<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>++codemasters</title>
	<atom:link href="http://c0demasters.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://c0demasters.wordpress.com</link>
	<description>Just a Greek Coding Team.</description>
	<lastBuildDate>Wed, 16 Feb 2011 17:26:56 +0000</lastBuildDate>
	<language>el-po</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='c0demasters.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/d0d4ebb62e844dd84924bdcd2dab8edc?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>++codemasters</title>
		<link>http://c0demasters.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://c0demasters.wordpress.com/osd.xml" title="++codemasters" />
	<atom:link rel='hub' href='http://c0demasters.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Defcon 18, best of White/Gray/Black Hat security papers :)</title>
		<link>http://c0demasters.wordpress.com/2011/02/16/defcon-18-best-of-whitegrayblack-hat-security-papers/</link>
		<comments>http://c0demasters.wordpress.com/2011/02/16/defcon-18-best-of-whitegrayblack-hat-security-papers/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 17:25:44 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[defcon 18]]></category>
		<category><![CDATA[engine]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploiting]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hooking]]></category>
		<category><![CDATA[ics]]></category>
		<category><![CDATA[katana]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[multi-boot]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[osx]]></category>
		<category><![CDATA[scada]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[system]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=241</guid>
		<description><![CDATA[Here is a small article with some links of white/gray/black-papers from Defcon 18.. 0&#215;01) Scada and ICS for Security Experts: How to Avoid Cyberdouchery http://www.defcon.org/images/defcon-18/dc-18-presentations/Arlen/DEFCON-18-Arlen-SCADA-Cyberdouchery.pdf 0&#215;02) Non-Executable Stack ARM Exploitation http://www.defcon.org/images/defcon-18/dc-18-presentations/Avraham/DEFCON-18-Avraham-Modern%20ARM-Exploitation-WP.pdf 0&#215;03) Exploiting SCADA Systems http://www.defcon.org/images/defcon-18/dc-18-presentations/JBrown/DEFCON-18-Brown-SCADA.pdf 0&#215;04) Function Hooking for OSX and Linux http://www.defcon.org/images/defcon-18/dc-18-presentations/Damato/DEFCON-18-Damato-Function-Hooking.pdf 0&#215;05) Exploiting Internet Surveillance Systems http://www.defcon.org/images/defcon-18/dc-18-presentations/Decius/DEFCON-18-Decius-Exploiting-Internet-Surveillance-Systems.pdf 0&#215;06) Katana &#8211; Portable Multi-Boot [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=241&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong><em>Here is a small article with some links of white/gray/black-papers from Defcon 18.. </em></strong></p>
<p><strong>0&#215;01) Scada and ICS for Security Experts: How to Avoid Cyberdouchery</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Arlen/DEFCON-18-Arlen-SCADA-Cyberdouchery.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Arlen/DEFCON-18-Arlen-SCADA-Cyberdouchery.pdf</a></p>
<p><strong>0&#215;02) Non-Executable Stack ARM Exploitation</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Avraham/DEFCON-18-Avraham-Modern%20ARM-Exploitation-WP.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Avraham/DEFCON-18-Avraham-Modern%20ARM-Exploitation-WP.pdf</a></p>
<p><strong>0&#215;03) Exploiting SCADA Systems</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/JBrown/DEFCON-18-Brown-SCADA.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/JBrown/DEFCON-18-Brown-SCADA.pdf</a></p>
<p><strong>0&#215;04) Function Hooking for OSX and Linux</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Damato/DEFCON-18-Damato-Function-Hooking.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Damato/DEFCON-18-Damato-Function-Hooking.pdf</a></p>
<p><strong>0&#215;05) Exploiting Internet Surveillance Systems</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Decius/DEFCON-18-Decius-Exploiting-Internet-Surveillance-Systems.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Decius/DEFCON-18-Decius-Exploiting-Internet-Surveillance-Systems.pdf</a></p>
<p><strong>0&#215;06) Katana &#8211; Portable Multi-Boot Security Suite</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Dunning/DEFCON-18-Dunning-Katana.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Dunning/DEFCON-18-Dunning-Katana.pdf</a></p>
<p><strong>0&#215;07) Hacking and protecting Oracle Database Vault</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Martinez-Fayo/DEFCON-18-Martinez-Fayo-Oracle-Database-Vault.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Martinez-Fayo/DEFCON-18-Martinez-Fayo-Oracle-Database-Vault.pdf</a></p>
<p><strong>0&#215;08) Mastering the Nmap Scripting Engine</strong> <a href="http://www.defcon.org/images/defcon-18/dc-18-presentations/Fyodor-Fifield/DEFCON-18-Fyodor-Fifield-NMAP.pdf">http://www.defcon.org/images/defcon-18/dc-18-presentations/Fyodor-Fifield/DEFCON-18-Fyodor-Fifield-NMAP.pdf</a></p>
<p><em><strong>For more about Defcon, you can visit the official site:</strong></em> <a href="http://www.defcon.org/">http://www.defcon.org/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/241/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=241&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2011/02/16/defcon-18-best-of-whitegrayblack-hat-security-papers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>SourceForge.net Attack: Full Report</title>
		<link>http://c0demasters.wordpress.com/2011/02/02/sourceforge-net-attack-full-report/</link>
		<comments>http://c0demasters.wordpress.com/2011/02/02/sourceforge-net-attack-full-report/#comments</comments>
		<pubDate>Wed, 02 Feb 2011 12:28:00 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[CVS]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[sourceforge]]></category>
		<category><![CDATA[sourceforge.net]]></category>
		<category><![CDATA[ssh access]]></category>
		<category><![CDATA[Vulnerable]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=227</guid>
		<description><![CDATA[As we’ve previously announced, SourceForge.net has been the target of a directed attack. We have completed the first round of analysis, and have a much more solid picture of what happened, the extent of the impact, our plan to reduce future risk of attack. We’re still working hard on fixing things, but we wanted to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=227&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>
<p>As we’ve previously announced, SourceForge.net has been the  target of a directed attack.   We have completed the first round of  analysis, and have a much more solid picture of what happened, the  extent of the impact, our plan to reduce future risk of attack.  We’re  still working hard on fixing things, but we wanted to share what we know  with the community.</p>
<p>We discovered the attack on Wednesday, and have been working hard to  get things back in order since then.  While several boxes were  compromised we believe we caught things before the attack escalated  beyond its first stages.</p>
<p>Our early assessment of which services and hosts were impacted, and  the choice to disable CVS, ishell, file uploads, and project web updates  appears to have prevented any further escalation of the attack or any  data corruption activities.</p>
