<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Disenchant's Blog &#187; Fun</title>
	<atom:link href="http://www.disenchant.ch/blog/category/fun/feed" rel="self" type="application/rss+xml" />
	<link>http://www.disenchant.ch/blog</link>
	<description>Blog of Sven Vetsch / Disenchant</description>
	<lastBuildDate>Thu, 22 Oct 2009 16:25:14 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Let&#8217;s Crash Google&#8217;s Chrome Browser</title>
		<link>http://www.disenchant.ch/blog/lets-crash-googles-chrome-browser/184</link>
		<comments>http://www.disenchant.ch/blog/lets-crash-googles-chrome-browser/184#comments</comments>
		<pubDate>Tue, 02 Sep 2008 22:19:00 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/?p=184</guid>
		<description><![CDATA[As you might know, today Google released it&#8217;s own web browser called Chrome. I just had to have a look at it and have to say, it&#8217;s really not that bad but I just wanted to know if I&#8217;m able to crash it  
Here&#8217;s my result after a few minutes:

The movie is that long [...]]]></description>
			<content:encoded><![CDATA[<p>As you might know, today Google released it&#8217;s own web browser called <a href="http://www.google.com/chrome">Chrome</a>. I just had to have a look at it and have to say, it&#8217;s really not that bad but I just wanted to know if I&#8217;m able to crash it <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Here&#8217;s my result after a few minutes:</p>
<p><img src="http://www.disenchant.ch/blog/wp-content/plugins/flash-video-player/default_video_player.gif" /></p>
<p>The movie is that long because I always had to check if my string is already long enough. The indicator for it was the mouse over effect (highlighting) of the button.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/lets-crash-googles-chrome-browser/184/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Swiss Post owned by Terrorists</title>
		<link>http://www.disenchant.ch/blog/swiss-post-owned-by-terrorists/148</link>
		<comments>http://www.disenchant.ch/blog/swiss-post-owned-by-terrorists/148#comments</comments>
		<pubDate>Thu, 28 Aug 2008 09:16:48 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/?p=148</guid>
		<description><![CDATA[My sister had her birthday a few days ago and she got a lot of cards from all over Switzerland. One of them was very interesting because it was a letter, sent from our aunts who&#8217;re living in Zurich Kloten which is where also the Zurich Airport is. Now remember 9/11 and have a look [...]]]></description>
			<content:encoded><![CDATA[<p>My sister had her birthday a few days ago and she got a lot of cards from all over Switzerland. One of them was very interesting because it was a letter, sent from our aunts who&#8217;re living in <a href="http://maps.google.com/maps?q=z%C3%BCrich+kloten">Zurich Kloten</a> which is where also the Zurich Airport is. Now remember 9/11 and have a look at the official post stamp on the letter:</p>
<p><a href="http://www.disenchant.ch/blog/wp-content/uploads/2008/08/post_terror_2.jpg"><img src="http://www.disenchant.ch/blog/wp-content/uploads/2008/08/post_terror_2.jpg" alt="" title="post_terror_2" width="174" height="99" class="aligncenter size-full wp-image-150" /></a></p>
<p><a href="http://www.disenchant.ch/blog/wp-content/uploads/2008/08/post_terror.jpg"><img src="http://www.disenchant.ch/blog/wp-content/uploads/2008/08/post_terror-300x211.jpg" alt="" title="post_terror" width="300" height="211" class="aligncenter size-medium wp-image-149" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/swiss-post-owned-by-terrorists/148/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Coffee Makers</title>
		<link>http://www.disenchant.ch/blog/hacking-coffee-makers/132</link>
		<comments>http://www.disenchant.ch/blog/hacking-coffee-makers/132#comments</comments>
		<pubDate>Wed, 18 Jun 2008 10:49:34 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/?p=132</guid>
		<description><![CDATA[Yesterday, Craig Wright has sent an email to the BugTraq mailing list and because it&#8217;s a funny story, I&#8217;d like to share it with my readers.

Hi All,
I have a Jura F90 Coffee maker with the Jura Internet Connection Kit. The idea is to:
&#8220;Enable the Jura Impressa F90 to communicate with the Internet, via a PC.
