<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Geekness - closer to the world &#187; Security</title>
	<atom:link href="http://cocaman.ch/wp/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://cocaman.ch/wp</link>
	<description>Geeky at the Lake of Zurich</description>
	<lastBuildDate>Mon, 12 Sep 2011 18:11:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Google Account 2-Step Verification</title>
		<link>http://cocaman.ch/wp/2011/02/google-account-2-step-verification/</link>
		<comments>http://cocaman.ch/wp/2011/02/google-account-2-step-verification/#comments</comments>
		<pubDate>Wed, 16 Feb 2011 12:10:40 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[android]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[2-step]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[Google]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=3325</guid>
		<description><![CDATA[I managed to activate the new 2-step verification for my Google Account. The setup takes up to 15 minutes. And they aren&#8217;t lying about that. It is quite long and different things are changed or printed out. I&#8217;ve taken some screenshots for you to check it out: At the end, you need to define passwords [...]]]></description>
			<content:encoded><![CDATA[<p>I managed to activate the new 2-step verification for my Google Account. The setup takes up to 15 minutes. And they aren&#8217;t lying about that. It is quite long and different things are changed or printed out. I&#8217;ve taken some screenshots for you to check it out:</p>

<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/2-step-verification/' title='2-step verification'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/2-step-verification-150x150.png" class="attachment-thumbnail" alt="2-step verification" title="2-step verification" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/system-2/' title='System-2'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/System-2-150x150.png" class="attachment-thumbnail" alt="System-2" title="System-2" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/2-step-verification-1-2/' title='2-step verification-1'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/2-step-verification-11-150x150.png" class="attachment-thumbnail" alt="2-step verification-1" title="2-step verification-1" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/2-step-verification-2/' title='2-step verification-2'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/2-step-verification-2-150x150.png" class="attachment-thumbnail" alt="2-step verification-2" title="2-step verification-2" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/2-step-verification-3/' title='2-step verification-3'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/2-step-verification-3-150x150.png" class="attachment-thumbnail" alt="2-step verification-3" title="2-step verification-3" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/2-step-verification-4/' title='2-step verification-4'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/2-step-verification-4-150x150.png" class="attachment-thumbnail" alt="2-step verification-4" title="2-step verification-4" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/dock-1/' title='Dock-1'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/Dock-1-150x150.png" class="attachment-thumbnail" alt="Dock-1" title="Dock-1" /></a>
<a href='http://cocaman.ch/wp/2011/02/google-account-2-step-verification/my-account/' title='My Account'><img width="150" height="150" src="http://cocaman.ch/wp/wp-content/uploads/2011/02/My-Account-150x150.png" class="attachment-thumbnail" alt="My Account" title="My Account" /></a>

<p>At the end, you need to <a href="http://www.google.com/support/accounts/bin/static.py?page=guide.cs&#038;guide=1056283&#038;topic=1056286">define passwords</a> for applications, which do not support 2-step authentication. This includes your Android device (email and Google Account), your Adwords profile, desktop tools (Adium, GTalk). Each password is assigned with a custom, 16 character password.</p>
<p>Let&#8217;s see how this all works out in the future.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=3325&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2008/06/google-you-and-me-in-front-better-call-your-doctor/" title="Google, You And Me In Front, Better Call Your Doctor">Google, You And Me In Front, Better Call Your Doctor</a></li><li><a href="http://cocaman.ch/wp/2011/03/google-android-market-launches-stats/" title="Google Android Market Launches Stats">Google Android Market Launches Stats</a></li><li><a href="http://cocaman.ch/wp/2011/02/the-dirty-little-secrets-of-search-additional-information/" title="&#8220;The Dirty Little Secrets of Search&#8221; &#8211; Additional Information">&#8220;The Dirty Little Secrets of Search&#8221; &#8211; Additional Information</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2011/02/google-account-2-step-verification/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>My New Job: Security Analyst</title>
		<link>http://cocaman.ch/wp/2010/12/security-analyst-compass-security-disclaimer/</link>
		<comments>http://cocaman.ch/wp/2010/12/security-analyst-compass-security-disclaimer/#comments</comments>
		<pubDate>Fri, 10 Dec 2010 09:21:48 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[compass]]></category>
		<category><![CDATA[csnc]]></category>
		<category><![CDATA[me]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[security-analyst]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=3185</guid>
		<description><![CDATA[My name is Corsin Camichel and I am working for Compass Security AG. The views expressed on this blog are mine alone and do not necessarily reflect the views of my employer. Everything here, though, is my personal opinion and is not read or approved before it is posted. No warranties or other guarantees will [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>My name is Corsin Camichel and I am working for Compass Security AG. The views expressed on this blog are mine alone and do not necessarily reflect the views of my employer. Everything here, though, is my personal opinion and is not read or approved before it is posted. No warranties or other guarantees will be offered as to the quality of the opinions or anything else offered here.</p></blockquote>
<p>This little paragraph is now very important. As of October 2010 I am employed by Compass Security, a leader in Penetration Tests and Security Checks in Switzerland. As a security analyst I am conducting such checks and tests. Everything I do is confidential and can not be discussed in public. Just a note to my blog readers. If I describe or write about security related issues (which I think I will do in the future) it expressed my personal opinion, findings and research and is not backed or sourced by work I have done. I will occasionally publish or link to stuff which is work related, but only information that is or should be public knowledge. Like events or presentation we are holding. But I will do my best to disclose my relationship on all those posts.</p>
