<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments for MBs Windows Security</title>
	<atom:link href="http://xato.com/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://xato.com</link>
	<description>Mark Burnetts Windows Security</description>
	<pubDate>Tue, 09 Feb 2010 05:36:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on A bad month for CAPTCHAs by MustLive</title>
		<link>http://xato.com/windows-security/a-bad-month-for-captchas/comment-page-1#comment-277</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Thu, 06 Dec 2007 18:47:26 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/#comment-277</guid>
		<description>&lt;blockquote&gt;In reality, the only function that CAPTCHA on my blog serves is to reduce the number of spam comments&lt;/blockquote&gt;
Mark, your site is about security, so you need reliable captcha. Previous and current one are not reliable enough, so you need more secure captcha.

&lt;blockquote&gt;which I have very much enjoyed following&lt;/blockquote&gt;
I'm glad that you like it. I hope many people, especially security guys and web developers enjoyed my MoBiC project.

&lt;blockquote&gt;On a side note, I decided to change my own CAPTCHA.&lt;/blockquote&gt;
It's good, because previous captcha was very weak, but new one is unsecure too. As you alrady know from my artcile about Cryptographp captcha.

And after I checked today your new captcha (which is using Cryptographp plugin + additional checks) it is vulnerable. This captcha is vulnerable for session reusing with constant captcha
bypass method + bypassing additional protections. I have written you all details in email. So your captcha need to be improved.

&lt;blockquote&gt;The best way to improve on these is to prove me wrong.&lt;/blockquote&gt;
Like I told you, current captcha is unreliable ;-). Man, no need to look for OCR (or cheap work force) when there are holes in captcha. Like I told in Month of Bugs in Captchas using vulnerabilities to bypass captchas is more effective way. So until there are holes in some captcha, it can be reliable.

&lt;blockquote&gt;MustLive, you got any good OCR scripts?&lt;/blockquote&gt;
No, Mark, I have not such scripts. I'm only interesting in a posteriori vulnerabilities (holes in algorithms), not a priori vulnerabilities (holes in idea). So I'm as security auditor interesting only in holes in captchas (others two bypassing methods, OCR and cheap work force, is less interesting for me).</description>
		<content:encoded><![CDATA[<blockquote><p>In reality, the only function that CAPTCHA on my blog serves is to reduce the number of spam comments</p></blockquote>
<p>Mark, your site is about security, so you need reliable captcha. Previous and current one are not reliable enough, so you need more secure captcha.</p>
<blockquote><p>which I have very much enjoyed following</p></blockquote>
<p>I&#8217;m glad that you like it. I hope many people, especially security guys and web developers enjoyed my MoBiC project.</p>
<blockquote><p>On a side note, I decided to change my own CAPTCHA.</p></blockquote>
<p>It&#8217;s good, because previous captcha was very weak, but new one is unsecure too. As you alrady know from my artcile about Cryptographp captcha.</p>
<p>And after I checked today your new captcha (which is using Cryptographp plugin + additional checks) it is vulnerable. This captcha is vulnerable for session reusing with constant captcha<br />
bypass method + bypassing additional protections. I have written you all details in email. So your captcha need to be improved.</p>
<blockquote><p>The best way to improve on these is to prove me wrong.</p></blockquote>
<p>Like I told you, current captcha is unreliable ;-). Man, no need to look for OCR (or cheap work force) when there are holes in captcha. Like I told in Month of Bugs in Captchas using vulnerabilities to bypass captchas is more effective way. So until there are holes in some captcha, it can be reliable.</p>
<blockquote><p>MustLive, you got any good OCR scripts?</p></blockquote>
<p>No, Mark, I have not such scripts. I&#8217;m only interesting in a posteriori vulnerabilities (holes in algorithms), not a priori vulnerabilities (holes in idea). So I&#8217;m as security auditor interesting only in holes in captchas (others two bypassing methods, OCR and cheap work force, is less interesting for me).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A bad month for CAPTCHAs by Test</title>
		<link>http://xato.com/windows-security/a-bad-month-for-captchas/comment-page-1#comment-276</link>
		<dc:creator>Test</dc:creator>
		<pubDate>Thu, 06 Dec 2007 17:16:19 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/12/05/a-bad-month-for-captchas/#comment-276</guid>
		<description>Test :-)</description>
		<content:encoded><![CDATA[<p>Test :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by mb</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-259</link>
		<dc:creator>mb</dc:creator>
		<pubDate>Fri, 30 Nov 2007 16:37:35 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-259</guid>
		<description>a</description>
		<content:encoded><![CDATA[<p>a</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on China caught hacking, good thing our government does not do that by Test</title>
		<link>http://xato.com/windows-security/china-caught-hacking-good-thing-our-government-does-not-do-that/comment-page-1#comment-273</link>
		<dc:creator>Test</dc:creator>
		<pubDate>Fri, 30 Nov 2007 03:38:22 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/09/06/china-caught-hacking-good-thing-our-government-does-not-do-that/#comment-273</guid>
		<description>Captcha bypass test.</description>
		<content:encoded><![CDATA[<p>Captcha bypass test.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pakistan Wants to Learn How to Hack? by Saqib Saud</title>
		<link>http://xato.com/windows-security/pakistan-wants-to-learn-how-to-hack/comment-page-1#comment-275</link>
		<dc:creator>Saqib Saud</dc:creator>
		<pubDate>Sat, 17 Nov 2007 12:42:39 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/11/16/pakistan-wants-to-learn-how-to-hack/#comment-275</guid>
		<description>I am from Pakistan.I just stumbled at you blog.

