<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>http://united-geeks.org/blog - InSecurity</title>
    <link>http://united-geeks.org/blog/</link>
    <description>Für die tägliche Portion Info-Gulasch...</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.0 - http://www.s9y.org/</generator>
    <pubDate>Sat, 24 Oct 2009 16:59:47 GMT</pubDate>

    <image>
        <url>http://united-geeks.org/blog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: http://united-geeks.org/blog - InSecurity - Für die tägliche Portion Info-Gulasch...</title>
        <link>http://united-geeks.org/blog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Rescuing your DSL password from a Beetel 220BX ADSL2+ Modem</title>
    <link>http://united-geeks.org/blog/index.php?/archives/99-Rescuing-your-DSL-password-from-a-Beetel-220BX-ADSL2+-Modem.html</link>
            <category>InSecurity</category>
    
    <comments>http://united-geeks.org/blog/index.php?/archives/99-Rescuing-your-DSL-password-from-a-Beetel-220BX-ADSL2+-Modem.html#comments</comments>
    <wfw:comment>http://united-geeks.org/blog/wfwcomment.php?cid=99</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://united-geeks.org/blog/rss.php?version=2.0&amp;type=comments&amp;cid=99</wfw:commentRss>
    

    <author>nospam@example.com (n00dl3s)</author>
    <content:encoded>
    In case it helps anybody...&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t know the DSL password which connects your Beetel 220BX to the ISP network (Airtel in India does never provide it to the customers, they&#039;d rather send a guy to enter it by hand...),  but the router still functions, you can get the passwords even though you only see ******** in the web-interface. It&#039;s really easy:&lt;br /&gt;
&lt;br /&gt;
1. Connect to the router IP with telnet (user: admin, password is the same as for the web-interface)&lt;br /&gt;
2. Go to Management (press 9)&lt;br /&gt;
3. Go to Settings (press 1)&lt;br /&gt;
3. Dump settings (press 3)&lt;br /&gt;
4. Look for the line that starts with: ppp_conId1 userName=&quot;***********_dsl@airtelbroadband.in&quot; password=&quot;cGFzc3dvcmQ=&quot; ....&lt;br /&gt;
5. Copy and paste the value of password into a base64 decoder (locally or i.e. you can use an online decoder, such as here: &lt;a href=&quot;http://www.opinionatedgeek.com/dotnet/tools/Base64Decode/&quot; &gt;http://www.opinionatedgeek.com/dotnet/tools/Base64Decode/&lt;/a&gt;)&lt;br /&gt;
6. Congrats, you now have your DSL password which Airtel wouldn&#039;t tell you &lt;img src=&quot;http://united-geeks.org/blog/templates/default/img/emoticons/wink.png&quot; alt=&quot;;-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;&lt;br /&gt;
  
    </content:encoded>

    <pubDate>Sat, 24 Oct 2009 18:59:47 +0200</pubDate>
    <guid isPermaLink="false">http://united-geeks.org/blog/index.php?/archives/99-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/</creativeCommons:license>
</item>
<item>
    <title>Robocop auf russisch</title>
    <link>http://united-geeks.org/blog/index.php?/archives/63-Robocop-auf-russisch.html</link>
            <category>InSecurity</category>
    
    <comments>http://united-geeks.org/blog/index.php?/archives/63-Robocop-auf-russisch.html#comments</comments>
    <wfw:comment>http://united-geeks.org/blog/wfwcomment.php?cid=63</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://united-geeks.org/blog/rss.php?version=2.0&amp;type=comments&amp;cid=63</wfw:commentRss>
    

    <author>nospam@example.com (n00dl3s)</author>
    <content:encoded>
    Einfach nur lustig, dieses &lt;a href=&quot;http://www.spiegel.de/video/video-28317.html&quot; &gt;Spiegel-TV Video&lt;/a&gt;.   
    </content:encoded>

    <pubDate>Sun, 23 Mar 2008 17:18:14 +0100</pubDate>
    <guid isPermaLink="false">http://united-geeks.org/blog/index.php?/archives/63-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/</creativeCommons:license>
</item>
<item>
    <title>Is Skype trying to spy on us?</title>
    <link>http://united-geeks.org/blog/index.php?/archives/45-Is-Skype-trying-to-spy-on-us.html</link>
            <category>InSecurity</category>
    
    <comments>http://united-geeks.org/blog/index.php?/archives/45-Is-Skype-trying-to-spy-on-us.html#comments</comments>
    <wfw:comment>http://united-geeks.org/blog/wfwcomment.php?cid=45</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://united-geeks.org/blog/rss.php?version=2.0&amp;type=comments&amp;cid=45</wfw:commentRss>
    

