<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;CE4ARXc7eSp7ImA9WhBXEEg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942</id><updated>2013-03-23T16:35:44.901+01:00</updated><category term="Whitepaper" /><category term="Hardware hacking" /><category term="Vulnerabilties" /><category term="0day" /><category term="Advisory" /><category term="sslaudit" /><category term="Omron 3S4YR-MVFW Card reader" /><category term="Misc" /><category term="How-to" /><category term="Bluetooth" /><category term="About" /><category term="Rants from Thierry" /><category term="Interesting Reads" /><category term="Lectures" /><category term="Vulnerability disclosure Policy" /><category term="zero day" /><category term="Tool" /><category term="BTcrack" /><title>Musings on  Information Security</title><subtitle type="html">_     Where facts are few, experts are many</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://blog.zoller.lu/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://blog.zoller.lu/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>163</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/thierryzoller" /><feedburner:info uri="thierryzoller" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>thierryzoller</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><entry gd:etag="W/&quot;CE4ARXc6fCp7ImA9WhBXEEg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-2778492877113350546</id><published>2013-03-23T15:56:00.000+01:00</published><updated>2013-03-23T16:35:44.914+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-23T16:35:44.914+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Interesting Reads" /><title>Interesting Reads - Week 12 / 2013</title><content type="html">Interesting Reads - Week 12 / 2013

Binary Instrumentation for Exploit Analysis Purposes (part 1)
Binary Instrumentation for Exploit Analysis Purposes (part 2)
Using the PIN instrumentalisation framework to analyse exploits
Randomly failed!...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/9szL6gXZp_o" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=2778492877113350546" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/2778492877113350546?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/2778492877113350546?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/9szL6gXZp_o/interesting-reads-week-12-2013.html" title="Interesting Reads - Week 12 / 2013" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2013/03/interesting-reads-week-12-2013.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cMSXs6cCp7ImA9WhBXEEg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-2583740852924155355</id><published>2013-03-03T21:32:00.004+01:00</published><updated>2013-03-23T16:04:48.518+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-23T16:04:48.518+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="sslaudit" /><category scheme="http://www.blogger.com/atom/ns#" term="Tool" /><title>SSL Audit v.08 released</title><content type="html">I have updated my little TLS/SSL Scanner called "SSL Audit" to version 0.8. I tweaked it slightly but the tool is still based on it's own rudimentary SSL Engine and hence is not limited by the number of ciphersuites and protocols available to...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/NQ0h2Nyqkn8" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=2583740852924155355" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/2583740852924155355?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/2583740852924155355?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/NQ0h2Nyqkn8/tool-ssl-audit-v08-release.html" title="SSL Audit v.08 released" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-ZKY0EELd6_w/UTOyAnrRv3I/AAAAAAAAAao/juIrrJl0zHE/s72-c/sslaudit.PNG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2013/03/tool-ssl-audit-v08-release.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEMGQXc-eyp7ImA9WhNQE0s.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-3993368163968645222</id><published>2012-11-19T22:22:00.000+01:00</published><updated>2012-11-19T23:00:20.953+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-19T23:00:20.953+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Interesting Reads" /><category scheme="http://www.blogger.com/atom/ns#" term="Misc" /><category scheme="http://www.blogger.com/atom/ns#" term="Whitepaper" /><title>OWASP BeNeLux 2012 - Invitation</title><content type="html">I would like to invite you to this years OWASP BeNeLux Event, I won't give a talk this year but I happily invite you as part of OWASP BeNeLux Program Committee: 




Quick Facts

Date : 29-30 Novembre&amp;nbsp;
Location: Leuven (Belgium)
Price :...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/0k9tHDypFrI" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=3993368163968645222" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/3993368163968645222?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/3993368163968645222?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/0k9tHDypFrI/owasp-benelux-2012-invitation.html" title="OWASP BeNeLux 2012 - Invitation" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-ETUpnrWCvsU/UKqq7zPkpGI/AAAAAAAAAZg/YF86oQAFeg4/s72-c/owasp_benelux.JPG" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/11/owasp-benelux-2012-invitation.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cAQ3k8fSp7ImA9WhJXE0o.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-7456078532208424237</id><published>2012-08-05T19:40:00.000+02:00</published><updated>2012-08-07T23:30:42.775+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-08-07T23:30:42.775+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Interesting Reads" /><category scheme="http://www.blogger.com/atom/ns#" term="Misc" /><title>Mistakes made in Incident Response</title><content type="html">[ Updated : Added&amp;nbsp; "10 Common Mistakes of Incident Responders" at the bottom]




