<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>And what's the time?</title>
	<atom:link href="http://ohsoninja.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ohsoninja.wordpress.com</link>
	<description>An ethical approach to examining security in an insecure world</description>
	<lastBuildDate>Tue, 08 Dec 2009 00:24:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='ohsoninja.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>And what's the time?</title>
		<link>http://ohsoninja.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://ohsoninja.wordpress.com/osd.xml" title="And what&#039;s the time?" />
	<atom:link rel='hub' href='http://ohsoninja.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Strange Days</title>
		<link>http://ohsoninja.wordpress.com/2009/05/24/strange-days/</link>
		<comments>http://ohsoninja.wordpress.com/2009/05/24/strange-days/#comments</comments>
		<pubDate>Sun, 24 May 2009 04:07:14 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=49</guid>
		<description><![CDATA[After my blog post about hacking the gibson, incoming search terms got really weird.  I would like to request that all the people searching for things like &#8220;angelina jolie very young,&#8221; please don&#8217;t do anything creepy around my blog. Lastly, while it isn&#8217;t official, I am pretty sure nUbuntu is dead&#8230;  On that note, it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=49&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>After my blog post about <a href="http://ohsoninja.wordpress.com/2008/04/20/the-ultimate-hacking-tutorial-the-gibson/">hacking the gibson</a>, incoming search terms got really weird.  I would like to request that all the people searching for things like &#8220;angelina jolie very young,&#8221; please don&#8217;t do anything creepy around my blog.</p>
<p>Lastly, while it isn&#8217;t official, I am pretty sure nUbuntu is dead&#8230;  On that note, it was fun and thanks to everyone involved.</p>
<p>Cheers.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=49&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2009/05/24/strange-days/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>N.S&#8230;.Hey!</title>
		<link>http://ohsoninja.wordpress.com/2009/01/22/nshey/</link>
		<comments>http://ohsoninja.wordpress.com/2009/01/22/nshey/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 08:56:45 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[spies]]></category>
		<category><![CDATA[spying]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=47</guid>
		<description><![CDATA[I can understand why things like this make the news, but really, at this point, why is anyone surprised? &#8220;The National Security Agency had access to all Americans&#8217; communications &#8212; faxes, phone calls, and their computer communications,&#8221; Tice claimed. &#8220;It didn&#8217;t matter whether you were in Kansas, in the middle of the country, and you [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=47&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I can understand why things like this make the news, but really, at this point, why is anyone surprised?</p>
<blockquote><p>
&#8220;The National Security Agency had access to <em>all</em> Americans&#8217; communications &#8212; faxes, phone calls, and their computer communications,&#8221; Tice claimed. &#8220;It didn&#8217;t matter whether you were in Kansas, in the middle of the country, and you never made foreign communications at all. They monitored <em>all</em> communications.&#8221;</p>
<p>Tice further explained that &#8220;even for the NSA it&#8217;s impossible to literally collect all communications. &#8230; What was done was sort of an ability to look at the metadata &#8230; and ferret that information to determine what communications would ultimately be collected.&#8221;</p></blockquote>
<p>Go on you say?  Read more <a href="http://http://rawstory.com/news/2008/Whistleblower_Bushs_NSA_targeted_reporters_0121.html">here</a></p>
<p>Looks like all you TOR lovers aren&#8217;t as safe as you thought! ; )</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/47/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=47&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2009/01/22/nshey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>There&#8217;s No Day Like 0-day</title>
		<link>http://ohsoninja.wordpress.com/2008/10/25/theres-no-day-like-0-day/</link>
		<comments>http://ohsoninja.wordpress.com/2008/10/25/theres-no-day-like-0-day/#comments</comments>
		<pubDate>Sat, 25 Oct 2008 17:46:30 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[intrusion detection]]></category>
		<category><![CDATA[intrusion prevention]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[terrible IDS vendors]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[zero day]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=37</guid>
		<description><![CDATA[Hello Childrens! So it&#8217;s been a long while and as I still have people viewing this blog despite the spell of inactivity, I thought it might be best to give any of the regulars an update. I&#8217;ve been pretty busy since I took a new job as a system administrator/in-house security guy but I am [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=37&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://ohsoninja.files.wordpress.com/2008/10/graffiti_skull.jpg"><img class="aligncenter size-full wp-image-38" title="graffiti_skull" src="http://ohsoninja.files.wordpress.com/2008/10/graffiti_skull.jpg?w=400&#038;h=266" alt="" width="400" height="266" /></a></p>