<p>We expect to continue work on validating data through the weekend,  and begin restoring services early next week. There is a lot of data to  be validated and these tests will take some time to run.   We’ll provide  more timeline information as we have more information.</p>
<p>We recognize that we could get services back online faster if we cut  corners on data validtion.  We know downtime causes serious  inconveniences for some of you.  But given the negative consequences of  corrupted data, we feel it’s vital to take the time to validate  everything that could potentially have been touched.</p>
<h3 id="attack_description">Attack Description</h3>
<p>The general course of the attack was pretty standard. There was a  root privilege escalation on one of our platforms which permitted  exposure of credentials that were then used to access machines with  externally-facing SSH.  Our network partitioning prevented escalation to  other zones of our network.</p>
<p>This is the point where we found the attack, locked down servers, and began work on analysis and response.</p>
<h3>Immediate Response</h3>
<p>Our first action response included many of the standard steps:</p>
<p>* analysis of the attack and log files on the compromised servers<br />
* methodically checking all other services and servers for exploits<br />
* further network lockdown and updating of server credentials</p>
<h3 id="service_shutdown">Service shutdown</h3>
<p>Once we knew the attack was present, we locked down the impacted  hosts, so that we could reduce the risk of escalation, from those  servers to other hosts, and prevent possible data gathering activities.</p>
<p>This strategy resulted in service downtime for:</p>
<p>* CVS Hosting<br />
* ViewVC<br />
* New Release upload capability<br />
* ProjectWeb/shell</p>
<h3 id="password_invalidation">Password invalidation</h3>
<p>Our analysis uncovered (among other things) a hacked SSH  daemon, which was modified to do password capture.  We don’t have reason  to the attacker was successful in collecting passwords.  But, the  presence of this daemon and server level access to one-way hashed, and  encrypted, password data led us to take the precautionary measure of  invalidating all SourceForge user account passwords.  Users have been  asked to recover account access by email.</p>
<h3 id="data_validation">Data Validation</h3>
<p>It’s better to be safe than sorry, so we’ve decided to perform  a comprehensive validation of project data from file releases, to SCM  commits.   We will compare data agains pre-attack backups, and will  identify changed and added.   We will review that data, and will will  also  refer anything suspicious to individual  project teams for further  assessment as needed.</p>
<p>The validation work is a precaution, because while we don’t  have evidence of any data tampering, we’d much prefer to burn a bunch of  CPU cycles verifying everything than to discover later that some  extra special trickery lead to some undetected badness.</p>
<h3 id="service_restoration">Service Restoration</h3>
<p>Now that most of the analysis is done, we’ve started the next stage  of our efforts, which includes the obvious work of restoring compromised  boxes from bare metal, and implementing a number of new controls to  reduce likelihood of future attack.</p>
<p>We will of course also be updating the credentials which reside  on these hosts and performed quite a few steps to further lock down  access to these machines.</p>
<p>We are in process of bringing services back one by one, as  data validation is completed, and we get the newly configured hosts  online. We expect that data validation will progress through the  weekend, and we’ll really start getting swinging on service restoration  early next week.</p>
<h3 id="file_release_services">File Release Services</h3>
<p>Many folks have suggested that the most likely motivation for  an attack against sourceforge would be to corrupt project releases.</p>
<p>We’ve found no evidence of this, but are taking extrodinary care  to make sure that we don’t somehow distribute corrupted release files.</p>
<p>We are performing validation of data against stored hashes, backups, and additional data copies.</p>
<h5>We expect to restore these services first, as soon as data validation is completed.</h5>
<h3 id="project_web">Project Web</h3>
<p>One attack vector that impacts our services directly is the  shared project web space.  So, let’s talk about that in a bit more  detail.</p>
<p>Sourceforge.net has been around a long time, and security  decisions made a decade ago are now being reassessed.   In most cases  past decisions were made around the general principle that we trust  open source developers to work together, play nice, and generally do the  right thing.   Services were rolled out based on widespread trust  for the developer community.  And that philosophy served us well.</p>
<p>But in the years since then, we’ve evolved from hundreds of  sf.net users to millions, and in many cases it’s time to re-asses the  balance between widespread trust and security.   Project Web is a  prime example of this, and we’ve been working at a deliberate pace to  isolate project web space, and have begun rolling out the new  “secure project web” service to many of our projects.</p>
<p>This new secure project web includes a new security model that moves  us away from shared hosting while preserving the scalability we need for  mass hosting.</p>
<p>Because of this attack we’ll be accelerating the rollout of  Secure Project Web services as part of the process of bringing the  project web service back online.  This will allow us to provide both  improved functionality, and better secruity.</p>
<h3 id="cvs">CVS</h3>
<p>CVS service is one of SourceForge.net’s oldest services and, due to  limitations in CVS itself, cannot readily live on our scalable network  storage solution. Validation of this data is going to require several  days and we anticipate that this service will be restored sometime in  the later part of week.</p>
<p>We are also considering the end-of-life of the CVS service and hope  to have user support in migrating CVS users to Subversion in coming  months.  Subversion generally provides parity to CVS commands, and many  of our users have made this transition successfully in the past.</p>
<p>From SVN, projects can move to Git if desired.</p>
<h3 id="concluding_remarks">Looking forward</h3>
<p>We are very much committed to the ongoing process of improving our  security, and we will continue making behind the scenes improvements to  our infrastructure on a regular basis.   This isn’t a one time event,  it’s a process, and we’re going to stay fully engaged over the long  term.</p>
<p>I’d like to end with a more personal note, I’ve been working with our  Ops team a lot this week, and I think we can all say that the patience  and support that we’ve received from the community has been the best  part of a very bad week.</p>
<p>Thanks again for all the support and encouragement.</p>
<p>source:<a title="sourceforge.net Blog" href="http://sourceforge.net/blog/sourceforge-attack-full-report/" target="_blank"> http://sourceforge.net/blog/sourceforge-attack-full-report/</a></p>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/227/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/227/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/227/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=227&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2011/02/02/sourceforge-net-attack-full-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>Hackers sell access to military and government academic websites</title>
