<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Iljas Blag</title>
	<atom:link href="http://blogs.23.nu/ilja/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.23.nu/ilja</link>
	<description>Mostly incoherent ramblings and rants about computer security</description>
	<lastBuildDate>Mon, 03 Aug 2009 11:11:30 +0200</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on surely you jest by ilja</title>
		<link>http://blogs.23.nu/ilja/2009/06/surely-you-gest/comment-page-1/#comment-991</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Mon, 03 Aug 2009 11:11:30 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/ilja/?p=236#comment-991</guid>
		<description>the rumours are false. I am not, nor have I ever been, an employee at Microsoft.</description>
		<content:encoded><![CDATA[<p>the rumours are false. I am not, nor have I ever been, an employee at Microsoft.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on surely you jest by heh</title>
		<link>http://blogs.23.nu/ilja/2009/06/surely-you-gest/comment-page-1/#comment-990</link>
		<dc:creator>heh</dc:creator>
		<pubDate>Mon, 03 Aug 2009 07:45:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.23.nu/ilja/?p=236#comment-990</guid>
		<description>Are you working for microsoft now? Are the rumours true?

Thanks</description>
		<content:encoded><![CDATA[<p>Are you working for microsoft now? Are the rumours true?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on all shells suck ! by walkingbit</title>
		<link>http://blogs.23.nu/ilja/2006/01/antville-11101/comment-page-1/#comment-622</link>
		<dc:creator>walkingbit</dc:creator>
		<pubDate>Thu, 12 Mar 2009 14:50:04 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/01/antville-11101/#comment-622</guid>
		<description>No fail with Bash anymore!

GNU bash, version 3.2.25(1)-release (powerpc-apple-darwin8.11.0)</description>
		<content:encoded><![CDATA[<p>No fail with Bash anymore!</p>
<p>GNU bash, version 3.2.25(1)-release (powerpc-apple-darwin8.11.0)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Various things by CVE-2009-0478: Squid HTTP Version Remote DoS &#171; xorl %eax, %eax</title>
		<link>http://blogs.23.nu/ilja/2006/04/antville-11673/comment-page-1/#comment-562</link>
		<dc:creator>CVE-2009-0478: Squid HTTP Version Remote DoS &#171; xorl %eax, %eax</dc:creator>
		<pubDate>Wed, 11 Feb 2009 19:37:39 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/04/antville-11673/#comment-562</guid>
		<description>[...] I&#8217;m a big supporter of ilja&#8217;s opinion on assert(3) calls for production code which you can read at his blag. In addition to this, Squid is just full of assertions&#8230; Imagine, a crappy parsing like this [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;m a big supporter of ilja&#8217;s opinion on assert(3) calls for production code which you can read at his blag. In addition to this, Squid is just full of assertions&#8230; Imagine, a crappy parsing like this [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on readlink abuse by CVE-2009-0269: Linux eCryptFS off-by-one Underflow &#171; xorl %eax, %eax</title>
		<link>http://blogs.23.nu/ilja/2006/08/antville-12551/comment-page-1/#comment-537</link>
		<dc:creator>CVE-2009-0269: Linux eCryptFS off-by-one Underflow &#171; xorl %eax, %eax</dc:creator>
		<pubDate>Thu, 29 Jan 2009 14:18:33 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/08/antville-12551/#comment-537</guid>
		<description>[...] is a classic off-by-one which is documented at least since 2006 when Ilja van Sprundel wrote on his blog about it. Our case is only vulnerable to an off-by-one underflow according to ilja&#8217;s post. [...]</description>
		<content:encoded><![CDATA[<p>[...] is a classic off-by-one which is documented at least since 2006 when Ilja van Sprundel wrote on his blog about it. Our case is only vulnerable to an off-by-one underflow according to ilja&#8217;s post. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by ah</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-90</link>
		<dc:creator>ah</dc:creator>
		<pubDate>Tue, 21 Oct 2008 23:47:12 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-90</guid>
		<description>It&#039;s a shame. I am looking for the talk for several weeks now. But noone has it. I watched it on the congress itself and I kind of liked it. Would love to see it again. Maybe I find a mirror somewhere ...</description>
		<content:encoded><![CDATA[<p>It&#8217;s a shame. I am looking for the talk for several weeks now. But noone has it. I watched it on the congress itself and I kind of liked it. Would love to see it again. Maybe I find a mirror somewhere &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on 79.666% of all statistics are made up on the spot by replaced</title>
		<link>http://blogs.23.nu/ilja/2006/03/antville-11415/comment-page-1/#comment-85</link>
		<dc:creator>replaced</dc:creator>
		<pubDate>Thu, 16 Oct 2008 14:55:24 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/03/antville-11415/#comment-85</guid>
		<description>how i hate openbsd fanboys ;P</description>
		<content:encoded><![CDATA[<p>how i hate openbsd fanboys ;P</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dave on finding vulnerabilities by ntronic</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13345/comment-page-1/#comment-84</link>
		<dc:creator>ntronic</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:44:01 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13345/#comment-84</guid>
		<description>Ilya

Ilya
How are you my man? Long time no see :-)

ntronic


 This comment was originally posted on 20061113T13:36:32</description>
		<content:encoded><![CDATA[<p>Ilya</p>
<p>Ilya<br />
How are you my man? Long time no see :-)</p>
<p>ntronic</p>
<p> This comment was originally posted on 20061113T13:36:32</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on proftpd by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13474/comment-page-1/#comment-83</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:59 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13474/#comment-83</guid>
		<description>hahaha

hahaha
that is hilarious !


