<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Viewpoints &#187; Security fun</title>
	<atom:link href="http://advosys.ca/viewpoints/category/fun/feed/" rel="self" type="application/rss+xml" />
	<link>http://advosys.ca/viewpoints</link>
	<description>Security, operating systems and the IT industry</description>
	<lastBuildDate>Tue, 31 Aug 2010 13:06:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Pwnie Award winners 2009</title>
		<link>http://advosys.ca/viewpoints/2009/08/pwnie-award-winners-2009/</link>
		<comments>http://advosys.ca/viewpoints/2009/08/pwnie-award-winners-2009/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 21:39:00 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Security fun]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=579</guid>
		<description><![CDATA[The winners of the &#8220;prestigious&#8221; Pwnie Awards were announced last Saturday at Black Hat USA. The honored recipients are: Best Server-Side Bug: Linux SCTP FWD Chunk Memory Corruption (CVE-2009-0065) Best Privilege Escalation Bug: Linux udev Netlink Message Privilege Escalation (CVE-2009-1185) Best Client-Side Bug: msvidctl.dll MPEG2TuneRequest Stack buffer overflow (CVE-2008-0015) Mass 0wnage: Red Hat Networks Backdoored [...]]]></description>
			<content:encoded><![CDATA[<p>The winners of the &#8220;prestigious&#8221; <a title="Pwnie award winners 2009" href="http://pwnie-awards.org/2009/awards.html">Pwnie Awards</a> were announced last Saturday at Black Hat USA. The honored recipients are:</p>
<ul>
<li><strong>Best Server-Side Bug:</strong> Linux SCTP FWD Chunk Memory Corruption (<a title="CVE-2009-0065" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0065">CVE-2009-0065</a>)</li>
<li><strong>Best Privilege Escalation Bug:</strong> Linux udev Netlink Message Privilege Escalation (<a title="CVE-2009-1185" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185">CVE-2009-1185</a>)</li>
<li><strong>Best Client-Side Bug:</strong> msvidctl.dll MPEG2TuneRequest Stack buffer overflow (<a title="CVE-2008-0015" href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0015">CVE-2008-0015</a>)</li>
<li><strong>Mass 0wnage:</strong> Red Hat Networks Backdoored OpenSSH Packages (<a title="CVE-2008-3844" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3844">CVE-2008-3844</a>)</li>
<li><strong>Best Research:</strong> <a href="https://www.sec-consult.com/files/Pwning_Nokia_V1.03_PUB.pdf">From 0 to 0day on Symbian</a> (pdf)</li>
<li><strong>Lamest Vendor Response:</strong> Linux (for continually assuming that all <a title="[Security, resend] Instant crash with rtl8169 and large packets" href="http://lkml.org/lkml/2009/6/8/194">kernel memory corruption bugs</a> are only denial-of-service)</li>
<li><strong>Most Overhyped Bug:</strong> MS08-067 Server Service NetpwPathCanonicalize() Stack Overflow  (<a title="CVE-2008-4250" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4250">CVE-2008-4250</a>)</li>
<li><strong>Most Epic FAIL:</strong> <a title="The Anatomy Of The Twitter Attack" href="http://www.techcrunch.com/2009/07/19/the-anatomy-of-the-twitter-attack/">Twitter Gets Hacked</a> and the &#8220;Cloud Crisis&#8221;</li>
<li><strong>Lifetime Achievement Award:</strong> <a title="Alexander Peslyak (Solar Designer) Biography" href="http://openwall.info/wiki/people/solar/bio">Solar Designer</a></li>
<li><strong>Best Song:</strong> <a href="http://www.sophsec.com/nice_report.mp3">Nice Report</a> (mp3) by Doctor RAID</li>
</ul>
<p>Linux was justly trashed in this year&#8217;s awards. The kernel bugs and the <a title="Red Hat hack prompts critical OpenSSH update" href="http://www.theregister.co.uk/2008/08/22/red_hat_systems_hacked/">Red Hat (and Fedora) compromise</a> were significant (Fedora was also hit), as was last year&#8217;s Pwnie winning <a title="Vulnerability Note VU#925211" href="http://www.kb.cert.org/vuls/id/925211">Debian OpenSSL debacle</a>.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2009/07/pwnie-award-nominations-2009/' rel='bookmark' title='Permanent Link: Pwnie Award nominations close July 15'>Pwnie Award nominations close July 15</a></li>
<li><a href='http://advosys.ca/viewpoints/2007/08/pwnie-award-nominees/' rel='bookmark' title='Permanent Link: Pwnie Award nominees are out'>Pwnie Award nominees are out</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2009/08/pwnie-award-winners-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.sophsec.com/nice_report.mp3" length="7683072" type="audio/mpeg" />
