<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6134556270169308040</id><updated>2011-11-27T15:18:48.763-08:00</updated><title type='text'>Experiments on computer security</title><subtitle type='html'>Rambling on life in general , computer security in particular</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-150600821255049889</id><published>2007-12-07T09:03:00.000-08:00</published><updated>2007-12-07T09:08:50.733-08:00</updated><title type='text'>Computer security explained</title><content type='html'>Many a times, I have been asked by people to explain computer security to them.People who are thoroughly non technical, who use computers and internet to just get their work done,  who are not much into security, but who would like to keep their systems secure. I have tried many ways, the one that worked well so far has been to present an allegorical analogy that people can understand more readily.&lt;br /&gt;&lt;br /&gt;This is the story I tell them:&lt;br /&gt;&lt;br /&gt;One upon a time, there was this gentleman who saw a vast tract                      of land. He thought he would do something useful and productive                      with the land. He decided to setup a town there. He went to                      the king ( Microsoft ) and requested him to assign the land                      (Windows ) to him. The king agreed, albeit with a hefty monetary                      tribute, and named him governor of this town( granted him                      a license ). He also sent a few of his servants (programs                      like notepad, paintbrush ) who would let him get along smoothly.&lt;br /&gt;                    The servants were trained for various purposes. While one                      was a good cook, the other was a good gardener, and likewise.&lt;br /&gt;                    Soon, people started settling in this town ( data and programs                      ). Whenever the governor needed some special work done ( spreadsheet,                      word processor ), he would pay a handsome tribute to the king                      or his associates ( bought a license ) and ask them to send                      one of his specialist people( MSWord , Excel)&lt;br /&gt;                    There were many other smaller towns around this town, some                      even in the neighboring kingdoms ( Other computers with different                      operating systems ). The neighboring towns were interconnected                      by good roads ( networking) and their people prospered with                      good trade and tourism ( advent of internet ). This got our                      governor thinking. He requested the king to build roads from                      his town neighboring towns. To use the roads, people needed                      chariots. The king's artisans made chariots and sold it to                      the governor.&lt;br /&gt;                    However, people in another town built a nicer and cheap chariot                      ( Netscape). The king feared those chariots would rule the                      roads, and so, started giving away chariots for free ( Internet                      Explorer). To ensure that his chariot could run faster, he                      put charioteers in each chariot. These were no ordinary charioteers.                      They knew the way around the town very well. So much so, they                      could get the chariot right inside the governor's treasury,                      only if the passenger knew how and what to ask of the charioteer                      (Active X etc )&lt;br /&gt;                    Now that the roads were getting a lot of varied traffic, the                      governor thought about managing it in a better way. The king                      had him designate each town gate ( port) for a specialized                      purpose to be manned by a specialized team( program using                      that port, like IIS using port 80 for a web server). So there                      was a gate which was used solely for moving agriculture produce                      The people manning the gates were trained by the king's people                      , and specialized in distinguishing good food grains from                      bad, and ensured that only the good stuff entered the town.                      (the programs responded to proper requests only) There was                      a different gate for household items, and a different one                      for tourists. ( like port 25 for SMTP email service , port                      21 FTP file transfer service ),This led to a well organized                      system of entering the town for different purposes, and saved                      time and money for the visiting traders as well as residents.                     &lt;br /&gt;                    However, local ironsmiths were having a hard time competing                      with cheap imports. They petitioned the governor and the governor                      ordered shutting down the iron trading gate. No one could                      now import iron into this town.&lt;br /&gt;                    Some of the gates (like the pottery gate) were not used too                      much. Over the years the governor all but forgot about such                      gates. It just remained with the gatekeepers whiling away                      their time.&lt;br /&gt;                    Now that roads had come up and chariots started to move around                      to neighboring towns and other places, the bandits in the                      forest around the town got interested in this town.