		<link>http://c0demasters.wordpress.com/2011/01/24/hackers-sell-access-to-military-and-government-academic-websites/</link>
		<comments>http://c0demasters.wordpress.com/2011/01/24/hackers-sell-access-to-military-and-government-academic-websites/#comments</comments>
		<pubDate>Mon, 24 Jan 2011 20:25:38 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[goverment websites]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[military websites]]></category>
		<category><![CDATA[sql injection goverment]]></category>
		<category><![CDATA[SQLi]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=215</guid>
		<description><![CDATA[Dozens of military, government and education websites have been hacked and are up for sale,  according to researchers from Imperva&#8217;s Hacker Intelligence Initiative (HII). The firm&#8217;s HII &#8211; hacker intelligence initiative &#8211; has unearthed evidence that dozens of sites are up for sale, including defence and state sites in the US and Europe. According to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=215&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Dozens of military, government and education  websites have been hacked and are up for sale,  according to researchers  from Imperva&#8217;s Hacker Intelligence Initiative (HII). The firm&#8217;s HII &#8211; hacker intelligence  initiative &#8211; has unearthed evidence that dozens of sites are up for  sale, including defence and state sites in the US and Europe.</p>
<div>
<p>According to a team led by Noa Bar Yosef,<a href="http://www,imperva.com/" target="_blank"> Imperva&#8217;s</a> senior security strategist, high-profile sites such as the official  Italian government website (http://itcgcesaro.gov.it), the Department of  Defense Pharmacoeconomic centre (http://pec.ha.osd.mil/) and even the  US Army, Communications-Electronics Command (CECOM)  (http://cecom.army.mil ) are available.</p>
<p>In a <a href="http://blog.imperva.com/2011/01/major-websites-govmiledu-are-hacked-and-up-for-sale.html" target="_blank">security blog posting</a>, Rob Rachwald of Imperva says that the hacker has put up a range of sites for anything between $55 and $499.</p>
<p>Imperva&#8217;s research team also claims to have discovered that the  hacker was also offering personal information from the hacked websites  at $20 per 1000 records.</p>
<p>&#8220; The hacker is also selling info personally identifiable information  from hacked sites, for $20 per 1K records&#8221;, says the blog, citing an  example of &#8220; a list of UConn staff&#8221;.</p>
<p>Imperva&#8217;s post is complete with screenshots, which the hacker claims as a proof of access.</p>
<p>According to Rachwald, the victim sites&#8217; vulnerabilities were  probably obtained by an SQL injection vulnerability automatic scanner  and exploited in automated manner, as the hacker published his methods  in a post in some hacker forum.</p>
<p>&#8220; In the screen shot [<a href="http://imperva.typepad.com/.a/6a01156f8c7ad8970c0147e1cc78d8970b-pi" target="_blank">here</a>]  we can see IRC chat between the SQLi &#8220; master&#8221; = @evil which issues the  scanning commands and the exploiting &#8220; x0owner&#8221; which performs the  commands&#8221;, says the Imperva blog.</p>
<p>&#8220; In this specific case @evil issues command for to x0wner to obtain  DB tables names (!tbls) from vulnerable link  (www.site.gr/athlete.php?id=&#8230;) x0wner reports its findings  &#8211; the  tables &#8216;activities&#8217;,'admin&#8217;,&#8221; the blog notes.</p>
<p>Security researcher <a href="http://krebsonsecurity.com/2011/01/ready-for-cyberwar/" target="_blank">Brian Krebs </a>picked  up Imperva&#8217;s research over the weekend, detailing a lot of the site  information that Rachwald chose to block out in his blog.</p>
<p>In his security blog, Krebs said that he finds it ironic that one of  these sites allegedly for sale is the Department of Defense  Pharmacoeconomic Center, which is a DoD site tasked with &#8216;improving the  clinical, economic, and humanistic outcomes of drug therapy in support  of the military health system&#8217;.</p>
<p>&#8220; In all likelihood, if access to this site is purchased, it will be  by someone looking to plant links to rogue online pharmacies of the sort  frequently advertised in junk e-mail&#8221;, said Krebs.</p>
<p>&#8220; People who get paid to promote these rogue pharmacies typically do  so by hacking legitimate websites and including links back to  fly-by-night pharma sites, and they particularly like dot-mil, dot-gov  and dot-edu sites because search engines tend to treat links coming from  those domains with more authority than random .com sites&#8221;, he added.</p>
<p>Krebs also noted that the &#8216;Undetected Private Java Driveby Exploit&#8217;  that the hacker is selling is &#8220; none other than the social engineering  trick I blogged about last week.&#8221;</p>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/215/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/215/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/215/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=215&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2011/01/24/hackers-sell-access-to-military-and-government-academic-websites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft releases free secure development tool</title>
		<link>http://c0demasters.wordpress.com/2011/01/23/microsoft-releases-free-secure-development-tool/</link>
		<comments>http://c0demasters.wordpress.com/2011/01/23/microsoft-releases-free-secure-development-tool/#comments</comments>
		<pubDate>Sun, 23 Jan 2011 16:22:52 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=211</guid>
		<description><![CDATA[Microsoft on Monday announced the free availability of a new software verification tool designed for coders, as well as IT professionals. Announced at this week&#8217;s Black Hat conference in Washington, D.C., the tool, called Attack Surface Analyzer, helps determine when poorly designed applications widen the attack surface of a Windows system. The tool is used [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=211&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Microsoft on Monday announced the free availability of a new software  verification tool designed for coders, as well as IT professionals.</p>
<p>Announced at this week&#8217;s Black Hat conference in Washington, D.C.,  the tool, called Attack Surface Analyzer, helps determine when poorly  designed applications widen the attack surface of a Windows system.</p>
<p>The tool is used to &#8220; highlight the changes in system state, run-time  parameters and securable objects on the Windows operating system,&#8221;  according to a Security Development Lifecycle blog <a href="http://blogs.msdn.com/b/sdl/archive/2011/01/17/announcing-attack-surface-analyzer.aspx">post</a>.  It identifies altered or new files, registry keys, services, ActiveX  controls, listening ports, access control lists and other components  that could increase an attack surface.</p>
<p>&#8220; The tool takes snapshots of an organization&#8217;s system and compares  these to identify changes,&#8221; the post said, citing a product description.  &#8220; [It] does not analyze a system based on signatures or known  vulnerabilities; instead, it looks for classes of security weaknesses as  applications are installed on the Windows operating system.&#8221;</p>
<p>The tool also produces a report detailing the changes that a particular application may have made to a system.</p>
