<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jonathan T Rajewski &#187; hacking</title>
	<atom:link href="http://jtrajewski.com/blog/category/hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://jtrajewski.com/blog</link>
	<description>A look into the world of digital forensics, white collar crime and related topics</description>
	<lastBuildDate>Wed, 05 Aug 2009 13:50:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ICE takes Cal State student into custody for violating the DMCA</title>
		<link>http://jtrajewski.com/blog/2009/08/05/ice-takes-cal-state-student-into-custody-for-violating-the-dmca/</link>
		<comments>http://jtrajewski.com/blog/2009/08/05/ice-takes-cal-state-student-into-custody-for-violating-the-dmca/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 13:50:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[cal state]]></category>
		<category><![CDATA[DMCA]]></category>
		<category><![CDATA[Matthew Lloyd Crippen]]></category>
		<category><![CDATA[video game systems]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/?p=78</guid>
		<description><![CDATA[This article describes how Immigration Customs and Enforcement (ICE) arrested Matthew Lloyd Crippen &#8220;Monday on federal charges that he illegally modified Xbox, Playstation, Wii and other video game consoles to enable the machines to play pirated video games.&#8221;
Crippen was indicted by a federal grand jury on two counts of violating the Digital Millennium Copyright Act.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nbcdfw.com/news/tech/Cal-State-Student-Faces-10-Year-Prison-Term-for-Playing-with-Video-Games-52386872.html">This article</a> describes how Immigration Customs and Enforcement (ICE) arrested Matthew Lloyd Crippen &#8220;Monday on federal charges that he illegally modified Xbox, Playstation, Wii and other video game consoles to enable the machines to play pirated video games.&#8221;</p>
<p>Crippen was indicted by a federal grand jury on two counts of violating the Digital Millennium Copyright Act.</p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2009/08/05/ice-takes-cal-state-student-into-custody-for-violating-the-dmca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weaponizing Web 2.0</title>
		<link>http://jtrajewski.com/blog/2009/07/30/weaponizing-web-2-0/</link>
		<comments>http://jtrajewski.com/blog/2009/07/30/weaponizing-web-2-0/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 14:32:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[Web 2.0]]></category>
		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/?p=64</guid>
		<description><![CDATA[In this link Brian Krebs blog, he describes how researchers Nathan Hamiel and Shawn Moyer presented a method to (link to paper &#8211; Moyer-Hamiel-DC17-Dynamic-CSRF) automate cross-site request forgery (CSRF) attacks.
Taken from the article &#8220;To take the Alice and Bob on the forum example a step further, consider what happens when Alice views a forum posting [...]]]></description>
			<content:encoded><![CDATA[<p>In this <a href="http://voices.washingtonpost.com/securityfix/2009/07/weaponizing_web_20.html#more">link</a> Brian Krebs blog, he describes how researchers Nathan Hamiel and Shawn Moyer presented a method to (<a href='http://jtrajewski.com/blog/wp-content/uploads/2009/07/Moyer-Hamiel-DC17-Dynamic-CSRF.pdf'>link to paper &#8211; Moyer-Hamiel-DC17-Dynamic-CSRF</a>) automate cross-site request forgery (CSRF) attacks.</p>
<p>Taken from the article <em>&#8220;To take the Alice and Bob on the forum example a step further, consider what happens when Alice views a forum posting by Bob that includes a link to an off-site image hosted at a site controlled by Bob. That image, when loaded by Alice&#8217;s browser, will automatically send Bob&#8217;s site a referrer URL that includes the full token that is unique to Alice&#8217;s browser session with that forum. Armed with the referring URL&#8217;s token, Bob can then respond to the image request from Alice&#8217;s browser with a request to silently take action on that forum in Alice&#8217;s name.&#8221;</em></p>
<p>This interesting attack has been around since <a href="  http://www.tux.org/~peterw/csrf.txt">2001</a>. The two researchers brought the CSRF concept a bit farther by systematically packaging payloads based on the referring site.. so essentially, they can have attacks ready for particular websites. <em>&#8220;We&#8217;ve come up with a way to take those tokens and repackage them on a payload-per-domain basis, with different types of payloads based on the referring site,&#8221; Hamiel said. &#8220;So, if it&#8217;s linked off of Twitter, the tool might respond one way, or if it&#8217;s linked off of something like LinkedIn, it might respond another way.&#8221;</em> </p>
<p>This also gives attackers the ability to scale up attacks in a modular fashion so updates can be made to payloads on fly when referring websites make changes.</p>
<p>Just something to keep your eye on.. </p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2009/07/30/weaponizing-web-2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers attack Large Hadron Collider</title>
		<link>http://jtrajewski.com/blog/2008/09/12/hackers-attack-large-hadron-collider/</link>
		<comments>http://jtrajewski.com/blog/2008/09/12/hackers-attack-large-hadron-collider/#comments</comments>
		<pubDate>Sat, 13 Sep 2008 01:20:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cyber Terrorism]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[large hadron collider]]></category>
		<category><![CDATA[lhc]]></category>
		<category><![CDATA[network intrusion]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/?p=30</guid>
		<description><![CDATA[The Large Hadron Collider is a controversial international research/science project. A (group of) hacker(s) decided to hack into the system&#8230; The following is a quote from the article..