(crackers)                      They hitched rides in the chariots that were going to or coming                      from the neighboring towns ( connection hijacking), befriended                      the charioteer (trust abuse), dumped the passenger , looked                      for any poorly manned gate (like our pottery gate ), fooled                      the gatekeepers, and sneaked in. Once in, they had the charioteer                      take them to the governor's treasury and decamped with his                      treasure. ( Computer compromised) The governor was irritated.                      He had the king create a moat (firewall) around his town,                      and had drawbridges installed. Only those gates which he explicitly                      permitted were to be allowed to be open and had their drawbridges                      lowered. ("default deny", allow selective access)&lt;br /&gt;                    He also gave passphrases to all people in his town, and to                      all regular visitors and traders.(authentication)They were                      to speak out their passphrases aloud at the gate.If it was                      right, they were allowed in.&lt;br /&gt;                    The bandits start arriving at the gate in hordes, and start                      saying out any and every phrase that existed/ they could think                      of. After many wild guesses, few of the guesses turned out                      to be right and the bandit who gave the right phrase could                      get in and steal stuff from the town(brute force ). To check                      this, he started issuing complicated long phrases in weird                      and foreign languages. Guessing the right phrase was still                      possible but would take a lot more time and effort (strong                      password)&lt;br /&gt;                    The bandits then started eavesdropping on the visitor-gatekeeper                      exchange and steal the visitor's phrase to gain entry. To                      prevent this he started issuing non forgeable certificates                      to the traders(SSL certificates). He also installed a sound                      proof cabin at each gate so that the pass phrase cannot be                      heard outside (Encrypted communication). No one without the                      certificate was allowed to even attempt an entry. The system                      worked well till the time a lot of genuine but new traders                      start showing up. They were vital to the town's growth, but                      letting them in without proper validation was a risk. To help                      with this, he authorized 5 highly trusted people to setup                      offices in neighborhood towns and issue certificates to issue                      the non forgeable certificates to valid and genuine traders.(                      like Verisign and Thwate)&lt;br /&gt;                    Of course, our governor had a huge and extended family living                      with him. The governor's relatives and family wielded as much                      power as the governor (privileged accounts), but unfortunately,                      some of them were quite gullible.&lt;br /&gt;                    At times, the bandits succeeded in intercepting one of the                      governor's family members. They would befriend him, ride back                      to the town, have him call off the gate staff, and finally                      get fellow bandits in through the unguarded gates.&lt;br /&gt;                    To counter this, the governed disempowered most of his relatives                      ( unprivileged user account). The gate staff would no longer                      obey them. For some of his work though, he still needed to                      empower some people, and he did empower a hand picked bunch                      of his loyal followers with various levels of authority (Selective                      access grant)&lt;br /&gt;                    However, the governor soon discovered that some of the gate                      people had problems which prevented them from doing them job                      perfectly. For example, one of the gate manning teams had                      a person with a slight hearing disability, and another who                      had slight visual impairment (vulnerable programs) . Bandits                      could gain entry on this gate by displaying forged certificates                      and uttering words which sounded similar to the required phrase.                      (exploits)&lt;br /&gt;                    Soon he discovered more problems with the gate people. Every                      time there was a problem with some gate person, the king would                      have that person examined, and if possible, help handling                      the problem.( patch releases)&lt;br /&gt;                    Some of the bandits however were not interested in money.                      All they wanted was to vandalize the town (viruses). These                      bandits adopted a variety of ways to get in and wreak havoc.                      One would pose as a skilful mason, and when the governor let                      him in and asked him to work, the mason would wreck the town.                      One would pose as a beautiful dancer, enter the town and dig                      up the roads.