<p>The Attack Surface Analyzer can be downloaded <a href="http://www.microsoft.com/security/sdl/getstarted/tools.aspx">here</a>.</p>
<p>Source: <a title="scmagazineus" href="http://www.scmagazineus.com/microsoft-releases-free-secure-development-tool/article/194470/">http://www.scmagazineus.com/microsoft-releases-free-secure-development-tool/article/194470/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/211/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=211&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2011/01/23/microsoft-releases-free-secure-development-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>IT director gets jail term for hacking former employer&#8217;s site</title>
		<link>http://c0demasters.wordpress.com/2010/11/01/it-director-gets-jail-term-for-hacking-former-employers-site/</link>
		<comments>http://c0demasters.wordpress.com/2010/11/01/it-director-gets-jail-term-for-hacking-former-employers-site/#comments</comments>
		<pubDate>Mon, 01 Nov 2010 10:34:11 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=196</guid>
		<description><![CDATA[IDG News Service &#8211; A man fired as IT director for a Richmond, Virginia, seller of telecom equipment has been sentenced to 27 months in prison for hacking into his former employer&#8217;s website and deleting files, the U.S. Department of Justice said. Darnell Albert-El, 53, pleaded guilty to one count of intentionally damaging a protected [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=196&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p id="first_paragraph">IDG News Service &#8211; A man fired as IT director for a Richmond, Virginia, seller of telecom equipment has been sentenced to 27 months in prison for hacking into his former employer&#8217;s website and deleting files, the U.S. Department of Justice said.</p>
<p>Darnell Albert-El, 53, pleaded guilty to one count of intentionally damaging a protected computer without authorization on June 29. He was sentenced Friday in U.S. District Court for the Eastern District of Virginia and, in addition to the prison time, ordered to pay US$6,700 in restitution to Trans Marx, which sells discounted telecom equipment and supplies.</p>
<p>Albert-El, of Richmond, worked at Trans Marx from February to June 2008, according to court documents. Before he was fired, Albert-El had access to the Trans Marx computer network, including the company website hosted in Georgia, the DOJ said.</p>
<p>On July 25, Albert-El used a personal computer and an administrator account to access the computer hosting the company&#8217;s website, and he deleted about 1,000 files related to the Trans Marx website, the DOJ said.</p>
<p>In his plea agreement and an earlier interview with U.S. Federal Bureau of Investigation agents, Albert-El said he deleted the files because he was angry about being fired, the DOJ said.</p>
<p>Albert-El later told Trans Marx employees where backup tapes were located and offered to assist them in restoring the files, said his lawyer, Mary Maguire, while arguing in court documents for a lenient sentence.<a title="Source" href="http://www.computerworld.com/s/article/9194027/IT_director_gets_jail_term_for_hacking_former_employer_s_site"></a></p>
<p>Source:  <a title="Source" href="http://www.computerworld.com/s/article/9194027/IT_director_gets_jail_term_for_hacking_former_employer_s_site" target="_blank">http://www.computerworld.com/s/article/9194027/IT_director_gets_jail_term_for_hacking_former_employer_s_site</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=196&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2010/11/01/it-director-gets-jail-term-for-hacking-former-employers-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>Adobe warns of 0-day hole in Flash Player</title>
		<link>http://c0demasters.wordpress.com/2010/09/14/adobe-warns-of-0-day-hole-in-flash-player/</link>
		<comments>http://c0demasters.wordpress.com/2010/09/14/adobe-warns-of-0-day-hole-in-flash-player/#comments</comments>
		<pubDate>Tue, 14 Sep 2010 00:42:48 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[0-day in Flash]]></category>
		<category><![CDATA[Flash Player]]></category>
		<category><![CDATA[Flash Vulnerability]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=192</guid>
		<description><![CDATA[Adobe Systems on Monday warned of a 0-day hole in Flash Player that reportedly is being exploited in the wild and could allow an attacker to take control of a computer. The critical vulnerability affects Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Mac, Linux, Solaris, and Android. It also affects Adobe Reader 9.3.4 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=192&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>Adobe Systems on Monday warned of a 0-day hole in Flash Player that reportedly is being exploited in the wild and could allow an attacker to take control of a computer.</p>
<p>The critical vulnerability affects Adobe Flash Player 10.1.82.76 and earlier versions for Windows, Mac, Linux, Solaris, and Android. It also affects Adobe Reader 9.3.4 and earlier version for Windows, Mac, and Unix and Adobe Acrobat 9.3.4 and earlier versions for Windows and Mac. Adobe is not aware of any attacks exploiting the hole against Adobe Reader or Acrobat, the company said in its security advisory.</p>
<div>
<div>
<p>Adobe is finalizing a fix for the hole and expects to provide an update for Flash Player for Windows, Mac, Solaris, and Android during the week of September 27, the advisory said. Updates for Adobe Reader are expected during the week of October 4.</p>
<p>Adobe is moving up the date of its next quarterly security update for Adobe Reader and Acrobat and will also release a patch the week of October 4 for a critical zero-day hole in Adobe Reader and Acrobat that was disclosed last week and is being exploited in attacks on. As a result, there will be no updates on October 12, which was the next scheduled quarterly release date.</p>
<p>In the meantime, <a title="Microsoft, Adobe: PDF security flaw treatable -- Saturday, Sep 11, 2010" href="http://news.cnet.com/8301-1009_3-20016161-83.html">Microsoft has a tool</a> that can help block the attacks on Adobe Reader and Acrobat on Windows machines.<br />
<a href="http://news.cnet.com/security/?tag=hdr;snav#ixzz0zSa37Tqp"></a></p>
<div>
<div>Source: <a href="http://news.cnet.com/8301-27080_3-20016301-245.html">InSecurity Complex</a><a href="http://news.cnet.com/security/?tag=hdr;snav#ixzz0zSZttN5Y"></a></div>
</div>
<p><a href="http://news.cnet.com/security/?tag=hdr;snav#ixzz0zSZnxZy8"></a></div>
</div>
<p><a href="http://news.cnet.com/security/?tag=hdr;snav#ixzz0zSZhUddD"></a></div>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/192/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/192/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/192/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=192&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2010/09/14/adobe-warns-of-0-day-hole-in-flash-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>Microsoft Releases Advisory On XP Help Vulnerability</title>
		<link>http://c0demasters.wordpress.com/2010/06/15/microsoft-releases-advisory-on-xp-help-vulnerability/</link>
		<comments>http://c0demasters.wordpress.com/2010/06/15/microsoft-releases-advisory-on-xp-help-vulnerability/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 15:20:32 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[Help]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Vulnerable]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=181</guid>
