<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>hackinSTACK</title>
	<atom:link href="http://blog.hackinstack.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.hackinstack.com</link>
	<description></description>
	<pubDate>Mon, 14 Jul 2008 05:15:15 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<language>en</language>
			<item>
		<title>Firewall Build: Part II</title>
		<link>http://blog.hackinstack.com/2008/07/11/firewall-build-part-ii/</link>
		<comments>http://blog.hackinstack.com/2008/07/11/firewall-build-part-ii/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 02:34:39 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Miscellaneous]]></category>

		<category><![CDATA[c3]]></category>

		<category><![CDATA[epia]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[ipcop]]></category>

		<category><![CDATA[linux]]></category>

		<category><![CDATA[VIA]]></category>

		<category><![CDATA[web proxy]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=74</guid>
		<description><![CDATA[Now continuing my ongoing saga of trying to get the VIA EPIA 800 board to boot a Linux kernel&#8230;

I finally gave up on using Fedora. I couldn&#8217;t get any of the default installs to work and I was not looking forward to trying to cross-compile a custom kernel from my AMD64 machine to the supposed-working [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Now continuing my ongoing saga of trying to get the VIA EPIA 800 board to boot a Linux kernel&#8230;</p>
<p><span id="more-74"></span></p>
<p>I finally gave up on using Fedora. I couldn&#8217;t get any of the default installs to work and I was not looking forward to trying to cross-compile a custom kernel from my AMD64 machine to the supposed-working i586 target type that the VIA is supposed to work under.</p>
<p>At the suggestion of a friend I tried installing the latest version of Ubuntu. (Server edition v8.04) Initially the install failed during CD-ROM detection with a &#8220;Failed to copy file..&#8221; error. The odd thing is that the kernel would boot off the install media and I could drop to a shell and browse the contents which were mounted under /media/cdrom just fine. After searching endlessly through unanswered forum posts I finally decided to try swapping my CD as the primary master and the HDD as secondary master &#8212; this did the trick. The installation continued until finally bailing out with numerous errors about either copying, validating or uncompressing packages.</p>
<p>A quick reboot later and I had yet another dead installation&#8230;</p>
<p>I was about ready to give up when I tried a &#8220;hail mary&#8221; install of the <a title="IPCop" href="http://www.ipcop.org/" target="_blank">IPCop</a> distribution. At first glance it looked like the Fisher-Price version of my-first-firewall. (dangerous interface is labeled RED and internal network is labeled GREEN)  But after closer inspection it looks like it is built on a solid platform. The kernel is compiled for a compatible instruction set for the VIA EPIA C3 by default apparently because after a fairly painless install with only one hiccup<strong>**</strong> I had a working kernel on the hardware.</p>
<p><strong>**Note</strong>: for whatever reason (my guess is it is formatting related) the install takes <em>forever </em>to setup the &#8220;logging&#8221; partition. I thought it was hung, but was frustrated and after taking a break to go eat dinner and letting it run I came back and it had continued through to the rest of the install.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/74/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/74/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/74/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/74/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/74/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=74&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/07/11/firewall-build-part-ii/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>
	</item>
		<item>
		<title>Defcon Badge-hacking &#8216;08</title>
		<link>http://blog.hackinstack.com/2008/07/10/defcon-badge-hacking-08/</link>
		<comments>http://blog.hackinstack.com/2008/07/10/defcon-badge-hacking-08/#comments</comments>
		<pubDate>Thu, 10 Jul 2008 14:56:52 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Electronics]]></category>

