<?xml version='1.0' encoding='utf-8' ?>
<!--  If you are running a bot please visit this policy page outlining rules you must respect. http://www.livejournal.com/bots/  -->
<rss version='2.0' xmlns:lj='http://www.livejournal.org/rss/lj/1.0/' xmlns:media='http://search.yahoo.com/mrss/' xmlns:atom10='http://www.w3.org/2005/Atom'>
<channel>
  <title>PaulDotCom&apos;s Blog</title>
  <link>http://kungfuhacker.livejournal.com/</link>
  <description>PaulDotCom&apos;s Blog - LiveJournal.com</description>
  <lastBuildDate>Tue, 15 Nov 2005 16:37:19 GMT</lastBuildDate>
  <generator>LiveJournal / LiveJournal.com</generator>
  <lj:journal>kungfuhacker</lj:journal>
  <lj:journalid>8600424</lj:journalid>
  <lj:journaltype>personal</lj:journaltype>
  <atom10:link rel='hub' href='http://pubsubhubbub.appspot.com/' />
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/8429.html</guid>
  <pubDate>Tue, 15 Nov 2005 16:37:19 GMT</pubDate>
  <title>PaulDotCom Is Moving</title>
  <link>http://kungfuhacker.livejournal.com/8429.html</link>
  <description>After pulling my hair out (Yes, I have hair now :) for the past week or so I&apos;ve finally got my new site operational.  I am very excited to have complete control of my site, blog, and RSS feeds.&lt;br /&gt;&lt;br /&gt;You can now access my blog, podcasting, and all content by going directly to:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://pauldotcom.com&quot;&gt;http://pauldotcom.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I will be updating my blog frequently with the latest security news, research, geek stuff, and of course PaulDotCom Security Weekly.&lt;br /&gt;&lt;br /&gt;I am also going to move over my entries from livejournal to the new site as time permits.  You can still access the content through the following links:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://pauldotcom.com/podcast/&quot;&gt;http://pauldotcom.com/podcast/&lt;/a&gt; - PaulDotCom Security Weekly&lt;br /&gt;&lt;a href=&quot;http://pauldotcom.com/blog/&quot;&gt;http://pauldotcom.com/blog/&lt;/a&gt; - My security/geek stuff blog&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;br /&gt;Please send me your feedback/comments/suggestions:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;mailto:paul@pauldotcom.com&quot;&gt;Paul Asadoorian&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(This will be the last post to this blog)&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/8429.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/8095.html</guid>
  <pubDate>Mon, 14 Nov 2005 20:42:02 GMT</pubDate>
  <title>Home Computer and Network Security Course</title>
  <link>http://kungfuhacker.livejournal.com/8095.html</link>
  <description>I will be teaching the &lt;a href=&quot;https://www.sans.org/&quot;&gt;SANS&lt;/a&gt; Stay Sharp course titled &lt;a href=&quot;http://www.sans.org/staysharp/details.php?id=1298&quot;&gt;Home Computer and Network Security&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This course will cover:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;In this class, you will learn about many different threats, antivirus programs, firewalls, anti-spyware, identity theft, Phishing, how to create strong passwords and more. This course will give you the basic skills you need to protect yourself from various threats on the Internet whether you are at home, on the road or at work. &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;It will be held on January 18, 2006 from 6:00PM-9:00PM at &lt;a href=&quot;http://www.oshean.org&quot;&gt;OSHEAN&lt;/a&gt; in N. Kingstown, RI.&lt;br /&gt;&lt;br /&gt;The cost of the course if $50.00 per student and you can &lt;b&gt;&lt;a href=&quot;https://www.sans.org/registration/register.php?conferenceid=1298&quot;&gt;REGISTER HERE&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Tell all your friends :)&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/8095.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/7697.html</guid>
  <pubDate>Mon, 14 Nov 2005 14:44:00 GMT</pubDate>
  <title> IPS Bake-Off</title>
  <link>http://kungfuhacker.livejournal.com/7697.html</link>
