<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>LogicX</title>
	<atom:link href="http://logicx.net/feed" rel="self" type="application/rss+xml" />
	<link>http://LogicX.net</link>
	<description>Information Security in Corporate IT</description>
	<pubDate>Thu, 24 Apr 2008 20:15:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
	<language>en</language>
			<item>
		<title>New Colo Box</title>
		<link>http://LogicX.net/security/new-colo-box</link>
		<comments>http://LogicX.net/security/new-colo-box#comments</comments>
		<pubDate>Wed, 25 Apr 2007 13:51:22 +0000</pubDate>
		<dc:creator>LogicX</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://LogicX.net/security/new-colo-box</guid>
		<description><![CDATA[I&#8217;ve had a colo box with ColoPronto for over a year now.  Its been a great, inexpensive box to play on.  Since I&#8217;ve been in Boston I&#8217;ve been trying to locate a reasonbly priced local colo option, so I can be more &#8216;hands on&#8217; with the server and upgrades.  Unfortunately for the [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had a colo box with <a href="http://colopronto.com">ColoPronto</a> for over a year now.  Its been a great, inexpensive box to play on.  Since I&#8217;ve been in Boston I&#8217;ve been trying to locate a reasonbly priced local colo option, so I can be more &#8216;hands on&#8217; with the server and upgrades.  Unfortunately for the last year my search results have been pathetic.  The best I&#8217;ve been able to find is around $100/mo for 1U with 1/4Mbit/sec (80GB/mo).  That is just totally unacceptable, considering I get 500GB/mo with ColoPronto for $20/mo.</p>
<p>I recently received a reply to a post on WebHostingTalk where I asked for Boston Colo Options.  Through this I learned of <a href="http://prospeed.net">Prospeed.net</a>.  They offer 1U in their Cambridge, MA facility, with Level3 Communications, with generous bandwidth allowances.  I&#8217;ve contacted Prospeed, and began the process of getting some space there.  I ordered a Core2Duo 1U from AntOnline which arrived today; and I hope to get it live in the next few days.</p>
<p>What will I do with this box you ask?  Well &#8212; for starters, it will run gentoo, and run vmware-server.  I will then be able to run a number of VMs inside it.  One of them will likely be a <a href="http://mindtouch.com/node/300?subsection=Download">DekiWiki 5-User VM</a>.  I will also continue to expand my knowledge by being able to run servers and experiment with new OS choices, etc.</p>
<p>A broader goal &#8212; which I&#8217;ll write about in more detail later &#8212; is to offer VMs on the box to interested High School and College students who do not have the resources available to them &#8212; but would like to experiment with running a server, hosting sites, and the learning that comes with offering such services.</p>
<p>Update 4/24/08: I&#8217;ve been very pleased with ProSpeed.net for the time I&#8217;ve been with them now.  I&#8217;ve had very little downtime, service has been good and they even didn&#8217;t have an issue when my CC expired, and they weren&#8217;t paid for 5 months - they called me up and we cleared it all up.   I had a friend who was looking into colo services contact them however, and I don&#8217;t believe they&#8217;re offering this deal at this pricepoint anymore.</p>
]]></content:encoded>
			<wfw:commentRss>http://LogicX.net/security/new-colo-box/feed</wfw:commentRss>
		</item>
		<item>
		<title>DekiWiki and MindTouch Deki Review</title>
		<link>http://LogicX.net/wiki/dekiwiki-and-mindtouch-deki-review</link>
		<comments>http://LogicX.net/wiki/dekiwiki-and-mindtouch-deki-review#comments</comments>
		<pubDate>Fri, 06 Apr 2007 13:00:48 +0000</pubDate>
		<dc:creator>LogicX</dc:creator>
		
		<category><![CDATA[Wiki]]></category>

		<guid isPermaLink="false">http://LogicX.net/security/dekiwiki-and-mindtouch-deki-review</guid>
		<description><![CDATA[I work for an Information Security Consulting firm near Boston, MA  &#8212; I&#8217;ve grown up using FreeBSD, Linux, and open source software, and  personally run Linux and FreeBSD on my desktops, servers, and laptop. It  should even be noted that I have a co-located FreeBSD server in Miami  Florida that I [...]]]></description>
