<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for sudosecure.net</title>
	<atom:link href="http://www.sudosecure.net/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://www.sudosecure.net</link>
	<description>is anything truly secure...</description>
	<lastBuildDate>Sat, 20 Mar 2010 20:29:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Silly Network Printer Fun by Franc</title>
		<link>http://www.sudosecure.net/archives/611/comment-page-1#comment-243</link>
		<dc:creator>Franc</dc:creator>
		<pubDate>Sat, 20 Mar 2010 20:29:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=611#comment-243</guid>
		<description>Couple of points.

Most printers will stop when the bin fills up so it&#039;w will not be the mess as you pictured it (and good thing they do or our office would be a mess sometimes ;)

What i do in these cases is pick a random port and translate it back to 9100. Not 100% safe but less likely to be discoverd.

In windows you can change the port in the raw settings of the tcp/ip port

did not know about the raw dump anything you want trick though</description>
		<content:encoded><![CDATA[<p>Couple of points.</p>
<p>Most printers will stop when the bin fills up so it&#8217;w will not be the mess as you pictured it (and good thing they do or our office would be a mess sometimes <img src='http://www.sudosecure.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>What i do in these cases is pick a random port and translate it back to 9100. Not 100% safe but less likely to be discoverd.</p>
<p>In windows you can change the port in the raw settings of the tcp/ip port</p>
<p>did not know about the raw dump anything you want trick though</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Monitoring the Waledac Zombies by ESET Latinoamérica &#8211; Laboratorio &#187; Blog Archive &#187; Dos redes botnets desaparecen: adios Waledac y Mariposa</title>
		<link>http://www.sudosecure.net/archives/606/comment-page-1#comment-242</link>
		<dc:creator>ESET Latinoamérica &#8211; Laboratorio &#187; Blog Archive &#187; Dos redes botnets desaparecen: adios Waledac y Mariposa</dc:creator>
		<pubDate>Wed, 03 Mar 2010 15:53:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=606#comment-242</guid>
		<description>[...] destacar que, según el portal sudosecure.net, las medidas han sido exitosas y se ha notado un decremento importante en la actividad de la [...]</description>
		<content:encoded><![CDATA[<p>[...] destacar que, según el portal sudosecure.net, las medidas han sido exitosas y se ha notado un decremento importante en la actividad de la [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New StormCodec.exe and StormCodec8.exe offered free of charge via the Storm Worm by azza</title>
		<link>http://www.sudosecure.net/archives/43/comment-page-1#comment-236</link>
		<dc:creator>azza</dc:creator>
		<pubDate>Sun, 06 Dec 2009 21:17:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=43#comment-236</guid>
		<description>i like that program thank u</description>
		<content:encoded><![CDATA[<p>i like that program thank u</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm Morphs to only serve exploits by Anti-Virus &#38; Anti-Malware website. &#187; New Storm Moving In – Presumably for Mother’s Day</title>
		<link>http://www.sudosecure.net/archives/61/comment-page-1#comment-235</link>
		<dc:creator>Anti-Virus &#38; Anti-Malware website. &#187; New Storm Moving In – Presumably for Mother’s Day</dc:creator>
		<pubDate>Sun, 06 Dec 2009 04:20:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=61#comment-235</guid>
		<description>[...] Jeremy over at sudosecure.net has posted some more info here. [...]</description>
		<content:encoded><![CDATA[<p>[...] Jeremy over at sudosecure.net has posted some more info here. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm &#8211; Go away, we&#8217;re not home by TheCatcher</title>
		<link>http://www.sudosecure.net/archives/264/comment-page-1#comment-234</link>
		<dc:creator>TheCatcher</dc:creator>
		<pubDate>Sat, 31 Oct 2009 04:07:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=264#comment-234</guid>
		<description>I found an additional source of the &quot;Go Away, We&#039;re not home messages&quot;...