  <description>Ed Skoudis &amp; Mike Poor if &lt;a href=&quot;http://www.intelguardians.com&quot;&gt;Intelguardians&lt;/a&gt; tested 5 Intrusion Prevention Systems, including how well they handled evasion techniques.  You may be surprised at the results...&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://informationsecurity.techtarget.com/&quot;&gt;http://informationsecurity.techtarget.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/7697.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/7309.html</guid>
  <pubDate>Sun, 13 Nov 2005 13:40:23 GMT</pubDate>
  <title>PaulotDotCom Security Weekly - Episode 2 - Nov 11, 2005</title>
  <link>http://kungfuhacker.livejournal.com/7309.html</link>
  <description>Our second episode has been released!  We&apos;ve got a whole new audio setup and sounding pretty better than ever (although that&apos;s not saying much).  Here are this weeks show notes/topics:&lt;br /&gt;&lt;br /&gt;- We beat the Sony DRM drum a few times because, well, we were the only ones who hadn&apos;t yet&lt;br /&gt;- You can get a list of CD&apos;s that have the rootkit &lt;a href=&quot;http://www.boingboing.net/2005/11/09/list_of_cds_infected.html&quot;&gt;HERE&lt;/a&gt;&lt;br /&gt;- We covered the MS05-053 exploit&lt;br /&gt;- Botnets that use HTTP/HTTPS, presentation &lt;a href=&quot;http://taosecurity.blogspot.com/2005/11/websense-toorcon-presentation-thanks.html&quot;&gt;HERE&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://ispots.mit.edu/&quot;&gt;Tracking MIT Students&lt;/a&gt;&lt;br /&gt;- Sniffing passwords and clear text protocols, from the excellent blog by &lt;a href=&quot;http://www.schneier.com/blog/archives/2005/11/sniffing_passwo.html&quot;&gt;Bruce Schneier&lt;/a&gt;&lt;br /&gt;- The overrated &lt;a href=&quot;http://www.securityfocus.com/columnists/368?ref=rss&quot;&gt;Linux Worm&lt;/a&gt;&lt;br /&gt;- Fun (and profit) with &lt;a href=&quot;http://www.rainbowcrack-online.com/&quot;&gt;Rainbow Tables&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hosts: &lt;a href=&quot;mailto:larry@pauldotcom.com&quot;&gt;Larry Pesce&lt;/a&gt;, &lt;a href=&quot;mailto:paul@pauldotcom.com&quot;&gt;Paul Asadoorian&lt;/a&gt;&lt;br /&gt;Sound: Andrew Veitch&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://hydrogen.oshean.org/pauldotcom-SW-episode2.mp3&quot;&gt;Direct Mp3 Download Link&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Special thanks to &lt;a href=&quot;http://www.oshean.org&quot;&gt;OSHEAN&lt;/a&gt; for providing the bandwidth.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt; &lt;a href=&quot;http://pauldotcom.com/podcast/psw.xml&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/xml.png&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt;&lt;/a&gt;  &lt;a href=&quot;http://www.odeo.com/channel/38062/view&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/badge-channel-black.gif&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt;&lt;/a&gt; &lt;a href=&quot;http://www.podnova.com/index_podnova_station.srf?url=http://pauldotcom.com/podcast/psw.xml&amp;amp;fkg=&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/podnova.gif&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://podcasts.yahoo.com/series?s=c611e99550618299a1022fa747055fe4&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/yahoo.gif&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt; &lt;img src=&quot;http://pauldotcom.com/images/itunes.gif&quot; border=&quot;0&quot; hspace=&quot;2&quot;&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/7309.html</comments>
  <category>security weekly</category>
  <lj:security>public</lj:security>
  <lj:reply-count>1</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/6918.html</guid>
  <pubDate>Wed, 09 Nov 2005 20:02:21 GMT</pubDate>
  <title>We&apos;re On iTunes!</title>
  <link>http://kungfuhacker.livejournal.com/6918.html</link>
  <description>We are proud to announce that PaulDotCom Security Weekly is now available via the iTunes music store:&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a href=&quot;http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687&quot;&gt; &lt;img src=&quot;http://pauldotcom.com/images/itunes.gif&quot;&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;You can get Episode 1 and the Marty Roesch interview.  We are planning to record Episode 2 this Friday and release it sometime this weekend.&lt;br /&gt;&lt;br /&gt;If you&apos;ve got comments/suggestions/topics please send them to us:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;mailto:paul@pauldotcom.com&quot;&gt;Paul Asadoorian&lt;/a&gt; &lt;br /&gt;&lt;a href=&quot;mailto:larry@pauldotcom.com&quot;&gt;Larry Pesce&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Stay tuned...&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/6918.html</comments>
