<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>elblogg &#187; security</title>
	<atom:link href="http://blog.elzapp.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.elzapp.com</link>
	<description>blogge v1 (norr bloðga, av *blod) skjære, stikke fisk slik at blodet renner ut, jf *bløgge</description>
	<lastBuildDate>Fri, 09 Jul 2010 13:38:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>e-valg</title>
		<link>http://blog.elzapp.com/2009/03/06/e-valg.html</link>
		<comments>http://blog.elzapp.com/2009/03/06/e-valg.html#comments</comments>
		<pubDate>Fri, 06 Mar 2009 10:14:36 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[misc]]></category>
		<category><![CDATA[demokrati]]></category>
		<category><![CDATA[e-valg]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[fri programvare]]></category>
		<category><![CDATA[norsk]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sikkerhet]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/?p=1217</guid>
		<description><![CDATA[Regjeringen vil visstnok ha elektronisk valg i enkelte kommuner i 2011, og har startet en anbudsrunde på levering av e-valg-løsning. Det som er litt interessant i denne saken er at så godt som alle teknologer er skeptiske, og advarer mot e-valg, samtidig som ingen kan gi noen god begrunnelse på hvorfor vi skal ha det. [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://flickr.com/search/?l=cc&amp;q=evalg"><img src="http://blog.elzapp.com/wp-content/uploads/picture-19.png" alt="evalg illustrasjon" title="evalg illustrasjon" width="274" height="84" class="alignright size-full wp-image-1236"  style="border:2px solid #CCC;padding:5px;margin:5px;" /></a><br />
Regjeringen vil visstnok ha elektronisk valg i enkelte kommuner i 2011, og har <a href="http://www.tu.no/it/article201358.ece">startet en anbudsrunde</a> på levering av e-valg-løsning. Det som er litt interessant i denne saken er at så godt som alle teknologer er skeptiske, og <a href="http://www.tu.no/it/article201062.ece">advarer mot e-valg</a>, samtidig som ingen kan gi noen god begrunnelse på hvorfor vi skal ha det. Den eneste begrunnelsen jeg har sett, og som jeg kan komme på selv, er at opptellingen vil gå raskere. Det kan i neste runde gjøre at en kan gjøre mer <em>show</em> ut av valgnatten på TV, siden valgresultatet kan komme før folk legger seg for kvelden. Videre kan kanskje det føre til et større engasjement for valget. Men her er det mange <em>hvis</em> og <em>kan</em>, dessuten mener jeg det er feil vektor å angripe manglende valgdeltakelse på.</p>
<p>Videre må man ta høyde for at det finnes en del teknofober, og generellt folk som ikke klarer å bruke datamaskiner, nærmest uansett hvor intuitivt og enkelt en prøver å lage det.</p>
<p><del>Det er ikke snakk om valg over internett, og bra er det.</del> <add>Det åpnes også for at en skal på sikt ha stemming over internett.</add> Det er nok sikkerhetskomplikasjoner med e-valg om det ikke går over internett om ikke en skal utsette seg for risikoen ved å gå over internett i tillegg.</p>
<p>Valg skal være <em>anonyme</em> og <em>korrekte</em>, dette er, når en snakker om datasikkerhet to motstridende faktorer. Dvs, ikke direkte, men i og med at de fleste mekanismer for å sikre korrekthet baserer seg på identitet for verifikasjon. Det blir dermed vanskelig å verifisere korrektheten ved dataene selv uten at dataene sendes over internet, og umulig å sikre anonymitet, korrekthet og ikke minst en person &#8211; en stemme når det stemmes over internett.</p>
<p>Jeg mener det ikke foreligger tilstrekkelige fordeler ved å benytte seg av elektronisk valg til at en skal risikere våre demokratiske rettigheter på dene måten.</p>
<p>Men dersom det skulle ende opp med at vi ender opp med elektronisk valg, må det være <strong>et absolutt krav om at programvaren <em>og maskinvaren</em> som benyttes er fri(prog)</strong>, slik at det i allefall kan verifiseres at programvaren og maskinvaren gjør akkurat det den skal.<br />
<span id="more-1217"></span></p>
<h3>Mer om e-valg:</h3>
<ul><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article202920.ece'>tu.no - Slik skal Norge lykkes med e-valg - Teknisk Ukeblad</a></li><li><a href='http://www.nrk.no/'><img src='http://www.nrk.no//favicon.ico' alt='nrk.no:' style='vertical-align:middle' /></a><a href='http://www.nrk.no/nyheter/1.6488679'>Stem elektronisk i 2011 - Nyheter - NRK Nyheter</a></li><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article201358.ece'>E-valget ute på anbud - Teknisk Ukeblad</a></li><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article199510.ece'>tu.no - E-valg kommer i 2011 - Teknisk Ukeblad</a></li><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article187013.ece'>tu.no - Rapport: Lett å hacke e-valg - Teknisk Ukeblad</a></li><li><a href='http://www.idg.no/'><img src='http://www.idg.no//favicon.ico' alt='idg.no:' style='vertical-align:middle' /></a><a href='http://www.idg.no/computerworld/article61334.ece'>Åpner for internettvalg i 2011</a></li><li><a href='http://www.dagbladet.no/'><img src='http://www.dagbladet.no//favicon.ico' alt='dagbladet.no:' style='vertical-align:middle' /></a><a href='http://www.dagbladet.no/nyheter/2007/08/08/508275.html'>- 2011-valget blir elektronisk - Innenriks - Dagbladet.no</a></li><li><a href='http://www.liberaleren.no/'><img src='http://www.liberaleren.no//favicon.ico' alt='liberaleren.no:' style='vertical-align:middle' /></a><a href='http://www.liberaleren.no/arkiv/003483.php'>Liberaleren - din daglige dose frihet</a></li><li><a href='http://www.regjeringen.no/'><img src='http://www.regjeringen.no//favicon.ico' alt='regjeringen.no:' style='vertical-align:middle' /></a><a href='http://www.regjeringen.no/nb/dep/krd/kampanjer/valg/elektroniskstemmegivning.html?id=437385'>E-valg 2011-prosjektet - regjeringen.no</a></li><li><a href='http://avisenagder.no/'><img src='http://avisenagder.no//favicon.ico' alt='avisenagder.no:' style='vertical-align:middle' /></a><a href='http://avisenagder.no/Nyheter/tabid/250/Default.aspx?ModuleId=19113&articleView=true'>Valg på internett i 2011 - Avisen Agder</a></li><li><a href='http://www.aasavis.no/'><img src='http://www.aasavis.no//favicon.ico' alt='aasavis.no:' style='vertical-align:middle' /></a><a href='http://www.aasavis.no/innenriks/politikk/article4138945.ece'>Forsøk med e-valg i 2011 - aasavis.no</a></li><li><a href='http://www.dagbladet.no/'><img src='http://www.dagbladet.no//favicon.ico' alt='dagbladet.no:' style='vertical-align:middle' /></a><a href='http://www.dagbladet.no/2009/02/19/nyheter/valg_2009/politikk/innenriks/regjeringen/4934490/'>Regjeringen åpner for e-valg i 2011 - nyheter - Dagbladet.no</a></li><li><a href='http://www.sb.no/'><img src='http://www.sb.no//favicon.ico' alt='sb.no:' style='vertical-align:middle' /></a><a href='http://www.sb.no/article/20090219/NYHETER/244353136'>Elektronisk valg i 2011?</a></li><li><a href='http://www.vg.no/'><img src='http://www.vg.no//favicon.ico' alt='vg.no:' style='vertical-align:middle' /></a><a href='http://www.vg.no/nyheter/innenriks/artikkel.php?artid=547954'>Forsøk med elektronisk valg i 2011 - VG Nett</a></li><li><a href='http://www.liberaleren.no/'><img src='http://www.liberaleren.no//favicon.ico' alt='liberaleren.no:' style='vertical-align:middle' /></a><a href='http://www.liberaleren.no/2009/02/19/elektronisk-valg-i-norge/'>Elektronisk valg i Norge | Liberaleren</a></li><li><a href='http://www.an.no/'><img src='http://www.an.no//favicon.ico' alt='an.no:' style='vertical-align:middle' /></a><a href='http://www.an.no/nyheter/article4139548.ece'>Vil forsøke elektronisk valg i 2011 - an.no</a></li><li><a href='http://www.bygdeposten.no/'><img src='http://www.bygdeposten.no//favicon.ico' alt='bygdeposten.no:' style='vertical-align:middle' /></a><a href='http://www.bygdeposten.no/lokale_nyheter/article4138586.ece'>Forsøk med elektronisk valg i 2011 - bygdeposten.no</a></li><li><a href='http://www.kommunal-rapport.no/'><img src='http://www.kommunal-rapport.no//favicon.ico' alt='kommunal-rapport.no:' style='vertical-align:middle' /></a><a href='http://www.kommunal-rapport.no/index.gan?id=11193604&subid=0'>E-valgforsøk i 2011 klart i år</a></li><li><a href='http://www.idg.no/'><img