<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>Michal Sobiegraj | Security Consultant and Evangelist</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/" />
   <link rel="self" type="application/atom+xml" href="http://sobiegraj.com/blog/atom.xml" />
   <id>tag:sobiegraj.com,2008:/blog//1</id>
   <updated>2008-10-03T22:55:19Z</updated>
   
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type 3.34</generator>

<entry>
   <title>Why is security awareness important</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/09/why_is_security_awareness_impo_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.72</id>
   
   <published>2008-09-28T15:11:42Z</published>
   <updated>2008-10-03T22:55:19Z</updated>
   
   <summary>Since you are reading this, you probably think security is oh-so important. Well, here is a funny surprise: turns out most people out there actually think that living their lives, doing their business and running their errands is way more...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Marketing security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>Since you are reading this, you probably think security is oh-so important. Well, here is a funny surprise: turns out most people out there actually think that living their lives, doing their business and running their errands  is way more important.</p>

<p>And some of them actually have an idea <a href="http://sethgodin.typepad.com/seths_blog/2008/09/random-travel-t.html">how to make things better</a>. Worth taking into account when your business relies on people buying your security solutions or services. It seems like the very least you should do is to make sure your users and customers understand how THEY benefit from the introduced security measures and why the inconveniences they introduce are absolutely necessary for them to work. And better make sure they really are necessary.<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F09%2Fwhy_is_security_awareness_impo_1.html&amp;title=Why%20is%20security%20awareness%20important&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>Cartoons</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/09/cartoons.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.71</id>
   
   <published>2008-09-23T13:46:10Z</published>
   <updated>2008-10-03T23:33:21Z</updated>
   
   <summary> Last week Tom Fishburne’s This One Time at Brand Camp (his latest cartoon book) got to me finally and I’m here to report to you that it’s been a wonderful read! The cartoons generally talk about marketing. I’m not...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Miscellaneous" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: left;padding-right: 10px;'><a href="http://www.flickr.com/photos/brandcamp/2240150178/in/set-72157603843758644/"><img src="http://farm3.static.flickr.com/2028/2240150178_e6264a7f40_m.jpg" style="width: 240px; height: 185px;" /></a></div>

<p>Last week <a href="http://skydeckcartoons.com/">Tom Fishburne’s</a> <a href="http://stores.lulu.com/tomfishburne">This One Time at Brand Camp</a> (his latest cartoon book) got to me finally and I’m here to report to you that it’s been a wonderful read! The cartoons generally talk about marketing. I’m not a marketing pro or anything, you probably know this, so I think I am a pretty good test for Tom’s toons and their amusingness to a layperson. And I have to say, they passed the test surprisingly well. Even better, I learned quite a bit while laughing out loud. Can you wish for more?</p>

<p>One of the best cartoons from the book (in my opinion of curse) is the one on the left (click it to enlarge).</p>

<p>Brilliant! Not even a word and the message is crystal clear. Makes you nod and go “Right. That’s how it is.” Just brilliant!</p>

<p>Great job Tom! Please keep it going :-)<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F09%2Fcartoons.html&amp;title=Cartoons&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>Usable data encryption for mobile devices</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/09/usable_data_encryption_for_mob_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.70</id>
   
   <published>2008-09-19T14:52:36Z</published>
   <updated>2008-09-19T15:19:57Z</updated>
   
   <summary>It comes to be more and more tempting to store and process important business docs on our mobiles/smart-phones as the devices keep growing bigger, mightier and more usable. Together with the time saving benefits we get from being able to...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>It comes to be more and more tempting to store and process important business docs on our mobiles/smart-phones as the devices keep growing bigger, mightier and more usable. Together with the time saving benefits we get from being able to do the work while on the go, there is also a still growing danger of our precious information being stolen together with the device and used by a thief for whatever evil purpose they intend it to use.</p>

<p>And face it, you wouldn’t work on a report or an email while in a cab or a plane if it wasn’t an essential and really urgent thing to do. So, I guess we can safely assume that the data you have on the device may be worth a lot for someone who knows this and that about your business.</p>