  <category>security weekly</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/6853.html</guid>
  <pubDate>Tue, 08 Nov 2005 15:08:27 GMT</pubDate>
  <title>Oracle: Policies can protect passwords</title>
  <link>http://kungfuhacker.livejournal.com/6853.html</link>
  <description>&lt;em&gt;&quot;In response to criticism published by two researchers last week that the protection mechanism for Oracle database user passwords is weak, Oracle is reminding users to apply good password protection policies...&quot;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://news.com.com/2061-10789_3-5924051.html?part=rss&amp;tag=feed&amp;subj=news&quot;&gt;http://news.com.com/2061-10789_3-5924051.html?part=rss&amp;tag=feed&amp;subj=news&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;First off, even a strong password by most people&apos;s standards could be cracked within hours with the proper setup (and you wouldn&apos;t necessarily need a fast machine).  Second, table permissions only solve part of the problem as the password hash can be sniffed off the network.  Oracle needs to wake up...&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/6853.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/6624.html</guid>
  <pubDate>Tue, 08 Nov 2005 13:20:31 GMT</pubDate>
  <title>Spyware company believed to help bust botnet</title>
  <link>http://kungfuhacker.livejournal.com/6624.html</link>
  <description>What could their motivation be?  How about help me I&apos;m being DoS&apos;d:&lt;br /&gt;&lt;br /&gt;&quot;...180Solutions contacted the FBI after the botnet controllers launched a distributed denial-of-service (DDoS) attack against the company for terminating its distribution contract.&quot;&lt;br /&gt;&lt;br /&gt;Read the full article &lt;a href=&quot;http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1141163,00.html?track=sy160&quot;&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/6624.html</comments>
  <category>security</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/6237.html</guid>
  <pubDate>Mon, 07 Nov 2005 03:10:22 GMT</pubDate>
  <title>PaulDotCom Security Weekly - RSS Feed Update</title>
  <link>http://kungfuhacker.livejournal.com/6237.html</link>
  <description>We finally have an RSS feed for our podcast, the direct link is here:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://pauldotcom.com/podcast/psw.xml&quot;&gt;http://pauldotcom.com/podcast/psw.xml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We are also registered in iTunes (pending approval), and &lt;a href=&quot;http://www.odeo.com/channel/38062/view&quot;&gt;ODEO&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;.com&lt;br /&gt;&lt;br /&gt;&lt;center&gt; &lt;a href=&quot;http://pauldotcom.com/podcast/psw.xml&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/xml.png&quot;&gt;&lt;/a&gt;  &lt;a href=&quot;http://www.odeo.com/channel/38062/view&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/badge-channel-black.gif&quot;&gt;&lt;/a&gt; &lt;a href=&quot;http://www.podnova.com/index_podnova_station.srf?url=http://pauldotcom.com/podcast/psw.xml&amp;amp;fkg=&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/podnova.gif&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://podcasts.yahoo.com/series?s=c611e99550618299a1022fa747055fe4&quot;&gt;&lt;img src=&quot;http://pauldotcom.com/images/yahoo.gif&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687&quot;&gt; &lt;img src=&quot;http://pauldotcom.com/images/itunes.gif&quot;&gt;&lt;/center&gt;&lt;/a&gt;</description>
  <comments>http://kungfuhacker.livejournal.com/6237.html</comments>
  <category>security weekly</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/6061.html</guid>
  <pubDate>Sat, 05 Nov 2005 13:50:13 GMT</pubDate>
  <title>Unsecured Wi-Fi Would Be Outlawed By N.Y. County</title>
  <link>http://kungfuhacker.livejournal.com/6061.html</link>