			<content:encoded><![CDATA[<p>I work for an <a href="http://www.smpone.com">Information Security Consulting firm</a> near Boston, MA  &#8212; I&#8217;ve grown up using FreeBSD, Linux, and open source software, and  personally run Linux and FreeBSD on my desktops, servers, and laptop. It  should even be noted that I have a <a href="http://colopronto.com/" target="_blank">co-located</a> FreeBSD server in Miami  Florida that I host some of my websites on, I run and maintain the  server, I also have a <a href="http://www.dreamhost.com/r.cgi" target="_blank">Dreamhost</a> webhosting account, and I have  access to a number of other dedicated servers which I help maintain.</p>
<p>I&#8217;ve been frustrated for some time by the fact that I need easy ways to  manage and update information, and I really like the idea of wikis,  however I feel that I&#8217;m traveling back in time by doing the &#8216;let me try  this syntax, now let me click a button to render the page and see if its  what I wanted&#8217; type of system that Wiki syntax is currently at. It feels  to me very much like the early days of HTML &#8212; and along with it the  myriad of poor -WYSIWYMG (What you might get) type solutions &#8212; I&#8217;ve  previously tried, and am not a fan of generic WYSIWYG overlays for  MediaWiki &#8212; such as fckeditor. (Specifically the fact that it does  horrid javascript popups for things such as URL inputs).</p>
<p>At my current company I realized that we really need a system for managing  our information &#8212; and so I&#8217;ve recently been evaluating Microsoft  Sharepoint. To that end, Sharepoint has wiki functionality &#8212; once  again, with a horrid WYSIWYG overlay, and I wanted to see what else is  out there. I used <a href="http://www.wikimatrix.org" target="_blank">WikiMatrix.org</a> to narrow down my choices, and <a href="http://www.wikimatrix.org/show/DekiWiki">DekiWiki</a>  was one of the first ones I checked out. I was very thrown off by the <a href="http://www.opengarden.org/dekiwiki" target="_blank">OpenGarden website</a> &#8212; particularly the <a href="http://www.opengarden.org" target="_blank">front page</a> &#8212; I had no idea what  to make of it, could barely read the text under the DekiWiki and Dream  options, etc. &#8212; I somehow came across a link to the <a href="http://mindtouch.com/" target="_blank">Mindtouch</a> site, and  sighed in relief as the pleasant, easy to read site. I viewed the <a href="http://mindtouch.com/demo/index.html" title="Mindtouch Deki Flash Demo" target="_blank">flash  demo</a> and was instantly impressed by the attaching of files &#8212; this was  an excellent marketing tool.</p>
<p>Seeing as I use <a href="http://www.vmware.com/products/server/" target="_blank">VMWare</a> on a daily basis, I downloaded the <a href="http://mindtouch.com/node/300?subsection=Download" target="_blank">VMWare image</a>,  and gave it a whirl. After a few initial problems getting it to properly  start (I ended up having to delete it, re-extract and try again) &#8212; I  got it up and working. Seeing as I work in the security field, I was  surprised by the fact that the interface emailed me my password when I  added an account, and so I immediately began tracing back the email to  understand how it had sent it out, and what sorts of communications the  VM was making out from our corporate environment. As I intended to use  the Wiki to store sensitive corporate data, I would have to prove the  security of the system to a supervisor. I ended up inspecting the host  that the mail came from, and discovered an IRC server, connected, and  ended up talking to a number of the developers about the security of the  email system, and they informed me that they&#8217;re looking into the option  of specifying your email servers in the configuration, so that mail  stays local to your LAN. I can understand the need to make it work &#8216;out  of the box&#8217; and so relaying mail out to ensure delivery is a good  method; however I think there should be the option to reassure  administrators that passwords are not flying around the Internet  unencrypted.</p>
<p>Talking to the developers I finally gained a better understanding of OpenGarden, and its role with DekiWiki, and Mindtouch&#8217;s  commercialization of the product.<br />
I shared this information with a co-worker and we decided to see how  much was involved in getting DekiWiki installed on a Gentoo server at  our office. While we did struggle somewhat, and still don&#8217;t have all  features working, we were able to get it up and begin using it; and  decided to stick with it for now over the VM, and see how it goes over  in the office.</p>
