<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1794023487457673746</id><updated>2012-02-16T15:02:11.082-08:00</updated><category term='BASIC'/><category term='WEP'/><category term='Defcon'/><category term='BlackHat'/><title type='text'>EvilPacket</title><subtitle type='html'>Research, opinions and comments about security and technology.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>13</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-2426419971974367740</id><published>2008-06-25T15:39:00.000-07:00</published><updated>2008-06-25T15:41:51.422-07:00</updated><title type='text'>Low-Cost Heads-Up Display Technology</title><content type='html'>http://www.grandideastudio.com/news/patent-granted-for-low-cost-heads-up-display/&lt;br /&gt;&lt;br /&gt;"... describes a low-cost method of displaying information optically on an existing eyewear lens."&lt;br /&gt;&lt;br /&gt;*drool* please make it into a product someday soon..please!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-2426419971974367740?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/2426419971974367740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=2426419971974367740' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/2426419971974367740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/2426419971974367740'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2008/06/low-cost-heads-up-display-technology.html' title='Low-Cost Heads-Up Display Technology'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-1362439457866584780</id><published>2008-06-24T15:10:00.000-07:00</published><updated>2008-06-24T15:15:55.769-07:00</updated><title type='text'>Fridge Magnet Exploit Code</title><content type='html'>&lt;a href="http://www.matasano.com/log/1073/the-web-pest-poet/#comment-326593"&gt;Matasano&lt;/a&gt; has a great idea.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.matasano.com/log/wp-content/uploads/2008/06/mag-3.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px;" src="http://www.matasano.com/log/wp-content/uploads/2008/06/mag-3.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"It’s a perforated sheet of refrigerator magnets with exploit words on them"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-1362439457866584780?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/1362439457866584780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=1362439457866584780' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/1362439457866584780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/1362439457866584780'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2008/06/fridge-magnet-exploit-code.html' title='Fridge Magnet Exploit Code'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-4340334652290449571</id><published>2008-06-23T22:16:00.000-07:00</published><updated>2008-06-23T22:28:32.588-07:00</updated><title type='text'>Team psychoholics and Back to the basics</title><content type='html'>With &lt;a href="http://defcon.org"&gt;Defcon 16&lt;/a&gt; right around the corner that means so is the &lt;a href="http://mysterychallenge.org/"&gt;Mystery Challenge&lt;/a&gt;. Flirzan, lastnight (possibly) and I are registered as team psychoholics and are excited to be competing.&lt;br /&gt;&lt;br /&gt;In other news I'm excited to be getting more into locksport. I have been interested in lockpicking for a while, but always seem to get distracted by some other shiny object. I need to start with the basics and get some new tools. To get back into the swing of things I ordered a 22 piece pickset from &lt;a href="http://www.southord.com/"&gt;Southord&lt;/a&gt; as well as a pimp practice lock from &lt;a href="http://learnlockpicking.com"&gt;learnlockpicking.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-4340334652290449571?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/4340334652290449571/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=4340334652290449571' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/4340334652290449571'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/4340334652290449571'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2008/06/team-psychoholics-and-back-to-basics.html' title='Team psychoholics and Back to the basics'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-349513987843963921</id><published>2008-01-25T10:57:00.000-08:00</published><updated>2008-01-25T11:16:09.912-08:00</updated><title type='text'>Is your Wireless Network Secure?</title><content type='html'>&lt;a href="http://www.dc509.org"&gt;DC509 &lt;/a&gt;Presents: "Is Your Wireless Network Secure?"  &lt;p&gt; DC509, a group of Tri-Cities security professionals, presents their  inaugural community outreach presentation at the Kennewick Branch of the  Mid-Columbia Library on February 16th at 6:00 PM. &lt;a href="http://www.ngenuity-is.com"&gt;Adam Baldwin&lt;/a&gt; will  discuss wireless security options for home and business networks and  methods to secure those wireless networks. The DC509 group will also  show just how easily criminals (or your neighbor) can access wireless  networks with live demonstrations. &lt;/p&gt;  &lt;p&gt; Please bring your wireless network questions, and the group will try to  answer them. &lt;/p&gt; &lt;p&gt; The Kennewick Branch of the Mid-Columbia Library is located at 1620 S. Union, in Kennewick. The library closes at 5PM, so you must enter at the side door. This is  the first in a continuing series of community outreach programs to help  educate and inform our community.