<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecuriTeam Blogs &#187; noam</title>
	<atom:link href="http://blogs.securiteam.com/index.php/archives/author/noam/feed" rel="self" type="application/rss+xml" />
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<lastBuildDate>Tue, 15 May 2012 05:11:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Hacktivity 2012 CFP</title>
		<link>http://blogs.securiteam.com/index.php/archives/1711</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1711#comments</comments>
		<pubDate>Tue, 15 May 2012 05:11:30 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=1711</guid>
		<description><![CDATA[Hacktivity 2012 Call For Papers: Deadline June 1st The 9th annual IT Security Festival for Central and Eastern Europe will be held in Hungary in late September. The Hacktivity 2012 conference/festival will bring together information security professionals from all of central Europe in an informal, educational, but highly technical form. Papers for HACKTIVITY 2012 are [...]]]></description>
			<content:encoded><![CDATA[<p>Hacktivity 2012 Call For Papers: Deadline June 1st</p>
<p>The 9th annual IT Security Festival for Central and Eastern Europe will be held in Hungary in late September. The Hacktivity 2012 conference/festival will bring together information security professionals from all of central Europe in an informal, educational, but highly technical form.</p>
<p>Papers for HACKTIVITY 2012 are now being solicited and we invite you to participate.</p>
<p>For more information see: <a href="https://hacktivity.com/en/news/cfp-is-out-hurry-up/">https://hacktivity.com/en/news/cfp-is-out-hurry-up/  </a></p>
<p>For a list of the 36 presentations done in 2011 see: <a href="https://hacktivity.com/en/hacktivity-2011/programs/">https://hacktivity.com/en/hacktivity-2011/programs/</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1711&amp;title=Hacktivity%202012%20CFP" id="wpa2a_2"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1711/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NOPCON 2012</title>
		<link>http://blogs.securiteam.com/index.php/archives/1698</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1698#comments</comments>
		<pubDate>Thu, 10 May 2012 12:48:09 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/?p=1698</guid>
		<description><![CDATA[NOPcon is a non-profit and free hacker conference which will be held in Istanbul, TURKEY on the 21 May. The conference will be the first technical and international hacker conference in Istanbul. The conference aims to learn and exchange ideas and experiences between researchers , consultants and developers. SPEAKERS Moti Joseph &#8211; &#8220;Advanced Browser Exploiting&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>NOPcon is a non-profit and free hacker conference which will be held in Istanbul, TURKEY on the 21 May.<br />
The conference will be the first technical and international hacker conference in Istanbul. The conference aims to learn and exchange ideas and experiences between researchers , consultants and developers.</p>
<p><strong>SPEAKERS</strong><br />
Moti Joseph &#8211; &#8220;Advanced Browser Exploiting&#8221;<br />
Mohhammad Hluchan &#8211; &#8220;Militarization of Hacking and the New Cyber Arms Race in the Middle East&#8221;<br />
Sertan Kolat &#8211; &#8220;Attacking iOS Applications&#8221;<br />
Yasin Surer &#8211;  &#8220;Kernel Exploiting&#8221;<br />
Mert Sarica &#8211; &#8220;Attacking Android Applications&#8221;<br />
Nebi Senol Yilmaz &#8211; &#8220;Defeating DDOS in FreeBSD Kernel&#8221;<br />
Melih Tas &#8211; &#8220;Penetration Testing VOIP&#8221;<br />
Ozan Ucar &#8211; &#8220;Real-world Penetration Testing Examples [Workshop]&#8221;<br />
Evren Yalcin &#8211; &#8220;Advanced Web Application Security [Workshop]&#8221;<br />
Celil Unuver  &#8211; &#8220;SCADA (in)Security&#8221;</p>
<p><strong>Registration</strong><br />
Registration for the conference can be made at free: <a href="http://www.nopcon.org/register/">http://www.nopcon.org/register/</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1698&amp;title=NOPCON%202012" id="wpa2a_4"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1698/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XSSQL attack (HTML5)</title>
		<link>http://blogs.securiteam.com/index.php/archives/1524</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1524#comments</comments>
		<pubDate>Mon, 11 Jul 2011 07:36:53 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1524</guid>
		<description><![CDATA[HTML 5 brings a lot of new features to the web. One of its features is SQLite &#8211; a client side database engine which allows storage of data on the client side. Databases can be created and queried by the JavaScript. It is pretty clear that many developers would use the opportunity to store information [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>HTML 5 brings a lot of new features to the web. One of its features is SQLite &#8211; a client side database engine which allows storage of data on the client side. Databases can be created and queried by the JavaScript.</p>
