<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Maksym Schipka's Playground &#187; Security</title>
	<atom:link href="http://schipka.com/archives/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://schipka.com</link>
	<description>Thinking out loud</description>
	<lastBuildDate>Fri, 20 Mar 2009 13:12:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Security Experts and journalists</title>
		<link>http://schipka.com/archives/76</link>
		<comments>http://schipka.com/archives/76#comments</comments>
		<pubDate>Tue, 28 Oct 2008 23:43:09 +0000</pubDate>
		<dc:creator>maksym</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://schipka.com/?p=76</guid>
		<description><![CDATA[Because of what I do, I have to deal with media quite often. Usually, we have an excellent relationship: I help the journalists dig out the facts, figures, research and opinions for their articles, they help me by promoting good security practices with their target audience, and by mentioning my company, which, I believe, does an [...]]]></description>
			<content:encoded><![CDATA[<p>Because of what I do, I have to deal with media quite often. Usually, we have an excellent relationship: I help the journalists dig out the facts, figures, research and opinions for their articles, they help me by promoting good security practices with their target audience, and by mentioning <a href="http://www.messagelabs.com" target="_blank">my company</a>, which, I believe, does an excellent job in stopping modern threats. This has lead to a number of good quotes in well-known media like <a href="http://www.timesonline.co.uk/tol/news/uk/article462124.ece" target="_blank">Times</a>, <a href="http://www.dailymail.co.uk/news/article-311742/Computer-virus-hits-Google.html" target="_blank">Daily Mail</a>, <a href="http://www.independent.co.uk/news/business/analysis-and-features/how-cyber-crime-went-professional-892882.html" target="_blank">Independent</a>, <a href="http://www.guardian.co.uk/technology/2007/nov/15/news.crime" target="_blank">Guardian</a>, <a href="http://news.bbc.co.uk/2/hi/technology/4599501.stm" target="_blank">BBC News</a>, <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/03/22/AR2008032201128.html" target="_blank">Washington Post</a>, <a href="http://www.pcworld.com/article/138576/a_hackers_holiday_shopping_list.html" target="_blank">PC World</a>, <a href="http://www.infomaticsonline.co.uk/vnunet/news/2206851/researcher-uncovers-shadow-economy" target="_blank">VNUNet</a>, <a href="http://www.computerworld.com/securitytopics/security/virus/story/0,10801,102143,00.html" target="_blank">ComputerWorld</a>, <a href="http://news.zdnet.com/2100-1009_22-143027.html" target="_blank">ZDNet</a>, <a href="http://blog.wired.com/sterling/2008/01/the-malware-sha.html" target="_blank">Wired</a> and many others. It has also lead to BBC3 and TV5 videos, some podcasts, etc. The bottom line is that generally, it is a pleasure working with journalists together, finding new angles to look at the work I, my team and my company do every day. I had my good share of good, well-formed and correct quotes.</p>
<p>But statistically, it should level out somehow, right? As the majority, if not all, of previous quotes were positive, with good messages, it was only a matter of time before misquoting or taking a quote out of context were to happen. I was not amazed, but rather quite disappointed that it happened with Metro today.</p>
<p>Apparently, I appear in a piece where online cyber-criminals are depicted as almost heros and the security industry &#8211; as a bunch of know-nothings. I feel that not only my words were <strong>taken out of context</strong> and <strong>altered beyond recognition</strong> in a way which puts a whole different meaning to them, but also that the Metro target audience (which would be your normal usual people taking buses or underground to work and back, possibly knowing little about computer security) was let down and misled by this &#8220;article&#8221;.</p>
<p>It just happens that <strong>some</strong> journalists find it amusing to either intentionally or unintentionally misquote people they interview, hunting for yet another sensation, putting a spin on words, and fighting for the front pages. Those journalists are quite different from the people I normally work with &#8211; people who are after long-term relationships and after maintaining journalism (the second oldest profession, mind you) as a respectful job. Although we are trained to deal with tricky situations during interviews and we normally have safeguards against them, sometimes sh*t happens. I&#8217;m just sad that it happened in such a way that reached such a large audience.</p>
<p>I&#8217;m not alone in having been misquoted both in secuirty field and outside. In fact, I don&#8217;t know a single public speaker that hasn&#8217;t experienced that.</p>