  <description>&lt;em&gt;&quot;The draft proposal offered this week would compel all &quot;commercial businesses&quot; with an open wireless access point to have a &quot;network gateway server&quot; outfitted with a software or hardware firewall.&quot;&lt;br /&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Here&apos;s a tip, when making a law you should at least know what a firewall is and how it works.  This is a pretty ridiculous law, especially considering that most of the risks on wireless networks relate to unprotected clients and insecure wireless protocols, both of which have nothing to do with a &quot;network gateway server&quot;.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://news.zdnet.com/2100-1035_22-5934194.html&quot;&gt;http://news.zdnet.com/2100-1035_22-5934194.html&lt;/a&gt;</description>
  <comments>http://kungfuhacker.livejournal.com/6061.html</comments>
  <category>security</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/5755.html</guid>
  <pubDate>Fri, 04 Nov 2005 20:53:35 GMT</pubDate>
  <title>PaulDotCom Security Weekly - Special Edition - Marty Roesch Interview</title>
  <link>http://kungfuhacker.livejournal.com/5755.html</link>
  <description>We are proud to bring you our second podcast, an exclusive interview from &lt;a href=&quot;http://www.sans.org&quot;&gt;SANS&lt;/a&gt; 2005 in LA with Marty Roesch, creator of &lt;a href=&quot;http://www.snort.org&quot;&gt;Snort&lt;/a&gt;, an open-source intrusion detection system, and co-founder/CTO of &lt;a href=&quot;http://www.sourcefire.com&quot;&gt;Sourcefire&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://hydrogen.oshean.org/PSW-Special-Marty-Roesch.mp3&quot;&gt;Download It Here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Marty talks about:&lt;br /&gt;&lt;br /&gt;- The history of Snort&lt;br /&gt;- Recent Back Orifice buffer overflow&lt;br /&gt;- New and exciting technologies at Sourcefire&lt;br /&gt;- His love for Mac (which we share)&lt;br /&gt;&lt;br /&gt;(We apologize in advance for the poor audio quality, new equipment is on the way.  If you have suggestions or comments feel free to drop me a note, paul /at/ pauldotcom.com).&lt;br /&gt;&lt;br /&gt;Again, thanks to our sponsor &lt;a href=&quot;http://www.oshean.org&quot;&gt;OSHEAN&lt;/a&gt; for providing the bandwidth.&lt;br /&gt;&lt;br /&gt;&quot;Snort saved my bacon&quot;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/5755.html</comments>
  <category>security weekly</category>
  <lj:security>public</lj:security>
  <lj:reply-count>3</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/5544.html</guid>
  <pubDate>Fri, 04 Nov 2005 16:01:54 GMT</pubDate>
  <title>Mwcollect - Malware Collector</title>
  <link>http://kungfuhacker.livejournal.com/5544.html</link>
  <description>&quot;mwcollect is an easy solution to collect worms and other autonomous spreading malware in a non-native environment like FreeBSD or Linux. The first versions were used to collect binaries for botnet monitoring and bots are still what mwcollect is mostly used for collecting.&quot;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.securiteam.com/tools/6S0050AEKI.html&quot;&gt;http://www.securiteam.com/tools/6S0050AEKI.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is definitely a tool I want to try out...&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/5544.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/5257.html</guid>
  <pubDate>Fri, 04 Nov 2005 15:04:23 GMT</pubDate>
  <title>Suspected bot master busted</title>
  <link>http://kungfuhacker.livejournal.com/5257.html</link>
  <description>&quot; &quot;This is the first case to charge someone for using bots for generating profits,&quot; said James Aquilina, Assistant U.S. Attorney for the Central District of California and the prosecutor on the case. &quot;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.securityfocus.com/news/11353&quot;&gt;http://www.securityfocus.com/news/11353&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I believe this is a trend we are going to see continue as botnets become yet even more popular and evil.&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/5257.html</comments>
  <category>security</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/5026.html</guid>
  <pubDate>Thu, 03 Nov 2005 22:12:58 GMT</pubDate>
  <title>More pics from LA</title>
  <link>http://kungfuhacker.livejournal.com/5026.html</link>