 This comment was originally posted on 20061127T04:02:06</description>
		<content:encoded><![CDATA[<p>hahaha</p>
<p>hahaha<br />
that is hilarious !</p>
<p> This comment was originally posted on 20061127T04:02:06</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on proftpd by evgeny legerov</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13474/comment-page-1/#comment-82</link>
		<dc:creator>evgeny legerov</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:58 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13474/#comment-82</guid>
		<description>their exact response was:

their exact response was:
&quot;&quot;&quot;
I don&#039;t believe this assertion about our sstrncpy() is correct. Here is our
sstrncpy() implementation:

char *sstrncpy(char *dest, const char *src, size_t n) {
  register char *d = dest;

  if (!dest)
    return NULL;

  if (n == 0)
    return NULL;

  if (src &amp;&amp; *src) {
    for (; *src &amp;&amp; n &gt; 1; n--)
      *d++ = *src++;
  }
  
  *d = &#039;&#039;;

  return dest;
}

As you can see, the &#039;*src &amp;&amp; n &gt; 1&#039; check will only copy data if n (the
passed count) is positive.&quot;&quot;&quot;


 This comment was originally posted on 20061126T08:56:04</description>
		<content:encoded><![CDATA[<p>their exact response was:</p>
<p>their exact response was:<br />
&#8220;&#8221;"<br />
I don&#8217;t believe this assertion about our sstrncpy() is correct. Here is our<br />
sstrncpy() implementation:</p>
<p>char *sstrncpy(char *dest, const char *src, size_t n) {<br />
  register char *d = dest;</p>
<p>  if (!dest)<br />
    return NULL;</p>
<p>  if (n == 0)<br />
    return NULL;</p>
<p>  if (src &amp;&amp; *src) {<br />
    for (; *src &amp;&amp; n &gt; 1; n&#8211;)<br />
      *d++ = *src++;<br />
  }</p>
<p>  *d = &#8221;;</p>
<p>  return dest;<br />
}</p>
<p>As you can see, the &#8216;*src &amp;&amp; n &gt; 1&#8242; check will only copy data if n (the<br />
passed count) is positive.&#8221;"&#8221;</p>
<p> This comment was originally posted on 20061126T08:56:04</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on proftpd by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13474/comment-page-1/#comment-81</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:57 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13474/#comment-81</guid>
		<description>


Really ? that&#039;s strange, IIRC the size argument in sstrncpy() is of type size_t. then again, it&#039;s proftpd, so I can see how they wouldn&#039;t get it :)


 This comment was originally posted on 20061126T06:16:31</description>
		<content:encoded><![CDATA[<p>Really ? that&#8217;s strange, IIRC the size argument in sstrncpy() is of type size_t. then again, it&#8217;s proftpd, so I can see how they wouldn&#8217;t get it :)</p>
<p> This comment was originally posted on 20061126T06:16:31</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on proftpd by evgeny legerov</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13474/comment-page-1/#comment-80</link>
		<dc:creator>evgeny legerov</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:56 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13474/#comment-80</guid>
		<description>yeah, it is not my bug

yeah, it is not my bug
I already wrote about it on dailydave@ list:
http://seclists.org/dailydave/2006/q4/0223.html
I reported my bug to proftpd team, so I hope that I will be able to release vd_proftpd at the beginning of the next week.
ProFTPD guys are suprised me a lot , they think that their sstrncpy(dst,src,n) will not work when the third argument &#039;n&#039; set to a negative value ;-)


 This comment was originally posted on 20061125T19:11:17</description>
		<content:encoded><![CDATA[<p>yeah, it is not my bug</p>
<p>yeah, it is not my bug<br />
I already wrote about it on dailydave@ list:<br />
<a href="http://seclists.org/dailydave/2006/q4/0223.html" rel="nofollow">http://seclists.org/dailydave/2006/q4/0223.html</a><br />
I reported my bug to proftpd team, so I hope that I will be able to release vd_proftpd at the beginning of the next week.<br />
ProFTPD guys are suprised me a lot , they think that their sstrncpy(dst,src,n) will not work when the third argument &#8216;n&#8217; set to a negative value ;-)</p>
<p> This comment was originally posted on 20061125T19:11:17</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on close and fclose by mdornseif</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13494/comment-page-1/#comment-79</link>
		<dc:creator>mdornseif</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:55 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13494/#comment-79</guid>
		<description>


One nice habit is tat on a fork in the child you close all filediscriptors unless you really want them - see DJC code for a nice example.

Regarding high level languages. You are right, but then there  is a single point in my code where I have to concentrate on fixing the issue,  not one bazillion.

Skimming &lt;a href=&quot;http://svn.python.org/view/python/trunk/Objects/fileobject.c?rev=52139&amp;view=markup&quot; rel=&quot;nofollow&quot;&gt;this&lt;/a&gt; leaves me with mixed feelings. Somebody thought about checking thr return code in file_dealloc but leaves no way of acting on that issue (unless you count reading  stderr). Hmgmpf. If  you nicely close the file (file_close) then you get a return value - which you must check by hand.

IMHO the code should be changed to raise an exception if close fails. Normally that would terminate the programm unless the programmer decides to catch the exception in which case he hopfully knows what he is doing.


 This comment was originally posted on 20061126T08:08:34</description>
		<content:encoded><![CDATA[<p>One nice habit is tat on a fork in the child you close all filediscriptors unless you really want them &#8211; see DJC code for a nice example.</p>
<p>Regarding high level languages. You are right, but then there  is a single point in my code where I have to concentrate on fixing the issue,  not one bazillion.</p>
<p>Skimming <a href="http://svn.python.org/view/python/trunk/Objects/fileobject.c?rev=52139&amp;view=markup" rel="nofollow">this</a> leaves me with mixed feelings. Somebody thought about checking thr return code in file_dealloc but leaves no way of acting on that issue (unless you count reading  stderr). Hmgmpf. If  you nicely close the file (file_close) then you get a return value &#8211; which you must check by hand.</p>
<p>IMHO the code should be changed to raise an exception if close fails. Normally that would terminate the programm unless the programmer decides to catch the exception in which case he hopfully knows what he is doing.</p>
<p> This comment was originally posted on 20061126T08:08:34</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on close and fclose by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13494/comment-page-1/#comment-78</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:54 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13494/#comment-78</guid>
		<description>


hm, well in unix files always stay open unless you explicitly close them or call exit, they survive fork and execve (unless you set close on exec, but its not set by default). This turns out to be a pain in the ass for a lot of perl programmers, who never close files. (mostly, coz they run out of file descriptors)

Oh, and I bet those highlevel garbage collectors end up calling close() without checking the return value :)


 This comment was originally posted on 20061126T05:36:32</description>
		<content:encoded><![CDATA[<p>hm, well in unix files always stay open unless you explicitly close them or call exit, they survive fork and execve (unless you set close on exec, but its not set by default). This turns out to be a pain in the ass for a lot of perl programmers, who never close files. (mostly, coz they run out of file descriptors)</p>
<p>Oh, and I bet those highlevel garbage collectors end up calling close() without checking the return value :)</p>
<p> This comment was originally posted on 20061126T05:36:32</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on close and fclose by mdornseif</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13494/comment-page-1/#comment-77</link>
		<dc:creator>mdornseif</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:53 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13494/#comment-77</guid>
		<description>


Don&#039;t you have a garbage collector to close your files when they fall out  of scope?