The following post will brake one major rule I adhere to&amp;nbsp; when blogging, a post shall have not more than 10% of content that is not authored by myself. The...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/oHYiDeusuok" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=7456078532208424237" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/7456078532208424237?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/7456078532208424237?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/oHYiDeusuok/mistakes-made-in-incident-response.html" title="Mistakes made in Incident Response" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-bt_wmMCFUYI/UB6vKYLUQZI/AAAAAAAAAXM/ryt728K1NRc/s72-c/bd623fa766512fdf6b57db66f522b741.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/08/mistakes-made-in-incident-response.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UBRXo8eyp7ImA9WhJXE0o.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-4184453865683855618</id><published>2012-08-04T16:44:00.000+02:00</published><updated>2012-08-07T23:34:14.473+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-08-07T23:34:14.473+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerabilties" /><title>What you need to know about the vulnerabilities in MSCHAPv2</title><content type="html">A post within the "straight to the meat" category :



There was a talk at Defcon 20 entitled "Defeating PPTP VPNs and WPA2 Enterprise with MS-CHAPv2", by Moxie and David Hulton - the talk announced the implementation of a tool that reduced the...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/gJBnXZ1YaIQ" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=4184453865683855618" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4184453865683855618?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4184453865683855618?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/gJBnXZ1YaIQ/what-you-need-to-know-about.html" title="What you need to know about the vulnerabilities in MSCHAPv2" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-HsxzgDDFsys/UB01zVM_H8I/AAAAAAAAAW4/oblA2ZDbRLw/s72-c/eaps.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/08/what-you-need-to-know-about.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UCRXkzfyp7ImA9WhJXE0o.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-1858116292674118071</id><published>2012-07-02T22:15:00.001+02:00</published><updated>2012-08-07T23:34:24.787+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-08-07T23:34:24.787+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="BTcrack" /><category scheme="http://www.blogger.com/atom/ns#" term="Tool" /><title>BTcrack OSS 1.01 - Updated release</title><content type="html">I updated BTCrack Open Source Edition (BTCrack OSS) to version 1.01 by patching 2 bugs that were reported by Michael Ossmann and Carl Dunhamm. 












Description

The&amp;nbsp; primary goal of BTcrack is to crack/recover the PIN and reconstruct...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/XFxHPYq_RXw" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=1858116292674118071" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/1858116292674118071?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/1858116292674118071?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/XFxHPYq_RXw/btcrack-101-updated-release.html" title="BTcrack OSS 1.01 - Updated release" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-7zwNKMZIYaM/SZHu2yH-lpI/AAAAAAAAACY/39L6QELMd-U/s72-c/btcrack_splash.png" height="72" width="72" /><thr:total>1</thr:total><georss:featurename>Luxembourg</georss:featurename><georss:point>49.815273 6.129583</georss:point><georss:box>49.487429 5.497869000000001 50.143117 6.761297</georss:box><feedburner:origLink>http://blog.zoller.lu/2012/07/btcrack-101-updated-release.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcFQ38zeip7ImA9WhJTFUk.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-6833318658221322963</id><published>2012-06-24T14:45:00.000+02:00</published><updated>2012-06-24T14:46:52.182+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-24T14:46:52.182+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Interesting Reads" /><title>Recommended Reads - Week 25 / 2012</title><content type="html">Publications

In a blink of an eye - there goes your AES Key 
Advances in extracting keying material from Hardware (FPGA)
Visualising Botnets
Why allowing active ipv6 stacks on your network is a bad idea (but we don't route ipv6)
A bad couple of...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/PXLtl_Mz2Ss" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=6833318658221322963" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/6833318658221322963?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/6833318658221322963?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/PXLtl_Mz2Ss/recommended-reads-week-25-2012.html" title="Recommended Reads - Week 25 / 2012" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/06/recommended-reads-week-25-2012.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkYFQXs5eSp7ImA9WhVaE0g.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-8561174980972942296</id><published>2012-06-10T20:48:00.000+02:00</published><updated>2012-06-10T20:48:30.521+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-10T20:48:30.521+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Interesting Reads" /><title>Recommended Reads - Week 23</title><content type="html">Tools / Techniques