  <description>Pics from PaulDotCom Security Weekly - Episode 1 (Which was sponsored by the wonderful folks at &lt;a href=&quot;http://www.coresecurity.com&quot;&gt;Core Security&lt;/a&gt;):&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://pauldotcom.com/PSW-Episode1/&quot;&gt;http://pauldotcom.com/PSW-Episode1/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;General pics from the trip:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://pauldotcom.com/SANSLA2/&quot;&gt;http://pauldotcom.com/SANSLA2/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/5026.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/4658.html</guid>
  <pubDate>Thu, 03 Nov 2005 21:47:46 GMT</pubDate>
  <title>Mwcollect - Malware Collector</title>
  <link>http://kungfuhacker.livejournal.com/4658.html</link>
  <description>&quot;mwcollect is an easy solution to collect worms and other autonomous spreading malware in a non-native environment like FreeBSD or Linux. The first versions were used to collect binaries for botnet monitoring...&quot;&lt;br /&gt;&lt;br /&gt;Sounds like a tool I need to play around with...&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.mwcollect.org/&quot;&gt;http://www.mwcollect.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/4658.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/4484.html</guid>
  <pubDate>Mon, 31 Oct 2005 22:24:52 GMT</pubDate>
  <title>SANS LA 2005 - Final Thoughts</title>
  <link>http://kungfuhacker.livejournal.com/4484.html</link>
  <description>Well the conference is over and I am back home now filled with all sorts of good information.  We spent the last day talking about PKI (try to contain your excitement).  My brain is fried, so I will post the rest of the pictures and video from the conference at a later date.&lt;br /&gt;&lt;br /&gt;One interesting note is that &lt;a href=&quot;http://www.ee.oulu.fi/research/ouspg/frontier/sota/whitepaper-wots/specs/draft-josefsson-pppext-eap-tls-eap-07.txt&quot;&gt;PEAPv2&lt;/a&gt; is in the works and allows for different inner authentication types.&lt;br /&gt;&lt;br /&gt;.com&lt;br /&gt;-</description>
  <comments>http://kungfuhacker.livejournal.com/4484.html</comments>
  <category>sans la 2005</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/4307.html</guid>
  <pubDate>Sat, 29 Oct 2005 15:59:40 GMT</pubDate>
  <title>MSN CAPTURE - MSN Messenger Packet Parser</title>
  <link>http://kungfuhacker.livejournal.com/4307.html</link>
  <description>This looks like a neat tool, however I can think of no legitimate purpose.  Although the sample conversation in the comments of the code is pretty funny.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.securiteam.com/tools/6Y00O1PEAE.html&quot;&gt;http://www.securiteam.com/tools/6Y00O1PEAE.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/4307.html</comments>
  <category>security</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/4035.html</guid>
  <pubDate>Sat, 29 Oct 2005 14:20:42 GMT</pubDate>
  <title>SANS LA Day 5</title>
  <link>http://kungfuhacker.livejournal.com/4035.html</link>
  <description>Josh&apos;s class was pretty cool yesterday.  We got to the section on how to get around VPN protected wireless networks, here are a couple of the tools:&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.foundstone.com/resources/freetooldownload.htm?file=superscan4.zip&quot;&gt;Superscan 4&lt;/a&gt; - This updated free tool from Foundstone will let you enumerate registry entries over &lt;a href=&quot;http://www.brown.edu/Facilities/CIS/CIRT/help/netbiosnull.html&quot;&gt;NULL Sessions&lt;/a&gt;. &lt;br /&gt;- &lt;a href=&quot;http://nstx.dereference.de/nstx/&quot;&gt;nstx&lt;/a&gt; - Makes it possible to tunnel IP traffic in DNS queries using recursive lookups and the TXT record type.&lt;br /&gt;&lt;br /&gt;Also:&lt;br /&gt;&lt;br /&gt;- We also learned that &lt;a href=&quot;http://asleap.sourceforge.net/&quot;&gt;Asleap&lt;/a&gt; can crack PPTP passwords too.&lt;br /&gt;&lt;br /&gt;We got a chance to get to Little Tokyo last night.  Had some good sushi and other Japanese dishes.  We also found that Little Tokyo was in a a not-so-good part of town and were approached by panhandlers and other shady people (not before I got a ninja t-shirt though!).&lt;br /&gt;&lt;br /&gt;More pictures coming soon...&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/4035.html</comments>
