Slashdot Mirror


User: iago-vL

iago-vL's activity in the archive.

Stories
0
Comments
161
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 161

  1. Re:Credibility anyone? on PayPal Reinstates Fund For WikiLeaker Manning · · Score: 1

    +1. I've been through this exact same thing with Paypal.

  2. Re:A new domain specific language is born on Nmap Developers Release a Picture of the Web · · Score: 2, Informative

    NSE isn't actually domain specific, it's the tried, tested, and fast Lua (with extensions to make it fit with the Nmap scanner). You get the speed of Nmap to find hosts/ports plus the NSE scripts backing it up to do deeper probes.

    Wireshark, Snort, Nmap, and plenty of other tools use Lua for scripting, so it's a valuable language to learn. I recommend it!

  3. Cross breeding... on First Superbugs, Now Superweeds · · Score: 4, Interesting

    I'm sure it doesn't help that the plants that are resistant to roundup will cross-pollinate with the weeds that are supposed to be killed with roundup, thereby making everything resistant. I remember people saying a long time ago that this would happen, and here we are!

  4. Re:Multi-page article on Taking Apart the Energizer Trojan · · Score: 5, Informative

    Haha, I hadn't even thought of that!

    I originally wrote it as a single page, but 60 images + that much text was too much, so I broke it into 4 pages. For what it's worth, I don't have any ads or anything so it's not like I'm profiting from it.

  5. Re:Detect it with Nmap on Energizer USB Battery Charger Software Infects PCs · · Score: 2, Informative

    Yeah, the simple xor 'encryption' is pretty oldschool. I can't believe I didn't notice that right away myself. I didn't see it till I started looking at the send/recv functions.

    As to the CLSID, good thought, but no -- the CLSID isn't a real CLSID, it's just a way of identifying its own commands. Basically, it's a list of if(!strcmpi(command, "clsid1")) { do_this() } elseif(!strcmpi(command, "clsid2")) { do_that() } etc.

    It only has those 9 or so CLSID's included, and if it isn't on the list the command is simply discarded.

    And for what it's worth, the initial "'\x00\x00\x00" that you're seeing is a length (0x27 = the length of the CLSID = ').

  6. Detect it with Nmap on Energizer USB Battery Charger Software Infects PCs · · Score: 3, Informative

    I spent the morning reverse engineering the Trojan and wrote an Nmap script to detect if a remote system is infected. Hope it helps out: http://www.skullsecurity.org/blog/?p=563.

    Ron

  7. Re:Bloat. on Nmap 5.00 Released, With Many Improvements · · Score: 5, Informative

    As the original poster, and the author of a dozen or more Nmap scripts, I agree 100%. If you look at the tool itself, you'll see that everything is fairly separate and independent, even if they share a common codebase -- between the scripting and the "bonus" tools, the core is still fairly tight.

    My comment at the end about the bloat + Emacs was intended 100% as humour, not actual commentary. I'm hoping nobody took it as a legitimate stab at Nmap, because it wasn't.

  8. Re:So... on Taming Conficker, the Easy Way · · Score: 2, Informative

    That's correct. I added a 'safe' parameter last night, since the Connficker check is safe, and have been advocating its use in all my posts (you'll see "script-args=safe=1" in everything). Watch out for that.

    And for what it's worth, even if 'safe' is missing, it's only going to crash stuff that isn't patched for MS08-067.

  9. Re:So... on Taming Conficker, the Easy Way · · Score: 0, Troll

    Glad to hear it! When I wrote the ms08-067 script, I was surprised to see it posted around the Internet -- I wrote it as a demo of what Nmap can do, not as a production-grade scanner, and I guess it ended up being more useful than the other scripts that I've put *far* more work into :)

  10. Re:So... on Taming Conficker, the Easy Way · · Score: 4, Informative

    Hey guys,

    I'm the author of that script, and that's exactly right. I posted a full explanation on my blog.

  11. Re:Mod parent up on Are Long URLs Wasting Bandwidth? · · Score: 1, Troll

    Google and the like don't care what your source IP is, just that you have the proper cookie. Something else is causing your problem.

    (If you want proof, drag a laptop to your friends' houses, and you'll still be logged in)

  12. Re:My thoughts exactly on Huge Supernova Baffles Scientists · · Score: 1, Troll

    Based on the context, even if somebody doesn't know the word, it should still be perfectly cromulent.