&lt;br /&gt;                    Fortunately, there were people in other kingdoms who knew                      these bandits by face (anti virus). The governor hired one                      of these people to protect his town. Every morning, the guard's                      kingdom's general sent him an album containing mug shots of                      newly discovered bandits (antivirus updates). That way, our                      guard was always up to date and knew of just about all vandal                      bandits.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-150600821255049889?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/150600821255049889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=150600821255049889' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/150600821255049889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/150600821255049889'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/12/computer-security-explained.html' title='Computer security explained'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-8651860465170168591</id><published>2007-07-19T21:34:00.000-07:00</published><updated>2008-12-10T07:31:26.807-08:00</updated><title type='text'>Pharming exposed</title><content type='html'>While many people know and understand &lt;span style="font-weight: bold;"&gt;phishing&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;pharming &lt;/span&gt;as a threat doesn’t seem to have caught popular imagination. In this article, I attempt to show how ignorance, or maybe, simple oversight can lead to a complete compromise of your system, causing your system to be a part of a bot network remote controlled by an attacker.&lt;br /&gt;There are many variants of pharming. Here , in this article, I demonstrate one that is very easy to pull off by a beginner to moderate level attacker.&lt;br /&gt;The attack leverages the fact that most ADSL modems run an http server for configuration, which is not secured&lt;br /&gt;Most of the time, a guy from the phone company comes and installs the ADSL modem, and the user is all set. What they dont tell you is that you need to change the default password on your ADSL modem immediately.To drive home my point, I thought it better to put on my bad guy hat, and get to work.Please note that no actual breakin was attempted on any of the systems, and that information is provided for educational purposes only.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Assumptions:&lt;br /&gt;You know how to set up a DNS and a HTTP server, and have your computer on the internet ( You will need to DMZ your own system if you are behind a ADSL router, and open up your firewall )&lt;br /&gt;You know how to set up a gateway and enable IP forwarding on it.&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-weight: bold;"&gt;Step 1&lt;/span&gt;: &lt;span style="font-weight: bold;"&gt;Reconnaissance&lt;/span&gt;&lt;br /&gt;&lt;span style=""&gt;            &lt;/span&gt;The first step is of course a reconnaissance attempt to find potential victims. I run a quick check for the world visible IP address my router has. I am lazy , so I simply visit showmyip.com. It shows me xxx.xxx.191.16&lt;br /&gt;Not surprisingly, I am in my isp's address block.I just take a small sample of 255 systems in my vicinity, whose IP would be in the range xxx.xxx.191.1 to xxx.xxx.191.255&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now I need to find out which all DSL modems in this range are systems with default password.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I know that my ISP uses Beetel ,DLink and Huawei modems , which generally have admin as id and passwords range from 1234, password, admin,utstar.So, I write a program ( uses &lt;a href="http://curl.haxx.se/"&gt;libcurl&lt;/a&gt;) which spawns 30 threads and tries each&lt;span style=""&gt;  &lt;/span&gt;IP in the range with the default id and password.A scan of the 255 addressess takes me 3 minutes and shows me 14 open DSL modems&lt;br /&gt;.The systems with 200 as HTTP response code will accept the default id and password (See figure below )&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z9oTliirjB4/RqBMtjgWZuI/AAAAAAAAACU/rIA0HmTgcvc/s1600-h/vulnlist.jpg"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_Z9oTliirjB4/RqBMtjgWZuI/AAAAAAAAACU/rIA0HmTgcvc/s200/vulnlist.jpg" alt="" id="BLOGGER_PHOTO_ID_5089151924437411554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Here is a screenshot of my system discovery code ( He he he, the actual code that does the recon is not shown )&lt;br /&gt;&lt;/p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Z9oTliirjB4/RqBCxDgWZrI/AAAAAAAAAB8/pKfVCaKWy5Q/s1600-h/code.JPG"&gt;&lt;img style="cursor: pointer; width: 331px; height: 194px;" src="http://1.bp.blogspot.com/_Z9oTliirjB4/RqBCxDgWZrI/AAAAAAAAAB8/pKfVCaKWy5Q/s200/code.JPG" alt="" id="BLOGGER_PHOTO_ID_5089140989450675890" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Click to enlarge: Code screenshot&lt;br /&gt;&lt;br /&gt;If you have a dedicated system and unlimited data transfer, you can probably run this whole day to scan thousands of IP addresses.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-weight: bold;"&gt;Step 2: Preparing for the attack:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Now I need to decide what I want to do with these open systems. There are just too many things one can do with this. The possibilities ...I will explain later. For now, lets just say I want to grab those user's email id and password. For this, I can set up my own DNS, and put in authoritative entries for gmail, hotmail,yahoo, whatever I fancy. For all other domains, I simply forward them to my ISP's DNS. This is how it will work.&lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z9oTliirjB4/RqBKCzgWZsI/AAAAAAAAACE/1qSBgXSCnvY/s1600-h/normal.jpg"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_Z9oTliirjB4/RqBKCzgWZsI/AAAAAAAAACE/1qSBgXSCnvY/s200/normal.jpg" alt="" id="BLOGGER_PHOTO_ID_5089148990974748354" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Click to enlarge: normal steady state DSL in operation&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;Once I have set up my DNS, I also need to put up a webserver to server those pages.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;So, two major cavaets here are , &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;1. To setup a DNS server&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;2. To setup a webserver with a DataBase at the backend to grab the user id and passwords&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-weight: bold;"&gt;Step 3: The attack:&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Though this step can be completely automated with scripts, or C programs,I do this manually with one single system, just as a matter of example:&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;The schematic of a DNS hijacking attack is shown below&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z9oTliirjB4/RqBLLTgWZtI/AAAAAAAAACM/IU0eC_w_pDI/s1600-h/dnsijack.jpg"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_Z9oTliirjB4/RqBLLTgWZtI/AAAAAAAAACM/IU0eC_w_pDI/s200/dnsijack.jpg" alt="" id="BLOGGER_PHOTO_ID_5089150236515264210" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;So I login to this person's DSL modem, and point his DNS to my DNS server .And would you believe it??Thats all I need to do to grab this persons internet.&lt;/p&gt;&lt;br /&gt;Logging in to the victim's router&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z9oTliirjB4/RqBOOjgWZvI/AAAAAAAAACc/IfOCDVYulz4/s1600-h/victim_home.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_Z9oTliirjB4/RqBOOjgWZvI/AAAAAAAAACc/IfOCDVYulz4/s200/victim_home.JPG" alt="" id="BLOGGER_PHOTO_ID_5089153590884722418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Altering the DNS address&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z9oTliirjB4/RqBQyjgWZwI/AAAAAAAAACk/0_lhWzQbCIE/s1600-h/victim_dns.jpg"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_Z9oTliirjB4/RqBQyjgWZwI/AAAAAAAAACk/0_lhWzQbCIE/s200/victim_dns.jpg" alt="" id="BLOGGER_PHOTO_ID_5089156408383268610" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;So that was easy, you could harvest a ton of stuff this way. But this doesnt give you much.So additional stuff can I try??Ummm..why not intercept ALL his traffic ?How ??Thats easy...set up your system to be gateway and do an IP forwarding&lt;br /&gt;&lt;br /&gt;But then I want his whole system. Not just the traffic.Umm..OK, put his system on the DMZ. That way he is out in the open. I let nm&lt;a href="javascript:void(0)" onclick="return false;" tabindex="10"&gt;&lt;span&gt;&lt;/span&gt;&lt;/a&gt;ap take shot at identifying what OS he os running, pull out a bunch of exploits and throw at this system , and presto...I have his computer.&lt;br /&gt;&lt;br /&gt;But what will I do with his computer ? Will think about that later&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-8651860465170168591?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/8651860465170168591/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=8651860465170168591' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/8651860465170168591'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/8651860465170168591'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/07/pharming-exposed.html' title='Pharming exposed'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Z9oTliirjB4/RqBMtjgWZuI/AAAAAAAAACU/rIA0HmTgcvc/s72-c/vulnlist.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-7384302924341350298</id><published>2007-07-17T20:51:00.000-07:00</published><updated>2008-12-10T07:31:27.660-08:00</updated><title type='text'>Identifying Phish</title><content type='html'>Today, I got a &lt;a href="http://www.mcafee.com/phishing_quiz/"&gt;Mcafee link&lt;/a&gt; which apparently is a phish awareness testing quiz.So, off I went , took the quiz, got 7/10.Great. Now to the point: Somehow, I never expected a security company to offer lame ways of identifying Phish.&lt;br /&gt;If I were to identify Phish, the easiest way is to just take a look at the address bar, and check the site (Yeah, the phisher can put an image on the address bar , but that is easy to figure  out).Another precaution is beware of wrong SSL certificates. These 2 prime measures seem to have been conveniently ignored.&lt;br /&gt;Just have a look:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;This is the original aol phish page:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z9oTliirjB4/Rp2ceDgWZlI/AAAAAAAAABM/-1D_-nO2r90/s1600-h/aol_page.jpg"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_Z9oTliirjB4/Rp2ceDgWZlI/AAAAAAAAABM/-1D_-nO2r90/s200/aol_page.jpg" alt="" id="BLOGGER_PHOTO_ID_5088395194149529170" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;This is siteadvisor's explanation:&lt;/b&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z9oTliirjB4/Rp2c_TgWZmI/AAAAAAAAABU/XYU3RGbOXww/s1600-h/aol_explain.jpg"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_Z9oTliirjB4/Rp2c_TgWZmI/AAAAAAAAABU/XYU3RGbOXww/s200/aol_explain.jpg" alt="" id="BLOGGER_PHOTO_ID_5088395765380179554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Bank of America Phish analysis offered by siteadvisor&lt;/b&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z9oTliirjB4/Rp2dnTgWZnI/AAAAAAAAABc/6jX3CIkt5rE/s1600-h/boa.jpg"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_Z9oTliirjB4/Rp2dnTgWZnI/AAAAAAAAABc/6jX3CIkt5rE/s200/boa.jpg" alt="" id="BLOGGER_PHOTO_ID_5088396452574946930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Capital One Phish analysis&lt;/b&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z9oTliirjB4/Rp2eDDgWZoI/AAAAAAAAABk/qN8DRsWFbBM/s1600-h/cap_one.