  <category>sans la 2005</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/3695.html</guid>
  <pubDate>Fri, 28 Oct 2005 14:40:59 GMT</pubDate>
  <title>SANS LA Day 3 &amp; 4</title>
  <link>http://kungfuhacker.livejournal.com/3695.html</link>
  <description>I cannot even begin to describe just how much good stuff they have packed into this conference.  We&apos;ve been non-stop since we got here, here are the highlights from the past two days:&lt;br /&gt;&lt;br /&gt;- We did some mapping of the LA area and generated some maps.  You can find them &lt;a href=&quot;http://www.pauldotcom.com/lawarwalk1.png&quot;&gt;here&lt;/a&gt; and &lt;a href=&quot;http://www.pauldotcom.com/lawarwalk-wep.png&quot;&gt;here&lt;/a&gt;.  The &lt;a href=&quot;http://www.pauldotcom.com/lawarwalk-wep.png&quot;&gt;second one&lt;/a&gt; is interesting, green represents WEP, red represents default configuration with no WEP, and blue is open.&lt;br /&gt;&lt;br /&gt;- We also took some &lt;a href=&quot;http://www.pauldotcom.com/SANSLA-1/&quot;&gt;pictures&lt;/a&gt;.  I like &lt;a href=&quot;http://www.pauldotcom.com/SANSLA-1/SANSLA-1-Pages/Image15.html&quot;&gt;this one&lt;/a&gt; the best, you can correlate it with some of our maps if you look close. &lt;br /&gt;&lt;br /&gt;- Our homework from class yesterday was to find three rogue access points that were hidden inside the hotel.  This is challenge considering we find it difficult to find our rooms (even when we haven&apos;t been drinking).  We found one, then decided to eat.&lt;br /&gt;&lt;br /&gt;- Ed Skoudis of &lt;a href=&quot;http://www.intelguardians.com/&quot;&gt;Intelguardians&lt;/a&gt; gave a fantastic talk on hacking for fun and profit.  It seems that hacking is a big business now (you can get $500 per hour, per 100 thousands nodes rent for your botnet).  Scary stuff, heck why buy or build yourself when you can just rent.&lt;br /&gt;&lt;br /&gt;Stay tuned....&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/3695.html</comments>
  <category>sans la 2005</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/3485.html</guid>
  <pubDate>Thu, 27 Oct 2005 16:38:25 GMT</pubDate>
  <title>PaulDotCom Security Weekly - Episode 1</title>
  <link>http://kungfuhacker.livejournal.com/3485.html</link>
  <description>We recorded the first episode of &quot;&lt;a href=&quot;http://hydrogen.oshean.org/pauldotcom-SW-episode1.mp3&quot;&gt;PaulDotCom Security Weekly&lt;/a&gt;&quot;, our new podcast.   It was recorded last night at SANS LA and we talked about:&lt;br /&gt;&lt;br /&gt;- Oracle Password vulnerabilities&lt;br /&gt;- Nokia smartphone worms&lt;br /&gt;- Botnets&lt;br /&gt;- FBI Romanian hacking case&lt;br /&gt;- Terrorism and improvised explosives&lt;br /&gt;- And much more!&lt;br /&gt;&lt;br /&gt;This episode was sponsored by &lt;a href=&quot;http://www.coresecurity.com&quot;&gt;Core Security&lt;/a&gt; - an outstanding penetration testing tool.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://hydrogen.oshean.org/pauldotcom-SW-episode1.mp3&quot;&gt;Download it here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I promise future episodes will have show notes and be available via iTunes and other podcast sources.  Bear with us as we put it all together :)&lt;br /&gt;&lt;br /&gt;(Thanks to our other sponsor, &lt;a href=&quot;http://www.oshean.org&quot;&gt;OSHEAN&lt;/a&gt;, for providing the bandwidth)&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/3485.html</comments>
  <category>security weekly</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/3115.html</guid>
  <pubDate>Thu, 27 Oct 2005 16:14:37 GMT</pubDate>
  <title>Assessment of  Oracle Password Hashing Algorithm</title>
  <link>http://kungfuhacker.livejournal.com/3115.html</link>
  <description>This paper discussing several weaknesses in Oracle&apos;s password hashing algorithm as presented by Joshua Wright.  Reminds me of LANMAN....&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.sans.org/rr/special/index.php?id=oracle_pass&quot;&gt;Download the paper here&lt;/a&gt;&amp;nbsp;|&amp;nbsp;&lt;a href=&quot;http://digg.com/security/Assessment_of_Oracle_Password_Hashing_Algorithm&quot;&gt;digg story&lt;/a&gt;</description>