		</item>
		<item>
		<title>Pwnie Award nominations close July 15</title>
		<link>http://advosys.ca/viewpoints/2009/07/pwnie-award-nominations-2009/</link>
		<comments>http://advosys.ca/viewpoints/2009/07/pwnie-award-nominations-2009/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 12:04:44 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Security fun]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/?p=507</guid>
		<description><![CDATA[The Pwnie Awards are back this year&#8230; and there are just two more days to submit your nominations. The awards started in 2007 as a more than slightly irreverent recognition of &#8220;the best&#8221; in information security for the previous year. For The 2009 award categories are: Best Server-Side Bug Best Client-Side Bug Mass 0wnage Most [...]]]></description>
			<content:encoded><![CDATA[<p>The <a title="Pwnie awards 2009" href="http://pwnie-awards.org/2009/info.html">Pwnie Awards</a> are back this year&#8230; and there are just two more days to submit your nominations.</p>
<p>The awards started in 2007 as a more than slightly irreverent recognition of &#8220;the best&#8221; in information security for the previous year. For The 2009 award categories are:</p>
<ul>
<li>Best Server-Side Bug</li>
<li>Best Client-Side Bug</li>
<li>Mass 0wnage</li>
<li>Most Innovative Research</li>
<li>Lamest Vendor Response</li>
<li>Most Overhyped Bug</li>
<li>Best Song</li>
<li>Most Epic FAIL</li>
<li>Lifetime Achievement</li>
</ul>
<p>The ceremony is held during Blackhat USA, but nominations must be in by this Wednesday.</p>
<p><em>Update (Jul 22 2009):</em> The nominees have been <a title="http://pwnie-awards.org/2009/nominees.html" href="http://">announced</a>.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2007/08/pwnie-award-nominees/' rel='bookmark' title='Permanent Link: Pwnie Award nominees are out'>Pwnie Award nominees are out</a></li>
<li><a href='http://advosys.ca/viewpoints/2009/08/pwnie-award-winners-2009/' rel='bookmark' title='Permanent Link: Pwnie Award winners 2009'>Pwnie Award winners 2009</a></li>
<li><a href='http://advosys.ca/viewpoints/2006/08/stupid-security-awards/' rel='bookmark' title='Permanent Link: Stupid security awards'>Stupid security awards</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2009/07/pwnie-award-nominations-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pwnie Award nominees are out</title>
		<link>http://advosys.ca/viewpoints/2007/08/pwnie-award-nominees/</link>
		<comments>http://advosys.ca/viewpoints/2007/08/pwnie-award-nominees/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 13:56:09 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Security fun]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2007/08/pwnie-award-nominees/</guid>
		<description><![CDATA[The first annual Pwnie Awards have now published their list of nominees for 2007 and will be presenting the awards today at Blackhat Las Vegas. This extremely irreverent award was announced in July by security researcher Alexander Sotirov with the awards in the following categories: Best Server-Side Bug Best Client-Side Bug Mass 0wnage Most Innovative [...]]]></description>
			<content:encoded><![CDATA[<p>
   The first annual <a href="http://pwnie-awards.org/" title="The Pwnie Awards">Pwnie Awards</a>  have now published their <a href="http://pwnie-awards.org/awards.html" title="Pwnie Award Nominees 2007">list of nominees</a> for 2007 and will be presenting the awards today at Blackhat Las Vegas. This extremely irreverent award was <a href="http://fist.immunitysec.com/pipermail/dailydave/2007-July/004481.html" title="[Dailydave] The Pwnie Awards!">announced in July</a>  by security researcher Alexander Sotirov with the awards in the following categories:
</p>
<ul>
<li>Best Server-Side Bug</li>
<li>Best Client-Side Bug</li>
<li>Mass 0wnage</li>
<li>Most Innovative Research</li>
<li>Lamest Vendor Response</li>
<li>Most Overhyped Bug</li>
<li>Best Song <img src="http://advosys.ca/viewpoints/wp-content/plugins/miwa-editor-mu/js/tinymce/plugins/emotions/images/smiley-cool.gif" border="0" alt="Cool" title="Cool" /></li>
</ul>
<p>
   It&#8217;s always a good time when insiders poke fun at the security industry. The <a href="http://pwnie-awards.org/awards.html" title="Pwnie Award Nominees">nominations</a>  are a good read. They&#8217;d be hilarious if they weren&#8217;t such a tragic illustration of the state of software today.