This information is really interesting.</description>
		<content:encoded><![CDATA[<p>I am from Pakistan.I just stumbled at you blog.</p>
<p>This information is really interesting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Pakistan Wants to Learn How to Hack? by SEO Pakistan</title>
		<link>http://xato.com/windows-security/pakistan-wants-to-learn-how-to-hack/comment-page-1#comment-274</link>
		<dc:creator>SEO Pakistan</dc:creator>
		<pubDate>Sat, 17 Nov 2007 07:27:31 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/11/16/pakistan-wants-to-learn-how-to-hack/#comment-274</guid>
		<description>Interesting find! Being a Pakistani and an Internet addict, I never search for such a phrase but I'd tend to believe in ur finding...</description>
		<content:encoded><![CDATA[<p>Interesting find! Being a Pakistani and an Internet addict, I never search for such a phrase but I&#8217;d tend to believe in ur finding&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VMWare Guest Isolation Vulnerability by mb</title>
		<link>http://xato.com/windows-security/vmware-guest-isolation-vulnerability/comment-page-1#comment-271</link>
		<dc:creator>mb</dc:creator>
		<pubDate>Fri, 19 Oct 2007 17:41:55 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/22/vmware-guest-isolation-vulnerability/#comment-271</guid>
		<description>I don't use VMWare ACE, so I wouldn't be able to answer that.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t use VMWare ACE, so I wouldn&#8217;t be able to answer that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on VMWare Guest Isolation Vulnerability by grant</title>
		<link>http://xato.com/windows-security/vmware-guest-isolation-vulnerability/comment-page-1#comment-270</link>
		<dc:creator>grant</dc:creator>
		<pubDate>Fri, 19 Oct 2007 17:16:42 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/22/vmware-guest-isolation-vulnerability/#comment-270</guid>
		<description>How does this apply to the new VMWare ACE product? does it face the same problem?  Does it have countermeasures that would address this vulnerability (image encryption for example?)</description>
		<content:encoded><![CDATA[<p>How does this apply to the new VMWare ACE product? does it face the same problem?  Does it have countermeasures that would address this vulnerability (image encryption for example?)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by MustLive</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-258</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Wed, 17 Oct 2007 12:51:16 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-258</guid>
		<description>Mark!

Your captcha is vulnerable (as you can see from my Captcha bypass tests). Which is very ironical, because you wrote about captchas security in this article. So you need to find more secure captcha for yourself (without those weaknesses which you mentioned in this post). I'll write you an email about this hole.