<p>It is pretty clear that many developers would use the opportunity to store information on the client side. The risk will be high if they use this repository and store there sensitive information such us user passwords, session ids, credit card numbers etc.</p>
<p>In case of XSS vulnerability in such website it would be possible to query these databases via JavaScript.<br />
I even have a name for this attack &#8211; XSSQL <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  funny as well as concerning &#8230;</p>
<p>Eventually, XSS attacks still remain common and even more powerful with the ability to query client side databases and steal sensitive information.</p></blockquote>
<p>See more details at <a href="http://yossi-yakubov.blogspot.com/2011/07/html-5-xssql.html">http://yossi-yakubov.blogspot.com/2011/07/html-5-xssql.html</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1524&amp;title=XSSQL%20attack%20%28HTML5%29" id="wpa2a_6"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1524/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BlackHat 2011 USA</title>
		<link>http://blogs.securiteam.com/index.php/archives/1523</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1523#comments</comments>
		<pubDate>Tue, 28 Jun 2011 16:33:00 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1523</guid>
		<description><![CDATA[I wanted to congratulate Ivan and Nicolas our winners of the SecuriTeam Secure Disclosure free entry and travel expenses to BlackHat Briefings 2011 (USA). I hope to see the rest of our researchers there, I will be posting more details on our drink-o-party that is scheduled to occur during those two days. Follow my twitter [...]]]></description>
			<content:encoded><![CDATA[<p>I wanted to congratulate Ivan and Nicolas our winners of the <a href="http://www.beyondsecurity.com/ssd.html">SecuriTeam Secure Disclosure</a> free entry and travel expenses to BlackHat Briefings 2011 (USA).</p>
<p>I hope to see the rest of our researchers there, I will be posting more details on our drink-o-party that is scheduled to occur during those two days.</p>
<p>Follow my twitter @nrathaus, or email me at noamr[]beyondsecurity@com for more details.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1523&amp;title=BlackHat%202011%20USA" id="wpa2a_8"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1523/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CONfidence 2011 Wrapup</title>
		<link>http://blogs.securiteam.com/index.php/archives/1517</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1517#comments</comments>
		<pubDate>Fri, 27 May 2011 09:20:23 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1517</guid>
		<description><![CDATA[As always it was a pleasure to go to CONfidence, the atmosphere in this event is unique and has a very un-commercial feel to it. It started off with Lock Picking presentation by Deviant Ollam, which quite convincingly proved that your weakest point is physical security, and then gave everyone a run for their money [...]]]></description>
			<content:encoded><![CDATA[<p>As always it was a pleasure to go to CONfidence, the atmosphere in this event is unique and has a very un-commercial feel to it.</p>
<p>It started off with Lock Picking presentation by Deviant Ollam, which quite convincingly proved that your weakest point is physical security, and then gave everyone a run for their money with offering locks and lock picking tools to give people the feel of how easy (or in some cases not that difficult) it is to pick a lock &#8211; especially if it just looks tough but is actually a cheap knockoff.</p>
<p>The day then split to two distinctive tracks, I picked the Stuxnet one and learn less on that but more on cybercrime, cyberwarfare and how the United Nations Interregional Crime and Justice Research Institute is handling / looking out on that. Bottom line, a lot to do, little being done now and things are still shaking on the legal and control part of it &#8211; with many countries doing it and little threat of &#8220;political&#8221; issues for them.</p>
<p>After the launch break I got to hear a lecture about Gadu-Gadu vulnerabilities, unfortunately I did not catch the guy&#8217;s name so I cannot tell you what it is, but his lecture proved that XSS can be more than just a web site hack with Gadu-Gadu having XSS issues that would allow the execution of code. According to him, the vulnerabilities have been reported but discarded by the vendor as a non-threat, well no one in the audience felt that was a shocker.</p>
<p>Sitting on Mario Heiderich&#8217;s lecture proved to me once again that XSS is an endless mine of goodies, with SVG now becoming more and more acceptable, and having been built without much security in mind &#8211; SVG is the new XSS goldmine. So many issues, so little time to present them, should be Mario&#8217;s trademark <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I didn&#8217;t have the time to sit on any other lectures during that day, so I will skip to day 2</p>
