<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;D08HQno9fSp7ImA9WhRRFE4.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222</id><updated>2011-11-27T15:17:13.465-08:00</updated><category term="gareth" /><category term="milworm" /><category term="flash" /><category term="hack" /><category term="security portfel" /><category term="zagrozenie" /><category term="xss xbl xhtml security" /><category term="tygodnia" /><category term="adresy" /><category term="infiltracja" /><category term="milw0rm" /><category term="rip" /><category term="lifehack" /><category term="9:23" /><category term="ryzyko" /><category term="security" /><category term="vulnerability" /><category term="urodziny" /><category term="podatnosci" /><category term="xss security ie8 freebsd exploit wordpress garethheyes" /><category term="(in)security" /><category term="str0ke" /><category term="cryoto aes security" /><category term="policy" /><category term="bankowosc" /><category term="klient" /><category term="tokeny" /><category term="internetowa" /><category term="iphone" /><category term="dns" /><category term="csp" /><category term="ssl" /><category term="xss" /><category term="confidence 2.0" /><category term="stroke" /><category term="droid" /><category term="ciekawe" /><category term="exploit" /><category term="linki" /><category term="xss security ie8 sql inj nasa vulnerability" /><title>ThinkSecure - Michał Wiczyński</title><subtitle type="html">&amp;quot;...These five heads should be familiar to every general: he who knows them will be victorious; he who knows them not will fail.&amp;quot;

Sun Tzu
irytacje &amp;amp; przemyslenia by wheelq</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://thinklikeninja.blogspot.com/" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>21</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/thinksecure" /><feedburner:info uri="thinksecure" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;DU4AQXY8fSp7ImA9WxBXF0g.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-3164811451470423986</id><published>2010-01-29T01:39:00.000-08:00</published><updated>2010-01-29T01:39:00.875-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-29T01:39:00.875-08:00</app:edited><title>I jak tu (nie) ufac</title><summary type="html">By Rob Preece Crime Correspondent

"A FORMER anti-fraud boss at the Yorkshire-based bank First Direct has been jailed for stealing from customers' accounts to fund his alcoholism and cocaine addiction.
In his £65,000-a-year job as head of fraud operations, Richard Crawford, 41, was trusted with the personal details of account holders whose finances were thought to be most at risk from criminals."&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/KKwTEbxXI98" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/3164811451470423986/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2010/01/i-jak-tu-nie-ufac.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3164811451470423986?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3164811451470423986?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/KKwTEbxXI98/i-jak-tu-nie-ufac.html" title="I jak tu (nie) ufac" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2010/01/i-jak-tu-nie-ufac.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0ANQXwycCp7ImA9WxBQEkQ.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-7190443603860971588</id><published>2010-01-12T04:36:00.000-08:00</published><updated>2010-01-12T04:36:30.298-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-01-12T04:36:30.298-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="droid" /><category scheme="http://www.blogger.com/atom/ns#" term="vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="iphone" /><title>Niebezpieczny Droid</title><summary type="html">Zła wiadomość dla użytkowników Droid'a. Android OS ver. 2.0.1, czyli aktualna wersja na której działa Droid, posiada lukę bezpieczeństwa która umożliwia obejście zabezpieczenia blokady ekranu.



Zabezpieczenie polega na połączeniu kropek na ekranie, w taki sposób jaki wcześniej został zdefiniowany przez użytkownika. (iPhone posiada podobną opcję).

Obejście zabezpieczenia jest niezwykle łatwe. &lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/wCrk-zL4Gk8" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/7190443603860971588/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2010/01/niebezpieczny-droid.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/7190443603860971588?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/7190443603860971588?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/wCrk-zL4Gk8/niebezpieczny-droid.html" title="Niebezpieczny Droid" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2010/01/niebezpieczny-droid.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEADRH04eCp7ImA9WxBSEk4.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-7089558141604069967</id><published>2009-12-19T07:32:00.000-08:00</published><updated>2009-12-19T07:32:55.330-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-19T07:32:55.330-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="security portfel" /><title>Stalowa chrona kart zbliżeniowych</title><summary type="html">Posiadając, ostatnio często reklamowane przez różne bank, kartę zbliżeniową, jesteśmy narażeni na możliwość zczytania z niej danych.

W jaki sposób możemy się zabezpieczyć przed złodziejami? Z pomocą przychodzi portfel 'utkany ze stali'. 



Według opisu producenta, posiadając taki portfel, możemy się odprężyć i być spokojni, że nasze dane pozostaną przy nas.