How to Extract Flash Objects From Malicious MS Office Documents
Burp plugin for scanning GWT and JSON HTTP requests
SQLite3 Injection Cheat Sheet
Unoffical Guide to scapy
Scapy is immensely powerfull as a seperate tool or as...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/FyUUiledC9U" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=8561174980972942296" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/8561174980972942296?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/8561174980972942296?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/FyUUiledC9U/recommeded-reads-week-23.html" title="Recommended Reads - Week 23" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/06/recommeded-reads-week-23.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04NRnw8eyp7ImA9WhVaFk8.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-6176658019190767483</id><published>2012-06-09T15:00:00.001+02:00</published><updated>2012-06-13T23:13:17.273+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-13T23:13:17.273+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="How-to" /><title>Storing password securely - hashses, salts and bit stretching put into context</title><content type="html">Introduction
Due to the latest row of high profile websites being compromised and parts of the password hashes being published here's a quick crash course on storing passwords "securely", for those that want a quick heads up. In this case I'd define...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/5oeTYBdf5S4" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=6176658019190767483" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/6176658019190767483?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/6176658019190767483?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/5oeTYBdf5S4/storing-password-securely-hashses-salts.html" title="Storing password securely - hashses, salts and bit stretching put into context" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>6</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/06/storing-password-securely-hashses-salts.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkENQHw9fip7ImA9WhVbFkk.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-1093407873155397680</id><published>2012-06-02T14:50:00.000+02:00</published><updated>2012-06-02T15:44:51.266+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-02T15:44:51.266+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Interesting Reads" /><title>Interesting Reads of the Week - Week 22</title><content type="html">My Reads


The Vulnerabilities Market and the Future of Security
Bruce Schneier comments on the evolution of the Vulnerability Market and it's implications, the essay is surprisingly good supplement to the presentation I gave at OWASP on the...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/WMtr9jUvmKs" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=1093407873155397680" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/1093407873155397680?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/1093407873155397680?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/WMtr9jUvmKs/interesting-reads-of-week-week-22.html" title="Interesting Reads of the Week - Week 22" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/06/interesting-reads-of-week-week-22.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkcHQ3g5fCp7ImA9WhVUEkg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-8848427690374817996</id><published>2012-05-17T13:23:00.001+02:00</published><updated>2012-05-17T13:27:12.624+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-17T13:27:12.624+02:00</app:edited><title>Updates and Notable comments :</title><content type="html">Updated Posts :


The Post "Attacker Classes and Pyramid " has been updated to the third iteration. The post was updated in terms of coherency but I also added my OWASP BENELUX presentation entitled "The Rise of the Vulnerability Markets - History,...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/LF0CjUs5kT4" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=8848427690374817996" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/8848427690374817996?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/8848427690374817996?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/LF0CjUs5kT4/updated-posts-and-notable-updates.html" title="Updates and Notable comments :" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-bgX5PhXBxoA/T7Tej5fEJcI/AAAAAAAAAWY/eJlFlwHHEas/s72-c/exploit.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/05/updated-posts-and-notable-updates.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEIFRns7fSp7ImA9WhNREUw.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-5536191032653560194</id><published>2012-05-05T15:47:00.001+02:00</published><updated>2012-11-05T12:55:17.505+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-11-05T12:55:17.505+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Misc" /><title>PCI Compliance, Security in isolated System and Parking Tellers (2nd)</title><content type="html">Following up on my blog post a few months ago entitled "PCI compliance, Security in isolated systems and Parking Tellers Part 1" - I took a brief look the other day at another Ticket issued by a Parking Teller in Luxembourg.



Updated :


