<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vandeneynde.net &#187; Windows</title>
	<atom:link href="http://www.vandeneynde.net/category/windows/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vandeneynde.net</link>
	<description></description>
	<lastBuildDate>Fri, 20 Feb 2009 09:08:35 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Belgian Terrorists caught on possession of wiping software?</title>
		<link>http://www.vandeneynde.net/2008/06/09/belgian-terrorists-caught-on-possesion-of-wiping-software/</link>
		<comments>http://www.vandeneynde.net/2008/06/09/belgian-terrorists-caught-on-possesion-of-wiping-software/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 10:27:49 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.vandeneynde.net/?p=58</guid>
		<description><![CDATA[
An article in Datanews (dutch only) today reports on the police arresting four ex-CCC members on two facts:

They were linked to a terrorist organization in Italy
They had &#8216;encoding&#8217; software on their PC&#8217;s to securely wipe hard drives. (most likely the reporter meant wiping instead of encoding.)

On the first fact, I can certainly agree but with [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://www.vandeneynde.net/wp-content/uploads/2008/06/eraser.jpg" rel="lightbox"><img class="size-full wp-image-59 aligncenter" title="eraser" src="http://www.vandeneynde.net/wp-content/uploads/2008/06/eraser.jpg" alt="Eraser" /></a></p>
<p>An <a href="http://www.datanews.be/nl/90-7-18605/article.html?cid=rss">article in Datanews</a> (dutch only) today reports on the police arresting four ex-<a href="http://en.wikipedia.org/wiki/Communist_Combatant_Cells">CCC</a> members on two facts:</p>
<ol>
<li>They were linked to a terrorist organization in Italy</li>
<li>They had &#8216;encoding&#8217; software on their PC&#8217;s to securely wipe hard drives. (most likely the reporter meant wiping instead of encoding.)</li>
</ol>
<p>On the first fact, I can certainly agree but with regards to the second fact, I did not know it was illegal in Belgium to have this kind of software installed on your PC.</p>
<p>I for one have <a href="http://www.truecrypt.org/">Truecrypt </a>as encryption software and <a href="http://www.heidi.ie/node/6">Eraser </a>as DoD compliant erasing software installed on my laptop. Am I a terrorist now?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vandeneynde.net/2008/06/09/belgian-terrorists-caught-on-possesion-of-wiping-software/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Physical Access always means p0wned</title>
		<link>http://www.vandeneynde.net/2008/05/26/physical-access-always-means-p0wned/</link>
		<comments>http://www.vandeneynde.net/2008/05/26/physical-access-always-means-p0wned/#comments</comments>
		<pubDate>Mon, 26 May 2008 07:54:16 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://www.vandeneynde.net/?p=57</guid>
		<description><![CDATA[I blogged about it before but every now and then someone finds a new physical &#8216;hack&#8217; into windows. Here is an example of a recent hack using backtrack to gain access.
This just illustrates one of Microsoft&#8217;s 10 Immutable Laws of Security:
Law #3: If a bad guy has unrestricted physical access to your computer, it&#8217;s not [...]]]></description>
			<content:encoded><![CDATA[<p>I <a href="http://www.vandeneynde.net/2008/03/30/using-firewire-to-get-into-a-windows-pc/">blogged about</a> it before but every now and then someone finds a new physical &#8216;hack&#8217; into windows. <a href="http://www.offensive-security.com/movies/vistahack/vistahack.html">Here </a>is an example of a recent hack using backtrack to gain access.</p>
<p>This just illustrates one of<a href="http://www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx?mfr=true"> Microsoft&#8217;s 10 Immutable Laws of Security</a>:</p>
<p>Law #3: If a bad guy has unrestricted physical access to your computer, it&#8217;s not your computer anymore</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vandeneynde.net/2008/05/26/physical-access-always-means-p0wned/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Using firewire to get into a windows PC</title>
		<link>http://www.vandeneynde.net/2008/03/30/using-firewire-to-get-into-a-windows-pc/</link>
		<comments>http://www.vandeneynde.net/2008/03/30/using-firewire-to-get-into-a-windows-pc/#comments</comments>
		<pubDate>Sun, 30 Mar 2008 20:15:31 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://www.vandeneynde.net/2008/03/30/using-firewire-to-get-into-a-windows-pc/</guid>
		<description><![CDATA[As you may know, firewire devices can have access to the main memory of a PC thanks to DMA.