<p><a href="http://www.csnc.ch/"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/11/compass-logo-300dpi-300x145.png" alt="" title="compass-logo-300dpi-300x145" width="300" height="145" class="aligncenter size-full wp-image-3186" /></a></p>
<p><strong>Web:</strong> <a href="http://www.csnc.ch/">http://www.csnc.ch/</a><br />
<strong>Position:</strong> IT Security Analyst<br />
<strong>Company Description</strong>: <img src="http://cocaman.ch/wp/wp-content/uploads/2010/12/compass-services-small.png" alt="" title="compass-services-small" width="171" height="172" class="alignright size-full wp-image-3207" />Compass Security AG is a leading European service company based in Rapperswil-Jona (CH), which was founded in 1999, specialising in security assessments for the confidentiality, availability and integrity of corporate data. With penetration tests, ethical hacking and reviews Compass preventatively assesses ICT solutions in respect of security risks, detects existing weaknesses and supports the customers in their elimination. Hands-on workshops and trainings on IT-security topics as well as live-hacking-presentations to raise awareness of users complete the portfolio. Neutrality and product independence are essential components of the corporate policy. The clientele consists of national and international customers of any size and in various fields.<br />
<strong>Additional Projects:</strong></p>
<ul>
<li><a href="https://www.filebox-solution.com/login/">FileBox</a>, a secure document exchange solution.</li>
<li><a href="http://www.hacking-lab.com/">Hacking-Lab</a>, an online IT security learning environment and lab. Learn and understand newest attack vectors and learn how to avoid and protect yourself and your product from those.</li>
<li><a href="http://www.swisscyberstorm.com/">Swiss Cyberstorm III</a>, 2-day conference about IT security, with a 2-day hands-on security and hacking event.</li>
</ul>
<p><strong>Jobs:</strong> Yes, we are looking for <a href="http://www.csnc.ch/en/profile/jobs.html">talented and skilled people</a>.</p>
<p>If you have a project or product that you think could benefit from a security audit or review, please contact me at any time. We love to discuss any options with you.</p>
<p>Corsin Camichel, <a href="mailto:corsin.camichel@csnc.ch">corsin.camichel@csnc.ch</a></p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=3185&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2011/02/google-account-2-step-verification/" title="Google Account 2-Step Verification">Google Account 2-Step Verification</a></li><li><a href="http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/" title="Internet Storm Center lists suspiciuos .ch Domains">Internet Storm Center lists suspiciuos .ch Domains</a></li><li><a href="http://cocaman.ch/wp/2010/04/qq829-com-an-quick-investigation/" title="qq829.com &#8211; A Quick Investigation">qq829.com &#8211; A Quick Investigation</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/12/security-analyst-compass-security-disclaimer/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Internet Storm Center lists suspiciuos .ch Domains</title>
		<link>http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/</link>
		<comments>http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/#comments</comments>
		<pubDate>Wed, 08 Dec 2010 20:49:24 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[domains]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[switch]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=3211</guid>
		<description><![CDATA[Update December 10th: SWITCH has asked if I could link to their press release from a couple of weeks. Just one note on that: In the Wikileaks.ch press statement, SWITCH states that &#8220;a domain name is not the same as a website&#8221; and that SWITCH is not responsible for the content of any .ch or [...]]]></description>
			<content:encoded><![CDATA[<p>Update December 10th: SWITCH has asked if I could link to their <a href="http://switch.ch/about/news/2010/malware-nov2010.html">press release</a> from a couple of weeks.<br />
Just one note on that: In the <a href="http://switch.ch/about/news/2010/wikileaks">Wikileaks.ch</a> press statement, SWITCH states that &#8220;a domain name is not the same as a website&#8221; and that SWITCH is not responsible for the content of any .ch or .li domains. Funny, with the action against malware, they are clearly ignoring this fact and they act based solely on content of a website. Just my 2 cents&#8230;</p>
<p>Original post:<br />
The Swiss Domain Name registry SWITCH is allowed by law to remove/block access to malicious domains. I won&#8217;t talk if this makes sense or not&#8230; But today, thanks to Roman of abuse.ch I have found a new <a href="http://isc.sans.edu/tools/suspicious_domains.html">list</a> by the <a href="http://isc.sans.edu/">Internet Storm Center</a>. That list contains malicious or suspecious websites and domains. Not less than 11 of those domains are .ch domains.</p>
<ul>
<li>all-switzerland.ch (88.198.58.152)</li>
<li>alpine-balloon-challenge.ch (78.138.113.46)</li>
<li>artsimone.ch (217.26.52.28)</li>
<li>feuerwehr-zermatt.ch (80.86.198.13)</li>
<li>fivestar.ch (77.72.71.43)</li>
<li>jaquemet-zehnder.ch (82.195.224.107)</li>
<li>jes.ch (78.46.93.8)</li>
<li>jugendfeuerwehr-zermatt.ch (255.255.255.255, VERY strange)</li>
<li>mg-bern.ch (213.133.103.19)</li>
<li>tamiljugend.ch (66.147.240.158)</li>
<li>ushan.ch (not registered)</li>
</ul>
<p>What I have discovered, is that the websites are hosted with different providers. Therefor this does not seem to be a compromised server or anything.<br />
The question that remains is, if Switch (or nic.ch) will block those domains and if so, what can the owners of those domain names do against it?</p>
<p>Please keep in mind, these domains are only being suspected of hosting and distributing malicious content! But it is recommended to not visit any of these hosts!</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=3211&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2011/02/google-account-2-step-verification/" title="Google Account 2-Step Verification">Google Account 2-Step Verification</a></li><li><a href="http://cocaman.ch/wp/2010/12/security-analyst-compass-security-disclaimer/" title="My New Job: Security Analyst">My New Job: Security Analyst</a></li><li><a href="http://cocaman.ch/wp/2010/04/qq829-com-an-quick-investigation/" title="qq829.com &#8211; A Quick Investigation">qq829.com &#8211; A Quick Investigation</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TV.Centerr and Adobe Flash Player 10.1.92.10</title>
		<link>http://cocaman.ch/wp/2010/09/tv-centerr-and-adobe-flash-player-10-1-92-10/</link>
		<comments>http://cocaman.ch/wp/2010/09/tv-centerr-and-adobe-flash-player-10-1-92-10/#comments</comments>
