3.rz-berlin.mpg.de/cmp/beethoven.html"&gt;Beethoven&lt;/a&gt; on the History Channel this evening. If you're a musician you'll really understand how he must have driven himself crazy after going deaf. Anyway, in deference to genius I've traded in the progressive rock for the Moonlight Sonata and Tchaikovsky's violin concertos (Kyung-Wha Chung on violin).&lt;br /&gt;&lt;br /&gt;My &lt;a href="http://www.portknocking.org"&gt;port knocking&lt;/a&gt; implementation is almost complete. You'll be able to grab it here the second I finish commenting the code for you hackers. Then you admins / crackers can enjoy the goodness of backdoor shell access that is undetectable to portscans !&lt;br /&gt;&lt;br /&gt;More on an interesting work related scenario soon..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-108482187999842208?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/108482187999842208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/108482187999842208'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_05_01_archive.html#108482187999842208' title='Back From The Dead'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107798587233814642</id><published>2004-02-28T22:01:00.000+05:30</published><updated>2004-02-28T22:12:20.090+05:30</updated><title type='text'>Firewall.cx ties up with Searchnetworking.com, a new Nmap, Winamp plugins and prog rock !</title><content type='html'>Good news everyone, &lt;a href="http://www.firewall.cx"&gt;firewall.cx&lt;/a&gt; has tied up with &lt;a href="http://www.searchnetworking.com"&gt;Searchnetworking&lt;/a&gt;. Searchnetworking is one of the heavyweight networking sites in the techtarget group. It gets a tremendous amount of traffic everyday and under the new deal, Searchnetworking gets to use firewall.cx's exclusive articles and other content. This way searchnetworking benefits from getting really quality original articles and we get a load more traffic. I suggest you check out searchnetworking and sign-up there, there is a whole lot of really top-notch information on that site.. and now if you browse through their administrator academy you'll see a few of our firewall.cx articles up their already.&lt;br /&gt;&lt;br /&gt;In other news, &lt;a href="http://www.insecure.org/nmap"&gt;Nmap 3.50&lt;/a&gt; has been officially released. The improvements include a remote OS identification database that has doubled since its last incarnation as well as cosmetic changes to how the output is displayed. It is also supposedly faster. So go grab the Rolls-Royce of portscanners !&lt;br /&gt;&lt;br /&gt;I've also added a neat little thing called &lt;a href="http://www.geocities.com/insanitydrops/blogamp/en/"&gt;Blogamp&lt;/a&gt; to the bottom left of the page (in the sidebar below the virus information). This niftly little thing shows you the last five songs I've been playing in Winamp (and yes I own the CDs). Thanks Chris for letting me host it at firewall.cx :)&lt;br /&gt;&lt;br /&gt;As you can see I've just discovered the incredible progressive-rock band called &lt;a href="http://www.shadowgallery.com"&gt;Shadow Gallery&lt;/a&gt;. If you like prog rock, you owe it to yourself to check this band out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107798587233814642?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107798587233814642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107798587233814642'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_02_01_archive.html#107798587233814642' title='Firewall.cx ties up with Searchnetworking.com, a new Nmap, Winamp plugins and prog rock !'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107679118558616994</id><published>2004-02-15T02:09:00.000+05:30</published><updated>2004-02-15T02:16:35.873+05:30</updated><title type='text'>Vulnerability Database Added</title><content type='html'>I've just added the search code to the &lt;a href="http://icat.nist.gov/icat.cfm"&gt;ICAT CVE Vulnerability Database&lt;/a&gt;. This useful tool lets you search for vulnerabilities in any software by keyword or vendor. Its completely up-to-date and provides further information on any vulnerabilities it finds.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107679118558616994?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107679118558616994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107679118558616994'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_02_01_archive.html#107679118558616994' title='Vulnerability Database Added'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107523563547675705</id><published>2004-01-28T02:03:00.000+05:30</published><updated>2004-01-28T02:05:28.513+05:30</updated><title type='text'>Atom enabled news feeds !</title><content type='html'>In addition to the &lt;a href="http://thelocust.org/projects/instantrss/instantrss.php?url=http%3A%2F%2Ftftfotw.blogspot.com"&gt;RSS news feed&lt;/a&gt; we already have from &lt;a href="http://thelocust.org/projects/instantrss"&gt;InstantRSS&lt;/a&gt;, I've now added Bloggers own Atom news feeds. Not all newsreaders currently aggregate Atom content, but you have both options. &lt;a href="http://www.atomenabled.org/everyone/atomenabled/index.php?c=5"&gt;Here&lt;/a&gt; is a list of newsreaders that will handle the Atom feeds.&lt;br /&gt;&lt;br /&gt;Here is the feed (or you can access it from the sidebar)&lt;br /&gt;&lt;a href="http://tftfotw.blogspot.com/atom.xml"&gt;Atom Site Feed&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107523563547675705?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107523563547675705'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107523563547675705'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_01_01_archive.html#107523563547675705' title='Atom enabled news feeds !'