When I use the firewall on my AT&amp;T 2Wire Router to block a ports, it respnds to queries on the blocked ports with a forged TCP/IP response from the intended recipient with a payload of &quot;Go Away, We&#039;re not home.&quot;</description>
		<content:encoded><![CDATA[<p>I found an additional source of the &#8220;Go Away, We&#8217;re not home messages&#8221;&#8230;</p>
<p>When I use the firewall on my AT&amp;T 2Wire Router to block a ports, it respnds to queries on the blocked ports with a forged TCP/IP response from the intended recipient with a payload of &#8220;Go Away, We&#8217;re not home.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm spam modifications contain email addresses by BSK</title>
		<link>http://www.sudosecure.net/archives/129/comment-page-1#comment-233</link>
		<dc:creator>BSK</dc:creator>
		<pubDate>Thu, 17 Sep 2009 13:45:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=129#comment-233</guid>
		<description>Please remove my email adress you have listed above. That spam was not sent by me and I&#039;m sorry I didn&#039;t read through the nearly 33,000 failure notifications I recvd to respond to your email. That is my active acct and listing it is only generating more spam for me to recv.</description>
		<content:encoded><![CDATA[<p>Please remove my email adress you have listed above. That spam was not sent by me and I&#8217;m sorry I didn&#8217;t read through the nearly 33,000 failure notifications I recvd to respond to your email. That is my active acct and listing it is only generating more spam for me to recv.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Storm Worm &#8211; Go away, we&#8217;re not home by Of Bytes and Badges &#187; Downadup / Conficker: the Storm on the Horizon</title>
		<link>http://www.sudosecure.net/archives/264/comment-page-1#comment-232</link>
		<dc:creator>Of Bytes and Badges &#187; Downadup / Conficker: the Storm on the Horizon</dc:creator>
		<pubDate>Fri, 11 Sep 2009 18:17:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=264#comment-232</guid>
		<description>[...] the Storm Worm now in decline (perhaps pushed-aside for its creators&#8217; new project, Waledec, responsible for a host of fake [...]</description>
		<content:encoded><![CDATA[<p>[...] the Storm Worm now in decline (perhaps pushed-aside for its creators&#8217; new project, Waledec, responsible for a host of fake [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Emerging Threats: Exactly What A Collaborative Security Community Should Be! by Matt Jonkman</title>
		<link>http://www.sudosecure.net/archives/589/comment-page-1#comment-231</link>
		<dc:creator>Matt Jonkman</dc:creator>
		<pubDate>Wed, 02 Sep 2009 14:50:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=589#comment-231</guid>
		<description>ET Rocks!!!

Appreciate the complements Jeremy. ET is great because of the users, I just herd the signatures into their respective pens! 

To answer a couple questions up there:
1. I left and let bleeding snort die because of a license conflict that was about to arise with a sponsor. I let a sponsor get too cozy and they tried to take advantage. Moving was the cleanest way to nip that in the bud. Worked out for the best as that left the new project unemcumbered and we were able to secure grant funding from the NSF (National Science Foundation) and the Army Research Office. We&#039;re in a better place now, and are absolutely stable for the long term.

2. OISF. We&#039;re a good way into the development of the new IDS engine. We have about 15 guys on staff, the best and the brightest from all around the world. Ivan Ristic of Mod Security is writing our HTTP parser for example. I doubt there&#039;s a person on the planet more qualified. We have on staff Brazilians, Indians, Brits, Dutch, Americans, Spaniards, you name it. We&#039;ve dug up the best of the best regardless of where they are. And we need a few more by the way if anyone is interested in contract work. 

We will have a production release of the engine with it&#039;s phase one features on or before December 31 2009. It&#039;s a very aggressive development schedule, but DHS has been very generous in their support, and we&#039;ve got a team of coders and staff that just can&#039;t be beat!

Thanks again Jeremy for the good words, but the community is what it is because of you and all the other sig submitters and reviewers!