		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[blackhat]]></category>

		<category><![CDATA[defcon]]></category>

		<category><![CDATA[badge hacking]]></category>

		<category><![CDATA[badges]]></category>

		<category><![CDATA[joe grand]]></category>

		<guid isPermaLink="false">http://blog.hackinstack.com/?p=78</guid>
		<description><![CDATA[
Turns out there are some changes going on this year for Defcon badge hackers. Joe Grand, designer of the badge for the last 3 years has announced plans to pre-release some of the specs of this years design before the conference. (traditionally the badge details have been a big secret and eagerly anticipated until opening [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p style="text-align:center;"><a href="http://picasaweb.google.com/trey.keifer/HackinSTACK/photo#5221403044973697458"><img class="aligncenter" src="http://lh6.ggpht.com/trey.keifer/SHYmZ7zM2bI/AAAAAAAAA_c/C6jYPg47pcY/s144/defconlogo.gif.jpg" alt="" width="144" height="33" /></a></p>
<p>Turns out there are some changes going on this year for Defcon badge hackers. Joe Grand, designer of the badge for the last 3 years has announced plans to pre-release some of the specs of this years design before the conference. (traditionally the badge details have been a big secret and eagerly anticipated until opening day)</p>
<p><span id="more-78"></span></p>
<p>This was a concern to me&#8230; There is a contest centered around the best &#8220;hacks&#8221; of the badges and, <span style="text-decoration:line-through;">in previous years, the winners received a coveted &#8220;black&#8221; badge</span> (correction, see comments) which (in addition to being really cool) also allowed lifetime entrance into Defcon.</p>
<p><span style="font-weight:bold;">Ever since I found this out last year I&#8217;ve been obsessed with winning one&#8230;</span> <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I sent Joe a message directly asking if they would continue this and received this response&#8230; &#8220;I&#8217;m not sure if DT is planning to this year.&#8221;</p>
<p>AHH! it&#8217;s not even that I can&#8217;t afford to buy my way in every year, it is just my own personal pride that drove me to want to win this contest. See&#8230; part of the &#8220;cool-factor&#8221; for me personally was being able to source the parts necessary and put it all together at the conference and not in the comfort of my home. This, in my opinion gets to the true nature of hacking &#8212; resourcefulness, ingenuity and function before form &#8212; the way our hobby started.</p>
<p>Joe encouraged me to still submit this year regardless of the changes&#8230; so in keeping with the spirit of the event I plan to continue with my idea even with the changes. I&#8217;m still keeping the details under wraps for now, but keep an eye here for more information once I pick everything up opening day&#8230;</p>
<p>Until that time, I will be updating this entry with the leaked details as I discover them:</p>
<p>Defcon 2008 badge details:</p>
<ul>
<li><a title="Freescale Flexis MC9S08JM60" href="http://www.embeddeddeveloper.com/processors/2451/Freescale-Semiconductor/MC9S08JM60.htm" target="_blank">Freescale Flexis MC9S08JM60</a> processor</li>
<li>LED integration: &#8220;Yes, there are a few 0603 LEDs on board&#8221; <a title="[1]" href="https://forum.defcon.org/showthread.php?t=9502&amp;highlight=badge" target="_blank">[1]</a></li>
<li>SDCard integration: &#8220;Bring an SD card for maximum enjoyment and benefit&#8221; <a title="[1]" href="https://forum.defcon.org/showthread.php?t=9502&amp;highlight=badge" target="_blank">[1]</a></li>
</ul>
<p>&#8230;and predictions from me: (as I brainstorm them)</p>
<ul>
<li>the uC supports infrared, and Joe has mentioned it. I predict some sort of communication between badges over infrared. The badges haven&#8217;t ever talked to each other (that I know of) and I think it would be cool to see.</li>
<li>SDCard will be used to store transmitted messages. This would make perfect sense for the cards, although the recommendation for 64M sounds huge, so I&#8217;m wondering what exactly we are going to be exchanging.</li>
</ul>
<p>Stay tuned for updates until I get my hands on mine opening day this year&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/78/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/78/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/78/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/78/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/78/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=78&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/07/10/defcon-badge-hacking-08/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>

		<media:content url="http://lh6.ggpht.com/trey.keifer/SHYmZ7zM2bI/AAAAAAAAA_c/C6jYPg47pcY/s144/defconlogo.gif.jpg" medium="image" />
	</item>
		<item>
		<title>Mobile Posting&#8230;</title>
		<link>http://blog.hackinstack.com/2008/07/09/mobile-posting/</link>
		<comments>http://blog.hackinstack.com/2008/07/09/mobile-posting/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 14:54:57 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[iPhone]]></category>