Clarified...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/aHI-1zsORLE" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=5536191032653560194" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/5536191032653560194?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/5536191032653560194?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/aHI-1zsORLE/pci-compliance-security-in-isolated.html" title="PCI Compliance, Security in isolated System and Parking Tellers (2nd)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-5AGJ8RxwEhA/T6ggXIHdS8I/AAAAAAAAAVw/OwZaXV_R1ak/s72-c/cc_masked.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/05/pci-compliance-security-in-isolated.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEDQH89fip7ImA9WhVbFks.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-3537530159258704742</id><published>2012-03-24T14:51:00.000+01:00</published><updated>2012-06-02T22:24:31.166+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-02T22:24:31.166+02:00</app:edited><title>CVSS - Common Vulnerability Scoring System - a critique [ Part1 ]</title><content type="html">Ever since I started my career in information security I was both interested and&amp;nbsp;intrigued by metrics applied to vulnerabilities (or metrics in general for that matter). CVSS is&amp;nbsp;certainly&amp;nbsp;not new and I had to make the choice whether...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/8KUdP2NQDV8" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=3537530159258704742" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/3537530159258704742?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/3537530159258704742?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/8KUdP2NQDV8/cvss-common-vulnerability-scoring.html" title="CVSS - Common Vulnerability Scoring System - a critique [ Part1 ]" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-ff9MRpYgixI/T23ApSPJv1I/AAAAAAAAATE/ATdlKcLYAzE/s72-c/CVSS-model-temp.jpg" height="72" width="72" /><thr:total>3</thr:total><feedburner:origLink>http://blog.zoller.lu/2012/03/cvss-common-vulnerability-scoring.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ECQXkycCp7ImA9WhVbFko.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-7314969346455474057</id><published>2011-12-27T16:02:00.003+01:00</published><updated>2012-06-02T23:14:20.798+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-06-02T23:14:20.798+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tool" /><title>"SSL Audit" - Updated release (SSL/TLS Scanner)</title><content type="html">Preamble :


During my research on TLS/SSL Compatibility across different Operation Systems and Browsers I created supporting tools for myself and later decided to release them for the public. 



"SSL Audit" remotely scans web servers for SSL...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/40A547UPkuM" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=7314969346455474057" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/7314969346455474057?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/7314969346455474057?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/40A547UPkuM/ssl-audit-updated-released-ssltls.html" title="&quot;SSL Audit&quot; - Updated release (SSL/TLS Scanner)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-wEtM9J9q31E/Tvnc7CWv6oI/AAAAAAAAASc/VToPKwObotY/s72-c/sslaudit_screenshot.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/12/ssl-audit-updated-released-ssltls.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UEQXo4eSp7ImA9WhRXFkk.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-2463497595311468403</id><published>2011-12-23T13:19:00.000+01:00</published><updated>2011-12-23T14:00:00.431+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-12-23T14:00:00.431+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Whitepaper" /><title>Final - SSL/TLS renegotiation explained (CVE-2009-3555)</title><content type="html">Final release for my paper explaining the different attack vectors and impacts for (CVE-2009-3555) "TLS / SSL renegotiation vulnerability".


Added comments and corrections by Alun Jones (Who I hereby thank for his time)
Changed FTPS...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/SPMFeQtDntE" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=2463497595311468403" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/2463497595311468403?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/2463497595311468403?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/SPMFeQtDntE/final-ssltls-renegotiation-explained.html" title="Final - SSL/TLS renegotiation explained (CVE-2009-3555)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/12/final-ssltls-renegotiation-explained.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcAQng_fip7ImA9WhBQFE4.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-6481594316151050236</id><published>2011-12-06T20:13:00.001+01:00</published><updated>2013-03-16T13:47:23.646+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-16T13:47:23.646+01:00</app:edited><title>PCI compliance, Security in isolated systems and Parking Tellers (Part1)</title><content type="html">A colleague of mine spotted the below while doing expenses - The photograph below shows two separate receipts from two parking buildings that are not far away from each other in central Luxembourg (est. 1km). Both were paid by credit card / debit...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/PVJdzrnO6mQ" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=6481594316151050236" title="9 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/6481594316151050236?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/6481594316151050236?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/PVJdzrnO6mQ/pci-compliance-security-in-isolated.html" title="PCI compliance, Security in isolated systems and Parking Tellers (Part1)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-hshVF4Ayhig/Tt5pUM829eI/AAAAAAAAASI/6QSN2hfFI1U/s72-c/quittung.png" height="72" width="72" /><thr:total>9</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/12/pci-compliance-security-in-isolated.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UDQ384cSp7ImA9WhRTEUg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-1150969640359588852</id><published>2011-11-01T13:57:00.002+01:00</published><updated>2011-11-01T14:47:52.139+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-11-01T14:47:52.139+01:00</app:edited><title>Blog cleanup</title><content type="html">As some regulars might have noticed I restructed this blog a bit trying to get rid of some clutter. At the same time I updated a few specific pages I wanted to point out :


Vulnerability Coordination Policy ( More backround on the "why" )
About Me...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/QRum0TeKmec" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=1150969640359588852" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/1150969640359588852?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/1150969640359588852?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/QRum0TeKmec/blog-cleanup_01.html" title="Blog cleanup" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/11/blog-cleanup_01.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMGRHY9eSp7ImA9WhdaFkg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-8294795631782082724</id><published>2011-10-26T20:41:00.001+02:00</published><updated>2011-10-26T21:13:45.861+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-26T21:13:45.861+02:00</app:edited><title>THC SSL DoS - vs - Per Design</title><content type="html">Since this is a rather old topic with both sides having valid points I will keep this post short and sweet. I have had no time to measure of investigate in depth and I don't think I will find any.