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_Z9oTliirjB4/Rp2eDDgWZoI/AAAAAAAAABk/qN8DRsWFbBM/s200/cap_one.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5088396929316316802" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Its surprising how a security company promotes such crude means to identify phish.&lt;br /&gt;The sad part is that these guys &lt;b&gt;seem to imply&lt;/b&gt; that a site with correct grammar and graphics is &lt;b&gt;NOT&lt;/b&gt; a Phish site.Imagine what such inference does to the grandma class of users. This is unfortunate.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-7384302924341350298?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/7384302924341350298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=7384302924341350298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/7384302924341350298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/7384302924341350298'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/07/identifying-phishing.html' title='Identifying Phish'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Z9oTliirjB4/Rp2ceDgWZlI/AAAAAAAAABM/-1D_-nO2r90/s72-c/aol_page.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-360625670202177033</id><published>2007-07-12T05:43:00.000-07:00</published><updated>2008-12-10T07:31:28.482-08:00</updated><title type='text'>PhishPhighting</title><content type='html'>Today, in one of the &lt;a href="http://www.orkut.com/"&gt;orkut &lt;/a&gt;( a social networking site ) communities, I read a post on how a guy lost his gmail id on a phish site. He posted the &lt;a href="http://0rkut.hostistry.com/Glogin.aspx.htm"&gt;phish url&lt;/a&gt;, and warned others to be aware.&lt;p class="MsoNormal" style="text-indent: 0.5in;"&gt;True, other than try and steer clear of them ,there is little one can do for a phish attack.Surely, there are tons of advise on how to guard from phish.Whats more, security companies are making money out of identifying and flagging phish sites.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;Now that makes me wonder...Is there no other go? Reminded me of the "&lt;span style="color: rgb(51, 204, 255);"&gt;dont get mad, get even&lt;/span&gt;" adage.Lets see how we can do that. Think...what does a phisher do with the information he gleans?He uses it ,of course. From reading other’s emails to emptying bank accounts, they do it all.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;From a security perspective however, there is no such thing as foolproof security. Its just a matter of making it more difficult for the bad guy. So, in our attempt to get even with the phisher, that’s what we focus on. We try and make it difficult for him to use phished information. How?? We flood the phisher with junk data. Data that is trash, maybe randomly or dictionary generated. Once we flood the Phisher's database ( or whatever backend he is using) with trash, its like finding the proverbial needle in the haystack for the phish guy. Imagine having one valid victim credentials and ten thousand other garbage credentials.The only possible way for a phisher is to actually use the victim information to find out if its genuine.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;Later in the article I demonstrate how such a thing maybe accomplished.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;Surely, a more competent phisher will then possibly deploy countermeasures to such flooding.He may implement tracking , session or in extreme cases captchas in his phish site,.Maybe he will filter out the flooding IPs.We will probably think of a solution when they get there. Remember, I am talking about raising the bar. Not about eliminating the problem. Still, its not difficult to defeat such anti - antiphish countermeasures (Captchas would be an exception though)&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;Also, remember, I am not talking about protecting yourself from phishers, I am talking about making their life miserable enough to wean them away from it.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;br /&gt;&lt;/span&gt;The inspiration for this comes from the hilarious &lt;a href="http://419eater.com/"&gt;419eater.com&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now, as promised earlier lets look at how one may accomplish this.