Download [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, Craig Wright has sent an <a href="http://www.securityfocus.com/archive/1/493387">email to the BugTraq mailing</a> list and because it&#8217;s a funny story, I&#8217;d like to share it with my readers.</p>
<blockquote><p>
Hi All,<br />
I have a Jura F90 Coffee maker with the Jura Internet Connection Kit. The idea is to:</p>
<p>&#8220;Enable the Jura Impressa F90 to communicate with the Internet, via a PC.<br />
Download parameters to configure your espresso machine to your own personal taste.<br />
If there&#8217;s a problem, the engineers can run diagnostic tests and advise on the solution without your machine ever leaving the kitchen.&#8221;</p>
<p>Guess what &#8211; it can not be patched as far as I can tell <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  It also has a few software vulnerabilities.</p>
<p>Fun things you can do with a Jura coffee maker:<br />
1. Change the preset coffee settings (make weak or strong coffee)<br />
2. Change the amount of water per cup (say 300ml for a short black) and make a puddle<br />
3. Break it by engineering settings that are not compatible (and making it require a service)</p>
<p>The connectivity kit uses the connectivity of the PC it is running on to connect the coffee machine to the internet. This allows a remote coffee machine &#8220;engineer&#8221; to diagnose any problems and to remotely do a preliminary service.</p>
<p>Best yet, the software allows a remote attacker to gain access to the Windows XP system it is running on at the level of the user.</p>
<p>Compromise by Coffee.</p>
<p>Regards,<br />
Craig Wright GSE-Compliance
</p></blockquote>
<p>PS: I&#8217;m really looking forward to a coffee maker with a web interface <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/hacking-coffee-makers/132/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Youtube has got Code Monkeys</title>
		<link>http://www.disenchant.ch/blog/youtube-has-got-code-monkeys/121</link>
		<comments>http://www.disenchant.ch/blog/youtube-has-got-code-monkeys/121#comments</comments>
		<pubDate>Sat, 29 Mar 2008 12:47:53 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/youtube-has-got-code-monkeys/121</guid>
		<description><![CDATA[We all know the &#8220;500 Internal Server Error&#8221; but have you ever seen it on youtube.com:
http://m.youtube.com/index?warned=1&#038;session=%
It says:

Sorry, something went wrong.
A team of highly trained monkeys has been dispatched to deal with this situation. Please report this incident to customer service.
You guys made my day  
PS: For some reason you sometimes have to click on [...]]]></description>
			<content:encoded><![CDATA[<p>We all know the &#8220;500 Internal Server Error&#8221; but have you ever seen it on youtube.com:<br />
<a href="http://m.youtube.com/index?warned=1&#038;session=%">http://m.youtube.com/index?warned=1&#038;session=%</a></p>
<p>It says:</p>
<blockquote><p>
Sorry, something went wrong.<br />
A team of highly trained monkeys has been dispatched to deal with this situation. Please report this incident to customer service.</p></blockquote>
<p>You guys made my day <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>PS: For some reason you sometimes have to click on the link twice until you get the message.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/youtube-has-got-code-monkeys/121/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Advanced English?</title>
		<link>http://www.disenchant.ch/blog/advanced-english/111</link>
		<comments>http://www.disenchant.ch/blog/advanced-english/111#comments</comments>
		<pubDate>Thu, 28 Feb 2008 00:14:01 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[personal]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/advanced-english/111</guid>
		<description><![CDATA[As you might know, I&#8217;m actually studying computer science at the Bern University of Applied Sciences Engineering and Information Technology. Yesterday we had English lessons and I&#8217;m in the advanced group, which is the highest level we can attend in this semester. So let&#8217;s have a look at an exercise we&#8217;ve done in this lesson [...]]]></description>