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107523450441814974</id><published>2004-01-28T01:45:00.000+05:30</published><updated>2004-01-28T01:48:34.623+05:30</updated><title type='text'>Antivirus engines triggering on IE URL spoofing vulnerability while we wait for Microsoft to issue a patch</title><content type='html'>I received word from Cheetah, a &lt;a href="http://www.firewall.cx"&gt;firewall.cx&lt;/a&gt; member that the &lt;a href="http://tftfotw.blogspot.com/2003_12_01_tftfotw_archive.html#107126717526620477"&gt;IE URL spoofing vulnerability&lt;/a&gt; demonstrated on this blog (a few posts below this) is now being recognised by some anti virus scanners as a 'URL spoofing exploit'. This is a good thing, since we're still waiting for &lt;a href="www.microsoft.com/security"&gt;Microsoft&lt;/a&gt; to issue a patch for the exploit. I have moved the actual demonstration link to a separate page so that anti virus products don't run around telling you that TFTFOTW is trying to do something evil. Rest assured that there is no malicious content on this site. It just goes to show that trust is a hard asset to win, and an even harder one to hold on to these days.&lt;br /&gt;&lt;br /&gt;Once again, thanks to Cheetah for bringing this to my attention.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107523450441814974?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107523450441814974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107523450441814974'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_01_01_archive.html#107523450441814974' title='Antivirus engines triggering on IE URL spoofing vulnerability while we wait for Microsoft to issue a patch'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107329980828475092</id><published>2004-01-05T16:20:00.000+05:30</published><updated>2004-01-05T16:21:19.546+05:30</updated><title type='text'>Security predictions for 2004</title><content type='html'>Well after you've read the post below this for IT predictions, you can have a look at some security predictions for 2004. I had also predicted the growth of personal firewalls in the enterprise, lets see how that comes about by the end of this year.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computerworld.com.au/index.php?id=2057465071&amp;fp=16&amp;fpid=0"&gt;Security Predictions for 2004&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The last paragraph really stands out. It makes three very pointed observations about how the IT industry and users have been dealing with security for the longest time, and why that has to change.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107329980828475092?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107329980828475092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107329980828475092'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_01_01_archive.html#107329980828475092' title='Security predictions for 2004'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107315538473526550</id><published>2004-01-04T00:13:00.000+05:30</published><updated>2004-01-06T15:22:38.326+05:30</updated><title type='text'>IT predictions for 2004, and Wi-Fi Security</title><content type='html'>I pulled these two gems off &lt;a href="http://www.slashdot.org"&gt;Slashdot&lt;/a&gt;.&lt;br /&gt;The first are IT predictions for 2004, including the future of Microsoft and Linux, not to mention Sun, SCO, and Apple. Very worthwhile reading considering the guy who wrote this last year got 11 out of 15 predictions spot on. I'm not in total agreement with all his predictions, but what the heck, we'll know next year round won't we.&lt;br /&gt;&lt;a href="http://www.pbs.org/cringely/pulpit/pulpit20040101.html"&gt;It Predictions for 2004&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The second is a little Risk Assessment analysis of Wi-Fi networks. Don't expect too much technical detail, but some very good general risk identification ideas.&lt;br /&gt;&lt;a href="http://www.bankinfosecurity.com/?q=node/view/334"&gt;Risk Management of Wireless Networks&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Happy new year all.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107315538473526550?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107315538473526550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107315538473526550'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2004_01_01_archive.html#107315538473526550' title='IT predictions for 2004, and Wi-Fi Security'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107213275888983759</id><published>2003-12-23T04:09:00.000+05:30</published><updated>2003-12-23T04:10:38.216+05:30</updated><title type='text'>Introduction to security article</title><content type='html'>The Introduction to Security article that I've been working on for everyones favourite networking site, &lt;a href="http://www.firewall.cx"&gt;firewall.cx&lt;/a&gt;, has been published. &lt;br /&gt;Go have a look at it here :&lt;br /&gt;&lt;a href="http://www.firewall.cx/articles-network-security.php"&gt;An Introduction To Network Security&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can leave your comments here.. using the new comments system, or preferably in the &lt;a href="http://www.firewall.cx/modules.php?name=Forums"&gt;firewall.cx forums&lt;/a&gt;, where you'll usually find me skulking.&lt;br /&gt;&lt;br /&gt;Many thanks to Chris and Tfs for putting up with my incessantly mailing it to them for proofreading.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107213275888983759?