Because of this, firewire can be used as an attack vector against a running PC. This not news. Adam Boileau presented this technique back in 2006 but because of recent news, I decided to give it a [...]]]></description>
			<content:encoded><![CDATA[<p>As you may know, <a href="http://en.wikipedia.org/wiki/Firewire">firewire </a>devices can have access to the main memory of a PC thanks to <a href="http://en.wikipedia.org/wiki/Direct_memory_access">DMA</a>.<br />
Because of this, firewire can be used as an attack vector against a running PC. This not news.<a href="http://www.storm.net.nz/projects/16"> Adam Boileau</a> presented this technique back in 2006 but because of <a href="http://it.slashdot.org/article.pl?sid=08/03/04/1258210">recent</a> <a href="http://security4all.blogspot.com/2008/03/partytricks-winlockpwn-tutorial-or-how.html">news</a>, I decided to give it a go and see for myself how easy it is to exploit this attack vector:<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.youtube.com/v/dFlXKCzpm38&amp;rel=0&amp;hl=en" /><param name="wmode" value="transparent" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://www.youtube.com/v/dFlXKCzpm38&amp;rel=0&amp;hl=en" wmode="transparent"></embed></object><br />
Please note that this can also be used for good! Forensic investigators can use this technique to dump the memory of a running PC for investigation.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vandeneynde.net/2008/03/30/using-firewire-to-get-into-a-windows-pc/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Vista Gadgets</title>
		<link>http://www.vandeneynde.net/2008/01/26/vista-gadgets/</link>
		<comments>http://www.vandeneynde.net/2008/01/26/vista-gadgets/#comments</comments>
		<pubDate>Sat, 26 Jan 2008 13:54:36 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.vandeneynde.net/2008/01/26/vista-gadgets/</guid>
		<description><![CDATA[While I was looking into writing my own gadget for Vista’s Sidebar to display my Google Reader news, it hit me that Gadgets are really simple web browser applications.
They consist of only 1 XML and 1 HTML file in general and can contain JavaScript, vbscript, wmi scripts,… (everything basically). This should make you think because [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal"><span lang="EN-US">While I was looking into writing my own gadget for Vista’s Sidebar to display my Google Reader news, it hit me that Gadgets are really simple web browser applications.<o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">They consist of only 1 XML and 1 HTML file in general and can contain JavaScript, vbscript, wmi scripts,… (everything basically). This should make you think because XSS, XSRF and all kinds of web exploits can potentially work in your sidebar if the right precautions have not been made!<o:p></o:p><br />
</span></p>
<p class="MsoNormal"><span lang="EN-US">Vista’s UAC warns you when you install a gadget or when the gadget isn’t signed but how many users would click yes to install ‘that cool gadget which also happens to contain a little bit of malicious code’? Most likely all of them.</span></p>
<p class="MsoNormal"><span lang="EN-US">There are even more attack vectors for the Vista Gadget API and I found an interesting paper which discusses these and also shows which precautions Microsoft made: <a href="http://www.portcullis-security.com/uplds/Next_Generation_malware.pdf">http://www.portcullis-security.com/uplds/Next_Generation_malware.pdf</a> <o:p></o:p></span></p>
<p class="MsoNormal"><span lang="EN-US">It is not too long and goes not too deep but gives the reader enough info and links to investigate further if wanted. The portcullis-security.com website also has a nice download section which contains a lot of interesting tools.<o:p></o:p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.vandeneynde.net/2008/01/26/vista-gadgets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How NSA access was built into Windows</title>
		<link>http://www.vandeneynde.net/2007/01/15/how-nsa-access-was-built-into-windows/</link>
		<comments>http://www.vandeneynde.net/2007/01/15/how-nsa-access-was-built-into-windows/#comments</comments>
		<pubDate>Sun, 14 Jan 2007 23:26:25 +0000</pubDate>
		<dc:creator>Tom</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.vandeneynde.net/?p=8</guid>
		<description><![CDATA[A friend of mine sent me an email today with a link to an article stating  how NSA access was built into Windows.
Although, it seems that this news is quite old, I only heard from this today. In my opinion, it is very scary that there are master keys for the encryption in Windows. [...]]]></description>
			<content:encoded><![CDATA[<p>A friend of mine sent me an email today with a link to an article stating  <a href="http://www.heise.de/tp/r4/artikel/5/5263/1.html">how NSA access was built into Windows</a>.<br />
Although, it seems that this news is quite old, I only heard from this today. In my opinion, it is very scary that there are master keys for the encryption in Windows. This means that the NSA can look into your encrypted data at any time.</p>
<p>Now, while that may be handy for the NSA, what would happen if a disgruntled employee of the NSA/Microsoft dropped this &#8216;magic&#8217; key on the black market. Suddenly anyone willing to pay for it could decypher your precious encrypted data. Scary stuff.</p>
<p>So, my suggestion is not to use the MS implementation of Encrypted File Systems but go with Open Source solutions like <a href="http://www.truecrypt.org/">TrueCrypt </a>. At least for the OS soft, the code <em>can </em>be reviewed by others.</p>
<p>Tom</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vandeneynde.net/2007/01/15/how-nsa-access-was-built-into-windows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