Or are you still stuck with programming concepts from the 60&#039;s ;-)


 This comment was originally posted on 20061125T21:39:24</description>
		<content:encoded><![CDATA[<p>Don&#8217;t you have a garbage collector to close your files when they fall out  of scope?</p>
<p>Or are you still stuck with programming concepts from the 60&#8217;s ;-)</p>
<p> This comment was originally posted on 20061125T21:39:24</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fun with gdb by fefe</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13530/comment-page-1/#comment-76</link>
		<dc:creator>fefe</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:51 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13530/#comment-76</guid>
		<description>Uh, so you debug on untrusted machines?

Uh, so you debug on untrusted machines?
I don&#039;t.  And I rely on that feature all the time.
I have separate .gdbinit files for all my projects, and I use them to specify the command line for the processes I&#039;m about to debug.  Since these differ per process, it would suck if I couldn&#039;t do that because some Debilian idiot removed that feature.


 This comment was originally posted on 20061129T11:45:38</description>
		<content:encoded><![CDATA[<p>Uh, so you debug on untrusted machines?</p>
<p>Uh, so you debug on untrusted machines?<br />
I don&#8217;t.  And I rely on that feature all the time.<br />
I have separate .gdbinit files for all my projects, and I use them to specify the command line for the processes I&#8217;m about to debug.  Since these differ per process, it would suck if I couldn&#8217;t do that because some Debilian idiot removed that feature.</p>
<p> This comment was originally posted on 20061129T11:45:38</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fun with gdb by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13530/comment-page-1/#comment-75</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:51 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13530/#comment-75</guid>
		<description>


ah, that&#039;s good to know, I guess the documentation is outdated then.


 This comment was originally posted on 20061127T20:22:08</description>
		<content:encoded><![CDATA[<p>ah, that&#8217;s good to know, I guess the documentation is outdated then.</p>
<p> This comment was originally posted on 20061127T20:22:08</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fun with gdb by bugmenot</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13530/comment-page-1/#comment-74</link>
		<dc:creator>bugmenot</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:50 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13530/#comment-74</guid>
		<description>patched for a while

patched for a while
this is patched with gdb6.4 and gdb6.3 with debian security patches
.gdbinit which owner aren&#039;t the current user are ignored and a warning message is displayed

&gt; warning: not using untrusted file &quot;.gdbinit&quot;

tested with GNU gdb 6.3-debian and GNU gdb 6.4-debian
this flaw has been reported in may 2005
http://seclists.org/bugtraq/2005/May/0314.html


 This comment was originally posted on 20061127T15:00:23</description>
		<content:encoded><![CDATA[<p>patched for a while</p>
<p>patched for a while<br />
this is patched with gdb6.4 and gdb6.3 with debian security patches<br />
.gdbinit which owner aren&#8217;t the current user are ignored and a warning message is displayed</p>
<p>&gt; warning: not using untrusted file &#8220;.gdbinit&#8221;</p>
<p>tested with GNU gdb 6.3-debian and GNU gdb 6.4-debian<br />
this flaw has been reported in may 2005<br />
<a href="http://seclists.org/bugtraq/2005/May/0314.html" rel="nofollow">http://seclists.org/bugtraq/2005/May/0314.html</a></p>
<p> This comment was originally posted on 20061127T15:00:23</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fun with gdb by guest</title>
		<link>http://blogs.23.nu/ilja/2006/11/antville-13530/comment-page-1/#comment-73</link>
		<dc:creator>guest</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:49 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/11/antville-13530/#comment-73</guid>
		<description>doesn&#039;t work

doesn&#039;t work
warning: not using untrusted file &quot;.gdbinit&quot;


 This comment was originally posted on 20061127T14:54:55</description>
		<content:encoded><![CDATA[<p>doesn&#8217;t work</p>
<p>doesn&#8217;t work<br />
warning: not using untrusted file &#8220;.gdbinit&#8221;</p>
<p> This comment was originally posted on 20061127T14:54:55</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on oh, it&#8217;s just a kernel panic by bsdaemon</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13579/comment-page-1/#comment-72</link>
		<dc:creator>bsdaemon</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:47 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13579/#comment-72</guid>
		<description>I agree...

I agree...
The problem is more serious if the team does understand a bug and say it´s just a DoS, like i think you will remember ilja:

http://blogs.securiteam.com/index.php/archives/date
/2006/09/


 This comment was originally posted on 20061222T17:29:31</description>
		<content:encoded><![CDATA[<p>I agree&#8230;</p>
<p>I agree&#8230;<br />
The problem is more serious if the team does understand a bug and say it´s just a DoS, like i think you will remember ilja:</p>
<p><a href="http://blogs.securiteam.com/index.php/archives/date" rel="nofollow">http://blogs.securiteam.com/index.php/archives/date</a><br />
/2006/09/</p>
<p> This comment was originally posted on 20061222T17:29:31</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fuck you lenovo by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13580/comment-page-1/#comment-71</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:46 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13580/#comment-71</guid>
		<description>I dunnow

I dunnow
Good question. I honestly don&#039;t know, I&#039;ve been through quite a few laptops before I got my x31 (which died in the liquid experiment). And the x31 was really the only one I liked. Hence why I bough the x60, which lenovo totally fucked up !