		<description><![CDATA[Microsoft has released a formal security advisory for the vulnerability disclosed today in the Windows XP and Windows Server 2003 help systems. The first link downloads an .MSI file which runs a very short wizard. Tell it to proceed and then it&#8217;s done and you get an option to tell them what you think of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=181&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released <a href="http://www.microsoft.com/technet/security/advisory/2219475.mspx">a formal security advisory for the vulnerability disclosed today in the Windows XP and Windows Server 2003 help systems</a>.</p>
<p>The first link downloads an .MSI file which runs a very short wizard. Tell it to proceed and then it&#8217;s done and you get an option to tell them what you think of it. The second link runs a different .MSI which undoes the fix. Note this link, because after the patch is available and you apply it you&#8217;ll want to run the undo Fix it so that you can use your help system again.</p>
<p>Using these links is a far better option than manual registry hacking. Windows XP users, start Fix iting.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/181/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/181/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=181&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2010/06/15/microsoft-releases-advisory-on-xp-help-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>Bugs in Help System Makes Windows XP Vulnerable From Web</title>
		<link>http://c0demasters.wordpress.com/2010/06/11/bugs-in-help-system-makes-windows-xp-vulnerable-from-web/</link>
		<comments>http://c0demasters.wordpress.com/2010/06/11/bugs-in-help-system-makes-windows-xp-vulnerable-from-web/#comments</comments>
		<pubDate>Fri, 11 Jun 2010 11:09:56 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerable]]></category>
		<category><![CDATA[Web Attack]]></category>
		<category><![CDATA[Widnows XP]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=164</guid>
		<description><![CDATA[This morning Tavis Ormandy, a security researcher for Google, posted a vulnerability report to the Full-Disclosure mailing list detailing a vulnerability in Windows XP and, as it turns out, Windows Server 2003. Later versions of Windows are unaffected. The flaw is in the Help and Support Center, a relic of the time when Microsoft was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=164&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This morning Tavis Ormandy, a  security researcher for Google, <a href="http://seclists.org/fulldisclosure/2010/Jun/205">posted a  vulnerability report to the Full-Disclosure mailing list detailing a  vulnerability</a> in Windows XP and, as it turns out, Windows Server  2003. Later versions of Windows are unaffected.</p>
<p>The flaw is in the Help and  Support Center, a relic of the time when Microsoft was trying to make  everything on the computer a browser app. Help, Control Panel, Windows  Update and other components were browser or browser-like apps. In order  to access remote help, the Help and Support Center supports remote links  to help using hcp:// addresses. Windows XP SP2 introduced a model  whereby the program, when run with the /fromhcp parameter, runs in a  special restricted mode where only links from addresses on a special  whitelist can have privileged access. Ormandy&#8217;s vulnerability is a an  implementation error which allows bypass of the whitelist. Read the FD  posting if you want all the gory details, but the end result is  arbitrary code execution from links on the web. Ormandy notified  Microsoft about this bug on June 5, the Saturday before this last Patch  Tuesday.</p>
<p>This afternoon <a href="http://blogs.technet.com/b/msrc/archive/2010/06/10/windows-help-vulnerability-disclosure.aspx">the  Microsoft Security Response Center responded with a blog entry</a>.  They criticize Ormandy for releasing the information without giving them  a fair chance to evaluate it and then provide a registry hack to remove  all hcp support. This blocks the vulnerability as well as useful hcp  links, such as those in the Control Panel.</p>
<p>Ormandy also created an unofficial hotfix of his own and linked to it  from his posting. <a href="http://secunia.com/blog/103/">A Secunia  analysis of the issue</a> claims that the hotfix does not sufficiently  address the problem.</p>
<p>If you run Windows XP (and that&#8217;s your first mistake) you will be  much better off following Microsoft&#8217;s registry mitigation technique,  although I think you could probably get away with renaming the key  rather than deleting it. This should make it easier to undo when the  patch is available.</p>
<p>Ormandy posted the vulnerability report using his personal e-mail and  probably considers that he is acting here in a private capacity, but  don&#8217;t expect Microsoft to see it that way. Microsoft&#8217;s initial report on  the bug refers to Ormandy as &#8220; a Google security researcher&#8221; and <a href="http://twitter.com/msftsecresponse/status/15871268646">the tweet  announcing it</a> says &#8220; Information on the Windows Help vulnerability  disclosed by Google.&#8221; People can have reasonable disagreements about the  limits of full disclosure vs. &#8220; responsible&#8221; disclosure, but I doubt  Google would take kindly to a Microsoft researcher blind-siding them  like this. For Ormandy to expect turnaround like this during a heavy  Patch Tuesday is not reasonable. In fact, <a href="http://twitter.com/taviso/statuses/15874332662/">even Ormandy may  be reconsidering the wisdom of his move</a>.</p>
<p><a href="http://blogs.pcmag.com/securitywatch/2010/06/bugs_in_help_system_makes_wind.php">Source from Here</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/164/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/164/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/164/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=164&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2010/06/11/bugs-in-help-system-makes-windows-xp-vulnerable-from-web/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>The all truth about programmers&#8230; with a little python :)</title>
		<link>http://c0demasters.wordpress.com/2010/04/21/about-programmers/</link>
		<comments>http://c0demasters.wordpress.com/2010/04/21/about-programmers/#comments</comments>
		<pubDate>Wed, 21 Apr 2010 17:19:05 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[Fun for Geeks]]></category>
		<category><![CDATA[coding]]></category>
		<category><![CDATA[evolution of a python programmer]]></category>
		<category><![CDATA[evolution python]]></category>
		<category><![CDATA[fun]]></category>
		<category><![CDATA[geek]]></category>
		<category><![CDATA[programmer]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[python programmer]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=159</guid>
		<description><![CDATA[#Newbie programmer def factorial(x): if x == 0: return 1 else: return x * factorial(x - 1) print factorial(6) #First year programmer, studied Pascal def factorial(x): result = 1 i = 2 while i &#60;= x: result = result * i i = i + 1 return result print factorial(6) #First year programmer, studied C [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=159&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<pre style="color:#000000;background:#ffffff;"><span style="color:#696969;">#Newbie programmer</span>