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107213275888983759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107213275888983759'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107213275888983759' title='Introduction to security article'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107157255403666477</id><published>2003-12-16T16:32:00.000+05:30</published><updated>2003-12-16T16:35:44.996+05:30</updated><title type='text'>Acer Ferrari Laptop</title><content type='html'>You have to have a look at the Acer Ferrari 3000 Notebook. Its a top performance laptop officially licensed from &lt;a href="http://www.ferrari.it"&gt;Ferrari&lt;/a&gt;. While I'm more of a &lt;a href="http://www3.porsche.com"&gt;Porsche&lt;/a&gt; person myself, this notebood just looks so sexy.. wait till you check out its specs,&lt;br /&gt;Athlon XP 2500 , 60GB HDD, 512MB DDR SDRAM, DVD writer, ATI Radeon Mobility 9200 powering the 15 inch screen ! Start drooling&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.theregister.co.uk/media/1197.jpg" alt=F3000 border=0 align=center&gt;&lt;/img&gt;&lt;br /&gt;&lt;a href="http://global.acer.com/products/notebook/fr3000.htm"&gt;Acer Ferrari 3000 Notebook&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107157255403666477?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107157255403666477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107157255403666477'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107157255403666477' title='Acer Ferrari Laptop'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107148792805690434</id><published>2003-12-15T17:02:00.000+05:30</published><updated>2003-12-15T17:05:55.030+05:30</updated><title type='text'>Mozilla Firebird 0.7 beats IE</title><content type='html'>I've just been testing out &lt;a href="http://www.mozilla.org/products/firebird/"&gt;Mozilla Firebird&lt;/a&gt; after hearing all the wonderful things people say about it. This is the final word -- it really whips IE's ass ! The browser is quick to load, fully customisable and extendable via &lt;a href="http://texturizer.net/firebird/extensions/"&gt;extensions&lt;/a&gt; that can do anything from adding Opera's mouse gestures to having an RSS reader in the sidebar !&lt;br /&gt;&lt;br /&gt;The browser supports multiple windows as well as a tabbed interface and has some really neat keyboard shortcuts. The look is very clean and minimalistic (no unnecessary toolbars and buttons) however this does not mean it's dumbed down, its just very good UI design. The whole thing is skinnable as well ! Then you add all the usual jazz like built in google search and nifty full screen modes and you're ready to go ! &lt;br /&gt;&lt;br /&gt;Rendering wise, this baby is &lt;strong&gt;fast&lt;/strong&gt;! I would say its equivalent in speed to Opera, but it renders pages much better than Opera. The HTML and CSS support are as per international standards (unlike Microsoft which chooses to ignore tags as it pleases). In fact I find this blog looking much more like I intended it to look under Firebird than under IE ! That said, its now my default browser :).&lt;br /&gt;&lt;br /&gt;Oh yeah, did I mention it loads really quickly ? Hehe..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107148792805690434?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107148792805690434'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107148792805690434'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107148792805690434' title='Mozilla Firebird 0.7 beats IE'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107126717526620477</id><published>2003-12-13T03:42:00.000+05:30</published><updated>2004-01-28T01:39:03.576+05:30</updated><title type='text'>IE URL hiding vulnerability</title><content type='html'>I caught this on the security lists. There is a new vulnerability in Internet Explorer that allows an attacker to make any page appear to come from a URL of his choosing. The address bar will display whatever URL he wants, and even if you hover over the link, you won't see the location you're actually being sent to. This has a lot of relevance given how scammers may use it to mislead people into believing they're at &lt;a href="http://www.ebay.com"&gt;e-bay&lt;/a&gt; or &lt;a href="http://www.paypal.com"&gt;paypal&lt;/a&gt;. The actual exploit involves inserting a null character before the @ sign commonly used to denote a login and password combination when accessing a website or ftp server.&lt;br /&gt;&lt;br /&gt;To see a demonstration of the vulnerability, click the link below.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/urlspoof.html"&gt;Demonstration of the IE URL spoofing vulnerability&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Notice that even when you just hover over the link, it appears to be linked to www.google.com, the only way one might notice this attack is by viewing the source (or happening to notice that you're not making a TCP/IP connection to www.google.com). Both of which are fairly unlikely to happen. As of now there is no word on a patch.. so much for a patchless December from Microsoft !&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107126717526620477?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107126717526620477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107126717526620477'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107126717526620477' title='IE URL hiding vulnerability'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107109036492910179</id><published>2003-12-11T02:36:00.000+05:30</published><updated>2003-12-14T21:08:32.466+05:30</updated><title type='text'>Site update</title><content type='html'>Well I've also added the nifty little security news, security alerts scrollers courtesy &lt;a href="http://www.securityunit.com"&gt;SecurityUnit&lt;/a&gt; to the sidebar, as well as virus alerts courtesy &lt;a href="www.virusportal.com"&gt;VirusPortal&lt;/a&gt;. Also don't forget about the new &lt;a href="http://thelocust.org/projects/instantrss/instantrss.php?url=http%3A%2F%2Ftftfotw.blogspot.com"&gt;&lt;img src="http://www.wcc.vccs.edu/services/rssify/xml.gif" border=0 alt="This gif is freely copyable. Just right click, save"&gt; Feeds &lt;/a&gt;! I'm planning to work on them over the next week so that they have proper headlines. However this will have to do for now !