<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cristian Livadaru's blog &#187; Security</title>
	<atom:link href="http://cristian.livadaru.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://cristian.livadaru.net</link>
	<description>... think again ...</description>
	<lastBuildDate>Sat, 24 Jul 2010 19:20:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Telecommunications data retention (aka Vorratsdatenspeicherung)</title>
		<link>http://cristian.livadaru.net/2009/01/22/telecommunications-data-retention-aka-vorratsdatenspeicherung/</link>
		<comments>http://cristian.livadaru.net/2009/01/22/telecommunications-data-retention-aka-vorratsdatenspeicherung/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 10:06:27 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Stupidity]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Big Brother]]></category>
		<category><![CDATA[Telecommunications data retention]]></category>
		<category><![CDATA[Vorratsdatenspeicherung]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/?p=600</guid>
		<description><![CDATA[As more and more countries have implemented laws about Telecommunications data retention, I would like to share my thoughts about this. So Big Brother thinks they can stop Terrorism by the use of Telecommunications data retention. But it is so easy to communicate without leaving a trace. It&#8217;s possible for everyone with a PC and [...]]]></description>
			<content:encoded><![CDATA[<p><a class="thickbox"  href="http://cristian.livadaru.net/wp-content/uploads/2009/01/big_brother.jpg"><img class="alignleft size-medium wp-image-601" title="big_brother" src="http://cristian.livadaru.net/wp-content/uploads/2009/01/big_brother-300x199.jpg" alt="big_brother" width="300" height="199" align="left"/></a>As more and more countries have implemented laws about Telecommunications data retention, I would like to share my thoughts about this. So Big Brother thinks they can stop Terrorism by the use of Telecommunications data retention. But it is so easy to communicate without leaving a trace. It&#8217;s possible for everyone with a PC and a Internet connection to act as a Phone company without being registered anywhere, without anybody knowing that you even exist.<br />
You can buy phone numbers from every corner of the world, the server can also be in any corner of the world where some laws may or may not apply.<br />
Let me explain this with an example. Bart and Homer are a evil Terror organization <img src='http://cristian.livadaru.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  they are planing to blow something up. So Bart wants to call Homer and ask for some details about the Bomb. Let&#8217;s assume Big brother is only recording call details but not the call itself. So Bart calls an access number, this number is connected to a SIP Server (like asterisk).<br />
Once connected to the server he enters Homers number, the server dials his number with a fake caller ID and deletes the CDR (call detail records) after the call. The call is being initiated via a company based in Germany (just an example) and the server with asterisk is somewhere else, let&#8217;s say in China.<br />
So, what will data retention tell us after collecting all this data?</p>
<ul>
<li>Bart has made a call to some number, it is unknown whom this number belongs to. The number has been bought through one of several legal DID Exchnage platforms on the net where you can pay with PayPal or Credit card (which could be stolen), to find out where the number was connected would take a lot of time.
<ul>
<li>Ask the regulation agency, of the country the number belongs to, whom this number belongs</li>
<li>Ask the company owning the number who bought the number from them and the IP of the server it was connected to.</li>
</ul>
</li>
<li>After big brother has got this Data they would know that the number was connected to a server in China so the searching can begin once again.