Portfel utkany jest z ponad 20.000 &lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/K4mmI7V7T2Y" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/7089558141604069967/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/stalowa-chrona-kart-zblizeniowych.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/7089558141604069967?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/7089558141604069967?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/K4mmI7V7T2Y/stalowa-chrona-kart-zblizeniowych.html" title="Stalowa chrona kart zbliżeniowych" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/stalowa-chrona-kart-zblizeniowych.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMDQ38-fip7ImA9WxBSEk4.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-4954459875045374713</id><published>2009-12-16T03:10:00.000-08:00</published><updated>2009-12-19T07:44:32.156-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-19T07:44:32.156-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="xss" /><category scheme="http://www.blogger.com/atom/ns#" term="(in)security" /><category scheme="http://www.blogger.com/atom/ns#" term="urodziny" /><title>#10 'te #urodziny #xss ! sto lat sto lat :)</title><summary type="html">16-ego stycznia, 2000, dla małej grupki inżynierów w Microsoft, zostaly zasugerowane nastepujace nazwy:

Unauthorized Site Scripting
Unofficial Site Scripting
URL Parameter Script Insertion
Cross Site Scripting
Synthesized Scripting
Fraudulent Scripting
Następnego dnia uzgodniono nazwę - Cross Site Scripting.

Na początku lutego, wypuszczono dokument (CERT):

http://www.cert.org/advisories/CA-&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/ljzUwUJ-nic" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/4954459875045374713/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/10-te-urodziny-xss-sto-lat-sto-lat.html#comment-form" title="Komentarze (1)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/4954459875045374713?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/4954459875045374713?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/ljzUwUJ-nic/10-te-urodziny-xss-sto-lat-sto-lat.html" title="#10 'te #urodziny #xss ! sto lat sto lat :)" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/10-te-urodziny-xss-sto-lat-sto-lat.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8AQHs4cCp7ImA9WxBTE0s.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-6443990854115912469</id><published>2009-12-09T04:14:00.001-08:00</published><updated>2009-12-09T04:14:01.538-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-09T04:14:01.538-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="cryoto aes security" /><title>(update) do (in)security tygodnia</title><summary type="html">Nie wiem czemu ale zapodzialo mi się to gdzieś, więc wstawiam teraz:


http://www.heise-online.pl/security/news/item/Nowy-sposob-lamania-szyfru-AES-878754.html   Nowy sposób na #łamanie #AES #security #crypto&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/fpfU3bU7DbY" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/6443990854115912469/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/update-do-insecurity-tygodnia.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/6443990854115912469?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/6443990854115912469?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/fpfU3bU7DbY/update-do-insecurity-tygodnia.html" title="(update) do (in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/update-do-insecurity-tygodnia.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE8DQno-fCp7ImA9WxBTE0g.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-6388680113928358406</id><published>2009-12-09T03:07:00.000-08:00</published><updated>2009-12-09T03:07:53.454-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-09T03:07:53.454-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="xss xbl xhtml security" /><title>All in one exploit...s !</title><summary type="html">Witam. Dzisiaj w moje raczki wpadla super paczka mini tyci exploitow ;)

Otoz pan sirdarckcat przed chwilą opublikował niezły zestaw exploitów all in one.

Oto one:

http://0x.lv/xss.xml XBL+XHTML

http://0x.lv/xss.css (binding/expression/jsuri) 

http://0x.lv/xss.swf (getURL)

&amp;lt;script src=//0x.lv&amp;gt; LUB &amp;lt;link rel=stylesheet href=//0x.lv&amp;gt; LUB &amp;lt;img src=//0x.lv&amp;gt; LUB &amp;lt;iframe src=//0x.lv&amp;gt; także: XHR/&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/C4biYBDFMPM" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/6388680113928358406/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/all-in-one-exploits.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/6388680113928358406?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/6388680113928358406?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/C4biYBDFMPM/all-in-one-exploits.html" title="All in one exploit...s !" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/all-in-one-exploits.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MGR3k7eyp7ImA9WxBTE08.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-531753578677067031</id><published>2009-12-08T17:17:00.000-08:00</published><updated>2009-12-08T17:17:06.703-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-08T17:17:06.703-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="xss security ie8 sql inj nasa vulnerability" /><title>(in)security tygodnia</title><summary type="html">Witam ponownie, zgodnie z zapowiedzią kolejna porcja ciekawostek ze świata security:

http://www.net-security.org/secworld.php?id=8594
#Fake #fingerprint fools #biometric #devices #security


http://www.heise-online.pl/security/news/item/Ostatnia-deska-ratunku-UFO-hakera-877758.html
Ostatnia deska ratunku "#UFO-#haker a"#Gary ’ego #McKinnon a


http://www.networkworld.com/news/2009/120709-&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/JhEr9T-HiBw" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/531753578677067031/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/insecurity-tygodnia_08.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/531753578677067031?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/531753578677067031?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/JhEr9T-HiBw/insecurity-tygodnia_08.html" title="(in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/insecurity-tygodnia_08.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0YHQ3wzcCp7ImA9WxNaGU8.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-2562301015951875699</id><published>2009-12-02T14:10:00.000-08:00</published><updated>2009-12-04T04:18:52.288-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-04T04:18:52.288-08:00</app:edited><title>OWASP TOP10 2010 RC1 PL</title><summary type="html">W związku z niedawno opulbikowanym #OWASP TOP10 RC1 http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project postanowiłem przetłumaczyć dokument, wzbogacając go o parę własnych zdań. Dokument pobieramy tutaj: http://www.slideshare.net/thinksecure/owasp-top10-2010-rc1-pl


Aktualizacja:

Zapraszam rowniez na: http://pentester.jogger.pl/2009/12/02/owasp-top-10/


Owasp Top10 2010 RC1 PLView &lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/bCp2r0DpjEM" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/2562301015951875699/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/owasp-top10-2010-rc1-pl.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/2562301015951875699?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/2562301015951875699?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/bCp2r0DpjEM/owasp-top10-2010-rc1-pl.html" title="OWASP TOP10 2010 RC1 PL" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/owasp-top10-2010-rc1-pl.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8HQnoyfip7ImA9WxNaFkU.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-4508615642343303743</id><published>2009-12-01T09:17:00.000-08:00</published><updated>2009-12-01T09:17:13.496-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-12-01T09:17:13.496-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="xss security ie8 freebsd exploit wordpress garethheyes" /><title>(in)security tygodnia</title><summary type="html">&amp;lt;!--StartFragment--&amp;gt;  
Witam ponownie, zgodnie z zapowiedzią kolejna porcja ciekawostek ze świata security:


http://www.heise-online.pl/security/news/item/Exploit-dajacy-uprawnienia-roota-w-FreeBSD-Uzupelnienie-873354.html #Exploit dający uprawnienia roota w #FreeBSD #security #root

http://www.thespanner.co.uk/2009/11/23/ping-pong-obfuscation/ #Obfuskacja w obfuskacji obfuskacji... #xss #&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/hQiYDk8Ligc" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/4508615642343303743/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/12/insecurity-tygodnia.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/4508615642343303743?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/4508615642343303743?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/hQiYDk8Ligc/insecurity-tygodnia.html" title="(in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/12/insecurity-tygodnia.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUYMQX8zeSp7ImA9WxNbGUo.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-8345504820867736666</id><published>2009-11-23T03:49:00.000-08:00</published><updated>2009-11-23T03:53:00.181-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-23T03:53:00.181-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="gareth" /><category scheme="http://www.blogger.com/atom/ns#" term="xss" /><category scheme="http://www.blogger.com/atom/ns#" term="(in)security" /><category scheme="http://www.blogger.com/atom/ns#" term="csp" /><title>CSP na kolana</title><summary type="html">Gareth Heyes opublikował właśnie na swoim blogu, informację dotyczącą sposobu ominięcia zabezpieczeń w #CSP http://www.thespanner.co.uk/2009/11/23/bypassing-csp-for-fun-no-profit/


Na czym polega błąd?

Każda strona z feedem JSON'a nad którym może mieć kontrolę atakujący, może zostać zarażona własnym ciągiem JSON'a, dzięki czemu można kontrolować pozostałe elementy feed'a.
Wyjaśnijmy to na &lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/GBr0x-JscTw" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/8345504820867736666/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/csp-na-kolana.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/8345504820867736666?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/8345504820867736666?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/GBr0x-JscTw/csp-na-kolana.html" title="CSP na kolana" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/csp-na-kolana.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkUGSXczeyp7ImA9WxNbFUg.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-1696815493956292056</id><published>2009-11-18T05:15:00.000-08:00</published><updated>2009-11-18T05:17:08.983-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-18T05:17:08.983-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="lifehack" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>Każdy lubi puknąć</title><summary type="html">Przeglądając lifehack'i, trafiłem na dosyć ciekawe zastosowanie pukania jako klucza do drzwi.