Scientists working at Cern, the organisation that runs the vast smasher, were worried about what the hackers could do because they were &#8220;one step away&#8221; from the computer control system [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.lhc.ac.uk/" target="_blank">Large Hadron Collider</a> is a <a href="http://www.businessweek.com/globalbiz/content/sep2008/gb20080910_005256.htm?chan=globalbiz_europe+index+page_top+stories" target="_blank">controversial </a>international research/science project. A (group of) hacker(s) decided to hack into the system&#8230; The following is a quote from the <a href="http://www.telegraph.co.uk/earth/main.jhtml?xml=/earth/2008/09/12/scicern212.xml" target="_blank">article</a>..</p>
<blockquote><p>Scientists working at Cern, the organisation that runs the vast smasher, were worried about what <strong>the hackers</strong> could do because they <strong>were &#8220;one step away&#8221; from the computer control system</strong> of one of the huge detectors of the machine, a vast magnet that weighs 12,500 tons, measuring around 21 metres in length and 15 metres wide/high.</p>
<p>If they had hacked into a second computer network, they could have turned off parts of the vast detector and, said the insider, &#8220;it is hard enough to make these things work if no one is messing with it.&#8221;</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2008/09/12/hackers-attack-large-hadron-collider/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Volatile Memory &#8211; Hardware attack at Full Disk Encryption Keys</title>
		<link>http://jtrajewski.com/blog/2008/03/12/volatile-memory-hardware-attack-at-full-disk-encryption-keys/</link>
		<comments>http://jtrajewski.com/blog/2008/03/12/volatile-memory-hardware-attack-at-full-disk-encryption-keys/#comments</comments>
		<pubDate>Wed, 12 Mar 2008 20:46:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Cryptanalysis (kryptós analýein)]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[bitlocker]]></category>
		<category><![CDATA[bitunlocker]]></category>
		<category><![CDATA[encryption key]]></category>
		<category><![CDATA[pgp]]></category>
		<category><![CDATA[ram]]></category>
		<category><![CDATA[truecrypt]]></category>
		<category><![CDATA[volatile memory]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2008/03/12/volatile-memory-hardware-attack-at-full-disk-encryption-keys/</guid>
		<description><![CDATA[Researchers at Princeton University have made significant progress in the analysis of volatile memory, specifically DRAM.
Whitepaper
Video
]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://citp.princeton.edu/memory/">Researchers at Princeton University </a>have made significant progress in the analysis of volatile memory, specifically DRAM.</p>
<p><a target="_blank" href="http://citp.princeton.edu/pub/coldboot.pdf">Whitepaper</a></p>
<p><a target="_blank" href="http://www.youtube.com/watch?v=JDaicPIgn9U">Video</a></p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2008/03/12/volatile-memory-hardware-attack-at-full-disk-encryption-keys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FAA: Boeing&#8217;s New 787 May Be Vulnerable to Hacker Attack</title>
		<link>http://jtrajewski.com/blog/2008/01/07/faa-boeings-new-787-may-be-vulnerable-to-hacker-attack/</link>
		<comments>http://jtrajewski.com/blog/2008/01/07/faa-boeings-new-787-may-be-vulnerable-to-hacker-attack/#comments</comments>
		<pubDate>Mon, 07 Jan 2008 20:05:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[787]]></category>
		<category><![CDATA[boeing]]></category>
		<category><![CDATA[FAA]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[network]]></category>

		<guid isPermaLink="false">http://jtrajewski.com/blog/2008/01/07/faa-boeings-new-787-may-be-vulnerable-to-hacker-attack/</guid>
		<description><![CDATA[In this article, Wired&#8217;s Kim Zetter reports on how Boeing implemented an open computer network on their new 787&#8230; But passengers were on the same network as the flight control systems&#8230; which theoretically could be compromised in flight..
 &#8221;According to the FAA document published in the Federal Register (mirrored at Cryptome.org), the vulnerability exists because the [...]]]></description>
			<content:encoded><![CDATA[<p>In <a target="_blank" href="http://www.wired.com/politics/security/news/2008/01/dreamliner_security">this </a>article, Wired&#8217;s Kim Zetter reports on how Boeing implemented an open computer network on their new 787&#8230; But passengers were on the same network as the flight control systems&#8230; which theoretically could be compromised in flight..</p>
<p><em> &#8221;According to </em><a href="http://frwebgate6.access.gpo.gov/cgi-bin/waisgate.cgi?WAISdocID=486816490816+0+0+0&amp;WAISaction=retrieve"><em>the FAA document</em></a><em> published in the Federal Register (</em><a href="http://cryptome.org/faa010208.htm"><em>mirrored at Cryptome.org</em></a><em>), the vulnerability exists because the plane&#8217;s computer systems connect the passenger network with the flight-safety, control and navigation network. It also connects to the airline&#8217;s business and administrative-support network, which communicates maintenance issues to ground crews.&#8221;</em></p>
]]></content:encoded>
			<wfw:commentRss>http://jtrajewski.com/blog/2008/01/07/faa-boeings-new-787-may-be-vulnerable-to-hacker-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