		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://blog.hackinstack.com/2008/07/09/mobile-posting/</guid>
		<description><![CDATA[I just read that WordPress hosted (the location of this blog) now supports mobile posts from iPhones. This is awesome for me as I have A) lots of commuting time on trains, buses and subway cars to think up crazy ideas and B) own a first-gen hacked to the T-Mobile network.
In honor of these added [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I just read that WordPress hosted (the location of this blog) now supports mobile posts from iPhones. This is awesome for me as I have A) lots of commuting time on trains, buses and subway cars to think up crazy ideas and B) own a first-gen hacked to the T-Mobile network.</p>
<p>In honor of these added features, I made this post over my iPhone - look for more frequent updates (albeit a bit shorter and less flashy when mobile) in the future&#8230;.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/75/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/75/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/75/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/75/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/75/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=75&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/07/09/mobile-posting/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>
	</item>
		<item>
		<title>Improved Clock-Skew Techniques</title>
		<link>http://blog.hackinstack.com/2008/07/01/improved-clock-skew-techniques/</link>
		<comments>http://blog.hackinstack.com/2008/07/01/improved-clock-skew-techniques/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 14:32:52 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Miscellaneous]]></category>

		<category><![CDATA[cryptography]]></category>

		<category><![CDATA[crystal oscillators]]></category>

		<category><![CDATA[prng]]></category>

		<category><![CDATA[random number]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=73</guid>
		<description><![CDATA[I wanted to point out a new article that is in my shared RSS section right now on improved clock-skew techniques. When this first came out I heard a lot of talk about how it was too &#8220;theoretical&#8221; or obscure to be considered much of a threat&#8230;
It is important to remember that when buffer overflows [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I wanted to point out a new article that is in my shared RSS section right now on improved clock-skew techniques. When this first came out I heard a lot of talk about how it was too &#8220;theoretical&#8221; or obscure to be considered much of a threat&#8230;</p>
<p>It is important to remember that when buffer overflows really first hit the mainstream, many people also considered it too obscure or difficult to be useful. But now that our understanding of them has grown, we have things like the Metasploit archive that even the script kiddies can cut-and-paste from to their hearts delight.</p>
<p>This research is based on a sound problem - that being that crystal oscillators can vary slightly due to load induced temperature variances. I think it is an exciting topic if only because of the fact that it mixes hardware and software (which I get a big kick out of) but also because the implications to cryptography are very real if it can be reliably leveraged&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/73/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/73/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/73/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/73/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/73/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=73&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/07/01/improved-clock-skew-techniques/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>
	</item>
		<item>
		<title>Firewall Build: Part I</title>
		<link>http://blog.hackinstack.com/2008/06/30/firewall-build-part-i/</link>
		<comments>http://blog.hackinstack.com/2008/06/30/firewall-build-part-i/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 02:18:12 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Internet &amp; Tech]]></category>

