<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
	<title>Mike´s Blog</title>
	<description>each day is a drive thru story...</description>
	<link>http://mike.com.mx</link>
	<managingEditor>me@mike.com.mx (Miguel Jose Hernandez y Lopez)</managingEditor>
	<copyright>2004, Miguel Jose Hernandez y Lopez</copyright>
	<pubDate>Sat, 12 Jun 2010 11:00:15 -0700</pubDate>
	<generator>JAWS 0.7.4</generator>
	<item>
		<category>music</category>
		<title><![CDATA[ MGMT - Kids ]]></title>
		<description><![CDATA[ 	<p><center>
<object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/Qq60QBJ91gM&#038;hl=es_ES&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/Qq60QBJ91gM&#038;hl=es_ES&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed></object></center>
</p>
 ]]></description>
		<link>http://mike.com.mx/index.php/blog/show/MGMT---Kids.html</link>
		<author>me@mike.com.mx (Miguel Hernandez y Lopez)</author>
		<guid>http://mike.com.mx/index.php/blog/show/MGMT---Kids.html</guid>
		<pubDate>Sat, 12 Jun 2010 11:00:15 -0700</pubDate>
	</item>
	<item>
		<category>stuff</category>
		<category>software libre</category>
		<category>security</category>
		<category>honeypots</category>
		<category>Mexican Honeynet Project</category>
		<category>OpenSource</category>
		<category>honeynets</category>
		<category>Honeynet Project</category>
		<category>tools</category>
		<title><![CDATA[ Challenge 1 of the Forensic Challenge 2010 - pcap attack trace ]]></title>
		<description><![CDATA[ 	<p>Forensic Challenge 2010<br>
<br>
Challenge 1 - <b>pcap attack trace</b> - (provided by Tillmann Werner from the Giraffe Chapter) is to investigate a network attack.
Send submissions (please use the MS word submission template or the Open Office submission template) forensicchallenge2010@honeynet.org no later then 17:00 EST, Monday, February 1st 2010. Results will be released on Monday, February 15th 2010. Small prizes will be awarded to the top three submissions.<br>
<br>
Skill Level: Intermediate<br><br></p>
	<p>The Challenge:<br>
A network trace with attack data is provided. (Note that the IP address of the victim has been changed to hide the true location.) Analyze and answer the following questions:<br><br></p>
	<p>   1. Which systems (i.e. IP addresses) are involved? (2pts)<br>
   2. What can you find out about the attacking host (e.g., where is it located)? (2pts)<br>
   3. How many TCP sessions are contained in the dump file? (2pts)<br>
   4. How long did it take to perform the attack? (2pts)<br>
   5. Which operating system was targeted by the attack? And which service? Which vulnerability? (6pts)<br>
   6. Can you sketch an overview of the general actions performed by the attacker? (6pts)<br>
   7. What specific vulnerability was attacked? (2pts)<br>
   8. What actions does the shellcode perform? Pls list the shellcode. (8pts)<br>
   9. Do you think a Honeypot was used to pose as a vulnerable victim? Why? (6pts)<br>
  10. Was there malware involved? Whats the name of the malware? (We are not looking for a detailed malware analysis for this challenge) (2pts)<br>
  11. Do you think this is a manual or an automated attack? Why? (2pts)<br><br></p>
	<p>Download:<br>
<a href="https://www.honeynet.org/files/attack-trace.pcap_.gz">attack-trace.pcap_.gz</a> Sha1: 0f5ddab19034b2656ec316875b527d9bff1f035f
</p>
 ]]></description>
		<link>http://mike.com.mx/index.php/blog/show/Challenge-1-of-the-Forensic-Challenge-2010---pcap-attack-trace.html</link>
		<author>me@mike.com.mx (Miguel Hernandez y Lopez)</author>
		<guid>http://mike.com.mx/index.php/blog/show/Challenge-1-of-the-Forensic-Challenge-2010---pcap-attack-trace.html</guid>
		<pubDate>Fri, 22 Jan 2010 08:06:03 -0800</pubDate>
	</item>
	<item>
		<category>music</category>
		<category>lyrics</category>
		<title><![CDATA[ Flores sobre las piedras ]]></title>
		<description><![CDATA[ 	<p>- En tus pensamientos distingo un valle de lagrimas que desaparese pero existe<br>
- Toca mi cara y escuchame sentado, escucha mi dolor.<br>
- Dolor ?<br>
- Prefiero sentirme a salvo escuhando el indicio de un sonido que me hace vivir<br>
- Te refieres al terrible sonido tan vacio de la brisa o de los momentos en que las sombras despiertan ?<br>
- Al silencio final, al silencio del dolor<br>
- Si estas en un error estas cofundido<br></p>