		<pubDate>Wed, 15 Sep 2010 06:46:42 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[android]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[htc-desire]]></category>
		<category><![CDATA[player]]></category>
		<category><![CDATA[tv-centerr]]></category>
		<category><![CDATA[tvcenterr]]></category>
		<category><![CDATA[zattoo]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=3130</guid>
		<description><![CDATA[Adobe recently updated their Flash player for the Android platform. No big deal you should guess. But wrong. Somehow the managed to screw up big! There is a security hole, Adobe also managed to somehow break TV.Centerr and the general Zattoo.com stream. For now all you can do if TV.Centerr or Zattoo.com is not working [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe recently updated their Flash player for the Android platform. No big deal you should guess. But wrong. Somehow the managed to screw up big! There is a <a href="http://www.adobe.com/support/security/advisories/apsa10-03.html">security hole</a>, Adobe also managed to somehow break <a href="http://tv.centerr.com/">TV.Centerr</a> and the general Zattoo.com stream.</p>
<p>For now all you can do if TV.Centerr or Zattoo.com is not working for you, remove Adobe Flash player and install this version:<br />
<a href="http://tv.centerr.com/download/AdobeFlashPlayer10.1.92.8.apk">Download Adobe Flash Player 10.1.92.8 for Android</a></p>
<p>I am really sorry, but this is out of my hands.</p>
<p><code style="font-size:smaller"><br />
<span style="color:blue">DEBUG/QCvdec(161):  VDEC Open with new H 352 and W 416<br />
DEBUG/QCvdec(161): portDefn->nBufferSize 219648 m_height 352 m_width 416<br />
DEBUG/QCvdec(161): portDefn->nBufferSize 219648 m_height 352 m_width 416<br />
DEBUG/QCvdec(161): portDefn->nBufferSize 219648 m_height 352 m_width 416</span><br />
<span style="color:orange">WARN/QCvdec(161): H264_Utils::check_header<br />
WARN/QCvdec(161): check_header: start code 31<br />
WARN/QCvdec(161): check_header: start code got fisrt NAL 4<br />
WARN/QCvdec(161): check_header: start code looking for second NAL 4<br />
WARN/QCvdec(161): Error at extract rbsp line 1548<br />
WARN/QCvdec(161): check_header: start code partial nal in one buffer 31<br />
WARN/QCvdec(161): H264_Utils::check_header<br />
WARN/QCvdec(161): check_header: start code 8<br />
WARN/QCvdec(161): check_header: start code got fisrt NAL 4<br />
WARN/QCvdec(161): check_header: start code looking for second NAL 4<br />
WARN/QCvdec(161): Error at extract rbsp line 1548<br />
WARN/QCvdec(161): check_header: start code partial nal in one buffer 8<br />
WARN/QCvdec(161): H264 profile 77, level 21<br />
WARN/QCvdec(161): vdec_open</span><br />
<span style="color:red">ERROR/QCvdec(161): adsp: cannot open cpu_dma_latency, fd: 23 (Permission denied)</span><br />
<span style="color:orange">WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching arbitrary bytes -  SUBFRAME_TYPE_PREVIOUS_FRAME<br />
WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching arbitrary bytes -  SUBFRAME_TYPE_PREVIOUS_FRAME<br />
WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching arbitrary bytes -  SUBFRAME_TYPE_PREVIOUS_FRAME<br />
WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching - add entry previous buffer<br />
WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching arbitrary bytes -  SUBFRAME_TYPE_PREVIOUS_FRAME<br />
WARN/QCvdec(161): add_entry_subframe_stitching- H264<br />
WARN/QCvdec(161): add_entry_subframe_stitching - add entry previous buffer</span><br />
</code></p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=3130&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/07/unofficial-zattoo-android-app-android-2-2/" title="Unofficial Zattoo Android App (Android 2.2)">Unofficial Zattoo Android App (Android 2.2)</a></li><li><a href="http://cocaman.ch/wp/2010/12/adobe-flash-player-for-android-lol/" title="Adobe Flash Player for Android &#8230; *lol*">Adobe Flash Player for Android &#8230; *lol*</a></li><li><a href="http://cocaman.ch/wp/2010/07/zattoo-on-android-mobile-phones/" title="Zattoo on Android Mobile Phones">Zattoo on Android Mobile Phones</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/09/tv-centerr-and-adobe-flash-player-10-1-92-10/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Why I Love Android &#8211; I</title>
		<link>http://cocaman.ch/wp/2010/09/why-i-love-android-i/</link>
		<comments>http://cocaman.ch/wp/2010/09/why-i-love-android-i/#comments</comments>
		<pubDate>Wed, 08 Sep 2010 12:06:42 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[android]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[OpenSource]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[why-i-love-android]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=3118</guid>
		<description><![CDATA[This is the start of a series of posts about &#8220;Why I Love Android&#8221; and the community around it. No flame or hate against other platforms intended. And if you think I troll, please troll in the comments with me Reason why I Love Android from September 8th, 2010 Cloud2Android aka Android Cloud to Device [...]]]></description>
			<content:encoded><![CDATA[<p>This is the start of a series of posts about &#8220;<a href="http://cocaman.ch/wp/tag/why-i-love-android/">Why I Love Android</a>&#8221; and the community around it. No flame or hate against other platforms intended. And if you think I troll, please troll in the comments with me <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><strong>Reason why I Love Android</strong> from September 8th, 2010<br />
Cloud2Android aka <a href="http://developer.android.com/sdk/android-2.2-highlights.html#DeveloperServices">Android Cloud to Device Messaging</a> &#8211; send any website, Google Map (including navigation) or a phone number to your Android device and work with it. Need to read on the road? Send a URL. Need to make a call? Don&#8217;t type in the number, select it and send it to your device. Uses <a href="http://code.google.com/p/chrometophone/">ChromeToPhone</a>.</p>
<p><a href="http://code.google.com/p/android-notifier/">Remote Notifier</a> &#8211; See on your Mac/Linux/Windows computer any notifications. Got an SMS? Let Growl display it on your Mac. Get notified about your current battery state. Display incoming phone calls right on your desktop. This is sooo cool <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /><br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/09/macdroidnotifier.jpg"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/09/macdroidnotifier-311x300.jpg" alt="" title="macdroidnotifier" width="311" height="300" class="aligncenter size-medium wp-image-3119" /></a></p>
