<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Dreams of Thought &#187; computer security</title>
	<atom:link href="http://gingerjoos.com/blog/category/computer-security/feed" rel="self" type="application/rss+xml" />
	<link>http://gingerjoos.com/blog</link>
	<description>Are dreams thoughts... or are thoughts dreams..</description>
	<lastBuildDate>Sun, 18 Jul 2010 13:05:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>The most difficult captcha there is</title>
		<link>http://gingerjoos.com/blog/computer-security/the-most-difficult-captcha-there-is</link>
		<comments>http://gingerjoos.com/blog/computer-security/the-most-difficult-captcha-there-is#comments</comments>
		<pubDate>Tue, 02 Jun 2009 09:52:46 +0000</pubDate>
		<dc:creator>Anirudh</dc:creator>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[from the web]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[captcha]]></category>
		<category><![CDATA[gul panag]]></category>

		<guid isPermaLink="false">http://gingerjoos.com/blog/?p=93</guid>
		<description><![CDATA[I was browsing through the site of a celebrity recently and came across the contact page. I was shocked to find the captcha there. Take a look yourself and be amazed : http://www.gulpanag.net/contact_gul_panag.php Why would anyone display the captcha as text ready for a bot passing by to read? (It&#8217;s even got a nice class [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<p>I was browsing through the <a href="http://www.gulpanag.net/">site of a celebrity</a> recently and came across the contact page. I was shocked to find the <a href="http://en.wikipedia.org/wiki/Captcha">captcha</a> there. Take a look yourself and be amazed : <a href="http://www.gulpanag.net/contact_gul_panag.php"><span class="captchas">http://www.gulpanag.net/contact_gul_panag.php</span></a></p>
<p>Why would anyone display the captcha as text ready for a bot passing by to read? (It&#8217;s even got a nice class &#8211; captchas &#8211; wrapping it) Is that some kind of a honeypot? Is that a dummy form? Does the site admin feel lonely because no one sends him/her mail and is hoping to at least read spam?</p>


<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://gingerjoos.com/blog/computer-security/the-most-difficult-captcha-there-is/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Hoax mail from &#8220;Microsoft&#8221;</title>
		<link>http://gingerjoos.com/blog/computer-security/hoax-mail-from-microsoft</link>
		<comments>http://gingerjoos.com/blog/computer-security/hoax-mail-from-microsoft#comments</comments>
		<pubDate>Sun, 12 Oct 2008 03:36:02 +0000</pubDate>
		<dc:creator>Anirudh</dc:creator>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[hoax]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://dreamsofthought.wordpress.com/?p=24</guid>
		<description><![CDATA["Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows." I got this hoax by email. Be careful!


Related posts:<ol><li><a href='http://gingerjoos.com/blog/technology/iso-approves-microsofts-ooxml' rel='bookmark' title='Permanent Link: ISO approves Microsoft&#8217;s OOXML'>ISO approves Microsoft&#8217;s OOXML</a></li>
<li><a href='http://gingerjoos.com/blog/technology/how-i-recovered-my-thunderbird-mail-from-backup' rel='bookmark' title='Permanent Link: How I recovered my Thunderbird mail from backup'>How I recovered my Thunderbird mail from backup</a></li>
<li><a href='http://gingerjoos.com/blog/computer-security/computer-warming-the-new-risk' rel='bookmark' title='Permanent Link: Computer Warming &#8211; the new risk?!'>Computer Warming &#8211; the new risk?!</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<blockquote><p>Dear Microsoft Customer,</p>
<p>Please notice that Microsoft company has recently issued a Security Update for OS Microsoft Windows. The update applies to the following OS versions: Microsoft Windows 98, Microsoft Windows 2000, Microsoft Windows Millenium, Microsoft Windows XP, Microsoft Windows Vista.</p>
<p>Please notice, that present update applies to high-priority updates category. In order to help protect your computer against security threats and performance problems, we strongly recommend you to install this update.</p>
<p>Since public distribution of this Update through the official website <a href="http://www.microsoft.com/" target="_blank">http://www.microsoft.com</a> would have result in efficient creation of a malicious software, we made a decision to issue an experimental private version of an update for all Microsoft Windows OS users.</p>
<p>As your computer is set to receive notifications when new updates are available, you have received this notice.</p>
<p>In order to start the update, please follow the step-by-step instruction:<br />
1. Run the file, that you have received along with this message.<br />
2. Carefully follow all the instructions you see on the screen.</p>
<p>If nothing changes after you have run the file, probably in the settings of your OS you have an indication to run all the updates at a background routine. In that case, at this point the upgrade of your OS will be finished.</p>
<p>We apologize for any inconvenience this back order may be causing you.</p>
<p>Thank you,</p>
<p>Steve Lipner<br />
Director of Security Assurance<br />
Microsoft Corp.</p>
<p>&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br />
Version: PGP 7.1</p>
<p>O61N09JLE94LTDLYEQGYL779BT77V3HNOBDRRHH429ANQMKHZJ2KJTN4SOIHO7Q69<br />
P1T0FUAXM2NETPWIK57I76JW26P06ZMJVM3AALK2EHLW5FLLSD88MJ4CIQ44YUW7G<br />
D6M4BT8E0NMNPMKGKBL44AWDDFFOV6FN3WZUJWQ5IYT3FDUPEE5VEQ9PBJYOSDOSF<br />
2F0TAC0XCOBFL97K2ERH8UMJT6NWTACWT48EE7ODS6RDZP7ENZCRGMAOHYZGE1J70<br />
I8HH2YHXADGTIHCFWLIVBAZCB3B5UQDWN0X==<br />
&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;</p></blockquote>
<p>This is a better crafted hoax than others out there <img src='http://gingerjoos.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Still quite a few flaws <img src='http://gingerjoos.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  So don&#8217;t go and &#8220;install&#8221; the &#8220;update&#8221;.</p>
<ol>
<li>Microsoft &#8220;company&#8221;</li>
<li>OS Microsoft Windows</li>
</ol>
<p>A typical update from Microsoft would be something like this : http://www.microsoft.com/downloads/details.aspx?FamilyID=e0bd6fbe-f46e-4961-9a79-49ec77d39439&amp;DisplayLang=en</p>