		<category><![CDATA[fedora]]></category>

		<category><![CDATA[firewall]]></category>

		<category><![CDATA[mini-itx]]></category>

		<category><![CDATA[PicoPSU]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=71</guid>
		<description><![CDATA[I have been frustrated time and time again by my Linksys combo router/gateway device. While it normally works OK, it lacks a lot of the configuration and functionality of a &#8220;real&#8221; firewall and gateway device and I worry about the shady TCP/IP stack implementation Cisco came up with. This article will document the process of [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I have been frustrated time and time again by my Linksys combo router/gateway device. While it normally works OK, it lacks a lot of the configuration and functionality of a &#8220;real&#8221; firewall and gateway device and I worry about the shady TCP/IP stack implementation Cisco came up with. This article will document the process of building up a VIA mini-itx board as a dedicated firewall/gateway device for my home network&#8230;</p>
<p><span id="more-71"></span></p>
<p>First-thing-first, this project has ended up being a major pain. It was not smooth by any means&#8230;</p>
<p>The platform I chose to go with was an EPIA mini-itx motherboard with a VIA chipset. These are very small form-factor boards with much of the same functionality of bigger systems. This specific model is a C3 800mhz processor which supports up to 1Gb of onboard RAM. The product documentation says it boots via USB, but do not trust it. The implementation is extremely flawed. The specific BIOS version I have only had options for USB-FDD and USB-ZIP, neither of which worked with my bootable USB linux distro&#8217;s. I even tried fdisk&#8217;ing the USB key *exactly* to the specifications of the partitions for the USB-ZIP implementations&#8230; and still no luck.</p>
<p>Recent versions of VIA&#8217;s boards supposedly fix these headaches, but you have been warned&#8230;</p>
<p>The single network port will connect to the internal network and the external interface will be done through USB to the cable modem. The board does not support USB 2.0 but I do not think this will prevent me from using it.</p>
<p>Power will come from the PicoPSU devices which plug directly into the ATX connectors on the motherboard. These slick little devices take 12v power from a standard 5mm barrel connector and convert it for use on the board and accessories. I purchased a 12v 100w LCD power adapter to provide the juice to the PicoPSU and it seems to work just fine. The fact that these devices are fanless also make for very silent operation.</p>
<p>Note that your AC Adapter must supply the minimum Amps for the PicoPSU or it will never boot your board. I learned this the hard way after trying a hundred old wall-warts I had laying around.</p>
<p>Additionally, the PicoPSU cannot dissipate the power necessary for driving alot of accessory drives like full-size CDRom&#8217;s, etc&#8230; this leaves you with very few options for installing your OS if you have been keeping track.</p>
<p>Storage will be done off of a 40GB Toshiba HDD. I got one from an old laptop off ebay and it works just fine.</p>
<p>All of this will be placed in a mobile-computing mini-itx case (also obtained via eBay) and mounted securely to a plywood mount on the wall of my wiring closet. I picked everything up off eBay for about $200.</p>
<p>So far, so good on hardware &#8212; I&#8217;m to the point of installing Fedora and its proved a difficult challenge&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/71/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/71/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/71/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/71/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/71/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=71&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/06/30/firewall-build-part-i/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>
	</item>
		<item>
		<title>Why I go to BlackHat</title>
		<link>http://blog.hackinstack.com/2008/06/27/why-i-go-to-blackhat/</link>
		<comments>http://blog.hackinstack.com/2008/06/27/why-i-go-to-blackhat/#comments</comments>
		<pubDate>Fri, 27 Jun 2008 16:15:41 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[blackhat]]></category>

		<category><![CDATA[defcon]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=72</guid>
		<description><![CDATA[Although I am not part of the &#8220;Black Hat Bloggers Network&#8221; (I wasn&#8217;t even aware that there was one) I noticed this post over at www.stillsecureafteralltheseyears.com (which also wins the award for longest security related domain name) titled - Why go to Blackhat?

