<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;D08CRHk-eyp7ImA9WhRbEEo.&quot;"><id>tag:blogger.com,1999:blog-15117118</id><updated>2012-02-01T03:57:45.753-02:00</updated><category term="linux" /><category term="artigos" /><category term="selinux" /><category term="modsecurity" /><category term="openbsd" /><category term="apresentações" /><category term="sysadmin" /><category term="mysql" /><category term="apparmor" /><category term="apple" /><category term="vmware" /><category term="cissp" /><category term="red hat" /><category term="nagios" /><category term="outros" /><category term="postfix" /><category term="fedora" /><category term="wine" /><category term="django" /><category term="kde" /><category term="fisl" /><category term="rhel" /><category term="dell" /><category term="segurança" /><category term="ldap" /><category term="wireless" /><category term="python" /><category term="spam" /><category term="kernel" /><category term="mac" /><category term="script" /><category term="owasp" /><category term="waf" /><category term="eventos" /><category term="video" /><category term="windows" /><category term="freebsd" /><category term="performance" /><category term="fun" /><category term="ubuntu" /><category term="ossec" /><category term="ipv6" /><category term="vídeos" /><category term="tchelinux" /><title>Zucco Weblog</title><subtitle type="html" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://jczucco.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>259</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ZuccoWeblog" /><feedburner:info uri="zuccoweblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;CUIDRHY7eip7ImA9WhdaFkk.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-4460636904436422552</id><published>2011-10-26T13:30:00.005-02:00</published><updated>2011-10-26T13:39:35.802-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-26T13:39:35.802-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ossec" /><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Third Annual Week of OSSEC</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.ossec.net/img/ossec_logo.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 191px; height: 81px;" src="http://www.ossec.net/img/ossec_logo.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   O blog &lt;a href="http://www.immutablesecurity.com"&gt;Immutable Security&lt;/a&gt; realiza a cada ano a "Semana do &lt;a href="http://www.ossec.net"&gt;OSSEC&lt;/a&gt;. Esse é o terceiro ano, é interessante ler os posts dos demais anos: &lt;a href="http://www.ossec.net/main/week-of-ossec"&gt;aqui&lt;/a&gt; e &lt;a href="http://www.ossec.net/main/week-of-ossec-2woo-oct-17-23"&gt;aqui&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;   Eu prestei um mini-curso de um dia sobre o OSSEC no GTS-16. A apresentação pode ser vista abaixo. Segue os links para download dos vídeos do mini-curso:&lt;br /&gt;&lt;br /&gt;&lt;a href="ftp://ftp.registro.br/pub/gter/gter30/videos/mp4/Implementando_o_OSSEC_HIDS-Parte1.mp4"&gt;Vídeo parte 1&lt;/a&gt; - &lt;a href="ftp://ftp.registro.br/pub/gter/gter30/videos/mp4/Implementando_o_OSSEC_HIDS-Parte2.mp4"&gt;Vídeo parte 2&lt;/a&gt; - &lt;a href="ftp://ftp.registro.br/pub/gter/gter30/videos/mp4/Implementando_o_OSSEC_HIDS-Parte3.mp4"&gt;Vídeo parte 3&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px" id="__ss_6134128"&gt; &lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/jczucco/implementing-ossec" title="Implementing ossec" target="_blank"&gt;Implementing ossec&lt;/a&gt;&lt;/strong&gt; &lt;iframe src="http://www.slideshare.net/slideshow/embed_code/6134128" width="425" height="355" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"&gt;&lt;/iframe&gt; &lt;div style="padding:5px 0 12px"&gt; View more &lt;a href="http://www.slideshare.net/" target="_blank"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/jczucco" target="_blank"&gt;jczucco&lt;/a&gt; &lt;/div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-4460636904436422552?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TDx4V6MGZ--dubOgdphqVaflrGY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TDx4V6MGZ--dubOgdphqVaflrGY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TDx4V6MGZ--dubOgdphqVaflrGY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TDx4V6MGZ--dubOgdphqVaflrGY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/JWK-7XAmAQo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/4460636904436422552/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=4460636904436422552&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/4460636904436422552?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/4460636904436422552?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/JWK-7XAmAQo/third-annual-week-of-ossec.html" title="Third Annual Week of OSSEC" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/10/third-annual-week-of-ossec.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8MRXk7eCp7ImA9WhdUEUg.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-6954169419876074326</id><published>2011-09-27T16:46:00.001-03:00</published><updated>2011-09-27T16:48:04.700-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-27T16:48:04.700-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><category scheme="http://www.blogger.com/atom/ns#" term="eventos" /><title>OWASP AppSec Latin America 2011</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-nGy_Ijc-dK8/ToIobTm0MGI/AAAAAAAAAN0/BvDE5h4817g/s1600/FlyerOwasp2011.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 280px; height: 400px;" src="http://2.bp.blogspot.com/-nGy_Ijc-dK8/ToIobTm0MGI/AAAAAAAAAN0/BvDE5h4817g/s400/FlyerOwasp2011.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5657128531515420770" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-6954169419876074326?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/36IPKIeKPgdyFs2a3_Rk8vxmj-E/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/36IPKIeKPgdyFs2a3_Rk8vxmj-E/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/36IPKIeKPgdyFs2a3_Rk8vxmj-E/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/36IPKIeKPgdyFs2a3_Rk8vxmj-E/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/BUiV8H2Lv4E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/6954169419876074326/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=6954169419876074326&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/6954169419876074326?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/6954169419876074326?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/BUiV8H2Lv4E/owasp-appsec-latin-america-2011.html" title="OWASP AppSec Latin America 2011" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-nGy_Ijc-dK8/ToIobTm0MGI/AAAAAAAAAN0/BvDE5h4817g/s72-c/FlyerOwasp2011.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/09/owasp-appsec-latin-america-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0AEQn89eip7ImA9WhdWEUU.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-121189736750329869</id><published>2011-09-04T22:06:00.004-03:00</published><updated>2011-09-04T22:21:43.162-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-04T22:21:43.162-03:00</app:edited><title>Programação da OWASP AppSec Latin América 2011</title><content type="html">
&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-rGk3W1syrlo/TmQjxE-ezJI/AAAAAAAAANc/06Vi0x6QcD8/s1600/6outubro.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 450px; height: 369px;" src="http://1.bp.blogspot.com/-rGk3W1syrlo/TmQjxE-ezJI/AAAAAAAAANc/06Vi0x6QcD8/s400/6outubro.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5648679158685813906" /&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-S_fPhwF1cZ4/TmQj4c3s5fI/AAAAAAAAANk/eHaCeUS873s/s1600/7outubro.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 450px; height: 366px;" src="http://4.bp.blogspot.com/-S_fPhwF1cZ4/TmQj4c3s5fI/AAAAAAAAANk/eHaCeUS873s/s400/7outubro.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5648679285358913010" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-121189736750329869?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/hhnwoTjaXWrVvygM4NNqUwJhxOE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hhnwoTjaXWrVvygM4NNqUwJhxOE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/hhnwoTjaXWrVvygM4NNqUwJhxOE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hhnwoTjaXWrVvygM4NNqUwJhxOE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/PSZuzrMkG9E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/121189736750329869/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=121189736750329869&amp;isPopup=true" title="2 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/121189736750329869?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/121189736750329869?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/PSZuzrMkG9E/programacao-da-owasp-appsec-latin.html" title="Programação da OWASP AppSec Latin América 2011" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-rGk3W1syrlo/TmQjxE-ezJI/AAAAAAAAANc/06Vi0x6QcD8/s72-c/6outubro.png" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/09/programacao-da-owasp-appsec-latin.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEUGRHg_eyp7ImA9WhdXF08.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2317569556123385870</id><published>2011-08-30T14:41:00.002-03:00</published><updated>2011-08-30T14:43:45.643-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-08-30T14:43:45.643-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><title>OWASP AppSec Latin América 2011 - Inscrições Abertas</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-sb-EQg9V19g/Tl0hM_t2qzI/AAAAAAAAANU/vqArx_aHbfo/s1600/AppSec_Brasil_11_medio.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 166px;" src="http://1.bp.blogspot.com/-sb-EQg9V19g/Tl0hM_t2qzI/AAAAAAAAANU/vqArx_aHbfo/s320/AppSec_Brasil_11_medio.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5646706014938377010" /&gt;&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt; Inscrições abertas para a &lt;a href="http://www.appseclatam.org"&gt;OWASP AppSec Latin América 2011&lt;/a&gt;. Confira os valores e os treinamentos em &lt;a href="http://t.co/2lancJi"&gt;http://t.co/2lancJi&lt;/a&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2317569556123385870?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/OdrasrlV4GxVr8n-37upzEKMgqs/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OdrasrlV4GxVr8n-37upzEKMgqs/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/OdrasrlV4GxVr8n-37upzEKMgqs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OdrasrlV4GxVr8n-37upzEKMgqs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/Idmz7nrrb7o" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2317569556123385870/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2317569556123385870&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2317569556123385870?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2317569556123385870?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/Idmz7nrrb7o/owasp-appsec-latin-america-2011.html" title="OWASP AppSec Latin América 2011 - Inscrições Abertas" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-sb-EQg9V19g/Tl0hM_t2qzI/AAAAAAAAANU/vqArx_aHbfo/s72-c/AppSec_Brasil_11_medio.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/08/owasp-appsec-latin-america-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak8DQHo4eip7ImA9WhdTF0k.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-535145764095377099</id><published>2011-07-15T12:59:00.008-03:00</published><updated>2011-07-15T13:54:31.432-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-15T13:54:31.432-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="linux" /><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><category scheme="http://www.blogger.com/atom/ns#" term="modsecurity" /><title>Installing ModSecurity 2.6.1-rc1 + CRS (Core Rule Set) 2.2.0</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-E5g1yEm2-vA/TiBkcU1sdoI/AAAAAAAAALQ/eSu-OFlL5wc/s1600/modsec.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 270px; height: 74px;" src="http://4.bp.blogspot.com/-E5g1yEm2-vA/TiBkcU1sdoI/AAAAAAAAALQ/eSu-OFlL5wc/s400/modsec.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5629609972006155906" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.modsecurity.org/g/button-mscorerules.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 233px; height: 80px;" src="http://www.modsecurity.org/g/button-mscorerules.gif" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This post will help you how to install and configure &lt;a href="http://www.modsecurity.org"&gt;ModSecurity&lt;/a&gt; Web Application Firewall in your system, with the &lt;a href="https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project"&gt;Core Rule Set 2.2.0&lt;/a&gt;. The operations system base is CentOS 5.6.