<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2italianfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Information Security for Geeks</title><link>http://geekinfosecurity.blogspot.com/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/InformationSecurityForGeeks" /><description>Security, Hacking and Cracking</description><language>en</language><managingEditor>noreply@blogger.com (Roberto Scaccia)</managingEditor><lastBuildDate>Tue, 24 Jan 2012 22:48:16 PST</lastBuildDate><generator>Blogger</generator><atom:id xmlns:atom="http://www.w3.org/2005/Atom">tag:blogger.com,1999:blog-1908095138994940398</atom:id><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">440</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/InformationSecurityForGeeks" /><feedburner:info uri="informationsecurityforgeeks" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc-nd/2.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-nd/2.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>InformationSecurityForGeeks</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FInformationSecurityForGeeks" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/InformationSecurityForGeeks" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FInformationSecurityForGeeks" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FInformationSecurityForGeeks" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FInformationSecurityForGeeks" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://add.my.yahoo.com/content?lg=it&amp;url=http%3A%2F%2Ffeeds.feedburner.com%2FInformationSecurityForGeeks" src="http://eur.i1.yimg.com/eur.yimg.com/i/it/my/mioya1.gif">Subscribe with Mio Yahoo!</feedburner:feedFlare><item><title>JBoss Security: slides from OWASP</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/buVWNrFsELs/jboss-security-slides-from-owasp.html</link><category>application security</category><category>owasp</category><category>jboss</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Tue, 24 Jan 2012 22:48:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-4022499579777950628</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-p2H3gqjjvcQ/Tx-lKbnTu-I/AAAAAAAAAtk/XObes-bOWXk/s1600/Jboss-500x321.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="128" src="http://4.bp.blogspot.com/-p2H3gqjjvcQ/Tx-lKbnTu-I/AAAAAAAAAtk/XObes-bOWXk/s200/Jboss-500x321.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;a href="https://www.owasp.org/index.php/File:OWASP3011_Luca.pdf"&gt;Here is&lt;/a&gt; the new OWASP slides on JBoss Security. JBoss is a well known Java Web Application Server used in professional environment. So read it if you have it!&lt;br /&gt;
&lt;br /&gt;
The slides have been done by OWASP members who are very oriented to the Application Security. Well done guys!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-4022499579777950628?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=buVWNrFsELs:cs8E7IcKGxs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=buVWNrFsELs:cs8E7IcKGxs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=buVWNrFsELs:cs8E7IcKGxs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=buVWNrFsELs:cs8E7IcKGxs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/buVWNrFsELs" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2012-01-25T07:48:16.238+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-p2H3gqjjvcQ/Tx-lKbnTu-I/AAAAAAAAAtk/XObes-bOWXk/s72-c/Jboss-500x321.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2012/01/jboss-security-slides-from-owasp.html</feedburner:origLink></item><item><title>Alice &amp; Bob: il dato è sensibile perché ha freddo! Ovvero lo scanner ficcanaso</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/VBJb11IZrqY/alice-bob-il-dato-e-sensibile-perche-ha.html</link><category>scanner</category><category>alice and bob</category><category>privacy</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Thu, 19 Jan 2012 22:21:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-4708180711385981976</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-s5aEJEs1HOA/TxkC1tiad1I/AAAAAAAAAtc/YM6a6xHrnWs/s1600/800px-RICETTA_MEDICA.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://2.bp.blogspot.com/-s5aEJEs1HOA/TxkC1tiad1I/AAAAAAAAAtc/YM6a6xHrnWs/s200/800px-RICETTA_MEDICA.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "Che comodità questa stampante/scanner dipartimentale, mi ricordo che due anni fa avevo sollevato un &lt;a href="http://geekinfosecurity.blogspot.com/2009/06/alice-bob-la-stampante-dipartimentale.html"&gt;polverone incredibile&lt;/a&gt;&amp;nbsp;sulle scannerizzazioni di questi aggeggi. Ti ricordi Alice?"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "Sì sì sempre il solito, ma adesso i file scansionati li cancelliamo! Una volta al mese un complesso script di cancellazione azzera il contenuto della directory! hihihihi (stavolta l'ho fregato)"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "(complesso script...bah!) Una volta al mese? E a che serve? Per liberare spazio immagino..."&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "Beh sì, principalmente. Sai l'occupazione disco è un problema perché potrebbe generare fenomeni di tipo "Denial of Service" e quindi....bla bla...bla bla..."&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "(gli hanno fatto fare il solito corso introduttivo sulla sicurezza informatica e adesso ha bisogno di dimostrare che ci ha capito qualche cosa...)"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "Alice, scusa se interrompo il tuo soliloquio, ma i documenti andrebbero cancellati almeno ogni notte. Non puoi escludere che qualcuno scansioni delle (proprie) informazioni sensibili!"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "Ma dai se scansiona la sua busta paga o l'indirizzo non è un grosso problema"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "(questa è tonta)"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Bob: "Forse non mi sono spiegato, "Dato sensibile" secondo la definizione del "Codice per la tutela della Privacy". Quindi:&amp;nbsp;&lt;a href="http://it.wikipedia.org/wiki/Dati_sensibili"&gt;"...dati personali idonei a rivelare: l'origine razziale ed etnica, le convinzioni religiose, filosofiche o di altro genere, le opinioni politiche, l'adesione a partiti, sindacati, associazioni od organizzazioni a carattere religioso, filosofico, politico o sindacale, lo stato di salute e la vita sessuale"&lt;/a&gt;..."&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "E quindi?"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "(niente, non ci arriva proprio, facciamo finta che abbia 5 anni...)"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "Mettiamo il caso che tu scansioni una ricetta medica o un qualche cosa legato al tuo stato di salute. Tale documento rimane in formato elettronico nella memoria della stampante/scanner dipartimentale. Tu dovresti cancellarlo, ma ti scordi. Abbastanza comune tra gli utenti no?&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ora, poiché questa memoria è accessibile ad un insieme di persone che non comprende solo te, altri potrebbero &amp;nbsp;visualizzare tale documento e, in via ipotetica, iniziare pratiche discriminatorie nei tuoi confronti per le tue condizioni di salute. Discriminazione che potrebbe anche portare a fenomeni quali mobbing, licenziamento, o peggio, pratiche ricattatorie di vario tipo"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "?????!!!!????"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "Ma io sto bene di salute!"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "(non ci arrivi proprio eh!) Ok cancellate i documenti una volta al mese e buona fortuna!"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="color: #0b5394;"&gt;&lt;b&gt;Alice&lt;/b&gt;&lt;/span&gt;: "(sempre il solito rompiscatole...)"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Bob&lt;/b&gt;: "La solita idiota"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
P.S. (n.d.r.) il fatto che Alice sia di evidente sesso femminile non ha alcun legame con il suo ruolo in questi dialoghi (ruolo evidentemente non di spessore). Quindi non c'è alcun intento discriminatorio del sesso femminile.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-4708180711385981976?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=VBJb11IZrqY:GRTpoJNCHmU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=VBJb11IZrqY:GRTpoJNCHmU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=VBJb11IZrqY:GRTpoJNCHmU:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=VBJb11IZrqY:GRTpoJNCHmU:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/VBJb11IZrqY" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2012-01-20T07:21:06.603+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-s5aEJEs1HOA/TxkC1tiad1I/AAAAAAAAAtc/YM6a6xHrnWs/s72-c/800px-RICETTA_MEDICA.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2012/01/alice-bob-il-dato-e-sensibile-perche-ha.html</feedburner:origLink></item><item><title>Google: meglio saperlo!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/3QkfG8c-QlY/google-meglio-saperlo.html</link><category>sicurezza</category><category>authentication</category><category>google</category><category>privacy</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Wed, 18 Jan 2012 22:53:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-774962495681866830</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
Interessante piattaforma web di Google (&lt;a href="http://www.google.com/goodtoknow/"&gt;Google Goodtoknow&lt;/a&gt;) per l'educazione degli utenti alla sicurezza e privacy. Come sempre informazione chiara, semplice e fruibile da (quasi) tutti. Il sito è ovviamente in inglese e anche i video.&lt;/div&gt;
&lt;br /&gt;
Quattro le sezioni principali:&lt;br /&gt;
&lt;ol style="text-align: left;"&gt;
&lt;li&gt;Sicuri on-line&lt;/li&gt;
&lt;li&gt;I tuoi dati sul Web&lt;/li&gt;
&lt;li&gt;I tuoi dati su Google&lt;/li&gt;
&lt;li&gt;Gestisci i tuoi dati&lt;/li&gt;
&lt;/ol&gt;
In ognuna di esse è presente un video principale molto ben fatto (e corto!). Poi, nelle diverse sottosezioni, altri video e ulteriori informazioni. Interessante il sito&amp;nbsp;&lt;a href="http://www.dataliberation.org/home"&gt;http://www.dataliberation.org/home&lt;/a&gt;&amp;nbsp;che permette di "liberare" i propri dati dai servizi Google. Intendiamoci: è fatto da Google stessa!&lt;br /&gt;
&lt;br /&gt;
Ecco alcuni video:&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;
&lt;span class="Apple-style-span" style="font-size: large;"&gt;Sicuri on-line&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/nOgsXdB67Pc/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/nOgsXdB67Pc&amp;fs=1&amp;source=uds" /&gt;




&lt;param name="bgcolor" value="#FFFFFF" /&gt;




&lt;embed width="320" height="266"  src="http://www.youtube.com/v/nOgsXdB67Pc&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
(guardate il video qui sopra ci sono anche indicazioni su come aumentare il livello di sicurezza con i servizi Google, non pensiate di sapere tutto!)&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;span class="Apple-style-span" style="font-size: large;"&gt;Cosa sono i Cookie&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/TBR-xtJVq7E/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/TBR-xtJVq7E&amp;fs=1&amp;source=uds" /&gt;




&lt;param name="bgcolor" value="#FFFFFF" /&gt;




&lt;embed width="320" height="266"  src="http://www.youtube.com/v/TBR-xtJVq7E&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;/div&gt;
&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;
&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; text-align: center;"&gt;
&lt;span class="Apple-style-span" style="font-size: large;"&gt;Privacy &amp;amp; Google&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/7oe6pdQvyAc/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/7oe6pdQvyAc&amp;fs=1&amp;source=uds" /&gt;




&lt;param name="bgcolor" value="#FFFFFF" /&gt;