&lt;br /&gt;&lt;br /&gt;I've also added titles to each blog entry, and a link in the byline so you can link directly to a particular post. Now hows that for a days work eh ?&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107109036492910179?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107109036492910179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107109036492910179'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107109036492910179' title='Site update'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107105635007689221</id><published>2003-12-10T17:09:00.000+05:30</published><updated>2003-12-14T21:06:49.233+05:30</updated><title type='text'>XML Feed Added</title><content type='html'>I've just added RSS newsfeeds of the site, you can access these using the little orange XML icon at the top of the page. Shove this link into your favourite RSS aggregator. I recommend &lt;a href="http://www.disobey.com/amphetadesk"&gt;Amphetadesk&lt;/a&gt; or &lt;a href="http://www.feedreader.com"&gt;FeedReader&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I'm very grateful to Ben from &lt;a href="http://thelocust.org/projects/instantrss"&gt;thelocust.org&lt;/a&gt; for providing instantRSS for free. Thats how we're giving you the XML feeds. I recommend you visit his website&lt;br /&gt;&lt;br /&gt;Go grab that newsfeed !!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107105635007689221?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107105635007689221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107105635007689221'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107105635007689221' title='XML Feed Added'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-107078565405644600</id><published>2003-12-07T13:57:00.000+05:30</published><updated>2003-12-11T17:31:43.920+05:30</updated><title type='text'>System monitors and desktop art...</title><content type='html'>I just found a windows port of GkrellM, the incredible little stack of system monitors. &lt;br /&gt;&lt;br /&gt;For those who haven't used this beauty before, it is a fully skinnable and customisable stack of monitors which can be extended with lots of plugins.. the plugins do everything from scrolling your choice of news headlines, checking mail, controlling winamp etc etc.&lt;br /&gt;&lt;br /&gt;This is a must have !! Go get it&lt;br /&gt;&lt;a href=http://www.gkrellm.net&gt;GkrellM Linux/BSD/Solaris/MacOS&lt;/a&gt;&lt;br /&gt;&lt;a href=http://bill.nalens.com/&gt; GkrellM Windows port&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here are some screenshots of my desktop, click for full size images. GkrellM is the little stack of monitors on the right. As you can see I'm using it to monitor CPU/Disks/Memory, check my mail, control winamp and scroll security headlines and Google news. Oh yeah don't miss Flynn from Doom who shows you how messed your system in true Doom style !!&lt;br /&gt;&lt;br /&gt;&lt;a href=http://www.firewall.cx/sahirh/desktop2.jpg&gt;&lt;img src="http://www.firewall.cx/sahirh/desktop2.jpg" border=none ALT="Screenshot" WIDTH=400 HEIGHT=300&gt;&lt;/a&gt;  &lt;a href=http://www.firewall.cx/sahirh/desktop.jpg&gt;&lt;img src="http://www.firewall.cx/sahirh/desktop.jpg" ALT="Screenshot" WIDTH=400 HEIGHT=300 border=none&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Yes I know my desktop looks too cool to be Windows XP, but that will be dealt with in another post ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-107078565405644600?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107078565405644600'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/107078565405644600'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_12_01_archive.html#107078565405644600' title='System monitors and desktop art...'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106922589572616295</id><published>2003-11-19T12:41:00.000+05:30</published><updated>2003-12-11T03:12:02.576+05:30</updated><title type='text'>portscanners 'r us</title><content type='html'>This post will be appreciated by those of you who use Windows.&lt;br /&gt;&lt;br /&gt;I've been on the lookout for a good portscanner for those times when I'm using Windows (&lt;a href="http://www.insecure.org/nmap"&gt;Nmap&lt;/a&gt; doesn't work well off my PPP connection from home using WinPcap). I'd often heard of &lt;a href="http://www.foundstone.com"&gt;Foundstone's &lt;/a&gt;SuperScan being a very worthy windows scanner and so I checked it out. I must say I'm very impressed and wouldn't recommend any other scanner for the Windows OS. It has all the usual jazz you expect and some more. Some of the features :&lt;br /&gt;&lt;br /&gt;Host discovery using multiple methods&lt;br /&gt;Windows NetBIOS enumeration&lt;br /&gt;UDP scanning&lt;br /&gt;SYN stealth (half-connect) scanning&lt;br /&gt;Banner grabbing&lt;br /&gt;Built in tools such as zone transfer, whois, traceroute, bulk resolve, http requests&lt;br /&gt;HTML report generation&lt;br /&gt;&lt;br /&gt;I've been going through a whole lot of foundstones &lt;a href="http://www.foundstone.com/resources/freetools.htm"&gt;free tools&lt;/a&gt; and they really do have some interesting stuff, I suggest you check it out. Here's a direct link for &lt;a href="http://www.foundstone.com/resources/proddesc/superscan4.htm"&gt;SuperScan&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I'll also be adding a whole lot of Ebooks on a range of topics like security, programming and system administration. For all those of you who wanted to learn a programming language or linux or SQL, these will help you out. Its always good to have a book that covers material from the basics up.