<p>Hello Childrens!</p>
<p>So it&#8217;s been a long while and as I still have people viewing this blog despite the spell of inactivity, I thought it might be best to give any of the regulars an update.</p>
<p>I&#8217;ve been pretty busy since I took a new job as a system administrator/in-house security guy but I am really enjoying my job.  I get a fair amount of freedom to &#8220;play,&#8221; with my security hobbies in the name of work and at the same time, learn a lot from an administrator&#8217;s point of view rather than just an attacker.  Recently we began testing a new IDS/IPS and I was more or less put in charge of auditing it and seeing how well it would perform.  My initial impression was that it was simplified enough to provide information directly to the user with no bullshit in between but this impression was given before I had enough time to actually probe the application.  As it turns out, during this testing (in less than 24 hours) 2 zero day vulnerabilities were discovered.  The first vulnerability is one which allows a remote attacker to inject arbitrary data into the hosts list of the application.  This was initially discovered during some automated exploit testing to see how it reported, what it picked up, etc.  After the test(s) concluded, I went to check the logs and noticed that I had some massive Unicode strings under the hosts list.  After examining this further, this string looked like the payload of a buffer overflow.  Based upon this, it became apparent that an attacker could add any information to the hosts list for this particular IDS.  I have also been working to find out if this attack can be leveraged to remove hosts from the list but as of yet, I have not had enough time.</p>
<p>The second 0 day which kind of piggybacks off of the first results DoS condition on the database the IDPS uses or at least its search function.  If you inject 5 of these unicode strings into the target monitoring list, the search function never completes.  That&#8217;s right, if you add 5 of these strings, click search, the database hangs and the search never completes rendering the program&#8217;s only reporting interface for Linux (the web interface) completely useless.</p>
<p>Both of these exploits can be accomplished remotely, with no authentication required, having no knowledge of anything on the target system.  All you need to do is launch this at the IP and it automagically works.</p>
<p>This is particularly disappointing as I was finally starting to like this product more for mass-deployment but this has proved to be a major setback regarding the amount of faith I was willing to put in this application.   For the time being, as I am not an advocate of any disclosure methods, the product and vendor will remain unnamed.  I am working in conjunction with the vendor to patch these issues so that maybe there is still hope for deploying the product but at this point, it is entirely too difficult to tell.</p>
<p>On a final note I am working on my term paper which deals with buffer overflows, polymorphic shellcode and IDS evasion and it will probably be awesome, just like everything else I write.  Maybe I can make it less formal and turn it into a posting series or maybe I can make it too complicated to follow and call it a whitepaper.  I am thinking to go with the first option.</p>
<p>That&#8217;s about all I have for now.  Have a great weekend and don&#8217;t do anything too stupid.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/37/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/37/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/37/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=37&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/10/25/theres-no-day-like-0-day/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>

		<media:content url="http://ohsoninja.files.wordpress.com/2008/10/graffiti_skull.jpg" medium="image">
			<media:title type="html">graffiti_skull</media:title>
		</media:content>
	</item>
		<item>
		<title>nUbuntu Tools and Suggestions</title>
		<link>http://ohsoninja.wordpress.com/2008/08/22/nubuntu-tools-and-suggestions/</link>
		<comments>http://ohsoninja.wordpress.com/2008/08/22/nubuntu-tools-and-suggestions/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 18:19:52 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacking tools]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[networking]]></category>
		<category><![CDATA[nubuntu]]></category>
		<category><![CDATA[opensource]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=33</guid>
		<description><![CDATA[Per my last post, I have been pretty involved in a the nUbuntu project and I would like to poll the community and readers of this blog for suggestions. Below is a list of new tools which I/we hope to have implemented in the next beta/alpha release. -W3af - BlindCrawl for forward bruteforce DNS - [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=33&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Per my last post, I have been pretty involved in a the nUbuntu project and I would like to poll the community and readers of this blog for suggestions.</p>
<p>Below is a list of new tools which I/we hope to have implemented in the next beta/alpha release.</p>
<p>-W3af</p>
<p>- BlindCrawl for forward bruteforce DNS</p>
<p>- SPIKE</p>
<p>-Inguma and it&#8217;s openDis and Krash fuzzing components.</p>
<p>-Ettercap GTK GUI</p>