<ul>
<li>Ask the provider for Details about the owner of the server</li>
<li>Ask for access to the server to search for CDR.</li>
<li>No results where found since the server has been already cleaned up or destroyed etc etc.</li>
</ul>
</li>
<li>On the other side, big brother knows Homer got a phone call on his cell, from a number in Namibia (which of course it&#8217;s fake)</li>
</ul>
<p>So in the end, big brother knows nothing! Of course if they record the content of the call they could have some information but there are ways of avoiding this. Like using a Softphone on a laptop with mobile internet conected to the SIP server via VPN. There are so many ways and all you need is a creditcard, no ID, no personal data, nothing.</p>
<p>So the state is trying to convince us that their intention is to &#8220;protect&#8221; us? I mean come on, you don&#8217;t need to be a genius to come up with something like this.</p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2009/01/22/telecommunications-data-retention-aka-vorratsdatenspeicherung/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You get what you pay for</title>
		<link>http://cristian.livadaru.net/2008/06/09/you-get-what-you-pay-for/</link>
		<comments>http://cristian.livadaru.net/2008/06/09/you-get-what-you-pay-for/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 07:18:40 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[InterNet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Hacked]]></category>
		<category><![CDATA[Hosting]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/?p=471</guid>
		<description><![CDATA[Some time ago I got an hosting account at a cheap company (I won&#8217;t mention any names). All was good and fine until the trouble started. 1. No detailed access logs There is no way to see who logged in when over ftp. The only thing that is logged is the access over the web [...]]]></description>
			<content:encoded><![CDATA[<p>Some time ago I got an hosting account at a cheap company (I won&#8217;t mention any names). All was good and fine until the trouble started.</p>
<p><strong>1. No detailed access logs</strong></p>
<p>There is no way to see who logged in when over ftp. The only thing that is logged is the access over the web interface. This is not enough! I just found out that several index.html and index.php files where modified between april and may. They all where &#8220;infected&#8221; with some extra javascript code. Funny enough, somewhen during this time there was a modification to the FTP server of that provider. All passwords where modified and you had to change the password over the webinterface for all accounts. Strange isn&#8217;t it. There was no official statement about anything getting hacked. </p>
<p><strong>2. Useless webstats</strong></p>
<p>One of my sites hosted there had in a day about 200Gig traffic. Although they promise you about 5000 Gig traffic per month, all my sites where locked down due to bandwidth exceeding. Support told me this:</p>
<blockquote><p>All ***** accounts are allowed to use 167 GB of transfer per day. If you site goes over this limit it will be taken offline until the next day. </p></blockquote>
<p> I tried to find anything about this on their website and find no trace about this limitation. Anyway, the reason for the huge traffic amount was of course someone with bad intentions. It is weird since there is no real website on that account. It was used for exchanging larger files (legal content, no piracy) and nothing that would really be of interest to someone. I couldn&#8217;t find out what was downloaded and from where to cause such huge traffic, the support was of no help and <strong>ALL MY SITES WHERE OFFLINE</strong> for one day. Really all of them! Not just the one causing the traffic. </p>
<p>There where some other minor issues why I don&#8217;t like this provider, but they I can&#8217;t remember now and anyway, like I mentioned, they where minor issues. The two big issues I mentioned above is the reason why I will cancel my account. </p>
<p> </p>
<p>oh yes &#8230; one of the minor issues is they don&#8217;t support sFTP or FTP with SSL, just plain unencrypted FTP. Not very nice.</p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2008/06/09/you-get-what-you-pay-for/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DoS attack</title>
		<link>http://cristian.livadaru.net/2008/02/12/dos-attack-2/</link>
		<comments>http://cristian.livadaru.net/2008/02/12/dos-attack-2/#comments</comments>
		<pubDate>Tue, 12 Feb 2008 12:37:14 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/2008/02/12/dos-attack-2/</guid>
		<description><![CDATA[Since yesterday I am facing a DoS attack on one of my IP&#8217;s The server is being hit by UDP packets on port 80. I could solve some of the issues created by this high load and server are running, but the attack is still going on as I write this with 20Mbit and creating [...]]]></description>
			<content:encoded><![CDATA[<p>Since yesterday I am facing a DoS attack on one of my IP&#8217;s<br />
The server is being hit by UDP packets on port 80. I could solve some of the issues created by this high load and server are running, but the attack is still going on as I write this with 20Mbit and creating traffic of about 9 GB/hour. </p>
<p><a href="/wp-content/uploads/cris/2008/dos_1.png" rel="lightbox"  ><img src="/wp-content/uploads/cris/2008/.thumbs/th_dos_1.png" alt="dos_1.png" title="dos_1.png" align="left" border="0" /></a><br />