<p>So, what options do we have here? Not getting much into technical details, let’s just try to figure out what could work for someone who most importantly wants to do their job without their phone driving them nuts and secondly wants the solution to provide a reasonable level of security to the precious data in it. It’s quite obvious that we need to encrypt, but how? Again, technical details aside, let’s just focus on user-device interaction.</p>]]>
      <![CDATA[<p>First question seems to be this: <strong>should we encrypt the whole thing or is it enough to encrypt just the important stuff?</strong> If you think about it, in the light of what I said earlier, this question doesn’t make much sense. Just to reiterate: the most important docs that you carry around are about your contemporary business and are accessed a lot and changed a lot. So, if you encrypt these and agree to all the hassle (whatever they might be, like typing in the longish password over and over again), you may as well encrypt also the less important, less frequently or even barely accessed data. And if you do so, you free yourself from the trouble of deciding what is unimportant enough to stay unencrypted and from remembering to actually keep all the important data in an encrypted part of the storage. So, if you can, it seems to be the best option to stick with the whole-memory encryption.</p>

<p>And this leads us to another important question: <strong>how to make this solution at least remotely acceptable to a user?</strong> It’s quite obvious that no sane person would agree to type in a strong password on a phone keyboard (even a QWERTY) each time they need to access their mailbox. And to make the solution reliable it’s quite important to automatically expire the session after a short period of inactivity (hence even more of password typing). Also, what if the phone is taken from us while it’s in use and unlocked?</p>

<p>So, to restate the question: <strong>how could we make it user friendly and mugger unfriendly enough to eventually turn it into a useful feature and not just another pseudo-solution that nobody wants to use?</strong></p>

<p>Here is what we need: 1) a quick and easy way to authenticate (unlock the encryption key and allow memory to be decrypted), 2) a quick way to lock the device and the encryption key when someone wants to snatch our mobile and 3) an automatic device locking mechanism.</p>

<p>So, how about building a quality <strong>fingerprint scanner</strong> into a phone providing an easy way to quickly authenticate and unlock it? As for a quick and super-easy way to automatically lock the device and an encryption key – ever heard of an <strong>accelerometer</strong>? A motion sensor. Some phones already have it, Wii remote has it. How about locking a phone just by shaking it? This way when someone snatches the phone from your hand and runes… well… they may as well wave all the data goodbye as the phone will instantly lock itself. And timer based locking mechanisms, well, that’s been already done like a million times.</p>

<p>Well, Nokia, there you have it! How about a fingerprint scanner and an accelerometer put to some good use in the next business-targeted phone for a change?</p>]]>

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F09%2Fusable_data_encryption_for_mob_1.html&amp;title=Usable%20data%20encryption%20for%20mobile%20devices&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>ISSA meetings in Wrocław back after summer (Sep 23, 2008)</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/09/issa_meetings_in_wroclaw_back_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.69</id>
   
   <published>2008-09-14T13:48:07Z</published>
   <updated>2008-09-16T21:44:15Z</updated>
   
   <summary> [UPDATE: If you are planning to come to the meeting, we will need your name in order for security to let you into the building. So, please send us an email with a subject &quot;[ISSA] Potwierdzenie udziału w spotkaniu...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/issa-logo-small.png' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='110' width='200'/></div>

<p>[UPDATE: If you are planning to come to the meeting, we will need your name in order for security to let you into the building. So, please send us an email with a subject "[ISSA] Potwierdzenie udziału w spotkaniu - Wroclaw 2008-09-23" to wroclaw at issa.org.pl</p>

<p>Be sure to actually include your name!]</p>

<p><br />
I’m happy to invite you to this month’s ISSA meeting on September 23. We'll be talking about security policies and, more on the technical side, about DNS cache poisoning.</p>

<p>When: September 23, 6:30 PM</p>

<p>Where: <a href="http://maps.google.com/maps?f=q&hl=pl&geocode=&q=pl.+Grunwaldzki+25,+Wroc%C5%82aw+&ie=UTF8&ll=51.114246,17.061253&spn=0.011261,0.026479&z=15&iwloc=cent">Credit Suisse, Grunwaldzki Center building B, fourth floor, Grunwaldzki Square 25, Wrocław</a></p>

