<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[SMD] - 8L0G5PH3R3 &#187; Security</title>
	<atom:link href="http://www.sumardi.net/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sumardi.net</link>
	<description>/home/smd/public_html/blog</description>
	<lastBuildDate>Mon, 06 Feb 2012 13:30:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Aircrack fixed channel mon0 : -1</title>
		<link>http://www.sumardi.net/2011/01/10/aircrack-fixed-channel-mon0-1/</link>
		<comments>http://www.sumardi.net/2011/01/10/aircrack-fixed-channel-mon0-1/#comments</comments>
		<pubDate>Sun, 09 Jan 2011 18:01:36 +0000</pubDate>
		<dc:creator>SMD</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.sumardi.net/?p=664</guid>
		<description><![CDATA[Here is the solution (at your own risk). $ sudo apt-get install linux-headers-$(uname -r) $ wget http://wireless.kernel.org/download/compat-wireless-2.6/compat-wireless-2010-12-20.tar.bz2 $ tar -jxf compat-wireless-2010-12-20.tar.bz2 $ cd compat-wireless-2010-12-20 $ wget http://patches.aircrack-ng.org/channel-negative-one-maxim.patch $ sudo apt-get install patch $ patch ./net/wireless/chan.c channel-negative-one-maxim.patch $ make $ sudo make install $ sudo make unload $ sudo reboot]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sumardi.net%2F2011%2F01%2F10%2Faircrack-fixed-channel-mon0-1%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sumardi.net%2F2011%2F01%2F10%2Faircrack-fixed-channel-mon0-1%2F&amp;source=sumardi&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Here is the solution (at your own risk).</p>
<p><code><br />
$ sudo apt-get install linux-headers-$(uname -r)<br />
$ wget http://wireless.kernel.org/download/compat-wireless-2.6/compat-wireless-2010-12-20.tar.bz2<br />
$ tar -jxf compat-wireless-2010-12-20.tar.bz2<br />
$ cd compat-wireless-2010-12-20<br />
$ wget http://patches.aircrack-ng.org/channel-negative-one-maxim.patch<br />
$ sudo apt-get install patch<br />
$ patch ./net/wireless/chan.c channel-negative-one-maxim.patch<br />
$ make<br />
$ sudo make install<br />
$ sudo make unload<br />
$ sudo reboot<br />
</code></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sumardi.net/2011/01/10/aircrack-fixed-channel-mon0-1/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>PHP Security Talk at MyGOSSCON 2010</title>
		<link>http://www.sumardi.net/2010/11/11/php-security-talk-at-mygosscon-2010/</link>
		<comments>http://www.sumardi.net/2010/11/11/php-security-talk-at-mygosscon-2010/#comments</comments>
		<pubDate>Wed, 10 Nov 2010 19:59:20 +0000</pubDate>
		<dc:creator>SMD</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[PHP Programming]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.sumardi.net/?p=644</guid>
		<description><![CDATA[Slide from my recent presentation at MyGOSSCON 2010 PHP Security View more presentations from Sumardi Shukor. A big thank you to those who attended my presentation. Big applause to the organizer.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sumardi.net%2F2010%2F11%2F11%2Fphp-security-talk-at-mygosscon-2010%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sumardi.net%2F2010%2F11%2F11%2Fphp-security-talk-at-mygosscon-2010%2F&amp;source=sumardi&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Slide from my recent presentation at MyGOSSCON 2010</p>
<div style="width:425px" id="__ss_5661948"><strong style="display:block;margin:12px 0 4px"><a href="http://www.slideshare.net/sumardi1/php-security-5661948" title="PHP Security">PHP Security</a></strong><object id="__sse5661948" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=php03security-101103220229-phpapp01&#038;stripped_title=php-security-5661948&#038;userName=sumardi1" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed name="__sse5661948" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=php03security-101103220229-phpapp01&#038;stripped_title=php-security-5661948&#038;userName=sumardi1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object>
<div style="padding:5px 0 12px">View more <a href="http://www.slideshare.net/">presentations</a> from <a href="http://www.slideshare.net/sumardi1">Sumardi Shukor</a>.</div>
</div>
<p>A big thank you to those who attended my presentation. Big applause to the organizer. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.sumardi.net/2010/11/11/php-security-talk-at-mygosscon-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress 2.6.2 Is Available</title>
		<link>http://www.sumardi.net/2008/09/09/wordpress-262-is-available/</link>
		<comments>http://www.sumardi.net/2008/09/09/wordpress-262-is-available/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 04:48:42 +0000</pubDate>
		<dc:creator>SMD</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.sumardi.net/?p=524</guid>
		<description><![CDATA[WordPress has a new release to fix the danger of SQL Column Truncation. It is recommended if you are allow open registration on your blog. This problem is not critical but it is annoying. Upgrade to the latest version is highly recommended.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sumardi.net%2F2008%2F09%2F09%2Fwordpress-262-is-available%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sumardi.net%2F2008%2F09%2F09%2Fwordpress-262-is-available%2F&amp;source=sumardi&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>WordPress has a new release to fix the danger of <a href="http://www.sumardi.net/2008/09/08/wordpress-261-vulnerability-not-critical/">SQL Column Truncation</a>. It is recommended if you are allow open registration on your blog. This problem is not critical but it is annoying. </p>
<p>Upgrade to the latest version is highly recommended.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sumardi.net/2008/09/09/wordpress-262-is-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Your MySQL Installation</title>
		<link>http://www.sumardi.net/2007/06/24/securing-your-mysql-installation/</link>
		<comments>http://www.sumardi.net/2007/06/24/securing-your-mysql-installation/#comments</comments>
		<pubDate>Sun, 24 Jun 2007 12:58:18 +0000</pubDate>