			<content:encoded><![CDATA[<p>As you might know, I&#8217;m actually studying computer science at the <a href="http://ti.bfh.ch/">Bern University of Applied Sciences Engineering and Information Technology</a>. Yesterday we had English lessons and I&#8217;m in the advanced group, which is the highest level we can attend in this semester. So let&#8217;s have a look at an exercise we&#8217;ve done in this lesson and I really think, that anyone who can read my blog should ask my school if they can give you a certificate in English Advanced because you really should be able to solve the following. At least for me the word advanced means something completely different <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p><a href='http://www.disenchant.ch/blog/wp-content/uploads/2008/02/advanced_english.jpg' title='Advanced English'><img src='http://www.disenchant.ch/blog/wp-content/uploads/2008/02/advanced_english.thumbnail.jpg' alt='Advanced English' /></a><br />
(click to enlarge)</p>
<p>Hope you enjoy solving this &#8220;advanced&#8221; exercise and no, it&#8217;s not the only advanced exercise we&#8217;ve done <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/advanced-english/111/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>A Native &#8220;JavaScript&#8221; Speaker?</title>
		<link>http://www.disenchant.ch/blog/a-native-javascript-speaker/107</link>
		<comments>http://www.disenchant.ch/blog/a-native-javascript-speaker/107#comments</comments>
		<pubDate>Mon, 11 Feb 2008 07:01:34 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/a-native-javascript-speaker/107</guid>
		<description><![CDATA[I just found a website, where you can let a bot read an article to you. You might say that this isn&#8217;t special but there was this parameter called &#8220;id&#8221; which I had to play with. When I used id=8838 it was some kind of special because it was reading the code of it&#8217;s own [...]]]></description>
			<content:encoded><![CDATA[<p>I just found a website, where you can let a bot read an article to you. You might say that this isn&#8217;t special but there was this parameter called &#8220;id&#8221; which I had to play with. When I used id=8838 it was some kind of special because it was reading the code of it&#8217;s own JavaScript function vh_sceneLoaded(). It says:</p>
<blockquote><p>
<em>&#x6C;&#x6F;&#x61;&#x64;&#x54;&#x65;&#x78;&#x74;&#x28;&#x27;&#x2E;&#x20;&#x2E;&#x64;&#x72;&#x75;&#x63;&#x6B;&#x65;&#x6E;&#x20;&#x7B;&#x64;&#x69;&#x73;&#x70;&#x6C;&#x61;&#x79;&#x3A;&#x20;&#x6E;&#x6F;&#x6E;&#x65;&#x3B;&#x7D;&#x2E;&#x73;&#x65;&#x6E;&#x64;&#x65;&#x6E;&#x20;&#x7B;&#x64;&#x69;&#x73;&#x70;&#x6C;&#x61;&#x79;&#x3A;&#x20;&#x6E;&#x6F;&#x6E;&#x65;&#x3B;&#x7D;&#x2E;&#x71;&#x75;&#x65;&#x6C;&#x6C;&#x65;&#x20;&#x7B;&#x64;&#x69;&#x73;&#x70;&#x6C;&#x61;&#x79;&#x3A;&#x20;&#x6E;&#x6F;&#x6E;&#x65;&#x3B;&#x7D;&#x2E;&#x61;&#x72;&#x74;&#x62;&#x6F;&#x78;&#x62;&#x6F;&#x74;&#x74;&#x6F;&#x6D;&#x32;&#x73;&#x70;&#x20;&#x7B;&#x68;&#x65;&#x69;&#x67;&#x68;&#x74;&#x3A;&#x20;&#x31;&#x35;&#x70;&#x78;&#x3B;&#x77;&#x69;&#x64;&#x74;&#x68;&#x3A;&#x20;&#x34;&#x36;&#x35;&#x3B;&#x62;&#x61;&#x63;&#x6B;&#x67;&#x72;&#x6F;&#x75;&#x6E;&#x64;&#x3A;&#x20;&#x75;&#x72;&#x6C;&#x28;&#x2F;&#x5F;&#x69;&#x6D;&#x61;&#x67;&#x65;&#x73;&#x5F;&#x2F;&#x68;&#x67;&#x5F;&#x73;&#x70;&#x69;&#x74;&#x7A;&#x6D;&#x61;&#x72;&#x6B;&#x65;&#x5F;&#x32;&#x73;&#x70;&#x5F;&#x62;&#x6F;&#x74;&#x74;&#x6F;&#x6D;&#x2E;&#x67;&#x69;&#x66;&#x29;&#x3B;&#x7D;&#x20;&#x57;&#x65;&#x62;&#x77;&#x77;&#x77;&#x2E;&#x65;&#x73;&#x70;&#x61;&#x63;&#x65;&#x2E;&#x63;&#x68;&#x27;&#x2C;&#x32;&#x2C;&#x33;&#x2C;&#x32;&#x29;&#x3B;</em>
</p></blockquote>
<p>Who knows, perhaps JavaScript will become the first natively spoken programming language. At least it would be really easy to speak for me because it seems that in &#8220;JavaScriptish&#8221;, the spelling is the same as in German <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p> <a href="http://www.espace.ch/_inc_/text2speech/player.asp?id=8838">Meet the native Javascript Speaker</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/a-native-javascript-speaker/107/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How was the Hotel? &#8211; Vulnerable!</title>
		<link>http://www.disenchant.ch/blog/how-was-the-hotel-vulnerable/108</link>
		<comments>http://www.disenchant.ch/blog/how-was-the-hotel-vulnerable/108#comments</comments>
		<pubDate>Wed, 23 Jan 2008 10:08:07 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/how-was-the-hotel-vulnerable/108</guid>
		<description><![CDATA[(According to the following blog posting, be aware of that I&#8217;ve never bypassed any authorization mechanism, nor did I break, access or change anything I was not allowed to.)