<p>Chris Valasek&#8217;s heap spraying and analysis proved once again that he should be dubbed the Heap Spray King with a new method to cause the apparently unexploitable hole in IIS FTP&#8217;s server to become exploitable by using ground breaking research of how to cause fragmentation and reassembly of heap blocks to allow in the end for the EIP to be under our control &#8211; with the promise to release the exploit &#8211; more to come from this great guy.</p>
<p>Alexey Sintsov showed us that even the most small and simple &#8220;holes&#8221; such as allowing to resolve hostnames on a compromised host can be easily turned to a full fledged remote controlling mechanism, though not new, the way it was presented showed that it is not just theoretical but actually quite easily made into practice.</p>
<p>Michele Orru presented his <a href="http://code.google.com/p/beef/">BeEF</a> &#8211; Browser Exploitation Framework &#8211; and the ability to &#8211; once you have compromised a host by getting him to visit your website &#8211; control a remote browser and get it to do what you want. In his demo he compromised a host that had access to a vulnerable JBoss server and using the browser got the JBoss to reverse open a shell on the server &#8211; effectively gaining him root access &#8211; nice!</p>
<p>Aleksandr Matrosov, Eugene Rodionov showed how x64 operating systems are getting compromised by TDL rootkits and how they have researched cleanup methods &#8211; and successfully done so. Apparently the method of used by the TDL rootkit is going back to infecting your MBR &#8211; remember those methods? feels like a time warp.</p>
<p>Michał Sajdak proved that lack of security can even happen to security aware companies like CISCO or to their bought of companies Linksys &#8211; using simple methods of command injection (such as ;/bin/ls) he was able to completely compromise a CISCO device. A simple web scan of that application would have discovered this vulnerability &#8211; I cannot say why that product came to market with such an obvious vulnerability.</p>
<p>At that point again, I had to leave the conference.</p>
<p>It was great, see you next year.</p>
<p>Things I saw that were weird and cool at the same time:<br />
1) The CONFidence treasure hunt was wacky, with tasks such as bring a nude stripper to gain points or have a tattoo of a sailor on your arm for double points<br />
2) Wii and PS3 stations proved once again to be packed with hackers showing their skills<br />
3) Barbecue and beer idea was a hit<br />
4) Giving speakers a free beer as a drink on stage was weird but a good idea on how to release pressure from the speaker</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1517&amp;title=CONfidence%202011%20Wrapup" id="wpa2a_10"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1517/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kindle Book Sharing</title>
		<link>http://blogs.securiteam.com/index.php/archives/1511</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1511#comments</comments>
		<pubDate>Mon, 02 May 2011 01:45:38 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1511</guid>
		<description><![CDATA[This post won&#8217;t be about security, but still something that is worth mentioning. If you want to share your Kindle content with your colleague? you can either loan it to him (but then he has two weeks to finish the book!) or you can just swap Kindles (devices) after deregistering them both, and reregistering them [...]]]></description>
			<content:encoded><![CDATA[<p>This post won&#8217;t be about security, but still something that is worth mentioning.</p>
<p>If you want to share your Kindle content with your colleague? you can either loan it to him (but then he has two weeks to finish the book!) or you can just swap Kindles (devices) after deregistering them both, and reregistering them both, remember to put everything outside your Collections or they will get &#8220;lost&#8221; in the swapping.</p>
<p>I just tried it with a work colleague and it worked great!</p>
<p>Enjoy!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1511&amp;title=Kindle%20Book%20Sharing" id="wpa2a_12"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1511/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DD-WRT Fuzzing and Monitoring</title>
		<link>http://blogs.securiteam.com/index.php/archives/1494</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1494#comments</comments>
		<pubDate>Tue, 15 Mar 2011 22:12:50 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1494</guid>
		<description><![CDATA[We recently got a request for a vendor who has taken upon itself to add some interesting stuff to the DD-WRT router to provide him with some form of monitoring that would integrate with our beSTORM fuzzer. Regular monitoring inherently built into beSTORM which include ARP, ICMP Echo, UDP/TCP Ping and remote debugging weren&#8217;t quite [...]]]></description>
