<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>blocg - security</title>
    <link>http://blog.s6y.org/</link>
    <description>notes and hints...</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Thu, 06 May 2010 14:06:06 GMT</pubDate>

    <image>
        <url>http://blog.s6y.org/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: blocg - security - notes and hints...</title>
        <link>http://blog.s6y.org/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>TrumanBox development continues at SourceForge</title>
    <link>http://blog.s6y.org/index.php?/archives/9-TrumanBox-development-continues-at-SourceForge.html</link>
            <category>security</category>
    
    <comments>http://blog.s6y.org/index.php?/archives/9-TrumanBox-development-continues-at-SourceForge.html#comments</comments>
    <wfw:comment>http://blog.s6y.org/wfwcomment.php?cid=9</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.s6y.org/rss.php?version=2.0&amp;type=comments&amp;cid=9</wfw:commentRss>
    

    <author>nospam@example.com (christian)</author>
    <content:encoded>
    After a couple of requests about TrumanBox 0.1.03 which is available at &lt;a href=&quot;http://trumanbox.s6y.org&quot; title=&quot;TrumanBox&quot;&gt;trumanbox.s6y.org&lt;/a&gt; I would like to point you to &lt;a href=&quot;http://trumanbox.sourceforge.net&quot; title=&quot;trumanbox.sourceforge.net&quot;&gt;trumanbox.sourceforge.net&lt;/a&gt; where you may find the latest development version provided via subversion. It has many new features and many parts of the code have been rewritten/-structured by Lothar Braun who continued development since July 2009. The only reason for keeping the version at trumanbox.s6y.org online is that it was pretty stable, when I submitted it as a result of my thesis work in July 2007. 
    </content:encoded>

    <pubDate>Thu, 06 May 2010 11:50:03 +0200</pubDate>
    <guid isPermaLink="false">http://blog.s6y.org/index.php?/archives/9-guid.html</guid>
    
</item>
<item>
    <title>RFI Project</title>
    <link>http://blog.s6y.org/index.php?/archives/8-RFI-Project.html</link>
            <category>security</category>
    
    <comments>http://blog.s6y.org/index.php?/archives/8-RFI-Project.html#comments</comments>
    <wfw:comment>http://blog.s6y.org/wfwcomment.php?cid=8</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://blog.s6y.org/rss.php?version=2.0&amp;type=comments&amp;cid=8</wfw:commentRss>
    

    <author>nospam@example.com (christian)</author>
    <content:encoded>
    As I have mentioned in my &lt;a href=&quot;http://blog.s6y.org/index.php?/archives/7-Once-up-on-a-time-I-had-a-closer-look-on-RFI....html&quot; title=&quot;previous posting&quot;&gt;previous posting&lt;/a&gt; I have had a look at RFI attacks some time ago and planned to publish my results. Since those results were quite outdated we decided to alse collect come new data. Here one of my colleagues had a great idea, which he has also published on his &lt;a href=&quot;http://zeroq.kulando.de/post/2009/03/10/collecting-rfi-data&quot; title=&quot;blog&quot;&gt;blog&lt;/a&gt;. By proposing certain .htaccess configurations we allow others to easily protect themseleves from being rfi attacked while in the same time increasing our data feeds regarding RFI attacking attempts. By now we have put some more work on this and came up with a simple &lt;a href=&quot;http://link.informatik.uni-mannheim.de/rfi&quot; title=&quot;&quot;rfi project&quot; page&quot;&gt;&quot;rfi project&quot; page&lt;/a&gt; where we also present some statistics. If you would like to contribute you can do so &lt;a href=&quot;http://link.informatik.uni-mannheim.de/rfi/index.php?site=htaccessgen&quot; title=&quot;.htaccess generator&quot;&gt;here&lt;/a&gt;. If there are any questions don&#039;t hesitate to drop us a line... 
    </content:encoded>

    <pubDate>Mon, 06 Apr 2009 14:47:46 +0200</pubDate>
    <guid isPermaLink="false">http://blog.s6y.org/index.php?/archives/8-guid.html</guid>
    
</item>
<item>
    <title>Once up on a time I had a closer look on RFI...</title>
    <link>http://blog.s6y.org/index.php?/archives/7-Once-up-on-a-time-I-had-a-closer-look-on-RFI....html</link>
            <category>security</category>
    
    <comments>http://blog.s6y.org/index.php?/archives/7-Once-up-on-a-time-I-had-a-closer-look-on-RFI....html#comments</comments>
    <wfw:comment>http://blog.s6y.org/wfwcomment.php?cid=7</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.s6y.org/rss.php?version=2.0&amp;type=comments&amp;cid=7</wfw:commentRss>
    

    <author>nospam@example.com (christian)</author>
    <content:encoded>
    While enjoying my first coffee this morning I read about one &lt;a href=&quot;http://asert.arbornetworks.com/2009/01/quick-rfi-analysis/&quot; title=&quot;Quick RFI Analysis&quot;&gt;&quot;Quick RFI Analysis&quot;&lt;/a&gt; Jose Nazario published on &quot;The Arbor Networks Security Blog&quot;. This reminded me of some research I have been doing at the beginning of last year. Remote File Inclusion (RFI) is an attack usually exploiting vulnerabilities within PHP scripts, allowing to include PHP code from another (remote) server. Even though RFI is well known already for a couple of years it still seems to be an issue, particularly since, as Jose writes in his Quick RFI Analysis: &quot;AV is rarely ever invoked&quot;.  I am going to publish some of my results in this field as soon as I find some time... 
    </content:encoded>

    <pubDate>Thu, 29 Jan 2009 10:43:08 +0100</pubDate>
    <guid isPermaLink="false">http://blog.s6y.org/index.php?/archives/7-guid.html</guid>
    
</item>
<item>
    <title>TrumanBox - Internet Emulation</title>
    <link>http://blog.s6y.org/index.php?/archives/3-TrumanBox-Internet-Emulation.html</link>
            <category>security</category>
    
    <comments>http://blog.s6y.org/index.php?/archives/3-TrumanBox-Internet-Emulation.html#comments</comments>
    <wfw:comment>http://blog.s6y.org/wfwcomment.php?cid=3</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.s6y.org/rss.php?version=2.0&amp;type=comments&amp;cid=3</wfw:commentRss>
    

    <author>nospam@example.com (christian)</author>
    <content:encoded>
    Last week I uploaded the result of my thesis - TrumanBox. Even though it is more than one year ago, I still get requests for the source code every now and then. Hence I uploaded a small website providing the source code and the corresponding thesis. Both can be found &lt;a href=&quot;http://trumanbox.s6y.org&quot; title=&quot;TrumanBox&quot;&gt;here&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Tue, 02 Sep 2008 07:59:30 +0200</pubDate>
    <guid isPermaLink="false">http://blog.s6y.org/index.php?/archives/3-guid.html</guid>
    
</item>

</channel>
</rss>