<p>Agenda:<br />
1. Welcome after summer - Michał Sobiegraj<br />
2. Development and Deployment of Security Policies - Radek Michalski<br />
3. DNS Cache Poisoning (recent update) - Jarek Sajko</p>

<p>We plan to end the official part of the meeting around 8:30.</p>

<p>See you!<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F09%2Fissa_meetings_in_wroclaw_back_1.html&amp;title=ISSA%20meetings%20in%20Wroc%C5%82aw%20back%20after%20summer%20%28Sep%2023%2C%202008%29&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>New biz-cards</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/09/new_bizcards_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.68</id>
   
   <published>2008-09-12T13:26:06Z</published>
   <updated>2008-09-12T14:04:37Z</updated>
   
   <summary> As some say (me included), it’s nice to give people something of value just the moment you first meet. It binds. And what is of more value than an insightful point delivered in a funny way? Plus it doesn’t...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Miscellaneous" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: right'><a href="http://flickr.com/photos/sobiegraj/2850040617/"><img src='http://farm4.static.flickr.com/3157/2850040617_9249b5c9f0_m.jpg' alt='Biz-cards' style='margin: 10px 5px 10px 10px;border: 1px solid #aaa;' height='180' width='250'/></a></div>

<p>As some say (me included), it’s nice to give people something of value just the moment you first meet. It binds. And what is of more value than an insightful point delivered in a funny way? Plus it doesn’t cost you much and has potential to change the world (a wee bit, but still).</p>

<p>So why not add some value to the usual biz-card exchange? Say, in form of couple of valuable words on the back side of a card? And I bet you can also make it fun to read. In order to boost up the fun factor I used couple of doodles by <a href="http://www.gapingvoid.com/">Hugh MacLeod</a>.</p>

<p>If you want to print each card with a unique picture on the back, <a href="http://www.moo.com/">moo.com</a> is the place.<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F09%2Fnew_bizcards_1.html&amp;title=New%20biz-cards&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>IT Risk management in Wrocław once again (July 23.)</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/07/it_risk_management_in_wroclaw.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.67</id>
   
   <published>2008-07-09T16:02:12Z</published>
   <updated>2008-07-09T16:20:31Z</updated>
   
   <summary>Since the meeting didn’t work out the last time due to some unexpected circumstances, please let me invite you to the event again. The agenda stays the same. When: July 23, 6PM Where: Credit Suisse, Kameleon building at Szewska st.,...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>Since the meeting didn’t work out the last time due to some unexpected circumstances, please let me invite you to the event again. The agenda stays the same.</p>

<p><strong>When</strong>: July 23, 6PM</p>

<p><strong>Where</strong>: Credit Suisse, <a href="http://maps.google.com/maps?f=q&hl=pl&geocode=&q=poland,+wroc%C5%82aw,+szewska+5&sll=37.0625,-95.677068&sspn=60.635244,108.457031&ie=UTF8&ll=51.109989,17.033958&spn=0.011936,0.026479&z=15&iwloc=addr">Kameleon building at Szewska st.</a>, 1st. floor</p>

<p>See you at the meeting!<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F07%2Fit_risk_management_in_wroclaw.html&amp;title=IT%20Risk%20management%20in%20Wroc%C5%82aw%20once%20again%20%28July%2023.%29&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>IT Risk management in Wrocław on July 3.</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/06/it_risk_management_in_wroclaw_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.66</id>
   
   <published>2008-06-28T13:43:59Z</published>
   <updated>2008-06-28T14:05:45Z</updated>
   
   <summary>I haven&apos;t posted in ages! I&apos;ve even managed to forget the MT backend script name (not to mention I&apos;ve lost my bookmarks somewhere down the road). But I&apos;m back! Unfortunately I&apos;m still busy as... well... as someone very busy, so...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>I haven't posted in ages! I've even managed to forget the MT backend script name (not to mention I've lost my bookmarks somewhere down the road). But I'm back! Unfortunately I'm still busy as... well... as someone very busy, so I'll keep it short this time.</p>