&lt;/p&gt;&lt;br /&gt;While it is not mentioned in the description, information that is relevant from a recent &lt;a href="http://www.ngenuity-is.com/"&gt;nGenuity Information Services&lt;/a&gt; wireless research project will be included in the presentation, so attend to get a sneak peek before the paper is published.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-349513987843963921?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/349513987843963921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=349513987843963921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/349513987843963921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/349513987843963921'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2008/01/is-your-wireless-network-secure.html' title='Is your Wireless Network Secure?'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-2157025611211947185</id><published>2007-08-28T19:09:00.000-07:00</published><updated>2007-08-28T19:13:05.228-07:00</updated><title type='text'>This is 2007 right?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_wUYgOi-Gh00/RtTVzbJSvxI/AAAAAAAAAHE/io5-0LFtL9g/s1600-h/SP_A0117.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_wUYgOi-Gh00/RtTVzbJSvxI/AAAAAAAAAHE/io5-0LFtL9g/s320/SP_A0117.jpg" alt="" id="BLOGGER_PHOTO_ID_5103939357154393874" border="0" /&gt;&lt;/a&gt;No comment necessary for this one. (Crowne Plaza, Houston, TX)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-2157025611211947185?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/2157025611211947185/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=2157025611211947185' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/2157025611211947185'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/2157025611211947185'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/this-is-2007-right.html' title='This is 2007 right?'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_wUYgOi-Gh00/RtTVzbJSvxI/AAAAAAAAAHE/io5-0LFtL9g/s72-c/SP_A0117.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-9051737281195712057</id><published>2007-08-21T22:36:00.000-07:00</published><updated>2007-08-21T23:01:20.468-07:00</updated><title type='text'>PCI DSS</title><content type='html'>Compliance standards like Payment Card Industry Data Security Standard (PCI DSS) help define a minimum set of controls that need to be in place to protect some form of information. In the case of PCI you have card holder data. I have been subjected to working with PCI a lot lately. What I have noticed is that companies are not using PCI (and other standards) to augment their security program, but are building their security program to these minimums.&lt;br /&gt;&lt;br /&gt;The approach one should take with compliance programs is to apply them as constraint requirements against their security program.  Implement a real security program and along the way make sure you hit the checkmarks for the standard you will be audited against. I believe one actually ends up with a stronger security posture by taking this hybrid approach.&lt;br /&gt;&lt;br /&gt;This all may seem like common sense, but you would be surprised at the companies that get this 100% backward.&lt;br /&gt;&lt;br /&gt;Tip: Want to know what level of compliance your organization has to be? Compliance levels are owned and decided upon by the card companies themselves. For instance if you accept Visa and do less than 20,000 transactions per year you are &lt;a href="http://usa.visa.com/merchants/risk_management/cisp_merchants.html?it=c%7C/merchants/risk_management/cisp.html%7CDefining%20Your%20Merchant%20Level#anchor_2"&gt;level 4&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;For more information on PCI DSS:&lt;br /&gt;&lt;a href="https://www.pcisecuritystandards.org/"&gt;https://www.pcisecuritystandards.org/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-9051737281195712057?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/9051737281195712057/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=9051737281195712057' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/9051737281195712057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/9051737281195712057'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/pci-dss.html' title='PCI DSS'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-5403809462632224720</id><published>2007-08-20T22:14:00.000-07:00</published><updated>2007-08-20T22:29:58.262-07:00</updated><title type='text'>Santizied input vs sanitized output</title><content type='html'>In a recent visit to a website I found a xss and sql injection vulnerabilities in which the search capability of the site didn't properly sanitize user input. I reported this to the website owner and they promised to fix it and did the very next day. The problem with the fix. Their coders sanitized the output of the keywords, not the input, so all of the other places on that same page they used those keywords was another injection point using a slightly modified input string.&lt;br /&gt;&lt;br /&gt;So if the developer had listened to the original suggestions of input validation they wouldn't have had this secondary issue. I still think that sanitizing output is probably a good idea to avoid any race conditions between time of check and time of use(TOCTOU) in case the value can be manipulated in some other way that might avoid your magical input validation / sanitization.&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;http://www.