<a href="/wp-content/uploads/cris/2008/dos_2.png" rel="lightbox"  ><img src="/wp-content/uploads/cris/2008/.thumbs/th_dos_2.png" alt="dos_2.png" title="dos_2.png"  border="0" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2008/02/12/dos-attack-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On the worm that affects Skype for Windows users &#8211; Heartbeat</title>
		<link>http://cristian.livadaru.net/2007/09/11/on-the-worm-that-affects-skype-for-windows-users-heartbeat/</link>
		<comments>http://cristian.livadaru.net/2007/09/11/on-the-worm-that-affects-skype-for-windows-users-heartbeat/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 14:09:50 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[InterNet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/2007/09/11/on-the-worm-that-affects-skype-for-windows-users-heartbeat/</guid>
		<description><![CDATA[Skype has learned that a computer virus called “w32/Ramex.A” is affecting users of Skype for Windows. Users whose computers are infected with this virus will send a chat message to other Skype users asking them to click on a web link that can infect the computer of the person who receives the message. Please note [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Skype has learned that a computer virus called “w32/Ramex.A” is affecting users of Skype for Windows. Users whose computers are infected with this virus will send a chat message to other Skype users asking them to click on a web link that can infect the computer of the person who receives the message.</p>
<p>Please note that Skype users ONLY become infected after they have downloaded the link and run the malicious software. The chat message, of which there are several versions, is cleverly written and may appear to be a legitimate chat message, which may fool some users into clicking on the link.</p></blockquote>
<p><a href="http://heartbeat.skype.com/2007/09/the_worm_that_affects_skype_fo.html">On the worm that affects Skype for Windows users &#8211; Heartbeat</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2007/09/11/on-the-worm-that-affects-skype-for-windows-users-heartbeat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sistemul de alarma care nu scoate niciun sunet « Actualitatea « Revista Capital</title>
		<link>http://cristian.livadaru.net/2007/09/11/sistemul-de-alarma-care-nu-scoate-niciun-sunet/</link>
		<comments>http://cristian.livadaru.net/2007/09/11/sistemul-de-alarma-care-nu-scoate-niciun-sunet/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 11:30:34 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[fun]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/2007/09/11/sistemul-de-alarma-care-nu-scoate-niciun-sunet-%c2%ab-actualitatea-%c2%ab-revista-capital/</guid>
		<description><![CDATA[Oare sa imi pun si eu asa ceva in masina ? Pentru a-si proteja exponatele cele mai de pret marile magazine folosesc sisteme de alarma avansate sau bodyguarzi masivi. Totusi, magazinul Harrod’s din Londra a considerat ca acestia nu ar fi indeajuns. Retailerul a hotarat sa adopte o masura mai extrema pentru a proteja o [...]]]></description>
			<content:encoded><![CDATA[<p>Oare sa imi pun si eu asa ceva in masina ? </p>
<blockquote><p>Pentru a-si proteja exponatele cele mai de pret marile magazine folosesc sisteme de alarma avansate sau bodyguarzi masivi. Totusi, magazinul Harrod’s din Londra a considerat ca acestia nu ar fi indeajuns. </p>
<p>Retailerul a hotarat sa adopte o masura  mai extrema pentru a proteja o pereche de sandale Rene Caovilla in valoare de 120.000 de dolari, care urmau sa fie prezentate in data de 10 septembrie. </p>
<p>Harrod’s a considerat ca de un sarpe veninos nu se va apropia nimeni, de aceea a introdus unul in vitrina unde sunt expusi pantofii. Cobra egipteana a fost inchiriata sa patruleze prin vitrina in ziua lansarii. Dupa lansare, Harrod’s a restituit reptila proprietarului.</p></blockquote>
<p><a href="http://www.capital.ro/index.php?section=articole&#038;screen=index&#038;id=104265&#038;newsletter_link=1&#038;utm_source=newsletter_zilnic&#038;utm_medium=email">Sistemul de alarma care nu scoate niciun sunet « Actualitatea « Revista Capital</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2007/09/11/sistemul-de-alarma-care-nu-scoate-niciun-sunet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China’s cyber army is preparing to march on America, says Pentagon &#8211; Times Online</title>
		<link>http://cristian.livadaru.net/2007/09/11/china%e2%80%99s-cyber-army-is-preparing-to-march-on-america-says-pentagon-times-online/</link>
		<comments>http://cristian.livadaru.net/2007/09/11/china%e2%80%99s-cyber-army-is-preparing-to-march-on-america-says-pentagon-times-online/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 10:53:57 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[InterNet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/2007/09/11/china%e2%80%99s-cyber-army-is-preparing-to-march-on-america-says-pentagon-times-online/</guid>
		<description><![CDATA[Chinese military hackers have prepared a detailed plan to disable America’s aircraft battle carrier fleet with a devastating cyber attack, according to a Pentagon report obtained by The Times. China’s cyber army is preparing to march on America, says Pentagon &#8211; Times Online creepy &#8230;]]></description>
			<content:encoded><![CDATA[<blockquote><p>Chinese military hackers have prepared a detailed plan to disable America’s aircraft battle carrier fleet with a devastating cyber attack, according to a Pentagon report obtained by The Times.