So anyone have any suggestions ? 
What I&#039;m looking for is something that&#039;s small (12 inch), light, and strong as hell (as in, it can stand being dropped a few times). I dont care that much for battery life, but &gt; 1 hour would be nice. Oh and it has to be virtually silent. I&#039;ve had it with noisy laptops !


 This comment was originally posted on 20061204T06:59:59</description>
		<content:encoded><![CDATA[<p>I dunnow</p>
<p>I dunnow<br />
Good question. I honestly don&#8217;t know, I&#8217;ve been through quite a few laptops before I got my x31 (which died in the liquid experiment). And the x31 was really the only one I liked. Hence why I bough the x60, which lenovo totally fucked up !</p>
<p>So anyone have any suggestions ?<br />
What I&#8217;m looking for is something that&#8217;s small (12 inch), light, and strong as hell (as in, it can stand being dropped a few times). I dont care that much for battery life, but &gt; 1 hour would be nice. Oh and it has to be virtually silent. I&#8217;ve had it with noisy laptops !</p>
<p> This comment was originally posted on 20061204T06:59:59</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fuck you lenovo by str0ke</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13580/comment-page-1/#comment-70</link>
		<dc:creator>str0ke</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:45 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13580/#comment-70</guid>
		<description>laptop

laptop
If you could go back in time ilja, which laptop would you of gotten :)

/str0ke


 This comment was originally posted on 20061204T05:13:04</description>
		<content:encoded><![CDATA[<p>laptop</p>
<p>laptop<br />
If you could go back in time ilja, which laptop would you of gotten :)</p>
<p>/str0ke</p>
<p> This comment was originally posted on 20061204T05:13:04</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Fuck you lenovo by kaka</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13580/comment-page-1/#comment-69</link>
		<dc:creator>kaka</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:44 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13580/#comment-69</guid>
		<description>haha

haha
welcome to fuck lenovo :D

go to www.ibm.com and get your support :D


 This comment was originally posted on 20061204T01:22:07</description>
		<content:encoded><![CDATA[<p>haha</p>
<p>haha<br />
welcome to fuck lenovo :D</p>
<p>go to <a href="http://www.ibm.com" rel="nofollow">http://www.ibm.com</a> and get your support :D</p>
<p> This comment was originally posted on 20061204T01:22:07</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by miod</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-68</link>
		<dc:creator>miod</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:43 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-68</guid>
		<description>Indeed

Indeed
You need a shebang on the first line for the script to be recognized as such, which is why ilja&#039;s example works and grg&#039;s example doesn&#039;t.


 This comment was originally posted on 20070108T16:38:28</description>
		<content:encoded><![CDATA[<p>Indeed</p>
<p>Indeed<br />
You need a shebang on the first line for the script to be recognized as such, which is why ilja&#8217;s example works and grg&#8217;s example doesn&#8217;t.</p>
<p> This comment was originally posted on 20070108T16:38:28</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-67</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:42 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-67</guid>
		<description>errr... yes

errr... yes

(yes, it&#039;s a vmware screen capture, ...)


 This comment was originally posted on 20070104T19:49:25</description>
		<content:encoded><![CDATA[<p>errr&#8230; yes</p>
<p>errr&#8230; yes</p>
<p>(yes, it&#8217;s a vmware screen capture, &#8230;)</p>
<p> This comment was originally posted on 20070104T19:49:25</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by grg</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-66</link>
		<dc:creator>grg</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:41 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-66</guid>
		<description>errr... no

errr... no
What exactly makes you think that suid shell scripts work?

$ uname -r
4.0
$ mount
/dev/wd0a on / type ffs (NFS exported, local)
/dev/wd0f on /tmp type ffs (local, nodev, noexec, nosuid)
/dev/wd0g on /usr type ffs (local, nodev)
/dev/wd0e on /var type ffs (local, nodev, nosuid)
$ ls -l /usr/tmp/suidid            
-r-sr-xr-x  1 root  wheel  3 Jan  5 02:57 /usr/tmp/suidid*
$ cat /usr/tmp/suidid                                                   
id
$ id
uid=1001(grg) gid=100(grg) groups=100(grg), 0(wheel), 9(wsrc), 10(users)
$ /usr/tmp/suidid                                                       
uid=1001(grg) gid=100(grg) groups=100(grg), 0(wheel), 9(wsrc), 10(users)


 This comment was originally posted on 20070104T16:32:08</description>
		<content:encoded><![CDATA[<p>errr&#8230; no</p>
<p>errr&#8230; no<br />
What exactly makes you think that suid shell scripts work?</p>
<p>$ uname -r<br />
4.0<br />
$ mount<br />
/dev/wd0a on / type ffs (NFS exported, local)<br />
/dev/wd0f on /tmp type ffs (local, nodev, noexec, nosuid)<br />
/dev/wd0g on /usr type ffs (local, nodev)<br />
/dev/wd0e on /var type ffs (local, nodev, nosuid)<br />
$ ls -l /usr/tmp/suidid<br />
-r-sr-xr-x  1 root  wheel  3 Jan  5 02:57 /usr/tmp/suidid*<br />
$ cat /usr/tmp/suidid<br />
id<br />
$ id<br />
uid=1001(grg) gid=100(grg) groups=100(grg), 0(wheel), 9(wsrc), 10(users)<br />
$ /usr/tmp/suidid<br />
uid=1001(grg) gid=100(grg) groups=100(grg), 0(wheel), 9(wsrc), 10(users)</p>
<p> This comment was originally posted on 20070104T16:32:08</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by kasperle</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-65</link>
		<dc:creator>kasperle</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:40 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-65</guid>
		<description>


That does not change anything about the way OpenBSD treats suid shellscripts on / or /usr though.


