<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for Static in the Ether</title>
	<atom:link href="http://lair.moria.org/blog/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://lair.moria.org/blog</link>
	<description>Unix, Information Security &#38; Systems Administration</description>
	<pubDate>Mon, 01 Dec 2008 21:26:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
		<item>
		<title>Comment on XP failing to hibernate by wobtap</title>
		<link>http://lair.moria.org/blog/archives/14#comment-1587</link>
		<dc:creator>wobtap</dc:creator>
		<pubDate>Tue, 25 Nov 2008 08:47:19 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=14#comment-1587</guid>
		<description>Shot. I have been struggling to ask Google the right question!</description>
		<content:encoded><![CDATA[<p>Shot. I have been struggling to ask Google the right question!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Mafia take on the OSI stack by Daemon</title>
		<link>http://lair.moria.org/blog/archives/163#comment-1169</link>
		<dc:creator>Daemon</dc:creator>
		<pubDate>Wed, 12 Nov 2008 19:14:21 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=163#comment-1169</guid>
		<description>All
People
Seem
To
Need
Data
Pipes</description>
		<content:encoded><![CDATA[<p>All<br />
People<br />
Seem<br />
To<br />
Need<br />
Data<br />
Pipes</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Phishing on Phacebook ? by mh</title>
		<link>http://lair.moria.org/blog/archives/150#comment-777</link>
		<dc:creator>mh</dc:creator>
		<pubDate>Sat, 25 Oct 2008 09:26:05 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=150#comment-777</guid>
		<description>Interestingly enough, this months fortune magazine (or forbes - i cant quite recall) has a regular columnist whining about being caught in exactly such a scam. His creds were then used to send in facebook spam [with a sim. message) to his &#62;1000 friends..
He complained about FaceBook's lameness at not protecting him, and ended with their lameness at not warning their users of using the same creds they use on other sites like internet banking..
/mh
ps: for the redaction
a) the image is called domphishing - a casae insensitive search for dom on ur blog gives u a first hit winner
b) a fb search for rhodes - gives u b irwin as hit 1, and a dom as hit 2 (ooh, same pic)
c) if anyone in gauteng ever drove past a hair style like that, the image wld be burned in their mind forever and i submit it wld be more memorable than a name tag at a conf!</description>
		<content:encoded><![CDATA[<p>Interestingly enough, this months fortune magazine (or forbes - i cant quite recall) has a regular columnist whining about being caught in exactly such a scam. His creds were then used to send in facebook spam [with a sim. message) to his &gt;1000 friends..<br />
He complained about FaceBook&#8217;s lameness at not protecting him, and ended with their lameness at not warning their users of using the same creds they use on other sites like internet banking..<br />
/mh<br />
ps: for the redaction<br />
a) the image is called domphishing - a casae insensitive search for dom on ur blog gives u a first hit winner<br />
b) a fb search for rhodes - gives u b irwin as hit 1, and a dom as hit 2 (ooh, same pic)<br />
c) if anyone in gauteng ever drove past a hair style like that, the image wld be burned in their mind forever and i submit it wld be more memorable than a name tag at a conf!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on BibTeX frequency table by Recent URLs tagged Lyx - Urlrecorder</title>
		<link>http://lair.moria.org/blog/archives/36#comment-207</link>
		<dc:creator>Recent URLs tagged Lyx - Urlrecorder</dc:creator>
		<pubDate>Tue, 16 Sep 2008 06:58:50 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=36#comment-207</guid>
		<description>[...] Recent public urls tagged "lyx"  &#8594; BibTeX frequency table [...]</description>
		<content:encoded><![CDATA[<p>[...] Recent public urls tagged &#8220;lyx&#8221;  &rarr; BibTeX frequency table [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Defcon16 Toolsets by pascals.blog : L'&#233;t&#233; a &#233;t&#233; chaud...</title>
		<link>http://lair.moria.org/blog/archives/94#comment-113</link>
		<dc:creator>pascals.blog : L'&#233;t&#233; a &#233;t&#233; chaud...</dc:creator>
		<pubDate>Thu, 04 Sep 2008 17:09:25 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=94#comment-113</guid>
		<description>[...] pr&#233;sentations de l'&#233;t&#233; sont disponibles : Black Hat, DEFCON, ainsi que des compilations d'outils diffus&#233;s lors du [...]</description>
		<content:encoded><![CDATA[<p>[...] pr&#233;sentations de l&#8217;&#233;t&#233; sont disponibles : Black Hat, DEFCON, ainsi que des compilations d&#8217;outils diffus&#233;s lors du [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security and Networks Research Group (SNRG) Site launch by Barry Irwin</title>
		<link>http://lair.moria.org/blog/archives/129#comment-86</link>
		<dc:creator>Barry Irwin</dc:creator>
		<pubDate>Tue, 02 Sep 2008 11:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=129#comment-86</guid>
		<description>Loving the technical SNAFU's!!! Problem will be resolved by the next available.....</description>
		<content:encoded><![CDATA[<p>Loving the technical SNAFU&#8217;s!!! Problem will be resolved by the next available&#8230;..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Security and Networks Research Group (SNRG) Site launch by mh</title>
		<link>http://lair.moria.org/blog/archives/129#comment-85</link>
		<dc:creator>mh</dc:creator>
		<pubDate>Tue, 02 Sep 2008 10:19:10 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=129#comment-85</guid>
		<description>sanfu #n+1: HTTP/1.1 403 Forbidden