    <author>nospam@example.com (n00dl3s)</author>
    <content:encoded>
    As one can &lt;a href=&quot;http://forum.skype.com/index.php?showtopic=95261&quot;  title=&quot;Skype-Forum Post&quot;&gt;read on the official Skype-Forums&lt;/a&gt;, a Skype user (ZaphodB) just found out that Skype is trying to access certain files on your harddisk, like i.e. /etc/passwd and all the files in your Mozilla/Firefox profile-folder. He discovered all this by deploying AppArmor on his system to monitor Skypes behaviour (since it is closed source, he wanted to protect his system from a eventual Zero-Day-Exploit for Skype).&lt;br /&gt;
&lt;br /&gt;
Although in the forums post some people came up with reasonable explanations why Skype would read those files, I am not fully convinced it is &quot;just by design&quot; (i.e. using functions like &#039;getpwuid()&#039; which would read /etc/passwd, or trying to determine your proxy-settings by looking through your Firefox/Mozilla profile).&lt;br /&gt;
&lt;br /&gt;
I am not sure if this is anything to worry about or not, but I surely don&#039;t like it at all. Seems like AppArmor or the like are really needed when it comes to closed source software. &lt;br /&gt;
&lt;br /&gt;
Let&#039;s see if some Skype-Developers comment on the issue. Stay tuned for an update here, or just read the Skype forums yourself.  
    </content:encoded>

    <pubDate>Mon, 27 Aug 2007 07:13:34 +0200</pubDate>
    <guid isPermaLink="false">http://united-geeks.org/blog/index.php?/archives/45-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/</creativeCommons:license>
</item>
<item>
    <title>Aircrack-ptw - WEP is deader than dead!</title>
    <link>http://united-geeks.org/blog/index.php?/archives/24-Aircrack-ptw-WEP-is-deader-than-dead!.html</link>
            <category>InSecurity</category>
    
    <comments>http://united-geeks.org/blog/index.php?/archives/24-Aircrack-ptw-WEP-is-deader-than-dead!.html#comments</comments>
    <wfw:comment>http://united-geeks.org/blog/wfwcomment.php?cid=24</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://united-geeks.org/blog/rss.php?version=2.0&amp;type=comments&amp;cid=24</wfw:commentRss>
    

    <author>nospam@example.com (n00dl3s)</author>
    <content:encoded>
    A week ago I ran into a new tool for WEP-cracking that promised to achieve results in a fraction of the time compared to i.e. &quot;aircrack-ng&quot;. This - of  course - drew my attention... Unfortunately due to time constraints I wasn&#039;t able to attend the author&#039;s talk at the Easterhegg 2007, but their website provides the program itself and also all the necessary info (and - fortunately - there is also an gentoo ebuild in portage already). So, after emerging aircrack-ptw (which currently is in ~x86), I gave it a shot, and I was deeply impressed:  using arp-injection to generate more trafficI was able to sniff about 45.000 packets in 4mins, and as soon as I had those, aircrack-ptw was able to compute the WEP key in a matter of seconds!!!&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;This is awesome...&lt;/strong&gt;&lt;br /&gt;
&lt;br /&gt;
Props go out to: Erik Tews, Andrei Pychkine and Ralf-Philipp Weinmann. See &lt;a href=&quot;http://www.cdc.informatik.tu-darmstadt.de/aircrack-ptw/&quot; &gt;their website&lt;/a&gt; for more info.&lt;br /&gt;
If you understand german, you might also want to check out the latest &lt;a href=&quot;http://chaosradio.ccc.de/cre044.html&quot; &gt;Chaosradio Express episode&lt;/a&gt; where Tim and Erik talk about aircrack-ptw.  
    </content:encoded>

    <pubDate>Wed, 18 Apr 2007 20:32:38 +0200</pubDate>
    <guid isPermaLink="false">http://united-geeks.org/blog/index.php?/archives/24-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/</creativeCommons:license>
</item>
<item>
    <title>BlueSniper</title>
    <link>http://united-geeks.org/blog/index.php?/archives/13-BlueSniper.html</link>
            <category>InSecurity</category>
    
    <comments>http://united-geeks.org/blog/index.php?/archives/13-BlueSniper.html#comments</comments>
    <wfw:comment>http://united-geeks.org/blog/wfwcomment.php?cid=13</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://united-geeks.org/blog/rss.php?version=2.0&amp;type=comments&amp;cid=13</wfw:commentRss>
    

    <author>nospam@example.com (n00dl3s)</author>
    <content:encoded>
    Hehe, da haben sich ein paar Jungs mal wieder richtig Mühe gegeben und was lustiges gebastelt...&lt;br /&gt;
&lt;br /&gt;
Für Pazifisten wie mich mutet es allerdings seltsam an, dass &quot;Rifle&quot; (dt.: Gewehr) im Titel nicht von ungefährt kommt: haben sie doch tatsächlich den Schaft eines Luger(TM)-Gewehres gekauft und darin einen Mini-Computer (mit Embedded Linux) und als &quot;Lauf&quot; eine Yagi Antenne verbaut.&lt;br /&gt;
&lt;br /&gt;
Dennoch, schießen tut das Ding ja nicht, ob es gefährlich ist oder nicht kommt wohl darauf an was man damit vorhat. Mit einer Reichweite von angeblich 1km kann man damit schon ordentlich Unfug treiben.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.tomsnetworking.com/2005/03/08/how_to_bluesniper_pt1/&quot; &gt;Die ganze Story über das BT-Sniper-Rifle&lt;/a&gt; (externer Link)  
    </content:encoded>

    <pubDate>Mon, 14 Mar 2005 21:49:00 +0100</pubDate>
    <guid isPermaLink="false">http://united-geeks.org/blog/index.php?/archives/13-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/</creativeCommons:license>
</item>

</channel>
</rss>