<span style="color:#800000;font-weight:bold;">def</span> factorial<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">if</span> x <span style="color:#808030;">=</span><span style="color:#808030;">=</span> <span style="color:#008c00;">0</span><span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">return</span> <span style="color:#008c00;">1</span>
    <span style="color:#800000;font-weight:bold;">else</span><span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">return</span> x <span style="color:#808030;">*</span> factorial<span style="color:#808030;">(</span>x <span style="color:#808030;">-</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span>
<span style="color:#800000;font-weight:bold;">print</span> factorial<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#First year programmer, studied Pascal</span>
<span style="color:#800000;font-weight:bold;">def</span> factorial<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    result <span style="color:#808030;">=</span> <span style="color:#008c00;">1</span>
    i <span style="color:#808030;">=</span> <span style="color:#008c00;">2</span>
    <span style="color:#800000;font-weight:bold;">while</span> i <span style="color:#808030;">&lt;</span><span style="color:#808030;">=</span> x<span style="color:#808030;">:</span>
        result <span style="color:#808030;">=</span> result <span style="color:#808030;">*</span> i
        i <span style="color:#808030;">=</span> i <span style="color:#808030;">+</span> <span style="color:#008c00;">1</span>
    <span style="color:#800000;font-weight:bold;">return</span> result
<span style="color:#800000;font-weight:bold;">print</span> factorial<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#First year programmer, studied C</span>
<span style="color:#800000;font-weight:bold;">def</span> fact<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span> <span style="color:#696969;">#{</span>
    result <span style="color:#808030;">=</span> i <span style="color:#808030;">=</span> <span style="color:#008c00;">1</span><span style="color:#808030;">;</span>
    <span style="color:#800000;font-weight:bold;">while</span> <span style="color:#808030;">(</span>i <span style="color:#808030;">&lt;</span><span style="color:#808030;">=</span> x<span style="color:#808030;">)</span><span style="color:#808030;">:</span> <span style="color:#696969;">#{</span>
        result <span style="color:#808030;">*</span><span style="color:#808030;">=</span> i<span style="color:#808030;">;</span>
        i <span style="color:#808030;">+</span><span style="color:#808030;">=</span> <span style="color:#008c00;">1</span><span style="color:#808030;">;</span>
    <span style="color:#696969;">#}</span>
    <span style="color:#800000;font-weight:bold;">return</span> result<span style="color:#808030;">;</span>
<span style="color:#696969;">#}</span>
<span style="color:#800000;font-weight:bold;">print</span><span style="color:#808030;">(</span>fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#First year programmer, SICP</span>
@tailcall
<span style="color:#800000;font-weight:bold;">def</span> fact<span style="color:#808030;">(</span>x<span style="color:#808030;">,</span> acc<span style="color:#808030;">=</span><span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">if</span> <span style="color:#808030;">(</span>x <span style="color:#808030;">&gt;</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">:</span> <span style="color:#800000;font-weight:bold;">return</span> <span style="color:#808030;">(</span>fact<span style="color:#808030;">(</span><span style="color:#808030;">(</span>x <span style="color:#808030;">-</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">,</span> <span style="color:#808030;">(</span>acc <span style="color:#808030;">*</span> x<span style="color:#808030;">)</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span>
    <span style="color:#800000;font-weight:bold;">else</span><span style="color:#808030;">:</span>       <span style="color:#800000;font-weight:bold;">return</span> acc
<span style="color:#800000;font-weight:bold;">print</span><span style="color:#808030;">(</span>fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#First year programmer, Python</span>
<span style="color:#800000;font-weight:bold;">def</span> Factorial<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    res <span style="color:#808030;">=</span> <span style="color:#008c00;">1</span>
    <span style="color:#800000;font-weight:bold;">for</span> i <span style="color:#800000;font-weight:bold;">in</span> <span style="color:#e34adc;">xrange</span><span style="color:#808030;">(</span><span style="color:#008c00;">2</span><span style="color:#808030;">,</span> x <span style="color:#808030;">+</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        res <span style="color:#808030;">*</span><span style="color:#808030;">=</span> i
    <span style="color:#800000;font-weight:bold;">return</span> res
<span style="color:#800000;font-weight:bold;">print</span> Factorial<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Lazy Python programmer</span>
<span style="color:#800000;font-weight:bold;">def</span> fact<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">return</span> x <span style="color:#808030;">&gt;</span> <span style="color:#008c00;">1</span> <span style="color:#800000;font-weight:bold;">and</span> x <span style="color:#808030;">*</span> fact<span style="color:#808030;">(</span>x <span style="color:#808030;">-</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span> <span style="color:#800000;font-weight:bold;">or</span> <span style="color:#008c00;">1</span>
<span style="color:#800000;font-weight:bold;">print</span> fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Lazier Python programmer</span>
f <span style="color:#808030;">=</span> <span style="color:#e34adc;">lambda</span> x<span style="color:#808030;">:</span> x <span style="color:#800000;font-weight:bold;">and</span> x <span style="color:#808030;">*</span> f<span style="color:#808030;">(</span>x <span style="color:#808030;">-</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span> <span style="color:#800000;font-weight:bold;">or</span> <span style="color:#008c00;">1</span>
<span style="color:#800000;font-weight:bold;">print</span> f<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Python expert programmer</span>
fact <span style="color:#808030;">=</span> <span style="color:#e34adc;">lambda</span> x<span style="color:#808030;">:</span> <span style="color:#e34adc;">reduce</span><span style="color:#808030;">(</span><span style="color:#e34adc;">int</span><span style="color:#808030;">.</span><span style="color:#e34adc;">__mul__</span><span style="color:#808030;">,</span> <span style="color:#e34adc;">xrange</span><span style="color:#808030;">(</span><span style="color:#008c00;">2</span><span style="color:#808030;">,</span> x <span style="color:#808030;">+</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">,</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span>
<span style="color:#800000;font-weight:bold;">print</span> fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Python hacker</span>
<span style="color:#800000;font-weight:bold;">import</span> sys
@tailcall
<span style="color:#800000;font-weight:bold;">def</span> fact<span style="color:#808030;">(</span>x<span style="color:#808030;">,</span> acc<span style="color:#808030;">=</span><span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">if</span> x<span style="color:#808030;">:</span> <span style="color:#800000;font-weight:bold;">return</span> fact<span style="color:#808030;">(</span>x<span style="color:#808030;">.</span><span style="color:#e34adc;">__sub__</span><span style="color:#808030;">(</span><span style="color:#008c00;">1</span><span style="color:#808030;">)</span><span style="color:#808030;">,</span> acc<span style="color:#808030;">.</span><span style="color:#e34adc;">__mul__</span><span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">)</span>