<p>These are the two features for today. Both show what you can do with an open system like Android is. There is data pushing in both directions. And it is easy and everything I showed to you is open source and you can use it in your own applications. Just make sure to take security in your hands <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=3118&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/11/android-market-comes-to-the-web/" title="Android Market comes to the web">Android Market comes to the web</a></li><li><a href="http://cocaman.ch/wp/2010/08/google-wtf-chrome-to-phone-update/" title="Hey @Google WTF?? Chrome To Phone Update">Hey @Google WTF?? Chrome To Phone Update</a></li><li><a href="http://cocaman.ch/wp/2010/05/htc-removes-desire-kernel-sources/" title="@HTC removes Desire Kernel Sources?">@HTC removes Desire Kernel Sources?</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/09/why-i-love-android-i/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>qq829.com &#8211; A Quick Investigation</title>
		<link>http://cocaman.ch/wp/2010/04/qq829-com-an-quick-investigation/</link>
		<comments>http://cocaman.ch/wp/2010/04/qq829-com-an-quick-investigation/#comments</comments>
		<pubDate>Mon, 19 Apr 2010 09:22:44 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[cnzz]]></category>
		<category><![CDATA[qq829]]></category>
		<category><![CDATA[referrer]]></category>
		<category><![CDATA[statistic]]></category>
		<category><![CDATA[stats]]></category>
		<category><![CDATA[webstat]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=2677</guid>
		<description><![CDATA[For a couple of days, I see strange referrers to this blog. Some visitors are arriving from a qq829.com/web_stat.asp?dn=URL. On that website you see nothing special. Just an image that looks like a tracking icon. If you check the source code of the page you will see, that this icon is included with a Javascript [...]]]></description>
			<content:encoded><![CDATA[<p>For a couple of days, I see strange referrers to this blog. Some visitors are arriving from a qq829.com/web_stat.asp?dn=URL. On that website you see nothing special. Just an image that looks like a tracking icon. If you check the source code of the page you will see, that this icon is included with a Javascript code:<br />
<em>http://s130.cnzz.com/stat.php?id=1958849&#038;web_id=1958849&#038;show=pic1</em></p>
<p>And indeed, this Javascript file tracks visitors to the qq829.com domain. The hosted domain cnzz.com seems to offer website tracking stats and other services.</p>
<p>As far as I can tell now, it does not look like this is a malicious service (yet). What I do not understand is, why somebody wants to track webesites of mine for some stats. I have never registered anything at cnzz.com. And the exact affiliation of qq829.com and cnzz.com is unclear at this point. As a security measure, don&#8217;t click any links and do not visit those sites. For now there seems to be no real solution to block such access.</p>
<p>qq829.com was registered in August 2009 and is hosted in China.</p>
<p>More information can be found on the <a href="http://www.google.com/support/forum/p/Google+Analytics/thread?tid=753964c1b74e57d4&#038;hl=en">Google Analytics Support forum</a>.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=2677&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2011/02/google-account-2-step-verification/" title="Google Account 2-Step Verification">Google Account 2-Step Verification</a></li><li><a href="http://cocaman.ch/wp/2010/12/security-analyst-compass-security-disclaimer/" title="My New Job: Security Analyst">My New Job: Security Analyst</a></li><li><a href="http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/" title="Internet Storm Center lists suspiciuos .ch Domains">Internet Storm Center lists suspiciuos .ch Domains</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/04/qq829-com-an-quick-investigation/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Facebook Scam: Additional E-Mail Addresses</title>
		<link>http://cocaman.ch/wp/2010/04/facebook-scam-additional-e-mail-addresses/</link>
		<comments>http://cocaman.ch/wp/2010/04/facebook-scam-additional-e-mail-addresses/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 09:04:51 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[danger]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[SPAM]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=2656</guid>
		<description><![CDATA[Facebook is huge with soon 500 million users worldwide. And bad people try to abuse that large user base with different techniques and methods. One that I came across today is a scam email which wants to you view some photos. If you click the link, Facebook asks you for your password and to verify [...]]]></description>
			<content:encoded><![CDATA[<p>Facebook is huge with soon 500 million users worldwide. And bad people try to abuse that large user base with different techniques and methods. One that I came across today is a scam email which wants to you view some photos. If you click the link, Facebook asks you for your password and to verify that you want to add a new email address to your profile. <strong>Do not do this!</strong><br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/04/facebook_merge-accounts.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/04/facebook_merge-accounts-449x149.png" alt="" title="facebook_merge-accounts" width="449" height="149" class="aligncenter size-medium wp-image-2657" /></a></p>
<p>You may wonder why people want to add an email address to your profile. The reason is, that if you do this, they can request a password reset and can then use your Facebook profile.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=2656&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/" title="Internet Storm Center lists suspiciuos .ch Domains">Internet Storm Center lists suspiciuos .ch Domains</a></li><li><a href="http://cocaman.ch/wp/2010/06/facebook-new-privacy-settings/" title="Facebook &#8211; New Privacy Settings">Facebook &#8211; New Privacy Settings</a></li><li><a href="http://cocaman.ch/wp/2010/04/do-not-let-idiots-send-emails/" title="Do Not Let Idiots Send Emails">Do Not Let Idiots Send Emails</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/04/facebook-scam-additional-e-mail-addresses/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SofTax 2009 PDF Speichern/Kopieren</title>
		<link>http://cocaman.ch/wp/2010/03/softax-2009-pdf-speichernkopieren/</link>
		<comments>http://cocaman.ch/wp/2010/03/softax-2009-pdf-speichernkopieren/#comments</comments>
		<pubDate>Sun, 28 Mar 2010 17:41:49 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[graubünden]]></category>
		<category><![CDATA[macosx]]></category>
		<category><![CDATA[softax]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[steuern]]></category>
		<category><![CDATA[tax]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=2609</guid>
		<description><![CDATA[Es ist wieder einmal die Jahreszeit, wo tausende von Schweizer und Schweizerinnen ihre Steuererklärung ausfüllen und abgeben müssen. Wer die Graubünder Software &#8220;SofTax&#8221; verwendet, hat natürlich den digitalen Vorteil gegenüber der Papierversion. Jedoch lässt sich das generierte PDF nicht kopieren oder speichern. Eigentlich. Dank eines einfachen Tricks für Mac OS X lässt es sich doch [...]]]></description>