Your site works by IP, so:
wh00t:~ haroon$ telnet snrg.ict.ru.ac.za 80
Trying 146.231.120.74...
Connected to spiderman4.ict.ru.ac.za.
Escape character is '^]'.
GET / HTTP/1.0

HTTP/1.1 200 OK

is cool...

but:
wh00t:~ haroon$ telnet snrg.ict.ru.ac.za 80
Trying 146.231.120.74...
Connected to spiderman4.ict.ru.ac.za.
Escape character is '^]'.
GET / HTTP/1.1
Host: snrg.ict.ru.ac.za

HTTP/1.1 403 Forbidden

/mh</description>
		<content:encoded><![CDATA[<p>sanfu #n+1: HTTP/1.1 403 Forbidden</p>
<p>Your site works by IP, so:<br />
wh00t:~ haroon$ telnet snrg.ict.ru.ac.za 80<br />
Trying 146.231.120.74&#8230;<br />
Connected to spiderman4.ict.ru.ac.za.<br />
Escape character is &#8216;^]&#8217;.<br />
GET / HTTP/1.0</p>
<p>HTTP/1.1 200 OK</p>
<p>is cool&#8230;</p>
<p>but:<br />
wh00t:~ haroon$ telnet snrg.ict.ru.ac.za 80<br />
Trying 146.231.120.74&#8230;<br />
Connected to spiderman4.ict.ru.ac.za.<br />
Escape character is &#8216;^]&#8217;.<br />
GET / HTTP/1.1<br />
Host: snrg.ict.ru.ac.za</p>
<p>HTTP/1.1 403 Forbidden</p>
<p>/mh</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Verifying Smime content with openSSL by Shaun Dewberry</title>
		<link>http://lair.moria.org/blog/archives/123#comment-79</link>
		<dc:creator>Shaun Dewberry</dc:creator>
		<pubDate>Mon, 01 Sep 2008 22:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=123#comment-79</guid>
		<description>Ah yes, the old corporate email disclaimer that gets bolted on haphazardly at the mail gateway, often using nothing more than a sendmail rewrite kluge. I've been fighting the battle against email disclaimers for over 5 years, specifically because of the integrity damage it does to a message. (and also cos its just a damned waste of bandwidth)

I came up with three solutions - 
1. Add an extra message header at the gateway, which references the URL of a message disclaimer (i.e. X-Disclaimer: Visit http://x.y/disclaimer). Not sure how well this gets through the legal minefield, but at least it doesn't mess with the email.
2. Plead ignorance, stupidity or incompetence when asked to add this functionality to corporate mail servers. ("Sorry boss, I have no idea how to do that, but I think if we spend $$$++ we can get it")
3. Try and get everyone to add the standard corporate sig/disclaimer directly in their email client.