<p>I then decided I wanted a Wiki for this site, and once again  tried to turn to DekiWiki. I was unable to install the open source  version on my FreeBSD server, as its running a 64Bit version of FreeBSD,  and there is no mono support for AMD64 FreeBSD.</p>
<p>I figured that <a href="http://www.dreamhost.com/r.cgi" target="_blank">Dreamhost</a> would not have all the required components  installed to get it working there (I&#8217;ve since submitted a suggestion that they offer DekiWiki as a <a href="http://wiki.dreamhost.com/One_Click_Installs" target="_blank">one-click install</a>). I did some more searching and came  across viawiki.com &#8212; The account creation functionality does not work,  I emailed them and although received a nice reply, they had no ETA on  when it would be working again. That was many weeks ago, and it still  does not work.</p>
<p>I then came across <a href="http://Wik.is">Wik.is</a>. I signed up for an account &#8212; there is very  little technical information on wik.is as to what exactly it is.  Exploring my account I saw many of the standard features, however I  wanted to store some personal information in the wiki that I could lock  down to only my account. I then read the why Upgrade page, saw the  &#8216;Privacy: Make your wiki accessible only to selected users.&#8221; and decided  that as this was what I wanted, and I was already now familiar with  DekiWiki, and impressed by <a href="http://www.mindtouch.com/support" target="_blank">MindTouch backing</a> all of this, I would  signup. I also wanted to know more about the integration, as once again  &#8212; I run my own server, host my websites, etc. &#8212; and wanted to see what  exactly was in store for integration options.</p>
<p>Even after signing up &#8212; there&#8217;s almost no further information about  what had just occurred. There was very little hand-holding, explanations,  and no links to additional documentation to help me figure out how to  take advantage of the &#8216;pro&#8217; features I&#8217;d just purchased.  The Customizable URL seems to be done well &#8212; I just  took a stab, and set my DNS to the IP address I was being hosted at with  a domain name &#8212; It still would&#8217;ve been nice to have some documentation  that assured me &#8216;this is the IP address to resolve your hostname to &#8212;  set it to the same value in this field in the configuration&#8217;. I consider  myself a very technically advanced user; and so I shudder at the thought  of others figuring these things out.</p>
<p>In the end it turns out that Wik.is provides only full public or private content functionality &#8212; no granular distinctions.  As their target audience is not-so-technical consumers.  They were nice enough to refund my money, based on my mis-understanding of their offering.</p>
<p>I really do think the <a href="http://www.vmware.com/vmtn/appliances/directory/705" target="_blank">MindTouch VM</a> is an excellent idea, and the whole  model of the VM and physical <a href="http://www.mindtouch.com/dekibox" target="_blank">DekiBox</a>, with the automatic upgrades, etc. &#8212;  is a very good way to implement the product.<br />
The unique way in which all the open source dependencies have  been tied together to create a fluid product makes for a great final  product, which however is difficult to setup; and MindTouch is doing a  great job of releasing it in an easy to manage product.</p>
<p>I also look forward to DekiWiki integration of OpenID, as detailed through their <a href="http://opengarden.org/community/blog/open_web_iniative" target="_blank">Open Web Initiative</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://LogicX.net/wiki/dekiwiki-and-mindtouch-deki-review/feed</wfw:commentRss>
		</item>
		<item>
		<title>Jikto Source Code Situation</title>
		<link>http://LogicX.net/security/jikto-source-code-situation</link>
		<comments>http://LogicX.net/security/jikto-source-code-situation#comments</comments>
		<pubDate>Mon, 02 Apr 2007 19:43:54 +0000</pubDate>
		<dc:creator>LogicX</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://LogicX.net/security/jikto-source-code-situation</guid>
		<description><![CDATA[I read Billy&#8217;s Post concerning the release of Jikto code, and want to share my thoughts.