			<content:encoded><![CDATA[<p>Es ist wieder einmal die Jahreszeit, wo tausende von Schweizer und Schweizerinnen ihre Steuererklärung ausfüllen und abgeben müssen. Wer die Graubünder Software &#8220;<a href="http://www.gr.ch/DE/institutionen/verwaltung/dfg/stv/dienstleistungen/deklarationssoftware/einkommens_und_vermoegenssteuer/Seiten/download.aspx">SofTax</a>&#8221; verwendet, hat natürlich den digitalen Vorteil gegenüber der Papierversion. Jedoch lässt sich das generierte PDF nicht kopieren oder speichern. Eigentlich. Dank eines einfachen Tricks für Mac OS X lässt es sich doch speichern und kopieren. Dazu muss man einfach das geöffnete PDF in den Papierkorb verschieben. Diese Option findet man in &#8220;Preview&#8221; (&#8220;Vorschau&#8221; auf deutsch&#8221;) unter &#8220;Bearbeiten&#8221;, &#8220;Geöffnetes PDF in den Papierkorb verschieben&#8221;.<br />
<img src="http://cocaman.ch/wp/wp-content/uploads/2010/03/Softax-PDF-in-Papierkorb-verschieben.png" alt="" title="Softax PDF in Papierkorb verschieben" width="413" height="360" class="aligncenter size-full wp-image-2610" /></p>
<p>Hat man das Dokument in den Papierkorb verschoben, kann man es ganz einfach auf den Desktop verschieben und hat vollen Zugriff auf das Dokument. Also kopieren oder per E-Mail versenden.</p>
<p>Vielleicht klappt der Trick auch für andere Steuersoftware. Verifizieren kann ich das selbst nicht <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> . Auch nicht, ob es einen ähnlichen Tipp für Windows Systeme gibt.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=2609&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/02/backblaze-online-backup/" title="Perfect Online Backup Strategy">Perfect Online Backup Strategy</a></li><li><a href="http://cocaman.ch/wp/2010/11/xtra-zone-app-von-android-market-entfernt/" title="Xtra Zone App von Android Market entfernt">Xtra Zone App von Android Market entfernt</a></li><li><a href="http://cocaman.ch/wp/2010/08/xtrazone-android-app/" title="XtraZone Android App">XtraZone Android App</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/03/softax-2009-pdf-speichernkopieren/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Perfect Online Backup Strategy</title>
		<link>http://cocaman.ch/wp/2010/02/backblaze-online-backup/</link>
		<comments>http://cocaman.ch/wp/2010/02/backblaze-online-backup/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 08:30:31 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Stuff]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[backblaze]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[cloud-backup]]></category>
		<category><![CDATA[cloud-storage]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[macosx]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[storage]]></category>
		<category><![CDATA[trial]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=2529</guid>
		<description><![CDATA[For over 15 months I am using BackBlaze as an online backup system. Once installed and configured, it automatically backs up all my data in the background. No matter how many files or how large your backup is, everything is safe. BackBlaze currently backs up 38 GB of data in 634&#8217;244 files for me. Now [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.backblaze.com/partner/af0569"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/bzad_486X60-red2.gif" alt="" title="bzad_486X60-red2" width="468" height="60" class="aligncenter size-full wp-image-2530" /></a></p>
<p>For over 15 months I am using <a href="http://www.backblaze.com/partner/af0569">BackBlaze</a> as an online backup system. Once installed and configured, it automatically backs up all my data in the background. No matter how many files or how large your backup is, everything is safe. BackBlaze currently backs up 38 GB of data in 634&#8217;244 files for me.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.07.18-AM.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.07.18-AM-420x300.png" alt="" title="Screen shot 2010-02-25 at 9.07.18 AM" width="420" height="300" class="aligncenter size-medium wp-image-2532" /></a></p>
<p>Now you might wonder how much <a href="http://www.backblaze.com/partner/af0569">BackBlaze</a> costs. All with unlimited space and file storage. It is j<a href="http://www.backblaze.com/partner/af0569">ust $5/month</a>. This price is insanely low.</p>
<p>The system works for Windows and Mac OS X computers. It is very easy to set up and use. Why not give it a <a href="http://www.backblaze.com/partner/af0569">quick try</a>? It&#8217;s free and if you like it, you already have started your <a href="http://www.backblaze.com/partner/af0569">backup strategy</a>!</p>
<p>A feature list:</p>
<ul>
<li>Online Backup</li>
<li>Web Download Restore</li>
<li>Unlimited Storage</li>
<li>DVD or USB Drive Restore</li>
<li>Backup External Drives</li>
<li>FSCAN Performance</li>
<li>Automatically Finds Files</li>
<li>Versioning</li>
<li>Finer Control Options</li>
<li>Activity Reports</li>
<li>Military-Grade Encryption</li>
<li>11 Language Interface</li>
<li>Idle-Time Backup</li>
<li>Custom Network Throttle</li>
<li>Scheduled Backup</li>
<li>Just $5/Month</li>
</ul>
<h3>Screenshots</h3>
<p>Settings panel, allows you to set the backup speed, external devices and so on.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.12.25-AM.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.12.25-AM-403x300.png" alt="" title="Screen shot 2010-02-25 at 9.12.25 AM" width="403" height="300" class="aligncenter size-medium wp-image-2533" /></a></p>
<p>Schedule backup or continuously back up your data.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.12.58-AM.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.12.58-AM-403x300.png" alt="" title="Screen shot 2010-02-25 at 9.12.58 AM" width="403" height="300" class="aligncenter size-medium wp-image-2534" /></a></p>
<p>Exclude folder you do not want secured.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.13.28-AM.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.13.28-AM-403x300.png" alt="" title="Screen shot 2010-02-25 at 9.13.28 AM" width="403" height="300" class="aligncenter size-medium wp-image-2535" /></a></p>
<p>Encrypt your files. Set a password and your files are stored with high encryption.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.13.51-AM.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.13.51-AM-403x300.png" alt="" title="Screen shot 2010-02-25 at 9.13.51 AM" width="403" height="300" class="aligncenter size-medium wp-image-2536" /></a></p>
<p>Detailed view of what files you have stored.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.14.34-AM.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/Screen-shot-2010-02-25-at-9.14.34-AM-403x300.png" alt="" title="Screen shot 2010-02-25 at 9.14.34 AM" width="403" height="300" class="aligncenter size-medium wp-image-2537" /></a></p>