________.com/search/?search=&amp;amp;query=%22%3E%3Cscript%3Ealert%28%22ESRL%22%29%3B%3C%2Fscript%3E%3C&lt;br /&gt;&lt;br /&gt;Resources:&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Reviewing_code_for_XSS_issues"&gt;Reviewing code for XSS issues&lt;/a&gt; at &lt;a href="http://www.owasp.org"&gt;OWASP&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.gnucitizen.org/xssdb/application.htm"&gt;GNUCitizen XSS DB&lt;/a&gt;&lt;br /&gt;&lt;a href="http://ha.ckers.org/xss.html"&gt;XSS Cheat Sheet&lt;/a&gt; (rsnake)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-5403809462632224720?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/5403809462632224720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=5403809462632224720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/5403809462632224720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/5403809462632224720'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/santizied-input-vs-sanitized-output.html' title='Santizied input vs sanitized output'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-7333885632826823030</id><published>2007-08-20T10:50:00.000-07:00</published><updated>2007-08-20T10:54:14.094-07:00</updated><title type='text'>Team Tapeworm</title><content type='html'>Even though we got a lowly 5th place in the LosT@Con mysterybox challenge, our team (tapeworm) got listed on the front page of &lt;a href="http://www.defcon.org"&gt;defcon.org&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Other stats of interest from the posting&lt;br /&gt;&lt;br /&gt;"Total teams to complete the challenge: 13&lt;br /&gt;      Percentage of teams to complete the challenge: 52%&lt;br /&gt;      Total Boxen weight (combined): 821.128 lbs ;)"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-7333885632826823030?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/7333885632826823030/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=7333885632826823030' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/7333885632826823030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/7333885632826823030'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/team-tapeworm.html' title='Team Tapeworm'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-876362613209746691</id><published>2007-08-10T13:26:00.000-07:00</published><updated>2007-08-10T13:42:49.165-07:00</updated><title type='text'>Reading the signs</title><content type='html'>I have been away from home for 2 weeks and in a foul mood because of it. This actually made me laugh when I got to my gate in Houston (IAH).&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;a href="http://picasaweb.google.com/evilpacket/FromPhone/photo#5097170436155614578"&gt;&lt;img src="http://lh3.google.com/evilpacket/RrzJgXatpXI/AAAAAAAAADk/TuMZLnGPguE/s144/SP_A0108.jpg" /&gt;&lt;/a&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;This made me think. What was the root cause of this crap on the gate board? Was it bad hardware, software bug, l337 h@x0r or just a stupid user at the terminal? How does one efficiently&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;differentiate what is a security incident and what is something else. There is no situation that I can presently think of where a piece of code, hardware or user not performing as expected that does not impact the security of an organization. What is the order of operation an admin should proceed with troubleshooting? Should they consider whatever problem that is encountered to be a security incident and work backwards from there or should they consider it just a problem and until it is proven to be a vulnerability or threat against the company proceed as if it were security related?&lt;br /&gt;&lt;br /&gt;Any thoughts?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-876362613209746691?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/876362613209746691/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=876362613209746691' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/876362613209746691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/876362613209746691'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/reading-signs.html' title='Reading the signs'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-3663084239451352702</id><published>2007-08-05T18:46:00.000-07:00</published><updated>2007-08-05T18:59:26.503-07:00</updated><title type='text'>Mystery Challenge Complete</title><content type='html'>Our team finished the LosT@Con mystery challenge at Defcon 15 in 5th place. We completed it in 25 hours and 6 minutes.&lt;br /&gt;&lt;br /&gt;The challenge required completing many different tasks.&lt;br /&gt;&lt;br /&gt;1. Riddle solving&lt;br /&gt;2. Crypto&lt;br /&gt;3. Lockpicking&lt;br /&gt;4. Social engineering. From what we understand we were the only team that got the maintenance of the hotel to assist with our quest. We were unable to pick the bottom lock soooo we used a drill press. I heard some teams were able to pick it, but I can not confirm that.&lt;br /&gt;5. Constructing a circuit to read a message sent via a led..mmm soldering&lt;br /&gt;6. MORE riddle solving.&lt;br /&gt;..oh and dialing a phone with 1337 skills.&lt;br /&gt;&lt;br /&gt;We were told the team has a guaranteed place in next years mystery challenge so we can bypass any pre-qualification round that might be setup, or at least I hope we can.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-3663084239451352702?