Last weekend, I went snowboarding in the Swiss mountains and the weather including the snow was just perfect. Because the winter sport season hasn&#8217;t started yet, there [...]]]></description>
			<content:encoded><![CDATA[<p>(According to the following blog posting, be aware of that I&#8217;ve never bypassed any authorization mechanism, nor did I break, access or change anything I was not allowed to.)</p>
<p>Last weekend, I went snowboarding in the Swiss mountains and the weather including the snow was just perfect. Because the winter sport season hasn&#8217;t started yet, there wasn&#8217;t much going on in the evening and so I was using one of the public Hotspots of the hotel. As you can think, I had to make some security related stuff and so I surfed to the Hotel&#8217;s website. There are SQL injections, XSS, Local File Inclusions and much more but I don&#8217;t want to talk more about it because there was something much more interesting. Normally when you offer a Hotspot as a hotel or any other company, you should separate it from your internal LAN but don&#8217;t even think of anyone is really doing this unless they have to for any reason. So, my IP address was now 192.168.44.36 which&#8217;s an internal IP address. The next step was of course to use our all friend <a href="http://nmap.org/">nmap</a> and let&#8217;s see what I&#8217;ve got:</p>
<blockquote><p>
Interesting ports on 192.168.1.5:<br />
PORT   STATE SERVICE VERSION<br />
25/tcp open  smtp    Microsoft ESMTP 5.0.2195.6713<br />
80/tcp open  http    Microsoft IIS webserver 5.0
</p></blockquote>
<p>Jackpot, I&#8217;ve got a Microsoft IIS 5.0 webserver on the standard HTTP port 80 and this means hopefully an internal web application <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I connected to 192.168.1.5 with my favorite web browser and wow, amazing security measures there. No sorry, I&#8217;m just joking. There where no security measures at all. I simply get a menu, where I could choose a &#8220;console&#8221;. I took the first one because the others seemed to be offline. Oh my god (who&#8217;s by the way the <a href="http://www.venganza.org/">FSM</a>), I was now having control over more or less the whole hotel (don&#8217;t ask me why this is the case with the product of a company describing itself as &#8220;<a href="http://www.otrum.com/">OTRUM</a> is a leading provider of interactive TV solutions and content to the hospitality industry.&#8221;).</p>
<p>Let&#8217;s have a look at who&#8217;re my neighbors:<br />
<a href='http://www.disenchant.ch/blog/wp-content/uploads/2008/01/hotel_guest_list.jpg' title='Hotel Guest List Small'><img src='http://www.disenchant.ch/blog/wp-content/uploads/2008/01/hotel_guest_list_small.jpg' alt='Hotel Guest List Small' /></a><br />
(Click the image to enlarge)</p>
<p>Cool stuff, with this I even know in which language I can say good morning to my neighbors <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>There where much more information than just the things for the reception. When you clicked on &#8220;Main Menu&#8221;, you had several other options than just &#8220;Reception&#8221;. For example you where able to create new rooms, new employers, new TV channels, have a look at a whole bunch of statistics or define even a room&#8217;s temperature and much more. The funniest thing I found (which wasn&#8217;t used by the hotel I was in), was a statistic, checking if the mini bar has been opened and how many times. My advice if you want to make the guys at the reception looking strange at you would be to open your mini bar at least one hundred times a day <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>As you can think, it was fun to see all this stuff and an evil guy (or girl) could have done nasty stuff there but hey, I never had to authenticate myself so it was open to everyone and because of this it&#8217;s not illegal to just surf this &#8220;website&#8221;.</p>
<p>For sure this application was the most interesting thing for me but there where even more security problems like:</p>
<p>http://192.168.1.5/cgi-bin/thrusocket.pl?&#038;gltemplatefile=../../../../../boot.ini</p>
<blockquote><p>
[boot loader]<br />
timeout=30<br />
default=multi(0)disk(0)rdisk(0)partition(1)\WINNT<br />
[operating systems]<br />
multi(0)disk(0)rdisk(0)partition(1)\WINNT=&#8221;Microsoft Windows 2000 Server&#8221; /fastdetect
</p></blockquote>
<p>OK, anyone can read your data on the server but who want&#8217;s to read files if you can make an automated wake up call at 5 o&#8217;clock in the morning to every guest in the whole hotel? <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>There was also a Directory Listing at http://192.168.1.5/cgi-bin/ and some other not really interesting things. I can say, that I enjoyed the stay in this hotel for sure.</p>
<p>Lesson learned here: Don&#8217;t let security guys into your hotel if you don&#8217;t want them to have a look at your infrastructure <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/how-was-the-hotel-vulnerable/108/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Become a Suspect</title>
		<link>http://www.disenchant.ch/blog/become-a-suspect/99</link>
		<comments>http://www.disenchant.ch/blog/become-a-suspect/99#comments</comments>
		<pubDate>Wed, 28 Nov 2007 18:05:32 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/become-a-suspect/99</guid>
		<description><![CDATA[A few days ago, I&#8217;ve got the following Mail (it&#8217;s in German):
Hallo,
das warst doch du, der unser Sprachportal (MobiLingua, Uni Passau) über das Forum gehackt hat und mir damit einen gehörigen Schrecken eingejagt hat, oder?