<p>To the point: if you're from Wrocław area or if you happen to be around on July 3, be sure to come to the ISSA Polska meeting in Wrocław. We plan the meeting to be real fun this time. We'll be having a guest from Credit Suisse IT Risk dept. giving a talk. We also plan to discuss latest incidents in Poland.</p>

<p>When: July 3, 6PM</p>

<p>Where: Credit Suisse, <a href=" http://maps.google.com/maps?f=q&hl=pl&geocode=&q=poland,+wroc%C5%82aw,+szewska+5&sll=37.0625,-95.677068&sspn=60.635244,108.457031&ie=UTF8&ll=51.109989,17.033958&spn=0.011936,0.026479&z=15">Kameleon building at Szewska st.</a>, 1st. floor</p>

<p>See you there!</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F06%2Fit_risk_management_in_wroclaw_1.html&amp;title=IT%20Risk%20management%20in%20Wroc%C5%82aw%20on%20July%203.&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>A piece of phishing email</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/05/a_piece_of_phishing_email_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.65</id>
   
   <published>2008-05-06T15:25:04Z</published>
   <updated>2008-05-06T15:38:22Z</updated>
   
   <summary>Not that long ago I got this: When was the last time you got a phishing email? Not that long ago, I bet. Me too. There is nothing unusual in it, nowadays we get so much of it that we...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>Not that long ago I got this:</p>

<p><img style='margin: 10px 5px 10px 10px;' src="http://sobiegraj.com/gfx/visa.jpg" width="400" height="400" alt="VISA phishing email" /></p>

<p>When was the last time you got a phishing email? Not that long ago, I bet. Me too. There is nothing unusual in it, nowadays we get so much of it that we simply get used to it and usually just silently delete or ignore it (if spam filters don’t do it for us).</p>

<p>So, why am I talking about this? Well, because of a funny coincidence. Or maybe it wasn’t that much of a coincidence… Here is the story.</p>]]>
      <![CDATA[<p>Not that long ago my VISA card was about to expire. I’ve ordered a new one, but I didn’t rush myself to activating it as I still had the old one. So the new card landed on a shelf waiting for its time to come. Then, after a month or so I decided to finally activate it. An important note here is that I didn’t remember getting even a piece of VISA phishing email ever before. It didn’t mean I never got it, it just meant nothing like that had gotten my attention for quite some time.</p>

<p>And suddenly, within minutes, I got one! Whoohoo! The nice piece of email pictured at the beginning of this post landed in my mailbox. Then it repeated once or twice a day or two later and stopped. My first reaction was that I got myself some malware that got hold of the credit card activation process and triggered the mailing. But it wouldn’t make much sense. If I had something locally (and I hadn’t, as all sorts of scans showed some time later), what would stop it from reading my previous credit card number and all the authentication information when I submit it during an on-line transaction? It wasn’t on the line with the bank either, as the connection was securely SSLed. So, how come? It might have been an accident, of course, but… a funny one…</p>

<p>The whole thing got me thinking. And what if this information leaked from VISA themselves (I’m not even trying to guess how it could happen). Yes, I know it sounds stupidly paranoid, but, well, you know… things happen. So, if you experienced something like this, I would be really happy to hear from you. I’d at least know I’m not delusional (or not that much at least).</p>]]>

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F05%2Fa_piece_of_phishing_email_1.html&amp;title=A%20piece%20of%20phishing%20email&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>Fifth ISSA meeting in Wroclaw (May 19, 2008)</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/05/fifth_issa_meeting_in_wroclaw_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.64</id>
   
   <published>2008-05-06T12:14:15Z</published>
   <updated>2008-05-06T12:57:08Z</updated>
   
   <summary> We&apos;re gonna do it for the fifth time already! Whooohoo! :) This time the main theme will be Intrusion Detection Systems and Web Application Firewalls. Also a discussion panel is planned so that we all could shout at each...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/ISSA-Polska.jpg' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='60' width='200'/></div>

<p>We're gonna do it for the fifth time already! Whooohoo! :)</p>

<p>This time the main theme will be Intrusion Detection Systems and Web Application Firewalls. Also a discussion panel is planned so that we all could shout at each other and throw blunt objects in each other’s general directions.<br />
Here is the agenda:</p>

