<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>pi3 blog</title>
	<link>http://blog.pi3.com.pl</link>
	<description>bughunt exploiting</description>
	<lastBuildDate>Tue, 27 Jul 2010 12:25:03 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0.1" -->

	<item>
		<title>Hospital&#8230;</title>
		<description><![CDATA[Today (27.07.2010) I&#8217;m going to the hospital (Hospital de la Tour) for surgery&#8230; I don&#8217;t know how long I&#8217;m going to stay in the hospital after the surgery and when I will be available&#8230; Wish me good luck! Best regards, Adam Zabrocki]]></description>
		<link>http://blog.pi3.com.pl/?p=118</link>
			</item>
	<item>
		<title>OPIE Authentication System off-by-one</title>
		<description><![CDATA[In co-operation with Maksymilian Arciemowicz we were analysing implementation of  OPIE Authentication System on FreeBSD. The result is discovered off-by-one vulnerability in library &#8216;libopie&#8217;. The most interesting point of this vulnerability is a possibility to exploit it pre-auth remotely! A lot of softwares using this library for authentication module. For example FreeBSD team change a [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=111</link>
			</item>
	<item>
		<title>White Area lecture at CERN</title>
		<description><![CDATA[Yesterday (30 of April) I gave a lecture in WA (White Area) at CERN. I was talking about my new project (in fact Master of Degree thesis topic). This is automated testing tool which uses fuzzing technique. It can be used for generate CLI, API, Unit, Functionally, Regression, &#8230; , tests &#8211; in fact we [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=108</link>
			</item>
	<item>
		<title>Remote stack overflows</title>
		<description><![CDATA[One day I was reviewing all bugs in bugtraq IDs (popular bids). I want to know which kind of bugs is it now popular and what is the trend of modern bugs. I came to two main conclusions: 1) The most popular are SQL/XSS bugs but in 60% this is found in software which nobody [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=82</link>
			</item>
	<item>
		<title>Lecture at CERN</title>
		<description><![CDATA[28th of February I had a IT group meeting.  On this meeting I had been giving lecture about modern rootkits, virus and malwares for 1 hour. The presentation give a point for malware called bankers, attacks for device (skimming), new attack for CHIP cards, and how rootkits hide in *NIX systems. I have had really [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=79</link>
			</item>
	<item>
		<title>Intel lecture&#8230;</title>
		<description><![CDATA[CERN openlab / Intel Computer Architecture and Performance Tuning Workshop Winter 2010&#8230; From 9:00 (9th of February) until 17:00 (10th of February) openlab are filled by people who wants to learn smth from Intel&#8217;s guys&#8230; At the beginning I want to say that one of the speaker will be Polish guy &#8211; Andrzej Nowak. Here [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=71</link>
			</item>
	<item>
		<title>CVE-2010-0010: Apache mod_proxy vulnerability</title>
		<description><![CDATA[CVE-2010-0010: Apache mod_proxy vulnerability After contact with Apache security team i can publish new advisory. This bug exists only in apache 1.3 version in mod_proxy modules, only in 64 bits architecture. I would like to thanks Colm MacCárthaigh &#8211; the guy responsible for contact with me and patch this hole. Bugfix ﻿is available in a [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=69</link>
			</item>
	<item>
		<title>Apache vulnerability</title>
		<description><![CDATA[This will be very short post&#8230; I have found (few months ago) security vulnerability in one of Apache server/module. I contact with apache security team. After few days I will decide about &#8220;future&#8221; of this bug &#8211; publish or wait for security path and publish after it. Now I can paste here simple output from [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=67</link>
			</item>
	<item>
		<title>Mtr advisory&#8230;</title>
		<description><![CDATA[More than year ago I was publish advisory in &#8216;mtr&#8217; software. I think, personally, it is great bug because it can&#8217;t exist without unspecified situation in  libresolv library The question is why have I written information about it on blog? I forgot add this advisory in my site (sic!) Now it&#8217;s ok and you can [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=63</link>
			</item>
	<item>
		<title>Exploitable CPU bugs&#8230;</title>
		<description><![CDATA[Is it a dream? Impossible? Bugs in CPU? No&#8230; it&#8217;s reality! CPU is only a piece of hardware. Everything have bugs&#8230; CPU too. I will give here only a piece of information about bugs in INTEL products&#8230; From time to time Intel release erratas for his products! But not many people know about it and [...]]]></description>
		<link>http://blog.pi3.com.pl/?p=55</link>
			</item>
</channel>
</rss>