<p>Related posts:<ol><li><a href='http://gingerjoos.com/blog/technology/iso-approves-microsofts-ooxml' rel='bookmark' title='Permanent Link: ISO approves Microsoft&#8217;s OOXML'>ISO approves Microsoft&#8217;s OOXML</a></li>
<li><a href='http://gingerjoos.com/blog/technology/how-i-recovered-my-thunderbird-mail-from-backup' rel='bookmark' title='Permanent Link: How I recovered my Thunderbird mail from backup'>How I recovered my Thunderbird mail from backup</a></li>
<li><a href='http://gingerjoos.com/blog/computer-security/computer-warming-the-new-risk' rel='bookmark' title='Permanent Link: Computer Warming &#8211; the new risk?!'>Computer Warming &#8211; the new risk?!</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gingerjoos.com/blog/computer-security/hoax-mail-from-microsoft/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Computer Warming &#8211; the new risk?!</title>
		<link>http://gingerjoos.com/blog/computer-security/computer-warming-the-new-risk</link>
		<comments>http://gingerjoos.com/blog/computer-security/computer-warming-the-new-risk#comments</comments>
		<pubDate>Sat, 30 Dec 2006 13:02:39 +0000</pubDate>
		<dc:creator>Anirudh</dc:creator>
				<category><![CDATA[computer security]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://dreamsofthought.wordpress.com/2006/12/30/computer-warming-the-new-risk/</guid>
		<description><![CDATA[Happened to come across a pointer in Slashdot to a Wired article.  From the article - BERLIN &#8212; A security researcher has a devised a novel attack on online anonymity systems in which he literally takes a computer&#8217;s temperature over the Internet. The attack uses a phenomenon called &#8220;clock skew&#8221; &#8212; the tendency for the [...]


Related posts:<ol><li><a href='http://gingerjoos.com/blog/films/sita-sings-the-blues' rel='bookmark' title='Permanent Link: Sita Sings the Blues'>Sita Sings the Blues</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Happened to come across <a href="http://yro.slashdot.org/article.pl?sid=06/12/30/0645249&amp;from=rss" target="_blank">a pointer in Slashdot</a> to a <a href="http://www.wired.com/news/technology/0,72375-0.html?tw=rss.technology" target="_blank">Wired article</a>.  From the article -</p>
<blockquote><p>BERLIN &#8212; A security researcher has a devised a novel attack on online anonymity systems in which he literally takes a computer&#8217;s temperature over the Internet.</p>
<p>The attack uses a phenomenon called &#8220;clock skew&#8221; &#8212; the tendency for the precise clocks in modern computers to drift off of the correct time at slightly different rates, which can be affected by heat.</p></blockquote>
<p>As I understand it, the basic premise goes like this. It seems possible to identify a computer based on <a href="http://en.wikipedia.org/wiki/Clock_skew" target="_blank">clock skew</a>. Clock skew is unavoidable although most digital systems try their best to reduce it. You change the temperature, you change the clock skew. So overload a particular server suddenly and there is a change in its clock. This means the time stored on that server also changes. Now use timestamps to find the server which has drifted off. This is not the entire story, read more at <a href="http://www.wired.com/news/technology/0,72375-0.html?tw=rss.technology" target="_blank">Wired</a>.</p>
<p>This is a rather roundabout way of doing things. Not really the best way to do it, but what it does show is that such things are possible. Perhaps this concept might be useful in some other context. Personally, I don&#8217;t expect such attacks to come in anytime in the future. There are far simpler and effective ways and it doesn&#8217;t make sense to use such a complicated method.</p>


<p>Related posts:<ol><li><a href='http://gingerjoos.com/blog/films/sita-sings-the-blues' rel='bookmark' title='Permanent Link: Sita Sings the Blues'>Sita Sings the Blues</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://gingerjoos.com/blog/computer-security/computer-warming-the-new-risk/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.516 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2010-07-30 23:34:56 -->