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Before I do that, there are some tools , libraries and utilities that I used, To name a few , &lt;a href="http://parosproxy.org/"&gt;&lt;st1:place st="on"&gt;Paros&lt;/st1:place&gt; &lt;/a&gt;, &lt;a href="http://curl.haxx.se/"&gt;libcurl ,&lt;/a&gt; perl, gcc , linux…Wow…&lt;/p&gt;  &lt;p class="MsoNormal"&gt;The phish site:&lt;/p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z9oTliirjB4/RpZD0TgWZeI/AAAAAAAAAAU/uwPc87oKdC0/s1600-h/phishpage.JPG"&gt;&lt;img style="cursor: pointer; width: 358px; height: 322px;" src="http://4.bp.blogspot.com/_Z9oTliirjB4/RpZD0TgWZeI/AAAAAAAAAAU/uwPc87oKdC0/s400/phishpage.JPG" alt="" id="BLOGGER_PHOTO_ID_5086327395029771746" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Then I fire up my favorite : &lt;/span&gt;&lt;st1:place style="font-weight: bold;" st="on"&gt;Paros&lt;/st1:place&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z9oTliirjB4/RpZE0zgWZfI/AAAAAAAAAAc/KCJuCJUQL1Y/s1600-h/parossettings.JPG"&gt;&lt;img style="cursor: pointer; width: 363px; height: 307px;" src="http://2.bp.blogspot.com/_Z9oTliirjB4/RpZE0zgWZfI/AAAAAAAAAAc/KCJuCJUQL1Y/s400/parossettings.JPG" alt="" id="BLOGGER_PHOTO_ID_5086328503131334130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Then I set my browser to use this proxy&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z9oTliirjB4/RpZFYTgWZgI/AAAAAAAAAAk/R8lfCjWAG1w/s1600-h/browsersettings.JPG"&gt;&lt;img style="cursor: pointer; width: 359px; height: 228px;" src="http://4.bp.blogspot.com/_Z9oTliirjB4/RpZFYTgWZgI/AAAAAAAAAAk/R8lfCjWAG1w/s400/browsersettings.JPG" alt="" id="BLOGGER_PHOTO_ID_5086329113016690178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;And then I get victimized&lt;/p&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z9oTliirjB4/RpZF9DgWZhI/AAAAAAAAAAs/NWWvePW4B4o/s1600-h/victimised.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_Z9oTliirjB4/RpZF9DgWZhI/AAAAAAAAAAs/NWWvePW4B4o/s400/victimised.JPG" alt="" id="BLOGGER_PHOTO_ID_5086329744376882706" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p style="font-weight: bold;" class="MsoNormal"&gt;Here is what the phish request looks like:&lt;/p&gt;  &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z9oTliirjB4/RpZGgzgWZiI/AAAAAAAAAA0/6MXr7JpFVzw/s1600-h/success.JPG"&gt;&lt;img style="cursor: pointer; width: 360px; height: 295px;" src="http://2.bp.blogspot.com/_Z9oTliirjB4/RpZGgzgWZiI/AAAAAAAAAA0/6MXr7JpFVzw/s400/success.JPG" alt="" id="BLOGGER_PHOTO_ID_5086330358557206050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;After trying this with various permutations and combinations of systems and credentials, I found that other than the credentials, everything else remains the same everytime I get phished.This means , I am in luck. All I need to hose the phisher’s inbox is to keep sending him garbage post requests. Great. Now to some actual work.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Now there are many ways I can swamp this guy. I can do a quick and dirty command line ( ahh…isn’t curl great !!!), or , write my own C code using libcurl, or do a plain and simple perl script that uses libcurl binding.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;I tried all three. But somehow, doesn’t seem to be a good idea to publish the code. I haven’t actually hosed the guy yet, I am in an ethical dilemma. Gunning down someone ,even if that person is a crook , is still a crime. Let me sleep over it&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-360625670202177033?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/360625670202177033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=360625670202177033' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/360625670202177033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/360625670202177033'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/07/phishphighting.html' title='PhishPhighting'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z9oTliirjB4/RpZD0TgWZeI/AAAAAAAAAAU/uwPc87oKdC0/s72-c/phishpage.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-6559595082410375261</id><published>2007-07-02T19:17:00.000-07:00</published><updated>2007-07-02T19:27:25.986-07:00</updated><title type='text'>business emails on 3rd party webmail servers?</title><content type='html'>The other day, I heard about an individual whose company email account was not functioning. There had been some problems with her account. Instead of getting it fixed by contacting IT and helpdesk , she started using her personal email id on gmail for business communications. Important and confidential information regarding the product she works on , code snippets, developer discussions are all a part of google data centers now.&lt;br /&gt;  What bothers me is that this is not an one off isolated case. There are probably countless other instances where people are sending out sensitive business information over 3rd party public email severs.&lt;br /&gt;  It's probably a matter of time before someone comes up with a proposal for harvesting and profiting from sensitive data on email data centers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-6559595082410375261?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/6559595082410375261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=6559595082410375261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/6559595082410375261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/6559595082410375261'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/07/business-emails-on-3rd-party-webmail.html' title='business emails on 3rd party webmail servers?'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-5563347473274971942</id><published>2007-06-29T10:39:00.000-07:00</published><updated>2007-06-29T11:12:51.872-07:00</updated><title type='text'>The penetration tester</title><content type='html'>As I mentioned in the last post, I was slated to interview a potential penetration tester.&lt;br /&gt;At the appointed time, the guy walks in, with a voluminous stack of printouts of emails from various sources crediting his work.&lt;br /&gt;Boy...was I impressed.A guy with close to 8 years of experience, well versed with both black box and white box, with experience on security focused code reviews, a member of a web app security group, exploits under his belt and what not ...