			<content:encoded><![CDATA[<p>We recently got a request for a vendor who has taken upon itself to add some interesting stuff to the DD-WRT router to provide him with some form of monitoring that would integrate with our beSTORM fuzzer.</p>
<p>Regular monitoring inherently built into beSTORM which include ARP, ICMP Echo, UDP/TCP Ping and remote debugging weren&#8217;t quite up to it &#8211; ARP, ICMP Echo and UDP/TCP ping could not tell the vendor when the router was expecting heavy load due to our test which was one of the criteria he has defined inside beSTORM as being an exception (a vulnerability).</p>
<p>Our typical backup option is a gdb-style remote debugger, but the DD-WRT&#8217;s debugger doesn&#8217;t easily provide that information, therefore we have built a simple monitoring agent that can connect to the DD-WRT web interface and query the load value of the router. When a certain value (above a certain number) is reached an exception is reported back to beSTORM.</p>
<p>This little neat trick allowed the vendor to identify several strange packets that can cause his modified router to become unresponsive (take more than a few seconds to respond), as well as detect when the router was responsive but the load on it was unusually high.</p>
<p>The script is now bundled with the full version of beSTORM, feel free to get the latest version and look into it. A trial is always available <a title="beSTORM Trial" href="http://www.beyondsecurity.com/bestorm-trial.html">here</a>. It&#8217;s also available below:</p>
<blockquote>
<p align="left">
#!/usr/bin/perl<br />
# Copyright Beyond Security 2011<br />
# beSTORM support: support@beyondsecurity.com</p>
<p>use strict;<br />
use Getopt::Long;<br />
use LWP::UserAgent;<br />
use IO::Socket;</p>
<p>my @children;<br />
my $beSTORM_port = &#8220;6969&#8243;;<br />
my $beSTORM_ip = &#8220;192.168.1.2&#8243;;<br />
my $router_ip = &#8220;192.168.1.1&#8243;;<br />
my $router_username = &#8220;root&#8221;;<br />
my $router_password = &#8220;admin&#8221;;</p>
<p>my $pingTimeout = 1;	#ping every x seconds<br />
my $bContinue = 1;      #Stay in loop.</p>
<p>#Install signal handlers<br />
$SIG{ABRT} = \&signaled;<br />
$SIG{INT} = \&signaled;<br />
$SIG{HUP} = \&signaled;</p>
<p>my $options = { };<br />
GetOptions(<br />
 &#8216;host=s&#8217; => \$options->{&#8216;bH&#8217;},<br />
 &#8216;port=i&#8217; => \$options->{&#8216;bP&#8217;},<br />
 &#8220;router=s&#8221; => \$options->{&#8216;rH&#8217;},<br />
 &#8220;username=s&#8221; => \$options->{&#8216;rU&#8217;},<br />
 &#8220;password=s&#8221; => \$options->{&#8216;rP&#8217;},<br />
 );</p>
<p>#Sanity check<br />
my $bPrintUsage = 0;<br />
if (! $options->{&#8216;bH&#8217;} ) {<br />
 $bPrintUsage = 1;<br />
 print &#8220;No host value has been provided\n&#8221;;<br />
}<br />
if (! $options->{&#8216;rH&#8217;} ) {<br />
 $bPrintUsage = 1;<br />
 print &#8220;No router value has been provided\n&#8221;;<br />
}</p>
<p>if ($bPrintUsage) {<br />
 usage();<br />
 exit 0;<br />
}</p>
<p>$beSTORM_ip = $options->{&#8216;bH&#8217;};<br />
$beSTORM_port = $options->{&#8216;bP&#8217;};<br />
if (not defined $beSTORM_port) {<br />
 $beSTORM_port = 6969;<br />
}</p>
<p>$router_ip = $options->{&#8216;rH&#8217;};<br />
$router_username = $options->{&#8216;rU&#8217;};<br />
if (not defined $router_username) {<br />
 $router_username = &#8220;root&#8221;;<br />
}</p>
<p>$router_password = $options->{&#8216;rP&#8217;};<br />
if (not defined $router_password) {<br />
 $router_password = &#8220;admin&#8221;;<br />
}</p>
<p>while ($bContinue) {<br />
 my $ua = LWP::UserAgent->new;<br />
 $ua->timeout(2);</p>
<p> my $URL = &#8220;http://$router_username:$router_password\@$router_ip&#8221; . &#8220;/Status_Router.live.asp&#8221;;<br />
 print &#8220;Connecting to: $URL\n&#8221;;<br />
 my $response = $ua->get($URL);</p>
<p> my $content = &#8220;&#8221;;<br />
 if ($response->is_success) {<br />
  $content = $response->decoded_content;  # or whatever<br />
 }<br />
 else {<br />
  send_notification($beSTORM_ip, $beSTORM_port, &#8220;Failed to receive response from router&#8217;s web server: &#8220;.$response->status_line);<br />
 }</p>
<p> my $load = &#8220;&#8221;;<br />
 if($content =~ /, load average: ([^}]+)\}/gs) {<br />
  $load = $1;<br />
 } else {<br />
  print &#8220;Failed to find load average inside content: [$content]\n&#8221;;<br />
  send_notification($beSTORM_ip, $beSTORM_port, &#8220;Failed to locate load average value&#8221;);<br />
 }</p>
<p> print &#8220;$load\n&#8221;;<br />
 sleep(1);<br />
}</p>
<p>###<br />
#<br />
sub send_notification {<br />
 my $Host = shift;<br />
 my $Port = shift;<br />
 my $Exception = shift;<br />
 print STDERR &#8220;\n\nSending to $Host:$Port this exception: [$Exception]\n\n\n&#8221;;</p>
<p> my $sock = IO::Socket::INET->new(<br />
    Proto    => &#8216;udp&#8217;,<br />
    PeerPort => $Port,<br />
    PeerAddr => $Host,<br />
 ) or die &#8220;Could not create socket: $!\n&#8221;;</p>
<p> print STDERR &#8220;Exception: [$Exception]\n&#8221;;<br />
 $sock->send($Exception) or die &#8220;Send error: $!\n&#8221;;</p>