		<dc:creator>SMD</dc:creator>
				<category><![CDATA[Debian]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://www.sumardi.net/2007/06/24/securing-your-mysql-installation/</guid>
		<description><![CDATA[Many distributions of Linux have an option to install MySQL. In this case, or even if you compile MySQL, the default password is blank. Make sure that you set password for the root user. This is the command: mysql -u root mysql SET PASSWORD FOR 'root'@'localhost' = PASSWORD('s3cr3tp4s5w0rd');]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sumardi.net%2F2007%2F06%2F24%2Fsecuring-your-mysql-installation%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sumardi.net%2F2007%2F06%2F24%2Fsecuring-your-mysql-installation%2F&amp;source=sumardi&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Many distributions of Linux have an option to install MySQL. In this case, or even if you compile MySQL, the default password is blank.</p>
<p>Make sure that you set password for the root user. This is the command:</p>
<p><code>mysql -u root mysql<br />
SET PASSWORD FOR 'root'@'localhost' = PASSWORD('s3cr3tp4s5w0rd');</code></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sumardi.net/2007/06/24/securing-your-mysql-installation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Inspekt Build Available</title>
		<link>http://www.sumardi.net/2007/06/07/inspekt-build-available/</link>
		<comments>http://www.sumardi.net/2007/06/07/inspekt-build-available/#comments</comments>
		<pubDate>Thu, 07 Jun 2007 05:37:55 +0000</pubDate>
		<dc:creator>SMD</dc:creator>
				<category><![CDATA[PHP Programming]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.sumardi.net/2007/06/07/inspekt-build-available/</guid>
		<description><![CDATA[Yesteday, I presented a full-day tutorial on SQL Injection &#038; Session Hijacking In PHP Programming which seems to have been well received by those who attended. And today, I would like to present to you a new Inspekt Build available to be downloaded at Google Code. What is Inspekt? Inspekt acts as a sort of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sumardi.net%2F2007%2F06%2F07%2Finspekt-build-available%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sumardi.net%2F2007%2F06%2F07%2Finspekt-build-available%2F&amp;source=sumardi&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Yesteday, I presented a full-day tutorial on <em>SQL Injection &#038; Session Hijacking In PHP Programming</em> which seems to have been well received by those who attended. And today, I would like to present to you a new Inspekt Build available to be downloaded at <a href="http://code.google.com/p/inspekt">Google Code</a>.</p>
<p><strong>What is Inspekt?</strong></p>
<p>Inspekt acts as a sort of &#8216;firewall&#8217; API between user input and the rest of the application. It takes PHP superglobal arrays, encapsulates their data in an &#8220;cage&#8221; object, and destroys the original superglobal. Data can then be retrieved from the input data object using a variety of accessor methods that apply filtering, or the data can be checked against validation methods. Raw data can only be accessed via a &#8216;getRaw()&#8217; method, forcing the developer to show clear intent.<br />
- From Inspekt</p>
<p>It supports PHP4 &#038; PHP5. More info at <a href="http://code.google.com/p/inspekt/">http://code.google.com/p/inspekt/</a></p>
<p>- <a href="http://code.google.com/p/inspekt/wiki/BasicUsage">Sample Basic Usage</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sumardi.net/2007/06/07/inspekt-build-available/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure Your Gmail On A Public Wifi</title>
		<link>http://www.sumardi.net/2007/01/16/secure-your-gmail-on-a-public-wifi/</link>
		<comments>http://www.sumardi.net/2007/01/16/secure-your-gmail-on-a-public-wifi/#comments</comments>
		<pubDate>Tue, 16 Jan 2007 14:13:37 +0000</pubDate>
		<dc:creator>SMD</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.sumardi.net/2007/01/16/secure-your-gmail-on-a-public-wifi/</guid>
		<description><![CDATA[Yes. It&#8217;s True. Public Wifi can be dangerous if you don&#8217;t use it securely. Unsecured connections make it possible for anonymous attacker track your surfing. If you want to use Gmail in a public Wifi : If you go to the default google mail page &#8211; http://gmail.google.com you will be redirected to a secure site [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sumardi.net%2F2007%2F01%2F16%2Fsecure-your-gmail-on-a-public-wifi%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sumardi.net%2F2007%2F01%2F16%2Fsecure-your-gmail-on-a-public-wifi%2F&amp;source=sumardi&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Yes. It&#8217;s True. Public Wifi can be dangerous if you don&#8217;t use it securely. Unsecured connections make it possible for anonymous attacker track your surfing. If you want to use Gmail in a public Wifi :</p>
<blockquote><p>If you go to the default google mail page &#8211; <a onclick="javascript:urchinTracker ('/outbound/article/gmail.google.com');" href="http://gmail.google.com/">http://gmail.google.com</a> you will be redirected to a secure site to log in, but will then be redirected to an unencrypted site for emailing. This makes you a potential risk for anyone who might be eavesdropping on the network.</p>
</blockquote>
<p>via <a href="http://www.friedbeef.com/2007/01/10/how-access-gmail-securely-on-a-public-wifi-network/">FriedBeef</a><br />
Simply type an <em>’s’</em> at the http ID like this: <a onclick="javascript:urchinTracker ('/outbound/article/gmail.google.com');" href="https://gmail.google.com/">https://gmail.google.com</a> (and bookmark the URL) and you will be encrypted with <a onclick="javascript:urchinTracker ('/outbound/article/en.wikipedia.org');" href="http://en.wikipedia.org/wiki/Ssl">SSL</a> throughout your entire email session.</p>
<p>Ok Friends! Be safe.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sumardi.net/2007/01/16/secure-your-gmail-on-a-public-wifi/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