<p>1.	A warm welcome (myself)<br />
2.	Intrusion Detection Systems (Wojtek Wirkijowski)<br />
3.	Web Application Firewalls (Edward Weinert)<br />
4.	Discussion Panel (Andrzej Piotr Kleśnicki)</p>

<p>And as always, there is a prize to be won.</p>

<p>See you at the meeting!<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F05%2Ffifth_issa_meeting_in_wroclaw_1.html&amp;title=Fifth%20ISSA%20meeting%20in%20Wroclaw%20%28May%2019%2C%202008%29&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>A funny thing with Thunderbird</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/04/a_funny_thing_with_thunderbird.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.63</id>
   
   <published>2008-04-30T09:48:22Z</published>
   <updated>2008-04-30T10:44:13Z</updated>
   
   <summary>I’m using Thunderbird as my email client on a daily basis. Not that long ago I’ve been trying to send a PDF document, that I previously got from the Web, as an email attachment. To my surprise the normal drag’n’drop...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>I’m using Thunderbird as my email client on a daily basis. Not that long ago I’ve been trying to send a PDF document, that I previously got from the Web, as an email attachment. To my surprise the normal drag’n’drop and send routine didn’t do it. A short glance at the filename made it obvious &mdash; the percent-encoded forward slashes (<tt>%2F</tt>) in the filename got in the way.</p>

<p>As probably most of you guys, I’m not spending my day fuzzing stuff, but, probably as most of you again, I’m bumping over a software glitch from time to time. Sometimes, when I’m in the mood, I’m poking the hole to see what happens. </p>

<p>And I was in the mood that day.</p>]]>
      <![CDATA[<p>As it seems, when an email is glued together (after punching the "send" button), the attachment file name is percent-decoded. This way when trying to send a file attachment named something like this:</p>

<p><code>..%2F..%2F..%2F..%2F..%2FWINDOWS%2Fwinnt.bmp%00.txt</code></p>

<p>a victim will most likely end up sending a winnt.bmp file from their windows directory instead of what they actually intended to send. The actual content of a file that the victim is trying to attach is of course irrelevant. </p>

<p>I wouldn’t be me if I left it at this. So, as an enhancement to the basic idea, we can add some more jumps to the upper directory to have better chance that we get to the root level of the file system: </p>

<p><code><br />
..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F<br />
..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F<br />
..%2F..%2F..%2F..%2F..%2FWINDOWS%2Fwinnt.bmp</code> </p>

<p>And to add some more fun we can, say, get ourselves someone's SAM file from the windows\repair directory: </p>

<p><code><br />
..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F<br />
..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F..%2F<br />
..%2F..%2F..%2F..%2F..%2FWINDOWS%2Frepair%2Fsam%00.bmp</code></p>

<p>The .bmp extension ensures proper encoding of a binary file (I've been really impressed how perfectly the <tt>%00</tt> gets its job done).</p>

<p>Finally we can do some obfuscation: </p>

<p><code><br />
%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F<br />
%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%57%49%4E<br />
%44%4F%57%53%2F%72%65%70%61%69%72%2F%73%61%6D%00%.bmp</code> </p>

<p>As for the severity of this flaw, it certainly couldn’t be called serious as 1) it takes a lot of user interaction (i.e. downloading the funny named file and then sending it as an attachment) and 2) an attacker needs to be able to sniff the sent email off the wire. I can think of some highly directed attacks under which this bug can potentially result in exploitable conditions, but my guess is that one would rather find an easier way to get the job done.</p>

<p>Even though it’s nothing serious this time, it gives us some food for thought. Firstly, there is no such thing as "we know this kind of bugs for ages and they don’t happen anymore". Secondly, a well thought over architecture, a robust coding framework and a proper code quality assurance shouldn’t be optional. And finally, you can never have enough of code quality assurance.<br />
</p>]]>

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F04%2Fa_funny_thing_with_thunderbird.html&amp;title=A%20funny%20thing%20with%20Thunderbird&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>After ISSA Wroclaw meeting #4</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/04/after_issa_wroclaw_meeting_4_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.62</id>
   