</p>
<p>
   &#8220;Lamest vendor response&#8221; is my favorite category&#8230; when security is the last thing considered by software developers (assuming it&#8217;s considered at all), vendor action is critical.  By now most vendors have learned to stop attacking security researchers who audit their products for free, but denial and downplaying the importance of flaws is still common. When serious flaws were reported in forensic tool EnCase (darling of law enforcement everywhere),  the vendor reaction was a classic <a href="http://www.securityfocus.com/archive/1/474727" title="Guidance Software response to iSEC report on EnCase">downplay and dismiss</a>. One response <a href="http://www.securityfocus.com/archive/1/474750">tearing their argument apart</a> was also classic.
</p>
<p>
  <em>Update:</em> <a href="http://pwnie-awards.org/winners.html" title="Pwnie Award Winners">The &#8220;winners&#8221;</a>  have been announced.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p><em>Related posts:</em><ul><li><a href='http://advosys.ca/viewpoints/2009/07/pwnie-award-nominations-2009/' rel='bookmark' title='Permanent Link: Pwnie Award nominations close July 15'>Pwnie Award nominations close July 15</a></li>
<li><a href='http://advosys.ca/viewpoints/2009/08/pwnie-award-winners-2009/' rel='bookmark' title='Permanent Link: Pwnie Award winners 2009'>Pwnie Award winners 2009</a></li>
</ul></p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2007/08/pwnie-award-nominees/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Incredible statement</title>
		<link>http://advosys.ca/viewpoints/2006/10/incredible-statement/</link>
		<comments>http://advosys.ca/viewpoints/2006/10/incredible-statement/#comments</comments>
		<pubDate>Tue, 24 Oct 2006 02:37:54 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Security fun]]></category>
		<category><![CDATA[macintosh]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2006/10/incredible-statement/</guid>
		<description><![CDATA[We&#8217;ve all seen examples of really stupid security thinking, but I&#8217;m betting this is a joke&#8230; &#34;We&#8217;re going to buy Mac Minis and run Windows on them because Macs aren&#8217;t affected by these security problems.&#34; Read the whole thing here: DeadBeefCafe Incredible statement. Copyright &#169; 2012 Advosys Consulting Inc. No related posts.]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve all seen examples of really stupid security thinking, but I&#8217;m betting this is a joke&#8230;</p>
<blockquote>
<p>&quot;We&rsquo;re going to buy Mac Minis and run Windows on them because Macs aren&rsquo;t affected by these security problems.&quot;</p>
</blockquote>
<p>Read the whole thing here: <a href="http://www.deadbeefcafe.org/archives/56">DeadBeefCafe Incredible statement</a>.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2006/10/incredible-statement/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Give us all your money</title>
		<link>http://advosys.ca/viewpoints/2006/10/give-us-all-your-money/</link>
		<comments>http://advosys.ca/viewpoints/2006/10/give-us-all-your-money/#comments</comments>
		<pubDate>Wed, 18 Oct 2006 11:05:23 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Security fun]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2006/10/give-us-all-your-money/</guid>
		<description><![CDATA[Phishers just aren&#8217;t trying as hard as they used to: check out giveusallyourmoney.com (via Security Curve weblog) Though the site is (I hope) a joke, when you press the submit button it takes you to a page &#8220;taketheirmoney.php&#8221; which right now spits out a nice PHP error message about not being able to open file [...]]]></description>
			<content:encoded><![CDATA[<p>
Phishers just aren&#8217;t trying as hard as they used to: check out <a href="http://www.giveusallyourmoney.com/">giveusallyourmoney.com</a> (via <a href="http://www.securitycurve.com/blog/" title="Security Curve weblog">Security Curve weblog</a>)
</p>
<p>
Though the site is (I hope) a joke, when you press the submit button it takes you to a page &#8220;taketheirmoney.php&#8221; which right now spits out a nice PHP error message about not being able to open file &#8220;creditcards.txt&#8221;.