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/3663084239451352702/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=3663084239451352702' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/3663084239451352702'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/3663084239451352702'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/mystery-challenge-complete.html' title='Mystery Challenge Complete'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-4204700069384607842</id><published>2007-08-04T02:47:00.000-07:00</published><updated>2007-08-04T02:56:00.158-07:00</updated><title type='text'>Defcon Mystery Box - Phase 1 Complete</title><content type='html'>At 1:30 AM (not sure what day this is...no really I don't know) it was only Tim, myself and one stranger that decided to wander in and help. This was 12.5 hours after we received the first box. A small purple box containing clues.&lt;br /&gt;&lt;br /&gt;1. A pad of paper with 1x21 written in it&lt;br /&gt;2. An alphabet missing the letter e. Letters were printed on little books and were circular cut outs&lt;br /&gt;3. A clue sheet with 185 (or 184 I don't remember) characters of cyphertext.&lt;br /&gt;&lt;br /&gt;Lessons learned. Trust your instinct. The reason it took us so long was that we were using the wrong program (algorithm) to decode the text. If we had used the proper one it would have saved ohhhh about 6-8 hours of number crunching madness!&lt;br /&gt;&lt;br /&gt;We can't get our hardware box or phase 2 box until morning because LosT has gone to bed.... will post screenshots, etc after the contest is done so I don't leak any info, but then again who the fuck reads this thing anyway?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-4204700069384607842?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/4204700069384607842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=4204700069384607842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/4204700069384607842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/4204700069384607842'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/08/defcon-mystery-box-phase-1-complete.html' title='Defcon Mystery Box - Phase 1 Complete'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-5067624028726905401</id><published>2007-07-30T09:37:00.000-07:00</published><updated>2007-07-30T09:45:16.690-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='BlackHat'/><category scheme='http://www.blogger.com/atom/ns#' term='BASIC'/><category scheme='http://www.blogger.com/atom/ns#' term='WEP'/><category scheme='http://www.blogger.com/atom/ns#' term='Defcon'/><title type='text'>Viva Las Vegas</title><content type='html'>Today is a good day. I'm home for once on a Monday.&lt;br /&gt;&lt;br /&gt;Today my BASIC stamp from &lt;a href="http://www.parallax.com/"&gt;Parallax&lt;/a&gt; arrives. Software is so boring anymore that I'm starting to dive back into hardware. I never did know enough about analog electronics so mixing up the stamp with some other assorted parts should be fun.&lt;br /&gt;&lt;br /&gt;I would love to someday put together a hardware WEP cracking device. All of those ap scanners out there that tell you when you have signal should also have a button that cracks the wep key for those wep protected ap's.&lt;br /&gt;&lt;br /&gt;Tomorrow I head to Vegas for BlackHat / Defcon. From what I can gather from the speakers and topics this year should be pretty mindblowing. I'm especially interested in take 2 of Intranet hacking via the web browser. Naughty javascript, spank(). I'm interested to see if they bring up the HTML 5 spec and the global storage and sql support...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-5067624028726905401?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/5067624028726905401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=5067624028726905401' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/5067624028726905401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/5067624028726905401'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/07/viva-las-vegas.html' title='Viva Las Vegas'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1794023487457673746.post-7539220590230103034</id><published>2007-07-24T19:25:00.000-07:00</published><updated>2007-07-24T19:35:58.020-07:00</updated><title type='text'>Defcon 15 - Mystery Challenge</title><content type='html'>I have never participated in a contest at &lt;a href="http://www.defcon.org"&gt;Defcon&lt;/a&gt;. This year at Defcon 15 I will join four other individuals on a team to participate in the &lt;a href="http://www.mysterychallenge.org/"&gt;LosT@Con Mystery Challenge&lt;/a&gt;. Should be an interesting time considering all the forum banter and pictures I have seen from last years. I will post after the contest is over to tell how we did.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1794023487457673746-7539220590230103034?l=evilpacket.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilpacket.blogspot.com/feeds/7539220590230103034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1794023487457673746&amp;postID=7539220590230103034' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/7539220590230103034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1794023487457673746/posts/default/7539220590230103034'/><link rel='alternate' type='text/html' href='http://evilpacket.blogspot.com/2007/07/defcon-15-mystery-challenge.html' title='Defcon 15 - Mystery Challenge'/><author><name>Adam Baldwin</name><uri>http://www.blogger.com/profile/10461188860745846521</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