Perhaps some sort of "network notaries" system could be setup similar to Firefox extension Perspectives (http://www.cs.cmu.edu/~perspectives/firefox.html) which could turn the above "strip and verify" manual process into something more automated.</description>
		<content:encoded><![CDATA[<p>Ah yes, the old corporate email disclaimer that gets bolted on haphazardly at the mail gateway, often using nothing more than a sendmail rewrite kluge. I&#8217;ve been fighting the battle against email disclaimers for over 5 years, specifically because of the integrity damage it does to a message. (and also cos its just a damned waste of bandwidth)</p>
<p>I came up with three solutions -<br />
1. Add an extra message header at the gateway, which references the URL of a message disclaimer (i.e. X-Disclaimer: Visit <a href="http://x.y/disclaimer" rel="nofollow">http://x.y/disclaimer</a>). Not sure how well this gets through the legal minefield, but at least it doesn&#8217;t mess with the email.<br />
2. Plead ignorance, stupidity or incompetence when asked to add this functionality to corporate mail servers. (&#8221;Sorry boss, I have no idea how to do that, but I think if we spend $$$++ we can get it&#8221;)<br />
3. Try and get everyone to add the standard corporate sig/disclaimer directly in their email client.</p>
<p>Perhaps some sort of &#8220;network notaries&#8221; system could be setup similar to Firefox extension Perspectives (http://www.cs.cmu.edu/~perspectives/firefox.html) which could turn the above &#8220;strip and verify&#8221; manual process into something more automated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Points Transfer with CAcert by Barry Irwin</title>
		<link>http://lair.moria.org/blog/archives/84#comment-47</link>
		<dc:creator>Barry Irwin</dc:creator>
		<pubDate>Tue, 26 Aug 2008 11:07:59 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=84#comment-47</guid>
		<description>I Can generate Valid signed certificates from the CACert site, however these require the explicit installation of the CAcert Class 1 certificate in order to be seamlessly used with browsers.  This has to do with the current non-inclusion of the cert in the CApacks commonly used by browser vendors.  

CAcert is currently getting its ducks in a row with hopeful inclusion in the next edition of Firefox.