Just to make sure facts stay straight &#8211;
I was at Shmoocon, and watched Billy Hoffman&#8217;s presentation about Jikto.  At one point during the presentation he was trying to show how the code worked, and switched to a window displaying [...]]]></description>
			<content:encoded><![CDATA[<p>I read <a href="http://portal.spidynamics.com/blogs/spilabs/archive/2007/04/02/Jikto-in-the-wild.aspx" target="_blank">Billy&#8217;s Post</a> concerning the release of Jikto code, and want to share my thoughts.</p>
<p>Just to make sure facts stay straight &#8211;</p>
<p>I was at Shmoocon, and watched Billy Hoffman&#8217;s presentation about Jikto.  At one point during the presentation he was trying to show how the code worked, and switched to a window displaying the URL it was including.  As this part of the demonstration showed how it can be incorporated into sites such as Google Translate, jikto needed to be accessible to Google Translate.  I was sitting near the front, caught the URL, and downloaded it.</p>
<p>I had put the code up on a site of mine for only a short while before Billy called me and kindly asked me to take it down, and explained the media frenzy surrounding the code, its purpose, and SPI Dynamic&#8217;s release of it. I meant no harm to Billy or SPI, and immediately took it down. My interest in the code was purely from the perspective of  how it worked.  I&#8217;m an Information Security Consultant with <a href="http://www.smpone.com" target="_blank">Security Management Partners</a> in Boston, MA and imagined being able to use his proof of concept for Phishing exercises we create for clients.</p>
<p>We create fake websites, and email employees to test their compliance with policies regarding clicking links or attachments in emails.  Obviously being able to include code which could perform reconnaissance of their Internal network before we even step on site would be an excellent demonstration to clients as to the severity of employees accessing unknown sites.  Even more extreme is the fact that this can be included via XSS attacks, making it come from a real site such as cnn.com.</p>
<p>My understanding of Jikto is that it will not take down the Internet, or other alarmists reactions; but just that its a interesting Proof of Concept demonstrating an interesting way to enumerate information about systems while dealing with the constraints of the security model.</p>
<p>Regarding RSnake&#8217;s comment, I believe Billy did actually go to great lengths to protect the code, and still perform his demonstration.  A testament to this is the fact that all I actually got was client-side code &#8212; I did not get the GUI control component, viewer, etc. So the piece released was incomplete, and not actually usable in its current form.  I&#8217;ve not executed the code, and unless others have coded their own control/viewer component, its not that big of a deal that a small piece of it got out.</p>
<p>Update: IDG <a href="http://www.networkworld.com/news/2007/040207-javascript-botnet-code-leaked-to.html">articles</a> are released such as <a href="http://www.infoworld.com/article/07/04/02/HNjavascriptbotnet_1.html">InfoWorld</a>, <a href="http://blogs.zdnet.com/security/?p=146">ZDNet blogged</a> about it, <a href="http://news.com.com/2061-10789_3-6172605.html">CNet Security Blog</a>,  I posted on <a href="http://blog.vulnerableminds.com">VulnerableMinds</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://LogicX.net/security/jikto-source-code-situation/feed</wfw:commentRss>
		</item>
		<item>
		<title>Shmoocon Hack or Halo - Winner!</title>
		<link>http://LogicX.net/security/shmoocon-hack-or-halo-winner</link>
		<comments>http://LogicX.net/security/shmoocon-hack-or-halo-winner#comments</comments>
		<pubDate>Mon, 02 Apr 2007 03:00:12 +0000</pubDate>
		<dc:creator>LogicX</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://LogicX.net/security/shmoocon-hack-or-halo-winner</guid>
		<description><![CDATA[I competed in the Hack or Halo competition this past week at Shmoocon 2007.
There were about 40 people competing, in two sessions of 20. I completed 9 of the 22 goals, and was declared the winner during the closing ceremony Sunday afternoon.  I received an Xbox 360!