<p> $bContinue = 0;<br />
}</p>
<p>sub usage<br />
{<br />
 print &#8220;\nUsage: $0 &#8211;host <host> [--port
<port>] &#8211;router <router>\n\n&#8221;;<br />
 print &#8220;\t&#8211;host beSTORM client host\n&#8221;;<br />
 print &#8220;\t&#8211;port beSTORM client UDP port for exception information (default 6969)\n&#8221;;<br />
 print &#8220;\t&#8211;router the Router being monitored\n&#8221;;<br />
 print &#8220;\t&#8211;username used by the router to authenticate (root)\n&#8221;;<br />
 print &#8220;\t&#8211;password used by the router to authenticate (admin)\n&#8221;;<br />
}</p>
<p>#Ping beSTORM host that we are alive every $timeout<br />
sub start_notifier<br />
{<br />
 my $timeout = shift;<br />
 if (! defined $beSTORM_ip) {return; };</p>
<p> my $pid= fork();<br />
 if ($pid < 0)<br />
 {<br />
  die "Could not fork\n";<br />
 }<br />
 if ($pid > 0)<br />
 {<br />
  push @children, $pid;<br />
 }<br />
 #Child<br />
 if ($pid == 0)<br />
 {<br />
  print &#8220;Starting beSTORM notifier. Will send heartbeat to $beSTORM_ip every $timeout second(s)\n&#8221;;<br />
  while ($bContinue)<br />
  {<br />
   my $sock = IO::Socket::INET->new(Proto    => &#8216;udp&#8217;,<br />
                                    PeerAddr => $beSTORM_ip,<br />
                                    PeerPort => &#8217;6970&#8242;,<br />
                                    Type     => SOCK_DGRAM,<br />
                                   ) or die &#8220;socket: $@&#8221;;<br />
   print $sock &#8220;NOOP&#8221;;<br />
   close $sock;<br />
   sleep($timeout);<br />
  }<br />
  print &#8220;beSTORM notifier Stopped\n&#8221;;<br />
  exit 0;<br />
 }<br />
}</p>
<p>sub stop_notifier<br />
{<br />
 my $sig = shift;<br />
 print &#8220;Shutting down beSTORM notifier (it may take up to 5 seconds to stop)\n&#8221;;<br />
 if (@children)<br />
 {<br />
  print &#8220;Signaling: (@children) with sig $sig\n&#8221;;<br />
  kill $sig, @children;<br />
 }<br />
}</p>
<p>sub signaled<br />
{<br />
 my $sig = shift;<br />
 print &#8220;Recieved signal $sig. Shutting down\n&#8221;;<br />
 stop_notifier($sig);<br />
 $bContinue = 0;<br />
}</p>
<p>#The end<br />
</router></port></host></p>
</blockquote>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1494&amp;title=DD-WRT%20Fuzzing%20and%20Monitoring" id="wpa2a_14"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1494/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CanSecWest, chrome 0-days, breaking the Blackberry fortress</title>
		<link>http://blogs.securiteam.com/index.php/archives/1489</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1489#comments</comments>
		<pubDate>Sat, 12 Mar 2011 18:43:35 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1489</guid>
		<description><![CDATA[CanSecWest was fun, met a lot of people researchers, consultants and customers. Lot of them came to hear good quality lectures and I believe they have found them. Quite a few came to see the buzz around Pwn2Own and I don&#8217;t think they could have missed the shouts of victory and the press eagerly interviewing [...]]]></description>
			<content:encoded><![CDATA[<p>CanSecWest was fun, met a lot of people researchers, consultants and customers. Lot of them came to hear good quality lectures and I believe they have found them.</p>
<p>Quite a few came to see the buzz around Pwn2Own and I don&#8217;t think they could have missed the shouts of victory and the press eagerly interviewing them after their triumphant wins. I also had a chance to meet a few of our SSD researchers which shared some thoughts on the Pwn2Own even highligting the fact that 15K isn&#8217;t that much anymore for a IE8 vulnerability that can bunk its protected mode, or get you elevated privileges on the Chrome browser &#8211; I have to agree on that. This probably means there <strong>are</strong> a few chrome 0-days out there, but they are simply being sold for larger amounts of money.<br />
Also got a chance to talk to a few of the mobile researchers that were quite impressed with the BlackBerry find, highlighting how ground breaking that was, as being the first publicly done and documented breach into the BlackBerry &#8220;fortress&#8221; &#8211; I am not sure if it is in fact the first one but it was impressive none-the-less.</p>
<p>For all those that came and talked to us in our booth about the SecuriTeam Secure Disclosure, just in case you didn&#8217;t write it down, the way to reach our program is by emailing SSD@beyondsecurity.com, we also offer our existing researchers a 1,000 USD bring-a-friend offer &#8211; if you need more details email me.</p>
<p>Thanks,<br />
Noam</p>
<p>noamr[]beyondsecurity[@]com</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1489&amp;title=CanSecWest%2C%20chrome%200-days%2C%20breaking%20the%20Blackberry%20fortress" id="wpa2a_16"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1489/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CanSecWest 2011 Afterparty</title>
		<link>http://blogs.securiteam.com/index.php/archives/1488</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1488#comments</comments>