  <comments>http://kungfuhacker.livejournal.com/3115.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/2821.html</guid>
  <pubDate>Wed, 26 Oct 2005 15:07:17 GMT</pubDate>
  <title>SANS LA Day 2</title>
  <link>http://kungfuhacker.livejournal.com/2821.html</link>
  <description>Well Day 2 is behind is us now and as usual we can feel our brains getting full.  I spent the day learning about how wireless networks operate at layer 1 (which involves a little bit of physics, math, and RF engineering).  Interesting stuff!&lt;br /&gt;&lt;br /&gt;The 802.11n standard is going to be pretty cool, its based on 802.11a but will provide speeds of 100mb/s.  Its going to be a while, considering that they had to vote on how to pronounce MIMO (&quot;My-Moe&quot;).  I wonder how long that took!&lt;br /&gt;&lt;br /&gt;Oh, and make certain that everyone goes and gets the FCC&apos;s &lt;a href=&quot;http://www.ntia.doc.gov/osmhome/allochrt.pdf&quot;&gt;frequency allocation chart&lt;/a&gt;.  &lt;br /&gt;&lt;br /&gt;We then sat in on a talk titled &quot;Terrorism and the use of improvised explosives&quot;.  It was a nice diversion from the technical stuff, gave us some insight on the groups and their motivations.  We actually had a few drinks with the presenter, ex-FBI agent, really cool guy.  Shed some light on things like how three-letter-government agencies changed after Sept. 11th, how FBI agents go through airport security fully armed (I was always curious about that), and gave me a web site to visit to provide more information on terrorist groups, &lt;a href=&quot;http://www.mipt.org/&quot;&gt;www.mipt.org&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I have more juicy stuff, but can&apos;t talk about it (otherwise those black suburbans will come pick me up), but I will have more information about some cutting edge wireless hacking tools that have not yet been released, and of course some pictures!  &lt;br /&gt;&lt;br /&gt;I think we are going to record our first podcast tonight from the revolving bar on the top floor of the hotel.  More to come!&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/2821.html</comments>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/2753.html</guid>
  <pubDate>Tue, 25 Oct 2005 15:20:22 GMT</pubDate>
  <title>3 DVDs for $12 shipped</title>
  <link>http://kungfuhacker.livejournal.com/2753.html</link>
  <description>A really good DVD deal, few Kung Fu Movies thrown in there too, such as:&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.deepdiscountdvd.com/dvd.cfm?itemid=BVD025132&quot;&gt;Iron Monkey&lt;/a&gt;&lt;br /&gt;- Jackie Chan&apos;s &lt;a href=&quot;http://www.deepdiscountdvd.com/dvd.cfm?itemid=BVD035230&quot;&gt;Dragon Lord&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.deepdiscountdvd.com/dvd.cfm?itemid=BVD031486&quot;&gt;China Strike Force&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And more!&lt;br /&gt;&lt;br /&gt;Okay, off to class now...&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.slickdeals.net/#p6639&quot;&gt;http://www.slickdeals.net/#p6639&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/2753.html</comments>
  <category>kung fu</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/2520.html</guid>
  <pubDate>Tue, 25 Oct 2005 03:36:13 GMT</pubDate>
  <title>SANS LA DAY 1 - Botnets</title>
  <link>http://kungfuhacker.livejournal.com/2520.html</link>
  <description>It was a fun day with Mike Poor learning about botnets.  We learned about an awesome tool for analyzing sessions in a tcpdump capture file called &lt;a href=&quot;http://chaosreader.sourceforge.net/&quot;&gt;chaosreader&lt;/a&gt;.  Also found a cool wen site that will convert stuff (like ASCII to base64, etc...) call &lt;a href=&quot;http://www.snarkles.net/scripts/sneak/sneak.php&quot;&gt;Snarkles&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Mike is the man, he really liked our idea for creating a RI Internet Storm Center, and I&apos;ve actually got some more ideas for this project, so stay tuned.&lt;br /&gt;&lt;br /&gt;We also decided that our podcast will be completely independent of any organization, which means we get to the set the content, topics, format, and basically talk about whatever we want.  We are actively drinking and trying to find a name for the podcast, but decided that we would keep the format to IT security.  We have guests lined up and plan to do our first episode this week.&lt;br /&gt;&lt;br /&gt;$1.95 burgers and nachos at &lt;a href=&quot;http://www.mccormickandschmicks.com/&quot;&gt;McCormick &amp; Schmick&apos;s&lt;/a&gt; were awesome.&lt;br /&gt;&lt;br /&gt;Off to go hack something (that won&apos;t land me in an orange jumpsuit, because well, orange isn&apos;t my color).&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/2520.html</comments>