 This comment was originally posted on 20061204T23:19:35</description>
		<content:encoded><![CDATA[<p>That does not change anything about the way OpenBSD treats suid shellscripts on / or /usr though.</p>
<p> This comment was originally posted on 20061204T23:19:35</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by rgouveia</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-64</link>
		<dc:creator>rgouveia</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:39 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-64</guid>
		<description>


I think you didn&#039;t create any partitions besides the root &#039;a&#039; in the install or else the install script would have added in the &quot;nosuid&quot; option to fstab:
/dev/wd1a / ffs rw 1 1
/dev/wd1e /tmp ffs rw,nodev,nosuid,softdep 1 2
/dev/wd1f /usr ffs rw,nodev,softdep 1 2
/dev/wd1d /var ffs rw,nodev,nosuid,softdep 1 2
/dev/wd1g /home ffs rw,nodev,nosuid,softdep 1 2


 This comment was originally posted on 20061204T21:37:45</description>
		<content:encoded><![CDATA[<p>I think you didn&#8217;t create any partitions besides the root &#8216;a&#8217; in the install or else the install script would have added in the &#8220;nosuid&#8221; option to fstab:<br />
/dev/wd1a / ffs rw 1 1<br />
/dev/wd1e /tmp ffs rw,nodev,nosuid,softdep 1 2<br />
/dev/wd1f /usr ffs rw,nodev,softdep 1 2<br />
/dev/wd1d /var ffs rw,nodev,nosuid,softdep 1 2<br />
/dev/wd1g /home ffs rw,nodev,nosuid,softdep 1 2</p>
<p> This comment was originally posted on 20061204T21:37:45</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-63</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:39 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-63</guid>
		<description>


but you would expect something like that from sun.
I didn&#039;t think the OpenBSD guys would allow this.


 This comment was originally posted on 20061204T12:10:31</description>
		<content:encoded><![CDATA[<p>but you would expect something like that from sun.<br />
I didn&#8217;t think the OpenBSD guys would allow this.</p>
<p> This comment was originally posted on 20061204T12:10:31</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on OpenBSD allows suid shellscripts ? by alert7</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13587/comment-page-1/#comment-62</link>
		<dc:creator>alert7</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:38 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13587/#comment-62</guid>
		<description>solaris8,9 also allow suid shellscripts

solaris8,9 also allow suid shellscripts
as i remember , solaris8,9 also allow suid shellscripts.
i didn&#039;t test solaris 10.


 This comment was originally posted on 20061204T12:04:53</description>
		<content:encoded><![CDATA[<p>solaris8,9 also allow suid shellscripts</p>
<p>solaris8,9 also allow suid shellscripts<br />
as i remember , solaris8,9 also allow suid shellscripts.<br />
i didn&#8217;t test solaris 10.</p>
<p> This comment was originally posted on 20061204T12:04:53</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hardcoded off-by-one&#8217;s by ilja</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13685/comment-page-1/#comment-61</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:36 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13685/#comment-61</guid>
		<description>


yea, I saw that. 
the code in makesalt() is still wrong tho :)


 This comment was originally posted on 20061216T17:54:51</description>
		<content:encoded><![CDATA[<p>yea, I saw that.<br />
the code in makesalt() is still wrong tho :)</p>
<p> This comment was originally posted on 20061216T17:54:51</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hardcoded off-by-one&#8217;s by cklein</title>
		<link>http://blogs.23.nu/ilja/2006/12/antville-13685/comment-page-1/#comment-60</link>
		<dc:creator>cklein</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:35 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2006/12/antville-13685/#comment-60</guid>
		<description>


I think it&#039;s just bad style of coding:
&lt;code&gt;
PAM_EXTERN int
pam_sm_chauthtok(pam_handle_t *pamh, int flags,
    int argc __unused, const char *argv[] __unused)
{       
        char salt[SALTSIZE + 1];
        [...]
        makesalt(salt);

&lt;/code&gt;


 This comment was originally posted on 20061216T09:56:59</description>
		<content:encoded><![CDATA[<p>I think it&#8217;s just bad style of coding:<br />
<code><br />
PAM_EXTERN int<br />
pam_sm_chauthtok(pam_handle_t *pamh, int flags,<br />
    int argc __unused, const char *argv[] __unused)<br />
{<br />
        char salt[SALTSIZE + 1];<br />
        [...]<br />
        makesalt(salt);</p>
<p></code></p>
<p> This comment was originally posted on 20061216T09:56:59</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by hynek</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-59</link>
		<dc:creator>hynek</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:33 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-59</guid>
		<description>


Found it finally: http://23c3.ccc-trier.de/videos/official/23C3-1428-en-you_cant_make_this_stuff_up.m4v


 This comment was originally posted on 20070112T13:48:57</description>
		<content:encoded><![CDATA[<p>Found it finally: <a href="http://23c3.ccc-trier.de/videos/official/23C3-1428-en-you_cant_make_this_stuff_up.m4v" rel="nofollow">http://23c3.ccc-trier.de/videos/official/23C3-1428-en-you_cant_make_this_stuff_up.m4v</a></p>
<p> This comment was originally posted on 20070112T13:48:57</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by thoth</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-58</link>
		<dc:creator>thoth</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:32 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-58</guid>
		<description>


http://mirror1.kaschwig.net/23C3/wmv/
http://debian.tu-bs.de/mirror/ccc/23C3-mitschnitte/
are up as of this post

I can&#039;t read German but somewhere there might be &#039;standup&#039; :)


 This comment was originally posted on 20070111T22:18:38</description>
		<content:encoded><![CDATA[<p><a href="http://mirror1.kaschwig.net/23C3/wmv/" rel="nofollow">http://mirror1.kaschwig.net/23C3/wmv/</a><br />
<a href="http://debian.tu-bs.de/mirror/ccc/23C3-mitschnitte/" rel="nofollow">http://debian.tu-bs.de/mirror/ccc/23C3-mitschnitte/</a><br />
are up as of this post</p>
<p>I can&#8217;t read German but somewhere there might be &#8217;standup&#8217; :)</p>
<p> This comment was originally posted on 20070111T22:18:38</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by hynek</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-57</link>
		<dc:creator>hynek</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:32 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-57</guid>
		<description>010