&lt;embed width="320" height="266"  src="http://www.youtube.com/v/7oe6pdQvyAc&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-774962495681866830?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=3QkfG8c-QlY:PNuHlumyYOI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=3QkfG8c-QlY:PNuHlumyYOI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=3QkfG8c-QlY:PNuHlumyYOI:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=3QkfG8c-QlY:PNuHlumyYOI:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/3QkfG8c-QlY" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2012-01-19T07:13:19.264+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2012/01/google-meglio-saperlo.html</feedburner:origLink></item><item><title>Contro la censura (SOPA)!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/TuMJMZhAeWs/contro-la-censura-sopa.html</link><category>censura</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Tue, 17 Jan 2012 23:12:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-6451560739834664918</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;span id="goog_345213902"&gt;&lt;/span&gt;&lt;img border="0" height="160" src="http://sopastrike.com/strike/strike-paper-new.jpg" width="400" /&gt;&lt;span id="goog_345213903"&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://sopastrike.com/strike/"&gt;http://sopastrike.com/strike/&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
---- UPDATE ----&lt;br /&gt;
&lt;br /&gt;
Sembra che la diffusa protesta mondiale stia facendo ritornare sui loro passi gli estensori della legge. Internet Power!&lt;br /&gt;
&lt;br /&gt;
Qui &lt;a href="http://attivissimo.blogspot.com/2012/01/24-di-oscuramento-di-wikipedia-e-altri.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+Disinformatico+%28Il+Disinformatico%29"&gt;una esauriente spiegazione del bravissimo Paolo Attivissimo&lt;/a&gt; del perché questa protesta ha avuto e ha un senso.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-6451560739834664918?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=TuMJMZhAeWs:GERthLtdbUs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=TuMJMZhAeWs:GERthLtdbUs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=TuMJMZhAeWs:GERthLtdbUs:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=TuMJMZhAeWs:GERthLtdbUs:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/TuMJMZhAeWs" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2012-01-19T07:18:48.419+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2012/01/contro-la-censura-sopa.html</feedburner:origLink></item><item><title>OpenSSL Multiple Vulnerabilities</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/7-UdhG0-R0o/openssl-multiple-vulnerabilities.html</link><category>vulnerabilità</category><category>ssl</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Mon, 09 Jan 2012 23:07:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-2268835367417985027</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Doveroso rimbalzare la &lt;a href="http://www.securityfocus.com/bid/51281/info"&gt;notizia&lt;/a&gt;. Vista la pervasività di OpenSSL sui sistemi *nix, forse è il caso di fare un update no?&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-2268835367417985027?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=7-UdhG0-R0o:djSH2pq482I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=7-UdhG0-R0o:djSH2pq482I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=7-UdhG0-R0o:djSH2pq482I:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=7-UdhG0-R0o:djSH2pq482I:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/7-UdhG0-R0o" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2012-01-18T07:55:37.028+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2012/01/openssl-multiple-vulnerabilities.html</feedburner:origLink></item><item><title>Hash Table, Collisioni e attacchi (D)DoS</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/8oQj33GorIw/hash-table-collisioni-e-attacchi-ddos.html</link><category>DDoS</category><category>vulnerabilità</category><category>software security</category><category>0-day</category><category>DoS</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Tue, 03 Jan 2012 08:22:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-3117289849293766022</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-9XbHeVTbanE/TwK5e3RaYLI/AAAAAAAAAtU/Saz7z6z1YKI/s1600/HASHTB08.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="112" src="http://1.bp.blogspot.com/-9XbHeVTbanE/TwK5e3RaYLI/AAAAAAAAAtU/Saz7z6z1YKI/s200/HASHTB08.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Rischia di passare sotto silenzio questa &lt;a href="http://www.kb.cert.org/vuls/id/903934"&gt;vulnerabilità&lt;/a&gt; incredibilmente longeva e, almeno dalle prime valutazioni, assai pericolosa.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Pericolosa, perché con delle semplici REQUEST POST si riesce a provocare un consumo di CPU del 100%, per un tempo che può arrivare anche a delle ore. Quindi DoS o peggio DDoS.&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Pericolosa, perché non è relativa a questa o quella piattaforma, ma a come i diversi linguaggi implementano la funzione di hashing per &amp;nbsp;la gestione delle strutture dati chiamate "Hash Table" (da non confondere con gli &lt;a href="http://it.wikipedia.org/wiki/Hash#Hash_e_crittografia"&gt;hash crittografici&lt;/a&gt; che, sebbene siano pur sempre degli hash, hanno altre finalità e caratteristiche).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Longeva, perché il primo lavoro su di essa fu presentato nel &lt;a href="http://www.cs.rice.edu/~scrosby/hash/CrosbyWallach_UsenixSec2003.pdf"&gt;2003 in una conferenza USENIX&lt;/a&gt; e solo oggi, dopo la &lt;a href="http://events.ccc.de/congress/2011/Fahrplan/events/4661.en.html"&gt;presentazione al CCC&lt;/a&gt; (congresso del Chaos Computer Club), ci si è forse resi conto dell'impatto che può avere un attacco che sfrutta tale vulnerabilità.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La sostanza: &lt;b&gt;inserire nelle hash table dei nuovi valori che generano collisioni con un degradamento "quadratico" del tempo di computazione&lt;/b&gt;.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Le &lt;a href="http://it.wikipedia.org/wiki/Hash_table"&gt;hash table&lt;/a&gt; vengono utilizzate normalmente in tutti i linguaggi per realizzare i cosiddetti "array associativi", ovvero array che indicizzano i valori contenuti attraverso delle chiavi alfanumeriche:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;arrayAssoc["pippo"] = "paperino";&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;print&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;arrayAssoc&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;["pippo"] ==&amp;gt; "paperino"&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;div style="text-align: justify;"&gt;
Il principio su cui si basano le hash table è semplice: calcolare una funzione H(x) (dove H sta per Hash e x è la chiave), la quale restituisce un intero che è l'indice dell'array sottostante:&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;H("pippo") = 3&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-style-span" style="font-family: 'Courier New', Courier, monospace;"&gt;array[H("pippo)] = array[3] = "paperino"&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Tendenzialmente la funzione H presenta delle collisioni, ossia a chiavi diverse corrisponde lo stesso indice numerico ed in questo caso i valori sono organizzati in una lista collegata all'indice stesso. Nel caso di collisioni, la lista viene scorsa ad ogni inserimento.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
E' questo il punto "debole" dell'algoritmo, perché&amp;nbsp;l'inserimento di n elementi costa nel caso medio O(n), ovvero O(1) per ogni elemento inserito (tempo costante per ogni inserimento). Nel caso peggiore invece, diventa O(n^2), perché ogni elemento inserito ha la stessa chiave e quindi bisogna scansionare la linked-list del bucket corrispondente.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Quindi, per ritornare al dominio dei Web App Server, inviare dei POST che generano collisioni nelle hash table, implica in alcuni casi un tempo O(n^2), ovvero un carico della CPU fuori della norma.&lt;/div&gt;
&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Non c'è però da demonizzare le funzioni hash perché, se usate in un contesto chiuso, ovvero in un'applicazione client, questa "caratteristica" non crea grossi problemi ma solo inefficienze che possono essere anche accettate. Quando invece vengono utilizzate da codice Web che processa POST data, allora l'impatto dell'attacco è di una magnitudo superiore.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La vulnerabilità è assai pervasiva, perché di fatto quasi tutti i linguaggi hanno delle implementazioni non sicure di tale funzione: PHP, ASP.NET (e quindi C#, VB.NET, etc.), Java (Tomcat, JBoss, GlassFish), Ruby e Perl (ma sembra che questi abbiano già provveduto...), etc.&amp;nbsp;O meglio, quasi tutti i Web Application Server basati su questi linguaggi!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Cosa fare?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Aspettare il rilascio della nuova versione del linguaggio di programmazione o dell'ambiente non è forse la cosa migliore nel breve periodo. &lt;b&gt;Gli stessi autori dello speech al CCC suggeriscono di limitare il POST size e il numero dei parametri POST nei Web App Server come workaround&lt;/b&gt;.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Nel lungo periodo, non "scordarsi" di aggiornare i Web App Server. Ma questo vale un po' per tutto! :)&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ecco il video della presentazione al CCC:&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/R2Cq3CLI6H8/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/R2Cq3CLI6H8&amp;fs=1&amp;source=uds" /&gt;
&lt;param name="bgcolor" value="#FFFFFF" /&gt;
&lt;embed width="320" height="266"  src="http://www.youtube.com/v/R2Cq3CLI6H8&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Se non avete un'ora a disposizione, fate prima a guardarvi le slide in formato PDF &lt;a href="http://events.ccc.de/congress/2011/Fahrplan/attachments/2007_28C3_Effective_DoS_on_web_application_platforms.pdf"&gt;scaricabili qui&lt;/a&gt;. Sono ben fatte e si capiscono!&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-3117289849293766022?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=8oQj33GorIw:jCSK611RSP8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=8oQj33GorIw:jCSK611RSP8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=8oQj33GorIw:jCSK611RSP8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=8oQj33GorIw:jCSK611RSP8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/8oQj33GorIw" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2012-01-03T17:22:47.041+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-9XbHeVTbanE/TwK5e3RaYLI/AAAAAAAAAtU/Saz7z6z1YKI/s72-c/HASHTB08.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2012/01/hash-table-collisioni-e-attacchi-ddos.html</feedburner:origLink></item><item><title>Qualitapa.gov.it e Rainews24.rai.it hackerati: credenziali pubblicate. Controllate please!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/J04vJqnVu5U/qualitapagovit-e-rainews24raiit.html</link><category>password</category><category>pastebin</category><category>data breach</category><category>hacking</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Fri, 30 Dec 2011 23:02:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-6843987339354443253</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://2.bp.blogspot.com/-Is4bfsfe-So/Tv6x9r-bdbI/AAAAAAAAAtI/CoLpQjPFpGE/s1600/Schermata+12-2455927+alle+07.55.01.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-Is4bfsfe-So/Tv6x9r-bdbI/AAAAAAAAAtI/CoLpQjPFpGE/s1600/Schermata+12-2455927+alle+07.55.01.png" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