Matt</description>
		<content:encoded><![CDATA[<p>ET Rocks!!!</p>
<p>Appreciate the complements Jeremy. ET is great because of the users, I just herd the signatures into their respective pens! </p>
<p>To answer a couple questions up there:<br />
1. I left and let bleeding snort die because of a license conflict that was about to arise with a sponsor. I let a sponsor get too cozy and they tried to take advantage. Moving was the cleanest way to nip that in the bud. Worked out for the best as that left the new project unemcumbered and we were able to secure grant funding from the NSF (National Science Foundation) and the Army Research Office. We&#8217;re in a better place now, and are absolutely stable for the long term.</p>
<p>2. OISF. We&#8217;re a good way into the development of the new IDS engine. We have about 15 guys on staff, the best and the brightest from all around the world. Ivan Ristic of Mod Security is writing our HTTP parser for example. I doubt there&#8217;s a person on the planet more qualified. We have on staff Brazilians, Indians, Brits, Dutch, Americans, Spaniards, you name it. We&#8217;ve dug up the best of the best regardless of where they are. And we need a few more by the way if anyone is interested in contract work. </p>
<p>We will have a production release of the engine with it&#8217;s phase one features on or before December 31 2009. It&#8217;s a very aggressive development schedule, but DHS has been very generous in their support, and we&#8217;ve got a team of coders and staff that just can&#8217;t be beat!</p>
<p>Thanks again Jeremy for the good words, but the community is what it is because of you and all the other sig submitters and reviewers!</p>
<p>Matt</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Brainbench.com Assessment Engine JavaScript Injection Vulnerability by jeremy</title>
		<link>http://www.sudosecure.net/archives/549/comment-page-1#comment-229</link>
		<dc:creator>jeremy</dc:creator>
		<pubDate>Tue, 21 Jul 2009 15:08:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=549#comment-229</guid>
		<description>Thanks for the response Brainbench TS! I am glad to hear you all are tracking this some how on the backend admin reports.  I would question these reports a little though, as I have used this hack to take well over the time limit and still received the official certification on more than one occasion, but at least it is a good start to fixing the issue at hand.</description>
		<content:encoded><![CDATA[<p>Thanks for the response Brainbench TS! I am glad to hear you all are tracking this some how on the backend admin reports.  I would question these reports a little though, as I have used this hack to take well over the time limit and still received the official certification on more than one occasion, but at least it is a good start to fixing the issue at hand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Brainbench.com Assessment Engine JavaScript Injection Vulnerability by Brainbench TS</title>
		<link>http://www.sudosecure.net/archives/549/comment-page-1#comment-228</link>
		<dc:creator>Brainbench TS</dc:creator>
		<pubDate>Tue, 21 Jul 2009 13:59:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.sudosecure.net/?p=549#comment-228</guid>
		<description>Thanks for your findings. We have received your emails, and we have looked into the issue. While your finding is accurate, it should be noted that the Brainbench assessments are intended to be open book technical knowledge tests with the time being an indicator of that knowledge. While the client side timer is used to eliminate server and network latency, it is not the only time reported to administrators. In fact, the example you use below would be indicated as cheating in the admin’s report. &lt;A&gt;Click here.&lt;/a&gt;

PreVisor takes these issues seriously and is constantly looking for better ways to secure our content and systems. This issue will be addressed in future releases.

PreVisor Technical Support</description>
		<content:encoded><![CDATA[<p>Thanks for your findings. We have received your emails, and we have looked into the issue. While your finding is accurate, it should be noted that the Brainbench assessments are intended to be open book technical knowledge tests with the time being an indicator of that knowledge. While the client side timer is used to eliminate server and network latency, it is not the only time reported to administrators. In fact, the example you use below would be indicated as cheating in the admin’s report. <a>Click here.</a></p>
<p>PreVisor takes these issues seriously and is constantly looking for better ways to secure our content and systems. This issue will be addressed in future releases.</p>
<p>PreVisor Technical Support</p>
]]></content:encoded>
	</item>
</channel>
</rss>