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Install dependencies:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# yum install gcc openssl-devel openssl apr-util-devel apr-devel pcre pcre-devel libjpeg-devel gd-devel libpng-devel libjpeg gd libpng gettext gettext-devel libmcrypt-devel libmcrypt libxml2 libxml2-devel bison zlib zlib-devel bzip2 bzip2-devel libtool libtool-ltdl readline readline-devel ncurses ncurses-devel curl curl-devel&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Get the source codes:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;- Apache: &lt;a href="http://httpd.apache.org/download.cgi"&gt;http://httpd.apache.org/download.cgi&lt;/a&gt;&lt;br /&gt;- Lua: &lt;a href="http://www.lua.org/ftp/lua-5.1.4.tar.gz"&gt;http://www.lua.org/ftp/lua-5.1.4.tar.gz&lt;/a&gt;&lt;br /&gt;- ModSecurity: &lt;a href="http://www.modsecurity.org/download/modsecurity-apache_2.6.1-rc1.tar.gz"&gt;http://www.modsecurity.org/download/modsecurity-apache_2.6.1-rc1.tar.gz&lt;/a&gt;&lt;br /&gt;- Core Rule Set: &lt;a href="http://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/"&gt;http://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Check the integrity of sources with md5sum or sha1sum&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;-  Install &lt;a href="http://httpd.apache.org"&gt;Apache&lt;/a&gt; from source:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# ./configure --prefix=/var/www --enable-auth-digest --enable-mime-magic --enable-usertrack --enable-ssl --enable-http --disable-cgi --enable-vhost-alias --disable-userdir --enable-so --enable-unique-id --enable-rewrite --with-z --disable-dav --disable-proxy --with-pcre --enable-deflate --enable-expires&lt;br /&gt;&lt;br /&gt;# make&lt;br /&gt;&lt;br /&gt;# make install&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Compile &lt;a href="http://www.lua.org"&gt;Lua&lt;/a&gt;:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# tar xvfz lua-5.1.4.tar.gz&lt;br /&gt;# cd lua-5.1.4&lt;br /&gt;# make all linux&lt;br /&gt;# make install INSTALL_TOP=/usr/local/lua-5.1.4&lt;br /&gt;# cd src&lt;br /&gt;# rm -f lua.o luac.o print.o &amp;&amp; gcc -shared -Wall -O2 -o liblua5.1.so *.o&lt;br /&gt;# cp liblua5.1.so /usr/local/lua-5.1.4/lib&lt;br /&gt;# ln -s /usr/local/lua-5.1.4 /usr/local/lua&lt;br /&gt;# echo "/usr/local/lua/lib" &gt;&gt; /etc/ld.so.conf&lt;br /&gt;# ldconfig&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Compile &lt;a href="http://www.modsecurity.org"&gt;ModSecurity&lt;/a&gt;:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# tar xvfz modsecurity-apache_2.6.1-rc1.tar.gz&lt;br /&gt;# cd modsecurity-apache_2.6.1-rc1&lt;br /&gt;# ./configure --with-apxs=/var/www/bin/apxs --with-lua=/usr/local/lua&lt;br /&gt;# make&lt;br /&gt;# make install&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Install and configure Core Rule Set:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# mkdir /var/www/conf/modsecurity&lt;br /&gt;# mkdir /var/www/conf/modsecurity/crs&lt;br /&gt;# cp modsecurity-apache_2.6.1-rc1/modsecurity.conf-recommended /var/www/conf/modsecurity/modsecurity.conf&lt;br /&gt;# touch /var/www/conf/modsecurity/whitelist.conf&lt;br /&gt;&lt;br /&gt;# tar xvfz modsecurity-crs_2.2.0.tar.gz&lt;br /&gt;# cp -a modsecurity-crs_2.2.0/* /var/www/conf/modsecurity/crs&lt;br /&gt;&lt;br /&gt;# cd /var/www/conf/modsecurity/crs&lt;br /&gt;# for f in `ls base_rules/` ; do ln -s ../base_rules/$f activated_rules/$f ; done&lt;br /&gt;# cp modsecurity_crs_10_config.conf.example modsecurity_crs_10_config.conf&lt;br /&gt;# ln -s ../modsecurity_crs_10_config.conf activated_rules/&lt;br /&gt;# ls -l activated_rules/    /* Check simbolic links */&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Configure Apache (httpd.conf)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;LoadFile /usr/lib/libxml2.so.2&lt;br /&gt;LoadFile /usr/local/lua/lib/liblua5.1.so&lt;br /&gt;LoadModule security2_module modules/mod_security2.so&lt;br /&gt;# CRS&lt;br /&gt;&amp;lt;IfModule security2_module&amp;gt;&lt;br /&gt;  Include conf/modsecurity/modsecurity.conf&lt;br /&gt;  Include conf/modsecurity/whitelist.conf&lt;br /&gt;  Include conf/modsecurity/crs/modsecurity_crs_10_config.conf&lt;br /&gt;  Include conf/modsecurity/crs/activated_rules/*.conf&lt;br /&gt;&amp;lt;/IfModule&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Edit modsecurity.conf:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;SecRuleEngine On&lt;br /&gt;SecAuditLog logs/modsec_audit.log&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Start Apache and check error_log&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;[warn] Init: Session Cache is not configured [hint: SSLSessionCache]&lt;br /&gt;[notice] ModSecurity for Apache/2.6.1-rc1 (http://www.modsecurity.org/) configured.&lt;br /&gt;[notice] ModSecurity: APR compiled version="1.2.7"; loaded version="1.2.7"&lt;br /&gt;[notice] ModSecurity: PCRE compiled version="6.6"; loaded version="5.0 13-Sep-2004"&lt;br /&gt;[notice] ModSecurity: LUA compiled version="Lua 5.1"&lt;br /&gt;[notice] ModSecurity: LIBXML compiled version="2.6.26"&lt;br /&gt;[notice] Digest: generating secret for digest authentication ...&lt;br /&gt;[notice] Digest: done&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;- Test your ModSecurity:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Access one url with a blocked estension, like: &lt;span style="font-weight:bold;"&gt;http://server/test.sql&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;You will see in &lt;span style="font-weight:bold;"&gt;apache error_log&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;[error] [client 127.0.0.1] ModSecurity: Access denied with code 403 (phase 2). String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .resources/ .resx/ .sql/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. [file "/var/www/conf/modsecurity/crs/activated_rules/modsecurity_crs_30_http_policy.conf"] [line "88"] [id "960035"] [msg "URL file extension is restricted by policy"] [data ".alq"] [severity "CRITICAL"] [tag "POLICY/EXT_RESTRICTED"] [tag "WASCTC/WASC-15"] [tag "OWASP_TOP_10/A7"] [tag "PCI/6.5.10"] [hostname "localhost"] [uri "/test.SQL"] [unique_id "Th8c038AAAEAAGugG2kAAAAD"]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;   Now, your work is &lt;span style="font-weight:bold;"&gt;just in the begining&lt;/span&gt;. Now you have to test your application for false positives and false negatives.&lt;br /&gt;  &lt;br /&gt;   If you use Wordpress, joomla, phpbb, etc, check the &lt;span style="font-weight:bold;"&gt;slr_rules&lt;/span&gt; directory. You have to enable it in httpd.conf.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-535145764095377099?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/_a_qw7OWa6Jm9WGngZ1FJ0qKn54/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_a_qw7OWa6Jm9WGngZ1FJ0qKn54/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/_a_qw7OWa6Jm9WGngZ1FJ0qKn54/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/_a_qw7OWa6Jm9WGngZ1FJ0qKn54/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/g7dR5WZ5OY0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/535145764095377099/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=535145764095377099&amp;isPopup=true" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/535145764095377099?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/535145764095377099?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/g7dR5WZ5OY0/installing-modsecurity-261-rc1-crs-core.html" title="Installing ModSecurity 2.6.1-rc1 + CRS (Core Rule Set) 2.2.0" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-E5g1yEm2-vA/TiBkcU1sdoI/AAAAAAAAALQ/eSu-OFlL5wc/s72-c/modsec.png" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/07/installing-modsecurity-261-rc1-crs-core.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkAEQHo6cSp7ImA9WhZUEU0.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2501919752298753216</id><published>2011-06-03T09:18:00.003-03:00</published><updated>2011-06-03T09:38:21.419-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-03T09:38:21.419-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Usando 2 fatores de autenticação no Google</title><content type="html">Devido aos &lt;a href="http://www.searchthenetnow.com/the-truth-behind-gmail-hack/2011/06/02/"&gt;recentes acontecimentos&lt;/a&gt; com contas do Google, resolvi contribuir na divulgação do uso de 2 fatores de autenticação, conforme explicado no vídeo (em inglês). Para quem não sabe o que é fator de autenticação, pode escutar esse &lt;a href="http://twit.tv/sn90"&gt;podcast&lt;/a&gt; ou ler o texto abaixo:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Fatores de autenticação&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Os fatores de autenticação para humanos são normalmente classificados em três casos:&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight:bold;"&gt;Aquilo que o usuário é&lt;/span&gt; (impressão digital, padrão retinal, sequência de DNA, padrão de voz, reconhecimento de assinatura, sinais elétricos unicamente identificáveis produzidos por um corpo vivo, ou qualquer outro meio biométrico).&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight:bold;"&gt;Aquilo que o usuário tem&lt;/span&gt; (cartão de identificação, security token, software token ou telefone celular)&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight:bold;"&gt;Aquilo que o usuário sabe&lt;/span&gt; (senha, frase de segurança, PIN)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Frequentemente é utilizada uma &lt;span style="font-weight:bold;"&gt;combinação de dois ou mais métodos&lt;/span&gt;. Um banco, por exemplo, pode requisitar uma "frase de segurança" além da senha, neste caso o termo "&lt;span style="font-weight:bold;"&gt;autenticação de dois fatores&lt;/span&gt;" é utilizado.Também pode ser chamado de &lt;span style="font-weight:bold;"&gt;autenticação forte&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;iframe width="560" height="349" src="http://www.youtube.com/embed/zMabEyrtPRg" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2501919752298753216?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uCoBMJuA3qoeS2zlW9-6b8Zuwbc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uCoBMJuA3qoeS2zlW9-6b8Zuwbc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uCoBMJuA3qoeS2zlW9-6b8Zuwbc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uCoBMJuA3qoeS2zlW9-6b8Zuwbc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/WN5Go3OVS58" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2501919752298753216/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2501919752298753216&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2501919752298753216?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2501919752298753216?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/WN5Go3OVS58/usando-2-fatores-de-autenticacao-no.html" title="Usando 2 fatores de autenticação no Google" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/zMabEyrtPRg/default.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/06/usando-2-fatores-de-autenticacao-no.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUHRHc-fip7ImA9WhZQFkQ.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-1295820211317852256</id><published>2011-04-24T21:31:00.005-03:00</published><updated>2011-04-24T21:43:55.956-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-24T21:43:55.956-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Hardening de Sistemas Operacionais e Serviços</title><content type="html">Quer deixar seu sistema mais &lt;span style="font-weight:bold;"&gt;seguro&lt;/span&gt; e não sabe por onde começar ? &lt;br /&gt;&lt;br /&gt;Existem diversos guias/checklists disponíveis na internet para lhe ajudar nessa tarefa:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- NIST National Checklist Program Repository docs by OS - &lt;a href="http://web.nvd.nist.gov/view/ncp/repository"&gt;http://web.nvd.nist.gov/view/ncp/repository&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-vLelk7BlhUA/TbTBuEDsNSI/AAAAAAAAAJo/tTuwHfY95Pc/s1600/ncplogobg.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 195px; height: 112px;" src="http://3.bp.blogspot.com/-vLelk7BlhUA/TbTBuEDsNSI/AAAAAAAAAJo/tTuwHfY95Pc/s400/ncplogobg.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5599313233835734306" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- NSA Security Configuration Guides: &lt;a href="http://www.nsa.gov/ia/guidance/security_configuration_guides/current_guides.shtml"&gt;http://www.nsa.gov/ia/guidance/security_configuration_guides/current_guides.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-VV0YE2lKx-8/TbTDB0MwxbI/AAAAAAAAAJw/PxeKtWPZydw/s1600/nsa.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 300px; height: 300px;" src="http://2.bp.blogspot.com/-VV0YE2lKx-8/TbTDB0MwxbI/AAAAAAAAAJw/PxeKtWPZydw/s400/nsa.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5599314672687826354" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- CIS Security Configuration Benchmarks: &lt;a href="http://cisecurity.org"&gt;http://cisecurity.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-M6Y_tonQtWM/TbTDcn9pvjI/AAAAAAAAAJ4/5aOBZczgO04/s1600/logo-header.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 283px; height: 82px;" src="http://2.bp.blogspot.com/-M6Y_tonQtWM/TbTDcn9pvjI/AAAAAAAAAJ4/5aOBZczgO04/s400/logo-header.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5599315133259693618" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Como você pode ver, há bastante trabalho a ser feito. Baixe os guias/checklists e comece já!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-1295820211317852256?