<p>-Immunity Debugger (might be a WiNE nightmare)</p>
<p>-Lynis</p>
<p>-Paros Proxy</p>
<p>-BurpSuite</p>
<p>-ProxyStrike</p>
<p>-IKE-scan</p>
<p>-Hydra/xHydra</p>
<p>-ASP.NET application scanner</p>
<p>-DNS Predict for DNS enumeration</p>
<p>-Firetester</p>
<p>-Pantera</p>
<p>-MaltegoCE</p>
<p>-DirBuster</p>
<p>And more will come up as we think of them.  There are a lot of great tools listed above but there a lot more to be added of course!  If you can think of any that have not been listed that you find particularly useful, feel free to leave a comment and it will definitely be taken into consideration.</p>
<p>On a final note we could also use a mirror to help us with snapshot releases so if anyone wants to donate some bandwidth <strong>please</strong> leave a comment as your assistance would be greatly appreciated in the growth of this project.</p>
<p>Stay classy!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/33/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/33/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/33/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=33&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/08/22/nubuntu-tools-and-suggestions/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>nUbuntu</title>
		<link>http://ohsoninja.wordpress.com/2008/07/17/nubuntu/</link>
		<comments>http://ohsoninja.wordpress.com/2008/07/17/nubuntu/#comments</comments>
		<pubDate>Thu, 17 Jul 2008 19:54:18 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[nubuntu]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=31</guid>
		<description><![CDATA[Well it&#8217;s been quite some time since I updated this blog and to those that keep checking back, my apologies and appreciation. Things have been hectic this summer but there are a lot of cool projects underway. Inguma will (hopefully) have another release sometime in the near future with some awesome modules and exploits but [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=31&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Well it&#8217;s been quite some time since I updated this blog and to those that keep checking back, my apologies and appreciation.  Things have been hectic this summer but there are a lot of cool projects underway.  Inguma will (hopefully) have another release sometime in the near future with some awesome modules and exploits but unfortunately I can&#8217;t get into details on that.  However, I can go into details on another new project which has recently caught my eye, <a href="http://www.nubuntu.org/">nUbuntu</a>!</p>
<p>What is nUbuntu you ask?  Well I am glad you asked.  Per the words of the site:</p>
<blockquote><p>The main goal of nUbuntu is to create a distribution which is derived from the Ubuntu distribution, and add packages related to security testing, and remove unneeded packages, such as Gnome, Openoffice.org, and Evolution. nUbuntu is the result of an idea two people had to create a new distribution for the learning experience. Many people ask, &#8220;What makes it better than X?&#8221;, or &#8220;Why should I use this over Y&#8221;. Our answer to this question is, we do not think about whether people are using it or not. We are more concerned about the learning process. If you want to try something with a clean interface, fast, and an excellent range of programs please don&#8217;t hesitate to download nUbuntu.</p></blockquote>
<p>Last night I downloaded the .iso and needless to say I am very impressed.  </p>
<p>It should be noted that nUbuntu was originally released as a stripped down version of 6.10 and has since been pretty dormant.  Recently the project was resurrected from the depths of FOSS abandonment and looks to be making a strong comeback.  The 8.04 release is still in alpha and as with any alpha release, there is a lot of work to be done but so far the included utilities are off to a fantastic start.</p>
<p>Even as a liveCD in a VirtualBox, nUbuntu performs quickly and is terribly responsive.  The tools, while not all complete and/or fully implemented (it&#8217;s alpha!) really do a great job of demonstrating just how flexible and useful this distro aims to be.  While I could go on about the utilities and what it includes, <a href="http://www.thecodingstudio.com/opensource/linux/screenshots/index.php?linux_distribution_sm=nUbuntu%206.10">the screenshots</a> do a pretty fantastic job of that for me so take a look and see what it has to offer.</p>
<p>One last thing before we conclude todays episode of excitement, I often get the feeling like a lot of people in the community just want awesome tools without having to do much work which is not the spirit of community-based development.  Rather than preach about the merits of contributing I will simply say this: download it, break it, improve it, donate it, make suggestions and help us give <strong>you</strong> a better tool to work with.</p>
<p>Open source is sexy and so are you.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/31/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/31/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=31&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/07/17/nubuntu/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>Who Has My Data!?</title>
		<link>http://ohsoninja.wordpress.com/2008/06/02/who-has-my-data/</link>
		<comments>http://ohsoninja.wordpress.com/2008/06/02/who-has-my-data/#comments</comments>