Since this will be my third year attending I felt experienced enough to [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Although I am not part of the &#8220;Black Hat Bloggers Network&#8221; (I wasn&#8217;t even aware that there was one) I noticed this post over at www.stillsecureafteralltheseyears.com (which also wins the award for longest security related domain name) titled - Why go to Blackhat?</p>
<p><span id="more-72"></span></p>
<p>Since this will be my third year attending I felt experienced enough to answer:</p>
<p>Here is why I go to BlackHat (and what I stay away from):</p>
<p>- <span style="font-weight:bold;">Training</span>: my company offers one paid training session per year (typically) and I want the absolute best for my (and the company&#8217;s) dollar. Very few other conferences offer the quality of BlackHat - with CanSecWest being a notable exception.</p>
<p>- <span style="font-weight:bold;">Topics</span>: I&#8217;ve noticed over the years that BlackHat topics give a good &#8220;state-of-the-union&#8221; of the security industry. You get to see the familiar names and what they have been, or are, working on. Depending on what tools, talks, books, etc&#8230; are being discussed you generally know what the major threat areas are and can pick out who is winning and who is losing in the infosec battle.</p>
<p>- <span style="font-weight:bold;">Vendors</span>: I do not go for vendors. They are great for the parties, but I&#8217;ve seen it turn into more of a status thing over the years - &#8220;Oh, you don&#8217;t have a pass to the Microsoft party &#8212; oh, you must not be of the *in* crowd&#8221; (give me a break!) I can get just as drunk with 3 of my friends than I can with all of the Microsoft Security Team&#8230; don&#8217;t be one of these guys&#8230; as a side note, I still owe Cisco a remote root advisory in IOS for locking me out of *MY* club for their private party at Wet in Caesars last year <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>- <span style="font-weight:bold;">Books</span>: They are cheaper at Amazon. Don&#8217;t fall for paying full price at the table. I will say &#8220;authors&#8221; though, because quite a few have come up to chat when I picked up their publications while standing around the table. (Hi Pedram) And I can get a better feel in 5mins of talking to them whether it is worth reading.</p>
<p>- <span style="font-weight:bold;">Coworkers</span>: Security is a close knit group, we all know each other. BlackHat is one of the few (only) places that I can catch up with people I haven&#8217;t seen in awhile. It is the one week out of the year that 90% of the fun assessment guys are not being contracted out.</p>
<p>- <span style="font-weight:bold;">Vegas</span>: Been there done that&#8230; I wish someday they would choose another venue, but I realize there are always &#8220;first-timers&#8221; that haven&#8217;t been and would lament them moving it. Morality aside, if you do not like dealing with the party crowd, for gods sake, get out of there before the weekend crowds come.</p>
<p>- <span style="font-weight:bold;">Vacation</span>: it is the only &#8220;vacation&#8221; I take throughout the year&#8230; <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>&#8230;and a bonus:</p>
<p>- <span style="font-weight:bold;">Defcon</span>: go to defcon, its free anyway if you went to BH and it is a completely different crowd. It gives a well-rounded view of what being a &#8220;h4&#215;0r&#8221; is and is not&#8230; plus, the badges kick ass!</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/72/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/72/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=72&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/06/27/why-i-go-to-blackhat/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>
	</item>
		<item>
		<title>Shared RSS Syndication</title>
		<link>http://blog.hackinstack.com/2008/06/12/shared-rss-syndication/</link>
		<comments>http://blog.hackinstack.com/2008/06/12/shared-rss-syndication/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 00:54:23 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Miscellaneous]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=69</guid>
		<description><![CDATA[I&#8217;ve added a new feature here. Sometimes I find things that are interesting, but off topic for the blog. (they fall outside of the technology/hardware/hacking realm or are re-hashes of other people&#8217;s work) In order to still share these little gems, but keep the pages here on-topic I&#8217;ve added the &#8220;My Shared RSS&#8221; section on [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve added a new feature here. Sometimes I find things that are interesting, but off topic for the blog. (they fall outside of the technology/hardware/hacking realm or are re-hashes of other people&#8217;s work) In order to still share these little gems, but keep the pages here on-topic I&#8217;ve added the &#8220;My Shared RSS&#8221; section on the right-hand sidebar. These are listings of items that I have marked as share-able in my google RSS feed list. Many of them will be quite intriguing little things I&#8217;ve found, but have decided (for one reason or another) are better being linked to off site, than me opening a post here on&#8230; I hope you will check them out and enjoy&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/69/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/69/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/69/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=69&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/06/12/shared-rss-syndication/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>
	</item>
		<item>
		<title>Bigfoot on Mars?</title>
		<link>http://blog.hackinstack.com/2008/06/01/bigfoot-on-mars/</link>
		<comments>http://blog.hackinstack.com/2008/06/01/bigfoot-on-mars/#comments</comments>
		<pubDate>Sun, 01 Jun 2008 19:34:03 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Miscellaneous]]></category>