  <category>sans la 2005</category>
  <lj:security>public</lj:security>
  <lj:reply-count>1</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/2226.html</guid>
  <pubDate>Mon, 24 Oct 2005 13:44:38 GMT</pubDate>
  <title>SANS LA - Day 0</title>
  <link>http://kungfuhacker.livejournal.com/2226.html</link>
  <description>We have landed!  our flights out were actually trouble free and quite pleasant.  I watched two Kung Fu movies on the way out,&lt;a href=&quot;http://www.kungfucinema.com/reviews/shaolintempleagainstlama.htm&quot;&gt; Shaolin Against Lama&lt;/a&gt; and &lt;a href=&quot;http://monsterhunter.coldfusionvideo.com/Screaming_Tiger.html&quot;&gt;Screaming Tiger&lt;/a&gt;.  &lt;a href=&quot;http://www.kungfucinema.com/reviews/shaolintempleagainstlama.htm&quot;&gt;Shaolin Against Lama&lt;/a&gt; was by far the better flick, some awesome action and good choreography.  Jimmy Wang Yu was a little disappointing in Screaming Tiger, until the end fight scene that involves throwing people from trains and fighting in the river with a waterfall (reminded me of Kung Pow: Enter the fist, of rather the original movie that was based called &lt;a href=&quot;http://www.hkflix.com/xq/asp/filmID.533883/qx/details.htm&quot;&gt;Savage Killers (AKA Tiger and Crane Fists)&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The hotel, the &lt;a href=&quot;http://www.starwoodhotels.com/westin/search/hotel_detail.html?propertyID=1004&amp;amp;EM=aa_Google_westin_bonaventure_122104&quot;&gt;Westin Bonaventure&lt;/a&gt;, is really nice.  Its the same one that they filmed True Lies at (I&apos;m waiting to see Arnold hanging out one of the glass elevators any minute now).  Our cab driver was cool too, he was Armenian (so am I :).&lt;br /&gt;&lt;br /&gt;We checked out the revolving bar (it spins on its own), which was really cool.  Gotta go now and get ready to learn about botnets....&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/2226.html</comments>
  <category>sans la 2005</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
<item>
  <guid isPermaLink='true'>http://kungfuhacker.livejournal.com/2027.html</guid>
  <pubDate>Sun, 23 Oct 2005 15:20:09 GMT</pubDate>
  <title>Podcasts I listen to</title>
  <link>http://kungfuhacker.livejournal.com/2027.html</link>
  <description>Many people ask me which podcasts I have been listening to, so here it goes:&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.twit.tv/&quot;&gt;TWIT&lt;/a&gt; (This Week In Tech) - All the old screensavers crew does a weekly podcast about geek stuff.&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://revision3.com/diggnation&quot;&gt;Diggnation&lt;/a&gt; - Kevin and Alex rock.  Weekly commentary on the social bookmarking site digg.com (See my diggs here).&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.grc.com/securitynow.htm&quot;&gt;Security Now!&lt;/a&gt; - Steve Gibson and Leo Laporte talk about secuirty topics.  Ironically this weeks episode is about wireless security. Heh.&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://leoville.tv/radio/pmwiki.php&quot;&gt;KFI&apos;s Tech Guy&lt;/a&gt; - Another Leo Laporte podcast, good stuff.&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.chinesepod.com/&quot;&gt;Learning Chinese&lt;/a&gt; - A very cool take on learning Chinese, phrases you can use.  Kinda fun (And funny).&lt;br /&gt;&lt;br /&gt;I also have all of the &lt;a href=&quot;http://digitallifetv.com/blogs/digitallifetv/default.aspx&quot;&gt;Digital Life&lt;/a&gt; podcasts from Patrick Norton, but haven&apos;t listened to them yet.&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;br /&gt;.com</description>
  <comments>http://kungfuhacker.livejournal.com/2027.html</comments>
  <category>geek stuff</category>
  <lj:security>public</lj:security>
  <lj:reply-count>0</lj:reply-count>
</item>
</channel>
</rss>