010
So it does run in wine, right? ;)

Your unusual bugs talk was great btw, do you know by any chance if there&#039;s somewhere a stream of the standup comedy? Last time I looked at the official place, it wasn&#039;t there and now the site is down. :/


 This comment was originally posted on 20070111T12:57:21</description>
		<content:encoded><![CDATA[<p>010</p>
<p>010<br />
So it does run in wine, right? ;)</p>
<p>Your unusual bugs talk was great btw, do you know by any chance if there&#8217;s somewhere a stream of the standup comedy? Last time I looked at the official place, it wasn&#8217;t there and now the site is down. :/</p>
<p> This comment was originally posted on 20070111T12:57:21</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by fbz</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-56</link>
		<dc:creator>fbz</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-56</guid>
		<description>openbsd-ers fix stuff quickly

openbsd-ers fix stuff quickly
right after your talk i was walking by the bsd t-shirt area and they all asked if i had filmed/photographed the part of your talk with the openbsd stuff, i had video so they had me fast-forward to that part and zoom in on your slides. talk about quick fixes!


 This comment was originally posted on 20070110T10:22:42</description>
		<content:encoded><![CDATA[<p>openbsd-ers fix stuff quickly</p>
<p>openbsd-ers fix stuff quickly<br />
right after your talk i was walking by the bsd t-shirt area and they all asked if i had filmed/photographed the part of your talk with the openbsd stuff, i had video so they had me fast-forward to that part and zoom in on your slides. talk about quick fixes!</p>
<p> This comment was originally posted on 20070110T10:22:42</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by ilja</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-55</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:30 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-55</guid>
		<description>


yes, I will, at some point. I might try and integrate it in my csw talk (assuming it gets accepted) and hence won&#039;t publish that right now. Ofcourse I&#039;ll credit people for telling me !


 This comment was originally posted on 20070109T23:14:06</description>
		<content:encoded><![CDATA[<p>yes, I will, at some point. I might try and integrate it in my csw talk (assuming it gets accepted) and hence won&#8217;t publish that right now. Ofcourse I&#8217;ll credit people for telling me !</p>
<p> This comment was originally posted on 20070109T23:14:06</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on No, I&#8217;m not dead yet by d3fn011</title>
		<link>http://blogs.23.nu/ilja/2007/01/antville-13882/comment-page-1/#comment-54</link>
		<dc:creator>d3fn011</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:29 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/01/antville-13882/#comment-54</guid>
		<description>Publish Related Comments

Publish Related Comments
In the paragraph about the Unusual Bugs talk you mention, &quot;I got some awesome feedback on it, and people have told me about some related things I didn&#039;t know yet.&quot;  Are you going to publish those &quot;related things?&quot;


 This comment was originally posted on 20070109T22:50:29</description>
		<content:encoded><![CDATA[<p>Publish Related Comments</p>
<p>Publish Related Comments<br />
In the paragraph about the Unusual Bugs talk you mention, &#8220;I got some awesome feedback on it, and people have told me about some related things I didn&#8217;t know yet.&#8221;  Are you going to publish those &#8220;related things?&#8221;</p>
<p> This comment was originally posted on 20070109T22:50:29</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Guestblagging! by guest</title>
		<link>http://blogs.23.nu/ilja/2007/02/antville-14258/comment-page-1/#comment-53</link>
		<dc:creator>guest</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:28 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/02/antville-14258/#comment-53</guid>
		<description>bitty?!

bitty?!
Have you ever looked up what bitty means?
http://www.urbandictionary.com/define.php?term=bitty


 This comment was originally posted on 20070218T11:23:33</description>
		<content:encoded><![CDATA[<p>bitty?!</p>
<p>bitty?!<br />
Have you ever looked up what bitty means?<br />
<a href="http://www.urbandictionary.com/define.php?term=bitty" rel="nofollow">http://www.urbandictionary.com/define.php?term=bitty</a></p>
<p> This comment was originally posted on 20070218T11:23:33</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Guestblagging! by prdelka</title>
		<link>http://blogs.23.nu/ilja/2007/02/antville-14258/comment-page-1/#comment-52</link>
		<dc:creator>prdelka</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:27 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/02/antville-14258/#comment-52</guid>
		<description>not guilty.

not guilty.
i maintain my innocence despite the overwhelming evidence. i am not guilty.

~ prdelka


 This comment was originally posted on 20070214T10:29:19</description>
		<content:encoded><![CDATA[<p>not guilty.</p>
<p>not guilty.<br />
i maintain my innocence despite the overwhelming evidence. i am not guilty.</p>
<p>~ prdelka</p>
<p> This comment was originally posted on 20070214T10:29:19</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on too funny by cochy</title>
		<link>http://blogs.23.nu/ilja/2007/02/antville-14266/comment-page-1/#comment-51</link>
		<dc:creator>cochy</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:26 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/02/antville-14266/#comment-51</guid>
		<description>informed

informed
I have informed this web site of their problem.  As of now they seemed to have removed that problematic FAQ.  Hopefully they will implement better security measures, if they would like to accept CCs.


 This comment was originally posted on 20070217T21:28:32</description>
		<content:encoded><![CDATA[<p>informed</p>
<p>informed<br />
I have informed this web site of their problem.  As of now they seemed to have removed that problematic FAQ.  Hopefully they will implement better security measures, if they would like to accept CCs.</p>
<p> This comment was originally posted on 20070217T21:28:32</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on too funny by vlooy</title>
		<link>http://blogs.23.nu/ilja/2007/02/antville-14266/comment-page-1/#comment-50</link>
		<dc:creator>vlooy</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:25 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/02/antville-14266/#comment-50</guid>
		<description>tap

tap
They better wrote this:

Q: I think your security sucks, ...
A: http://www.usatap.org/images/PIX/1328.jpg

:p


 This comment was originally posted on 20070214T17:48:07</description>
		<content:encoded><![CDATA[<p>tap</p>
<p>tap<br />
They better wrote this:</p>
<p>Q: I think your security sucks, &#8230;<br />
A: <a href="http://www.usatap.org/images/PIX/1328.jpg" rel="nofollow">http://www.usatap.org/images/PIX/1328.jpg</a></p>
<p>:p</p>
<p> This comment was originally posted on 20070214T17:48:07</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on too funny by teemu</title>
		<link>http://blogs.23.nu/ilja/2007/02/antville-14266/comment-page-1/#comment-49</link>
		<dc:creator>teemu</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:24 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/02/antville-14266/#comment-49</guid>
		<description>


geezus ..