I siti "&lt;a href="http://pastebin.com/NUNn4vGT"&gt;qualitapa.gov.it&lt;/a&gt;" e "&lt;a href="http://pastebin.com/h8bA3P0Q"&gt;rainews24.rai.it&lt;/a&gt;" sono stati hackerati, e le credenziali di accesso ad essi pubblicate su pastebin.com!&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Scorrendo la lista di credenziali, salta all'occhio che per la maggior parte di esse le password associate sono, molto probabilmente, quelle assegnate dalla piattaforma. Ma per alcune utenze invece la password è stata cambiata dagli stessi utenti.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ottimo, se non fosse che spesso gli utenti riutilizzano le stesse password per accessi ad altri siti (tipo la posta elettronica...). Ovviamente in questi casi a rischio non c'è solo l'accesso alla piattaforma hackerata ma anche i diversi servizi acceduti dall'utente. Con un po' di prove e conoscendo email e password si possono guadagnare accessi sempre crescenti. E se poi si riesce ad avere accesso alla casella di posta elettronica...&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Controllate quindi se siete nelle liste, o se ci sono persone che conoscete, ed avvisatele. E comunque anche se la password è quella di default, cambiatela!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Però una riflessione è d'obbligo: ancora con le password storate nei DB? Ma basta! Nel DB ci vanno solo gli Hash crittografici delle password e non le password (anche se cifrate).&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-6843987339354443253?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=J04vJqnVu5U:28jTaBewUlE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=J04vJqnVu5U:28jTaBewUlE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=J04vJqnVu5U:28jTaBewUlE:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=J04vJqnVu5U:28jTaBewUlE:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/J04vJqnVu5U" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-12-31T08:02:20.257+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-Is4bfsfe-So/Tv6x9r-bdbI/AAAAAAAAAtI/CoLpQjPFpGE/s72-c/Schermata+12-2455927+alle+07.55.01.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/12/qualitapagovit-e-rainews24raiit.html</feedburner:origLink></item><item><title>Ci voleva il Natale! Podcast video Defcon 19</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/HQlOrq5S4EQ/ci-voleva-il-natale-podcast-video.html</link><category>defcon</category><category>podcast</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Fri, 30 Dec 2011 00:17:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-725015431740637542</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
Ci voleva Babbo Natale per convincere quelli del Defcon 19 a rilasciare un bel &lt;a href="https://www.defcon.org/podcast/defcon-19-video.rss"&gt;podcast&lt;/a&gt;. Finalmente dico io! Almeno potremo farci gli affari loro e passare queste feste allenando la mente, oltre che lo stomaco. Lasciate il panettone e buttatevi quindi sul podcast.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Su iTunes è molto semplice aggiungere il podcast (https://www.defcon.org/podcast/defcon-19-video.rss) altrimenti usate quello che vi pare eh!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Buon (passato) Natale&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-725015431740637542?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=HQlOrq5S4EQ:Xuj_wq5mxS8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=HQlOrq5S4EQ:Xuj_wq5mxS8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=HQlOrq5S4EQ:Xuj_wq5mxS8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=HQlOrq5S4EQ:Xuj_wq5mxS8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/HQlOrq5S4EQ" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-12-30T09:17:26.509+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/12/ci-voleva-il-natale-podcast-video.html</feedburner:origLink></item><item><title>Attenti a quel gioco sul market Android: è un malware</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/YKMGhPdDhnM/attenti-quel-gioco-sul-market-android-e.html</link><category>malware</category><category>market</category><category>android</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Sat, 24 Dec 2011 22:48:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-5312750983422345214</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
&lt;a href="http://www.f-secure.com/weblog/archives/00002286.html"&gt;F-Secure segnala&lt;/a&gt; una pratica molto pericolosa: &lt;b&gt;la pubblicazioni nei market di giochi che hanno un nome simile alla versione ufficiale e che invece sono dei malware&lt;/b&gt;. Un esempio per tutti è "Cut the Rope", che nella sua versione originale è a pagamento, mentre il malware ha come nome "Cut the Rope FREE" ed è appunto gratis. Stessa cosa per giochi come "Angry Birds Seasons FREE", etc.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Credo che il problema sussista principalmente nel market Android (vista la politica più restrittiva di Apple) ma bisogna sempre stare attenti, perché anche alla Mela potrebbe sfuggire qualche app maliziosa.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Un suggerimento utile è ovviamente quello di controllare il nome degli autori della app sia nella versione a pagamento che in quella free. Se coincidono allora non ci sono problemi (ma attenti a nomi leggermente diversi eh!).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Questa immagine è abbastanza esplicativa:&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: center;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-gXo0Snv0YIM/TvgcKi7VBBI/AAAAAAAAAs8/eHw1GDjzEkc/s1600/EldarLimitedAndroidMarket.PNG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://4.bp.blogspot.com/-gXo0Snv0YIM/TvgcKi7VBBI/AAAAAAAAAs8/eHw1GDjzEkc/s320/EldarLimitedAndroidMarket.PNG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Come vedete compare il FREE che invoglia l'ignaro utente a scaricare il gioco-malware.&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-5312750983422345214?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=YKMGhPdDhnM:nMBkt_9AuH8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=YKMGhPdDhnM:nMBkt_9AuH8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=YKMGhPdDhnM:nMBkt_9AuH8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=YKMGhPdDhnM:nMBkt_9AuH8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/YKMGhPdDhnM" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-12-26T08:03:33.465+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-gXo0Snv0YIM/TvgcKi7VBBI/AAAAAAAAAs8/eHw1GDjzEkc/s72-c/EldarLimitedAndroidMarket.PNG" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/12/attenti-quel-gioco-sul-market-android-e.html</feedburner:origLink></item><item><title>Quante cose si possono fare con una lattina!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/t9jrnKy20mw/quante-cose-si-possono-fare-con-una.html</link><category>lockpicking</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Sat, 24 Dec 2011 00:06:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-5338318742770091482</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
Ci saranno un milione di video sul &lt;a href="http://en.wikipedia.org/wiki/Lock_picking"&gt;lockpicking&lt;/a&gt;, però è sempre sorprendente vedere come ci possono fregare! Per non dover sentir dire più "Accidenti non sapevo ci mettessero così poco".&lt;/div&gt;
&lt;br /&gt;
Quindi sorprendetevi!&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/fRjNnnLOpmE/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/fRjNnnLOpmE&amp;fs=1&amp;source=uds" /&gt;
&lt;param name="bgcolor" value="#FFFFFF" /&gt;
&lt;embed width="320" height="266"  src="http://www.youtube.com/v/fRjNnnLOpmE&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
(&lt;a href="http://www.itstactical.com/skillcom/lock-picking/how-to-open-a-padlock-with-a-coke-can/"&gt;link&lt;/a&gt;)&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-5338318742770091482?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=t9jrnKy20mw:wBT3dOztsfk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=t9jrnKy20mw:wBT3dOztsfk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=t9jrnKy20mw:wBT3dOztsfk:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=t9jrnKy20mw:wBT3dOztsfk:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/t9jrnKy20mw" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-12-24T09:06:38.854+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/12/quante-cose-si-possono-fare-con-una.html</feedburner:origLink></item><item><title>Cloud: un pericolo o un'opportunità? sfatiamo il mito...</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/ECOWwPWquV4/cloud-un-pericolo-o-unopportunita.html</link><category>cloud security</category><category>sicurezza</category><category>privacy</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Mon, 21 Nov 2011 22:17:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-4020147309309512398</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-ZfEijhQzKbw/TtHho0GDtTI/AAAAAAAAAsw/3q1hkbFzGNQ/s1600/cloud.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="171" src="http://4.bp.blogspot.com/-ZfEijhQzKbw/TtHho0GDtTI/AAAAAAAAAsw/3q1hkbFzGNQ/s200/cloud.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
"Cloud": credo non ci sia termine più abusato negli ultimi tempi.&amp;nbsp;Ma poi cosa sarà mai questo benedetto Cloud?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Non è altro che la possibilità di avere i nostri documenti, applicazioni, backup, immagini, foto, etc. sempre disponibili in Internet. Dove? Non lo saprete ed ecco perché il termine "cloud" ovvero "nuvola".&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Iniziamo con lo sfatare qualche mito: non c'è bisogno di aderire ai servizi Cloud di Amazon per essere nel Cloud! Se utilizzate un qualsiasi servizio di Google (mail, picasa, docs) o il vostro iPhone o Android, siete di fatto già nel Cloud! Per non parlare di Facebook: cosa c'è di più importante delle vostre abitudini, contatti, messaggi personali, geolocalizzazione?&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
E bisogna ammettere che questo "Cloud" è davvero molto comodo. Alcuni esempi:&lt;/div&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li style="text-align: justify;"&gt;il backup del vostro iPhone lo potete recuperare direttamente da iCloud nell'Apple Store, magari dopo un cambio del melafonino;&amp;nbsp;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;tenere il documento con le spese familiari su docs.google.com;&amp;nbsp;&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;le app di Android e iPhone sempre disponibili (con i relativi dati)&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;l'impareggiabile DropBox!&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;i contatti, l'agenda e le mail disponibili sempre e ovunque&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;....&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
E questo è solo un piccolo esempio per l'utenza consumer.&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Se consideriamo invece l'utenza "business" il Cloud è un'opportunità imperdibile. Non si ha più bisogno di comprare infrastruttura per attività spot, perché possiamo utilizzare l'infrastruttura del Cloud per storage o potenza di calcolo "on demand".&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Le oscure sigle IAAS (Infrastructure as a service), PAAS (Platform as a Service) o SAAS (Software as a Service) sono unicamente la specificazione del livello del cloud: rispettivamente se utilizzate l'infrastruttura (storage o potenza di calcolo), la piattaforma (l'ambiente d sviluppo per es.), o il software (i backup iCloud, le App sempre disponibili, i documenti, la rubrica, etc.).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ma la sostanza è sempre la stessa: &lt;b&gt;servizi e dati in rete, non precisamente localizzati, sempre disponibili&lt;/b&gt;.&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Ma c'è ovviamente il rovescio della medaglia: la sicurezza dei dati e la privacy. Mentre per l'aspetto sicurezza dovrete ovviamente affidarvi (e fidarvi) del provider che fornisce il servizio nel Cloud (Amazon, Google, etc.), che si spera abbia un buon livello di sicurezza, per gli aspetti legati alla privacy son dolori!&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Eh sì, perché se da una parte è vero che la vostra privacy è legata in modo imprescindibile alla sicurezza del Cloud, dall'altra è anche vero che a fronte di un qualsiasi incidente di privacy gli aspetti legali saranno un vero incubo. Quale legislazione bisogna considerare? Dove sono i miei dati? Quali sono le procedure per richiedere i tracciati di uso?&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Tutti aspetti contrattuali, e quindi legali, che richiedono una conoscenza approfondita del fenomeno, dei legali preparati (e lo sono in pochi) e dei periti anch'essi preparati nel contesto specifico. Da non sottovalutare anche l'aspetto economico: probabilmente dovrete instaurare rapporti con altri paesi e venire a capo della matassa che si srotola dal nostro bel paese fino a...dove?&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Insomma, come detto, un vero incubo!&amp;nbsp;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Però è anche vero che se non siete per esempio una grossa azienda con segreti industriali o un PA, ma bensì dei semplici utenti che già usano gmail, perché preoccuparsi? Siete già nel Cloud e tutti i vostri dati sono già nell'accogliente grembo di mamma Google (e probabilmente dell'NSA).&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