src='http://www.idg.no//favicon.ico' alt='idg.no:' style='vertical-align:middle' /></a><a href='http://www.idg.no/computerworld/article121877.ece'>- Evalg er ikke trygt</a></li><li><a href='http://www.eub.no/'><img src='http://www.eub.no//favicon.ico' alt='eub.no:' style='vertical-align:middle' /></a><a href='http://www.eub.no/nyheter/article4140857.ece'>Gi din stemme på internett - eub.no</a></li><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article201062.ece'>Advarer mot e-valg - Teknisk Ukeblad</a></li><li><a href='http://www.idg.no/'><img src='http://www.idg.no//favicon.ico' alt='idg.no:' style='vertical-align:middle' /></a><a href='http://www.idg.no/computerworld/article122125.ece'>- Trygge norske e-valg i 2011</a></li><li><a href='http://www.vg.no/'><img src='http://www.vg.no//favicon.ico' alt='vg.no:' style='vertical-align:middle' /></a><a href='http://www.vg.no/teknologi/artikkel.php?artid=547208'>- E-valg er ikke trygt - VG Nett om Data og nett</a></li><li><a href='http://www.idg.no/'><img src='http://www.idg.no//favicon.ico' alt='idg.no:' style='vertical-align:middle' /></a><a href='http://www.idg.no/computerworld/article122203.ece'>- Du ser ikke at du blir lurt</a></li><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article202329.ece'>Mange kokker på e-valg - Teknisk Ukeblad</a></li><li><a href='http://www.tu.no/'><img src='http://www.tu.no//favicon.ico' alt='tu.no:' style='vertical-align:middle' /></a><a href='http://www.tu.no/it/article202049.ece'>tu.no - 8 år til norsk nettvalg - Teknisk Ukeblad</a></li></ul>
<h4>Aktivitet på twitter</h4>
<ul></ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2009/03/06/e-valg.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>New howto: Using apache to create an authenticated proxy</title>
		<link>http://blog.elzapp.com/2009/03/04/new-howto-using-apache-to-create-an-authenticated-proxy.html</link>
		<comments>http://blog.elzapp.com/2009/03/04/new-howto-using-apache-to-create-an-authenticated-proxy.html#comments</comments>
		<pubDate>Wed, 04 Mar 2009 11:44:50 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[docs]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/?p=1208</guid>
		<description><![CDATA[I just wrote a description on how you can use apache to create an authenticated proxy ahead of your development server, or other http-based servers that doesn&#8217;t provide authentication themselves. You can find it under the docs-section or by clicking here: Using apache to create an authenticated proxy.]]></description>
			<content:encoded><![CDATA[<p>I just wrote a description on how you can use apache to create an authenticated proxy ahead of your development server, or other http-based servers that doesn&#8217;t provide authentication themselves.<br />
You can find it under the <a href="/docs">docs-section</a> or by clicking here: <a href="http://blog.elzapp.com/docs/apache-proxy">Using apache to create an authenticated proxy</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2009/03/04/new-howto-using-apache-to-create-an-authenticated-proxy.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to make wordpress easy upgradeable</title>
		<link>http://blog.elzapp.com/2008/03/31/how-to-make-wordpress-easy-upgradeable.html</link>
		<comments>http://blog.elzapp.com/2008/03/31/how-to-make-wordpress-easy-upgradeable.html#comments</comments>
		<pubDate>Mon, 31 Mar 2008 17:02:13 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[misc]]></category>
		<category><![CDATA[howto]]></category>
		<category><![CDATA[meta]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webdesign]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/?p=308</guid>
		<description><![CDATA[The first thing I have to say about this is keep your worpress up to date at all times! Skipping a release will not only make you vulnerable to hackers, but also make it more difficult to upgrade later. But this, of course is something you already know, lets see what we could do to [...]]]></description>
			<content:encoded><![CDATA[<p>The first thing I have to say about this is <em>keep your worpress up to date at all times</em>! Skipping a release will not only make you vulnerable to hackers, but also make it more difficult to upgrade later. But this, of course is something you already know, lets see what we could do to make it easier to manage this.</p>
<p>Wouldn&#8217;t it be nice if you had a distribution system for wordpress?<br />
Actually, you have! You can use Subversion to install wordpress, and upgrading later is as easy as just switching repositories, if you follow static versions, or svn update if you install from trunk.</p>
<p>This makes upgrades a 4 step procedure (you can cut it down to 2 if you like to live risky, or if you don&#8217;t use custom plugins):</p>
<ul>
<li>Disable all plugins</li>
<li style="text-align: left;">run <code>svn sw http://svn.automattic.com/wordpress/tags/2.5/</code></li>
<li>go to your wp-admin, and update database (one click operation)</li>
<li>Enable your plugins again</li>
</ul>
<p>As mentioned, you may skip the first and the last point.</p>
<p><a href="http://codex.wordpress.org/Installing/Updating_WordPress_with_Subversion">See wordpress.org for more info</a>, on how to switch from a tarball installed wordpress to a svn-installed wordpress, or performing a fresh install from svn.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2008/03/31/how-to-make-wordpress-easy-upgradeable.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Upgraded wordpress again</title>
		<link>http://blog.elzapp.com/2008/03/30/upgraded-wordpress-again.html</link>
		<comments>http://blog.elzapp.com/2008/03/30/upgraded-wordpress-again.html#comments</comments>
		<pubDate>Sun, 30 Mar 2008 13:12:43 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[misc]]></category>
		<category><![CDATA[FOSS]]></category>
		<category><![CDATA[meta]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webdesign]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/?p=303</guid>
		<description><![CDATA[This time from 2.3.3 to 2.5 using subversion. It was dead easy! Though I find the user interface a bit confusing, I&#8217;m very happy to have found a way to keep the blog up-to-date in an easy way. It is very cool to be able to manage photos and galleries inside wordpress too]]></description>
			<content:encoded><![CDATA[<p>This time from 2.3.3 to 2.5 using subversion. It was dead easy! Though I find the user interface a bit confusing, I&#8217;m very happy to have found a way to keep the blog up-to-date in an easy way.</p>
<p><a href="http://blog.elzapp.com/wp-content/uploads/2008/03/wordpress25.png"><img class="aligncenter size-medium wp-image-304" title="wordpress 2.5" src="http://blog.elzapp.com/wp-content/uploads/2008/03/wordpress25-300x93.png" alt="Just had to test the image upload suport" width="300" height="93" /></a></p>
<p>It is very cool to be able to manage photos and galleries inside wordpress too <img src='http://blog.elzapp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2008/03/30/upgraded-wordpress-again.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>w00t?</title>
		<link>http://blog.elzapp.com/2008/03/25/w00t.html</link>
		<comments>http://blog.elzapp.com/2008/03/25/w00t.html#comments</comments>
		<pubDate>Tue, 25 Mar 2008 12:30:34 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[english]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sikkerhet]]></category>
		<category><![CDATA[undring]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/2008/03/25/w00t.html</guid>
		<description><![CDATA[Today I noticed this in my access.log: ?View Code APACHE67.19.113.154 - - [24/Mar/2008:16:02:10 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 &#34;-&#34; &#34;-&#34; 65.111.181.35 - - [24/Mar/2008:20:02:22 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 &#34;-&#34; &#34;-&#34; 67.19.113.154 - - [24/Mar/2008:20:15:38 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 &#34;-&#34; &#34;-&#34; 67.19.113.154 - - [25/Mar/2008:00:26:37 +0100] &#34;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&#34; 400 363 [...]]]></description>
			<content:encoded><![CDATA[<p>Today I noticed this in my access.log:</p>