Jedenfalls danke für den Hinweis &#8211; das ist halt der Nachteil von CMS: Man kann zwar mit relativ wenig Hintergrundwissen ein [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago, I&#8217;ve got the following Mail (it&#8217;s in German):</p>
<blockquote><p>Hallo,<br />
das warst doch du, der unser Sprachportal (MobiLingua, Uni Passau) über das Forum gehackt hat und mir damit einen gehörigen Schrecken eingejagt hat, oder?<br />
Jedenfalls danke für den Hinweis &#8211; das ist halt der Nachteil von CMS: Man kann zwar mit relativ wenig Hintergrundwissen ein Layout anpassen und Inhalte bereitstellen, denkt aber in der Regel nicht an Sicherheitsaspekte (in der Hoffnung, dass das System das schon macht <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ) </p>
<p>LG, [name of the sender]</p></blockquote>
<p>In English this means, that someone of the <a href="http://www.uni-passau.de/index.php?id=6&#038;L=1">University of Passau</a> thinks, that I&#8217;ve hacked their online platform called <a href="http://ocp.uni-passau.de/sprachportal/?q=en">MobiLingua</a>. Of course I didn&#8217;t hack their page and also I never heard about this  MobiLingua before. Because of this, I answered the following:</p>
<blockquote><p>Hallo,<br />
ich beschäftige mich zwar beruflich sowie privat mit der Sicherheit von Webanwendungen, doch habe ich noch nie von genanntem Portal (MobiLingua, Uni Passau) gehört, geschweige denn habe ich dieses angegriffen.</p>
<p>Ich würde mich sehr darüber freuen, wenn Sie mich so schnell als möglich darüber informieren könnten, wie Sie auf mich kommen in diesem Zusammenhang.</p>
<p>Freundliche Grüsse und ein schönes Wochenende,<br />
Sven Vetsch</p></blockquote>
<p>This means, that I just wanted to know, why they think that I have attacked their site because it&#8217;s true that I have to deal with web application security every day but why they think I&#8217;ve done something when I know, that I didn&#8217;t do anything? The next mail I get answered this question:</p>
<blockquote><p>Hallo,<br />
bitte entschuldigen Sie, wenn ich mit meiner Vermutung falsch lag. Jemand hatte ein Online-Portal mit einem Foreneintrag gehackt, in dem HTML und Javascript untergebracht worden war. Dies war ein nett gemeinter Hinweis, auf eine bestehende Sicherheitslücke, offensichtlich ohne böse Absichten. Jedenfalls wurde dadurch in mein Layout statt dem üblichen Logo ein &#8220;Hacked&#8221;-Logo eingebaut, bei dem die URL auf Ihre Domain verwies. Ein Blick auf die Inhalte dieser Seite hat gezeigt, dass Sie sich mit eben solchen Sicherheitslücken auseinandersetzen und ich glaubte den &#8220;Verursacher&#8221; gefunden zu haben. </p>
<p>Ich entschuldige mich deshalb vielmals für meinen Fehler.. </p>
<p>Mit freundlichen Grüßen und ein schönes Wochenende,<br />
[name of the sender]</p></blockquote>