Ricordate sempre che sulla bilancia ci sono usabilità e sicurezza. Volete maggiore sicurezza? Perderete qualche comodità. Volete maggiore comodità? Dovrete rinunciare a un po' di sicurezza.&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div style="text-align: justify;"&gt;
C'est la vie! Nel Cloud.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Qualche video:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://0.gvt0.com/vi/QJncFirhjPg/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/QJncFirhjPg&amp;fs=1&amp;source=uds" /&gt;
&lt;param name="bgcolor" value="#FFFFFF" /&gt;
&lt;embed width="320" height="266"  src="http://www.youtube.com/v/QJncFirhjPg&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
(questo è un po' "pettinato" ma rende l'idea sui vantaggi)&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://3.gvt0.com/vi/h9SB4gDsO_c/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/h9SB4gDsO_c&amp;fs=1&amp;source=uds" /&gt;
&lt;param name="bgcolor" value="#FFFFFF" /&gt;
&lt;embed width="320" height="266"  src="http://www.youtube.com/v/h9SB4gDsO_c&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
(questo invece è da vedere assolutamente: analisi molto lucida di pregi e difetti del Cloud)&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-4020147309309512398?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=ECOWwPWquV4:lnXCEf8rLl8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=ECOWwPWquV4:lnXCEf8rLl8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ECOWwPWquV4:lnXCEf8rLl8:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=ECOWwPWquV4:lnXCEf8rLl8:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/ECOWwPWquV4" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-11-27T08:36:14.549+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-ZfEijhQzKbw/TtHho0GDtTI/AAAAAAAAAsw/3q1hkbFzGNQ/s72-c/cloud.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/11/cloud-un-pericolo-o-unopportunita.html</feedburner:origLink></item><item><title>E' nato! Duqu figlio di Stuxnet</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/6T6FkJDBLcc/e-nato-duqu-figlio-di-stuxnet.html</link><category>video</category><category>stuxnet</category><category>virus</category><category>worm</category><category>duqu</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Sat, 22 Oct 2011 23:23:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-2701665158586474533</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-1HbDiOniDZo/TqOxaV4E5wI/AAAAAAAAAsg/ZdYDgxkFCzw/s1600/febbre-da-cavallo-locandina1.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="150" src="http://3.bp.blogspot.com/-1HbDiOniDZo/TqOxaV4E5wI/AAAAAAAAAsg/ZdYDgxkFCzw/s200/febbre-da-cavallo-locandina1.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
Gira da un po' la notizia e quindi è meglio rilanciarla che stare zitti.&lt;br /&gt;
&lt;br /&gt;
Pare che &lt;b&gt;Duqu&lt;/b&gt; sia figlio di Stuxnet (&lt;a href="http://youtu.be/DR8DWCBsqws"&gt;sembra Febbre da Cavallo&lt;/a&gt;). Ma non ha le finalità distruttive del "padre". Del resto le nuove generazioni sono miti in tutto.&lt;br /&gt;
&lt;br /&gt;
Pare che il suo unico scopo sia quello di farsi gli affari nostri, probabilmente per un successivo e più distruttivo attacco. Per una descrizione sommaria il sito di &lt;a href="http://www.f-secure.com/v-descs/backdoor_w32_duqu.shtml"&gt;F-Secure&lt;/a&gt;, altrimenti il &lt;a href="http://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/w32_duqu_the_precursor_to_the_next_stuxnet.pdf"&gt;PDF "monumentale" di Symantec&lt;/a&gt; (fatto molto bene).&lt;br /&gt;
&lt;br /&gt;
Da tenere d'occhio!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-2701665158586474533?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=6T6FkJDBLcc:Ip6m7RKpEN4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=6T6FkJDBLcc:Ip6m7RKpEN4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6T6FkJDBLcc:Ip6m7RKpEN4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=6T6FkJDBLcc:Ip6m7RKpEN4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/6T6FkJDBLcc" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-10-23T08:23:21.343+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-1HbDiOniDZo/TqOxaV4E5wI/AAAAAAAAAsg/ZdYDgxkFCzw/s72-c/febbre-da-cavallo-locandina1.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/10/e-nato-duqu-figlio-di-stuxnet.html</feedburner:origLink></item><item><title>Sicurezza Fisica? Google (e Batman) insegna!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/hSz_Gm0Vk7Y/sicurezza-fisica-google-e-batman.html</link><category>google</category><category>sicurezza fisica</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Tue, 18 Oct 2011 23:13:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-2704289012954586588</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-kklyMNyqTLE/Tp5qJW2uhuI/AAAAAAAAAsY/WaQpG-5MxpE/s1600/batman-nb3631.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-kklyMNyqTLE/Tp5qJW2uhuI/AAAAAAAAAsY/WaQpG-5MxpE/s200/batman-nb3631.jpg" width="143" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Dovete fare un capitolato d'appalto per la sicurezza fisica della vostra azienda o dell'ente in cui lavorate? Guardate prima questo video :-)&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
C'è praticamente tutto, anche i soldi (una montagna) che Google ha. Altrimenti chiamate Batman e vedete se vi fa dei prezzi vantaggiosi.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Da notare il processo di distruzione dei dischi rigidi, il riconoscimento biometrico a più livelli e la costante presenza di "umani" (perché qualcuno pensa che i controlli di sicurezza fisica elminino il fattore umano....poveretto).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Mi viene da ridere pensando a certe soluzioni nostrane con strane porte "bus-like", operatori distratti e riconoscimenti facciali alquanto discutibili...ma questa è un'altra storia!&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://2.gvt0.com/vi/1SCZzgfdTBo/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/1SCZzgfdTBo&amp;fs=1&amp;source=uds" /&gt;
&lt;param name="bgcolor" value="#FFFFFF" /&gt;
&lt;embed width="320" height="266"  src="http://www.youtube.com/v/1SCZzgfdTBo&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-2704289012954586588?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=hSz_Gm0Vk7Y:ZPt-Yzqrmog:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=hSz_Gm0Vk7Y:ZPt-Yzqrmog:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hSz_Gm0Vk7Y:ZPt-Yzqrmog:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=hSz_Gm0Vk7Y:ZPt-Yzqrmog:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/hSz_Gm0Vk7Y" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-10-19T08:13:33.431+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-kklyMNyqTLE/Tp5qJW2uhuI/AAAAAAAAAsY/WaQpG-5MxpE/s72-c/batman-nb3631.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/10/sicurezza-fisica-google-e-batman.html</feedburner:origLink></item><item><title>Defcon 19: disponibile il DVD...gratis!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/sYmjH7_3OOc/defcon-19-disponibile-il-dvdgratis.html</link><category>hacker</category><category>defcon</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Tue, 18 Oct 2011 22:25:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-4072282610561455992</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Scaricate il DVD dell'ultimo Defcon con le slide degli interventi e qualche altra cosa:&amp;nbsp;&lt;a href="https://www.defcon.org/index.html#dc19dvd"&gt;https://www.defcon.org/index.html#dc19dvd&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Vederli su Internet avrà anche il suo fascino ma se ce li avete belli e pronti è meglio no? ;-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-4072282610561455992?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=sYmjH7_3OOc:pF-15nxrfRk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=sYmjH7_3OOc:pF-15nxrfRk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=sYmjH7_3OOc:pF-15nxrfRk:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=sYmjH7_3OOc:pF-15nxrfRk:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/sYmjH7_3OOc" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-10-19T07:25:16.000+02:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/10/defcon-19-disponibile-il-dvdgratis.html</feedburner:origLink></item><item><title>Steve Jobs è morto: viva il Re</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/6KXPUEr1Zyw/steve-jobs-e-morto-viva-il-re.html</link><category>apple</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Wed, 05 Oct 2011 21:58:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-3789546457817110477</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
Si può pensar bene o male di lui, dei suoi prodotti, della sua vita, delle sue scelte, ma resta il fatto che è stato un visionario che ha contribuito in modo decisivo al futuro tecnologico di tutti noi.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: center;"&gt;
"Stay hungry. Stay foolish"&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/nFKY8CVwOaU/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/nFKY8CVwOaU&amp;fs=1&amp;source=uds" /&gt;



&lt;param name="bgcolor" value="#FFFFFF" /&gt;



&lt;embed width="320" height="266"  src="http://www.youtube.com/v/nFKY8CVwOaU&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://1.gvt0.com/vi/G3bCOLl_1NE/0.jpg" height="266" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/G3bCOLl_1NE&amp;fs=1&amp;source=uds" /&gt;

&lt;param name="bgcolor" value="#FFFFFF" /&gt;

&lt;embed width="320" height="266"  src="http://www.youtube.com/v/G3bCOLl_1NE&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