</p></blockquote>
<p><a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/the_web/article2409865.ece">China’s cyber army is preparing to march on America, says Pentagon &#8211; Times Online</a></p>
<p>creepy &#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2007/09/11/china%e2%80%99s-cyber-army-is-preparing-to-march-on-america-says-pentagon-times-online/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DEranged gives you 100 passwords to Governments &amp; Embassies</title>
		<link>http://cristian.livadaru.net/2007/09/11/deranged-gives-you-100-passwords-to-governments-embassies/</link>
		<comments>http://cristian.livadaru.net/2007/09/11/deranged-gives-you-100-passwords-to-governments-embassies/#comments</comments>
		<pubDate>Tue, 11 Sep 2007 09:44:36 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[InterNet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/2007/09/11/deranged-gives-you-100-passwords-to-governments-embassies/</guid>
		<description><![CDATA[Want to send an email in the name of the Iran embassy ? Or maybe the Indian embassy? Here a list with working passwords to exactly 100 email-accounts to Embassies and Governments around the world DEranged Security » Blog Archive » DEranged gives you 100 passwords to Governments &#038; Embassies]]></description>
			<content:encoded><![CDATA[<p>Want to send an email in the name of the Iran embassy ? Or maybe the Indian embassy?<br />
Here a list with working passwords to exactly 100 email-accounts to Embassies and Governments around the world</p>
<p><a href="http://derangedsecurity.com/deranged-gives-you-100-passwords-to-governments-embassies/">DEranged Security » Blog Archive » DEranged gives you 100 passwords to Governments &#038; Embassies</a></p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2007/09/11/deranged-gives-you-100-passwords-to-governments-embassies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Skype Reads Your BIOS and Motherboard Serial Number</title>
		<link>http://cristian.livadaru.net/2007/02/08/skype-reads-your-bios-and-motherboard-serial-number/</link>
		<comments>http://cristian.livadaru.net/2007/02/08/skype-reads-your-bios-and-motherboard-serial-number/#comments</comments>
		<pubDate>Thu, 08 Feb 2007 10:33:13 +0000</pubDate>
		<dc:creator>Cristian Livadaru</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[InterNet]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://cristian.livadaru.net/2007/02/08/skype-reads-your-bios-and-motherboard-serial-number/</guid>
		<description><![CDATA[This is very interesting. I have no clue what use this could be &#8230; pagetable.com » Blog Archive » Skype Reads Your BIOS and Motherboard Serial Number Skype Reads Your BIOS and Motherboard Serial Number]]></description>
			<content:encoded><![CDATA[<p>This is very interesting. I have no clue what use this could be &#8230; </p>
<p><a href="http://www.pagetable.com/?p=27">pagetable.com » Blog Archive » Skype Reads Your BIOS and Motherboard Serial Number</a><br />
Skype Reads Your BIOS and Motherboard Serial Number</p>
]]></content:encoded>
			<wfw:commentRss>http://cristian.livadaru.net/2007/02/08/skype-reads-your-bios-and-motherboard-serial-number/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