&lt;br /&gt;&lt;br /&gt;Oh yeah you can now get &lt;a href="http://seattlepi.nwsource.com/business/146115_blogger30.html"&gt;fired&lt;/a&gt; for blogging at work ! Isn't this a funny one !&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106922589572616295?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106922589572616295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106922589572616295'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_11_01_archive.html#106922589572616295' title='portscanners &apos;r us'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106858768152973353</id><published>2003-11-12T03:24:00.000+05:30</published><updated>2003-12-11T03:17:31.450+05:30</updated><title type='text'>Bad perl coding 101</title><content type='html'>For some reason a lot of people ask me how to find what webserver is running on a machine. To help you work this out and show you some pathetic coding along the way, I dug out an old perl script I'd written when I first started learning perl. Hey the code is far from beautiful.. but it works. If its some use to you, download it -&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/head.pl"&gt;Webserver identifier script&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Though I don't understand why you just dont nc www.fu.fu 80 ? Anyway some people like doing things the complicated way.&lt;br /&gt;&lt;br /&gt;If you use windows, you can get perl from &lt;a href="http://www.activestate.com"&gt;Activestate.com&lt;/a&gt;. Its free, and will run any perl script you find on the net.&lt;br /&gt;&lt;br /&gt;Blah lame post ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106858768152973353?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106858768152973353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106858768152973353'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_11_01_archive.html#106858768152973353' title='Bad perl coding 101'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106794785464690420</id><published>2003-11-04T17:40:00.000+05:30</published><updated>2003-12-11T03:17:57.496+05:30</updated><title type='text'>New documents for old !!</title><content type='html'>I'm in a generous mood so I'm handing out a couple of treats. So for taking the time to visit Thoughts From The Fringe Of The Web you're gonna get yourself a tutorial on database hacking (SQL injection). Its not the worlds newest topic, but 9/10 sites that I've visited with SQL backends and login pages are vulnerable. Best of all you can test this stuff using just your browser. Remember you're supposed to use this information to check &lt;strong&gt;your own &lt;/strong&gt; intranet / website security ;)&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/SQL_injection.html"&gt;SQL Injection&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And as a little bonus, heres a default password list, no this is not a list of common passwords like a dictionary wordlist, this is a list of vendors and products, with their associated default logins and passwords. Most of the time nobody bothers changing the default password. Someone should do a survey on how many Cisco routers are sitting pretty on the net with the default password 'cisco'. Anway grep the list for all the products you own and make sure you've changed your default passwords.&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/default_passwords.htm"&gt;Default Password List&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Credit to Eric Knight for maintaining the default password list.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106794785464690420?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106794785464690420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106794785464690420'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_11_01_archive.html#106794785464690420' title='New documents for old !!'/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106763389395115108</id><published>2003-11-01T02:28:00.000+05:30</published><updated>2003-11-01T02:29:27.240+05:30</updated><title type='text'></title><content type='html'>Found a pretty decent site today. A nice selection of texts and tutorials, a few that I have in the library, but quite a few that I haven't seen before. Also has some good original material. Give it a look&lt;br /&gt;&lt;a href="http://angelx.cjb.net/"&gt;http://angelx.cjb.net&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Firewall.cx has added some really neat flash games (check out Max Arcade from the side menu) :) kudos to Chris and the gang for constantly keeping the site among the top, its a real pleasure to be part of the team.&lt;br /&gt;Also check out two of my posts at firewall.cx in the Security / Firewalls forum... one is a pretty basic introduction to security and the other details my pen-testing methodology (yes my kung-fu is better than yours !)&lt;br /&gt;&lt;br /&gt;I'm doing my CCNA recertification on the 5th of the month.. will let people know whether they made it harder.. lets hope not !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106763389395115108?