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/1Xmdamg18qQ1WunoPFUUbQxMn-c/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1Xmdamg18qQ1WunoPFUUbQxMn-c/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/1Xmdamg18qQ1WunoPFUUbQxMn-c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/1Xmdamg18qQ1WunoPFUUbQxMn-c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/UYJGbC3vroI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/1295820211317852256/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=1295820211317852256&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/1295820211317852256?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/1295820211317852256?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/UYJGbC3vroI/hardening-de-sistemas-operacionais-e.html" title="Hardening de Sistemas Operacionais e Serviços" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-vLelk7BlhUA/TbTBuEDsNSI/AAAAAAAAAJo/tTuwHfY95Pc/s72-c/ncplogobg.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/04/hardening-de-sistemas-operacionais-e.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0EAQ3o4cCp7ImA9WhZQFU8.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-6087194680283830448</id><published>2011-04-22T23:24:00.002-03:00</published><updated>2011-04-22T23:27:22.438-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-22T23:27:22.438-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Segurança Física e Proteção de Dados em um Datacenter do Google</title><content type="html">Muito bom esse vídeo sobre os controles de acesso e segurança de dados dos datacenters do google. É possível habilitar as legendas e a tradução automática para português:&lt;br /&gt;&lt;br /&gt;&lt;object style="height: 390px; width: 640px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/1SCZzgfdTBo?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/1SCZzgfdTBo?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="640" height="390"&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-6087194680283830448?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Rl_x16od9Nv8sgX1r0JJCx9XvVM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rl_x16od9Nv8sgX1r0JJCx9XvVM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Rl_x16od9Nv8sgX1r0JJCx9XvVM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rl_x16od9Nv8sgX1r0JJCx9XvVM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/olg55-bOMbo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/6087194680283830448/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=6087194680283830448&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/6087194680283830448?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/6087194680283830448?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/olg55-bOMbo/seguranca-fisica-e-protecao-de-dados-em.html" title="Segurança Física e Proteção de Dados em um Datacenter do Google" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/04/seguranca-fisica-e-protecao-de-dados-em.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMNRXY-fSp7ImA9WhZQE00.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2485277864325747591</id><published>2011-04-16T14:20:00.004-03:00</published><updated>2011-04-20T08:54:54.855-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-20T08:54:54.855-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><category scheme="http://www.blogger.com/atom/ns#" term="eventos" /><title>Pesquisa sobre Treinamentos para a AppSec Latin America 2011</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-nLxLUT9ko4g/Ta7Jfhx-CcI/AAAAAAAAAJg/r0dz8Q_OSfQ/s1600/AppSec_Brasil_11_menor.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 166px;" src="http://1.bp.blogspot.com/-nLxLUT9ko4g/Ta7Jfhx-CcI/AAAAAAAAAJg/r0dz8Q_OSfQ/s320/AppSec_Brasil_11_menor.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5597632930349189570" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.appseclatam.org"&gt;OWASP Global AppSec Latin América 2011&lt;/a&gt; irá acontecer no Brasil na cidade de Porto Alegre, estado do Rio Grande do Sul nos dias 04 à 07 de outubro de 2011. Ocorrerão cursos no dias 4 e 5 de outubro, e as sessões plenárias nos dias 6 e 7 de outubro.&lt;br /&gt;&lt;br /&gt;Está sendo realizada uma pesquisa sobre os temas para treinamentos. Você pode ajudar, respondendo a pesquisa no seguinte endereço:&lt;br /&gt;&lt;a href="http://www.surveymonkey.com/s/3RCZ9RR"&gt;http://www.surveymonkey.com/s/3RCZ9RR&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Em breve serão anunciados os Call for Papers e Call for Trainings. Acompanhe através do site &lt;a href="http://www.appseclatam.org"&gt;http://www.appseclatam.org&lt;/a&gt; ou pelo twitter &lt;a href="https://twitter.com/AppSecLatam"&gt;AppSecLatam&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2485277864325747591?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ExBkvKLfUoLBk0ee_Myx14etbe4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ExBkvKLfUoLBk0ee_Myx14etbe4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ExBkvKLfUoLBk0ee_Myx14etbe4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ExBkvKLfUoLBk0ee_Myx14etbe4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/kfwp3jWvKf8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2485277864325747591/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2485277864325747591&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2485277864325747591?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2485277864325747591?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/kfwp3jWvKf8/owasp-global-appsec-latin-america-2011.html" title="Pesquisa sobre Treinamentos para a AppSec Latin America 2011" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-nLxLUT9ko4g/Ta7Jfhx-CcI/AAAAAAAAAJg/r0dz8Q_OSfQ/s72-c/AppSec_Brasil_11_menor.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/04/owasp-global-appsec-latin-america-2011.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0EGSX07fyp7ImA9WhZREEg.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-726821106709254799</id><published>2011-04-05T23:05:00.001-03:00</published><updated>2011-04-05T23:07:08.307-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-04-05T23:07:08.307-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="waf" /><category scheme="http://www.blogger.com/atom/ns#" term="apresentações" /><category scheme="http://www.blogger.com/atom/ns#" term="modsecurity" /><title>Introducão a Web Applications Firewalls</title><content type="html">Apresentação realizada no dia 31/março/2011 no primeiro encontro do grupo OWASP Porto Alegre - &lt;a href="http://www.owasp.org/index.php/Porto_Alegre"&gt;http://www.owasp.org/index.php/Porto_Alegre&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px" id="__ss_7529475"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/jczucco/introducao-a-web-applications-firewalls" title="Introducao a Web Applications Firewalls"&gt;Introducao a Web Applications Firewalls&lt;/a&gt;&lt;/strong&gt;&lt;object id="__sse7529475" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=introducaowaf2011-110405205807-phpapp01&amp;stripped_title=introducao-a-web-applications-firewalls&amp;userName=jczucco" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed name="__sse7529475" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=introducaowaf2011-110405205807-phpapp01&amp;stripped_title=introducao-a-web-applications-firewalls&amp;userName=jczucco" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/jczucco"&gt;jczucco&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-726821106709254799?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/IjYd3UrwtYZb76AtmLnviFfEEbc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IjYd3UrwtYZb76AtmLnviFfEEbc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/IjYd3UrwtYZb76AtmLnviFfEEbc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/IjYd3UrwtYZb76AtmLnviFfEEbc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/EVG0zeWNGYY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/726821106709254799/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=726821106709254799&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/726821106709254799?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/726821106709254799?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/EVG0zeWNGYY/introducao-web-applications-firewalls.html" title="Introducão a Web Applications Firewalls" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/04/introducao-web-applications-firewalls.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YDQXw_cSp7ImA9Wx9aGEs.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2294360274965743408</id><published>2011-03-11T15:38:00.002-03:00</published><updated>2011-03-11T15:46:10.249-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-11T15:46:10.249-03:00</app:edited><title>Primeiro encontro do Capítulo OWASP Porto Alegre</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-jwe08Ys6Uks/TXpt2b2db_I/AAAAAAAAAJY/6c1pewYIFX8/s1600/Owasp-poa-eng.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 127px;" src="http://3.bp.blogspot.com/-jwe08Ys6Uks/TXpt2b2db_I/AAAAAAAAAJY/6c1pewYIFX8/s320/Owasp-poa-eng.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5582895470035693554" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;ANÚNCIO&lt;/span&gt;: Primeiro encontro do &lt;a href="http://www.owasp.org/index.php/Porto_Alegre"&gt;Capítulo OWASP Porto Alegre&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;DATA&lt;/span&gt;: 31 de março de 2011, às 19:30 hs - Entrada gratuita a todos embora o estacionamento seja pago.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;LOCAL&lt;/span&gt;: Unisinos - Auditório Sergio Gomes ( &lt;a href="http://maps.google.com/maps?f=q&amp;source=s_q&amp;hl=pt-BR&amp;geocode=&amp;q=Avenida+Unisinos,+950,+S%C3%A3o+Leopoldo+-+Rio+Grande+do+Sul,+Brasil&amp;aq=0&amp;sll=37.062301,-95.676498&amp;sspn=0.209856,0.676346&amp;ie=UTF8&amp;hq=&amp;hnear=Av.+Unisinos,+950+-+Cristo+Rei,+S%C3%A3o+Leopoldo+-+Rio+Grande+do+Sul,+93022-000,+Brasil&amp;z=16"&gt;Google Maps&lt;/a&gt; )&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;PROGRAMAÇÂO&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;19:30 - 19:40: Recepção&lt;br /&gt;&lt;br /&gt;19:40 - 20:20: OWASP na luta em pról de um mundo mais seguro - &lt;a href="http://www.owasp.org/index.php/User:Gustavo_Barbato"&gt;L. Gustavo C. Barbato&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;20:20 - 21:00: Introdução a Web Applications Firewalls - &lt;a href="http://www.owasp.org/index.php/User:Jeronimo_Zucco"&gt;Jerônimo Zucco&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;21:00 - 21:20: Intervalo&lt;br /&gt;&lt;br /&gt;21:20 - 22:00: Os Desafios da Segurança no Desenvolvimento com Métodos Ágeis - &lt;a href="http://www.owasp.org/index.php/User:Rafael_Dreher"&gt;Rafael Dreher&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;22:00 - 22:20: Perguntas e Respostas&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Agradecemos à &lt;a href="http://www.unisinos.br"&gt;UNISINOS&lt;/a&gt; por ceder a infraestrutura para a realização da reunião do capítulo.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2294360274965743408?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Qp9yeuZoZLkVX4uhUQNiM8f_u68/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Qp9yeuZoZLkVX4uhUQNiM8f_u68/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Qp9yeuZoZLkVX4uhUQNiM8f_u68/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Qp9yeuZoZLkVX4uhUQNiM8f_u68/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/omA1ifc5LrE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2294360274965743408/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2294360274965743408&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2294360274965743408?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2294360274965743408?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/omA1ifc5LrE/primeiro-encontro-do-capitulo-owasp.html" title="Primeiro encontro do Capítulo OWASP Porto Alegre" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-jwe08Ys6Uks/TXpt2b2db_I/AAAAAAAAAJY/6c1pewYIFX8/s72-c/Owasp-poa-eng.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/03/primeiro-encontro-do-capitulo-owasp.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ak4ARHYzcSp7ImA9Wx9bGUQ.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-7007611297257376338</id><published>2011-03-01T13:50:00.005-03:00</published><updated>2011-03-01T14:02:25.889-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-03-01T14:02:25.889-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="mac" /><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><category scheme="http://www.blogger.com/atom/ns#" term="apple" /><title>Guia de configuração segura para o Mac OS X 10.6 Snow Leopard</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-xJxMMPVPlP0/TW0lM3u-TAI/AAAAAAAAAJI/XFSTt2aknCg/s1600/2268548577_0fb468c051.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 266px;" src="http://1.bp.blogspot.com/-xJxMMPVPlP0/TW0lM3u-TAI/AAAAAAAAAJI/XFSTt2aknCg/s400/2268548577_0fb468c051.