<p>Online Restore View<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/backblaze-restore-view.jpg"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/backblaze-restore-view-450x203.jpg" alt="" title="backblaze-restore-view" width="450" height="203" class="aligncenter size-medium wp-image-2539" /></a></p>
<p>Online Restore Options<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2010/02/backblaze-restore-options.jpg"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/backblaze-restore-options-450x149.jpg" alt="" title="backblaze-restore-options" width="450" height="149" class="aligncenter size-medium wp-image-2540" /></a> </p>
<p><a href="http://www.backblaze.com/partner/af0569"><img src="http://cocaman.ch/wp/wp-content/uploads/2010/02/bzad_200x200-red3.gif" alt="" title="bzad_200x200-red3" width="200" height="200" class="alignleft size-full wp-image-2545" /></a> <a href="http://www.backblaze.com/partner/af0569">Give Backblaze a try</a>. It&#8217;s is free and your first step to a satisfying online backup system.<br clear="all" /></p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=2529&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2009/08/breaking-the-network/" title="Breaking the Network: SSH Server as Proxy for Secure Browsing">Breaking the Network: SSH Server as Proxy for Secure Browsing</a></li><li><a href="http://cocaman.ch/wp/2008/06/web-20-and-open-source-in-startups-a-sun-event/" title="Web 2.0 and Open Source in Startups &#8211; A Sun Event">Web 2.0 and Open Source in Startups &#8211; A Sun Event</a></li><li><a href="http://cocaman.ch/wp/2010/03/softax-2009-pdf-speichernkopieren/" title="SofTax 2009 PDF Speichern/Kopieren">SofTax 2009 PDF Speichern/Kopieren</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2010/02/backblaze-online-backup/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Spam of the Day: WifiNt Domain Spam</title>
		<link>http://cocaman.ch/wp/2009/10/spam-of-the-day-wifint-domain-spam/</link>
		<comments>http://cocaman.ch/wp/2009/10/spam-of-the-day-wifint-domain-spam/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 21:18:35 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[register]]></category>
		<category><![CDATA[SPAM]]></category>
		<category><![CDATA[trick]]></category>
		<category><![CDATA[wifint.cn]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=2065</guid>
		<description><![CDATA[Today in Spam: Hannah from Wifint.cn who write to tell me that Robert Jiang wants to register .cn/.com.cn/.hk/.asia and other domain names which are similar to a .com I own. Dear Sir/Madam We are a internet service (software development, website design and development, wifi network works to promote the protection of brands, search engine optimization, [...]]]></description>
			<content:encoded><![CDATA[<p>Today in Spam: Hannah from Wifint.cn who write to tell me that Robert Jiang wants to register .cn/.com.cn/.hk/.asia and other domain names which are similar to a .com I own.</p>
<blockquote><p>Dear Sir/Madam</p>
<p>We are a internet service (software development, website design and development, wifi network works to promote the protection of brands, search engine optimization, etc.) company in China,</p>
<p>Several days ago we received a formal application submited by Robert  Jiang who wanted to use the keyword  &#8220;<em>keyword</em>&#8221; to  register the Internet Brand and with</p>
<p>suffix  .cn /.com.cn /.net.cn/.hk/ .asia/ domain names. </p>
<p>After our initial checking through Internet , we found that the keyword &#8220;<em>keyword</em>&#8221; to be applied for registration  is  same as your  keyword.Accordingly,before we finish his registration,we would like to get  your final decision about  this,whether you mind his registration,if you believe his registration would affect your bussiness and produce conflict,then we could give your priority to register them,as the keyword is first used by your company.However,if you do not think so,please advise of that and then we will finish his registration.</p>
<p>For  proceeding the next step, Please contact us by Fax ,Telephone or Email as soon as possible.   Under the circumstance of no your reply during the next 5 working days ,we will consider you to give it up and finish his registration.</p>
<p>Yours sincerely </p>
<p>Hannah</p>
<p>Checking Department<br />
Tel:  86 513 85330968<br />
Fax:  86 513 80260106<br />
Email:Hannah@wifint.cn<br />
Website: www.wifint.cn
</p></blockquote>
<p>Nice try Hannah but I call your bluff. There is no way that somebody wants that domain name and for sure are you not allowed to display names of a potential buyer. And no, I do not want you to &#8220;take action&#8221; and send me a bill for &#8220;your work avoiding some third party&#8221; to register a domain name.<br />
If you get an email like that, just delete it. This will not harm you.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=2065&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/04/do-not-let-idiots-send-emails/" title="Do Not Let Idiots Send Emails">Do Not Let Idiots Send Emails</a></li><li><a href="http://cocaman.ch/wp/2010/04/facebook-scam-additional-e-mail-addresses/" title="Facebook Scam: Additional E-Mail Addresses">Facebook Scam: Additional E-Mail Addresses</a></li><li><a href="http://cocaman.ch/wp/2009/10/srg-ssr-buys-sfr-ch-for-6000-eur/" title="SRG SSR Buys sfr.ch For 6000 EUR">SRG SSR Buys sfr.ch For 6000 EUR</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2009/10/spam-of-the-day-wifint-domain-spam/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Anti-WordPress-Hacking Suggestions</title>
		<link>http://cocaman.ch/wp/2009/09/anti-wordpress-hacking-suggestions/</link>
		<comments>http://cocaman.ch/wp/2009/09/anti-wordpress-hacking-suggestions/#comments</comments>
		<pubDate>Sat, 05 Sep 2009 20:47:06 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[idea]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=1966</guid>
		<description><![CDATA[After the recent discussion about the hacks that are used to break into blogs with the WordPress software, I came up with a few ideas on how to make WordPress more secure. More security for adding administrators First of all I really would like to have a method in WordPress that sends an administrator an [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/09/icon_big.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/09/icon_big-150x150.png" alt="icon_big" title="icon_big" width="150" height="150" class="alignleft size-thumbnail wp-image-1970" /></a>After the <a href="http://lorelle.wordpress.com/2009/09/04/old-wordpress-versions-under-attack/">recent</a> <a href="http://friendfeed.com/scobleizer/cd43c6c3/i-dont-feel-safe-with-wordpress-hackers-broke-in">discussion</a> <a href="http://mashable.com/2009/09/05/wordpress-attack/">about</a> <a href="http://www.techcrunch.com/2009/09/05/security-threat-wordpress-under-attack/">the</a> <a href="http://search.twitter.com/search?q=wordpress+hack">hacks</a> that are used to break into blogs with the WordPress software, I came up with a few ideas on how to make WordPress more secure.</p>
