<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vnull&#039;s blog &#187; Security</title>
	<atom:link href="http://jakub.wartak.pl/blog/?feed=rss2&#038;cat=9" rel="self" type="application/rss+xml" />
	<link>http://jakub.wartak.pl/blog</link>
	<description>by Jakub Wartak</description>
	<lastBuildDate>Thu, 20 May 2010 12:53:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SHA1, SHA256, SHA512 in Oracle for free without using DBMS_CRYPTO</title>
		<link>http://jakub.wartak.pl/blog/?p=124</link>
		<comments>http://jakub.wartak.pl/blog/?p=124#comments</comments>
		<pubDate>Thu, 21 May 2009 18:10:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=124</guid>
		<description><![CDATA[SHA1, SHA256, SHA512 in Oracle for free without using DBMS_CRYPTO! (yay! without Enterprise Edition!) powered by GNU CRYPTO project 
For detailed list of algorithms please consider this link. (much more than DBMS_CRYPTO in 11g, which requires you to buy Enterprise Edition).

[oracle@xeno src]$ ls -l
total 764
-rw-rw-r-- 1 vnull vnull    458 Mar  1 [...]]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=124</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Oracle Database Vault, not so 0-day anymore, privilege escalation using ptrace(2) from UNIX account</title>
		<link>http://jakub.wartak.pl/blog/?p=92</link>
		<comments>http://jakub.wartak.pl/blog/?p=92#comments</comments>
		<pubDate>Tue, 18 Nov 2008 16:10:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=92</guid>
		<description><![CDATA[It seems, that there are many misunderstandings surrounding Database Vault (Oracle product for protecting sensitive data from company employees &#8211; such like *credit card* records and other very sensitve financial data). Oracle&#8217;s marketing tried to always claim that is product is able to protect data from administrators(!), which of course is not true. Let&#8217;s take [...]]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=92</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Securing OpenLDAP &#8211; userPassword issue</title>
		<link>http://jakub.wartak.pl/blog/?p=68</link>
		<comments>http://jakub.wartak.pl/blog/?p=68#comments</comments>
		<pubDate>Tue, 26 Jun 2007 10:03:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[LDAP]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Solaris]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=68</guid>
		<description><![CDATA[Unsecured OpenLDAP (slapd) server&#8230;
Output from Solaris 10 box:

-bash-3.00# ldaplist -l passwd test5
dn: uid=test5,ou=People,dc=lab1
uid: test5
cn: Johnny Doe
[..]
homeDirectory: /export/home/test5
userPassword: {MD5}DMF1ucDxtqgxw5niaXcmYQ==

After adding following snippet to OpenLDAP&#8217;s slapd.conf file we are preventing anyone from viewing user password(including Solaris LDAP proxy bind, excluding logging in user and admin/Manager of slapd):

access to attrs=userPassword,shadowLastChange
by dn="cn=admin,dc=lab1" write
by anonymous auth
by self write
by * read


-bash-3.00# [...]]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=68</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Confidence 2007</title>
		<link>http://jakub.wartak.pl/blog/?p=52</link>
		<comments>http://jakub.wartak.pl/blog/?p=52#comments</comments>
		<pubDate>Wed, 09 May 2007 16:16:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=52</guid>
		<description><![CDATA[You can meet me on Confidence 2007 security event &#8230;
]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=52</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MikroTik #2</title>
		<link>http://jakub.wartak.pl/blog/?p=8</link>
		<comments>http://jakub.wartak.pl/blog/?p=8#comments</comments>
		<pubDate>Tue, 13 Mar 2007 16:44:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=8</guid>
		<description><![CDATA[Post z dnia: 10/09/2006
Wyslalem microHOWTO, kody cracka, itd. do Mikrotika, nawet nie dostalem emaila z podziekowaniem.
WNIOSEK: nie oplaca sie przekazywac takich informacji do firm. Jesli to crack to lepiej puscic w net przez kilka krajow ( chiny, brazylia ) przez proxy i wpuscic do p2p. No w koncu nie maja czasu podziekowac to na pewno [...]]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=8</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>MikroTik #1</title>
		<link>http://jakub.wartak.pl/blog/?p=6</link>
		<comments>http://jakub.wartak.pl/blog/?p=6#comments</comments>
		<pubDate>Tue, 13 Mar 2007 16:40:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=6</guid>
		<description><![CDATA[Post z dnia: 08/09/2006
Wyslalem info o technice duplikowania(crackowania) Mikrotikow na tej samej licencji&#8230; do wlascicieli Mikrotika. Przyslali mi ze potencjalnie mi podziekuja ( ale z maila nie wynika zeby mi dziekowali?! ), i ze jesli im przekaze wiecej info to mnie nie oskarza w zaden sposob ( taki zrobilem sobie wymog ).
Napisali mi ze nie [...]]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=6</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cisco &#8211; security w ISP</title>
		<link>http://jakub.wartak.pl/blog/?p=4</link>
		<comments>http://jakub.wartak.pl/blog/?p=4#comments</comments>
		<pubDate>Tue, 13 Mar 2007 16:37:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://vnull.pcnet.com.pl/blog/?p=4</guid>
		<description><![CDATA[Post z dnia 15/08/2006:
Mam dobry pomysl na zabezpieczenie sieci klientow, zalety:
+ minimalizuje ilosc na prawde dobrych przelacznikow, tj. od cisco 2950 EE w gore
+ czyli mamy wszelkie zabezpieczenia typu IP source guard / ARPy itd.
Wady:
- caly ruch klientow przebiega przez te wlasnie switche glowne(dobre),
- klienci musza byc wpieci jednak do switchy zarzadzalnych z VLANami ( [...]]]></description>
		<wfw:commentRss>http://jakub.wartak.pl/blog/?feed=rss2&amp;p=4</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