</p>
<p>
Oops&#8230; a security issue! Now we know the web server is running PHP and, since the PHP setting display_errors was left enabled, we can see physical directories on the server and what may be the username of the site owner. Very helpful to an attacker. If this site really was phishing for card numbers mistakes like this could lead to a breach! <img src='http://advosys.ca/viewpoints/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />
</p>
<p>
(There are at least four other security issues with the site, but I&#8217;m not about to list them here. See how many problems you can spot!)
</p>
<p>
And speaking of security flaws, I think <a href="http://www.fixavote.com/">fixavote</a> is brilliant (via <a href="http://www.schneier.com/blog/" target="_blank">Schneier on Security</a>)</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2006/10/give-us-all-your-money/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A literal trojan horse</title>
		<link>http://advosys.ca/viewpoints/2006/08/literal-trojan-horse/</link>
		<comments>http://advosys.ca/viewpoints/2006/08/literal-trojan-horse/#comments</comments>
		<pubDate>Thu, 31 Aug 2006 01:21:43 +0000</pubDate>
		<dc:creator>D Webber</dc:creator>
				<category><![CDATA[Security fun]]></category>
		<category><![CDATA[humor]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://advosys.ca/viewpoints/2006/08/literal-trojan-horse/</guid>
		<description><![CDATA[This is more appropriate as a Friday fun post and is the first (and probably last) time I&#8217;ve linked to a video, but this clip &#8220;What have we learned from history?&#8221; clip from the Australian satire program &#8220;The Chaser&#8221; is too funny not to share. (warning: YouTube link) The show&#8217;s crew drove around Sydney towing [...]]]></description>
			<content:encoded><![CDATA[<p>
This is more appropriate as a Friday fun post and is the first (and probably last) time I&#8217;ve linked to a video, but this clip &#8220;<a href="http://www.youtube.com/watch?v=Xs3SfNANtig">What have we learned from history?&#8221;</a> clip from the Australian satire program &#8220;<a href="http://www.chaser.com.au/">The Chaser</a>&#8221; is too funny not to share. (warning: YouTube link)
</p>
<p>
The show&#8217;s crew drove around Sydney towing a literal trojan horse asking if they could park it over night inside various compounds.
</p>
<p>
It&#8217;s farcical but when such an obvious (and I&#8217;d hope widely known) physical security attack like this still works, I guess it&#8217;s not surprising that methods like <a href="http://software.silicon.com/security/0,39024655,39156503,00.htm">handing out trojaned CDROMs</a> to London commuters or leaving <a href="http://www.darkreading.com/document.asp?doc_id=95556&amp;WT.svl=column1_1">infected USB keys in company parking lots</a> are effective.</p>
Copyright &copy; 2012 <a href="http://advosys.ca/">Advosys Consulting Inc.</a>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://advosys.ca/viewpoints/2006/08/literal-trojan-horse/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