		<category><![CDATA[bigfoot]]></category>

		<category><![CDATA[nasa]]></category>

		<category><![CDATA[phoenix]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=68</guid>
		<description><![CDATA[
A funny photo indeed&#8230; This latest image from the home page of the NASA Phoenix mission reveals the secret evidence many people have hunted for clues on for so many years. Where is Bigfoot?
Apparently we now know why he has avoided detection for so long. He is obviously an interplanetary travel with a primary residence [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://picasaweb.google.com/trey.keifer/HackinSTACK/photo#5206996572455258466"><img class="alignleft" style="float:left;margin:10px;" src="http://lh5.ggpht.com/trey.keifer/SEL3y3ffSWI/AAAAAAAAA18/xvvVEgsyTj0/s144/ne_208.jpg" alt="" /></a></p>
<p>A funny photo indeed&#8230; This latest image from the home page of the <a href="http://www.nasa.gov/mission_pages/phoenix/main/index.html" target="_blank">NASA Phoenix</a> mission reveals the secret evidence many people have hunted for clues on for so many years. Where is Bigfoot?</p>
<p>Apparently we now know why he has avoided detection for so long. He is obviously an interplanetary travel with a primary residence on Mars and a vacation home here on Earth. This image provides unmistakable evidence of the fact that he (or she, to be fair, since we are pretty sure they do not reproduce asexually) has been on the planet the whole time and has obviously come by to check out the latest lander craft and possibly to help NASA make some repairs here and there. (I mean, come on, do you really think they can fix these landers all the time from the control center, just fiddling on their keyboards)</p>
<p>I can&#8217;t wait to see the stories once the *real* conspiracy theorists get ahold of this one&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/68/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/68/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=68&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/06/01/bigfoot-on-mars/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>

		<media:content url="http://lh5.ggpht.com/trey.keifer/SEL3y3ffSWI/AAAAAAAAA18/xvvVEgsyTj0/s144/ne_208.jpg" medium="image" />
	</item>
		<item>
		<title>Schematic Design Software</title>
		<link>http://blog.hackinstack.com/2008/05/21/schematic-design-software/</link>
		<comments>http://blog.hackinstack.com/2008/05/21/schematic-design-software/#comments</comments>
		<pubDate>Thu, 22 May 2008 01:20:40 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Electronics]]></category>

		<category><![CDATA[cadsoft]]></category>

		<category><![CDATA[eagle]]></category>

		<category><![CDATA[pcb]]></category>

		<category><![CDATA[schematics]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=65</guid>
		<description><![CDATA[I was all ready to publish an entry last night on how horrible most of the PCB design tools I&#8217;ve used are, when today I stumbled upon the new version of Cadsoft Eagle v5.0 and OH MY! did they ever fix alot of the headaches from before.

The interface has been polished up, non-standard buttons have [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I was all ready to publish an entry last night on how horrible most of the PCB design tools I&#8217;ve used are, when today I stumbled upon the new version of <a href="http://www.cadsoft.de/" target="_blank">Cadsoft Eagle v5.0</a> and <strong>OH MY!</strong> did they ever fix alot of the headaches from before.</p>
<p><img class="alignright" style="border:1px solid black;float:right;" src="http://lh4.ggpht.com/trey.keifer/SDTKy5UkTsI/AAAAAAAAAzU/JyycTLGuqrQ/s144/eagle50e.png" alt="" /></p>
<p>The interface has been polished up, non-standard buttons have been changed and functionality is much more intuitive. It still has its quirks from what I have seen, but the new version shows a real leap in their development of the product. I was able to finally put together some designs that had long sat on the shelf due to my inability to figure out certain bugs in either how the software was designed, or how I was trying to use it.</p>
<p>I strongly suggest going and checking it out. I will be publishing another longer article soon on some new things I&#8217;ve been working on and what functionality in the new version helped me accomplish those goals. Look for the info as soon as I can get them together&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/65/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/65/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/65/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/65/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/65/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=65&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/05/21/schematic-design-software/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>