In effect CAcert simply makes life a lot easier for peopole currently wanting to use Certificate bases systems without coing to the hastle of setting up their own CA system.</description>
		<content:encoded><![CDATA[<p>I Can generate Valid signed certificates from the CACert site, however these require the explicit installation of the CAcert Class 1 certificate in order to be seamlessly used with browsers.  This has to do with the current non-inclusion of the cert in the CApacks commonly used by browser vendors.  </p>
<p>CAcert is currently getting its ducks in a row with hopeful inclusion in the next edition of Firefox.</p>
<p>In effect CAcert simply makes life a lot easier for peopole currently wanting to use Certificate bases systems without coing to the hastle of setting up their own CA system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Verifying Smime content with openSSL by Barry Irwin</title>
		<link>http://lair.moria.org/blog/archives/123#comment-46</link>
		<dc:creator>Barry Irwin</dc:creator>
		<pubDate>Tue, 26 Aug 2008 11:04:30 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=123#comment-46</guid>
		<description>Yes this does seem to be a failing in the way Thunderbird processes the S/MIME packaging. With encrypted content it does seem to work however.  The question also comes on whether the CERTIFICATE is valid, or whether the Signature is valid?  It would appear that no warning is issued when the signature of the .s7m is found to be valid.  Certificates are ignored it appears.</description>
		<content:encoded><![CDATA[<p>Yes this does seem to be a failing in the way Thunderbird processes the S/MIME packaging. With encrypted content it does seem to work however.  The question also comes on whether the CERTIFICATE is valid, or whether the Signature is valid?  It would appear that no warning is issued when the signature of the .s7m is found to be valid.  Certificates are ignored it appears.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Points Transfer with CAcert by Anonymous</title>
		<link>http://lair.moria.org/blog/archives/84#comment-43</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Mon, 25 Aug 2008 20:20:01 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=84#comment-43</guid>
		<description>Do you get a valid cert trusted by your mother's browser?</description>
		<content:encoded><![CDATA[<p>Do you get a valid cert trusted by your mother&#8217;s browser?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Verifying Smime content with openSSL by Anonymous</title>
		<link>http://lair.moria.org/blog/archives/123#comment-42</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Mon, 25 Aug 2008 20:19:10 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=123#comment-42</guid>
		<description>So, if I tell Outlook to just send the signed bit and not send the clear text mail as well, Thunderbird reads and displays the e-mail just fine, and the sif relay attaches the disclaimer as a seperate attachment (because there is no text portion for it to append to). But, to Thunderbird's discredit, it has happily parsed the .s7m attachment, without mentioning whether the cert is valid!</description>
		<content:encoded><![CDATA[<p>So, if I tell Outlook to just send the signed bit and not send the clear text mail as well, Thunderbird reads and displays the e-mail just fine, and the sif relay attaches the disclaimer as a seperate attachment (because there is no text portion for it to append to). But, to Thunderbird&#8217;s discredit, it has happily parsed the .s7m attachment, without mentioning whether the cert is valid!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Defcon16 Toolsets by DEFCON 16 </title>
		<link>http://lair.moria.org/blog/archives/94#comment-33</link>
		<dc:creator>DEFCON 16 </dc:creator>
		<pubDate>Sun, 24 Aug 2008 18:01:39 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=94#comment-33</guid>
		<description>[...] http://lair.moria.org/blog/archives/94 [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://lair.moria.org/blog/archives/94" rel="nofollow">http://lair.moria.org/blog/archives/94</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Implementing Captchas by Dominic White</title>
		<link>http://lair.moria.org/blog/archives/110#comment-32</link>
		<dc:creator>Dominic White</dc:creator>
		<pubDate>Sun, 24 Aug 2008 17:41:52 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=110#comment-32</guid>
		<description>Yay, I'm glad to see that the security onion is catching on.</description>
		<content:encoded><![CDATA[<p>Yay, I&#8217;m glad to see that the security onion is catching on.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Free Windows CD authoring and image burning by Recent Faves Tagged With "gplv2" : MyNetFaves</title>
		<link>http://lair.moria.org/blog/archives/80#comment-30</link>
		<dc:creator>Recent Faves Tagged With "gplv2" : MyNetFaves</dc:creator>
		<pubDate>Sun, 24 Aug 2008 13:14:08 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=80#comment-30</guid>
		<description>[...] public links &#62;&#62; gplv2    License Compliance Engineering First saved by nullwert &#124; 0 days ago      Free Windows CD authoring and image burning First saved by hollygraham &#124; 2 days [...]</description>