<div class="wp_codebox_msgheader"><span class="right"><sup><a href="http://www.ericbess.com/ericblog/2008/03/03/wp-codebox/#examples" target="_blank" title="WP-CodeBox HowTo?"><span style="color: #99cc00">?</span></a></sup></span><span class="left"><a href="javascript:;" onclick="javascript:showCodeTxt('p294code2'); return false;">View Code</a> APACHE</span><div class="codebox_clear"></div></div><div class="wp_codebox"><table><tr id="p2942"><td class="code" id="p294code2"><pre class="apache" style="font-family:monospace;">67.19.113.154 - - [<span style="color: #ff0000;">24</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">16</span>:02:<span style="color: #ff0000;">10</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
65.111.181.35 - - [<span style="color: #ff0000;">24</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">20</span>:02:<span style="color: #ff0000;">22</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">24</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">20</span>:<span style="color: #ff0000;">15</span>:<span style="color: #ff0000;">38</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:00:<span style="color: #ff0000;">26</span>:<span style="color: #ff0000;">37</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:04:<span style="color: #ff0000;">37</span>:<span style="color: #ff0000;">39</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
...
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:08:<span style="color: #ff0000;">52</span>:<span style="color: #ff0000;">25</span> +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span>
67.19.113.154 - - [<span style="color: #ff0000;">25</span>/Mar/<span style="color: #ff0000;">2008</span>:<span style="color: #ff0000;">13</span>:05:07 +0100] <span style="color: #7f007f;">&quot;GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1&quot;</span> <span style="color: #ff0000;">400</span> <span style="color: #ff0000;">363</span> <span style="color: #7f007f;">&quot;-&quot;</span> <span style="color: #7f007f;">&quot;-&quot;</span></pre></td></tr></table></div>