<p>First it was written, that they&#8217;re sorry for suspecting me and afterwards it was described, why they think that I&#8217;ve done the hack on their platform and also what happened. Someone has inserted a &#8220;Hacked&#8221;-logo through a HTML- and Javascript-Injection (today aka. <a href="http://en.wikipedia.org/wiki/XSS" TARGET="_blank">XSS</a>) and on request I get the injected code:</p>
<blockquote style="text-align:left"><p>&#x3C;&#x73;&#x63;&#x72;&#x69;&#x70;&#x74;&#x3E;<br />
&#x0A;&#x0A;&#x20;&#x20;&#x61;&#x6C;&#x65;&#x72;&#x74;&#x28;&#x27;&#x49;&#x68;&#x72;&#x65;&#x20;&#x46;&#x65;&#x73;&#x74;&#x70;&#x6C;&#x61;&#x74;&#x74;&#x65;&#x20;&#x77;&#x69;&#x72;&#x64;&#x20;&#x66;&#x6F;&#x72;&#x6D;&#x61;&#x74;&#x69;&#x65;&#x72;&#x74;&#x20;&#x77;&#x65;&#x6E;&#x6E;&#x20;&#x53;&#x69;&#x65;&#x20;&#x4F;&#x4B;&#x20;&#x6B;&#x6C;&#x69;&#x63;&#x6B;&#x65;&#x6E;&#x2E;&#x20;&#x53;&#x63;&#x68;&#x61;&#x6C;&#x74;&#x65;&#x6E;&#x20;&#x53;&#x69;&#x65;&#x20;&#x49;&#x68;&#x72;&#x65;&#x6E;&#x20;&#x52;&#x65;&#x63;&#x68;&#x6E;&#x65;&#x72;&#x20;&#x61;&#x75;&#x73;&#x20;&#x75;&#x6D;&#x20;&#x61;&#x62;&#x7A;&#x75;&#x62;&#x72;&#x65;&#x63;&#x68;&#x65;&#x6E;&#x2E;&#x27;&#x29;&#x3B;<br />
&#x0A;&#x0A;&#x0A;&#x0A;&#x64;&#x6F;&#x63;&#x75;&#x6D;&#x65;&#x6E;&#x74;&#x2E;&#x67;&#x65;&#x74;&#x45;&#x6C;&#x65;&#x6D;&#x65;&#x6E;&#x74;&#x73;&#x42;&#x79;&#x54;&#x61;&#x67;&#x4E;&#x61;&#x6D;&#x65;&#x28;&#x22;&#x62;&#x6F;&#x64;&#x79;&#x22;&#x29;&#x5B;&#x30;&#x5D;&#x2E;&#x73;&#x74;&#x79;&#x6C;&#x65;&#x2E;&#x62;&#x61;&#x63;&#x6B;&#x67;&#x72;&#x6F;&#x75;&#x6E;&#x64;&#x43;&#x6F;&#x6C;&#x6F;&#x72;&#x20;&#x3D;&#x20;&#x22;&#x66;&#x75;&#x63;&#x68;&#x73;&#x69;&#x61;&#x22;&#x3B;<br />
&#x0A;&#x0A;&#x64;&#x6F;&#x63;&#x75;&#x6D;&#x65;&#x6E;&#x74;&#x2E;&#x67;&#x65;&#x74;&#x45;&#x6C;&#x65;&#x6D;&#x65;&#x6E;&#x74;&#x42;&#x79;&#x49;&#x64;&#x28;&#x22;&#x73;&#x69;&#x74;&#x65;&#x2D;&#x6C;&#x6F;&#x67;&#x6F;&#x22;&#x29;&#x2E;&#x73;&#x72;&#x63;&#x20;&#x3D;&#x20;&#x22;&#x68;&#x74;&#x74;&#x70;&#x3A;&#x2F;&#x2F;&#x77;&#x77;&#x77;&#x2E;&#x64;&#x69;&#x73;&#x65;&#x6E;&#x63;&#x68;&#x61;&#x6E;&#x74;&#x2E;&#x63;&#x68;&#x2F;&#x62;&#x6C;&#x6F;&#x67;&#x2F;&#x69;&#x6D;&#x61;&#x67;&#x65;&#x73;&#x2F;&#x65;&#x6E;&#x74;&#x72;&#x69;&#x65;&#x73;&#x2F;&#x68;&#x61;&#x63;&#x6B;&#x65;&#x64;&#x2E;&#x67;&#x69;&#x66;&#x22;&#x3B;<br />
&#x0A;&#x0A;&#x0A;&#x0A;&#x64;&#x6F;&#x63;&#x75;&#x6D;&#x65;&#x6E;&#x74;&#x2E;&#x67;&#x65;&#x74;&#x45;&#x6C;&#x65;&#x6D;&#x65;&#x6E;&#x74;&#x42;&#x79;&#x49;&#x64;&#x28;&#x22;&#x70;&#x61;&#x67;&#x65;&#x22;&#x29;&#x2E;&#x6C;&#x61;&#x73;&#x74;&#x43;&#x68;&#x69;&#x6C;&#x64;&#x2E;&#x69;&#x6E;&#x6E;&#x65;&#x72;&#x48;&#x54;&#x4D;&#x4C;&#x20;&#x2B;&#x3D;&#x20;&#x27;&#x3C;&#x62;&#x72;&#x3E;&#x44;&#x65;&#x66;&#x61;&#x63;&#x65;&#x6D;&#x65;&#x6E;&#x74;&#x3A;&#x20;&#x44;&#x61;&#x20;&#x33;&#x76;&#x31;&#x6C;&#x20;&#x48;&#x34;&#x58;&#x30;&#x72;&#x5A;&#x20;&#x32;&#x30;&#x30;&#x37;&#x20;&#x3B;&#x29;&#x20;&#x6C;&#x6F;&#x6C;&#x27;&#x3B;<br />
&#x0A;&#x0A;&#x66;&#x6F;&#x72;&#x28;&#x69;&#x20;&#x3D;&#x20;&#x30;&#x3B;&#x20;&#x69;&#x20;&#x3C;&#x20;&#x35;&#x30;&#x3B;&#x20;&#x69;&#x2B;&#x2B;&#x29;&#x7B;<br />