Muszę przyznać, że pomysł jest naprawdę oryginalny, ale ma wiele wad i raczej nie znajdzie zastosowania jako zabezpieczenie drzwi wejsciowych od domu.

http://www.engadget.com/2009/11/04/secret-knock-door-lock-defends-home-from-rhythmically-impaired/&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/kUgaUUgDBVc" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/1696815493956292056/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/rytmiczne-pukanie.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/1696815493956292056?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/1696815493956292056?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/kUgaUUgDBVc/rytmiczne-pukanie.html" title="Każdy lubi puknąć" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/rytmiczne-pukanie.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8ERHY7eCp7ImA9WxNbFUk.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-2656014643153615553</id><published>2009-11-18T04:36:00.001-08:00</published><updated>2009-11-18T04:36:45.800-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-18T04:36:45.800-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="infiltracja" /><category scheme="http://www.blogger.com/atom/ns#" term="(in)security" /><title>Infiltracja w Polsce</title><summary type="html">No proszę, myślałem że już nic mnie w tym kraju nie zaskoczy, a tu takie numery...


http://osnews.pl/rzad-ujawnil-projekt-filtrowania-internetu-w-polsce/&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/j6VK-wwfb74" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/2656014643153615553/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/infiltracja-w-polsce.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/2656014643153615553?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/2656014643153615553?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/j6VK-wwfb74/infiltracja-w-polsce.html" title="Infiltracja w Polsce" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/infiltracja-w-polsce.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEINRnk8fyp7ImA9WxNbFUk.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-4780278939364527066</id><published>2009-11-18T04:16:00.000-08:00</published><updated>2009-11-18T04:16:37.777-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-18T04:16:37.777-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="confidence 2.0" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><title>CONFidence 2.0</title><summary type="html">To już jutro,

Agenda: http://200902.confidence.org.pl/agenda/

Zapowiada się naprawdę ciekawie :)

Jednak widzę, że ponownie będzie problem z wyborem niektórych wykładów, np:

Gareth Heyes XSS Lightsabre techniques using Hackvertor
oraz w tym samym czasie:
Frank Breedijk AutoNessus: analyzing vulnerability assessment data the easy way…

tak samo: Gynvael Coldwind Practical security in computer &lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/OtIRkND4wW4" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/4780278939364527066/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/confidence-20.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/4780278939364527066?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/4780278939364527066?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/OtIRkND4wW4/confidence-20.html" title="CONFidence 2.0" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/confidence-20.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU4GQns8fCp7ImA9WxNbFEs.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-3824204894599806762</id><published>2009-11-17T06:25:00.000-08:00</published><updated>2009-11-17T06:25:23.574-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-17T06:25:23.574-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="dns" /><category scheme="http://www.blogger.com/atom/ns#" term="policy" /><category scheme="http://www.blogger.com/atom/ns#" term="ssl" /><category scheme="http://www.blogger.com/atom/ns#" term="exploit" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="flash" /><category scheme="http://www.blogger.com/atom/ns#" term="hack" /><title>(in)security tygodnia</title><summary type="html">Witam ponownie, zgodnie z zapowiedzią kolejna porcja ciekawostek ze świata security:



http://www.examiner.com/x-14651-Minneapolis-Information-Technology-Examiner~y2009m11d11-Cenzic-wants-to-make-sure-your-Web-site-is-healthy?cid=email-this-article
#Cenzic wants to make sure your #Web site is #healthy

http://www.darknet.org.uk/2009/11/ssl-renegotiation-bug-succesfully-used-to-attack-twitter/
#&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/4sDOg6Adejs" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/3824204894599806762/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/insecurity-tygodnia_17.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3824204894599806762?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3824204894599806762?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/4sDOg6Adejs/insecurity-tygodnia_17.html" title="(in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/insecurity-tygodnia_17.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEACQXszfSp7ImA9WxNUGEk.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-3396292139497611435</id><published>2009-11-10T01:52:00.000-08:00</published><updated>2009-11-10T01:52:40.585-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-10T01:52:40.585-08:00</app:edited><title>(in)security tygodnia</title><summary type="html">
Witam ponownie, zgodnie z zapowiedzią kolejna porcja ciekawostek:
http://blog.securitystandard.pl/news/352111.html - Łamanie haseł w chmurze #pgp #lamanie #security #cloud