<h3>More security for adding administrators</h3>
<p>First of all I really would like to have a method in WordPress that <strong>sends an administrator an email once a new admin is created.</strong> This <strong>email has to be verified</strong> (by clicking a link inside the email for example) and only after that has been done the new admin user is allowed to login and change settings and permissions.<br />
This of course only works if the new user is created via the web interface. If an attacker has rights to the underlying layer, the database, this method is useless.</p>
<h3>WordPress Table Names</h3>
<p>Which brings me to my second suggestion. Each and every WordPress installation uses tables in the format of &#8220;<em>wp_</em>&#8220;. This simplifies the method to inject SQL. A simple solution to this is to have a <strong>random string in front of wp_</strong> at the installation. Currently the default is just wp_. But what, if the default is randomly generated? Each installation would be in different tables. So instead of <em>wp_users</em> my users would be in <em>as3202_wp_users</em>.</p>
<p>What about a system that checks once a day what content has been changed on my blog. Like for example a hacker creates 100 new pages, the system sends me an email in the morning with all the changes. This allows me to have a quick overview what happened and has been changed. Or I can even tell the system I am on vacation and it should send me an email as soon as any content is altered. This sounds a little like a watchdog <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> .</p>
<p>Of course, it is not all WordPress&#8217; fault. What about faulty plugins? Everybody can create a malicious plugin or even a theme and distribute it. But there I see more the webmaster or blog owner to be responsible.</p>
<p>These are just three ideas that quickly came to mind. I am sure there are many more ideas and things one could use to make WordPress more secure.</p>
<p><strong>What do you think? Do you have your own ideas? Or think mine are crap? Please, share your ideas and thoughts in the comments!</strong></p>
<p><strong>Update:</strong> Matt <a href="http://wordpress.org/development/2009/09/keep-wordpress-secure/">just posted an entry</a> on the WordPress.org that explains a little bit what the worm does and that you always should update as soon as possible.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=1966&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/02/backblaze-online-backup/" title="Perfect Online Backup Strategy">Perfect Online Backup Strategy</a></li><li><a href="http://cocaman.ch/wp/2009/10/stis-update-and-news/" title="STIS Update and News">STIS Update and News</a></li><li><a href="http://cocaman.ch/wp/2009/02/annoying-wordpress-bug/" title="Annoying WordPress Bug">Annoying WordPress Bug</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2009/09/anti-wordpress-hacking-suggestions/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Breaking the Network: SSH Server as Proxy for Secure Browsing</title>
		<link>http://cocaman.ch/wp/2009/08/breaking-the-network/</link>
		<comments>http://cocaman.ch/wp/2009/08/breaking-the-network/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 16:39:18 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[lan]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[macosx]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[openssh]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=1801</guid>
		<description><![CDATA[Our university LAN is pretty restricted. You can only access the most basic ports like http (80), ftp (21), ssh (22), pop3, imap and so on. But what if you need another port like a port to manage a webserver? After some tuning and searching we came up with the almost perfect solution. And it [...]]]></description>
			<content:encoded><![CDATA[<p>Our <a href="http://www.hsr.ch/">university LAN</a> is pretty restricted. You can only access the most basic ports like http (80), ftp (21), ssh (22), pop3, imap and so on. But what if you need another port like a port to manage a webserver?<br />
After some tuning and searching we came up with the almost perfect solution. And it is very easy but effective.<br />
All you need is </p>
<ul>
<li>A UNIX (Linux/Ubuntu for example) server with a SSH server and your account</li>
<li><a href="http://getfirefox.com/">Firefox</a> 3.5 (works with earlier versions)</li>
<li><a href="http://foxyproxy.mozdev.org/">FoxyProxy</a> Addon for Firefox</li>
</ul>
<p>Install Foxyproxy and restart Firefox. If you install Foxyproxy later, the windows below will look differently! You will than have to use the <a href="#oldwindow">settings below</a> and add regex and so on later.</p>
<p>First open a xterm console and enter the following command:</p>
<blockquote><p><strong>ssh -C2qTnN -D &lt;port-you-want&gt; &lt;ssh-user&gt;@&lt;sshserver&gt;</strong></p></blockquote>
<p>Now edit your Firefox proxy settings under </p>
<blockquote><p><em>Preferences -> Advanced -> Network -> Connection -> Settings</em></p></blockquote>
<p>In this window enter the following values:<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-1.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-1-300x207.png" alt="ssh-proxy-1" title="ssh-proxy-1" width="300" height="207" class="aligncenter size-medium wp-image-1806" /></a><br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-4.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-4-300x201.png" alt="ssh-proxy-4" title="ssh-proxy-4" width="300" height="201" class="aligncenter size-medium wp-image-1813" /></a><br />
Enter <strong>localhost</strong> or <strong>127.0.0.1</strong> as the server and as port the number you used in the SSH command.</p>
<p><a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-2.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-2-300x225.png" alt="ssh-proxy-2" title="ssh-proxy-2" width="300" height="225" class="aligncenter size-medium wp-image-1809" /></a><br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-3.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-3-300x194.png" alt="ssh-proxy-3" title="ssh-proxy-3" width="300" height="194" class="aligncenter size-medium wp-image-1810" /></a><br />
I used a regex <em><strong>https?://.*:2083/.*</strong></em> that checks any URL I visit and if it matches, the &#8220;SSH Proxy&#8221; is activated. Of course the SSH connection has to be open to work. You can alter my regex and use any other port like 10000 for <a href="http://webmin.com/">Webmin</a> or 443 and that will redirect ALL SSL traffic trough your SSH server.</p>
<p>This works like a charm and is almost perfect. Next thing is to have the SSH connection being started directly by Foxyproxy.</p>
<p><a name="oldwindow"></a></p>
<h3>Settings for non Foxyproxy users</h3>