		<pubDate>Mon, 07 Mar 2011 15:03:00 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1488</guid>
		<description><![CDATA[We are organizing a party during CanSecWest 2011 starting out at 9pm at the local club &#8216;Cinema Public House&#8217;, the party will take place on the 9th of March. Party Details: * Cinema is reserving tables for our party. These tables will be marked * Drinks will be on us * Contact me for additional [...]]]></description>
			<content:encoded><![CDATA[<p>We are organizing a party during CanSecWest 2011 starting out at 9pm at the local club &#8216;Cinema Public House&#8217;, the party will take place on the 9th of March.</p>
<p>Party Details:<br />
 * Cinema is reserving tables for our party. These tables will be marked<br />
 * Drinks will be on us<br />
 * Contact me for additional details <a href="http://twitter.com/nrathaus">nrathaus</a></p>
<p>Thanks,<br />
Noam</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1488&amp;title=CanSecWest%202011%20Afterparty" id="wpa2a_18"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1488/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CanSecWest 2011 Winner</title>
		<link>http://blogs.securiteam.com/index.php/archives/1477</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1477#comments</comments>
		<pubDate>Tue, 08 Feb 2011 12:58:23 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1477</guid>
		<description><![CDATA[Hi, We have a winner to our SSD Researcher [name removed], he gets a free entry and flight expenses to CanSecWest. A big thank you to all our researchers that have worked with us in the past year, we have notified the winner of the prize, if he wants we will publish his name. We [...]]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>We have a winner to our SSD Researcher [name removed], he gets a free entry and flight expenses to CanSecWest.</p>
<p>A big thank you to all our researchers that have worked with us in the past year, we have notified the winner of the prize, if he wants we will publish his name.</p>
<p>We still have the tshirt contest going on, if you want your free entry to CanSecWest, give it a try.</p>
<p>Thanks,<br />
Noam</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1477&amp;title=CanSecWest%202011%20Winner" id="wpa2a_20"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1477/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Win Free Registration to CanSecWest</title>
		<link>http://blogs.securiteam.com/index.php/archives/1474</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1474#comments</comments>
		<pubDate>Thu, 03 Feb 2011 07:03:48 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1474</guid>
		<description><![CDATA[Hi, Help us design our (CanSecWest)link t-shirt and win a free registration to the event plus $250 for expenses. We will be giving away a t-shirt to booth visitors and if your idea is the best we will use it at the show. The design should be in one color and fit on the back [...]]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>Help us design our (CanSecWest)link t-shirt and win a free registration to the event plus $250 for expenses.</p>
<p>We will be giving away a t-shirt to booth visitors and if your idea is the best we will use it at the show.</p>
<p>The design should be in one color and fit on the back of the shirt. It can be something related to network security and could be text, an image or a cartoon.</p>
<p>Not planning to go to CanSecWest? Send in your idea anyway. If we use it we’ll send you the $250 and give the ticket to the second place design.</p>
<p>Noam.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1474&amp;title=Win%20Free%20Registration%20to%20CanSecWest" id="wpa2a_22"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1474/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CanSecWest 2011</title>
		<link>http://blogs.securiteam.com/index.php/archives/1471</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1471#comments</comments>
		<pubDate>Tue, 01 Feb 2011 11:57:14 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1471</guid>
		<description><![CDATA[Hi guys, We will be attending and sponsoring CanSecWest 2011. As part of the sponsorship we will invite a few of our readers of the blog to join us by giving out a free entry pass. Stay tuned for more details to be released in a few days. Just in case you don&#8217;t know what [...]]]></description>
			<content:encoded><![CDATA[<p>Hi guys,</p>
<p>We will be attending and sponsoring CanSecWest 2011. As part of the sponsorship we will invite a few of our readers of the blog to join us by giving out a free entry pass. Stay tuned for more details to be released in a few days.</p>
<p>Just in case you don&#8217;t know what CanSecWest is all about see:<br />