http://blogs.zdnet.com/security/?p=4805 - iHack wirus na iPhone #iphone #wirus #security #jail

http://livelabs.com/web-sandbox/ - Web sandbox od microsoft #microsoft #web #security #sandbox

http://chuvakin.blogspot.com/2009&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/4qkEMX3I61g" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/3396292139497611435/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/insecurity-tygodnia_10.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3396292139497611435?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3396292139497611435?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/4qkEMX3I61g/insecurity-tygodnia_10.html" title="(in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/insecurity-tygodnia_10.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEQARHg8fip7ImA9WxNUE08.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-7090977670148452698</id><published>2009-11-04T01:18:00.000-08:00</published><updated>2009-11-04T01:19:05.676-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-04T01:19:05.676-08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="str0ke" /><category scheme="http://www.blogger.com/atom/ns#" term="stroke" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="milw0rm" /><category scheme="http://www.blogger.com/atom/ns#" term="rip" /><category scheme="http://www.blogger.com/atom/ns#" term="9:23" /><category scheme="http://www.blogger.com/atom/ns#" term="milworm" /><title>str0ke nie żyje, milw0rm</title><summary type="html">bl4cksecurity.blogspot.com/2009/11/str0ke-milworms-funeral-is-this-friday.html

Many of us have wondered where str0ke has been and why #milw0rm has not been updated in a good while. I recently was informed that #str0ke has been hospitalized due to a strange condition with his heart, which he has had since he was a child.Sadly....I've just received information that str0ke @ milw0rm has passed away&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/S8TIzkD0Q4Y" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/7090977670148452698/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/str0ke-nie-zyje-milw0rm.html#comment-form" title="Komentarze (2)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/7090977670148452698?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/7090977670148452698?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/S8TIzkD0Q4Y/str0ke-nie-zyje-milw0rm.html" title="str0ke nie żyje, milw0rm" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>2</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/str0ke-nie-zyje-milw0rm.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UHSH8ycCp7ImA9WxNUEk0.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-253195183820213622</id><published>2009-11-02T15:40:00.000-08:00</published><updated>2009-11-02T15:40:39.198-08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-02T15:40:39.198-08:00</app:edited><title>(in)security tygodnia</title><summary type="html">Witam ponownie, zgodnie z zapowiedzią kolejna porcja ciekawostek:



   http://blog.itsecurityexpert.co.uk/2009/11/how-secure-is-your-uk-online-banking.html - odnośnie ostatniego wpisu

  
   http://www.heise-online.pl/security/news/item/Hasla-wielowyrazowe-w-systemie-platnosci-Amazona-846478.html

  
   http://www.securitum.pl/baza-wiedzy/publikacje/zdalny-root-na-routerze-soho

  
   http://&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/kpExovJHnW8" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/253195183820213622/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/11/insecurity-tygodnia.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/253195183820213622?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/253195183820213622?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/kpExovJHnW8/insecurity-tygodnia.html" title="(in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/11/insecurity-tygodnia.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0cMQHY_fSp7ImA9WxNVFks.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-1273673411963955047</id><published>2009-10-27T10:33:00.000-07:00</published><updated>2009-10-27T10:38:01.845-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-27T10:38:01.845-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="klient" /><category scheme="http://www.blogger.com/atom/ns#" term="bankowosc" /><category scheme="http://www.blogger.com/atom/ns#" term="tokeny" /><category scheme="http://www.blogger.com/atom/ns#" term="internetowa" /><title>nie-Bezpieczenstwo w bankowości internetowej.</title><summary type="html">Przymierzałem się do napisania notki odnośnie w/w tematu, ale Przemysław Skowron zrobił to wcześniej na swoim blogu :)

Nie zamierzam rezygnować z wpisu, więc...

Raport czytało się przyjemnie, ale tak jak wspomniał kolega P. Skowron, również podszedłbym do sprawy bezpieczeństwa w bankowości internetowej trochę z innej strony.