		<pubDate>Mon, 02 Jun 2008 17:38:22 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[cyberdouchery]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[stupidity]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=27</guid>
		<description><![CDATA[In this day and age when people fear for their identity and personal information to a greater extent than ever before, you would think the encryption of such data would be a priority that is without parallel. Unfortunately this is not the case. It seems like every time I check my RSS feeds there is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=27&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In this day and age when people fear for their identity and personal information to a greater extent than ever before, you would think the encryption of such data would be a priority that is without parallel. Unfortunately this is not the case. It seems like every time I check my RSS feeds there is always a story about some corporation who posesses a fantastic ability to completely ignore the privacy of the people who keep them in business. Case in point:</p>
<blockquote><p>Bank of New York Mellon Corp. officials last week confirmed that a box of unencrypted data storage tapes holding personal information of more than 4.5 million individuals was lost more than three months ago by a third-party vendor during transport to an off-site facility.</p></blockquote>
<p>I wish I had a more eloquent way to say this, but what the hell?<br />
The first thing that came to my mind was whether or not the data was encrypted.  Sure enough, &#8220;It contended that none of the <strong>unencrypted</strong> data has been accessed or used.&#8221;  This brings me back to my first point of &#8220;what the hell?&#8221;<br />
As it stands, computing power is greater than those in the past had previously envisioned and as a result, it has increased the speed and effeciency at which data can be encrypted.  With this in mind, why are huge corporations <em>still</em> not protecting their data?</p>
<blockquote><p>The Hong Kong branch of banking giant Hongkong and Shanghai Banking Corporation Limited (HSBC) has lost a computer server with client data involving about 159,000 accounts, the bank confirmed on Wednesday.  <a href="http://news.xinhuanet.com/english/2008-05/08/content_8126223.htm">Source</a></p></blockquote>
<p style="text-align:left;">But wait, there&#8217;s more!</p>
<blockquote><p>An Internal Revenue Service employee lost an agency laptop early last month that contained sensitive personal information on 291 workers and job applicants, a spokesman said yesterday.</p>
<p>The IRS&#8217;s Terry L. Lemons said the employee checked the laptop as luggage aboard a commercial flight while traveling to a job fair and never saw it again. The computer contained unencrypted names, birth dates, Social Security numbers and fingerprints of the employees and applicants, Lemons said.  <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/06/07/AR2006060701987.html">Source</a></p></blockquote>
<p style="text-align:left;">I can accept and understand that laptops and hard drives get lost or stolen.  While having lost them is more inexcusable than being stolen, let&#8217;s be honest, sometimes stuff just happens.  However, losing an entire server, that is quite an achievement.</p>
<p style="text-align:left;">It worries me that those who we trust to protect our personal information and data can so easily lose it.  Beyond simply losing it, the fact that it is unencrypted and thus unprotected makes matters exponentially worse.  With the technology and resources we have, there is absolutely no reason these cryptographic safeguards are not put into place.  If people cannot guarantee the physical safety of the data (and we all know in the business of infosec there are no guarantees) they need to take certain measures which so far, appear to be frighteningly far down on the list of priorities.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=27&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/06/02/who-has-my-data/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>Dally In the Desert</title>
		<link>http://ohsoninja.wordpress.com/2008/05/30/dally-in-the-desert/</link>
		<comments>http://ohsoninja.wordpress.com/2008/05/30/dally-in-the-desert/#comments</comments>
		<pubDate>Fri, 30 May 2008 19:27:35 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[dave lewis]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[HD Moore]]></category>
		<category><![CDATA[johnny long]]></category>
		<category><![CDATA[networking]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=25</guid>
		<description><![CDATA[That was probably the best image I could have possibly found for this post, and yes, at Defcon, everyone dies. On that note&#8230; As the title implies, Defcon 16 is coming up in August and it will no doubt follow its pattern of continuing to improve. So far the speaker list is looking very impressive [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=25&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-44" title="t10rts_05_defcon" src="http://ohsoninja.files.wordpress.com/2009/01/t10rts_05_defcon.jpg?w=300&#038;h=300" alt="t10rts_05_defcon" width="300" height="300" /></p>
<p>That was probably the best image I could have possibly found for this post, and yes, at Defcon, everyone dies.  On that note&#8230;</p>
