<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: If it was me&#8230;</title>
	<atom:link href="http://blog.hazrulnz.net/1557/if-it-was-me.html/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.hazrulnz.net/1557/if-it-was-me.html</link>
	<description>What&#039;s with the blog?</description>
	<lastBuildDate>Tue, 06 Dec 2011 17:11:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: mr_c00l</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57258</link>
		<dc:creator>mr_c00l</dc:creator>
		<pubDate>Wed, 10 Jun 2009 08:04:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57258</guid>
		<description>cool everyone... nobody is perfect in this world. everybody made a mistake. The important thing is we learn from that. And please, keep supporting others too :)

akram, here is the translation of the website.. google is always ur best friends..
http://translate.google.com/translate?js=n&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=http://www.8dou.net/html/article_show_30715.shtml&amp;sl=zh-CN&amp;tl=en&amp;history_state0=</description>
		<content:encoded><![CDATA[<p>cool everyone&#8230; nobody is perfect in this world. everybody made a mistake. The important thing is we learn from that. And please, keep supporting others too <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>akram, here is the translation of the website.. google is always ur best friends..<br />
<a href="http://translate.google.com/translate?js=n&#038;prev=_t&#038;hl=en&#038;ie=UTF-8&#038;u=http://www.8dou.net/html/article_show_30715.shtml&#038;sl=zh-CN&#038;tl=en&#038;history_state0" rel="nofollow">http://translate.google.com/translate?js=n&#038;prev=_t&#038;hl=en&#038;ie=UTF-8&#038;u=http://www.8dou.net/html/article_show_30715.shtml&#038;sl=zh-CN&#038;tl=en&#038;history_state0</a>=</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: spoonfork</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57195</link>
		<dc:creator>spoonfork</dc:creator>
		<pubDate>Mon, 08 Jun 2009 13:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57195</guid>
		<description>With regards to weak passwords: 

In the enterprise: domain controllers and PAM are capable of enforcing the usage of strong passwords enterprise-wide.

Application: it&#039;s entirely up to the developer. When was the last time maybank2u ask it&#039;s user to change password?

Users are hard to educate, but with the right enforcement, education and the correct usage and deployment of the right technology, a lot of problem can be solved.</description>
		<content:encoded><![CDATA[<p>With regards to weak passwords: </p>
<p>In the enterprise: domain controllers and PAM are capable of enforcing the usage of strong passwords enterprise-wide.</p>
<p>Application: it&#8217;s entirely up to the developer. When was the last time maybank2u ask it&#8217;s user to change password?</p>
<p>Users are hard to educate, but with the right enforcement, education and the correct usage and deployment of the right technology, a lot of problem can be solved.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ayoi</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57191</link>
		<dc:creator>ayoi</dc:creator>
		<pubDate>Mon, 08 Jun 2009 10:23:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57191</guid>
		<description>x1337

I think weak passwords are usually concern with human error/problem. And for this layer, I believe it should be governed by security policies.

But then there&#039;s no patch for human stupidity rite? ;)</description>
		<content:encoded><![CDATA[<p>x1337</p>
<p>I think weak passwords are usually concern with human error/problem. And for this layer, I believe it should be governed by security policies.</p>
<p>But then there&#8217;s no patch for human stupidity rite? <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: x1337</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57190</link>
		<dc:creator>x1337</dc:creator>
		<pubDate>Mon, 08 Jun 2009 09:51:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57190</guid>
		<description>RFI is freeking old? how about weak password? :-D</description>
		<content:encoded><![CDATA[<p>RFI is freeking old? how about weak password? <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':-D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Akram</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57187</link>
		<dc:creator>Akram</dc:creator>
		<pubDate>Mon, 08 Jun 2009 05:47:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57187</guid>
		<description>lee, any translation for that web? hehe i totally lost to understand any words in the website, hehehe.

yomuds,

chill bro chill! hehe</description>
		<content:encoded><![CDATA[<p>lee, any translation for that web? hehe i totally lost to understand any words in the website, hehehe.</p>
<p>yomuds,</p>
<p>chill bro chill! hehe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lclee_vx</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57102</link>
		<dc:creator>lclee_vx</dc:creator>
		<pubDate>Fri, 05 Jun 2009 05:20:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57102</guid>
		<description>http://www.8dou.net/html/article_show_30715.shtml</description>
		<content:encoded><![CDATA[<p><a href="http://www.8dou.net/html/article_show_30715.shtml" rel="nofollow">http://www.8dou.net/html/article_show_30715.shtml</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: y0muds</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57036</link>
		<dc:creator>y0muds</dc:creator>
		<pubDate>Thu, 04 Jun 2009 07:38:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57036</guid>
		<description>Dear spoonfork,

We showed/demoed how people can abuse RFI/SQL and command injection problem to get people realize the problems, later on we show them the real problem which is the insecure CODE practices. And we ask them to spot and fix the CODE(in handsout). and later on we ask them to study the apache log to find any pattern of those attacks.

*sighh*.we didn&#039;t bother to get people excited which demoing demm plain and old method of attacking RFI/SQL/etc..etc. Hence the training is cal as &quot;analyzing the intrusion&quot; instead of web hacking.*sighh*.

Dear &#039;my_friend&#039;,

Again, the whole class is to do analysis of RFI attack. seriously, what the fuss is about attacking?. and we&#039;re just try to show the impact of the bugs.*sighh*.That&#039;s the reason why we showing the demo. and demmit, the ctf thingy is just to get people not so sleepy (who want to learn analyzing stuff compare to breaking stuff? : ) ) ..*sighh*. 