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5579156416431541250" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; A Apple é conhecida por disponibilizar muita documentação e diversos vídeos demonstrando as funcionalidades de seus aplicativos e sistemas. Mas um que eu sempre recomendo, pois considero muito importante e uso como referência é o &lt;span style="font-weight:bold;"&gt;Guia de configuração segura para o Mac OS X 10.6 Snow Leopard&lt;/span&gt; (em inglês), disponibilizado para download no endereço &lt;a href="http://images.apple.com/support/security/guides/docs/SnowLeopard_Security_Config_v10.6.pdf"&gt;http://images.apple.com/support/security/guides/docs/SnowLeopard_Security_Config_v10.6.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;    Este guia fornece uma visão geral dos recursos do Mac OS X que você pode usar para manter o seu Mac seguro, tarefa também conhecida como &lt;span style="font-weight:bold;"&gt;hardening&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;    O documento é destinado principalmente aos profissionais de segurança ou usuários com uma certa experiência no sistema, pois as técnicas e funcionalidades expostas podem não ser apropriadas para alguns usuários ou ambientes.&lt;br /&gt;&lt;br /&gt;    O documento não é destinado para sistemas servidores, para esses ambientes a Apple disponibiliza um outro guia separado, o Mac OS X Server Security Configuration Guide, disponível para download em &lt;a href="http://images.apple.com/support/security/guides/docs/SnowLeopard_Server_Security_Config_v10.6.pdf"&gt;http://images.apple.com/support/security/guides/docs/SnowLeopard_Server_Security_Config_v10.6.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;    O Guia possui os seguintes capítulos:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Capítulo 1&lt;/span&gt; - Introdução à arquitetura de segurança do Mac OS X: Discute as camadas de segurança e infra-estrutura do Mac OS X.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Capítulo 2&lt;/span&gt; -  Instalando o Mac OS X: descreve como instalar o Mac OS X e também como instalar as atualizações de software explicando as permissões e como consertar problemas referente às permissões.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Capítulo 3&lt;/span&gt; - Securança de sistema e hardware: Explica como proteger fisicamente seu hardware e protegê-lo de ataques," hardware. Este capítulo também explica como proteger as configurações que afetam usuários do computador.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Capítulo 4&lt;/span&gt; - Configurações globais de segurança do sistema: Descreve algumas configurações de segurança globais no firmware e inicialização do Mac OS X Snow Leopard. Mostra também como habilitar os logs do sistema para monitoramento dos eventos.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Capítulo 5&lt;/span&gt; - Preferências de segurança do sistema: Mostra as configurações recomendadas do sistema para aumentar a segurança do Mac OS X.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Capítulo 6&lt;/span&gt; - Segurança de contas de usuário: Demonstra como configurar uma conta de usuário de forma segura. Isso inclui a proteção da conta administrador do sistema, usando o Open Directory, e usando a autenticação forte.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Capítulo 7&lt;/span&gt; - Segurança de dados e uso de criptografia: Descrever como cifrar dados através do uso de criptografia e como usar o método de deleção segura para verificar se os dados apagados são completamente removidos.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;Capítulo 8&lt;/span&gt; - Protegendo Aplicativos: Descreve como proteger seus dados ao usar aplicativos da Apple.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Capítulo 9&lt;/span&gt; - Configurando de forma segura serviços de rede: o título já é auto-explicativo.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Capítulo 10&lt;/span&gt; - Gerência avançada de segurança: mostra como realizar auditorias de segurança no sistema para validar a integridade do seu computador e dados.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Apêndice A&lt;/span&gt; - Checklist de segurança: Fornece uma lista de verificação para proteger seu sistema.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Apêndice B&lt;/span&gt; - Scripts de segurança: Fornece um modelo para criação de scripts para proteger o seu computador.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nota: Como a Apple lança periodicamente novas versões e atualizações do software, as imagens mostradas neste livro pode ser diferente do que você vê em sua tela. &lt;br /&gt;&lt;br /&gt;Caso você possua as versões mais antigas do Mac OS (Leopard, Tiger ou Panther), existem outros documentos disponíveis em &lt;a href="http://www.apple.com/support/security/guides/"&gt;http://www.apple.com/support/security/guides/&lt;/a&gt; (em inglês).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-b8MQ1xRwQx8/TW0lWgnBlRI/AAAAAAAAAJQ/JlNRPEMtEl8/s1600/apple-security.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 398px; height: 206px;" src="http://3.bp.blogspot.com/-b8MQ1xRwQx8/TW0lWgnBlRI/AAAAAAAAAJQ/JlNRPEMtEl8/s400/apple-security.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5579156582022878482" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Boa leitura, e fique seguro!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-7007611297257376338?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/MhP-flejkqF7TiQuTFIIwki1e18/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MhP-flejkqF7TiQuTFIIwki1e18/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/MhP-flejkqF7TiQuTFIIwki1e18/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/MhP-flejkqF7TiQuTFIIwki1e18/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/vZF8OCmO-Y0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/7007611297257376338/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=7007611297257376338&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/7007611297257376338?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/7007611297257376338?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/vZF8OCmO-Y0/guia-de-configuracao-segura-para-o-mac.html" title="Guia de configuração segura para o Mac OS X 10.6 Snow Leopard" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-xJxMMPVPlP0/TW0lM3u-TAI/AAAAAAAAAJI/XFSTt2aknCg/s72-c/2268548577_0fb468c051.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/03/guia-de-configuracao-segura-para-o-mac.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUMSXc9cSp7ImA9Wx9UE0k.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-1505930259170162893</id><published>2011-02-10T10:50:00.000-02:00</published><updated>2011-02-10T10:51:28.969-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-02-10T10:51:28.969-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><title>OWASP Appsec Tutorial Series - Episode 2: Injection Attacks</title><content type="html">&lt;iframe title="YouTube video player" width="640" height="390" src="http://www.youtube.com/embed/Ci_YtwOn150" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Ci_YtwOn150"&gt;http://www.youtube.com/watch?v=Ci_YtwOn150&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-1505930259170162893?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/2PujcCLqSlFSblqnR5qSnieuMlU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2PujcCLqSlFSblqnR5qSnieuMlU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/2PujcCLqSlFSblqnR5qSnieuMlU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/2PujcCLqSlFSblqnR5qSnieuMlU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/Vorp3SFe6Ck" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/1505930259170162893/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=1505930259170162893&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/1505930259170162893?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/1505930259170162893?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/Vorp3SFe6Ck/owasp-appsec-tutorial-series-episode-2.html" title="OWASP Appsec Tutorial Series - Episode 2: Injection Attacks" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/Ci_YtwOn150/default.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/02/owasp-appsec-tutorial-series-episode-2.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0cDRn89eip7ImA9Wx9UEUU.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-6967059735977201757</id><published>2011-02-08T16:16:00.000-02:00</published><updated>2011-02-08T16:17:57.162-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-02-08T16:17:57.162-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="owasp" /><title>OWASP Appsec Tutorial Series - Episode 1: Appsec Basics</title><content type="html">OWASP Appsec Tutorial Series - Episode 1: Appsec Basics&lt;br /&gt;&lt;br /&gt;&lt;iframe title="YouTube video player" width="640" height="390" src="http://www.youtube.com/embed/CDbWvEwBBxo" frameborder="0" allowfullscreen&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=CDbWvEwBBxo"&gt;http://www.youtube.com/watch?v=CDbWvEwBBxo&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-6967059735977201757?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Rlmdf_Yfqr4TtHtuSw7lfO-sdtY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rlmdf_Yfqr4TtHtuSw7lfO-sdtY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Rlmdf_Yfqr4TtHtuSw7lfO-sdtY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Rlmdf_Yfqr4TtHtuSw7lfO-sdtY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/vcekAlz6Mms" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/6967059735977201757/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=6967059735977201757&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/6967059735977201757?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/6967059735977201757?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/vcekAlz6Mms/owasp-appsec-tutorial-series-episode-1.html" title="OWASP Appsec Tutorial Series - Episode 1: Appsec Basics" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/CDbWvEwBBxo/default.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/02/owasp-appsec-tutorial-series-episode-1.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQERHk8cSp7ImA9Wx9VFkk.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-8430634068612751300</id><published>2011-02-02T08:48:00.004-02:00</published><updated>2011-02-02T08:58:25.779-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-02-02T08:58:25.779-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ipv6" /><title>O fim do IP conforme nós conhecemos</title><content type="html">&lt;span style="font-weight:bold;"&gt;Alerta do CAIS (Centro de Atendimento a Incidentes de Seguranca) de 01 de fevereiro de 2011&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.rnp.br/cais/alertas/rss.xml"&gt;http://www.rnp.br/cais/alertas/rss.xml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Prezados,&lt;br /&gt;&lt;br /&gt;O CAIS está repassando uma notícia publicada pelo ISC (Internet Storm Center) intitulada "The End Of IP As We Know It", que trata do esgotamento de endereçamento IPv4 disponível.&lt;br /&gt;&lt;br /&gt;No dia 01 de fevereiro de 2011 a IANA (Internet Assigned Numbers Authority), responsável pela coordenação global dos endereços IP, DNS raíz e pelo registro de protocolos de Internet anunciou a distribuição de mais duas classes de endereçamento IPv4 /8 à APNIC (Asia Pacific Network Information Centre).&lt;br /&gt;&lt;br /&gt;Como resultado, restaram somente 5 classes /8 à IANA, que colocou em prática uma política especial de distribuí-las à cada um dos registros regionais (RIR): AFRNIC (África), APNIC (Ásia Pacifico), ARIN (América do Norte), LACNIC (América Latina) e RIPE (Europa).&lt;br /&gt;&lt;br /&gt;Para esclarecer possíveis dúvidas sobre o esgotamento do endereçamento IPv4 disponível, o ISC preparou um FAQ sobre o tema. O FAQ segue traduzido ao final deste alerta.&lt;br /&gt;&lt;br /&gt;A IANA fornece endereçamentos IPs aos RIRs em blocos /8, repassando-os aos provedores de internet, que, por sua vez, os alocam aos usuários finais.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;1 - A Internet vai parar de funcionar?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Não. Na verdade, é improvável que a Internet IPv4 vá parar tão cedo. É provável que ela coexista pacificamente ao lado da Internet IPv6. Já existem alguns mecanismos de transição entre as duas versões. Apesar de não ser uma solução elegante, as duas "internets" podem falar entre si através de proxies e túneis.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;2 - Por que os endereços foram extintos?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Com IPv4 é possível alocar cerca de 4 bilhões de endereços. Há cerca de 6 bilhões de pessoas no mundo, imagine quantos endereços você precisa (telefone de casa, trabalho ...)? É uma questão simples de matemática, agravado pelo fato de que para ter um roteamento eficiente, não é possível &lt;br /&gt;alocar todos os endereços.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;3 - Vários endereços IPv4 ainda não são utilizados. Por que não&lt;br /&gt;utilizá-los de forma mais eficaz?&lt;/span&gt;&lt;br /&gt;        &lt;br /&gt;O problema não é somente o fato de esgotarem os endereços, ainda que este seja o motivo principal, a atribuição de endereços de forma mais eficaz implicaria em alocações menores, o que tornaria mais complexas as tabelas de roteamento. Para fazer isto, seria necessário "re-numerar" a Internet, e ainda assim, ficaríamos sem endereços disponíveis em algum momento.