<p>As the title implies, <a href="http://www.defcon.org/">Defcon 16</a> is coming up in August and it will no doubt follow its pattern of continuing to improve.  So far the <a href="http://www.defcon.org/html/defcon-16/dc-16-speakers.html">speaker list</a> is looking <strong>very</strong> impressive and while I will not be able to attend, I am looking forward to seeing some of the videos that will no doubt be released shortly after the conference concludes.</p>
<p>Moving a long but still keeping Defcon in mind, I&#8217;d like to take a minute to recap some of my favorite talks from last year&#8217;s Defcon.</p>
<p><a href="http://video.google.com/videoplay?docid=-2160824376898701015&amp;q=defcon+15&amp;ei=PE5ASOnYC6PQ4gK7tsWCCQ">Johnny Long&#8217;s &#8220;No Tech Hacking&#8221;</a></p>
<p><a href="http://video.google.com/videoplay?docid=8220256903673801959&amp;q=defcon+15&amp;ei=PE5ASOnYC6PQ4gK7tsWCCQ">H.D. Moore and Val Smith on &#8220;Tactical Exploitation&#8221;</a></p>
<p>And last but far from least, <a href="http://video.google.com/videoplay?docid=3470502418262982787&amp;q=defcon+15+dan&amp;ei=D1BASMyYH4j84AKfmriSCQ">Dan Kaminsky on Reviewing the Web</a></p>
<p>Before we conclude today&#8217;s awesomeness, I would like to mention that due to time constraints I have been unable to really put together a solid tutorial similar to my <a href="http://ohsoninja.wordpress.com/2008/04/15/dissecting-the-web-with-burp-proxy/">Burp Proxy tutorial</a> or <a href="http://ohsoninja.wordpress.com/2008/03/26/token-fuzzing-with-krash/">fuzzing with Krash</a> and for that I apologize.  In the mean time I will be trying to keep the site updated with some of the day&#8217;s breaking network and information security news/articles/opinions/whatevers.</p>
<p>Take care.</p>
<p>P.S.  Nice find from Dave Lewis <a href="http://www.liquidmatrix.org/blog/2008/05/28/advisory-ciscoworks-arbitrary-code-execution-vulnerability/">here</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/25/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/25/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=25&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/05/30/dally-in-the-desert/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>

		<media:content url="http://ohsoninja.files.wordpress.com/2009/01/t10rts_05_defcon.jpg" medium="image">
			<media:title type="html">t10rts_05_defcon</media:title>
		</media:content>
	</item>
		<item>
		<title>Yea, I know&#8230;</title>
		<link>http://ohsoninja.wordpress.com/2008/05/19/yea-i-know/</link>
		<comments>http://ohsoninja.wordpress.com/2008/05/19/yea-i-know/#comments</comments>
		<pubDate>Mon, 19 May 2008 07:00:24 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[application security]]></category>
		<category><![CDATA[brute force]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=24</guid>
		<description><![CDATA[I&#8217;ve been bad about updating. Things have been busy but hopefully I can work up something cool this coming week. I had thought about detailing the Debian OpenSSL problems that a lot of us have been reading about but in case you missed it, H.D. Moore already did an incredible job on it. On May [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=24&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been bad about updating.  Things have been busy but hopefully I can work up something cool this coming week.</p>
<p>I had thought about detailing the Debian OpenSSL problems that a lot of us have been reading about but in case you missed it, H.D. Moore already did an incredible job on it.</p>
<blockquote><p>On May 13th, 2008 the Debian project announced that Luciano Bello found an interesting vulnerability in the OpenSSL package they were distributing. The bug in question was caused by the removal of the following line of code from md_rand.c</p>
<p><code>MD_Update(&amp;m,buf,j);<br />
[ .. ]<br />
MD_Update(&amp;m,buf,j); /* purify complains */</code></p>
<p>These lines were removed because they caused the Valgrind and Purify tools to produce warnings about the use of uninitialized data in any code that was linked to OpenSSL. You can see one such report to the OpenSSL team here. Removing this code has the side effect of crippling the seeding process for the OpenSSL PRNG. Instead of mixing in random data for the initial seed, the only &#8220;random&#8221; value that was used was the current process ID. On the Linux platform, the default maximum process ID is 32,768, resulting in a very small number of seed values being used for all PRNG operations.</p></blockquote>
<p>To view his entry and input on the topic, click <a href="http://metasploit.com/users/hdm/tools/debian-openssl/">here</a>.</p>
<p>In the mean time, play with <a href="http://w3af.sourceforge.net/">w3af</a>.  It&#8217;s fun for the whole family!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/24/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/24/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=24&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/05/19/yea-i-know/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>Regulators!  Mount up!</title>
		<link>http://ohsoninja.wordpress.com/2008/05/06/regulators-mount-up/</link>
		<comments>http://ohsoninja.wordpress.com/2008/05/06/regulators-mount-up/#comments</comments>
		<pubDate>Tue, 06 May 2008 17:39:12 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blogs]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[insecurity]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=23</guid>