&#x0A;&#x0A;&#x64;&#x6F;&#x63;&#x75;&#x6D;&#x65;&#x6E;&#x74;&#x2E;&#x67;&#x65;&#x74;&#x45;&#x6C;&#x65;&#x6D;&#x65;&#x6E;&#x74;&#x73;&#x42;&#x79;&#x54;&#x61;&#x67;&#x4E;&#x61;&#x6D;&#x65;&#x28;&#x22;&#x64;&#x69;&#x76;&#x22;&#x29;&#x5B;&#x69;&#x5D;&#x2E;&#x73;&#x74;&#x79;&#x6C;&#x65;&#x2E;&#x62;&#x61;&#x63;&#x6B;&#x67;&#x72;&#x6F;&#x75;&#x6E;&#x64;&#x43;&#x6F;&#x6C;&#x6F;&#x72;&#x20;&#x3D;&#x20;&#x22;&#x66;&#x75;&#x63;&#x68;&#x73;&#x69;&#x61;&#x22;&#x3B;<br />
&#x0A;&#x0A;&#x7D;&#x0A;&#x0A;&#x0A;&#x0A;<br />
&#x3C;&#x2F;&#x73;&#x63;&#x72;&#x69;&#x70;&#x74;&#x3E;</p></blockquote>
<p>Now it was clear what happened. The image (<a href="http://www.disenchant.ch/blog/images/entries/hacked.gif">http://www.disenchant.ch/blog/images/entries/hacked.gif</a>) which was used for the hack or better call it now a defacement, was the one I&#8217;ve uploaded for my blog posting &#8220;<a href="http://www.disenchant.ch/blog/owasporg-hacked/69">owasp.org hacked</a>&#8220;, where I wrote about someone who &#8220;<a href="http://www.owasp.org/index.php?title=Category:OWASP_Papers&#038;oldid=18724">hacked</a>&#8221; <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  the <a href="http://owasp.org/">OWASP website/Wiki</a>. When the people from the University of Passau checked the code, they found out, that the image was hosted on my domain and that I&#8217;ve got something to do with web application security. Now everything is clear and life goes on but this story really make me think of what can happen by just linking to or on the other side hosting images, even if it&#8217;s just mistake. It really shows, how easy someone can become a suspect in our so called information century.</p>
<p>PS: I really have to translate the alert message of the used payload to English. &#8220;Ihre Festplatte wird formatiert wenn Sie OK klicken. Schalten Sie Ihren Rechner aus um abzubrechen.&#8221; means &#8220;Your hard disk will be formatted when you click OK. Turn off your computer to cancel.&#8221;. And I thought that at least these idiots became extinct years ago <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/become-a-suspect/99/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hide Email Address from Spam Bots</title>
		<link>http://www.disenchant.ch/blog/hide-email-address-from-spam-bots/86</link>
		<comments>http://www.disenchant.ch/blog/hide-email-address-from-spam-bots/86#comments</comments>
		<pubDate>Mon, 13 Aug 2007 15:20:08 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/hide-email-address-from-spam-bots/86</guid>
		<description><![CDATA[Today I came across the user profile of Foz at the wiki of the Chaos Communication Camp 2007. He&#8217;s done a really nice way of hiding his mail address from spam bots (I&#8217;ve done it now with my own address):
&#114&#117&#98&#121&#32&#45&#101&#32&#39&#112&#117&#116&#115&#32&#34&#104&#33&#99&#33&#46&#33&#116&#33&#110&#33&#97&#33&#104&#33&#99&#33&#110&#33&#101&#33&#115&#33&#105&#33&#100&#33&#64&#33&#104&#33&#99&#33&#115&#33&#116&#33&#101&#33&#118&#33&#46&#33&#110&#33&#101&#33&#118&#33&#115&#34&#46&#115&#112&#108&#105&#116&#40&#34&#33&#34&#41&#46&#106&#111&#105&#110&#46&#114&#101&#118&#101&#114&#115&#101&#39