<p>What goes on here?<br />
All these requests fail, ofcourse, but in addition to the obvious (404), the client also doesnt supply a <code>Host: </code> header for their HTTP/1.1 requests</p>
<h4>update</h4>
<p>It is safe to assume that this is an attempt to hack me in some way, DFind is appearantly some kind of security scanner<a href="http://www.atlink.it/~conti/2006/03/04/w00tw00tatiscsansdfind-update/"><sup>ref</sup></a>. The same IPs are also bruteforcing some URLs (like /phpmyadmin etc..) looking for somthing fun to poke around with.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2008/03/25/w00t.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Faked secuirty patch</title>
		<link>http://blog.elzapp.com/2004/07/29/faked-secuirty-patch.html</link>
		<comments>http://blog.elzapp.com/2004/07/29/faked-secuirty-patch.html#comments</comments>
		<pubDate>Thu, 29 Jul 2004 13:30:31 +0000</pubDate>
		<dc:creator>elzapp</dc:creator>
				<category><![CDATA[imported]]></category>
		<category><![CDATA[english]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sikkerhet]]></category>

		<guid isPermaLink="false">http://blog.elzapp.com/2004/07/29/faked-secuirty-patch.html</guid>
		<description><![CDATA[I received this mail today: FROM: "Microsoft Corporation Public Assistance" &#60;ozqgiilvehzsmvt_pddoeb@xwaq.com&#62; TO: "Customer" &#60;&#62; SUBJECT: Latest Security Pack MS Customer this is the latest version of security update, the "July 2004, Cumulative Patch" update which eliminates all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express as well as three newly [...]]]></description>
			<content:encoded><![CDATA[<p>I received this mail today:</p>
<pre>
FROM: "Microsoft Corporation Public Assistance" &lt;ozqgiilvehzsmvt_pddoeb@xwaq.com&gt;
TO: "Customer" &lt;&gt;
SUBJECT: Latest Security Pack