<p>If you do not want to use Foxyproxy, your proxy window should look like this:<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-5.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/08/ssh-proxy-5-300x295.png" alt="ssh-proxy-5" title="ssh-proxy-5" width="300" height="295" class="aligncenter size-medium wp-image-1817" /></a><br />
Make sure you only enter the IP address or localhost in the Sockets proxy section! If you try this and it wont work, enter <a href="about:config">about:config</a> in your browser bar and search this entry: <strong>network.proxy.socks_remote_dns</strong> and set it to <strong>true</strong>. Without Foxyproxy you will not be able to define different proxy server or use the proxy server based on rules/regular expressions. All your traffic will be routed trough your SSH server. And this could make surfing slower and your downloads even slower.</p>
<p>Some information from <a href="https://calomel.org/firefox_ssh_proxy.html">calomel.org</a>. Thanks to Christian for testing and researching with me.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=1801&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/02/backblaze-online-backup/" title="Perfect Online Backup Strategy">Perfect Online Backup Strategy</a></li><li><a href="http://cocaman.ch/wp/2009/04/vim-regex-search-and-delete-line/" title="vim: Regex Search and Delete Line">vim: Regex Search and Delete Line</a></li><li><a href="http://cocaman.ch/wp/2008/10/readings-for-today-10132008/" title="Readings for Today: 10/13/2008">Readings for Today: 10/13/2008</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2009/08/breaking-the-network/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Embed a Counter in Your Spam Messages</title>
		<link>http://cocaman.ch/wp/2009/04/embed-a-counter-in-your-spam-messages/</link>
		<comments>http://cocaman.ch/wp/2009/04/embed-a-counter-in-your-spam-messages/#comments</comments>
		<pubDate>Sat, 25 Apr 2009 17:25:07 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[mail.app]]></category>
		<category><![CDATA[SPAM]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=1434</guid>
		<description><![CDATA[I&#8217;ve got this email in my inbox &#8211; my junk folder to be more precise &#8211; today. Notice the counter on the bottom? 987994 people have read this email after 2 and a half hours of sending. Including me. The counter is hosted at a site called &#8220;Right Stats&#8221; (www.rightstats.com). It looks like a &#8220;real [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve got this email in my inbox &#8211; my junk folder to be more precise &#8211; today.<br />
<a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/04/mail_-_counter.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/04/mail_-_counter-300x238.png" alt="mail_-_counter" title="mail_-_counter" width="300" height="238" class="aligncenter size-medium wp-image-1433" /></a></p>
<p>Notice the counter on the bottom? <del datetime="2009-04-25T17:22:45+00:00">987</del>994 people have read this email after 2 and a half hours of sending. Including me.<br />
The counter is hosted at a site called &#8220;Right Stats&#8221; (www.rightstats.com). It looks like a &#8220;real free counter&#8221; website. But once you snooped around a little, you get 404 error messages all the time. A <code>whois</code> query shows that the page is hosted in Pakistan. They seem to offer a special counter version for emails.</p>
<p>Nevertheless, this is pretty new I think to embed a counter in your spam message. I will keep an eye on the counter and try to get access to the stats.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=1434&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2010/04/do-not-let-idiots-send-emails/" title="Do Not Let Idiots Send Emails">Do Not Let Idiots Send Emails</a></li><li><a href="http://cocaman.ch/wp/2010/04/facebook-scam-additional-e-mail-addresses/" title="Facebook Scam: Additional E-Mail Addresses">Facebook Scam: Additional E-Mail Addresses</a></li><li><a href="http://cocaman.ch/wp/2009/10/spam-of-the-day-wifint-domain-spam/" title="Spam of the Day: WifiNt Domain Spam">Spam of the Day: WifiNt Domain Spam</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2009/04/embed-a-counter-in-your-spam-messages/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Swiss Cyber Storm II &#8211; First Successful Day is Over</title>
		<link>http://cocaman.ch/wp/2009/04/swiss-cyber-storm-ii-first-successful-day-is-over/</link>
		<comments>http://cocaman.ch/wp/2009/04/swiss-cyber-storm-ii-first-successful-day-is-over/#comments</comments>
		<pubDate>Sat, 18 Apr 2009 15:50:49 +0000</pubDate>
		<dc:creator>CoCaman</dc:creator>
				<category><![CDATA[Event]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[hacking-lab]]></category>
		<category><![CDATA[Party]]></category>
		<category><![CDATA[scs2]]></category>
		<category><![CDATA[scsii]]></category>
		<category><![CDATA[swiss cyber storm]]></category>

		<guid isPermaLink="false">http://cocaman.ch/wp/?p=1397</guid>
		<description><![CDATA[I was 8th a few minutes before I made the screenshot&#60;/posing&#62; Gamlor is also here having a lot of phuns Cross Site Scripting his way up the ladder . Gugelhopf also has some fun I guess . She&#8217;s my favorite hacking girl this weekend! If you have time you definitely should drop by tomorrow and [...]]]></description>
			<content:encoded><![CDATA[<p><a rel="lightbox" href="http://cocaman.ch/wp/wp-content/uploads/2009/04/eventranking-_-hacking-labcom.png"><img src="http://cocaman.ch/wp/wp-content/uploads/2009/04/eventranking-_-hacking-labcom-300x210.png" alt="eventranking-_-hacking-labcom" title="eventranking-_-hacking-labcom" width="300" height="210" class="aligncenter size-medium wp-image-1396" /></a> <small>I was 8th a few minutes before I made the screenshot&lt;/posing&gt;</small></p>
<p><a href="http://gamlor.info/">Gamlor</a> is also here having a lot of phuns Cross Site Scripting his way up the ladder <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> . Gugelhopf also has some fun I guess <img src='http://cocaman.ch/wp/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> . She&#8217;s my favorite hacking girl this weekend!</p>
<p>If you have time you definitely should drop by tomorrow and have some fun with cool hackers.</p>
<img src="http://cocaman.ch/wp/?ak_action=api_record_view&id=1397&type=feed" alt="" /><h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://cocaman.ch/wp/2011/02/google-account-2-step-verification/" title="Google Account 2-Step Verification">Google Account 2-Step Verification</a></li><li><a href="http://cocaman.ch/wp/2010/12/security-analyst-compass-security-disclaimer/" title="My New Job: Security Analyst">My New Job: Security Analyst</a></li><li><a href="http://cocaman.ch/wp/2010/12/internet-storm-center-lists-suspiciuos-ch-domains/" title="Internet Storm Center lists suspiciuos .ch Domains">Internet Storm Center lists suspiciuos .ch Domains</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://cocaman.ch/wp/2009/04/swiss-cyber-storm-ii-first-successful-day-is-over/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