Of course no normal or better say &#8220;non-geek&#8221; person will be able to contact you anymore [...]]]></description>
			<content:encoded><![CDATA[<p>Today I came across the <a href="http://events.ccc.de/camp/2007/User:Foz">user profile of Foz</a> at the wiki of the <a href="http://events.ccc.de/camp/2007/Intro/">Chaos Communication Camp 2007</a>. He&#8217;s done a really nice way of hiding his mail address from spam bots (I&#8217;ve done it now with my own address):</p>
<blockquote><p>&#114&#117&#98&#121&#32&#45&#101&#32&#39&#112&#117&#116&#115&#32&#34&#104&#33&#99&#33&#46&#33&#116&#33&#110&#33&#97&#33&#104&#33&#99&#33&#110&#33&#101&#33&#115&#33&#105&#33&#100&#33&#64&#33&#104&#33&#99&#33&#115&#33&#116&#33&#101&#33&#118&#33&#46&#33&#110&#33&#101&#33&#118&#33&#115&#34&#46&#115&#112&#108&#105&#116&#40&#34&#33&#34&#41&#46&#106&#111&#105&#110&#46&#114&#101&#118&#101&#114&#115&#101&#39</p></blockquote>
<p>Of course no normal or better say &#8220;non-geek&#8221; person will be able to contact you anymore but I think it&#8217;s a cool idea and of course you can rewrite it for your favorite programming language just like Python or Perl <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Btw. sorry to everyone that I&#8217;m not writing that much at the moment but I&#8217;ve really much to do. Don&#8217;t worry, I&#8217;m working on some nice stuff and as soon as possible I&#8217;ll inform you on what you can expect from me in the near future.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/hide-email-address-from-spam-bots/86/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Craziest Captchas on the Web</title>
		<link>http://www.disenchant.ch/blog/craziest-captchas-on-the-web/84</link>
		<comments>http://www.disenchant.ch/blog/craziest-captchas-on-the-web/84#comments</comments>
		<pubDate>Mon, 30 Jul 2007 11:17:54 +0000</pubDate>
		<dc:creator>Disenchant</dc:creator>
				<category><![CDATA[Fun]]></category>

		<guid isPermaLink="false">http://www.disenchant.ch/blog/craziest-captchas-on-the-web/84</guid>
		<description><![CDATA[I found the following blog posting and like to share it with all of you. It has some really crazy examples of CAPTCHAS there and my favorite is definitely the one with the CAPTCHA string in the image&#8217;s URI   
Craziest Captchas on the Web
]]></description>
			<content:encoded><![CDATA[<p>I found the following blog posting and like to share it with all of you. It has some really crazy examples of CAPTCHAS there and my favorite is definitely the one with the CAPTCHA string in the image&#8217;s URI <img src='http://www.disenchant.ch/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  </p>
<p><a href="http://www.tonsai.de/blog-english/2007/craziest-captchas-on-the-web/">Craziest Captchas on the Web</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.disenchant.ch/blog/craziest-captchas-on-the-web/84/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
