<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Digital Undercurrents</title>
	<atom:link href="http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=134" rel="self" type="application/rss+xml" />
	<link>http://www.digitalundercurrents.com/blog</link>
	<description>Network And Security Consulting</description>
	<lastBuildDate>Fri, 30 Mar 2012 18:21:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>DNS Attack</title>
		<link>http://www.digitalundercurrents.com/blog/?p=287</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=287#comments</comments>
		<pubDate>Fri, 30 Mar 2012 18:21:28 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Networking]]></category>
		<category><![CDATA[Syndicated]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=287</guid>
		<description><![CDATA[Apparently the loosely organized hacking collective/meme known as Anonymous has announced that they will take out the Internet&#8217;s root DNS servers with a massive DDoS tomorrow. How likely is it that they&#8217;ll succeed? Not very, for a whole host of reasons.]]></description>
				<content:encoded><![CDATA[<p>Apparently the loosely organized hacking collective/meme known as Anonymous has announced that they will take out the Internet&#8217;s root DNS servers with a massive DDoS tomorrow.</p>
<p>How likely is it that they&#8217;ll succeed? Not very, <a href="http://www.cricketondns.com/post.cfm/could-a-ddos-attack-against-the-roots-succeed">for a whole host of reasons</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=287</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MS12-020</title>
		<link>http://www.digitalundercurrents.com/blog/?p=286</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=286#comments</comments>
		<pubDate>Wed, 14 Mar 2012 15:17:53 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=286</guid>
		<description><![CDATA[One of Microsoft&#8217;s recent patches should really be installed right away on any system running Remote Desktop Protocol. It&#8217;s only a matter of time &#8211; weeks at best, days at worst &#8212; before reverse engineers get to work on the patch and start crafting an exploit. Details available at the ISC.]]></description>
				<content:encoded><![CDATA[<p>One of Microsoft&#8217;s recent patches should really be installed right away on any system running Remote Desktop Protocol. It&#8217;s only a matter of time &#8211; weeks at best, days at worst &#8212; before reverse engineers get to work on the patch and start crafting an exploit. <a href="http://isc.sans.org/diary/Why+We+Rated+the+MS12-020+Issue+with+RDP+Patch+Now+/12781">Details available at the ISC</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=286</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SonicWall</title>
		<link>http://www.digitalundercurrents.com/blog/?p=285</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=285#comments</comments>
		<pubDate>Tue, 13 Mar 2012 13:20:03 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=285</guid>
		<description><![CDATA[Apparently Dell has agreed to purchase SonicWall from the private equity group that has owned them for the last couple of years. This should be an interesting transition for current SonicWall customers; hopefully the support experience doesn&#8217;t degrade too terribly much.]]></description>
				<content:encoded><![CDATA[<p>Apparently <a href="http://www.bloomberg.com/news/2012-03-13/dell-to-acquire-sonicwall-from-investor-group-to-gain-security-equipment.html">Dell has agreed to purchase SonicWall </a>from the private equity group that has owned them for the last couple of years. This should be an interesting transition for current SonicWall customers; hopefully the support experience doesn&#8217;t degrade too terribly much.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=285</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Open a Padlock With a Coke Can</title>
		<link>http://www.digitalundercurrents.com/blog/?p=282</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=282#comments</comments>
		<pubDate>Tue, 17 Jan 2012 16:13:39 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Syndicated]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=282</guid>
		<description><![CDATA[Well, I wish I&#8217;d known about this technique the last time I forgot my gym lock combination.]]></description>
				<content:encoded><![CDATA[<p>Well, I wish I&#8217;d <a href="http://www.itstactical.com/skillcom/lock-picking/how-to-open-a-padlock-with-a-coke-can/">known about this technique</a> the last time I forgot my gym lock combination.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=282</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WPS Flaw</title>
		<link>http://www.digitalundercurrents.com/blog/?p=279</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=279#comments</comments>
		<pubDate>Tue, 03 Jan 2012 14:59:41 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=279</guid>
		<description><![CDATA[WPS, or WiFi Protected Setup, is a vendor-neutral scheme to make it easier for computer neophytes to securely configured a home wireless access point. Unfortunately, the PIN-based scheme it uses for authentication is easily bruteforced. From the article: &#8220;When the PIN authentication fails the access point will send an EAP-NACK message back to the client. [...]]]></description>
				<content:encoded><![CDATA[<p>WPS, or WiFi Protected Setup, is a vendor-neutral scheme to make it easier for computer neophytes to securely configured a home wireless access point. Unfortunately, the PIN-based scheme it uses for authentication <a href="https://threatpost.com/en_us/blogs/wifi-protected-setup-flaw-can-lead-compromise-router-pins-122711">is easily bruteforced</a>.</p>
<p>From the article:</p>
<blockquote><p>&#8220;When the PIN authentication fails the access point will send an EAP-NACK message back to the client. The EAP-NACK messages are sent in a way that an attacker is able to determine if the first half of the PIN is correct. Also, the last digit of the PIN is known because it is a checksum for the PIN. This design greatly reduces the number of attempts needed to brute force the PIN. The number of attempts goes from 10<sup>8</sup> to 10<sup>4</sup> + 10<sup>3</sup> which is 11,000 attempts in total.&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=279</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iran Drone</title>