Both have understandable view points, so let's...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/ZOBgjNFBXvA" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=8294795631782082724" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/8294795631782082724?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/8294795631782082724?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/ZOBgjNFBXvA/thc-ssl-dos-vs-per-design.html" title="THC SSL DoS - vs - Per Design" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/10/thc-ssl-dos-vs-per-design.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYHQn04fip7ImA9WhVUEkg.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-5621727569677144142</id><published>2011-10-18T20:20:00.001+02:00</published><updated>2012-05-17T13:12:13.336+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-05-17T13:12:13.336+02:00</app:edited><title>Attacker Classes and Pyramid (Version 3)</title><content type="html">This is a living blog post I will update whenever I have time and new ideas.



TOC 


Introduction
Updates
Attacker Classes
Attacker Pyramid
Q&amp;amp;A

Introduction

The other day I was brainstorming further on the attacker classes I came up with...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/LIoHUHR2NfY" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=5621727569677144142" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/5621727569677144142?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/5621727569677144142?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/LIoHUHR2NfY/attacker-classes-and-pyramid-version-1.html" title="Attacker Classes and Pyramid (Version 3)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-nfFCb7SQkyE/T7TaBKdsgHI/AAAAAAAAAV8/ZISLX3VtE1Q/s72-c/attacker_pyramid_attacker_class.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/10/attacker-classes-and-pyramid-version-1.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ENRXk_cSp7ImA9WhdUFEQ.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-7096697410885773442</id><published>2011-09-26T16:18:00.000+02:00</published><updated>2011-10-01T21:01:34.749+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-01T21:01:34.749+02:00</app:edited><title>The BEAST summary - TLS, CBC, Countermeasures (Update 4)</title><content type="html">Lots of good information floating on the internet on the Proof of Concept (dubbed 'BEAST) against TLS 1.0 by Juliano Rizzo and Thai Duong at the Ekoparty. 




This blog post will be continuously updated as new items and possible mitigation...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/Mvqv5fDWooc" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=7096697410885773442" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/7096697410885773442?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/7096697410885773442?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/Mvqv5fDWooc/beast-summary-tls-cbc-countermeasures.html" title="The BEAST summary - TLS, CBC, Countermeasures (Update 4)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-DKzv733c-xU/ToCBwDmahUI/AAAAAAAAAQA/hzyW_XDU97E/s72-c/aaaaa2.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/09/beast-summary-tls-cbc-countermeasures.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8EQXw9eCp7ImA9WhdVGUs.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-4293378804439286873</id><published>2011-09-20T17:21:00.003+02:00</published><updated>2011-09-25T17:33:20.260+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-25T17:33:20.260+02:00</app:edited><title>TLS/SSL hardening and compatibility Report 2011</title><content type="html">This is a cross post from the G-SEC blog



My professional and private commitments made it difficult to maintain a healthy blogging style, I am trying to get back to some blogging on a more regular basis.




Quick Update:



G-SEC does&amp;nbsp;no...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/Eo4LpJM9MZE" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=4293378804439286873" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4293378804439286873?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4293378804439286873?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/Eo4LpJM9MZE/tlsssl-hardening-and-compatibility.html" title="TLS/SSL hardening and compatibility Report 2011" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-WRP9DFtnDyw/Tn9JsHDiAvI/AAAAAAAAAPk/knGPXb1xO2k/s72-c/aaaaa2.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/09/tlsssl-hardening-and-compatibility.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8ARH89fCp7ImA9WhdVGEo.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-231612040921714654</id><published>2011-08-23T20:47:00.000+02:00</published><updated>2011-09-24T17:24:05.164+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-24T17:24:05.164+02:00</app:edited><title>What did PHP crypt() and Alzheimer have in common ?</title><content type="html">I stumbled across this weird PHP bug in the crypt() implementation (version&amp;nbsp;5.3.7RC5) [1]
The bug reporter states that :