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;4 - E sobre a alocação de espaço IPv4 legada? A Apple realmente precisa &lt;br /&gt;de um /8?&lt;/span&gt;&lt;br /&gt;        &lt;br /&gt;No início da Internet, espaço de endereçamento IPv4 foi entregue de uma forma muito liberal. Lembre-se que a Internet era apenas uma experiência! Alguns dos participantes originais ainda têm grandes alocações IPv4 e não as utilizam de forma eficiente. No entanto, mesmo se todos eles &lt;br /&gt;entregassem seus espaços de volta, atrasaria o problema por apenas 1 ou 2 anos e implicaria em um grande custo para as empresas afetadas (e estas possuem contratos dando-lhes o direito de usar o espaço de endereço). Algumas "alocações legadas" foram devolvidas no passado.&lt;br /&gt;        &lt;br /&gt;&lt;span style="font-weight:bold;"&gt;5 - O que eu preciso fazer hoje?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Não precisa se desesperar. Nada vai acontecer tão rápido. Os RIRs (Regional Internet Registries) ainda possuem endereços alocáveis por alguns meses e, dependendo da região, por um ano. Quando estas alocações se esgotarem é que vai ficar mais complicado. Ficará mais difícil obter &lt;br /&gt;espaço de endereços IPv4. Eventualmente, os ISP (Internet Service Providers) poderão solicitar de volta espaços alocados a clientes, visto que eles não terão como obter novos endereços com o RIR. Ao longo do tempo, alocação de espaço IPv4 vai ficar mais cara que IPv6.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;6 - Então, eu posso apenas esperar e não fazer nada?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Não. O que você deve fazer amanhã (talvez hoje?) é configurar um laboratório de testes para se familiarizar com o IPv6. É fácil para começar. Pergunte ao seu ISP se ele já suporta IPv6 (ou quando suportará), ou configure um túnel com um provedor gratuito como o túnel Hurricane &lt;br /&gt;Electric [2] ou SixXS [3] (existem outros). Você precisa de um planejamento para saber como lidar com esta nova tecnologia. Mesmo que você não precise de IPv6, talvez seus parceiros de negócios podem começar a utilizá-lo e você precisará conectá-los via IPv6.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;7 - Não posso simplesmente ignorá-lo?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Lembre-se, porque você está usando o IP em primeiro lugar? Ele permite que você se conecte com clientes, fornecedores, filiais etc. Em suma: te mantém no negócio. Assim que estes parceiros começarem a migrar para conectividade IPv6, você provavelmente terá que mudar também. É como &lt;br /&gt;qualquer outra tecnologia, no fim ela tem que dar suporte ao negócio (e bem... também é muito divertido!).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;8 - O que vai mudar a partir de um ponto de vista da segurança?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Tudo e nada. A mudança mais importante de IPv4 para IPv6 é provavelmente o fato de que o NAT (Network Address Translation) vai se tornar menos importante. Proteção ao usuário final e firewalls bem configurados se tornarão mais importantes. A detecção passiva de recurso se tornará mais importante em relação à varredura ativa. Há um monte de artefatos de segurança que você possui e que provavelmente faz um péssimo trabalho ao lidar com IPv6. Eu mencionei que isto requer um planejamento e teste?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;MAIS INFORMAÇÕES&lt;br /&gt;&lt;br /&gt;. The End Of IP As We Know It&lt;br /&gt;  &lt;a href="http://isc.sans.edu/diary.html?storyid=10342"&gt;http://isc.sans.edu/diary.html?storyid=10342&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;. IANA IPv4 Address Space Registry&lt;br /&gt;  &lt;a href="http://www.iana.org/assignments/ipv4-address-space/ipv4-address-space.xml"&gt;http://www.iana.org/assignments/ipv4-address-space/ipv4-address-space.xml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;. Leading Global Internet Groups make Significant Announcement about the Status of the IPv4 Address Pool&lt;br /&gt;  &lt;a href="http://www.apnic.net/publications/news/2011/leading-global-internet-groups-make-significant-announcement-about-the-status-of-the-ipv4-address-pool"&gt;http://www.apnic.net/publications/news/2011/leading-global-internet-groups-make-significant-announcement-about-the-status-of-the-ipv4-address-pool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;. IPv6.BR&lt;br /&gt;  &lt;a href="http://www.ipv6.br/"&gt;http://www.ipv6.br/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Os Alertas do CAIS também são oferecidos no formato RSS/RDF e no Twitter:&lt;br /&gt;&lt;a href="http://www.rnp.br/cais/alertas/rss.xml"&gt;http://www.rnp.br/cais/alertas/rss.xml&lt;/a&gt;&lt;br /&gt;Siga &lt;a href="https://twitter.com/cais_rnp"&gt;@cais_rnp&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Atenciosamente,&lt;br /&gt;&lt;br /&gt;################################################################&lt;br /&gt;#   CENTRO DE ATENDIMENTO A INCIDENTES DE SEGURANCA (CAIS)     #&lt;br /&gt;#       Rede Nacional de Ensino e Pesquisa (RNP)               #&lt;br /&gt;#                                                              #&lt;br /&gt;# cais@cais.rnp.br       http://www.cais.rnp.br                #&lt;br /&gt;# Tel. 019-37873300      Fax. 019-37873301                     #&lt;br /&gt;# Chave PGP disponivel   http://www.rnp.br/cais/cais-pgp.key   #&lt;br /&gt;################################################################&lt;br /&gt;&lt;br /&gt;================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-8430634068612751300?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Qw44IlrSDRVCkgAvLJE8wz3xmWI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Qw44IlrSDRVCkgAvLJE8wz3xmWI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Qw44IlrSDRVCkgAvLJE8wz3xmWI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Qw44IlrSDRVCkgAvLJE8wz3xmWI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/FH4JJAeI_8E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/8430634068612751300/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=8430634068612751300&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/8430634068612751300?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/8430634068612751300?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/FH4JJAeI_8E/o-fim-do-ip-conforme-nos-conhecemos.html" title="O fim do IP conforme nós conhecemos" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/02/o-fim-do-ip-conforme-nos-conhecemos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk8FSXw9eSp7ImA9Wx9VFE4.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-1405959946636871033</id><published>2011-01-30T21:33:00.009-02:00</published><updated>2011-01-30T22:46:58.261-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-30T22:46:58.261-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Servidor VPN L2TP/IPSec</title><content type="html">Redes &lt;a href="https://secure.wikimedia.org/wikipedia/pt/wiki/Wifi"&gt;wi-fi&lt;/a&gt; abertas disponíveis ao público já são comuns de encontrar em eventos, bares, shoppings. Mas como navegar de maneira segura através das redes públicas?&lt;br /&gt;&lt;br /&gt;A solução para isso é uso de &lt;span style="font-weight:bold;"&gt;&lt;a href="https://secure.wikimedia.org/wikipedia/pt/wiki/Virtual_Private_Network"&gt;VPNs&lt;/a&gt;&lt;/span&gt; (&lt;span style="font-weight:bold;"&gt;Virtual Private Network&lt;/span&gt;, ou &lt;span style="font-weight:bold;"&gt;Rede Privada Virtual&lt;/span&gt;). Conforme definição na wikipedia:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Rede Privada Virtual&lt;/span&gt; é uma rede de comunicações privada normalmente utilizada por uma empresa ou um conjunto de empresas e/ou instituições, construída em cima de uma rede de comunicações pública (como por exemplo, a Internet). O tráfego de dados é levado pela rede pública utilizando protocolos padrão, não necessariamente seguros.&lt;br /&gt;&lt;br /&gt;VPNs seguras usam protocolos de criptografia por tunelamento que fornecem a confidencialidade, autenticação e integridade necessárias para garantir a privacidade das comunicações requeridas. Quando adequadamente implementados, estes protocolos podem assegurar comunicações seguras através de redes inseguras.&lt;br /&gt;&lt;br /&gt;Deve ser notado que a escolha, implementação e uso destes protocolos não é algo trivial, e várias soluções de VPN inseguras são distribuídas no mercado. Adverte-se os usuários para que investiguem com cuidado os produtos que fornecem VPNs. Por si só, o rótulo VPN é apenas uma ferramenta de marketing.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V8x6Zp7bni8/TUX3EcWVgfI/AAAAAAAAAI8/agsh6x2SZrU/s1600/vpn.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 119px;" src="http://2.bp.blogspot.com/_V8x6Zp7bni8/TUX3EcWVgfI/AAAAAAAAAI8/agsh6x2SZrU/s400/vpn.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5568128170014900722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;O PROBLEMA&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;Possuo um &lt;span style="font-weight:bold;"&gt;smartphone com o sistema operacional Android&lt;/span&gt;, e por diversas vezes preciso utilizar as redes wifi públicas para acessar alguns serviços da internet, e gostaria de fazer isso de forma segura e simples. Já que precisaria implantar um servidor de VPN, estabeleci alguns &lt;span style="font-weight:bold;"&gt;requisitos&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;- Simples de configurar nos clientes VPN&lt;br /&gt;- Uso de criptografia forte&lt;br /&gt;- Tenha clientes multiplataforma (Smartphones Android, IPhone, sistemas operacionais Mac OS, Linux, Windows, BSD)&lt;br /&gt;- Tenha cliente nativo em Android, sem necessidade de procedimento de root&lt;br /&gt;- Cliente nativo para Mac OS, para utilizar a VPN no notebook&lt;br /&gt;- Como vou utilizar um servidor Linux (em um provedor fora do país), utilizar pacotes disponíveis na distribuição Debian&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;A SOLUÇÃO:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Verificando os requisitos acima, cheguei até a opção de servidor VPN L2TP/IPSec (alguém tem alguma outra sugestão?). Para facilitar a configuração, a VPN vai ser através do uso de uma chave pré-compartilhada (&lt;a href="https://secure.wikimedia.org/wikipedia/en/wiki/Pre-shared_key"&gt;PSK&lt;/a&gt; - Pre-shared key) e uma autenticação de usuário e senha. Simples e eficiente. É possível fazer a configuração utilizando certificados digitais, porém sua configuração dos clientes é mais complicada.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;O servidor utilizado é um Linux Debian Lenny, utilizando sempre softwares instalados através do gerenciador de pacotes do repositório oficial. Alguns sites de referência que utilizei foram esses:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.jacco2.dds.nl/networking/openswan-macosx.html"&gt;http://www.jacco2.dds.nl/networking/openswan-macosx.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://riobard.com/blog/2010-04-30-l2tp-over-ipsec-ubuntu/"&gt;http://riobard.com/blog/2010-04-30-l2tp-over-ipsec-ubuntu/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://tools.ietf.org/html/rfc3193"&gt;http://tools.ietf.org/html/rfc3193&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://tools.ietf.org/html/rfc2661"&gt;http://tools.ietf.org/html/rfc2661&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Passo 1: Instalar os pacotes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;# apt-get install openswan xl2tpd ppp&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Passo 2: Configurar o IPSec&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Editar o arquivo &lt;span style="font-weight:bold;"&gt;/etc/ipsec.conf&lt;/span&gt; e colocar o seguinte conteúdo:&lt;br /&gt;&lt;br /&gt;version 2.0&lt;br /&gt;config setup&lt;br /&gt;    nat_traversal=yes&lt;br /&gt;    virtual_private=%v4:10.0.0.0/8   &lt;-- Mude os IPs da VPN conforme necessidade&lt;br /&gt;    protostack=netkey&lt;br /&gt;&lt;br /&gt;conn L2TP-PSK-NAT&lt;br /&gt;    rightsubnet=vhost:%priv&lt;br /&gt;    also=L2TP-PSK-noNAT&lt;br /&gt;&lt;br /&gt;conn L2TP-PSK-noNAT&lt;br /&gt;    authby=secret&lt;br /&gt;    pfs=no&lt;br /&gt;    auto=add&lt;br /&gt;    keyingtries=3&lt;br /&gt;    rekey=no&lt;br /&gt;    ikelifetime=8h&lt;br /&gt;    keylife=1h&lt;br /&gt;    type=transport&lt;br /&gt;    left=IP.SEU.SERVIDOR   &lt;-- Mude para o IP do seu servidor VPN&lt;br /&gt;    leftprotoport=17/1701&lt;br /&gt;    right=%any&lt;br /&gt;    rightprotoport=17/%any&lt;br /&gt;&lt;br /&gt;# 'include' this file to disable Opportunistic Encryption.&lt;br /&gt;# See /usr/share/doc/openswan/policygroups.html for details.