CanSecWest, focusing on applied digital security, will bring industry luminaries together in a relaxed environment which promotes collaboration and social networking. The conference features a single track of thought provoking presentations, each prepared by an experienced professional and talented educator who is at the cutting edge of his or her field. We give preference to new and innovative material, highlighting important, emergent technologies, techniques, or best industry practices.</p>
<p>Noam.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1471&amp;title=CanSecWest%202011" id="wpa2a_24"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1471/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The casting case</title>
		<link>http://blogs.securiteam.com/index.php/archives/1466</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1466#comments</comments>
		<pubDate>Mon, 10 Jan 2011 08:30:17 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1466</guid>
		<description><![CDATA[No, this isn&#8217;t a post on theater rather it is an interesting case of how a number gets &#8220;casted&#8221; from different types effectively bypassing safety checks and finally causing a crash to occur &#8211; and possibly the execution of code, as the memmove function is called with an overly large value to use for copying. [...]]]></description>
			<content:encoded><![CDATA[<p>No, this isn&#8217;t a post on theater <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  rather it is an interesting case of how a number gets &#8220;casted&#8221; from different types effectively bypassing safety checks and finally causing a crash to occur &#8211; and possibly the execution of code, as the memmove function is called with an overly large value to use for copying.</p>
<p>It starts of with a program receiving a value of -2147483648 as the length, why is this value important? it has certain characteristics to it which is important:<br />
1) It had to be negative<br />
2) It had to be fairly large as it needs to overflow the a variable of a type of int<br />
3) It couldn&#8217;t be too large as there were checks just before it to make sure it was too big</p>
<p>This magic number is not accidental it is actually (if you look at it in hex) it is the 0&#215;80000000 equivalent, i.e. it is the negative representation of this number. So as soon as you cast it to &#8220;unsigned int&#8221;, it looks positive, and when you cast it to just &#8220;int&#8221; it looks negative.</p>
<p>So if you programmed your code to do a check, and you didn&#8217;t make sure you casted the value when you did the check, for example you did:<br />
<code> if (con->content_len < buffered_len)</code></p>
<p>Where content_len is an "int", while you are comparing to an "unsigned int" value, the comparison will be flawed and the check will be true, even if the value being passed is negative and should be discarded.</p>
<p>Further, if you then call:<br />
</code><code> memmove(conn->buf, conn->buf + conn->request_len, conn->content_len);</code></p>
<p>The memmove&#8217;s last parameter is defined as an &#8220;unsigned int&#8221;, which in turn will cause this code to copy a positive value, rather then a negative value (not sure this would have helped in this case&#8230;), and in our scenario a very large memmove copy &#8211; which causes of course an Access Violation as the function reads data it shouldn&#8217;t be able to access.</p>
<p>This type of vulnerability and others like it can be easily detected by using <a href="http://www.beyondsecurity.com/black-box-testing.html">beSTORM fuzzer</a>, as it has the inherited capabilities of checking the relationships of values and their length, such as in this case.</p>
<p>UPDATE: My mistake on the example, my copy-paste skills were a bit flawed in this&#8230; I placed the patched version instead of the unpatched one.. causing the mixup, thanks for pointing it out jduck.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1466&amp;title=The%20casting%20case" id="wpa2a_26"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1466/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Fuzzing GTP-U</title>
		<link>http://blogs.securiteam.com/index.php/archives/1461</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1461#comments</comments>
		<pubDate>Wed, 29 Dec 2010 14:05:09 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1461</guid>
		<description><![CDATA[We were asked by one of our customers to provide them with a beSTORM GTP-U fuzzer module. Opening the spec and taking a peek of it revealed that it is a relatively straight forward protocol, though quite well documented, finding the documentation itself is quite hard &#8211; as there are multiple specs, which define various [...]]]></description>
			<content:encoded><![CDATA[<p>We were asked by one of our customers to provide them with a <a href="http://www.beyondsecurity.com/comparison.html">beSTORM GTP-U fuzzer</a> module. Opening the spec and taking a peek of it revealed that it is a relatively straight forward protocol, though quite well documented, finding the documentation itself is quite hard &#8211; as there are multiple specs, which define various &#8220;versions&#8221; (more like revisions) of the protocol, spanning the 15 years of history behind this protocol.</p>