		<media:content url="http://lh4.ggpht.com/trey.keifer/SDTKy5UkTsI/AAAAAAAAAzU/JyycTLGuqrQ/s144/eagle50e.png" medium="image" />
	</item>
		<item>
		<title>DEP and ASLR Identification</title>
		<link>http://blog.hackinstack.com/2008/05/05/dep-and-aslr-identification/</link>
		<comments>http://blog.hackinstack.com/2008/05/05/dep-and-aslr-identification/#comments</comments>
		<pubDate>Tue, 06 May 2008 02:52:56 +0000</pubDate>
		<dc:creator>tk</dc:creator>
		
		<category><![CDATA[Hacking]]></category>

		<category><![CDATA[Internet &amp; Tech]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[aslr]]></category>

		<category><![CDATA[dep]]></category>

		<category><![CDATA[process explorer]]></category>

		<guid isPermaLink="false">http://hackinstack.wordpress.com/?p=64</guid>
		<description><![CDATA[I&#8217;ve learned recently that good security testing is all too often a shadow of a larger skillset - good debugging knowledge. Because of this I&#8217;ve been following many more of the blogs of individuals on the Windows debugging and advanced troubleshooting teams and learning more about the tools they use to peer deeply into applications [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;ve learned recently that good security testing is all too often a shadow of a larger skillset - good debugging knowledge. Because of this I&#8217;ve been following many more of the blogs of individuals on the Windows debugging and advanced troubleshooting teams and learning more about the tools they use to peer deeply into applications and systems.</p>
<p>Two of the programs which come up often in their troubleshooting are <a href="http://www.microsoft.com/whdc/devtools/debugging/default.mspx" target="_blank">WinDBG</a> and <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" target="_blank">Process Explorer</a>. Having used each extensively over the last few months I noticed a cool new (to me at least) feature in Process Explorer tonight and thought I would share it - this is the <a href="http://en.wikipedia.org/wiki/Data_Execution_Prevention" target="_blank">DEP</a> and <a href="http://en.wikipedia.org/wiki/ASLR" target="_blank">ASLR</a> status tags.</p>
<p>To enable the identification tabs right-click on the column headings in the main window. This brings up a menu which allows you to select the appropriate tags&#8230;</p>
<p><a href="http://picasaweb.google.com/trey.keifer/HackinSTACK/photo#5197092107684007666"><img src="http://lh5.ggpht.com/trey.keifer/SB_HvI99zvI/AAAAAAAAAw4/09e0-YH9aA0/s144/PE-DEP_and_ASLR.png" alt="" /></a></p>
<p>Now you can quickly identify running programs having these features enabled. This is very similar to the information from <a href="http://erratasec.blogspot.com/2007/10/funny-vista-tricks-with-aslr.html" target="_blank">David Maynor&#8217;s</a> LookingGlass utility. (whose link seems to come and go in my bookmarks)</p>
<p>I prefer to have less applications that are more universally powerful than having to download a hundred different software utilities, each with specialized tasks, but YMMV.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/hackinstack.wordpress.com/64/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/hackinstack.wordpress.com/64/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackinstack.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackinstack.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackinstack.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackinstack.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackinstack.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackinstack.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackinstack.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackinstack.wordpress.com/64/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackinstack.wordpress.com/64/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackinstack.wordpress.com/64/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.hackinstack.com&blog=2694434&post=64&subd=hackinstack&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hackinstack.com/2008/05/05/dep-and-aslr-identification/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/hackinstack-128.jpg" medium="image">
			<media:title type="html">tk</media:title>
		</media:content>

		<media:content url="http://lh5.ggpht.com/trey.keifer/SB_HvI99zvI/AAAAAAAAAw4/09e0-YH9aA0/s144/PE-DEP_and_ASLR.png" medium="image" />
	</item>
	</channel>
</rss>