Ciao Steve e grazie.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-3789546457817110477?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=6KXPUEr1Zyw:vAuLTZzxckA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=6KXPUEr1Zyw:vAuLTZzxckA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=6KXPUEr1Zyw:vAuLTZzxckA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=6KXPUEr1Zyw:vAuLTZzxckA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/6KXPUEr1Zyw" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-10-13T07:17:23.738+02:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/10/steve-jobs-e-morto-viva-il-re.html</feedburner:origLink></item><item><title>Quando l'usabilità si coniuga con la sicurezza</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/_ypYvvRgBEc/quando-lusabilita-si-coniuga-con-la.html</link><category>timemachine</category><category>restore</category><category>backup</category><category>Lion</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Mon, 19 Sep 2011 09:29:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-7845802595029142867</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-YI6-xapq-Yc/TnY18zejPuI/AAAAAAAAAsQ/AkoO_9Y4uMA/s1600/Restore_up.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-YI6-xapq-Yc/TnY18zejPuI/AAAAAAAAAsQ/AkoO_9Y4uMA/s200/Restore_up.jpg" width="158" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Capita di rado di assistere ad un evento così. Per chi come me ha la fissazione della sicurezza poi ha quasi del miracoloso.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Se un software o un sistema è sicuro di solito non ce ne accorgiamo. E se è insicuro ce ne accorgiamo solo quando il danno è fatto e non c'è più niente da fare!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Partiamo dagli albori: confidenzialità, integrità e disponibilità. L'ho presa troppo alla larga? Forse. Però c'è un sottile file rosso. Seguiamolo.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Sulla &lt;b&gt;confidenzialità&lt;/b&gt; ce ne sarebbe da dire, ma una cosa è certa: non c'è aspetto più inusabile degli strumenti che mirano a mantenere la confidenzialità delle informazioni. Cifrari, chiavi, passphrase, hash e quant'altro sono lontani anni luce dall'uomo della strada. E se poi non ci ricordiamo la chiave? I dati sono persi? Insomma la confidenzialità è roba da esperti o poco ci manca.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Integrità e Disponibilità&lt;/b&gt; invece sono più vicine all'utente comune di quanto ci si possa aspettare. Non trovate più quel file che avete salvato, o lo trovate ma è corrotto? Bene nel primo caso avete un esempio lampante di "disponibilità", nel secondo di "integrità".&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ok, cerco di stringere: un esempio disponibilità e integrità che è alla portata dell'utente comune (che qualche spocchioso informatico chiama &lt;b&gt;utOnto&lt;/b&gt;) è il &lt;b&gt;backup &amp;amp; restore&lt;/b&gt;. Ora quello che vorrei fare è dimostrare al lettore che si può raggiungere un elevato livello di integrità e di disponibilità anche sul suo computer casalingo.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Cosa c'è di più tragico che reinizializzare (o reinstallare) il proprio computer? Dobbiamo formattare il disco, reinstallare il sistema operativo, le diverse applicazioni, rifare tutte le configurazioni, recuperare i dati, etc. Per poi scoprire che le cronologie sono definitivamente perse e, solo dopo un ragionevole tempo, che anche qualche cosa di importante non è stato salvato.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
E alla fine non possiamo che rassegnarci, SOB!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Bene, ieri ho finalmente avuto la dimostrazione che è possibile evitare tutti questi problemi. Ho infatti deciso di reinstallare da capo il mio MacBook Pro. Pur avendo già installato Lion avevo notato una certa "scattosità" della grafica, forse attribuibile ai miei diversi esperimenti.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Dopo un anno e mezzo ci può stare una reinstallazione del tutto (di solito sono restio, ma se la regola d'oro è "per prima cosa, riavvia", quella d'argento è "formatta e poi riprova").&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ovviamente da bravo security man, non contento del backup di TimeMachine che per un anno e mezzo mi ha tranquillizzato (senza considerare &lt;a href="http://mozy.ie/"&gt;Mozy&lt;/a&gt;...), ho fatto il backup dei dati importanti su due diversi dischi rigidi: gli stessi dati duplicati più il backup di TimeMachine. Poi ho creato ben due chiavi USB con il Lion sopra (non si sa mai, magari una è corrotta...) ed ho iniziato.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div class="separator" style="clear: both; text-align: justify;"&gt;
&lt;a href="http://4.bp.blogspot.com/-idHyXLWo6hw/TnY2WwIbFPI/AAAAAAAAAsU/KmnjunIrXto/s1600/LionMGM.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="133" src="http://4.bp.blogspot.com/-idHyXLWo6hw/TnY2WwIbFPI/AAAAAAAAAsU/KmnjunIrXto/s200/LionMGM.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Inizializzo il disco rigido da 750 GB (con una sovrascrittura di zeri che rende l'operazione non proprio breve) e l'installazione di Lion comincia. Dopo poco, al termine, mi chiede se ho un disco TimeMachine. Lo connetto e lui "tomo tomo, cacchio cacchio" comincia a cercare sul disco quali sono i dati archiviati nei backup precedenti. Ci mette un po' ma l'Hub USB e i 2 TB del disco rigido non aiutano. Alla fine seleziono tutto e, augurandomi che tutto vada bene ("tanto che mi importa alla fine ho i backup fatti a "mano"!") inizio il ripristino.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Lo lascio una notte a lavorare e la mattina seguente, come il giorno di Natale, trovo sotto l'albero un Mac completamente identico alla precedente installazione, ma estremamente più performante.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Che dire? Mi sono meravigliato di come un sistema di backup e soprattutto di restore possa essere così usabile. Capita spesso di fare dei backup o dei restore parziali, ma fare un restore di un intero disco rigido con dati che si avvicinano ai 300 GB diventa impresa più lunga e complessa&amp;nbsp;(non confondiamo il restore con la copia del dell'intera partizione; nel caso della copia, avrei ripristinato il sistema tale e quale con annessi tutti i problemi).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;TimeMachine e Mac OSX Lion hanno reso questo restore "epocale" una passeggiata, lunga e paziente, ma per nulla accidentata&lt;/b&gt;. A prova di utOnto insomma. E questo significa per me coniugare usabilità e sicurezza. Del resto cosa c'è di più importante dei propri dati?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
P.S. qualcuno penserà che sono un invasato di Mac o altre fesserie del genere. Se lo pensate e non avete mai provato quello che ho descritto nel post allora vi consiglio di essere un po' più cauti, nell'altro caso invece sarete sicuramente d'accordo con me.&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-7845802595029142867?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=_ypYvvRgBEc:-0gbUXVEn48:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=_ypYvvRgBEc:-0gbUXVEn48:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=_ypYvvRgBEc:-0gbUXVEn48:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=_ypYvvRgBEc:-0gbUXVEn48:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/_ypYvvRgBEc" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-09-19T18:29:56.672+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-YI6-xapq-Yc/TnY18zejPuI/AAAAAAAAAsQ/AkoO_9Y4uMA/s72-c/Restore_up.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/09/quando-lusabilita-si-coniuga-con-la.html</feedburner:origLink></item><item><title>Anche tu sei un hacker!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/hvK1lXFUaGQ/anche-tu-sei-un-hacker.html</link><category>video</category><category>hacker</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Wed, 31 Aug 2011 13:52:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-6237964497145273340</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
Probabilmente alla fine di questo video esclamerete:&lt;br /&gt;
&lt;br /&gt;
"Accidenti, sono un hacker e non lo sapevo!"&lt;br /&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;embed allowfullscreen="true" allowscriptaccess="always" id="VideoPlayback" src="http://video.google.com/googleplayer.swf?docid=-5112548212809281320&amp;amp;hl=en&amp;amp;fs=true" style="height: 326px; width: 400px;" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;br /&gt;
&lt;br /&gt;
Alcune verità assolute nel video:&lt;br /&gt;
&lt;br /&gt;
&lt;ul style="text-align: left;"&gt;
&lt;li&gt;Hacking è passione: quanti fanno lavori che odiano?&lt;/li&gt;
&lt;li&gt;Hacking è uscire dagli schemi: &lt;a href="http://it.wikipedia.org/wiki/Pensiero_laterale"&gt;pensiero laterale&lt;/a&gt;, grande dote!&lt;/li&gt;
&lt;li&gt;Hacking è stimoli intellettuali: fondamentali per sopravvivere.&lt;/li&gt;
&lt;li&gt;Hacker sono anche Donne e Bambini: dopo &lt;a href="http://it.wikipedia.org/wiki/Wargames_-_Giochi_di_guerra"&gt;wargames&lt;/a&gt; qualcuno si è convinto per i bambini ma per le donne...&lt;/li&gt;
&lt;li&gt;Gli Hacker sono cattivi? No, solo mal rappresentati dai Media&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-6237964497145273340?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=hvK1lXFUaGQ:gcl39BnWfRA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=hvK1lXFUaGQ:gcl39BnWfRA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=hvK1lXFUaGQ:gcl39BnWfRA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=hvK1lXFUaGQ:gcl39BnWfRA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/hvK1lXFUaGQ" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-08-31T22:52:33.174+02:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/08/anche-tu-sei-un-hacker.html</feedburner:origLink></item><item><title>Php 5.3.7 e Apache web server: vulnerabilità col botto!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/ofl44ehsxoQ/php-537-e-apache-web-server.html</link><category>vulnerabilità</category><category>exploit</category><category>php</category><category>apache</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Wed, 24 Aug 2011 23:30:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-4042633027551001040</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-I-OZ8SRBOBc/TlXrAKcHylI/AAAAAAAAAsM/z0_XIc07P7Q/s1600/il-botto.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="192" src="http://1.bp.blogspot.com/-I-OZ8SRBOBc/TlXrAKcHylI/AAAAAAAAAsM/z0_XIc07P7Q/s200/il-botto.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
E' da un po' di tempo che non faccio segnalazioni del genere. Ci sono molti siti a cui sarete affezionati e che sono sicuramente più tempestivi del sottoscritto. Ma quando esce qualche cosa di clamoroso, lo spirito di servizio di questo blog esce fuori :-)&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
- Cominciamo da &lt;b&gt;PHP&lt;/b&gt;: la &lt;a href="https://bugs.php.net/bug.php?id=55439"&gt;nuova versione &lt;b&gt;5.3.7&lt;/b&gt; implementa la crypt() in modo singolare&lt;/a&gt;, &lt;b&gt;perché alcune volte il risultato della cifratura è il solo SALT&lt;/b&gt;! Incredibile vero? Evitate quindi di fare l'upgrade a tale versione fino a che non sia uscita una patch per questa grave vulnerabilità.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
"&lt;span class="Apple-style-span" style="background-color: white; font-size: 14px;"&gt;&lt;pre class="note" style="display: inline !important; font-family: monospace; font-size: medium; margin-left: 10px; white-space: pre-wrap; width: 65em;"&gt;Description:&lt;/pre&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: verdana, arial, helvetica, sans-serif; font-size: 14px;"&gt;&lt;pre class="note" style="display: inline !important; font-family: monospace; font-size: medium; margin-left: 10px; white-space: pre-wrap; width: 65em;"&gt;If crypt() is executed with MD5 salts, the return value conists of the salt only.&lt;/pre&gt;
&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: verdana, arial, helvetica, sans-serif; font-size: 14px;"&gt;&lt;pre class="note" style="display: inline !important; font-family: monospace; font-size: medium; margin-left: 10px; text-align: justify; white-space: pre-wrap; width: 65em;"&gt;DES and BLOWFISH salts work as expected."&lt;/pre&gt;
&lt;/span&gt;&lt;/div&gt;
&lt;span class="Apple-style-span" style="background-color: white; font-family: verdana, arial, helvetica, sans-serif; font-size: 14px;"&gt;&lt;pre class="note" style="font-family: monospace; font-size: medium; margin-left: 10px; white-space: pre-wrap; width: 65em;"&gt;
&lt;/pre&gt;
&lt;/span&gt;&lt;div style="text-align: justify;"&gt;