<p>As this protocol is not currently endorsed by IETF, but rather by the 3GPP group, if you seek the specification for the GTP-U protocol look up <a href="http://www.3gpp.org/ftp/specs/html-info/29060.htm">3GPP TS 29.060</a>, it has what you need.</p>
<p>Once we finished building the module we ran some test, it doesn&#8217;t look good for the GTP implementors, I guess lack of tools for testing, fuzzing and compliance checking of the GTP infrastructure left a lot of room for the security players to come in and bash their heads.</p>
<p>Good luck with your GTP fuzzing!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1461&amp;title=Fuzzing%20GTP-U" id="wpa2a_28"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1461/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thanksgiving 2010 vs 2007</title>
		<link>http://blogs.securiteam.com/index.php/archives/1453</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1453#comments</comments>
		<pubDate>Thu, 25 Nov 2010 16:36:54 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1453</guid>
		<description><![CDATA[Hi, Nothing much has changed since 2007, in regard to turkeys at least, they are still getting eaten and they have still haven&#8217;t found a way to escape that (BTW we are looking for talented writers and comics artists to resurrect the securitoons, if you are interested drop me an email noamr[]beyondsecurity[dot]com)]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>Nothing much has changed since 2007, in regard to turkeys at least, they are still getting eaten and they have still haven&#8217;t found a way to escape that <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<a target="_new" href="http://blogs.securiteam.com/wp-content/ZO-04-Oct-07-TGving.jpg"><img src="http://blogs.securiteam.com/wp-content/ZO-04-Oct-07-TGving.jpg" border=0 alt="" style="width: 500px" /></a></p>
<p>(BTW we are looking for talented writers and comics artists to resurrect the securitoons, if you are interested drop me an email noamr[]beyondsecurity[dot]com)</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1453&amp;title=Thanksgiving%202010%20vs%202007" id="wpa2a_30"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1453/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>T2 Conference Challenges</title>
		<link>http://blogs.securiteam.com/index.php/archives/1435</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1435#comments</comments>
		<pubDate>Tue, 07 Sep 2010 06:51:19 +0000</pubDate>
		<dc:creator>noam</dc:creator>
				<category><![CDATA[Commentary]]></category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1435</guid>
		<description><![CDATA[Hi, Since the dawn of our species (well 2005, if you want to be picky about it) t2 has been granting free admission to the elite of their kind, the winners of the t2 Challenges. Don’t be suckered in by all the cheap imitations out there, their snooze-fest la-di-da dog and pony shows, because t2 [...]]]></description>
			<content:encoded><![CDATA[<p>Hi,</p>
<p>Since the dawn of our species (well 2005, if you want to be picky about it) t2 has been granting free admission to the elite of their kind, the winners of the t2 Challenges. Don’t be suckered in by all the cheap imitations out there, their snooze-fest la-di-da dog and pony shows, because t2 is back! And we’re pleased to announce the release of the<br />
t2’10 Challenge!</p>
<p>Now is your chance to join the past elites (<a href="http://t2.fi/challenge/">http://t2.fi/challenge/</a>) by winning free admission to this year’s t2’10 Infosec Conference!</p>
<p>This year’s t2’10 Challenge is based on multi-staging (much like good shell code), which will be powered by a scoreboard (<a href="http://t2.fi/ext/scoreboard">http://t2.fi/ext/scoreboard</a>) so that you can see — (almost) in real time — how the other participants are fairing out there in the land of the living.</p>
<p>The rules are simple: t2 will release the t2’10 Challenge and the first one to solve it will win free admission to the t2’10 Infosec Conference. But don’t stop just because you weren’t the first one to solve it: The Advisory Board will select another winner among the next ten correct answers, paying particular attention to the elegance of the solution rather than the speed. In other words you can win with either speed or style <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The t2’10 Challenge will be released 2010-08-28 10:00 EEST at <a href="http://t2.fi/">http://t2.fi/</a></p>
<p>Good luck</p>
<p><strong>UPDATE</strong>: A solution for the challenge has been posted, you can see it here: <a href="http://t2.fi/2010/09/07/t210-challenge-solution/">http://t2.fi/2010/09/07/t210-challenge-solution/</a> or you attend the conference and talk to the winner for yourself <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1435&amp;title=T2%20Conference%20Challenges" id="wpa2a_32"><img src="http://blogs.securiteam.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1435/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