And then again, we never ever claim ourself as demm rockstar in infosec world and as always, we have our own weaknesses and learning curve. 

And yes, i told everybody that RFI/SQL is freaking old and everybody know about it (RFI/SQL). But does anyone bother do any free training for analyzing and fixing the bugs to public at large?. &#039;sembang kosong&#039; is always what we do better, dude.:)
 
Do u really were there from the beginning i started our presentation. if u weren&#039;t there and still complaining abt old attack on RFI,u&#039;r absolutely talking out of context. We keep telling ppl that this is the &quot;BASIC and OLD attacks. Please google for more advance RFI/SQL injection stuffs&quot;.*sigh*

Dear ayoi,

since when collecting/analyzing pcap is new  stuff..heheh.just kidding dude. We just want people to be able to analyze their own code and their own web server log and spot any pattern of attacks and react to it.:).yeah, that&#039;s all i guess. we didn&#039;t intend to talk about breaking/hacking stuff at all.

 
Regards,
y0muds
n00b. 
p.s:i apologize in advance if i accidentally offended someone with my comments on ayois&#039; blog.:). sorry.

p.s.s:sorry ayoi for long comments.hahaha</description>
		<content:encoded><![CDATA[<p>Dear spoonfork,</p>
<p>We showed/demoed how people can abuse RFI/SQL and command injection problem to get people realize the problems, later on we show them the real problem which is the insecure CODE practices. And we ask them to spot and fix the CODE(in handsout). and later on we ask them to study the apache log to find any pattern of those attacks.</p>
<p>*sighh*.we didn&#8217;t bother to get people excited which demoing demm plain and old method of attacking RFI/SQL/etc..etc. Hence the training is cal as &#8220;analyzing the intrusion&#8221; instead of web hacking.*sighh*.</p>
<p>Dear &#8216;my_friend&#8217;,</p>
<p>Again, the whole class is to do analysis of RFI attack. seriously, what the fuss is about attacking?. and we&#8217;re just try to show the impact of the bugs.*sighh*.That&#8217;s the reason why we showing the demo. and demmit, the ctf thingy is just to get people not so sleepy (who want to learn analyzing stuff compare to breaking stuff? : ) ) ..*sighh*. </p>
<p>And then again, we never ever claim ourself as demm rockstar in infosec world and as always, we have our own weaknesses and learning curve. </p>
<p>And yes, i told everybody that RFI/SQL is freaking old and everybody know about it (RFI/SQL). But does anyone bother do any free training for analyzing and fixing the bugs to public at large?. &#8216;sembang kosong&#8217; is always what we do better, dude.:)</p>
<p>Do u really were there from the beginning i started our presentation. if u weren&#8217;t there and still complaining abt old attack on RFI,u&#8217;r absolutely talking out of context. We keep telling ppl that this is the &#8220;BASIC and OLD attacks. Please google for more advance RFI/SQL injection stuffs&#8221;.*sigh*</p>
<p>Dear ayoi,</p>
<p>since when collecting/analyzing pcap is new  stuff..heheh.just kidding dude. We just want people to be able to analyze their own code and their own web server log and spot any pattern of attacks and react to it.:).yeah, that&#8217;s all i guess. we didn&#8217;t intend to talk about breaking/hacking stuff at all.</p>
<p>Regards,<br />
y0muds<br />
n00b.<br />
p.s:i apologize in advance if i accidentally offended someone with my comments on ayois&#8217; blog.:). sorry.</p>
<p>p.s.s:sorry ayoi for long comments.hahaha</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: spoonfork</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-57008</link>
		<dc:creator>spoonfork</dc:creator>
		<pubDate>Thu, 04 Jun 2009 04:56:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-57008</guid>
		<description>Demoing an exploit on an application whose configurations allow insecure mode is just NOT the way to educate people. A better example would be exploiting coding errors such as lack of input filtering. Developers have control of their codes, but most likely not configuration of web application servers.

What we need is better education of developers, not to show off what attackers can do.</description>
		<content:encoded><![CDATA[<p>Demoing an exploit on an application whose configurations allow insecure mode is just NOT the way to educate people. A better example would be exploiting coding errors such as lack of input filtering. Developers have control of their codes, but most likely not configuration of web application servers.</p>
<p>What we need is better education of developers, not to show off what attackers can do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ayoi</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-56819</link>
		<dc:creator>ayoi</dc:creator>
		<pubDate>Wed, 03 Jun 2009 06:02:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-56819</guid>
		<description>Well, hats off to the presenters though. They have guts to do those presentations. But then yeah, perhaps nervous or some unforeseen mishaps disrupt the presentation..</description>
		<content:encoded><![CDATA[<p>Well, hats off to the presenters though. They have guts to do those presentations. But then yeah, perhaps nervous or some unforeseen mishaps disrupt the presentation..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: y0nd13</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html/comment-page-1#comment-56792</link>
		<dc:creator>y0nd13</dc:creator>
		<pubDate>Wed, 03 Jun 2009 03:31:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557#comment-56792</guid>
		<description>let Em all complain all they like.  Since complaining is the easiest thing that people can do..</description>
		<content:encoded><![CDATA[<p>let Em all complain all they like.  Since complaining is the easiest thing that people can do..</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.260 seconds -->