    <span style="color:#800000;font-weight:bold;">return</span> acc
sys<span style="color:#808030;">.</span>stdout<span style="color:#808030;">.</span>write<span style="color:#808030;">(</span><span style="color:#e34adc;">str</span><span style="color:#808030;">(</span>fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span> <span style="color:#808030;">+</span> <span style="color:#0000e6;">'\n'</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#EXPERT PROGRAMMER</span>
<span style="color:#800000;font-weight:bold;">from</span> c_math <span style="color:#800000;font-weight:bold;">import</span> fact
<span style="color:#800000;font-weight:bold;">print</span> fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#BRITISH EXPERT PROGRAMMER</span>
<span style="color:#800000;font-weight:bold;">from</span> c_maths <span style="color:#800000;font-weight:bold;">import</span> fact
<span style="color:#800000;font-weight:bold;">print</span> fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Web designer</span>
<span style="color:#800000;font-weight:bold;">def</span> factorial<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#696969;">#-------------------------------------------------</span>
    <span style="color:#696969;">#--- Code snippet from The Math Vault          ---</span>
    <span style="color:#696969;">#--- Calculate factorial (C) Arthur Smith 1999 ---</span>
    <span style="color:#696969;">#-------------------------------------------------</span>
    result <span style="color:#808030;">=</span> <span style="color:#e34adc;">str</span><span style="color:#808030;">(</span><span style="color:#008c00;">1</span><span style="color:#808030;">)</span>
    i <span style="color:#808030;">=</span> <span style="color:#008c00;">1</span> <span style="color:#696969;">#Thanks Adam</span>
    <span style="color:#800000;font-weight:bold;">while</span> i <span style="color:#808030;">&lt;</span><span style="color:#808030;">=</span> x<span style="color:#808030;">:</span>
        <span style="color:#696969;">#result = result * i  #It's faster to use *=</span>
        <span style="color:#696969;">#result = str(result * result + i)</span>
           <span style="color:#696969;">#result = int(result *= i) #??????</span>
        result <span style="color:#808030;">=</span> <span style="color:#e34adc;">str</span><span style="color:#808030;">(</span><span style="color:#e34adc;">int</span><span style="color:#808030;">(</span>result<span style="color:#808030;">)</span> <span style="color:#808030;">*</span> i<span style="color:#808030;">)</span>
        <span style="color:#696969;">#result = int(str(result) * i)</span>
        i <span style="color:#808030;">=</span> i <span style="color:#808030;">+</span> <span style="color:#008c00;">1</span>
    <span style="color:#800000;font-weight:bold;">return</span> result
<span style="color:#800000;font-weight:bold;">print</span> factorial<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Unix programmer</span>
<span style="color:#800000;font-weight:bold;">import</span> os
<span style="color:#800000;font-weight:bold;">def</span> fact<span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    os<span style="color:#808030;">.</span>system<span style="color:#808030;">(</span><span style="color:#0000e6;">'factorial '</span> <span style="color:#808030;">+</span> <span style="color:#e34adc;">str</span><span style="color:#808030;">(</span>x<span style="color:#808030;">)</span><span style="color:#808030;">)</span>
fact<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">)</span>

<span style="color:#696969;">#Windows programmer</span>
NULL <span style="color:#808030;">=</span> <span style="color:#e34adc;">None</span>
<span style="color:#800000;font-weight:bold;">def</span> CalculateAndPrintFactorialEx<span style="color:#808030;">(</span>dwNumber<span style="color:#808030;">,</span>
                                 hOutputDevice<span style="color:#808030;">,</span>
                                 lpLparam<span style="color:#808030;">,</span>
                                 lpWparam<span style="color:#808030;">,</span>
                                 lpsscSecurity<span style="color:#808030;">,</span>
                                 <span style="color:#808030;">*</span>dwReserved<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">if</span> lpsscSecurity <span style="color:#808030;">!</span><span style="color:#808030;">=</span> NULL<span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">return</span> NULL <span style="color:#696969;">#Not implemented</span>
    dwResult <span style="color:#808030;">=</span> dwCounter <span style="color:#808030;">=</span> <span style="color:#008c00;">1</span>
    <span style="color:#800000;font-weight:bold;">while</span> dwCounter <span style="color:#808030;">&lt;</span><span style="color:#808030;">=</span> dwNumber<span style="color:#808030;">:</span>
        dwResult <span style="color:#808030;">*</span><span style="color:#808030;">=</span> dwCounter
        dwCounter <span style="color:#808030;">+</span><span style="color:#808030;">=</span> <span style="color:#008c00;">1</span>
    hOutputDevice<span style="color:#808030;">.</span>write<span style="color:#808030;">(</span><span style="color:#e34adc;">str</span><span style="color:#808030;">(</span>dwResult<span style="color:#808030;">)</span><span style="color:#808030;">)</span>
    hOutputDevice<span style="color:#808030;">.</span>write<span style="color:#808030;">(</span><span style="color:#0000e6;">'\n'</span><span style="color:#808030;">)</span>
    <span style="color:#800000;font-weight:bold;">return</span> <span style="color:#008c00;">1</span>
<span style="color:#800000;font-weight:bold;">import</span> sys
CalculateAndPrintFactorialEx<span style="color:#808030;">(</span><span style="color:#008c00;">6</span><span style="color:#808030;">,</span> sys<span style="color:#808030;">.</span>stdout<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">,</span> NULL<span style="color:#808030;">)</span>

<span style="color:#696969;">#Enterprise programmer</span>
<span style="color:#800000;font-weight:bold;">def</span> new<span style="color:#808030;">(</span>cls<span style="color:#808030;">,</span> <span style="color:#808030;">*</span>args<span style="color:#808030;">,</span> <span style="color:#808030;">*</span><span style="color:#808030;">*</span>kwargs<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">return</span> cls<span style="color:#808030;">(</span><span style="color:#808030;">*</span>args<span style="color:#808030;">,</span> <span style="color:#808030;">*</span><span style="color:#808030;">*</span>kwargs<span style="color:#808030;">)</span>

<span style="color:#800000;font-weight:bold;">class</span> Number<span style="color:#808030;">(</span>object<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">pass</span>

<span style="color:#800000;font-weight:bold;">class</span> IntegralNumber<span style="color:#808030;">(</span><span style="color:#e34adc;">int</span><span style="color:#808030;">,</span> Number<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">def</span> toInt<span style="color:#808030;">(</span>self<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">return</span> new <span style="color:#808030;">(</span><span style="color:#e34adc;">int</span><span style="color:#808030;">,</span> self<span style="color:#808030;">)</span>