&lt;br /&gt;Still, I need to talk to him , assess his competencies.So, I write a few lines of code that creates an SQL query string on the fly using a fixed sized stack buffer, and ask for a review.&lt;br /&gt;And then the punishment began.&lt;br /&gt;He identified the buffer overflow . I asked him to explain the working of a buffer overflow.I got a "are you stupid" stare, and my candidate went on tangentially about a tool which can detect all "unsafe" function calls, and report it.I prompted him to focus on the question, he goes on again on a remarkable tool that he used ( No, he wasnt the author of the tool, but an user) to discover web app security vulnerabilities. Well done, I said and moved on...&lt;br /&gt;&lt;br /&gt;"Explain to me an XSS".He jumped to it. He explained.And I listened.We went to a site which had a blatant "staring  you on the face" XSS. He explained to me again that he uses yet another "tool" for detecting XSS, and wont be able to answer my question without access to his tool.&lt;br /&gt;&lt;br /&gt;But then, I do look for a possible flash of brilliance from people I interview. You can't expect people to know everything, can you? So, I go back to the code , and ask him how to mitigate the buffer overflow.&lt;br /&gt;&lt;br /&gt;The contrived code was something like this&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#00cccc;"&gt;int userExists( const char *name)&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#00cccc;"&gt;{&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#00cccc;"&gt;     char buffer[1024];&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#00cccc;"&gt;     sprintf(buffer,"select * from users where name='%s'",name);&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#00cccc;"&gt;     return runQuery(buffer);&lt;/span&gt;&lt;br /&gt;&lt;span style="color:#00cccc;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Solution...replace sprintf with&lt;br /&gt;&lt;span style="color:#33ccff;"&gt;&lt;strong&gt;memcpy(buffer,name, strlen(name) - 1);&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;At this stage, I had two options...thank him for his time and interest, or pull my hair out.&lt;br /&gt;I still have hair on my head...&lt;br /&gt;&lt;br /&gt;Resume padding can only get you an interview.Beyond that, you gotta know your stuff dude...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-5563347473274971942?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/5563347473274971942/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=5563347473274971942' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/5563347473274971942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/5563347473274971942'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/06/penetration-tester.html' title='The penetration tester'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-3354674290584924229</id><published>2007-06-29T10:26:00.000-07:00</published><updated>2007-06-29T10:38:44.639-07:00</updated><title type='text'>Tech Jargon</title><content type='html'>Two days ago, I was chatting with a lady ( lets call her Mary ) in the HR department.I was about to conclude the conversation&lt;br /&gt;Me      : I have to go now , Mary, I am scheduled to interview a guy.&lt;br /&gt;Mary  : Why don't you take up some of my work and let me interview the guy ?&lt;br /&gt;Me      : You can do an interview on "penetration testing" ??&lt;br /&gt;&lt;br /&gt;Mary goes red in the face, looks embarrassed, and returns to her desk without replying.I wonder why.&lt;br /&gt;Later in the day I realized . To the uninitiated, "penetration testing" seems to have a generous helping of sexual connotation.&lt;br /&gt;&lt;br /&gt;I emailed her a wikipedia link which explains &lt;a href="http://en.wikipedia.org/wiki/Penetration_Testing"&gt;penetration testing&lt;/a&gt; :-)&lt;br /&gt;&lt;br /&gt;Moral of the story: Do not use tech jargon in day to day life&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-3354674290584924229?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/3354674290584924229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=3354674290584924229' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/3354674290584924229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/3354674290584924229'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/06/tech-jargon.html' title='Tech Jargon'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-7252114970000389361</id><published>2007-06-17T21:26:00.000-07:00</published><updated>2007-06-17T21:35:39.632-07:00</updated><title type='text'>To hell with privacy</title><content type='html'>I am in an important discussion at office , and my cell rings.&lt;br /&gt;&lt;br /&gt;Caller: Good evening Sir, This is **** from citibank. You have a "first citizen" card with Shoppers stop , right.&lt;br /&gt;Me : Yeah , I do&lt;br /&gt;Caller:  Sir , we are offering life time free credit card to "First Citizen" card holders.&lt;br /&gt;Me : No I am not interested , thank you.(Disconnects)&lt;br /&gt;&lt;br /&gt;I have been getting 2 calls a day now , one on my fixed line ,and one on my cell, wanting me to signup for a citibank credit card. Its a different person each day , with the same story. shopper's stop, citibank ...&lt;br /&gt;All this , because I  signed up with SHOPPER'S STOP 's loyalty program,a store that doesn't care 2 hoots for your privacy , and goes on to share your personal information with every tom dick and harry&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The bottom line : Unless your life depends on it , be wary of divulging your personal details, because once you do , there is no respite.