		<content:encoded><![CDATA[<p>[...] public links &gt;&gt; gplv2    License Compliance Engineering First saved by nullwert | 0 days ago      Free Windows CD authoring and image burning First saved by hollygraham | 2 days [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DAVIX live CD looking for Beta Testers by Defcon16 Toolsets &#124; Static in the Ether</title>
		<link>http://lair.moria.org/blog/archives/55#comment-25</link>
		<dc:creator>Defcon16 Toolsets &#124; Static in the Ether</dc:creator>
		<pubDate>Wed, 20 Aug 2008 21:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=55#comment-25</guid>
		<description>[...] With the 16th incarnation of Defcon having come and gone last week, a number of people have put together a nice list of the various tools released. The ZDnet&#8217;s Rob Fuller has done all the hard work of tracking down the various tools and their websites in his article -  entitled &#8220; DEFCON 16: List of tools and stuff released &#8220;seems to be the most definitive.   Of all the tools release its DAVIX, that makes me happiest, other than it being a relaly slick Compilation of VizSec tools, it also features InetVis, which is a part of the postgraduate research by one of my students (Jean-Pierre van Riel), which I previously posted about. [...]</description>
		<content:encoded><![CDATA[<p>[...] With the 16th incarnation of Defcon having come and gone last week, a number of people have put together a nice list of the various tools released. The ZDnet&#8217;s Rob Fuller has done all the hard work of tracking down the various tools and their websites in his article -  entitled &#8220; DEFCON 16: List of tools and stuff released &#8220;seems to be the most definitive.   Of all the tools release its DAVIX, that makes me happiest, other than it being a relaly slick Compilation of VizSec tools, it also features InetVis, which is a part of the postgraduate research by one of my students (Jean-Pierre van Riel), which I previously posted about. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Migrating URLs with apache and mod_rewrite by RSS feeds have moved &#124; Static in the Ether</title>
		<link>http://lair.moria.org/blog/archives/47#comment-11</link>
		<dc:creator>RSS feeds have moved &#124; Static in the Ether</dc:creator>
		<pubDate>Tue, 10 Jun 2008 06:14:44 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=47#comment-11</guid>
		<description>[...] to my previous post about using mod_rewrite to direct my old feed URLs to the right place, its probably time to notify people who read them in aggregators that the URI [...]</description>
		<content:encoded><![CDATA[<p>[...] to my previous post about using mod_rewrite to direct my old feed URLs to the right place, its probably time to notify people who read them in aggregators that the URI [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on RFC BibTeX resource by Another RFC to BibTeX script &#124; Static in the Ether</title>
		<link>http://lair.moria.org/blog/archives/16#comment-9</link>
		<dc:creator>Another RFC to BibTeX script &#124; Static in the Ether</dc:creator>
		<pubDate>Mon, 09 Jun 2008 05:43:55 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=16#comment-9</guid>
		<description>[...] form my earlier post regarding a pre-compiled bibTeX database of all Internet RFCs, I discovered while browsing the CTAN archives that Richard Mortier wrote a awk script back in 2000 [...]</description>
		<content:encoded><![CDATA[<p>[...] form my earlier post regarding a pre-compiled bibTeX database of all Internet RFCs, I discovered while browsing the CTAN archives that Richard Mortier wrote a awk script back in 2000 [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on XP failing to hibernate by Wordpress and dealing with incoming hacks &#124; Static in the Ether</title>
		<link>http://lair.moria.org/blog/archives/14#comment-8</link>
		<dc:creator>Wordpress and dealing with incoming hacks &#124; Static in the Ether</dc:creator>
		<pubDate>Sat, 07 Jun 2008 17:17:30 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=14#comment-8</guid>
		<description>[...] rather amusing. Another interesting observation is the number of requests centered around http://lair.moria.org/blog/archives/14 my post relating to a title=&#8221;Windows XP failing to hibernate&#8221; [...]</description>
		<content:encoded><![CDATA[<p>[...] rather amusing. Another interesting observation is the number of requests centered around <a href="http://lair.moria.org/blog/archives/14" rel="nofollow">http://lair.moria.org/blog/archives/14</a> my post relating to a title=&#8221;Windows XP failing to hibernate&#8221; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Migrating URLs with apache and mod_rewrite by Barry Irwin</title>
		<link>http://lair.moria.org/blog/archives/47#comment-7</link>
		<dc:creator>Barry Irwin</dc:creator>
		<pubDate>Fri, 06 Jun 2008 17:41:52 +0000</pubDate>
		<guid isPermaLink="false">http://lair.moria.org/blog/?p=47#comment-7</guid>
		<description>http://www.askapache.com/htaccess/mod_rewrite-tips-and-tricks.html has some other really useful shortcuts.</description>
		<content:encoded><![CDATA[<p><a href="http://www.askapache.com/htaccess/mod_rewrite-tips-and-tricks.html" rel="nofollow">http://www.askapache.com/htaccess/mod_rewrite-tips-and-tricks.html</a> has some other really useful shortcuts.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