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106763389395115108'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106763389395115108'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_11_01_archive.html#106763389395115108' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106726121892985454</id><published>2003-10-27T18:56:00.000+05:30</published><updated>2003-10-27T19:05:34.223+05:30</updated><title type='text'></title><content type='html'>MS03-43 is the vulnerability in Windows' Messaging Service. This service is not to be confused with windows messenger which is totally different. However, this service is enabled by default in all versions of windows since Windows 98. If you're foolish enough to have not turned this off yet, I suggest you do.. why ? Because proof of concept code and an exploit are out in the wild. I'm posting the POC code for you to have a look at&lt;br /&gt;&lt;br /&gt;&lt;a href='http://www.geocities.com/sahir_h/ms0343.html'&gt;Proof Of Concept MS03-43&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you want to know how you can safely disable the service :&lt;br /&gt;&lt;br /&gt;1. Click Start&lt;br /&gt;2. Click Run type 'services.msc'&lt;br /&gt;3. Double click the 'Messenger' service&lt;br /&gt;4. Stop the service&lt;br /&gt;5. Change startup type to 'disabled'.&lt;br /&gt;&lt;br /&gt;More news later.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106726121892985454?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106726121892985454'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106726121892985454'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#106726121892985454' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106685894837263837</id><published>2003-10-23T03:12:00.000+05:30</published><updated>2003-10-23T03:12:27.913+05:30</updated><title type='text'></title><content type='html'>Just finished reading &lt;a href="http://www.amazon.com/exec/obidos/tg/detail/-/1931836876?v=glance"&gt;Stealing The Network: How To Own The Box&lt;/a&gt;. For those of you who haven't heard, its a book which concocts 10 fictitious hacking stories.. ranging from corporate espionage, to revenge.. and then showcases the hack with pretty good technical detail. Its been under a bit of controversy due to the usual ethics question. Frankly, though the book was really entertaining, there weren't any spectacularly new hacks.. I suppose that was part of the point -- to depict the genius involved in the strategy, rather than the tactics. All in all I'd give it a 7/10.&lt;br /&gt;&lt;br /&gt;The rest of the day was spent prowling a certain small ISP here and sending a detailed list of issues to the admin, god knows if it'll be acted on. Wonderful security included the default enable password on the border router, as well as full dns zone transfers available for the taking.&lt;br /&gt;&lt;br /&gt;Yknow when it comes to security, theres one bit of advice that nobody really gives and from my experience is the most important -- whatever shade of hat you wear -- its about being patient. Take things slowly.. whether you're scanning from the outside of the firewall, or dealing with an incident at your workplace -- take your time.....&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106685894837263837?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106685894837263837'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106685894837263837'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#106685894837263837' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106668727684651904</id><published>2003-10-21T03:31:00.000+05:30</published><updated>2003-10-27T19:02:48.786+05:30</updated><title type='text'></title><content type='html'>Ive added a new link to the sidebar, its a site called &lt;a href="http://www.djeaux.com/newsfeeds/security.shtml"&gt;djeaux.com&lt;/a&gt; and it provides aggregated news feeds from lots of different security news sources including bugtraq and full disclosure. The feeds are provided in RSS for an RSS reader as well as HTML for regular browsing. Very nice !&lt;br /&gt;&lt;br /&gt;I'm still busy uploading parts of my library, actually thats the easy part, the hard part is renaming all the files and classifying the material. If I really have the time I'll try and give it all some uniform formatting -- don't count on that though. &lt;br /&gt;&lt;br /&gt;All the material represents texts, tutorials or whitepapers that I have hand-picked because they represent original thought, interesting concepts, or just hard to find information. Consider it something like the &lt;a href="http://www.insecure.org/reading.html"&gt;good reading list&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here's a couple of teaser papers :&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/host_discovery.pdf"&gt;Advanced Host Discovery with Nmap&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/probing_firewalls.html"&gt;Probing Firewalls&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/http_tunnels.pdf"&gt;HTTP Tunnels through proxies&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/tcp_stack.html"&gt;Hardening the TCP Stack&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;All work is the copyright of the respective authors. If you want credit, or have a really good paper, let me know at sahir (at) firewall (dot) cx.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106668727684651904?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106668727684651904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106668727684651904'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#106668727684651904' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106628775391361426</id><published>2003-10-16T12:32:00.000+05:30</published><updated>2003-10-16T12:33:36.013+05:30</updated><title type='text'></title><content type='html'>So the newest version of &lt;a href='http://www.insecure.org/nmap'&gt;Nmap&lt;/a&gt; supports version scanning. In other words, not just will it tell you that port 80 is open, it will tell you that port 80 is running IIS/4.0... it'll even do this if the webserver is using a different port altogether. How does it do this ? Heres all you wanted to know about &lt;a href="http://www.insecure.org/nmap/versionscan.html"&gt;Nmap Version Scanning&lt;/a&gt;.