 This comment was originally posted on 20070209T11:24:16</description>
		<content:encoded><![CDATA[<p>geezus ..</p>
<p> This comment was originally posted on 20070209T11:24:16</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by tomten</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-48</link>
		<dc:creator>tomten</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:23 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-48</guid>
		<description>Problems with libfish and sparc

Problems with libfish and sparc
Hi, I&#039;m having trubbel with libfish. Don&#039;t like it muth, it has problems with operating on difrent archs. I run sparc64, and when i try to decode a msg from a intel machine all i get is junk! Think its a problem with the bytorder....

Great work on the blogg, hope to read more soon.


 This comment was originally posted on 20080723T09:43:29</description>
		<content:encoded><![CDATA[<p>Problems with libfish and sparc</p>
<p>Problems with libfish and sparc<br />
Hi, I&#8217;m having trubbel with libfish. Don&#8217;t like it muth, it has problems with operating on difrent archs. I run sparc64, and when i try to decode a msg from a intel machine all i get is junk! Think its a problem with the bytorder&#8230;.</p>
<p>Great work on the blogg, hope to read more soon.</p>
<p> This comment was originally posted on 20080723T09:43:29</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by ilja</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-47</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:22 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-47</guid>
		<description>


I didnt have to see that, I just barfed up my dinner.


 This comment was originally posted on 20070328T03:37:39</description>
		<content:encoded><![CDATA[<p>I didnt have to see that, I just barfed up my dinner.</p>
<p> This comment was originally posted on 20070328T03:37:39</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by oxff</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-46</link>
		<dc:creator>oxff</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:21 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-46</guid>
		<description>He prevents Buffer Overflows!

He prevents Buffer Overflows!
FiSH-irssi-v0.99-source.zip:FiSH.c:79

	// usually a received message does not exceed 512 chars, but we want to prevent evil buffer overflow
	if(msg_len &gt;= (int)(sizeof(bf_dest)*1.5)) msg_ptr[(int)(sizeof(bf_dest)*1.5)-20]=&#039;&#039;;

Isn&#039;t that cute?


 This comment was originally posted on 20070328T00:59:18</description>
		<content:encoded><![CDATA[<p>He prevents Buffer Overflows!</p>
<p>He prevents Buffer Overflows!<br />
FiSH-irssi-v0.99-source.zip:FiSH.c:79</p>
<p>	// usually a received message does not exceed 512 chars, but we want to prevent evil buffer overflow<br />
	if(msg_len &gt;= (int)(sizeof(bf_dest)*1.5)) msg_ptr[(int)(sizeof(bf_dest)*1.5)-20]=&#8221;;</p>
<p>Isn&#8217;t that cute?</p>
<p> This comment was originally posted on 20070328T00:59:18</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by calcite</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-45</link>
		<dc:creator>calcite</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-45</guid>
		<description>Wow

Wow
I&#039;m suprised to see strcpy() fuckup like that in such a widely used application.


 This comment was originally posted on 20070325T03:34:24</description>
		<content:encoded><![CDATA[<p>Wow</p>
<p>Wow<br />
I&#8217;m suprised to see strcpy() fuckup like that in such a widely used application.</p>
<p> This comment was originally posted on 20070325T03:34:24</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by ilja</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-44</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:19 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-44</guid>
		<description>


the fact that it has to be serverside in most cases is pretty obvious, and imo needn&#039;t even be mentioned. also it looks like you might be able to trigger the notice stacksmash clientside. 
I didn&#039;t know the xchat code was that different from the mirc code, I never looked, I just assumed, hence the &quot;I believe ...&quot; I wasn&#039;t stating facts.


 This comment was originally posted on 20070320T04:16:12</description>
		<content:encoded><![CDATA[<p>the fact that it has to be serverside in most cases is pretty obvious, and imo needn&#8217;t even be mentioned. also it looks like you might be able to trigger the notice stacksmash clientside.<br />
I didn&#8217;t know the xchat code was that different from the mirc code, I never looked, I just assumed, hence the &#8220;I believe &#8230;&#8221; I wasn&#8217;t stating facts.</p>
<p> This comment was originally posted on 20070320T04:16:12</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by slashy</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-43</link>
		<dc:creator>slashy</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:18 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-43</guid>
		<description>


well done research.. a bit further and you would have noticed that you can&#039;t attack this without full control of the ircserver (or you have to find irc-servers which have a nicklen setting &gt; 100).  Also it should be mentioned that this flaws only applies to xchat version .. the flawed part of the code ain&#039;t reused in mIRC version past 1.25

read here for more: http://fish.sekure.us/forum/viewtopic.php?p=1166#1166


 This comment was originally posted on 20070317T11:08:30</description>
		<content:encoded><![CDATA[<p>well done research.. a bit further and you would have noticed that you can&#8217;t attack this without full control of the ircserver (or you have to find irc-servers which have a nicklen setting &gt; 100).  Also it should be mentioned that this flaws only applies to xchat version .. the flawed part of the code ain&#8217;t reused in mIRC version past 1.25</p>
<p>read here for more: <a href="http://fish.sekure.us/forum/viewtopic.php?p=1166#1166" rel="nofollow">http://fish.sekure.us/forum/viewtopic.php?p=1166#1166</a></p>
<p> This comment was originally posted on 20070317T11:08:30</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by prdelka</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-42</link>
		<dc:creator>prdelka</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:17 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-42</guid>
		<description>


Month of retro bugs! :-D


 This comment was originally posted on 20070315T14:00:47</description>
		<content:encoded><![CDATA[<p>Month of retro bugs! :-D</p>
<p> This comment was originally posted on 20070315T14:00:47</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on fishy FiSH by sacrine</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14493/comment-page-1/#comment-41</link>
		<dc:creator>sacrine</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:17 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14493/#comment-41</guid>
		<description>RE:

RE:
Echte mannen gebruiken FiSH ?