This captcha (plugin) will be in my Month of Bugs in Captchas. The official announcement of my new project will be very soon.</description>
		<content:encoded><![CDATA[<p>Mark!</p>
<p>Your captcha is vulnerable (as you can see from my Captcha bypass tests). Which is very ironical, because you wrote about captchas security in this article. So you need to find more secure captcha for yourself (without those weaknesses which you mentioned in this post). I&#8217;ll write you an email about this hole.</p>
<p>This captcha (plugin) will be in my Month of Bugs in Captchas. The official announcement of my new project will be very soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by MustLive</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-257</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Wed, 17 Oct 2007 12:40:49 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-257</guid>
		<description>Captcha bypass test 3.</description>
		<content:encoded><![CDATA[<p>Captcha bypass test 3.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by MustLive</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-256</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Wed, 17 Oct 2007 12:40:09 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-256</guid>
		<description>Captcha bypass test 2.</description>
		<content:encoded><![CDATA[<p>Captcha bypass test 2.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by MustLive</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-255</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Wed, 17 Oct 2007 12:39:32 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-255</guid>
		<description>Captcha bypass test.</description>
		<content:encoded><![CDATA[<p>Captcha bypass test.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by MustLive</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-254</link>
		<dc:creator>MustLive</dc:creator>
		<pubDate>Fri, 12 Oct 2007 15:43:07 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-254</guid>
		<description>Nice article</description>
		<content:encoded><![CDATA[<p>Nice article</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on These CAPTCHAs are just not working out by Anne Kowalski &#187; Blog Archive &#187; Are CAPTCHAs Useless?</title>
		<link>http://xato.com/windows-security/these-captchas-are-just-not-working-out/comment-page-1#comment-253</link>
		<dc:creator>Anne Kowalski &#187; Blog Archive &#187; Are CAPTCHAs Useless?</dc:creator>
		<pubDate>Thu, 13 Sep 2007 05:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/08/21/these-captchas-are-just-not-working-out/#comment-253</guid>
		<description>[...] These CAPTCHAs are just not working out [...]</description>
		<content:encoded><![CDATA[<p>[...] These CAPTCHAs are just not working out [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on China caught hacking, good thing our government does not do that by rgl</title>
		<link>http://xato.com/windows-security/china-caught-hacking-good-thing-our-government-does-not-do-that/comment-page-1#comment-272</link>
		<dc:creator>rgl</dc:creator>
		<pubDate>Sat, 08 Sep 2007 00:50:42 +0000</pubDate>
		<guid isPermaLink="false">http://xato.net/bl/2007/09/06/china-caught-hacking-good-thing-our-government-does-not-do-that/#comment-272</guid>
		<description>This matter is not only concerning the US and British governments, but also the IT systems of Germany (and even probably those of other nations) have been illegally accessed by Chinese attackers, too.
An official newspaper article by "Spiegel", which is one of the German big news publishers reported this incident in detail on August 25th, 2007: http://www.spiegel.de/netzwelt/tech/0,1518,501954,00.html
Unfortunately this German speaking article has not been published in the international website of the newspaper (http://www.spiegel.de/international/).
But there are two smaller articles on the US website of the "Financial Times":
Beijing pledges crackdown on international hackers:
http://www.ft.com/cms/s/0/9b4cfc4e-54fe-11dc-890c-0000779fd2ac.html
China pledges to combat hacking: http://www.ft.com/cms/s/0/fd754098-54fe-11dc-890c-0000779fd2ac.html

Altogether not political interests alone, but as well economical motivation drives those attackers:
For years now there have been warnings of industrial espionage by national and international security advisors addressed especially to small and medium enterprises out there who still does not secure their perimeter infrastructure properly, either due to lack of knowledge or sometimes even simply because of reluctance to investments in seemingly "non-profit business areas".
In view of this development I do not feel very surprised by this current escalation, at all.</description>
		<content:encoded><![CDATA[<p>This matter is not only concerning the US and British governments, but also the IT systems of Germany (and even probably those of other nations) have been illegally accessed by Chinese attackers, too.<br />
An official newspaper article by &#8220;Spiegel&#8221;, which is one of the German big news publishers reported this incident in detail on August 25th, 2007: <a href="http://www.spiegel.de/netzwelt/tech/0,1518,501954,00.html" rel="nofollow">http://www.spiegel.de/netzwelt/tech/0,1518,501954,00.html</a><br />
Unfortunately this German speaking article has not been published in the international website of the newspaper (http://www.spiegel.de/international/).<br />
But there are two smaller articles on the US website of the &#8220;Financial Times&#8221;:<br />
Beijing pledges crackdown on international hackers:<br />
<a href="http://www.ft.com/cms/s/0/9b4cfc4e-54fe-11dc-890c-0000779fd2ac.html" rel="nofollow">http://www.ft.com/cms/s/0/9b4cfc4e-54fe-11dc-890c-0000779fd2ac.html</a><br />
China pledges to combat hacking: <a href="http://www.ft.com/cms/s/0/fd754098-54fe-11dc-890c-0000779fd2ac.html" rel="nofollow">http://www.ft.com/cms/s/0/fd754098-54fe-11dc-890c-0000779fd2ac.html</a></p>
<p>Altogether not political interests alone, but as well economical motivation drives those attackers:<br />
For years now there have been warnings of industrial espionage by national and international security advisors addressed especially to small and medium enterprises out there who still does not secure their perimeter infrastructure properly, either due to lack of knowledge or sometimes even simply because of reluctance to investments in seemingly &#8220;non-profit business areas&#8221;.<br />
In view of this development I do not feel very surprised by this current escalation, at all.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.450 seconds -->