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-7252114970000389361?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/7252114970000389361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=7252114970000389361' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/7252114970000389361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/7252114970000389361'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/06/to-hell-with-privacy.html' title='To hell with privacy'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-5920835584408980817</id><published>2007-06-15T21:53:00.000-07:00</published><updated>2007-06-15T22:17:29.336-07:00</updated><title type='text'>So here it is</title><content type='html'>During my &lt;a href="http://anerobic.blogspot.com/2007/05/gotcha.html"&gt;last post&lt;/a&gt; I talked about a networking site that looked to have a problem with their site. Sine then, I have written to them detailing my understanding and interpretation of the issue, and they haven't got beyond thanking me and promising to have someone talk to me about it. Well , its been a long while, and apparently, they aren't interested.&lt;br /&gt;So , here are the details on it:&lt;br /&gt;&lt;br /&gt;http://linkedin.com/redirect?url=http://anerobic.blogspot.com sends you to this page.&lt;br /&gt;url encoding the request to obfuscate it used to work earlier, when I first reported the problem, but stopped working after that. So , apparently, they did something, I mean, some fixing, to weed out potential phish bait urls which were url encoded. So, this doesnt work anymore&lt;br /&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://linkedin.com/%72ed%69re%63%74?url=%68tt%70%3A%2F%2Fw%77w%2Ey%61ho%6F%2E%63om" target="_blank"&gt;http://linkedin.com/%72ed%69re&lt;wbr&gt;%63%74?url=%68tt%70%3A%2F%2Fw&lt;wbr&gt;%77w%2Ey%61ho&lt;br /&gt;%6F%2E%63om&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;but this still works&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);font-size:85%;" &gt;&lt;br /&gt;&lt;a style="font-family: arial;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://linkedin.com/%72ed%69re%63%74?url=%72ed%69re%63%74?url=%68tt%70%3" target="_blank"&gt;&lt;/a&gt;&lt;/span&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://linkedin.com/%72ed%69re%63%74?url=%72ed%69re%63%74?url=%68tt%70%3A%2F%2Fw%77w%2Ey%61ho%6F%2E%63om" target="_blank"&gt;http://linkedin.com/%72ed%69re&lt;wbr&gt;%63%74?url=%72ed%69re%63%74&lt;wbr&gt;?url=%68tt%70%3&lt;br /&gt;A%2F%2Fw%77w%2Ey%61ho%6F%2E&lt;wbr&gt;%63om&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Keep up the good work LinkedIn.com  :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-5920835584408980817?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/5920835584408980817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=5920835584408980817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/5920835584408980817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/5920835584408980817'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/06/so-here-it-is.html' title='So here it is'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-8698393603046693528</id><published>2007-05-26T11:24:00.001-07:00</published><updated>2007-05-26T11:33:00.304-07:00</updated><title type='text'>Gotcha</title><content type='html'>&lt;span style="font-family:trebuchet ms;font-size:85%;"&gt;While going through a well known networking site, something weird caught my eye today.Hey...it looks familiar.I try out a few rudimentary stuff for confirmation , and uh oh...these guys have a security problem&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;font-size:85%;"&gt;It surprises me how so scant an attention is paid to a thing as important as information security.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;font-size:85%;"&gt;The problem is not that nasty, but it potentially puts the subscribers to that site ( a few millions I guess )  at risk&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;font-size:85%;"&gt;Anyways, I am gonna try and contact those guys to get them to fix it.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;font-size:85%;"&gt;Lets see how it goes.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-8698393603046693528?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/8698393603046693528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=8698393603046693528' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/8698393603046693528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/8698393603046693528'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/05/gotcha.html' title='Gotcha'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6134556270169308040.post-2580983700443541920</id><published>2007-02-25T11:00:00.000-08:00</published><updated>2007-02-25T11:01:39.168-08:00</updated><title type='text'>Test</title><content type='html'>Just testing out my first blog&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6134556270169308040-2580983700443541920?l=anerobic.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://anerobic.blogspot.com/feeds/2580983700443541920/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6134556270169308040&amp;postID=2580983700443541920' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/2580983700443541920'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6134556270169308040/posts/default/2580983700443541920'/><link rel='alternate' type='text/html' href='http://anerobic.blogspot.com/2007/02/test.html' title='Test'/><author><name>sudeep</name><uri>http://www.blogger.com/profile/08825812307909344810</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