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106628775391361426?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106628775391361426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106628775391361426'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#106628775391361426' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-10662860259860729</id><published>2003-10-16T12:03:00.000+05:30</published><updated>2003-10-16T12:04:31.896+05:30</updated><title type='text'></title><content type='html'>Here we go again. Four new vulnerabilities from the worlds most popular O/s maker. Vulnerable systems include Win2k and XP. &lt;br /&gt;&lt;a href="http://www.securityfocus.com/news/7213"&gt;Check it out&lt;/a&gt; &lt;br /&gt;Oh and you might want it from the horse's mouth:&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/winoct03.asp"&gt;Microsoft Security Bulletin October 03&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I'm busy uploading parts of my security and networking library. All the material in that library is hand picked and I'm quite proud of it. Of course you'll be able to access it all from here when I post a link.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-10662860259860729?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/10662860259860729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/10662860259860729'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#10662860259860729' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106569432210664190</id><published>2003-10-09T15:42:00.000+05:30</published><updated>2003-10-09T15:42:52.406+05:30</updated><title type='text'></title><content type='html'>Just read a groundbreaking paper which was posted to bugtraq entitled &lt;strong&gt;'Juggling With Packets'&lt;/strong&gt;. It describes, both in theory and in practice, how to use the latency or delay in network communications to store vast amounts of data (around 2gb from a 28.8kbps modem alone !) 'on the wire'! In other words, you have your data in an intermediate state in the network.. not on your disk.. never accessible to anyone except you. They describe many practical examples, including storing data in an email that will bounce back to you. I really can't explain the subject over here, but this one's worth a read if you wanna see some of the foundation shattering thoughts that can come out of bugtraq. It would be incredible to see an implementation of this !&lt;br /&gt;&lt;a href="http://www.securityfocus.com/archive/1/340362/2003-10-06/2003-10-12/2"&gt;Juggling With Packets&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Other stuff - I wrote a simple script for work that allows you to start simultaneous downloads on multiple machines and log the start and end time. I am modifying it to work in a master - slave fashion, so you can just issue a command on one system and get all the others to start downloading. Ill probably put up a link when its done so you can adapt it to any similar situations you might have.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106569432210664190?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106569432210664190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106569432210664190'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#106569432210664190' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106541547049018054</id><published>2003-10-06T10:14:00.000+05:30</published><updated>2003-10-06T10:15:46.073+05:30</updated><title type='text'></title><content type='html'>Just started helping out at Chris Partsenidis' stellar networking site &lt;a href="http://www.firewall.cx"&gt;firewall.cx&lt;/a&gt; as forum moderator. If you're looking for original content on networking and network security topics, this is the place to go ! I know a lot of people who study for certifications using the material on the site. Make sure you check out the forums as theres a lot of good information there too. I've added a link to the sidebar.&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106541547049018054?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106541547049018054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106541547049018054'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_10_01_archive.html#106541547049018054' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106356655187164042</id><published>2003-09-15T00:39:00.000+05:30</published><updated>2003-10-05T16:29:10.283+05:30</updated><title type='text'></title><content type='html'>My long weekend is over :( spent Thursday helping change the firewall topology at work, Check Point NG FP3 is pretty impressive from the little I've seen so far. As promised earlier &lt;a href="http://www.geocities.com/sahir_h/personal_firewalls.htm"&gt;here&lt;/a&gt; is the paper I wrote on the need for personal firewalls.&lt;br /&gt;&lt;br /&gt;I've been doing some research on buffer overflows, something I've never really dealt with since I stopped coding years ago (and am only just getting back into it). I found a couple of wonderfully written articles. Ultimately Aleph Ones &lt;a href="http://www.insecure.org/stf/smashstack.txt"&gt;Smashing The Stack For Fun &amp; Profit&lt;/a&gt; from Phrack issue 49 is the definitive paper.