<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Autarchy of the Private Cave &#187; security</title> <atom:link href="https://bogdan.org.ua/tags/security/feed" rel="self" type="application/rss+xml" /><link>https://bogdan.org.ua</link> <description>Tiny bits of bioinformatics, [web-]programming etc</description> <lastBuildDate>Wed, 28 Dec 2022 16:09:04 +0000</lastBuildDate> <language>en-US</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>https://wordpress.org/?v=3.8.27</generator> <item><title>Cloud-based bruteforcing, slowloris, and Golang: links</title><link>https://bogdan.org.ua/2009/11/13/cloud-based-bruteforcing-slowloris-and-golang-links.html</link> <comments>https://bogdan.org.ua/2009/11/13/cloud-based-bruteforcing-slowloris-and-golang-links.html#comments</comments> <pubDate>Fri, 13 Nov 2009 16:34:51 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[Links]]></category> <category><![CDATA[Misc]]></category> <category><![CDATA[Programming]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[Apache]]></category> <category><![CDATA[bruteforce]]></category> <category><![CDATA[complexity]]></category> <category><![CDATA[cost]]></category> <category><![CDATA[DOS]]></category> <category><![CDATA[EC]]></category> <category><![CDATA[go]]></category> <category><![CDATA[golang]]></category> <category><![CDATA[mod]]></category> <category><![CDATA[password]]></category> <category><![CDATA[security]]></category> <category><![CDATA[slowloris]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=931</guid> <description><![CDATA[A nice report on the cost of bruteforcing variable-length and variable-complexity passwords using cloud computing services (e.g. Amazon&#8217;s EC). There&#8217;s a kind of a tutorial in their previous post. Slow DoS attack with just 1 computer against a number of web servers, including Apache: slowloris. There is a solution for Apache, packaged for RedHat and [&#8230;]]]></description> <content:encoded><![CDATA[<p>A nice report on the <a
href="http://news.electricalchemy.net/2009/10/password-cracking-in-cloud-part-5.html">cost of bruteforcing variable-length and variable-complexity passwords</a> using cloud computing services (e.g. Amazon&#8217;s <abbr
title="Elastic Cloud">EC</abbr>). There&#8217;s a kind of a tutorial in their previous post.</p><p>Slow <abbr
title="Denial of Service">DoS</abbr> attack with just 1 computer against a number of web servers, including Apache: <a
href="http://ha.ckers.org/slowloris/" class="broken_link" rel="nofollow">slowloris</a>. There is a solution for Apache, packaged for <a
href="ftp://ftp.monshouwer.eu/pub/linux/mod_antiloris/">RedHat</a> and also available for <a
href="http://www.liranuna.com/securing-your-debian-server-against-slowloris/">Debian</a>.</p><p>Finally, there&#8217;s <a
href="http://golang.org/">Go programming language</a>. The most inspiring promise to me personally is the ease of execution parallelization with language&#8217;s built-in syntactic constructs. That is something highly desired. Also, I like that it is a compiled language. However, it might be 10%-20% slower than pure C. Let&#8217;s see how it grows.</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F11%2F13%2Fcloud-based-bruteforcing-slowloris-and-golang-links.html&amp;linkname=Cloud-based%20bruteforcing%2C%20slowloris%2C%20and%20Golang%3A%20links" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F11%2F13%2Fcloud-based-bruteforcing-slowloris-and-golang-links.html&amp;linkname=Cloud-based%20bruteforcing%2C%20slowloris%2C%20and%20Golang%3A%20links" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F11%2F13%2Fcloud-based-bruteforcing-slowloris-and-golang-links.html&amp;linkname=Cloud-based%20bruteforcing%2C%20slowloris%2C%20and%20Golang%3A%20links" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F11%2F13%2Fcloud-based-bruteforcing-slowloris-and-golang-links.html&amp;linkname=Cloud-based%20bruteforcing%2C%20slowloris%2C%20and%20Golang%3A%20links" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F11%2F13%2Fcloud-based-bruteforcing-slowloris-and-golang-links.html&amp;linkname=Cloud-based%20bruteforcing%2C%20slowloris%2C%20and%20Golang%3A%20links" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2009%2F11%2F13%2Fcloud-based-bruteforcing-slowloris-and-golang-links.html&#038;title=Cloud-based%20bruteforcing%2C%20slowloris%2C%20and%20Golang%3A%20links" data-a2a-url="https://bogdan.org.ua/2009/11/13/cloud-based-bruteforcing-slowloris-and-golang-links.html" data-a2a-title="Cloud-based bruteforcing, slowloris, and Golang: links"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2009/11/13/cloud-based-bruteforcing-slowloris-and-golang-links.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>SQL injection walkthrough</title><link>https://bogdan.org.ua/2009/05/11/sql-injection-walkthrough.html</link> <comments>https://bogdan.org.ua/2009/05/11/sql-injection-walkthrough.html#comments</comments> <pubDate>Mon, 11 May 2009 13:41:22 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[how-to]]></category> <category><![CDATA[Links]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[injection]]></category> <category><![CDATA[security]]></category> <category><![CDATA[sql]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=697</guid> <description><![CDATA[SecuriTeam has an old, but still very useful article on SQL injection. I&#8217;ve created a PDF of that article, containing some of the comments (all the &#8216;thank-you&#8217; and &#8216;help-me-hack&#8217; comments were removed): sql injection walkthrough pdf download. Note: there were no specific license terms attached to the article; I believe that the word &#8220;free&#8221; on [&#8230;]]]></description> <content:encoded><![CDATA[<p>SecuriTeam has an old, but still very useful article on <a
href="http://www.securiteam.com/securityreviews/5DP0N1P76E.html">SQL injection</a>.</p><p>I&#8217;ve created a PDF of that article, containing some of the comments (all the &#8216;thank-you&#8217; and &#8216;help-me-hack&#8217; comments were removed): <a
href="http://bogdan.org.ua/wp-content/uploads/2009/05/sql-injection-walkthrough.pdf">sql injection walkthrough pdf download</a>.</p><p><del
datetime="2009-05-13T08:16:21+00:00">Note: there were no specific license terms attached to the article; I believe that the word &#8220;free&#8221; on the SecuriTeam site logo refers to the &#8220;right of free use and copying&#8221;. If you know this is not the case &#8211; please let me know to remove this PDF from public access.</del> (see Brian&#8217;s comment)</p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F05%2F11%2Fsql-injection-walkthrough.html&amp;linkname=SQL%20injection%20walkthrough" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F05%2F11%2Fsql-injection-walkthrough.html&amp;linkname=SQL%20injection%20walkthrough" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F05%2F11%2Fsql-injection-walkthrough.html&amp;linkname=SQL%20injection%20walkthrough" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F05%2F11%2Fsql-injection-walkthrough.html&amp;linkname=SQL%20injection%20walkthrough" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F05%2F11%2Fsql-injection-walkthrough.html&amp;linkname=SQL%20injection%20walkthrough" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2009%2F05%2F11%2Fsql-injection-walkthrough.html&#038;title=SQL%20injection%20walkthrough" data-a2a-url="https://bogdan.org.ua/2009/05/11/sql-injection-walkthrough.html" data-a2a-title="SQL injection walkthrough"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2009/05/11/sql-injection-walkthrough.html/feed</wfw:commentRss> <slash:comments>3</slash:comments> </item> </channel> </rss>