<span style="color:#800000;font-weight:bold;">class</span> InternalBase<span style="color:#808030;">(</span>object<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">def</span> <span style="color:#e34adc;">__init__</span><span style="color:#808030;">(</span>self<span style="color:#808030;">,</span> base<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        self<span style="color:#808030;">.</span>base <span style="color:#808030;">=</span> base<span style="color:#808030;">.</span>toInt<span style="color:#808030;">(</span><span style="color:#808030;">)</span>

    <span style="color:#800000;font-weight:bold;">def</span> getBase<span style="color:#808030;">(</span>self<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">return</span> new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> self<span style="color:#808030;">.</span>base<span style="color:#808030;">)</span>

<span style="color:#800000;font-weight:bold;">class</span> MathematicsSystem<span style="color:#808030;">(</span>object<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">def</span> <span style="color:#e34adc;">__init__</span><span style="color:#808030;">(</span>self<span style="color:#808030;">,</span> ibase<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        Abstract

    @<span style="color:#e34adc;">classmethod</span>
    <span style="color:#800000;font-weight:bold;">def</span> getInstance<span style="color:#808030;">(</span>cls<span style="color:#808030;">,</span> ibase<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">try</span><span style="color:#808030;">:</span>
            cls<span style="color:#808030;">.</span>__instance
        <span style="color:#800000;font-weight:bold;">except</span> <span style="color:#e34adc;">AttributeError</span><span style="color:#808030;">:</span>
            cls<span style="color:#808030;">.</span>__instance <span style="color:#808030;">=</span> new <span style="color:#808030;">(</span>cls<span style="color:#808030;">,</span> ibase<span style="color:#808030;">)</span>
        <span style="color:#800000;font-weight:bold;">return</span> cls<span style="color:#808030;">.</span>__instance

<span style="color:#800000;font-weight:bold;">class</span> StandardMathematicsSystem<span style="color:#808030;">(</span>MathematicsSystem<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
    <span style="color:#800000;font-weight:bold;">def</span> <span style="color:#e34adc;">__init__</span><span style="color:#808030;">(</span>self<span style="color:#808030;">,</span> ibase<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        <span style="color:#800000;font-weight:bold;">if</span> ibase<span style="color:#808030;">.</span>getBase<span style="color:#808030;">(</span><span style="color:#808030;">)</span> <span style="color:#808030;">!</span><span style="color:#808030;">=</span> new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> <span style="color:#008c00;">2</span><span style="color:#808030;">)</span><span style="color:#808030;">:</span>
            <span style="color:#800000;font-weight:bold;">raise</span> NotImplementedError
        self<span style="color:#808030;">.</span>base <span style="color:#808030;">=</span> ibase<span style="color:#808030;">.</span>getBase<span style="color:#808030;">(</span><span style="color:#808030;">)</span>

    <span style="color:#800000;font-weight:bold;">def</span> calculateFactorial<span style="color:#808030;">(</span>self<span style="color:#808030;">,</span> target<span style="color:#808030;">)</span><span style="color:#808030;">:</span>
        result <span style="color:#808030;">=</span> new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span>
        i <span style="color:#808030;">=</span> new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> <span style="color:#008c00;">2</span><span style="color:#808030;">)</span>
        <span style="color:#800000;font-weight:bold;">while</span> i <span style="color:#808030;">&lt;</span><span style="color:#808030;">=</span> target<span style="color:#808030;">:</span>
            result <span style="color:#808030;">=</span> result <span style="color:#808030;">*</span> i
            i <span style="color:#808030;">=</span> i <span style="color:#808030;">+</span> new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> <span style="color:#008c00;">1</span><span style="color:#808030;">)</span>
        <span style="color:#800000;font-weight:bold;">return</span> result

<span style="color:#800000;font-weight:bold;">print</span> StandardMathematicsSystem<span style="color:#808030;">.</span>getInstance<span style="color:#808030;">(</span>new <span style="color:#808030;">(</span>InternalBase<span style="color:#808030;">,</span> new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> <span style="color:#008c00;">2</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span><span style="color:#808030;">.</span>calculateFactorial<span style="color:#808030;">(</span>new <span style="color:#808030;">(</span>IntegralNumber<span style="color:#808030;">,</span> <span style="color:#008c00;">6</span><span style="color:#808030;">)</span><span style="color:#808030;">)</span></pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/159/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=159&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2010/04/21/about-programmers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
		<item>
		<title>Κάτι που όλοι πρέπει να έχουν&#8230;.</title>
		<link>http://c0demasters.wordpress.com/2010/04/19/phenoelit/</link>
		<comments>http://c0demasters.wordpress.com/2010/04/19/phenoelit/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 08:47:13 +0000</pubDate>
		<dc:creator>c0demasters</dc:creator>
				<category><![CDATA[IT-Security Research and News]]></category>

		<guid isPermaLink="false">http://c0demasters.wordpress.com/?p=157</guid>
		<description><![CDATA[Αυτό το link πιστεύω ότι όλοι πρέπει να το έχουν.. είναι κάπως παλιό αλλά τώρα το βρήκα στα αρχεία μου και είπα να το προσθέσω και εδώ.. http://www.phenoelit-us.org/dpl/dpl.html Έχει λίστα με default passwords! Use it as you think better<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=157&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Αυτό το link πιστεύω ότι όλοι πρέπει να το έχουν.. είναι κάπως παλιό αλλά τώρα το βρήκα στα αρχεία μου και είπα να το προσθέσω και εδώ..</p>
<p><a title="Default Password for Telecomunications" href="http://www.phenoelit-us.org/dpl/dpl.html">http://www.phenoelit-us.org/dpl/dpl.html</a></p>
<p>Έχει λίστα με default passwords! Use it as you think better <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c0demasters.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c0demasters.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/c0demasters.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/c0demasters.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c0demasters.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c0demasters.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c0demasters.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c0demasters.wordpress.com/157/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0demasters.wordpress.com&amp;blog=7869630&amp;post=157&amp;subd=c0demasters&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://c0demasters.wordpress.com/2010/04/19/phenoelit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/9c3c70e9ed6d11988de42a0ee323d4bf?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0demasters</media:title>
		</media:content>
	</item>
	</channel>
</rss>