		<link>http://www.digitalundercurrents.com/blog/?p=277</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=277#comments</comments>
		<pubDate>Wed, 21 Dec 2011 13:46:37 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Syndicated]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=277</guid>
		<description><![CDATA[The recent capture of an American drone by Iranian forces has been a hot news item. Interestingly, Iranian engineers are coming forward with information on how it was captured. Rather than trying to crack the encryption on the command-and-control link to the pilot, they used spoofed GPS data to force its autopilot to land in [...]]]></description>
				<content:encoded><![CDATA[<p>The recent capture of an American drone by Iranian forces has been a hot news item. Interestingly, Iranian engineers are coming forward with information on how it was captured. Rather than trying to crack the encryption on the command-and-control link to the pilot, <a href="http://www.csmonitor.com/World/Middle-East/2011/1215/Exclusive-Iran-hijacked-US-drone-says-Iranian-engineer-Video">they used spoofed GPS data </a>to force its autopilot to land in Iran, all the while thinking it was in Kandahar. Nice hack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=277</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nmap Bundling</title>
		<link>http://www.digitalundercurrents.com/blog/?p=274</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=274#comments</comments>
		<pubDate>Wed, 07 Dec 2011 14:46:06 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Legal]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=274</guid>
		<description><![CDATA[Cnet&#8217;s download.com site has apparently begun bundling toolbars and spyware with nmap and other open source tools.]]></description>
				<content:encoded><![CDATA[<p>Cnet&#8217;s download.com site has apparently <a href="http://seclists.org/nmap-hackers/2011/5">begun bundling toolbars and spyware</a> with nmap and other open source tools.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=274</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Printer Attacks</title>
		<link>http://www.digitalundercurrents.com/blog/?p=272</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=272#comments</comments>
		<pubDate>Tue, 29 Nov 2011 15:31:23 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Exploits]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=272</guid>
		<description><![CDATA[HP is looking into some new attacks on their Laserjet printer line, discovered by researchers at Columbia. It seems that the printers will, by default, accept unauthenticated firmware updates sent along with a print job. Uh-oh.]]></description>
				<content:encoded><![CDATA[<p>HP is looking into some <a href="http://www.cccblog.org/2011/11/29/millions-of-printers-open-to-hack-attack/">new attacks on their Laserjet printer line</a>, discovered by researchers at Columbia. It seems that the printers will, by default, accept unauthenticated firmware updates sent along with a print job. Uh-oh.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=272</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>747s</title>
		<link>http://www.digitalundercurrents.com/blog/?p=271</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=271#comments</comments>
		<pubDate>Tue, 15 Nov 2011 13:55:25 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Syndicated]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=271</guid>
		<description><![CDATA[From a post on the Interesting People mailing list: Craig S Wright says: &#8220;I was contracted to test the systems on a Boeing 747. They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 &#8211; VLANs. We managed to break the VLANs and access [...]]]></description>
				<content:encoded><![CDATA[<p>From a post on the Interesting People mailing list:</p>
<p>Craig S Wright says: &#8220;I was contracted to test the systems on a Boeing 747. They had added a new video system that ran over IP. They segregated this from the control systems using layer 2 &#8211; VLANs. We managed to break the VLANs and access other systems and with source routing could access the Engine management systems.&#8221;</p>
<p><a href="https://plus.google.com/u/0/110897184785831382163/posts/5qsNxFEaiML">https://plus.google.com/u/0/110897184785831382163/posts/5qsNxFEaiML</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=271</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Columbia FOG</title>
		<link>http://www.digitalundercurrents.com/blog/?p=270</link>
		<comments>http://www.digitalundercurrents.com/blog/?p=270#comments</comments>
		<pubDate>Tue, 08 Nov 2011 13:30:56 +0000</pubDate>
		<dc:creator>matt</dc:creator>
				<category><![CDATA[Syndicated]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.digitalundercurrents.com/blog/?p=270</guid>
		<description><![CDATA[An interesting, DARPA-funded project over at Columbia: FOG allows for false documents to be created which then &#8220;beacon&#8221; a message back to the originator when they are opened. Clearly, the intent is twofold &#8211; to seed places like Wikileaks with false information, and to ferret out people who are trading in stolen documents.]]></description>
				<content:encoded><![CDATA[<p>An interesting, <a href="http://sneakers.cs.columbia.edu/ids/FOG/">DARPA-funded project over at Columbia</a>: FOG allows for false documents to be created which then &#8220;beacon&#8221; a message back to the originator when they are opened. Clearly, the intent is twofold &#8211; to seed places like Wikileaks with false information, and to ferret out people who are trading in stolen documents.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.digitalundercurrents.com/blog/?feed=rss2&#038;p=270</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