   <published>2008-04-14T01:18:59Z</published>
   <updated>2008-04-14T01:31:37Z</updated>
   
   <summary> It&apos;s been hands-on and it&apos;s been fun! :) Huge thanks goes to Edi Weinert and Tadeusz Kowalczyk who put all this together and made the whole thing possible. And of course thanks to you all! I hope you enjoyed...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: right'><a href="http://www.flickr.com/photos/sobiegraj/2410918613/" title="ISSA Wrocław"><img style='margin: 10px 5px 10px 10px;' src="http://farm4.static.flickr.com/3242/2410918613_3ccd984815_m.jpg" width="240" height="180" alt="ISSA Wrocław" /></a></div>

<p>It's been hands-on and it's been fun! :) Huge thanks goes to Edi Weinert and Tadeusz Kowalczyk who put all this together and made the whole thing possible. And of course thanks to you all! I hope you enjoyed the workshop and we'd really love to hear your comments on what we could do better next time.</p>

<p>Hope to see you next time! And in the meantime, be sure to click at the photo for more geeky shots.</p>

<p>Thank you all once again!</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F04%2Fafter_issa_wroclaw_meeting_4_1.html&amp;title=After%20ISSA%20Wroclaw%20meeting%20%234&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>After the 3rd ISSA meeting in Wroclaw</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/03/after_the_3rd_issa_meeting_in_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.61</id>
   
   <published>2008-03-13T13:34:27Z</published>
   <updated>2008-03-13T13:57:47Z</updated>
   
   <summary> Thank you! Thanks to all of you who made it to the meeting despite the fact that we have changed the location twice. And my apologies to all of you, who didn’t. We will do our best to make...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/ISSA-Polska.jpg' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='60' width='200'/></div>

<p>Thank you! Thanks to all of you who made it to the meeting despite the fact that we have changed the location twice. And my apologies to all of you, who didn’t. We will do our best to make sure it doesn’t happen anymore.</p>

<p>Despite all the trouble, the meeting was fun. We totally run out of schedule due to discussions that broke out during the first talk. Oh, and the cookies were awesome! Not to mention the coffee.</p>

<p>We have one piece of slides this time, so, for all of you who would like to go through the presentation again and for others that didn’t make it to the meeting, here it is.</p>

<div style="width:425px;text-align:left" id="__ss_304964"><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slideshare.net/swf/ssplayer2.swf?doc=issa-incident-responce-1205409194816616-3"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slideshare.net/swf/ssplayer2.swf?doc=issa-incident-responce-1205409194816616-3" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object></div>

<p>Thanks again and see you next month!<br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F03%2Fafter_the_3rd_issa_meeting_in_1.html&amp;title=After%20the%203rd%20ISSA%20meeting%20in%20Wroclaw&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>Third ISSA meeting in Wroclaw (Mar 11, 2008)</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/03/third_issa_meeting_in_wroclaw.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.60</id>
   
   <published>2008-03-03T13:25:53Z</published>
   <updated>2008-03-10T23:20:16Z</updated>
   
   <summary> Let me invite you to another ISSA meeting in Wroclaw. It’s the third meeting already and this time we’ll be discussing Computer Forensics and Incident Response. We’ll be having a discussion panel as the last time and we’ll let...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="ISSA" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<div style='float: right'><img src='http://sobiegraj.com/gfx/ISSA-Polska.jpg' alt='ISSA Polska' style='margin: 10px 5px 10px 10px;' height='60' width='200'/></div>

<p>Let me invite you to another <a href="http://www.issa.org.pl/">ISSA</a> meeting in Wroclaw. It’s the third meeting already and this time we’ll be discussing <em>Computer Forensics</em> and <em>Incident Response</em>. We’ll be having a discussion panel as the last time and we’ll let you guys win some prizes in a <a href="http://groups.google.com/group/issa-polska-wroclaw/browse_thread/thread/c180c74ba33423c7">competition</a>.</p>

<p>All that and even more on <strong>Mar 11, 2008</strong> at <strong>6pm</strong>.</p>