"If crypt() is executed with MD5 salts, the return value consists of the salt only." 
In other words the call...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/PsKLpyLTtmU" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=231612040921714654" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/231612040921714654?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/231612040921714654?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/PsKLpyLTtmU/what-does-php-crypt-and-alzheimer-had.html" title="What did PHP crypt() and Alzheimer have in common ?" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/08/what-does-php-crypt-and-alzheimer-had.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D04ARn8-eip7ImA9WhBQFEk.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-4147813315997820284</id><published>2011-08-01T22:20:00.000+02:00</published><updated>2013-03-16T15:59:07.152+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2013-03-16T15:59:07.152+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="How-to" /><category scheme="http://www.blogger.com/atom/ns#" term="About" /><category scheme="http://www.blogger.com/atom/ns#" term="Lectures" /><category scheme="http://www.blogger.com/atom/ns#" term="Misc" /><title>Tools, Whitepapers, Talks</title><content type="html">Talks / Lectures


During my career I had the opportunity to present my thoughts and views on Information Security to numerous people and organizations, below is a list of conferences I had the pleasure to present at.


2006 Luxembourg...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/Zl3UNvxhQQM" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=4147813315997820284" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4147813315997820284?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4147813315997820284?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/Zl3UNvxhQQM/tools-whitepapers-talks.html" title="Tools, Whitepapers, Talks" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-vrEWui6wxic/ToTTGNrHmkI/AAAAAAAAAQo/xK-oMkmoYzg/s72-c/avdefenseindepth2376769016_4e9c6e2d7c_b.jpg" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://blog.zoller.lu/2011/08/tools-whitepapers-talks.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0MNQHw4fCp7ImA9WhdVGEo.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-4220293074585707444</id><published>2010-08-22T23:33:00.015+02:00</published><updated>2011-09-24T17:51:31.234+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-24T17:51:31.234+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="0day" /><title>CVE-2010-x+n - Loadlibrary/Getprocaddress roars its evil head in 2010</title><content type="html">Subscribe to the RSS feed in case you are interested in updates






After Acrossecurity, published an interesting vulnerability and HDmoore appears to have stumbled on the same issue, I decided to investigate on my own. I am not 100% sure it's the...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/C6gVneAPWbY" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=4220293074585707444" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4220293074585707444?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/4220293074585707444?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/C6gVneAPWbY/cve-2010-xn-loadlibrarygetprocaddress.html" title="CVE-2010-x+n - Loadlibrary/Getprocaddress roars its evil head in 2010" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_LApW097P-0I/THGVpjhPktI/AAAAAAAAAMA/nGCcvsdZ9Io/s72-c/dll.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://blog.zoller.lu/2010/08/cve-2010-xn-loadlibrarygetprocaddress.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8GR3wyfSp7ImA9WxFaFEs.&quot;"><id>tag:blogger.com,1999:blog-3832621951001364942.post-3121983137680607621</id><published>2010-07-18T15:14:00.001+02:00</published><updated>2010-07-18T16:37:06.295+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-18T16:37:06.295+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="0day" /><title>CVE-2010-2568 - LNK Code execution - Proof of concept (Update)</title><content type="html">Subscribe to the RSS feed in case you are interested in updates



&amp;nbsp;Ivanlef0u released a POC for the exploit used in targeted attacks :http://ivanlef0u.nibbles.fr/repo/suckme.rar 


More information :ISC SANS 
USCERT 940193
Microsoft...&lt;br/&gt;
&lt;br/&gt;
Read more....&lt;img src="http://feeds.feedburner.com/~r/thierryzoller/~4/Uk9OAOexbe0" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=3832621951001364942&amp;postID=3121983137680607621" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/3121983137680607621?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3832621951001364942/posts/default/3121983137680607621?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thierryzoller/~3/Uk9OAOexbe0/cve-2010-2568-lnk-code-execution-proof.html" title="CVE-2010-2568 - LNK Code execution - Proof of concept (Update)" /><author><name>Thierry Zoller</name><uri>http://www.blogger.com/profile/14432216409558141236</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="19" src="http://1.bp.blogspot.com/-OUeVFgdBXdk/UB62hsC2E3I/AAAAAAAAAYU/2Ndr3yTWEbs/s220/380103_2658571636323_1422282575_n.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://blog.zoller.lu/2010/07/cve-2010-2568-lnk-code-execution-proof.html</feedburner:origLink></entry></feed>