I don&#039;t think so :)


 This comment was originally posted on 20070308T09:16:31</description>
		<content:encoded><![CDATA[<p>RE:</p>
<p>RE:<br />
Echte mannen gebruiken FiSH ?</p>
<p>I don&#8217;t think so :)</p>
<p> This comment was originally posted on 20070308T09:16:31</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A whole new world of amazon fun by fefe</title>
		<link>http://blogs.23.nu/ilja/2007/03/antville-14506/comment-page-1/#comment-40</link>
		<dc:creator>fefe</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:15 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2007/03/antville-14506/#comment-40</guid>
		<description>milk

milk
usually sort lowest rating first for very popular items, or go to generic bland items like milk and bananas:

http://www.amazon.com/dp/B00032G1S0
http://www.amazon.com/dp/B000328OH6


 This comment was originally posted on 20070313T22:21:58</description>
		<content:encoded><![CDATA[<p>milk</p>
<p>milk<br />
usually sort lowest rating first for very popular items, or go to generic bland items like milk and bananas:</p>
<p><a href="http://www.amazon.com/dp/B00032G1S0" rel="nofollow">http://www.amazon.com/dp/B00032G1S0</a><br />
<a href="http://www.amazon.com/dp/B000328OH6" rel="nofollow">http://www.amazon.com/dp/B000328OH6</a></p>
<p> This comment was originally posted on 20070313T22:21:58</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on auth by pid doesn&#8217;t work ! by ilja</title>
		<link>http://blogs.23.nu/ilja/2008/03/antville-17459/comment-page-1/#comment-39</link>
		<dc:creator>ilja</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:14 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2008/03/antville-17459/#comment-39</guid>
		<description>How can you be sure that the requetor process can be trusted ?

How can you be sure that the requetor process can be trusted ?
you simply can&#039;t. auth by pid is always broken ! 
while it may be trusted while it&#039;s doing it&#039;s ioctl call (if you do a privcheck first), the moment you switch back to userland it&#039;s no longer trusted (if all you&#039;re using for auth is a pid ofcourse).


 This comment was originally posted on 20080305T12:08:28</description>
		<content:encoded><![CDATA[<p>How can you be sure that the requetor process can be trusted ?</p>
<p>How can you be sure that the requetor process can be trusted ?<br />
you simply can&#8217;t. auth by pid is always broken !<br />
while it may be trusted while it&#8217;s doing it&#8217;s ioctl call (if you do a privcheck first), the moment you switch back to userland it&#8217;s no longer trusted (if all you&#8217;re using for auth is a pid ofcourse).</p>
<p> This comment was originally posted on 20080305T12:08:28</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on auth by pid doesn&#8217;t work ! by mxatone</title>
		<link>http://blogs.23.nu/ilja/2008/03/antville-17459/comment-page-1/#comment-38</link>
		<dc:creator>mxatone</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:13 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2008/03/antville-17459/#comment-38</guid>
		<description>On windows, you can make it better easily but ...

On windows, you can make it better easily but ...
Using PsSetLoadImageNotifyRoutine() you can see when registered pid stop.

But as process injection is a trivial task (CreateProcess gives you directly an handle on new process with many different ways to get control over a created process). 

The issue is more:

How can you be sure that the requetor process can be trusted ?

Most of the time, they authorized only a limited number of process but if you crash a trusted one, you can get control directly.


 This comment was originally posted on 20080305T11:52:04</description>
		<content:encoded><![CDATA[<p>On windows, you can make it better easily but &#8230;</p>
<p>On windows, you can make it better easily but &#8230;<br />
Using PsSetLoadImageNotifyRoutine() you can see when registered pid stop.</p>
<p>But as process injection is a trivial task (CreateProcess gives you directly an handle on new process with many different ways to get control over a created process). </p>
<p>The issue is more:</p>
<p>How can you be sure that the requetor process can be trusted ?</p>
<p>Most of the time, they authorized only a limited number of process but if you crash a trusted one, you can get control directly.</p>
<p> This comment was originally posted on 20080305T11:52:04</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on what year are we ? by tping</title>
		<link>http://blogs.23.nu/ilja/2008/08/antville-18776/comment-page-1/#comment-37</link>
		<dc:creator>tping</dc:creator>
		<pubDate>Thu, 16 Oct 2008 05:43:12 +0000</pubDate>
		<guid isPermaLink="false">http://3.blogs.23.nu/ilja/2008/08/antville-18776/#comment-37</guid>
		<description>lol

lol
sprintf ftw! :P

And here are some more at:
- getprotobyname()
http://plan9.bell-labs.com/sources/plan9/sys/src/ape/lib/bsd/getprotobyname.c

- getservbyname()
http://plan9.bell-labs.com/sources/plan9/sys/src/ape/lib/bsd/getservbyname.c

Probably there should be more of them


 This comment was originally posted on 20080830T13:40:39</description>
		<content:encoded><![CDATA[<p>lol</p>
<p>lol<br />
sprintf ftw! :P</p>
<p>And here are some more at:<br />
- getprotobyname()<br />
<a href="http://plan9.bell-labs.com/sources/plan9/sys/src/ape/lib/bsd/getprotobyname.c" rel="nofollow">http://plan9.bell-labs.com/sources/plan9/sys/src/ape/lib/bsd/getprotobyname.c</a></p>
<p>- getservbyname()<br />
<a href="http://plan9.bell-labs.com/sources/plan9/sys/src/ape/lib/bsd/getservbyname.c" rel="nofollow">http://plan9.bell-labs.com/sources/plan9/sys/src/ape/lib/bsd/getservbyname.c</a></p>
<p>Probably there should be more of them</p>
<p> This comment was originally posted on 20080830T13:40:39</p>
]]></content:encoded>
	</item>
</channel>
</rss>