		<description><![CDATA[So while I head into crunchtime a.k.a., last 2 weeks of classes, there won&#8217;t be any super sweet posts here. Make no mistake, every word I author is super sweet, but the content won&#8217;t be as major as previous entries. In the mean time, I&#8217;d like those who frequent my blog to be sure and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=23&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So while I head into crunchtime a.k.a., last 2 weeks of classes, there won&#8217;t be any super sweet posts here.  Make no mistake, every word I author is super sweet, but the content won&#8217;t be as major as previous entries.  In the mean time, I&#8217;d like those who frequent my blog to be sure and check out some other awesome security sites that you may not be familiar with.</p>
<p><a href="http://gnucitizen.org/">GNUCITIZEN</a><br />
GNUCitizen is a fantastic security blog and a site based around the hacker lifestyle.  They recently got some big attention regarding some Quicktime 0 day exploit but beyond that, it&#8217;s just good wholesome reading for the whole family.</p>
<p><a href="http://www.liquidmatrix.org/blog/">Liquid Matrix Security Digest</a><br />
This is the personal blog of security researcher Dave Lewis.  This is, without a doubt, on my list of top 5 blogs.  It is also the place where I first read about one of my newest and most favorite terms, cyberdouchery.</p>
<p><a href="http://www.darkreading.com/">Dark Reading Room</a><br />
The Dark Reading Room is a slick site which provides frequent updates on security articles and hacker activity.  It is also a great place to get lost catching up on old happenings you might have missed and put a bit more content into your security repertoire. (yea, we just Frenchified this blog, and no, I have no clue if that is a real word)</p>
<p>That&#8217;s really about all for now.  Hopefully I will be done with this semester incredibly fast and I look forward to doing some more tutorials.  If anyone has any suggestions for some material they would like to see covered, feel free to leave a comment as I enjoy hearing from readers.</p>
<p>Stay classy internet!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/23/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/23/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=23&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/05/06/regulators-mount-up/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
		<item>
		<title>NO! Pay attention IDS!</title>
		<link>http://ohsoninja.wordpress.com/2008/05/04/no-pay-attention-ids/</link>
		<comments>http://ohsoninja.wordpress.com/2008/05/04/no-pay-attention-ids/#comments</comments>
		<pubDate>Sun, 04 May 2008 07:31:30 +0000</pubDate>
		<dc:creator>ohsoninja</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[cracker]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[HIDS]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[intrustion detection system]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[NIDS]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://ohsoninja.wordpress.com/?p=22</guid>
		<description><![CDATA[While it isn&#8217;t the newest article (though it is pretty new), Dan Parker and Ryan Wegner have put an awesome piece together titled, &#8220;Integrating More Ingelligence into your IDS.&#8221; This 2 part article provides a lot of insight as to what can be done to fine tune an IDS. The more an intrusion detection system [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=22&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>While it isn&#8217;t the newest article (though it is pretty new), Dan Parker and Ryan Wegner have put an awesome piece together titled, &#8220;Integrating More Ingelligence into your IDS.&#8221;  This 2 part article provides a lot of insight as to what can be done to fine tune an IDS.</p>
<blockquote><p>
The more an intrusion detection system (IDS) knows about the network it is trying to protect, the better it will be able to protect the network. This is the fundamental principle behind target-based intrusion detection, where an IDS knows about the hosts on the network.</p></blockquote>
<p>And that is exactly what is discussed.  Why post this?  I feel that it is an excellent resource which can help beginners understand how an IDS does what it does and gives some tips for people that might be pros.  </p>
<p>Be sure to check it out in its entirety. <a href="http://www.securityfocus.com/infocus/1898">Part 1</a> <a href="http://www.securityfocus.com/infocus/1899">Part 2</a>.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/ohsoninja.wordpress.com/22/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/ohsoninja.wordpress.com/22/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/ohsoninja.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/ohsoninja.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/ohsoninja.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/ohsoninja.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/ohsoninja.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/ohsoninja.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/ohsoninja.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/ohsoninja.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=ohsoninja.wordpress.com&amp;blog=3245087&amp;post=22&amp;subd=ohsoninja&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://ohsoninja.wordpress.com/2008/05/04/no-pay-attention-ids/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/84a64aeb63f8fe404506e66b435b9e8a?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">ohsoninja</media:title>
		</media:content>
	</item>
	</channel>
</rss>