- E proseguiamo con &lt;b&gt;Apache web server&lt;/b&gt;: da &lt;a href="http://blog.spiderlabs.com/2011/08/mitigation-of-apache-range-header-dos-attack.html"&gt;quello che leggo la vulnerabilità era stata segnalata già dal 2007&lt;/a&gt; ma fino ad oggi (o dovrei dire ieri) non esisteva un &lt;a href="http://seclists.org/fulldisclosure/2011/Aug/175"&gt;PoC&lt;/a&gt;&amp;nbsp;in giro. Adesso c'è: una specie di &lt;b&gt;HTTP request della morte&lt;/b&gt;, con cui buttare giù un server web (apache) in poco tempo. Gli amministratori di sistema farebbero bene a prestarvi attenzione. In questi tempi i &lt;b&gt;DoS e i DDoS&lt;/b&gt; sono tornati di moda grazie ad Anonymous e vari, e allora...&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-4042633027551001040?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=ofl44ehsxoQ:uObhqI0Ro5M:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=ofl44ehsxoQ:uObhqI0Ro5M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=ofl44ehsxoQ:uObhqI0Ro5M:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=ofl44ehsxoQ:uObhqI0Ro5M:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/ofl44ehsxoQ" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-08-25T08:30:55.816+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-I-OZ8SRBOBc/TlXrAKcHylI/AAAAAAAAAsM/z0_XIc07P7Q/s72-c/il-botto.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/08/php-537-e-apache-web-server.html</feedburner:origLink></item><item><title>Alice &amp; Bob: password wallet</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/qTSH77RgPvA/alice-bob-password-wallet.html</link><category>password</category><category>alice and bob</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Mon, 22 Aug 2011 10:03:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-941566287259664083</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-PXsj11QuTFM/TlKLWj8_SAI/AAAAAAAAAsI/Hg5f3lwRUCA/s1600/images-1.jpeg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-PXsj11QuTFM/TlKLWj8_SAI/AAAAAAAAAsI/Hg5f3lwRUCA/s1600/images-1.jpeg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;b&gt;Bob&lt;/b&gt;: "...e quindi io alla fine per gestire le password utilizzo un "Password Wallet" "&lt;br /&gt;
&lt;br /&gt;
Alice: "Cosa?"&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bob&lt;/b&gt;: "Password Wallet: applicazione che memorizza le password, opportunamente protetta mediante cifratura ed unica password di accesso."&lt;br /&gt;
&lt;br /&gt;
Alice: "Ma nooo, io le password me le ricordo a memoria!"&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Bob&lt;/b&gt;: "(tranquilla lei!)"&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-941566287259664083?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=qTSH77RgPvA:UUtOn2rWmuA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=qTSH77RgPvA:UUtOn2rWmuA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=qTSH77RgPvA:UUtOn2rWmuA:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=qTSH77RgPvA:UUtOn2rWmuA:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/qTSH77RgPvA" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-08-22T19:04:32.498+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-PXsj11QuTFM/TlKLWj8_SAI/AAAAAAAAAsI/Hg5f3lwRUCA/s72-c/images-1.jpeg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/08/alice-bob-password-wallet.html</feedburner:origLink></item><item><title>20 anni di Password!</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/1Ia8-BIl2Sw/20-anni-di-password.html</link><category>comics</category><category>password</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Thu, 11 Aug 2011 09:31:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-1220509224822033600</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://imgs.xkcd.com/comics/password_strength.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="324" src="http://imgs.xkcd.com/comics/password_strength.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
"dopo 20 anni di sforzi, abbiamo e con successo insegnato a tutti ad usare password che sono difficili da ricordare ma facili da indovinare per un computer"&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Insomma un successo! :-)&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-1220509224822033600?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=1Ia8-BIl2Sw:kT8AEZDDJS4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=1Ia8-BIl2Sw:kT8AEZDDJS4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1Ia8-BIl2Sw:kT8AEZDDJS4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=1Ia8-BIl2Sw:kT8AEZDDJS4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/1Ia8-BIl2Sw" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-08-11T18:31:41.705+02:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/08/20-anni-di-password.html</feedburner:origLink></item><item><title>Google: video e istruzioni per l'autenticazione forte</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/s2vXCNaXs68/google-video-e-istruzioni-per.html</link><category>authentication</category><category>google</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Thu, 04 Aug 2011 23:48:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-8310600054445316676</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
Vi ho &lt;a href="http://geekinfosecurity.blogspot.com/2011/03/2-factor-authentication-per-google.html"&gt;rotto fino allo sfinimento&lt;/a&gt;. Ma se usate i servizi di Google non potete derogare sull'autenticazione forte. Username e password non bastano più. Serve un'autenticazione forte a due fattori. Seria. E &lt;a href="http://www.google.com/support/accounts/bin/static.py?page=guide.cs&amp;amp;guide=1056283&amp;amp;topic=1056284"&gt;Google sa come si fa&lt;/a&gt;:&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;object width="320" height="266" class="BLOGGER-youtube-video" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0" data-thumbnail-src="http://0.gvt0.com/vi/zMabEyrtPRg/0.jpg"&gt;&lt;param name="movie" value="http://www.youtube.com/v/zMabEyrtPRg&amp;fs=1&amp;source=uds" /&gt;
&lt;param name="bgcolor" value="#FFFFFF" /&gt;
&lt;embed width="320" height="266"  src="http://www.youtube.com/v/zMabEyrtPRg&amp;fs=1&amp;source=uds" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Se avete un cellulare, e lo avete di sicuro, l'autenticazione forte con Google non è un problema. E poi essere richiamati da un servizio vocale (quando magari l'SMS non arriva) con una voce in perfetto italiano (ma computerizzata) è una gran soddisfazione.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Fatelo!&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-8310600054445316676?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=s2vXCNaXs68:Q-awuHGj6Ns:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=s2vXCNaXs68:Q-awuHGj6Ns:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=s2vXCNaXs68:Q-awuHGj6Ns:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=s2vXCNaXs68:Q-awuHGj6Ns:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/s2vXCNaXs68" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-08-05T08:48:47.253+02:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/08/google-video-e-istruzioni-per.html</feedburner:origLink></item><item><title>Le migliori password della nostra vita</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/zSLjP1MErYI/le-migliori-password-della-nostra-vita.html</link><category>password</category><category>entropia</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Sun, 24 Jul 2011 23:27:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-5071877559847214074</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-KnohERpwspw/Tip9I6FZoWI/AAAAAAAAArU/xNP-20Zn6oQ/s1600/password.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-KnohERpwspw/Tip9I6FZoWI/AAAAAAAAArU/xNP-20Zn6oQ/s1600/password.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
State leggendo questo post, e vi state chiedendo se andare avanti: "&lt;i&gt;l'ennesimo post sulle migliori password, su che struttura debbano avere per raggiungere un livello di sicurezza adeguato. Non se ne può più!&lt;/i&gt;".&lt;br /&gt;
&lt;br /&gt;
Già m'immagino!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Non l'avrei di certo scritto, se non avessi alcune considerazioni da fare sui meccanismi di autenticazione&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Strong_authentication"&gt;forte&lt;/a&gt;&amp;nbsp;e sulle care vecchie password.&lt;br /&gt;
&lt;br /&gt;
Prendiamo l'autenticazione a due fattori con token. Come spero già sappiate (ma non siete certo obbligati) si dice "a due fattori" perché il primo fattore è una cosa che si conosce (es. le credenziali), mentre il secondo è una cosa che si possiede fisicamente (per es un &lt;a href="http://en.wikipedia.org/wiki/Token"&gt;token&lt;/a&gt; &lt;a href="http://en.wikipedia.org/wiki/One_Time_Password"&gt;OTP&lt;/a&gt;). In quest'ultimo caso però, dobbiamo avere fisicamente l'oggetto con noi, ed è questo il problema.&lt;br /&gt;
Un token (qualsiasi cosa esso sia) è una cosa troppo vincolante, poiché possiamo dimenticarcelo a casa e allora che fare? Di fatto, non potremmo accedere al servizio che richiede tale autenticazione!&lt;br /&gt;
&lt;a href="http://geekinfosecurity.blogspot.com/2011/03/2-factor-authentication-per-google.html"&gt;Google&lt;/a&gt; e molti altri propongono un'autenticazione a due fattori più "furba", che utilizza magari il cellulare come token (con SMS o telefonate con codici), oppure propongono l'immissione del PIN del Token solo per alcune operazioni (di solito le banche on-line).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Non parliamo poi di autenticazioni a 3 fattori: &lt;b&gt;"una cosa che tu sai"&lt;/b&gt;+&lt;b&gt;"una cosa che tu hai"&lt;/b&gt;+&lt;b&gt;"una cosa che tu sei"&lt;/b&gt;! L'iride, le impronte, il volto, l'orecchio e avanti con l'immaginazione per identificare un'altra parte del corpo che sia unica nelle sue caratteristiche. Di fatto però ci sono problemi di calibrazione degli strumenti di riconoscimento di tali parametri biometrici per non avere eccessivi falsi positivi o falsi negativi. Senza considerare poi che, dovendo tali sistemi verificare i parametri biometrici con quelli già memorizzati, tale autenticazione &lt;a href="http://it.wikipedia.org/wiki/Biometria"&gt;pone dei problemi di privacy&lt;/a&gt; per gli archivi di tali dati, che devono essere opportunamente gestiti secondo il codice di tutela della privacy.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Insomma, non solo mi devo portare dietro una smartcard, un token, il telefonino! Ma devo anche stare attento alla barba, oppure se ho la congiuntivite o le mani sudate. Un delirio insomma.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La cara vecchia password, per quanto vetusta, gode ancora di caratteristiche invidiabili: la &lt;a href="http://geekinfosecurity.blogspot.com/2011/01/alice-bob-password-delegation.html"&gt;delega&lt;/a&gt;, e l'usabilità.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Nel primo caso, possiamo in qualsiasi momento delegare qualcun altro ad accedere per nostro conto al servizio che ci interessa semplicemente comunicandogli la password (con ogni mezzo). Ovviamente stiamo rilassando la sicurezza generale e la stiamo affidando al nostro delegato. Quante volte lo facciamo nella vita reale? Basterà poi cambiare la password.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Nel secondo caso invece, cosa c'è di più usabile di una cosa da tenere a mente? Ci vuole solo un po' di esercizio in fondo.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ma non è tutto ora quello che luccica: le password soffrono di un problema ben conosciuto che si chiama "Social Engineering" (SE). Qual'è il modo migliore per catturare una password? &lt;a href="http://it.wikipedia.org/wiki/Man_in_the_middle"&gt;MTM&lt;/a&gt;? Brute Force? Attacchi del dizionario?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
No.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ce ne sono tanti di modi: osservare la nostra vittima mentre inserisce la password; fare qualche prova con il nome della moglie, del padre, della madre e relative date di nascita; provare con le domande di sicurezza (anzi direi di insicurezza); fingersi la vittima e chiamare l'helpdesk della sua compagnia telefonica; guardare quel foglietto con su scritta la password troppo complessa...TROPPO COMPLESSA!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Per questo le password non dovrebbero mai essere troppo complesse. Perché il rischio è che vengano scritte da qualche parte e allora attachi di Social Engineering potrebbero diventare una triste (per l'utente) realtà.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;&lt;span style="font-size: large;"&gt;Come determinare la robustezza di una password &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-FWmnUlsyNRY/Tip-_MN4RaI/AAAAAAAAArY/soWN26k34ME/s1600/bruteforce.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="160" src="http://1.bp.blogspot.com/-FWmnUlsyNRY/Tip-_MN4RaI/AAAAAAAAArY/soWN26k34ME/s200/bruteforce.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