&lt;br /&gt;&lt;br /&gt;For those of you who are just starting out on assembly or buffer overflows, here are a couple of beginner tutorials :&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/Overflow_Tutorial.htm"&gt;Buffer Overflow Tutorial&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sahir_h/beginner.html"&gt;A Beginners Tutorial&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Enjoy yourself, and remember, its only fun until someone loses an eye..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106356655187164042?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106356655187164042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106356655187164042'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_09_01_archive.html#106356655187164042' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106320379125354203</id><published>2003-09-10T19:53:00.000+05:30</published><updated>2003-09-10T19:53:57.380+05:30</updated><title type='text'></title><content type='html'>Finally fixed that damn style sheet error that was irritating me ! I read today that Kevin Mitnick has written a book on social engineering called &lt;a href="http://www.amazon.com/exec/obidos/tg/detail/-/0471237124%3Fv%3Dglance&amp;e=7629"&gt;"The Art Of Deception"&lt;/a&gt;. I feel pretty bad for the guy, he went to jail on top of his game, spent time in solitary confinement, got released, and is now (imho) pretty lost. When he went to jail the net as we know it didn't exist. Someone even had to show him how to surf !&lt;br /&gt;&lt;br /&gt;Got some good new music by two of my favourite bands :&lt;br /&gt;&lt;a href="http://www.queensryche.com"&gt;Queensryche&lt;/a&gt; and &lt;a href="http://www.dreamtheater.net"&gt;Dream Theater&lt;/a&gt;. &lt;br /&gt;I'm listening to Queensryche's Promised Land right now (thanks Ra, Mim ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106320379125354203?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106320379125354203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106320379125354203'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_09_01_archive.html#106320379125354203' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106296528520523153</id><published>2003-09-08T01:38:00.000+05:30</published><updated>2003-09-08T01:41:56.650+05:30</updated><title type='text'></title><content type='html'>Right, spent the last 45 minutes updating the look of the page. Its been a while since I put my HTML skills (!) to good use, I like how it turned out. Started writing a paper entitled &lt;b&gt;"A Case For Personal Firewalls"&lt;/b&gt;, will put up a link to it when I'm done. Also had a long discussion on religious fundamentalism (I'm a die-hard atheist). Excited about getting Red Hat 9.0 and installing it on my virtual machines powered by &lt;a href="http://www.vmware.com"&gt;VMware&lt;/a&gt; the most kick ass virtualisation software going ! Check it out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106296528520523153?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106296528520523153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106296528520523153'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_09_01_archive.html#106296528520523153' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106287929047619296</id><published>2003-09-07T01:44:00.000+05:30</published><updated>2003-09-15T00:41:40.836+05:30</updated><title type='text'></title><content type='html'>Ok, I'm sitting at Uttam's putting back a few beers. Tomorrow is Sunday so chances are that we wont be getting up anytime &lt;strong&gt; early &lt;/strong&gt;. They're planning to involve me in a big project at work from Monday onwards.. lets see how that goes.  Oh yeah check out Uttam's co's website - Flakey, Mellow &amp; Grounded.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flamelgro.com"&gt; Flakey website - Nice flash&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106287929047619296?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106287929047619296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106287929047619296'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_09_01_archive.html#106287929047619296' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106233884398232284</id><published>2003-08-31T19:37:00.000+05:30</published><updated>2003-10-09T16:31:08.400+05:30</updated><title type='text'></title><content type='html'>Just thought I'd drop in a few interesting security related links :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com"&gt;www.securityfocus.com&lt;/a&gt; - The new home of bugtraq and a very good general security site&lt;br /&gt;&lt;a href="http://neworder.box.sk"&gt;neworder.box.sk&lt;/a&gt; - Site with slightly more underground viewership, lots of $cript kiddie$&lt;br /&gt;&lt;a href="ftp://ftp.technotronic.com"&gt;ftp.technotronic.com&lt;/a&gt; - Perhaps the largest tools archive online ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106233884398232284?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106233884398232284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106233884398232284'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_08_01_archive.html#106233884398232284' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-5750556.post-106233831494828113</id><published>2003-08-31T19:28:00.000+05:30</published><updated>2003-08-31T19:28:34.816+05:30</updated><title type='text'></title><content type='html'>And so it begins .....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5750556-106233831494828113?l=tftfotw.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106233831494828113'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5750556/posts/default/106233831494828113'/><link rel='alternate' type='text/html' href='http://tftfotw.blogspot.com/2003_08_01_archive.html#106233831494828113' title=''/><author><name>sahirh</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