&lt;br /&gt;#&lt;br /&gt;# RCSID $Id: no_oe.conf.in,v 1.2 2004-10-03 19:33:10 paul Exp $&lt;br /&gt;conn block &lt;br /&gt;    auto=ignore&lt;br /&gt;&lt;br /&gt;conn private &lt;br /&gt;    auto=ignore&lt;br /&gt;&lt;br /&gt;conn private-or-clear &lt;br /&gt;    auto=ignore&lt;br /&gt;&lt;br /&gt;conn clear-or-private &lt;br /&gt;    auto=ignore&lt;br /&gt;&lt;br /&gt;conn clear &lt;br /&gt;    auto=ignore&lt;br /&gt;&lt;br /&gt;conn packetdefault &lt;br /&gt;    auto=ignore&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Editar o arquivo &lt;span style="font-weight:bold;"&gt;/etc/ipsec.secrets&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;IP.SEU.SERVIDOR   %any:  PSK "SuaSenhaCompartilhada"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Passo 3: Configurar o L2TP&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;O &lt;a href="https://secure.wikimedia.org/wikipedia/en/wiki/L2tp"&gt;L2TP&lt;/a&gt; (Layer 2 Tunneling Protocol) fornece um túnel para enviar dados. Ele não fornece criptografia e autenticação, porém, é por isso que precisamos usá-lo em conjunto com o IPSec. Curiosamente, tanto a Apple quanto a Microsoft costumam se referir ao L2TP como a tecnologia VPN segura, mas ignoram totalmente o fato de que a segurança é fornecida pelo IPSec.&lt;br /&gt;&lt;br /&gt;Edite o arquivo &lt;span style="font-weight:bold;"&gt;/etc/xl2tpd/xl2tpd.conf&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;[global]&lt;br /&gt;ipsec saref = yes&lt;br /&gt;&lt;br /&gt;[lns default]&lt;br /&gt;ip range = 10.1.2.2-10.1.2.255   &lt;-- Modifique de acordo com o número de clientes&lt;br /&gt;local ip = 10.1.2.1    &lt;-- IP do servidor VPN no túnel (lado esquerdo)&lt;br /&gt;refuse chap = yes&lt;br /&gt;refuse pap = yes&lt;br /&gt;require authentication = yes&lt;br /&gt;ppp debug = yes&lt;br /&gt;pppoptfile = /etc/ppp/options.xl2tpd&lt;br /&gt;length bit = yes&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Passo 4: Configuração do PPP&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Edite o arquivo &lt;span style="font-weight:bold;"&gt;/etc/ppp/options.xl2tpd&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;require-mschap-v2&lt;br /&gt;ms-dns 8.8.8.8  &lt;-- Coloquei aqui os servidores DNS públicos do google&lt;br /&gt;ms-dns 8.8.4.4&lt;br /&gt;asyncmap 0&lt;br /&gt;auth&lt;br /&gt;crtscts&lt;br /&gt;lock&lt;br /&gt;hide-password&lt;br /&gt;modem&lt;br /&gt;debug&lt;br /&gt;name l2tpd&lt;br /&gt;proxyarp&lt;br /&gt;lcp-echo-interval 30&lt;br /&gt;lcp-echo-failure 4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Edite o arquivo &lt;span style="font-weight:bold;"&gt;/etc/ppp/chap-secrets&lt;/span&gt; para cadastrar os usuários e senhas:&lt;br /&gt;# user      server      password            ip&lt;br /&gt;test        l2tpd       testpassword        *&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Passo 5: Prepare a rede conforme necessidade&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Eu criei um script de start de todos os serviços, já configurando a rede para a VPN e realizando &lt;a href="https://secure.wikimedia.org/wikipedia/pt/wiki/NAT"&gt;NAT&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;#!/bin/bash&lt;br /&gt;for each in /proc/sys/net/ipv4/conf/*&lt;br /&gt;do&lt;br /&gt;    echo 0 &gt; $each/accept_redirects&lt;br /&gt;    echo 0 &gt; $each/send_redirects&lt;br /&gt;done&lt;br /&gt;&lt;br /&gt;/etc/init.d/ipsec start&lt;br /&gt;/etc/init.d/xl2tpd start&lt;br /&gt;&lt;br /&gt;echo 1 &gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nesse site tem as configurações do cliente VPN em smartphones Android:&lt;a href="https://12vpn.com/wiki/index.php?title=Android_1.6_L2TP/IPSec_PSK_instructions"&gt;https://12vpn.com/wiki/index.php?title=Android_1.6_L2TP/IPSec_PSK_instructions&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Pronto. A configuração de clientes para Android e para Mac OS é bem simples e é nativo, não é necessário instalar nenhum programa para configuração. Agora você já pode utilizar as redes públicas abertas de forma segura.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-1405959946636871033?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Jf03KY_9LGdpE8agN9YAwd_LJTA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Jf03KY_9LGdpE8agN9YAwd_LJTA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Jf03KY_9LGdpE8agN9YAwd_LJTA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Jf03KY_9LGdpE8agN9YAwd_LJTA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/4f6aYpdW6DE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/1405959946636871033/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=1405959946636871033&amp;isPopup=true" title="2 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/1405959946636871033?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/1405959946636871033?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/4f6aYpdW6DE/servidor-vpn-l2tpipsec.html" title="Servidor VPN L2TP/IPSec" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_V8x6Zp7bni8/TUX3EcWVgfI/AAAAAAAAAI8/agsh6x2SZrU/s72-c/vpn.gif" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2011/01/servidor-vpn-l2tpipsec.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YBQXozeSp7ImA9Wx9REk0.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-5040570038232463858</id><published>2010-12-12T22:44:00.000-02:00</published><updated>2010-12-12T22:45:50.481-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-12T22:45:50.481-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="apresentações" /><title>Impacto das Redes Sociais na Segurança da Informação</title><content type="html">Apresentação realizada no evento ISSA Day Regional – Porto Alegre em 08 de dezembro de 2010 - &lt;a href="http://www.issabrasil.org/2010/12/04/issa-day-regional-porto-alegre"&gt;http://www.issabrasil.org/2010/12/04/issa-day-regional-porto-alegre&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px" id="__ss_6134246"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/jczucco/impacto-das-redes-sociais-na-segurana-da-informao" title="Impacto das Redes Sociais na Segurança da Informação"&gt;Impacto das Redes Sociais na Segurança da Informação&lt;/a&gt;&lt;/strong&gt;&lt;object id="__sse6134246" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=redessociaisissa2010-101212184109-phpapp01&amp;stripped_title=impacto-das-redes-sociais-na-segurana-da-informao&amp;userName=jczucco" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed name="__sse6134246" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=redessociaisissa2010-101212184109-phpapp01&amp;stripped_title=impacto-das-redes-sociais-na-segurana-da-informao&amp;userName=jczucco" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/jczucco"&gt;jczucco&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-5040570038232463858?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/rOsbYUdL_Rvw4s7_2DsvU7XyLTg/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rOsbYUdL_Rvw4s7_2DsvU7XyLTg/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/rOsbYUdL_Rvw4s7_2DsvU7XyLTg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/rOsbYUdL_Rvw4s7_2DsvU7XyLTg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/ktxHq40S1m0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/5040570038232463858/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=5040570038232463858&amp;isPopup=true" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/5040570038232463858?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/5040570038232463858?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/ktxHq40S1m0/impacto-das-redes-sociais-na-seguranca.html" title="Impacto das Redes Sociais na Segurança da Informação" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/12/impacto-das-redes-sociais-na-seguranca.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cAQns8eSp7ImA9Wx9REk0.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-8366853232563433033</id><published>2010-12-12T22:31:00.002-02:00</published><updated>2010-12-12T22:44:03.571-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-12T22:44:03.571-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="apresentações" /><title>Implementando o OSSEC HIDS</title><content type="html">Tutorial realizado no GTS 16 em 25 de novembro de 2010. Em breve o vídeo será disponibilizado.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://gter.nic.br/reunioes/gter-30/programa"&gt;&lt;br /&gt;http://gter.nic.br/reunioes/gter-30/programa&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="width:425px" id="__ss_6134128"&gt;&lt;strong style="display:block;margin:12px 0 4px"&gt;&lt;a href="http://www.slideshare.net/jczucco/implementing-ossec" title="Implementing ossec"&gt;Implementing ossec&lt;/a&gt;&lt;/strong&gt;&lt;object id="__sse6134128" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=implementandoossec-101212182718-phpapp01&amp;stripped_title=implementing-ossec&amp;userName=jczucco" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed name="__sse6134128" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=implementandoossec-101212182718-phpapp01&amp;stripped_title=implementing-ossec&amp;userName=jczucco" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="padding:5px 0 12px"&gt;View more &lt;a href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a href="http://www.slideshare.net/jczucco"&gt;jczucco&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-8366853232563433033?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9ve0d9OwNZ9JR5HM7fqEKxBVZAw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9ve0d9OwNZ9JR5HM7fqEKxBVZAw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9ve0d9OwNZ9JR5HM7fqEKxBVZAw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9ve0d9OwNZ9JR5HM7fqEKxBVZAw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/Zw7rJT1rc7I" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/8366853232563433033/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=8366853232563433033&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/8366853232563433033?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/8366853232563433033?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/Zw7rJT1rc7I/implementando-o-ossec-hids.html" title="Implementando o OSSEC HIDS" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/12/implementando-o-ossec-hids.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4AR3w_eCp7ImA9Wx5bF0Q.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2326294951766004946</id><published>2010-11-03T13:12:00.002-02:00</published><updated>2010-11-03T13:25:46.240-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-03T13:25:46.240-02:00</app:edited><title>Tutorial de OSSEC no GTER/GTS em São Leopoldo</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.ossec.net/img/ossec_logo.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 191px; height: 81px;" src="http://www.ossec.net/img/ossec_logo.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Irá ocorrer nos dias 25, 26 e 27 de novembro de 2010 o GTER - Grupo de Trabalho de Engenharia e Operação de Redes - 30ª Reunião e o GTS - Grupo de Trabalho em Segurança de Redes - 16ª Reunião, na Unisinos em São Leopoldo. O evento é gratuito e as inscrições estão abertas e podem ser feitas pelo site &lt;a href="http://gter.nic.br/reunioes/gter-30/"&gt;http://gter.nic.br/reunioes/gter-30/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Estarei ministrando no primeiro dia um tutorial de 8 horas sobre Implantação do &lt;a href="http://www.ossec.net"&gt;OSSEC HIDS&lt;/a&gt;. Abaixo segue a programação do tutorial:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Descrição&lt;/span&gt;:&lt;br /&gt;        Esse curso tem por objetivo apresentar de forma prática a implantação e uso do HIDS (Host-based intrusion detection system) de código aberto OSSEC - &lt;a href="http://www.ossec.net"&gt;http://www.ossec.net&lt;/a&gt; - criado pelo brasileiro Daniel Cid e muito utilizado para monitoramento de servidores.