	<p><a href="http://bit.ly/8bshsn" target="_blank">http://bit.ly/8bshsn</a>
</p>
 ]]></description>
		<link>http://mike.com.mx/index.php/blog/show/Flores-sobre-las-piedras.html</link>
		<author>me@mike.com.mx (Miguel Hernandez y Lopez)</author>
		<guid>http://mike.com.mx/index.php/blog/show/Flores-sobre-las-piedras.html</guid>
		<pubDate>Sun, 13 Dec 2009 16:23:58 -0800</pubDate>
	</item>
	<item>
		<category>general</category>
		<category>music</category>
		<title><![CDATA[ BTBAM - More of myself to kill... ]]></title>
		<description><![CDATA[ 	<p>You have all wept once more... why? I would never ask for such. Go. I have realized for once in my existence my true happiness. This is a first time for me... I feel innocent, caring, and non-threatening.</p>
	<p>Reincarnation for a better life... becoming one with true harmony. No gods have caressed or burned me, only
nature is willing to comfort me. Salvation is dead and all of you have passed away with
me today. I will never have to entertain or please any of you ever again. I am alive.</p>
	<p>My memory is the only thing keeping the old tears in my eyes.</p>
	<p>I still know that all of you are taking for the sake of not leaving. You are killing the innocent for your so-called nutrition. You are infecting our lands with your filth. You are killing for the sake of your promotions in life.</p>
	<p>One day we will all be in this soil... with no gods to slave to, and no heroes to kill for. 
</p>
 ]]></description>
		<link>http://mike.com.mx/index.php/blog/show/BTBAM---More-of-myself-to-kill.html</link>
		<author>me@mike.com.mx (Miguel Hernandez y Lopez)</author>
		<guid>http://mike.com.mx/index.php/blog/show/BTBAM---More-of-myself-to-kill.html</guid>
		<pubDate>Wed, 25 Nov 2009 12:10:50 -0800</pubDate>
	</item>
	<item>
		<category>stuff</category>
		<category>software libre</category>
		<category>security</category>
		<category>OpenSource</category>
		<category>tools</category>
		<title><![CDATA[ CSS a través de Atom y RSS en Opera & Chrome ]]></title>
		<description><![CDATA[ 	<p>Existe un error en el sistema de análisis de contenido de los navegadores Opera y Google Chrome. Un atacante remoto podría explotar esto para ejecutar código JavaScript arbitrario a través de un enlace que devuelva un "mime type" del tipo "text/xml", "text/atom-xml" o "text/rss-xml" con JavaScript incrustado. Estos navegadores lo procesarían sin motivo.</p>
	<p>El sistema de análisis de contenido de un navegador web debería comprobar qué tipo de datos son los que va a mostrar y activar o desactivar ciertas funcionalidades dependiendo del tipo; por ejemplo, no tendría sentido que un navegador ejecutara código JavaScript si accede a un fichero cuyo "mime type" en el servidor es "image/jpeg", puesto que en teoría, no debería existir ningún tipo de código JavaScript en un fichero de ese formato.</p>
	<p>Google ya ha solucionado esta vulnerabilidad y ha publicado un parche para su versión 3 que se puede aplicar desde el propio Chrome.</p>
	<p>En este momento Opera no ha actualizado ni notificado oficialmente esta vulnerabilidad en su sitio oficial, pero al parecer su equipo de desarrollo y seguridad están trabajando para solucionar este problema.</p>
	<p>Prueba de concepto:
<a href="http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/" target="_blank">http://securethoughts.com/2009/09/exploiting-chrome-and-operas-inbuilt-atomrss-reader-with-script-execution-and-more/</a></p>
	<p>Advisory de Chrome:
<a href="http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.html" target="_blank">http://googlechromereleases.blogspot.com/2009/09/stable-channel-update.html</a></p>
	<p>Sitio de Advisories de Opera:
<a href="http://www.opera.com/support/kb/advisory/page1/" target="_blank">http://www.opera.com/support/kb/advisory/page1/</a></p>
	<p>Fuente: <a href="http://www.hispasec.com/unaaldia/3981/" target="_blank">Hispasec</a>
</p>
 ]]></description>
		<link>http://mike.com.mx/index.php/blog/show/CSS-a-travs-de-Atom-y-RSS-en-Opera--Chrome.html</link>
		<author>me@mike.com.mx (Miguel Hernandez y Lopez)</author>
		<guid>http://mike.com.mx/index.php/blog/show/CSS-a-travs-de-Atom-y-RSS-en-Opera--Chrome.html</guid>
		<pubDate>Sat, 19 Sep 2009 15:20:59 -0700</pubDate>
	</item>
</channel>
</rss>