  13. Re:Alphabetical_list_of_open_source_games on New Open Source FPS Blood Frontier Shows Promise · · Score: 0

    Can you be more specific? I've played that game a significant amount, and beat a handful of the campaigns, but I've never had any issues that make the game out to be less than professional.

    As a disclaimer, I've never played online, so I don't know how their multiplayer gaming is set up.

  14. Re:LOL on New Law Will Require Camera Phones To "Click" · · Score: 0, Troll

    What about a loudener? Speed cocker? An attachment for shooting down police helicopters?

  15. Re:Keep spreading lies on Downadup Worm — When Will the Next Shoe Drop? · · Score: 0, Flamebait

    Actually, Flash provides a write-only clipboard. It can't read the clipboard unless the user gives it permission (short of some vulnerability in Flash, of course).

  16. Re:From the article on Security Flaws In Aussie Net Filter Exposed · · Score: 1, Troll

    Don't forget that every security patch that Microsoft releases is a hole that blackhats could already have been exploiting. Patches created now could (and often do) fix vulnerabilities dating back to the release of Windows 2000 or Windows NT. There's no way to guarantee that the holes aren't known and exploited by others.

    That being said, any system with proper firewalling mitigates much of the issue. If the only port open to the public network is the one running the proxy software (or whatever it is), then there is very little attack surface.

  17. Re:Sales are low! on Symantec Reports Spate of Attacks Via Recent Windows Flaw · · Score: 1, Troll

    Having worked at Symantec, I can tell you that it's nothing like that. There isn't even yelling or clamoring, it's just business as usual. There aren't even any blinking lights!

    Oh, and John Thompson (the current CEO) isn't involved in the decision, nor is he in the same country as the people who are.

  18. Re:hurp on Prevent Gmail From Emailing Under the Influence · · Score: 2, Funny

    Then I assume you HAVE chopped up your neighbour with an axe because it seemed like a fun thing to do?

  19. Re:That's pretty damning for the CIA and Bush admi on 10 Years of Translated Bin Laden Messages Leaked · · Score: 2, Informative

    Did you actually READ the links you posted? Here's a quote from one of them:

    The lawmakers pointed to an unclassified summary from a report by the National Ground Intelligence Center regarding 500 chemical munitions shells that had been buried near the Iranian border, and then long forgotten, by Iraqi troops during their eight-year war with Iran, which ended in 1988. The U.S. military announced in 2004 in Iraq that several crates of the old shells had been uncovered and that they contained a blister agent that was no longer active. Neither the military nor the White House nor the CIA considered the shells to be evidence of what was alleged by the Bush administration to be a current Iraqi program to make chemical, biological and nuclear weapons.

  20. Re:PFFFFFT on Black Screens For Unauthorized Copies of Windows · · Score: 0

    Or people, like some elderly friends of my family, who were duped and don't understand why Microsoft is harassing them.

  21. Re:Dangerous slide on DHS Official Considered Shock Collars For Air Travelers · · Score: 1, Insightful

    Seems like it should be easy enough. Just start shooting the passengers one by one until they give in and open the door.

    ... please don't tell anybody you got the idea from me!

  22. Re:ITYM... on Register, Others Call Plagiarism in "Limbo of the Lost" Game · · Score: 1, Informative

    I think YOU meant, "Ones own breath" -- when pronouns become possessive, they don't have apostrophes (like "its" and "yours")

    Is there a law yet for people inevitably making a mistake when correcting somebody? If not, we need to coin one. :)

  23. Re:"Open" on Wikia Search Upgrades Get Closer · · Score: 1, Interesting

    You're assuming that it'll be censored and say that way. I doubt that'll be the case -- if a user "censors" something, just like when a user vandalizes Wikipedia, it'll likely be reversed fairly quickly. It would surprise me if this became an issue.

  24. Re:I have this rock on Mars Probe Brings the "Weather Rock" New Respect · · Score: 1, Funny

    Does it keep lions away? Because I have one that does, and it's currently working at 100% capacity.

  25. Re:First time Bush has posted something sane. on President Bush Signs Genetic Nondiscrimination Act · · Score: 4, Insightful

    I think this post, more than any other, called for: [citation needed].