MS Customer

this is the latest version of security update, the
"July 2004, Cumulative Patch" update which eliminates
all known security vulnerabilities affecting
MS Internet Explorer, MS Outlook and MS Outlook Express
as well as three newly discovered vulnerabilities.
Install now to maintain the security of your computer
from these vulnerabilities, the most serious of which could
allow an attacker to run executable on your computer.
This update includes the functionality of all previously released patches.

System requirements: Windows 95/98/Me/2000/NT/XP
This update applies to:
 - MS Internet Explorer, version 4.01 and later
 - MS Outlook, version 8.00 and later
 - MS Outlook Express, version 4.01 and later

Recommendation: Customers should install the patch at the earliest opportun=
ity.
How to install: Run attached file. Choose Yes on displayed dialog box.
How to use: You don't need to do anything after installing this item.

Microsoft Product Support Services and Knowledge Base articles can be found=
 on the Microsoft Technical Support web site.

http://support.microsoft.com/

For security-related information about Microsoft products, please visit the=
 Microsoft Security Advisor web site

http://www.microsoft.com/security/

Thank you for using Microsoft products.

Please do not reply to this message.
It was sent from an unmonitored e-mail address and we are unable to respond=
 to any replies.

----------------------------------------------
The names of the actual companies and products mentioned herein are the tra=
demarks of their respective owners.</pre>
<p>This is the text/plain mime-version of the mail. It had a colorful microsoft-look-ish HTML version too.</p>
<p>Of course i knew this mail was a fake, furthermore gmail gave me this message:</p>
<blockquote><p> An attachment named &#8220;pack1919.exe&#8221; was removed from this document as it constituted a security hazard.  If you require this document, please contact the sender and arrange an alternate means of receiving it.</p></blockquote>
<p>Please remember: Microsoft NEVER send security-mail if you&#8217;re not registered at their site for receiving such mail. And they NEVER ever send attatchments with it.</p>
<p>It seems this is a variant of the <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.gibe@mm.html">W32/Gibe@mm</a> (W32/Gibe@mm, WORM_GIBE.A, W32/Gibe-A, I-Worm.Gibe, W32/Gibe.A@mm, Win32.Gibe.A, W32/Gibe@MM) worm. Although the name of the attachment, the greeting line and the subject of the message doesnt match the description at <a href="http://securityresponse.symantec.com">securityresponse</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.elzapp.com/2004/07/29/faked-secuirty-patch.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