<p>Fortunately, all of the people that matter the most to me &#8211; my friends, my colleagues in the company and outside, my family &#8211; simply did not see me in those quotes. A lot of them came back to me saying &#8220;I am absolutely confident that what is printed is not what you said&#8221;.</p>
<p>Then again, quoting Brendan Behan: &#8220;There is no such thing as bad publicity except your own obituary&#8221;. <img src='http://schipka.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://schipka.com/archives/76/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HELLO, D**KH**DS!</title>
		<link>http://schipka.com/archives/66</link>
		<comments>http://schipka.com/archives/66#comments</comments>
		<pubDate>Fri, 10 Oct 2008 03:05:11 +0000</pubDate>
		<dc:creator>maksym</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[shadow economy]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://schipka.com/?p=66</guid>
		<description><![CDATA[My wife is playing with setting up her own website. She by far is not an experienced user and is just learning how to run it. She is a psychologist, who is eager to improve her visibility and was going to use her own website as a part of that attempt. On the other hand, [...]]]></description>
			<content:encoded><![CDATA[<p>My wife is playing with setting up <a href="http://drj.cc" target="_blank">her own website</a>. She by far is not an experienced user and is just learning how to run it. She is a psychologist, who is eager to improve her visibility and was going to use her own website as a part of that attempt. On the other hand, she wants to do it all by herself &#8211; so I keep myself away from daily running of her website.</p>
<p>I initially set up a website for her, using an excellent <a href="http://en.wikipedia.org/wiki/Content_management_system" target="_blank">CMS</a> or framework, called <a href="http://www.joomla.org" target="_blank">Joomla</a>. Excellent system, and it is, perhaps, the easiest to use. From there on, she wants to manage it herself.</p>
<p>Guess what? There apparently are some d**kh**ds (and that&#8217;s who they are), who took pride in defacing her website, while I was flying back from a conference and could not help her identify and rectify the problem. Not even manual defacement &#8211; they are nothing more but some idiotic brainless script kiddies, who just used a kit to deface it. Very simple: apparently, in the version of Joomla she was using, it is possible to reset Admin password without authorisation &#8211; simple <a href="http://en.wikipedia.org/wiki/SQL_injection" target="_blank">SQL injection</a>. On the other hand, my better half was uploading templates to play with the design and, therefore, the /templates/ directory remained writable. Those dickheads felt proud to upload a remote shell script called <strong>r57shell.php</strong> from a russian &#8220;security&#8221; website, into a writable /templates/ directory, and try to run some rubbish. They even tried defacing my website.</p>
<p>They didn&#8217;t succeed in doing a lot &#8211; just replaced a front page. I guess, that is because their tiny brains are not suited for anything else. They had some sort of a grudge against clever people. Here is how they found my wife&#8217;s site:</p>
<p><strong>78.167.171.187 &#8211; - [09/Oct/2008:14:48:54 +0100] &#8220;GET /index.php?option=com_user&amp;view=remind HTTP/1.1&#8243; 200 6029 &#8220;</strong><a href="http://www.google.com.tr/search?hl=tr&amp;q=intitle%3Adoctor++inurl%3Acom_user&amp;btnG=Ara&amp;meta"><strong>http://www.google.com.tr/search?hl=tr&amp;q=intitle%3Adoctor++inurl%3Acom_user&amp;btnG=Ara&amp;meta</strong></a><strong>=&#8221; &#8220;Opera/9.50 (Windows NT 5.1; U; tr)&#8221;</strong> </p>
<p>So here is some information about the dickheads &#8211; internet community needs to know their heros.</p>
<ol>
<li>They belong to a group called Vezir.04 &#8211; it is a group of 4 kids, from Middle East &#8211; Turkey, Egypt and Albania</li>
<li>Their website <a href="http://www.turk-h.org">http://www.turk-h.org</a> listed my wife&#8217;s website as &#8220;defaced for political reasons&#8221;. Ha.</li>
<li>Two of their nicknames are Neg4tif and CrazyHacker16 &#8211; you can tell how old they are just from the nicknames </li>
<li>The IP addresses they used: <strong>41.235.3.33, 78.167.171.187, 88.250.36.197 and 85.103.76.43</strong></li>
<li>The person checking their work: <strong>78.168.65.3</strong></li>
</ol>
<p>Moral? Some would say &#8220;set up automatic updates&#8221;. Yes, that would work in this case &#8211; but there is a reason why I don&#8217;t normally do that. Believe me when I say that automatic updates do not often improve the security, and sometimes reduce it. I will write about it later.</p>
<p><strong>P.S.</strong> Legal authorities are notified, together with all the logs being passed to them.</p>
]]></content:encoded>
			<wfw:commentRss>http://schipka.com/archives/66/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