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Sumário&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;        - Introdução&lt;br /&gt;        - Arquitetura&lt;br /&gt;        - Análise de logs&lt;br /&gt;        - Monitoramento de integridade&lt;br /&gt;        - Detecção de rootkits&lt;br /&gt;        - Auditoria de políticas&lt;br /&gt;        - Alertas&lt;br /&gt;        - Active Response&lt;br /&gt;        - Instalação de servidor e agentes&lt;br /&gt;        - Configuração&lt;br /&gt;        - Arquivos de regras&lt;br /&gt;        - Personalização de regras: falso positivos e negativos&lt;br /&gt;        - Monitoramento e alertas&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Abaixo a programção dos demais dias do evento:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;25/11/2010 - Tutoriais&lt;/span&gt;&lt;br /&gt;08:00 - 17:00 Implementando o OSSEC HIDS&lt;br /&gt;             Jerônimo Zucco - Universidade de Caxias do Sul&lt;br /&gt;08:00 - 17:00 BGP para provedores de serviço&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;26/11/2010 - GTER 30&lt;/span&gt;&lt;br /&gt;08:00 - 08:50 Recepção&lt;br /&gt;08:50 - 09:00 Abertura&lt;br /&gt;&lt;br /&gt;09:00 - 09:20 De onde vem o spam? Seis meses de funcionamento de um 'spamtrap'&lt;br /&gt;              Danton Nunes - Internexo&lt;br /&gt;&lt;br /&gt;09:20 - 10:00 Boas práticas para peering no PTTMetro&lt;br /&gt;              Luís Balbinot - Commcorp Telecom&lt;br /&gt;&lt;br /&gt;10:00 - 10:30 DNSSEC - Provisionamento e reassinatura automática usando BIND&lt;br /&gt;              David Robert Camargo de Campos e Wilson Rogério Lopes - Nic.br&lt;br /&gt;&lt;br /&gt;10:30 - 11:00 Coffee Break&lt;br /&gt;&lt;br /&gt;11:00 - 11:30 Relato da entrada do servidor DNS raiz "I" em Porto Alegre&lt;br /&gt;              Leandro Bertholdo e Liane Tarouco - UFRGS&lt;br /&gt;&lt;br /&gt;11:30 - 12:30 DNS Root Signing HowTo, Lessons Learned, and Future Impact&lt;br /&gt;              Richard Lamb - ICANN&lt;br /&gt;&lt;br /&gt;12:30 - 14:00 Almoço&lt;br /&gt;&lt;br /&gt;14:00 - 14:50 Ferramentas para coexistência e transição IPv4 e IPv6&lt;br /&gt;              Antonio M. Moreiras - Nic.br&lt;br /&gt;&lt;br /&gt;14:50 - 15:10 ASN 32bits - Seu uso na Internet BR&lt;br /&gt;              Ricardo Patara - Nic.br&lt;br /&gt;&lt;br /&gt;15:10 - 15:40 Coffee Break&lt;br /&gt;&lt;br /&gt;15:40 - 16:00 IPv6 - Análise sobre seu uso na Internet BR&lt;br /&gt;              Ricardo Patara - Nic.br&lt;br /&gt;&lt;br /&gt;16:00 - 16:30 IPv6 sobre Redes Metropolitanas. Estudo de Caso: MetroPoa&lt;br /&gt;              Cesar Loureiro, Leandro Bertholdo e Liane Tarouco - UFRGS&lt;br /&gt;&lt;br /&gt;16:30 - 17:30 BIND 10 - The architecture of the next generation DNS server&lt;br /&gt;              Shane Kerr - ISC&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;27/11/2010 - GTS 16&lt;/span&gt;&lt;br /&gt;08:00 - 08:50 Recepção&lt;br /&gt;08:50 - 09:00 Abertura&lt;br /&gt;&lt;br /&gt;09:00 - 09:40 Secure Application Development for the Enterprise : Practical,&lt;br /&gt;              Real-world Tips&lt;br /&gt;              Luiz Gustavo Cunha Barbato, Mauricio Westendorff Pegoraro e&lt;br /&gt;              Rafael Dreher - Dell&lt;br /&gt;&lt;br /&gt;09:40 - 10:20 Coleta, Identificação e Extração de Dados (Data Carving)&lt;br /&gt;              em Mídias e em Redes&lt;br /&gt;              Ricardo Kléber Martins Galvão - IFRN&lt;br /&gt;&lt;br /&gt;10:20 - 10:50 Coffee Break&lt;br /&gt;&lt;br /&gt;10:50 - 11:30 Apresentação convidada (a definir)&lt;br /&gt;&lt;br /&gt;11:30 - 12:10 Resposta a incidentes: Diagnosticos equivocados e finais felizes&lt;br /&gt;              Nelson Murilo - DTE&lt;br /&gt;&lt;br /&gt;12:10 - 14:00 Almoço&lt;br /&gt;&lt;br /&gt;14:00 - 14:40 Usando visualização para documentação rápida de incidentes&lt;br /&gt;              de segurança&lt;br /&gt;              Gabriel Dieterich Cavalcante e Paulo Lício de Geus - IC/UNICAMP&lt;br /&gt;&lt;br /&gt;14:40 - 15:20  Análise Comportamental de Malware&lt;br /&gt;              André Grégio, Dario Fernandes, Vitor Afonso e&lt;br /&gt;              Paulo Lício de Geus - CTI/MCT e UNICAMP&lt;br /&gt;&lt;br /&gt;15:20 - 15:50 Coffee Break&lt;br /&gt;&lt;br /&gt;15:50 - 16:30 Estudos de Caso&lt;br /&gt;              Reinaldo de Medeiros - Entropia Security&lt;br /&gt;&lt;br /&gt;16:30 - 17:10 Segurança em Passaportes Eletrônicos&lt;br /&gt;              Ivo de Carvalho Peixinho - Polícia Federal&lt;br /&gt;&lt;br /&gt;17:10 - 17:20 Encerramento&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Estarei participando do evento nos dias 25 e 26, pois no dia 27 estarei indo à São Paulo participar da Sétima Edição da &lt;a href="http://www.h2hc.org.br"&gt;Hackers to Hackers Conference - H2HC&lt;/a&gt;. Pena que não vou conseguir participar do GTS, que também vai ser muito bom.&lt;br /&gt;&lt;br /&gt;Nos encontramos lá.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2326294951766004946?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/I77J7YJ523RCzjv5q53IFmGoRuk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/I77J7YJ523RCzjv5q53IFmGoRuk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/I77J7YJ523RCzjv5q53IFmGoRuk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/I77J7YJ523RCzjv5q53IFmGoRuk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/GdiqeLjjNAk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2326294951766004946/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2326294951766004946&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2326294951766004946?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2326294951766004946?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/GdiqeLjjNAk/tutorial-de-ossec-no-gtergts-em-sao.html" title="Tutorial de OSSEC no GTER/GTS em São Leopoldo" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/11/tutorial-de-ossec-no-gtergts-em-sao.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QESXs9fip7ImA9Wx5bEUQ.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-5706679776765928611</id><published>2010-10-27T14:48:00.003-02:00</published><updated>2010-10-27T15:08:28.566-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-10-27T15:08:28.566-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Três alternativas para se proteger do Firesheep</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://software.informaction.com/data/noscript/logo.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 128px; height: 128px;" src="http://software.informaction.com/data/noscript/logo.png" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Alternativa 1&lt;/span&gt;: Utilizar o plugin &lt;a href="http://noscript.net"&gt;NoScript&lt;/a&gt; no Firefox e configurar:&lt;br /&gt;&lt;br /&gt;NoScript-&gt;Options-&gt;Advanced-&gt;HTTPS&lt;br /&gt;&lt;br /&gt;Force the following sites to use secure (HTTPS) connections:&lt;br /&gt;twitter.com&lt;br /&gt;*.twitter.com&lt;br /&gt;google.com&lt;br /&gt;*.google.com&lt;br /&gt;facebook.com&lt;br /&gt;*.facebook.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="https://www.eff.org/files/HTTPS_Everywhere_new_logo.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 360px; height: 311px;" src="https://www.eff.org/files/HTTPS_Everywhere_new_logo.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Alternativa 2&lt;/span&gt;: Instalar o plugin &lt;a href="https://www.eff.org/https-everywhere"&gt;HTTPS Everywhere&lt;/a&gt; no Firefox;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Alternartiva 3&lt;/span&gt;:   Não usar twitter, facebook, gmail e qualquer serviço que não utilize sempre canal seguro para comunicação em redes públicas, ou sempre verificar se o seu acesso é sempre via https ou através de VPN.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Apresentação sobre o Firesheep realizada na Toorcon &lt;a href="http://codebutler.github.com/firesheep/tc12"&gt;aqui&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;O ataque do &lt;a href="http://codebutler.github.com/firesheep"&gt;Firesheep&lt;/a&gt; não é novidade, apenas facilitou com poucos cliques o que já era possível fazer a mão e escancarou o problema. E o Firesheep também não é único, também existe a ferramenta &lt;a href="http://jonty.co.uk/idiocy"&gt;Idiocy&lt;/a&gt;, feita em python.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Para os &lt;span style="font-weight:bold;"&gt;desenvolvedores Web&lt;/span&gt;:&lt;br /&gt;&lt;br /&gt;- Todos os cookies das aplicações devem estar com a flag "&lt;span style="font-weight:bold;"&gt;Secure&lt;/span&gt;" especificada.&lt;br /&gt;&lt;br /&gt;- Outro cuidado é também especificar a flag "&lt;span style="font-weight:bold;"&gt;HTTPOnly&lt;/span&gt;" nos cookies, para evitar ataques do tipo XSS (cross-site scripting).&lt;br /&gt;&lt;br /&gt;    Para maiores referências, verifiquem a página da OWASP: &lt;a href="http://www.owasp.org/index.php/Testing_for_cookies_attributes_%28OWASP-SM-002%29 "&gt;http://www.owasp.org/index.php/Testing_for_cookies_attributes_%28OWASP-SM-002%29 &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-5706679776765928611?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Usq8iglKphDlVuCLMEWXeN2r4Ec/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Usq8iglKphDlVuCLMEWXeN2r4Ec/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Usq8iglKphDlVuCLMEWXeN2r4Ec/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Usq8iglKphDlVuCLMEWXeN2r4Ec/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/iAhP5WbERAo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/5706679776765928611/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=5706679776765928611&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/5706679776765928611?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/5706679776765928611?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/iAhP5WbERAo/tres-alternativas-para-se-proteger-do.html" title="Três alternativas para se proteger do Firesheep" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/10/tres-alternativas-para-se-proteger-do.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08MQXk5eCp7ImA9Wx5UFko.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-8746419497051698695</id><published>2010-10-21T14:43:00.000-02:00</published><updated>2010-10-21T14:51:20.720-02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-10-21T14:51:20.720-02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="video" /><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Are You Smarter Than John?</title><content type="html">&lt;object width="640" height="385"&gt;&lt;param name="movie" value="http://www.youtube.com/v/fB7X7QOzJ_k?fs=1&amp;amp;hl=pt_BR"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/fB7X7QOzJ_k?fs=1&amp;amp;hl=pt_BR" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="640" height="385"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;via @ronaldotcom&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-8746419497051698695?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/SO3Tf9rYKE-IPor28B7g8LEsxfo/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SO3Tf9rYKE-IPor28B7g8LEsxfo/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/SO3Tf9rYKE-IPor28B7g8LEsxfo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/SO3Tf9rYKE-IPor28B7g8LEsxfo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/qSQoQQiPXgU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/8746419497051698695/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=8746419497051698695&amp;isPopup=true" title="2 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/8746419497051698695?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/8746419497051698695?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/qSQoQQiPXgU/are-you-smarter-than-john.html" title="Are You Smarter Than John?" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/10/are-you-smarter-than-john.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8MR3g_cCp7ImA9Wx5WGEo.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-459335012200232463</id><published>2010-09-30T17:10:00.004-03:00</published><updated>2010-09-30T17:18:06.648-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-09-30T17:18:06.648-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="eventos" /><title>Evento sobre Crimes Cibernéticos em Rio Grande</title><content type="html">Para quem é da região sul do RS, por favor ajudem a divulgar. O evento ocorrerá dia 14 de outubro, e é gratuito.&lt;br /&gt;&lt;br /&gt;   O evento em Rio Grande será promovido pela Superintendência Estadual Rio Grande do Sul da ABIN e pelo Comando do 5º Distrito Naval. É a primeira vez que ocorre um evento desse tipo à Metade Sul do estado. É aberto ao público em geral e tem inscrição gratuita, a ser feita previamente conforme explicado na programação do evento na figura abaixo:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V8x6Zp7bni8/TKTvEbdy1dI/AAAAAAAAAIw/HCAGmh_aZVk/s1600/Ciclo+de+Palestras+-+Rio+Grande+2010.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 412px; height: 1000px;" src="http://2.bp.blogspot.com/_V8x6Zp7bni8/TKTvEbdy1dI/AAAAAAAAAIw/HCAGmh_aZVk/s1600/Ciclo+de+Palestras+-+Rio+Grande+2010.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5522801902434309586" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-459335012200232463?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/9adYnN9_Z0fOBnuI1Idsk52CGzQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9adYnN9_Z0fOBnuI1Idsk52CGzQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/9adYnN9_Z0fOBnuI1Idsk52CGzQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/9adYnN9_Z0fOBnuI1Idsk52CGzQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/1Nr72b71Hq8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/459335012200232463/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=459335012200232463&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/459335012200232463?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/459335012200232463?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/1Nr72b71Hq8/evento-sobre-crimes-ciberneticos-em-rio.html" title="Evento sobre Crimes Cibernéticos em Rio Grande" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_V8x6Zp7bni8/TKTvEbdy1dI/AAAAAAAAAIw/HCAGmh_aZVk/s72-c/Ciclo+de+Palestras+-+Rio+Grande+2010.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/09/evento-sobre-crimes-ciberneticos-em-rio.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MASHcyfCp7ImA9Wx5VEUw.