I&#8217;d have to say that the Friday night [...]]]></description>
			<content:encoded><![CDATA[<p>I competed in the <a href="http://shmoocon.org/hoh.html">Hack or Halo</a> competition this past week at <a href="http://www.shmoocon.org">Shmoocon</a> 2007.</p>
<p>There were about 40 people competing, in two sessions of 20. I completed 9 of the 22 goals, and was declared the winner during the closing ceremony Sunday afternoon.  I received an Xbox 360!</p>
<p>I&#8217;d have to say that the Friday night practice session was very helpful.  I had my work pentesting laptop along with me for the weekend, preloaded with all my tools, the only one I discovered to be lacking were tools to decode stegnography, so I quickly got <a href="http://steghide.sourceforge.net/">steghide</a> prior to Saturday Night&#8217;s competition.</p>
]]></content:encoded>
			<wfw:commentRss>http://LogicX.net/security/shmoocon-hack-or-halo-winner/feed</wfw:commentRss>
		</item>
		<item>
		<title>Peaceful Warrior - Great Movie - Great Marketing</title>
		<link>http://LogicX.net/misc/peaceful-warrior-great-movie-great-marketing</link>
		<comments>http://LogicX.net/misc/peaceful-warrior-great-movie-great-marketing#comments</comments>
		<pubDate>Sun, 01 Apr 2007 14:59:12 +0000</pubDate>
		<dc:creator>LogicX</dc:creator>
		
		<category><![CDATA[Misc]]></category>

		<guid isPermaLink="false">http://logicx.net/?p=4</guid>
		<description><![CDATA[Last night I went to see Peaceful Warrior downtown with my girlfriend Julie.  Saw it for Free.  In the last few weeks, every deal website on the net has been giving out free tickets through a best buy promo.
After I saw the movie, which was very good, I realized what had just happened. [...]]]></description>
			<content:encoded><![CDATA[<p>Last night I went to see <a href="http://www.thepeacefulwarriormovie.com/" target="_blank">Peaceful Warrior</a> downtown with my girlfriend Julie.  Saw it for Free.  In the last few weeks, every deal website on the net has been giving out free tickets through a best buy promo.</p>
<p>After I saw the movie, which was very good, I realized what had just happened.  They had this great movie, and said &#8220;now how do we get people to come see it?  We don&#8217;t have any names, and we don&#8217;t have any special effects&#8221;  Will Smith&#8217;s <a href="http://www.sonypictures.com/movies/thepursuitofhappyness/" target="_blank">Pursuit of Happiness</a> recently was released, I felt it was a great motivational, &#8216;feel good&#8217; movie, and did great &#8212; but it had Will Smith, who drew the crowds.</p>
<p>Someone on the marketing team for Peaceful Warror said: &#8220;We&#8217;ll give away <a href="http://www.bestbuy.com/peacefulwarrior" target="_blank">free tickets</a> opening weekend to those who are into technology &#8212; through Best Buy &#8212; they&#8217;ll see it, and blog about what a great movie it is, and millions more will come see it in theaters, making up for those few free tickets opening weekend.&#8221; And now it has happened.</p>
<p><a href="http://www.jpk236.com" target="_blank">Justin</a> has enhanced my theory with a note that the movie was released in 2006, and re-released this year, <a href="http://www.imdb.com/title/tt0438315/" target="_blank">according to IMDB</a>, so potentially they released it, no-one saw it &#8212; and then the events above transpired.</p>
<p><strong>Supporting evidence:</strong><br />
<a href="http://contrarygoddess.blogspot.com/2007/03/peaceful-warrior.html">the Contrary Goddess</a>:  &#8220;Well, they gave me free tickets, so it seems the least I could do would be to blog about it.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://LogicX.net/misc/peaceful-warrior-great-movie-great-marketing/feed</wfw:commentRss>
		</item>
		<item>
		<title>WPAD</title>
		<link>http://LogicX.net/security/wpad</link>
		<comments>http://LogicX.net/security/wpad#comments</comments>
		<pubDate>Sun, 01 Apr 2007 07:19:37 +0000</pubDate>
		<dc:creator>LogicX</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://logicx.net/?p=3</guid>
		<description><![CDATA[Insecurity at its best &#8212; At Shmoocon I saw a presentation on WPAD, which is essentially a means of dispensing new proxy settings to browsers.  Of course this was implemented by Microsoft, with no forms of security in mind.  Over the next few months I intend to use WPAD at clients to dispense [...]]]></description>
			<content:encoded><![CDATA[<p>Insecurity at its best &#8212; At <a href="http://www.shmoocon.org">Shmoocon</a> I saw a presentation on WPAD, which is essentially a means of dispensing new proxy settings to browsers.  Of course this was implemented by Microsoft, with no forms of security in mind.  Over the next few months I intend to use WPAD at clients to dispense rogue proxy servers, and see what sensitive information can be gathered.</p>
]]></content:encoded>
			<wfw:commentRss>http://LogicX.net/security/wpad/feed</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.801 seconds -->