Załóżmy, że klient posiadający działalność gospodarczą posiada konto &lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/m26xOZZ-rnI" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/1273673411963955047/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/10/nie-bezpieczenstwo-w-bankowosci.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/1273673411963955047?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/1273673411963955047?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/m26xOZZ-rnI/nie-bezpieczenstwo-w-bankowosci.html" title="nie-Bezpieczenstwo w bankowości internetowej." /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/10/nie-bezpieczenstwo-w-bankowosci.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkIASHg7fCp7ImA9WxNVFkk.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-1324685175066485508</id><published>2009-10-27T03:48:00.000-07:00</published><updated>2009-10-27T03:49:09.604-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-27T03:49:09.604-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="adresy" /><category scheme="http://www.blogger.com/atom/ns#" term="ciekawe" /><category scheme="http://www.blogger.com/atom/ns#" term="tygodnia" /><category scheme="http://www.blogger.com/atom/ns#" term="security" /><category scheme="http://www.blogger.com/atom/ns#" term="(in)security" /><category scheme="http://www.blogger.com/atom/ns#" term="linki" /><title>(in)security tygodnia</title><summary type="html">Postanowiłem, co tydzień we wtorek, dzielić się z wami ciekawostkami z świata (in)security. Spośród setek informacji z różnych portafi wybrałem, moim zdaniem, te najciekawsze. Miłej lektury ;)


http://www.readwriteweb.com/archives/android_tor.php

http://pentestit.com/2009/10/26/dirsnatch-check-directory-listings-web-root/


http://isc.sans.org/diary.html?storyid=7450


http://rcpmag.com/&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/plH3_371M4g" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/1324685175066485508/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/10/insecurity-tygodnia.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/1324685175066485508?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/1324685175066485508?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/plH3_371M4g/insecurity-tygodnia.html" title="(in)security tygodnia" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/10/insecurity-tygodnia.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEQARHw4cCp7ImA9WxNWEU0.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-3575835683231388839</id><published>2009-10-09T05:40:00.000-07:00</published><updated>2009-10-09T08:32:25.238-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-09T08:32:25.238-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ryzyko" /><category scheme="http://www.blogger.com/atom/ns#" term="zagrozenie" /><category scheme="http://www.blogger.com/atom/ns#" term="xss" /><category scheme="http://www.blogger.com/atom/ns#" term="podatnosci" /><title>ryzyko podatność skutek zagrożenie błąd...</title><summary type="html">Podczas ostatniej konferencji (GigaCon BIN- Bezpieczenstwo i niezawodnosc) miałem możliwość wziąć udział w bardzo ciekawym wykładzie. Pani X (niestety nie pamiętam nazwiska, jeżeli ktoś był i zanotował to proszę o kontakt) rozpoczęła wykład od wytłumaczenia różnicy między zagrożeniem, ryzykiem, podatnością a skutkiem. Okazuje się, że wiele osób  myli w/ w pojęcia. Wyjaśniono, że:


- podatność to&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/Sj6_CARHChQ" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/3575835683231388839/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/10/ryzyko-podatnosc-skutek-zagrozenie-bad.html#comment-form" title="Komentarze (1)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3575835683231388839?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/3575835683231388839?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/Sj6_CARHChQ/ryzyko-podatnosc-skutek-zagrozenie-bad.html" title="ryzyko podatność skutek zagrożenie błąd..." /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/10/ryzyko-podatnosc-skutek-zagrozenie-bad.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0MCR3k6fCp7ImA9WxNWEEk.&quot;"><id>tag:blogger.com,1999:blog-6422406678944733222.post-9022031829406533933</id><published>2009-10-08T17:51:00.000-07:00</published><updated>2009-10-08T17:51:06.714-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-08T17:51:06.714-07:00</app:edited><title>A jednak</title><summary type="html">Witam wszystkich. Zlamalem sie, zalozylem bloga :) Znajdziecie tu:
...czas pokaze&lt;img src="http://feeds.feedburner.com/~r/thinksecure/~4/qGcskWL7vKY" height="1" width="1"/&gt;</summary><link rel="replies" type="application/atom+xml" href="http://thinklikeninja.blogspot.com/feeds/9022031829406533933/comments/default" title="Komentarze do posta" /><link rel="replies" type="text/html" href="http://thinklikeninja.blogspot.com/2009/10/jednak.html#comment-form" title="Komentarze (0)" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/9022031829406533933?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/6422406678944733222/posts/default/9022031829406533933?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/thinksecure/~3/qGcskWL7vKY/jednak.html" title="A jednak" /><author><name>Wheelq. Think Secure</name><uri>http://www.blogger.com/profile/01024402538869594204</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="30" height="32" src="http://3.bp.blogspot.com/_UxxvGhwuY8c/Ss8J7VPoC0I/AAAAAAAAC1Y/G5WYXtrzrrQ/S220/Clipboard01.jpg" /></author><thr:total>0</thr:total><feedburner:origLink>http://thinklikeninja.blogspot.com/2009/10/jednak.html</feedburner:origLink></entry></feed>