<p>Where? <strike>At BZ WBK Wroclaw HQ, <strong>Rynek 9/11</strong> (second door if you look from the pl. Solny direction).</strike> At Politechnika Wroclawska, Janiszewskiego 11/17, building C3, room 118 (enter either through building C-1 or C-5).</p>

<p>An important note: you need to register for the meeting before Feb 4, 2008, 9pm at the latest. In order to register, please use the following <a href="mailto:wroclaw@issa.org.pl?subject=[ISSA] Potwierdzenie udziału w spotkaniu 2008-03-11">link</a>.</p>

<p><strong>UPDATE: This time we meet  at Politechnika Wroclawska, Janiszewskiego 11/17, building C3, room 118 (enter either through building C-1 or C-5).</strong><br />
</p>]]>
      

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F03%2Fthird_issa_meeting_in_wroclaw.html&amp;title=Third%20ISSA%20meeting%20in%20Wroclaw%20%28Mar%2011%2C%202008%29&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>Automatische Antwort</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/02/automatische_antwort_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.59</id>
   
   <published>2008-02-25T12:40:11Z</published>
   <updated>2008-02-25T12:56:25Z</updated>
   
   <summary>What do you think happens when some spamming bots pick up your email address and start using it as a source address when throwing discounted Viagra and almost-like-the-real-thing watch replicas crap at people in unbelievable amounts? Tons, and I mean...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>What do you think happens when some spamming bots pick up your email address and start using it as a source address when throwing discounted Viagra and almost-like-the-real-thing watch replicas crap at people in unbelievable amounts?</p>

<p>Tons, and I mean TONS, of "undeliverable message" bounces together with quite a lot of my favourites – out of office notes. When you think about it, quite a lot of information is being thrown at you in such messages. Here are some sanitised examples (all in German, as my email address sells on a German market, apparently).<br />
</p>]]>
      <![CDATA[<p>Some phone numbers in case you are interested:<br />
<blockquote>Automatische Antwort - Zur Zeit nicht erreichbar</p>

<p>Vielen Dank für Ihre Anfrage, die uns erreicht hat.</p>

<p>Für eilige Rückfragen können Sie sich auch direkt an mich unter</p>

<p><strong>Tel. +49 (0)4XXX / XX XXX<br />
Mob. +49 (0)17X / XXX XX X5<br />
Fax. +49 (0)4XXX / XX XX0</strong></p>

<p>wenden.</p>

<p>Mit freundlichen Grüßen aus <strong>XXXX</strong>,</p>

<p>Ihre <strong>XXXX</strong><br />
</blockquote></p>

<p>Some names and email addresses (you can’t have too much of it):<br />
<blockquote>Automated reply from <strong>XXX@XXX.de</strong></p>

<p>Ich habe Ihre Mail betreffend 'Man Lebt nur einmal - probiers aus !' erhalten.</p>

<p>Von Freitag, dem 8. Februar bis Freitag dem 15. Februar  bin ich nicht im Büro zu erreichen. Bitte wenden Sie sich in dieser Zeit an meine Kollegin <strong>Susanne XXX</strong> (<strong>s.XXX@XXX.de</strong>). Ihre Mail wurde nicht weitergeleitet.</p>

<p>Mit besten Grüßen,</p>

<p><strong>XXXX</strong><br />
---------------------------------<br />
XXXX GmbH<br />
XXXX 1<br />
XXXX XXXX (Germany)</p>

<p>Fon: ++49(0)XXXX.XXXX5<br />
Fax: ++49(0)XXXX.XXXX6</p>

<p>Mail: XXX@XXX.de<br />
Web: http://XXXX.de<br />
Web: http://XXXX.com</p>

<p><strong>GF: YYYY YYYY, ZZZZ ZZZZ<br />
XXXXXXXXX</strong><br />
---------------------------------<br />
</blockquote></p>

<p>And some more names together with phones and email addresses:<br />
<blockquote><strong>Susanne XXX</strong> nicht erreichbar. Ihre E-Mail wird nicht gelesen.</p>

<p>Ich werde ab  29.01.2008 nicht im Büro sein. Ich kehre zurück am<br />
05.05.2008.</p>