Innanzitutto la "robustezza" che possiamo calcolare è quella rispetto ad attacchi di tipo brute force. Quindi enumerazioni di tutte le possibili password. Poi con alcuni accorgimenti si può partire dai criteri di robustezza per il brute force e ovviare anche al problema degli attacchi di tipo SE.&amp;nbsp;Per capire quanto è robusta una password ci sono due vie: quella semplice e quella complessa.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
La considerazione semplice da fare è che se scegliamo un password lunga N caratteri in cui ogni carattere è scelto da un alfabeto di Z simboli, allora la robustezza è pari a tutte le combinazioni possibili che si è costretti a fare per indovinarla: Z^N.&amp;nbsp;Che espresso in bit è pari a Log2(Z^N) = N*log2(Z).&lt;br /&gt;
&lt;br /&gt;
Ovvero un &lt;b&gt;attacco di tipo brute force deve enumerare tutte le stringhe binarie fino a Log2(Z^N)&lt;/b&gt;.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Per la via complessa, che introduce il concetto di entropia binaria, vi rimando alla fine di questo post.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;
&lt;b&gt;&lt;span style="font-size: large;"&gt;Come costruire una password &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://3.bp.blogspot.com/-LQQoUaLE8Nw/Tip_XwojGdI/AAAAAAAAArc/bGpYquuDOzA/s1600/passwords-are-like-pants.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-LQQoUaLE8Nw/Tip_XwojGdI/AAAAAAAAArc/bGpYquuDOzA/s200/passwords-are-like-pants.jpg" width="160" /&gt;&lt;/a&gt;&lt;/div&gt;
Vediamo un elenco di raccomandazioni su come costruire delle password robuste:&lt;/div&gt;
&lt;ul&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;fissate una lunghezza ragionevole&lt;/b&gt;: non eccessivamente lunga per le password casuali, abbastanza lunga per quelle non casuali e basate su parole appartenenti a domini "esotici". Se ricordate quanto detto prima, in fondo la robustezza è pari a Z^N, quindi se aumentate di solo un carattere la password, moltiplicate Z^N per N!&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;password casuali generate con PRNG o RNG&lt;/b&gt; (&lt;a href="http://en.wikipedia.org/wiki/Pseudorandom_number_generator"&gt;Pseudorandom Number Generator&lt;/a&gt; o &lt;a href="http://en.wikipedia.org/wiki/Random_number_generation"&gt;Random Number Generator&lt;/a&gt;): se hanno un alfabeto di simboli abbastanza ampio e una lunghezza ragionevole sono inattaccabili con metodi quali forza bruta, attacchi del dizionario ed altro; ma purtroppo sono difficilmente memorizzabili ed il rischio di trovarle memorizzate da qualche parte è molto alto. Quindi soggette ad attacchi di tipo SE.&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;password non casuali&lt;/b&gt;: (tra cui le &lt;a href="http://en.wikipedia.org/wiki/Passphrase"&gt;passphrase&lt;/a&gt;) sono composte da parole di senso compiuto che &amp;nbsp;possono creare delle frasi e quindi di facile memorizzazione. Alcune considerazioni che riguardano queste password però sono doverose:&lt;/li&gt;
&lt;/ul&gt;
&lt;ul&gt;&lt;ul&gt;
&lt;li style="text-align: justify;"&gt;se&lt;b&gt; sostituite ad alcune lettere&lt;/b&gt; (non a tutte!) &lt;b&gt;i numeri o le maiuscole&lt;/b&gt;, questo aumenta la forza della password solo per attacchi a forza bruta, perché invece attacchi del dizionario sono possibili con strategie adeguate (ogni volta che trovi una lettera, prova a sostituire con il numero equivalente se esiste, etc.)&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;potete &lt;b&gt;separare le parole con degli spazi&lt;/b&gt; che aumentano la memorizzabilità (sempre che il sistema accetti degli spazi)&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;fissate un&lt;b&gt; numero esatto di numeri o maiuscole &lt;/b&gt;da inserire: eviterà l'inserimento di password con tutti numeri, o tutte lettere maiuscole&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;evitate&lt;/b&gt; di mettere &lt;b&gt;tutti i numeri all'inizio o alla fine&lt;/b&gt; della password&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;scegliete un &lt;b&gt;dominio delle parole insolito&lt;/b&gt;: se è meno conosciuto e meno probabile che vi sia un dizionario già pronto&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;i &lt;b&gt;segni di interpunzione&lt;/b&gt; servono solo per ampliare l'alfabeto ma &lt;b&gt;sono terribilmente complicati da ricordare&lt;/b&gt;. Se fossi in voi li userei solo in casi eccezionali e in posizioni ben identificate&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;non prendete una frase di un libro&lt;/b&gt; perché con un po' di SE e&amp;nbsp;&lt;b&gt;Google&lt;/b&gt;&amp;nbsp;basta inserire l'incipit ed avete subito il resto; potete però cambiare la frase con qualche trucco che solo voi sapete&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;evitate delle password imbarazzanti &lt;/b&gt;o che rivelano vostre informazioni riservate: se la password rimane nascosta non è un problema, ma nel caso dobbiate rivelarla a qualcuno per motivi di urgenza, vi trovereste in imbarazzo&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;non vi complicate la vita: &lt;b&gt;relazionate la forma della password al rischio di compromissione&lt;/b&gt; della stessa; non avete bisogno di una password eccessivamente robusta per l'iscrizione con falso nome sul forum di giochi on-line!&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;cambio della &lt;b&gt;password&lt;/b&gt;: &lt;b&gt;cambiatela, ma non così spesso&lt;/b&gt;, alla fine rischiereste di usare le 3-4 password che usate di solito!&lt;/li&gt;
&lt;li style="text-align: justify;"&gt;&lt;b&gt;usate un &lt;a href="http://en.wikipedia.org/wiki/Password_manager"&gt;password wallet&lt;/a&gt;&amp;nbsp;elettronico&lt;/b&gt;: scegliete una master password abbastanza robusta ed un programma open source di cui sia possibile ispezionare il codice&lt;/li&gt;
&lt;/ul&gt;
&lt;/ul&gt;
&lt;div style="text-align: justify;"&gt;
&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;&lt;span style="font-size: large;"&gt;Approfondimento "entropico" &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://4.bp.blogspot.com/-YQM_qmqPzRw/Tip_toJxZRI/AAAAAAAAArg/4vjjUax0JLw/s1600/dice-red-black.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="178" src="http://4.bp.blogspot.com/-YQM_qmqPzRw/Tip_toJxZRI/AAAAAAAAArg/4vjjUax0JLw/s200/dice-red-black.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;
Proverò ad essere estremamente discorsivo, ma qualche concetto di &lt;a href="http://en.wikipedia.org/wiki/Information_theory"&gt;Teoria dell'Informazione&lt;/a&gt; è inevitabile (e anche interessante no?).&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Scegliamo una password di lunghezza N, in cui ogni carattere è scelto da un alfabeto A, dove |A| = Z è la &lt;a href="http://it.wikipedia.org/wiki/Cardinalit%C3%A0"&gt;cardinalità&lt;/a&gt; di A (gli elementi che ci sono in A).&lt;br /&gt;
&lt;br /&gt;
Sia PWD = C1 C2 C3....Cn.&amp;nbsp;L'&lt;a href="http://en.wikipedia.org/wiki/Binary_entropy"&gt;entropia binaria&lt;/a&gt; della password (ovvero, con molte semplificazioni, la sua robustezza) è quindi la seguente:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;[1]&lt;/b&gt; &lt;b&gt;&lt;i&gt;H(password) = H(C1,C2,..,Cn) = H(C1)+H(C2)+H(C3)+...+H(Cn)&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
(l'ultima uguaglianza vale perché le probabilità con cui compaiono i caratteri nella password sono indipendenti)&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Dove H(Ci) è l'entropia del carattere i-esimo nella password, che è a sua volta l'entropia del singolo carattere &amp;nbsp;Ci nell'alfabeto di appartenenza A. Quindi:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;&lt;i&gt;[2] H(Ci) = Somm 1..Z P(Ci)*I(ci) = Somm 1..Z P(Ci)*log2(1/P(Ci)) = Somm 1..Z P(Ci)*-log2(Pci) = - Somm 1..Z P(Ci)*log2(Pci)&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
H(Ci) quindi costituisce il numero "medio" di bit necessari per rappresentare un qualsiasi carattere dell'alfabeto A scelto.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;&lt;i&gt;I(Ci) = log2(1/P(Ci)) = -log2(P(Ci))&lt;/i&gt;&lt;/b&gt; è invece il contenuto informativo del carattere Ci, ovvero il numero di bit necessari per rappresentare la probabilità di accadimento dello stesso Ci: &lt;b&gt;più è alta la probabilità, più basso è il contenuto informativo collegato al fatto che quell'evento si è verificato&lt;/b&gt;.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Se la distribuzione di probabilità dei caratteri nell'alfabeto è equiprobabile (ovvero &lt;b&gt;P(Ci) = 1/|A| = 1/Z per ogni i&lt;/b&gt;, perché ogni carattere ha la stessa probabilità di comparire) e indipendente (P(Ci) non dipende da P(Cj) per i diverso da j) allora:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;&lt;i&gt;[3] H(Ci) = -Somm 1..Z &amp;nbsp;1/Z*log2(1/Z) = Somm 1..Z 1/Z*log2(Z) = (1/Z+1/Z...+1/Z)*log2(Z) = log2(Z)&lt;/i&gt;&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Quindi &lt;b&gt;H(Ci) = log2(Z)&lt;/b&gt;, ossia l'entropia binaria media di un carattere dell'alfabeto è pari al logaritmo in base 2 della cardinalità dell'alfabeto.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Abbiamo fatto un giro molto lungo ma alla fine siamo arrivati ad una conclusione intuitiva: per rappresentare |A| = Z caratteri diversi servono esattamente log2(Z) bit. Ovvero dobbiamo enumerare tutte le stringhe binarie lunghe log2(Z) bit. E' quello che si fa nel brute force, no?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Per cui ritornando a (1):&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;i&gt;[4] H(password) = log2(Z) + log2(Z) +...+log2(Z) = N*log2(Z)&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
ovvero per rappresentare una password di N caratteri scelti tra Z, servono esattamente N moltiplicato il numero dei bit necessario per ogni carattere.&amp;nbsp;Questa misura indica di fatto la robustezza della password perché, banalmente, per portare un attacco a forza bruta basterebbe "contare" tutte le stringhe da N*log2(Z) bit (ovvero log2(Z^N). Più è alta quest'ultima, più la password è robusta.&amp;nbsp;E guarda caso il risultato è lo stesso che con il calcolo delle combinazioni!&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Dopo la teoria (i matematici inorridirebbero per questa mia affermazione), passiamo ad un esempio pratico:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Sia dato l'alfabeto A={0,1,2,3,4,5,6,7} dove |A|=Z=8, allora la probabilità &amp;nbsp;P(Ci) = log2(Z) = log2(8) = 3. &amp;nbsp;Sono quindi mediamente necessari 3 bit per rappresentare qualsiasi numero da 0 a 7. &lt;br /&gt;
Se la nostra password è lunga N = 8 caratteri, allora serviranno esattamente N*log2(Z) = 8*log2(8) = 8*3=24 bit per rappresentarla. Nel caso peggiore, dovremo enumerare tutte le stringhe da 24 bit.&lt;br /&gt;
&lt;br /&gt;
Semplice no?&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-5071877559847214074?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=zSLjP1MErYI:lenQoYU1lK0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=zSLjP1MErYI:lenQoYU1lK0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=zSLjP1MErYI:lenQoYU1lK0:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=zSLjP1MErYI:lenQoYU1lK0:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/zSLjP1MErYI" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-07-26T08:39:09.793+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-KnohERpwspw/Tip9I6FZoWI/AAAAAAAAArU/xNP-20Zn6oQ/s72-c/password.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/07/le-migliori-password-della-nostra-vita.html</feedburner:origLink></item><item><title>Hacking time: cracckare chiavi WPA? facile con Fastweb e Alice</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/1a-XbV5gHDk/hacking-time-cracckare-chiavi-wpa.html</link><category>cracking</category><category>hacking</category><category>WPA</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Sun, 10 Jul 2011 22:19:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-635437995026870988</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;