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2280333779195017989</id><published>2010-09-29T21:42:00.008-03:00</published><updated>2010-10-03T11:17:29.994-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-10-03T11:17:29.994-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>RSS feed dos Blogs Brasileiros sobre Segurança da Informação</title><content type="html">Todos já devem conhecer a &lt;a href="http://tinyurl.com/blogseg"&gt;lista de Blogs sobre Segurança da Informação&lt;/a&gt; criada pelo &lt;a href="http://sseguranca.blogspot.com"&gt;Sandro Suffert&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Baseado nessa lista, eu criei um feed RSS no Google Reader com a reunião de todos os blogs e sites. Caso tenha interesse em assinar o feed, use a seguinte url:&lt;a href="http://www.google.com/reader/bundle/user%2F13736961360220030633%2Fbundle%2FBlogs%20de%20Seguran%C3%A7a%20Brasileiros"&gt;&lt;br /&gt;http://www.google.com/reader/bundle/user%2F13736961360220030633%2Fbundle%2FBlogs%20de%20Seguran%C3%A7a%20Brasileiros&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Tentarei sempre deixar o feed sincronizado com a lista do Suffert, que está em constante atualização. Caso encontre algum problema ou sugestão, por favor me avise.&lt;br /&gt;&lt;br /&gt;O ideal seria criar um planeta, como o do &lt;a href="http://www.securitybloggersnetwork.com"&gt;Security Bloggers Network&lt;/a&gt;, se alguém disponibilizar infraestrutura para hospedagem, pode ser criado um.&lt;br /&gt;&lt;br /&gt;Boa leitura!&lt;br /&gt;&lt;br /&gt;*UPDATE* : Criei mais um feed somente com os blogs de segurança de Portugal. Você pode assiná-lo aqui:&lt;br /&gt;&lt;a href="http://www.google.com/reader/bundle/user%2F13736961360220030633%2Fbundle%2FBlogs%20de%20Seguran%C3%A7a%20Portugueses"&gt;&lt;br /&gt;http://www.google.com/reader/bundle/user%2F13736961360220030633%2Fbundle%2FBlogs%20de%20Seguran%C3%A7a%20Portugueses&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2280333779195017989?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ENCktsFmyaKLGg8qo4fk4s1zOM4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ENCktsFmyaKLGg8qo4fk4s1zOM4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ENCktsFmyaKLGg8qo4fk4s1zOM4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ENCktsFmyaKLGg8qo4fk4s1zOM4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/fLch6uAhDUg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2280333779195017989/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2280333779195017989&amp;isPopup=true" title="8 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2280333779195017989?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2280333779195017989?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/fLch6uAhDUg/todos-ja-devem-conhecer-lista-de-blogs.html" title="RSS feed dos Blogs Brasileiros sobre Segurança da Informação" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>8</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/09/todos-ja-devem-conhecer-lista-de-blogs.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YBSXwzeSp7ImA9Wx5RFkg.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-2358470696892571777</id><published>2010-08-24T11:04:00.002-03:00</published><updated>2010-08-24T11:12:38.281-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-24T11:12:38.281-03:00</app:edited><title>Ciclo de Palestras da Agência Brasileira de Inteligência – ABIN  Os Crimes Cibernéticos  e a Proteção do Conhecimento Sensível</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_V8x6Zp7bni8/THPSLS0DfBI/AAAAAAAAAIg/g39Yf00P15o/s1600/Folder+Palestra+ABIN+-+Agosto+2010.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 155px; height: 400px;" src="http://2.bp.blogspot.com/_V8x6Zp7bni8/THPSLS0DfBI/AAAAAAAAAIg/g39Yf00P15o/s400/Folder+Palestra+ABIN+-+Agosto+2010.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5508977860674812946" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Dia 16 de setembro de 2010, quinta-feira&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; 8h30min     Recepção dos Convidados&lt;br /&gt;&lt;br /&gt; 9horas        Abertura&lt;br /&gt;&lt;br /&gt; 9h10min     A Proteção do Conhecimento Sensível -  Eduardo Arthur Izycki,  Agência Brasileira de Inteligência (Abin)&lt;br /&gt;&lt;br /&gt; 10 horas      Coffe-Break&lt;br /&gt;&lt;br /&gt; 10h15min   Investigação dos Crimes Praticados em Ambiente Virtual   Emerson Wendt, DRCI/Polícia Civil do Rio Grande do Sul &lt;br /&gt;&lt;br /&gt; 11h15min   Introdução a uso da Criptografia na Internet – César Bernado  Agência Brasileira de Inteligência (Abin)&lt;br /&gt;&lt;br /&gt; 12horas       Intervalo Almoço&lt;br /&gt;&lt;br /&gt; 14horas       Segurança da Informação – Aspectos Culturais -  Thiago Berto, PBI - Segurança da Informação.   &lt;br /&gt;&lt;br /&gt; 14h50min    Um panorama atual dos Ataques via Internet – Maria de Fátima Webber do Prado Lima e Jerônimo Zucco – Universidade de Caxias do Sul (UCS).   &lt;br /&gt;&lt;br /&gt; 15h45min       Coffee break&lt;br /&gt;&lt;br /&gt; 16h              Segurança em Redes Sociais – Robertson Frizero Barros     Agência Brasileira de Inteligência (Abin)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; 17h  Debate: Crimes Cibernéticos e Proteção do Conhecimento Sensível &lt;br /&gt;   Abin / DRCI/ PBI / UCS &lt;br /&gt;&lt;br /&gt; 17h45min        Encerramento&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ministrantes: &lt;br /&gt;-  Eduardo Arthur Izycki : Oficial de Inteligência da Agência Brasileira de Inteligência, lotado na sede do órgão em Brasília, atuando na Coordenação-Geral de Proteção do Conhecimento Sensível&lt;br /&gt;&lt;br /&gt;-  Emerson Wendt: Delegado de Polícia Civil do Rio Grande do Sul, Titular da Delegacia de Repressão aos Crimes Informáticos do Departamento Estadual de Investigações Criminais da Polícia Civil do RS. Professor dos cursos de Inteligência de Segurança Pública da Secretaria Nacional de Segurança Pública. Coordenador e Professor da disciplina de Inteligência Policial da Academia de Polícia Civil do RS.&lt;br /&gt;&lt;br /&gt;-  César Luiz Bernardo: Oficial de Inteligência atuando na área de Contra-Inteligência, no Programa Nacional de Proteção do Conhecimento Sensível (PNPC), na Superintendência Estadual do Mato Grosso do Sul&lt;br /&gt;&lt;br /&gt;- Thiago Berto: Sócio-fundador e diretor de Negócios da PBI - Segurança da Informação, possuindo mais de 11 anos de experiência na área e ainda algumas das mais importantes certificações no segmento de TI, tais como Microsoft Certified Systems Engineer, Red Hat Certified Engineer e Certificação ITIL Foundations.&lt;br /&gt;&lt;br /&gt;-  Maria de Fátima Webber do Prado Lima -  doutora em Informática na Educação, mestre em Ciência da Computação na área de redes de computadores. Professora e pesquisadora da UCS. Possui atuação na área de redes de computadores onde ministra disciplinas na graduação e no pós-graduação. Atuou como coordenadora da rede da UCS durante 9 anos.  &lt;br /&gt;&lt;br /&gt;Jerônimo Zucco:  é certificado CISSP (Certified Information Systems Security Professional), Bacharel em Ciência da Computação e Pós-Graduado em Gerência e Segurança de Redes de Computadores. Atua na área de segurança de sistemas a 10 anos e trabalha no Núcleo de Processamento de Dados da UCS. &lt;br /&gt;&lt;br /&gt;- Robertson Frizero Barros - Oficial de Inteligência atuando na área de Contra-Inteligência, no Programa Nacional de Proteção do Conhecimento Sensível (PNPC), na Superintendência Estadual do Rio Grande do Sul. Formado em Ciências Navais pela Escola Naval, foi Oficial do Corpo de Intendentes da Marinha. &lt;br /&gt;&lt;br /&gt;Informações Gerais e Inscrições: &lt;br /&gt;Local: Sala Florense – Bloco M – Cidade Universitária &lt;br /&gt;Público: alunos, professores, funcionários e empresas parceiras da UCS. &lt;br /&gt;Valor: Gratuito&lt;br /&gt;Inscrições no site da UCS no link &lt;a href="http://www.ucs.br/ucs/eventos/ciclo_palestras_agencia_brasileira_inteligencia_abin/apresentacao"&gt;http://www.ucs.br/ucs/eventos/ciclo_palestras_agencia_brasileira_inteligencia_abin/apresentacao&lt;/a&gt; &lt;br /&gt;Informações pelo e-mail: andresa.colloda@ucs.br. &lt;br /&gt;&lt;br /&gt;Organização:  Coordenadoria de Inovação, Desenvolvimento e Extensão&lt;br /&gt;  Escritório de Transferência de Tecnologia – ETT (sala 301, bloco A)&lt;br /&gt;  Andresa Colloda – andresa.colloda@ucs.br ((54) 3218.2148 ou ramal 2148)&lt;br /&gt;                       Andréa Venturini Pavan – avpavan@ucs.br&lt;br /&gt;  Agência Brasileira de Inteligência -Abin &lt;br /&gt;Obs.: O Ciclo de Palestras da Agência Brasileira de Inteligência (ABIN), tratando do tema "Os  Crimes Cibérneticos e a Proteção do Conhecimento Sensível" está inserida na Semana Acadêmica do Centro de Computação e Tecnologia da Informação - CCTI. A programação completa da Semana Acadêmica está no site da UCS: &lt;a href="http://www.ucs.br/portais/ccti/eventos/"&gt;http://www.ucs.br/portais/ccti/eventos/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-2358470696892571777?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/mDsL9F3p9JGqGYaUDQbSMeGK_NI/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mDsL9F3p9JGqGYaUDQbSMeGK_NI/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/mDsL9F3p9JGqGYaUDQbSMeGK_NI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/mDsL9F3p9JGqGYaUDQbSMeGK_NI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/MSSSp1uWr1U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/2358470696892571777/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=2358470696892571777&amp;isPopup=true" title="0 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2358470696892571777?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/2358470696892571777?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/MSSSp1uWr1U/ciclo-de-palestras-da-agencia.html" title="Ciclo de Palestras da Agência Brasileira de Inteligência – ABIN  Os Crimes Cibernéticos  e a Proteção do Conhecimento Sensível" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_V8x6Zp7bni8/THPSLS0DfBI/AAAAAAAAAIg/g39Yf00P15o/s72-c/Folder+Palestra+ABIN+-+Agosto+2010.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/08/ciclo-de-palestras-da-agencia.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0AEQXY4eyp7ImA9Wx5SGUs.&quot;"><id>tag:blogger.com,1999:blog-15117118.post-5917467621698882585</id><published>2010-08-16T11:31:00.002-03:00</published><updated>2010-08-16T11:41:40.833-03:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-16T11:41:40.833-03:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="artigos" /><category scheme="http://www.blogger.com/atom/ns#" term="segurança" /><title>Revista Stay Safe - Segunda Edição</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.staysafepodcast.com.br/wp-content/themes/Black_and_Red_Theme/Black_and_Red_Theme/images/header_img.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 270px; height: 178px;" src="http://www.staysafepodcast.com.br/wp-content/themes/Black_and_Red_Theme/Black_and_Red_Theme/images/header_img.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Saiu a segunda edição da revista de segurança brasileira Stay Safe. Tive o prazer de ter um artigo meu sobre &lt;a href="http://selinuxproject.org/page/SVirt"&gt;sVirt&lt;/a&gt; publicado nessa edição. Segue abaixo o índice de artigos:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- sVirt: Aumentando a Segurança na Virtualização - por Jerônimo Zucco&lt;br /&gt;&lt;br /&gt;- Coluna: Snort Rules - por Rodrigo Montoro&lt;br /&gt;&lt;br /&gt;- Segurança no Desenvolvimento de Software - por Renato Salatiel&lt;br /&gt;&lt;br /&gt;- Lixo Eletrônico - por Gilberto Sudré&lt;br /&gt;&lt;br /&gt;- Selecionadas Stay Safe - por Tony Rodrigues&lt;br /&gt;&lt;br /&gt;- Análise de Sessão com Afterflow - por Michel Barbosa&lt;br /&gt;&lt;br /&gt;- SET: Social Engineering Toolkit - por Mauro Risonho de Paula&lt;br /&gt;&lt;br /&gt;- Coluna Direito Digital - por Roney Médice&lt;br /&gt;&lt;br /&gt;- Construindo o futuro: Murphy - por Glaysson dos Santos Tomaz&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Baixe a edição através desse link: &lt;a href="http://www.staysafepodcast.com.br/revista/RevistaStaySafe_2.pdf"&gt;Revista Stay Safe – 08/2010&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/15117118-5917467621698882585?l=jczucco.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/hU6pVTTSxiz45KGCZNYoWoIAPkY/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hU6pVTTSxiz45KGCZNYoWoIAPkY/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/hU6pVTTSxiz45KGCZNYoWoIAPkY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/hU6pVTTSxiz45KGCZNYoWoIAPkY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/ZuccoWeblog/~4/ivp6clMyACM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://jczucco.blogspot.com/feeds/5917467621698882585/comments/default" title="Postar comentários" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=15117118&amp;postID=5917467621698882585&amp;isPopup=true" title="1 Comentários" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/5917467621698882585?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/15117118/posts/default/5917467621698882585?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ZuccoWeblog/~3/ivp6clMyACM/revista-stay-safe-segunda-edicao.html" title="Revista Stay Safe - Segunda Edição" /><author><name>Jeronimo Zucco</name><uri>http://www.blogger.com/profile/09047816424320636865</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="32" height="30" src="http://4.bp.blogspot.com/_V8x6Zp7bni8/TCobg8nIT8I/AAAAAAAAAHY/HyUAnIkj19E/S220/z3.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://jczucco.blogspot.com/2010/08/revista-stay-safe-segunda-edicao.html</feedburner:origLink></entry></feed>