<p><br />
Sehr geehrter Damen und Herren</p>

<p>Ich bin in Elternzeit.<br />
Ihre E-Mail wird nicht weitergeleitet.</p>

<p>Bitte wenden Sie sich entweder an<br />
<strong>Alexandra XXX, Tel. 089 - XXX XX - XXX<br />
e-mail XXX.a@XXX.de</strong><br />
oder an<br />
<strong>Carolin XXX, Tel. 089 - XXX XX - XXX oder e-mail<br />
XXX.c@XXX.de</strong></p>

<p>Vielen Dank und viele Grüße<br />
<strong>Susanne XXX</strong><br />
</blockquote></p>

<p>It’s not much, is it? But still some people would argue that together with some background info about what the particular people are responsible for in the organisation it may be enough to snatch some goodies from them.</p>

<p>It’s never wise to underestimate the power of people’s natural friendliness and urge to help others. Maybe sparing a few details wouldn’t defeat the purpose and would make it more difficult to carry out a successful social engineering attack. Specific procedures and awareness trainings also help, obviously.<br />
</p>]]>

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F02%2Fautomatische_antwort_1.html&amp;title=Automatische%20Antwort&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>
<entry>
   <title>Xploit #1</title>
   <link rel="alternate" type="text/html" href="http://sobiegraj.com/blog/2008/02/xploit_1_1.html" />
   <id>tag:sobiegraj.com,2008:/blog//1.58</id>
   
   <published>2008-02-19T11:28:34Z</published>
   <updated>2008-03-17T14:46:23Z</updated>
   
   <summary>For all of you guys around here in Poland, another opportunity to deepen your acquaintance with information security just appeared. The first issue of Xploit have just hit the shelves. What’s in it?A remote DoS on Vista,A tale of a...</summary>
   <author>
      <name>Michał Sobiegraj</name>
      <uri>http://sobiegraj.com/</uri>
   </author>
         <category term="Review" scheme="http://www.sixapart.com/ns/types#category" />
         <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
   
   
   <content type="html" xml:lang="en" xml:base="http://sobiegraj.com/blog/">
      <![CDATA[<p>For all of you guys around here in Poland, another opportunity to deepen your acquaintance with information security just appeared. The first issue of <a href="http://www.Xploit.pl/">Xploit</a> have just hit the shelves.</p>

<div style='float: right'><img src='http://sobiegraj.com/gfx/xploit1.jpg' alt='Xploit 1/2008' style='padding: 2px;margin: 10px 5px 10px 10px; border: 1px solid #aaa' height='250' width='179'/></div>

<p>What’s in it?<ul><li>A remote DoS on Vista,</li><li>A tale of a deadly <a href="http://code.google.com/android/">Android</a>,</li><li>A short story of hacking PSP,</li><li>Everything you ever wanted to know about hosting, but were afraid to ask,</li><li>Challenges of risk analysis,</li><li>Securing SQL Server 2005,</li><li>Polish law and hacking,</li><li>TPM in GNU/Linux,</li><li>and much, much more.</li></ul>All in Polish with a conventional live CD included.</p>

<p>I had a pleasure to share some thoughts on risk analysis in this issue, so be it only for that I really encourage you to visit your newsagent and give this fine new magazine a try. </p>]]>
      <![CDATA[<p><img src="http://sobiegraj.com/gfx/Xploit-michal sobiegraj-analiza ryzyka.jpg" alt="Michal Sobiegraj -- Analiza Ryzyka (Xploit #1)" style='padding: 2px; border: 1px solid #aaa' height='397 width='490' /></p>]]>

      &lt;p&gt;&lt;a style='font-size: 0.8em;font-family: "Lucida Grande", Verdana, Arial, Sans-Serif;background: url(http://sobiegraj.com/blog//gfx/16x16-digg-guy.gif) center left no-repeat; padding-left: 20px;' href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fsobiegraj.com%2Fblog%2F2008%2F02%2Fxploit_1_1.html&amp;title=Xploit%20%231&amp;bodytext=" rel="external"&gt;Digg It&lt;/a&gt;&lt;/p&gt;
   </content>
</entry>

</feed>