&lt;div style="text-align: justify;"&gt;
Sinceramente non mi sono mai dedicato al cracking delle chiavi WPA. Troppa fatica. Ma ultimamente ci sono dei programmini estremamente interessanti e astuti. Perché agire con la forza bruta quando si può raggiungere lo stesso risultato con l'astuzia?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Se vi dicessi che sia Fastweb che Alice danno in giro i loro router WiFi con una password precalcolata in base al MAC Address, e che tale Mac Address è nel caso di Fastweb ben visibile nel SSID, ci credereste?&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
E' invece è proprio così.&amp;nbsp;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ovviamente qualche buon tempone ha pensato bene di fare &lt;a href="http://wifiresearchers.wordpress.com/2010/03/25/pirelli-fastweb-free-access/"&gt;reverse engineering&lt;/a&gt;. Una volta capito l'algoritmo, TUTTI i router che usano questa astuta tecnica (praticamente la più becera Security Through Obscurity) sono facilmente crackabili.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Se leggerete con attenzione l'articolo linkato, capirete che gli errori dei progettisti sono stati diversi. Non solo il fatto di derivare la chiave condivisa da un dato ben visibile sulla rete come il SSID, ma anche quello di scegliere un algoritmo particolarmente banale, in cui:&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;l'alfabeto delle chiavi è assai ridotto: numeri e lettere dalla "a" alla "f" (vi ricorda qualche cosa?);&amp;nbsp;se vedo una stringa esadecimale, mi viene il dubbio che sia un MD5 e magari del MAC address (ed in parte purtroppo è vero!)&lt;/li&gt;
&lt;li&gt;la lunghezza delle chiavi è 10 per poter utilizzare la stessa chiave anche con WEP: così anche un attacco a forza bruta è fattibile (in virtù dell'alfabeto ridotto)&lt;/li&gt;
&lt;li&gt;il codice non è offuscato: serve a poco però aiuta!&lt;/li&gt;
&lt;li&gt;Solo per chi ha Fastweb: l'accesso alla rete permette di sapere vita morte e miracoli del possessore; basta andare sulla homepage Fastweb&lt;/li&gt;
&lt;li&gt;altre...&lt;/li&gt;
&lt;/ol&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Insomma le hanno fatte davvero tutte! Mi meraviglio che non abbiano "inventato" un nuovo algoritmo di cifratura! Magari uno XOR con una chiave segreta.&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Se avete una Mac, cercate lo script &lt;a href="http://www.google.it/search?client=safari&amp;amp;rls=en&amp;amp;q=rof.rb&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;redir_esc=&amp;amp;ei=WSsZTsqBF4T1sgaWusncDw"&gt;rof.rb in rete&lt;/a&gt;. Eseguitelo (tranquilli vi guida passo passo) e se siete fortunati, ma manco tanto, avrete la vostra chiave WPA!&lt;/div&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;
&lt;a href="http://1.bp.blogspot.com/-v0LdOQWxK8M/Thkuc4wYofI/AAAAAAAAArQ/2uX1fB58KPk/s1600/rofwpa.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="235" src="http://1.bp.blogspot.com/-v0LdOQWxK8M/Thkuc4wYofI/AAAAAAAAArQ/2uX1fB58KPk/s400/rofwpa.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style="text-align: justify;"&gt;
Non c'è quasi soddisfazione così :)&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;b&gt;Ovviamente tutto ciò è illegale e se dovete fare delle prove, fatele sui vostri sistemi.&lt;/b&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div style="text-align: justify;"&gt;
Ah, se siete dei fortunati possessori di router WiFi Alice e Fastweb: CAMBIATE LA CHIAVE!&lt;/div&gt;
&lt;/div&gt;
&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-635437995026870988?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=1a-XbV5gHDk:5xUb-Rn_D5s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=1a-XbV5gHDk:5xUb-Rn_D5s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=1a-XbV5gHDk:5xUb-Rn_D5s:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=1a-XbV5gHDk:5xUb-Rn_D5s:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/1a-XbV5gHDk" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-07-26T08:39:55.066+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-v0LdOQWxK8M/Thkuc4wYofI/AAAAAAAAArQ/2uX1fB58KPk/s72-c/rofwpa.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/07/hacking-time-cracckare-chiavi-wpa.html</feedburner:origLink></item><item><title>Anonymous: manuale di sopravvivenza</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/Z3W0r5abi8c/anonymous-manuale-di-sopravvivenza.html</link><category>hacktivism</category><category>anonymous</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Tue, 05 Jul 2011 22:41:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-995651556019830340</guid><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Lr4Yv9uzDww/ThP1OrUd4LI/AAAAAAAAArM/xALlj17OhCc/s1600/Schermata+2011-07-06+a+07.18.48.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img src="http://3.bp.blogspot.com/-Lr4Yv9uzDww/ThP1OrUd4LI/AAAAAAAAArM/xALlj17OhCc/s320/Schermata+2011-07-06+a+07.18.48.png" border="0" height="320" width="288" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Anonymous si dà all'editoria ed esce con &lt;a href="http://www.vulnerabilitydatabase.com/wp-content/uploads/2011/06/OpNewblood-Super-Secret-Security-Handbook.pdf"&gt;un manuale di istruzioni per il perfetto dissidente digitale&lt;/a&gt;. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;Dalla connessione alla rete TOR, a quella ai server IRC tramite tunnelling, fino al cambio dei DNS e alle macchine virtuali.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma tutto quello che un aspirante hacktivista digitale dovrebbe fare per essere sicuro di non essere scoperto. &lt;/div&gt;&lt;div style="text-align: justify;"&gt;Però, a guardar bene le istruzioni, queste possono essere viste anche come un buon vademecum per mantenere l'anonimità in rete, senza per forza essere degli attivisti (malevoli) digitali ed effettuare azioni lesive quali attacchi di tipo DDoS.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Comunque interessante da leggere :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-995651556019830340?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=Z3W0r5abi8c:FWiSf5c3bO4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=Z3W0r5abi8c:FWiSf5c3bO4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=Z3W0r5abi8c:FWiSf5c3bO4:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=Z3W0r5abi8c:FWiSf5c3bO4:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/Z3W0r5abi8c" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-07-06T11:28:57.669+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-Lr4Yv9uzDww/ThP1OrUd4LI/AAAAAAAAArM/xALlj17OhCc/s72-c/Schermata+2011-07-06+a+07.18.48.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/07/anonymous-manuale-di-sopravvivenza.html</feedburner:origLink></item><item><title>Security Conference: solo vaporware?</title><link>http://feedproxy.google.com/~r/InformationSecurityForGeeks/~3/nZiNcUFBVrQ/security-conference-solo-vaporware.html</link><category>cracking</category><category>security</category><category>hacking</category><author>noreply@blogger.com (Roberto Scaccia)</author><pubDate>Fri, 01 Jul 2011 08:37:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-1908095138994940398.post-5607263091919336819</guid><description>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-LLKTFtUGL5o/Tg3osnW8o1I/AAAAAAAAArI/P9Bym4xIa_I/s1600/images.jpeg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://3.bp.blogspot.com/-LLKTFtUGL5o/Tg3osnW8o1I/AAAAAAAAArI/P9Bym4xIa_I/s200/images.jpeg" width="152" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Non ce la faccio più! Questo è stato l'ennesimo convegno di sicurezza "fuffologico". Ma possibile che ultimamente tutti i convegni siano così scadenti? Almeno una volta ti volevano vendere il solito scatolotto, adesso nemmeno più quello! Qualità degli oratori scadente, qualità del contenuto degli interventi scadente, organizzazione scadente, etc.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;L'ultima che ho sentito è la "&lt;a href="http://it.wikipedia.org/wiki/Teoria_del_Cigno_Nero"&gt;Teoria del Cigno Nero&lt;/a&gt;". Metafora dell'evento raro impredicibile e catastrofico. Che per sua natura non è prevedibile. Roba da Wikipedia, copia-incolla e lavoro per i &lt;a href="http://it.wikipedia.org/wiki/Debunker"&gt;Debunker&lt;/a&gt; (vero &lt;a href="http://attivissimo.blogspot.com/"&gt;Paolo&lt;/a&gt;?). Capisco che abbia il suo fascino e colpisca la platea (ma solo un certo tipo eh...), ma suvvia questi colpi da teatro dell'orrore lasciamoli ad altri contesti no?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;E che dire della solita statistica con il numero di malware per paese? A che serve? A spaventare e quindi a vendere servizi? Alla fine anche quelli digiuni di sicurezza, dopo 5 anni, le hanno capite queste cose o no? Ah giusto, se parlassero con i loro tecnici invece che pascolare in giro per rinfreschi (ed essere stipendiati per farlo) forse saprebbero qualche cosa di più.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Poi cominci a guardare la platea di uditori e chi ti trovi? Generali, AD, "capoccioni" vari che manco sanno accendere un PC, figuriamoci capire cosa sia un DDoS, o chi siano gli "Anonymous", o peggio capire che c'è una differenza tra hacker e cracker. Forse lo capirebbero con un esempio banale? &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;"se il tuo bambino comincia a smontare e rimontare le cose, è un hacker!"&lt;/li&gt;&lt;li&gt;"se il tuo bambino comincia a smontare le mattonelle del bagno per nascondere la cocaina, allora è un cracker". &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;Ci vuole molto?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Insomma non se ne può più. La scelta è quindi oramai tra convegni organizzati dalle Università e in generale da enti di ricerca (ma spesso le conferenze sono a pagamento) e convegni nell'ambito dell'hacking (e qui già va meglio, ma gli hacker si sa per loro natura sono schivi). I primi godono certamente di alcuni approfondimenti derivati dalla ricerca. Dateci una rete Bayesiana ogni tanto, un grafo, una sommatoria vi prego!!! Ovviamente alcune parti potranno essere un po' troppo accademiche per alcuni, ma almeno saranno interessanti!&lt;/div&gt;&lt;div style="text-align: justify;"&gt;I secondi invece sono da sempre interventi molto "smanettosi" in cui si fanno vedere "cose" (oddio mi viene in mente però l'ennesimo speech sulla SQL injection), ma poi saranno compresi da un uditorio di burocrati interessati solo al break mangereccio?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Per concludere: per cortesia, tutti gli pseudo-esperti di sicurezza (e se hai una responsabilità in tal senso sei pregato di studiare prima) se ne restino a casa o almeno non tengano speech pretendendo di vendere al mondo la solita aria-fritta! &lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Alla fin fine "security means hacking"!&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1908095138994940398-5607263091919336819?l=geekinfosecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=nZiNcUFBVrQ:0BaOWzhM_Oo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=nZiNcUFBVrQ:0BaOWzhM_Oo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?a=nZiNcUFBVrQ:0BaOWzhM_Oo:-BTjWOF_DHI"&gt;&lt;img src="http://feeds.feedburner.com/~ff/InformationSecurityForGeeks?i=nZiNcUFBVrQ:0BaOWzhM_Oo:-BTjWOF_DHI" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/InformationSecurityForGeeks/~4/nZiNcUFBVrQ" height="1" width="1"/&gt;</description><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-07-03T15:19:59.242+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-LLKTFtUGL5o/Tg3osnW8o1I/AAAAAAAAArI/P9Bym4xIa_I/s72-c/images.jpeg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://geekinfosecurity.blogspot.com/2011/07/security-conference-solo-vaporware.html</feedburner:origLink></item></channel></rss>

