<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>javier arturo rodríguez &#187; Security</title>
	<atom:link href="http://javier.rodriguez.org.mx/index.php/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://javier.rodriguez.org.mx</link>
	<description>random musings</description>
	<lastBuildDate>Thu, 16 Apr 2009 14:00:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Link:  JSESSIONID considered harmful</title>
		<link>http://javier.rodriguez.org.mx/index.php/2009/04/16/link-jsessionid-considered-harmful</link>
		<comments>http://javier.rodriguez.org.mx/index.php/2009/04/16/link-jsessionid-considered-harmful#comments</comments>
		<pubDate>Thu, 16 Apr 2009 14:00:13 +0000</pubDate>
		<dc:creator>javier</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[link]]></category>

		<guid isPermaLink="false">http://javier.rodriguez.org.mx/?p=227</guid>
		<description><![CDATA[Craig Condit makes a strong case against JSESSIONID in JSESSIONID considered harmful. And I just learned that it is disabled by default in Grails 1.1.
]]></description>
			<content:encoded><![CDATA[<p><a href="">Craig Condit</a> makes a strong case against JSESSIONID in <a href="http://randomcoder.com/articles/jsessionid-considered-harmful">JSESSIONID considered harmful</a>. And I just learned that it is <a href="http://jira.codehaus.org/browse/GRAILS-3364">disabled by default in Grails 1.1</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://javier.rodriguez.org.mx/index.php/2009/04/16/link-jsessionid-considered-harmful/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Prodigy Infinitum, SMTP through port 25, botnets and such</title>
		<link>http://javier.rodriguez.org.mx/index.php/2007/12/26/prodigy-infinitum-smtp-through-port-25-botnets-and-such</link>
		<comments>http://javier.rodriguez.org.mx/index.php/2007/12/26/prodigy-infinitum-smtp-through-port-25-botnets-and-such#comments</comments>
		<pubDate>Wed, 26 Dec 2007 19:15:57 +0000</pubDate>
		<dc:creator>javier</dc:creator>
				<category><![CDATA[Living]]></category>
		<category><![CDATA[Mexico]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[dsl]]></category>
		<category><![CDATA[infinitum]]></category>
		<category><![CDATA[telmex]]></category>

		<guid isPermaLink="false">http://javier.rodriguez.org.mx/index.php/2007/12/26/prodigy-infinitum-smtp-through-port-25-botnets-and-such/</guid>
		<description><![CDATA[After pulling my hair for a couple of days I just realized that my DSL provider is blocking all outgoing connections to port 25 with an ICMP Unreachable packet, which translates as a totally bogus &#8220;no route to host&#8221; message (An ICMP RST would be more kosher, BTW). The only explanation that comes to my [...]]]></description>
			<content:encoded><![CDATA[<p><img src='http://javier.rodriguez.org.mx/wp-content/uploads/2007/12/dsl.jpg' alt='dsl.jpg' align='left' />After pulling my hair for a couple of days I just realized that my DSL provider is blocking all outgoing connections to port 25 with an ICMP Unreachable packet, which translates as a totally bogus &#8220;no route to host&#8221; message (An ICMP RST would be more kosher, BTW). The only explanation that comes to my mind is that Telmex has finally realized that it has become one of the largest botnet hosts in the world and decided to do something about it. This is a terrible inconvenience for me, because I run a backup MX at my home office and all the email I write while I&#8217;m at home is relayed through it. And now it believes that it has been cut out from the Internet, and is suffering from Internet withdrawal syndrome. Oh, and all attempts to use an external relay -like my primary MTA or the office&#8217;s- through port 25 fail as well, so I have had to set up an elaborate workaround *just to send email*.<br />
*Argh!* I hate to pay up for those ignorant Windows home users.<br />
Add to that the fact that i get 800KBps tops in a 2GBps line, and <a href="http://www.creabits.com/2007/08/01/telmex-limita-a-4gb-de-transferencia-mensual-a-prodigy-infinitum/">recurrent reports</a> of arbitrary  bandwidth capping</a> and Infinitum stops looking like a good alternative for home broadband. I&#8217;ll have to look for a cost-effective alternative, but after experiencing 20MBps/20EUR in Europe I&#8217;m afraid that I&#8217;ve been spoiled for life.<br />
In the meantime, if you were expecting a mail from me in the last five days or so, I&#8217;m sorry to say that it is either on its way or lost forever.<br />
Anyway&#8230; Merry Christmas!<br />
<b>Update 20080104:</b> AJ Gibson <a href="http://javier.rodriguez.org.mx/index.php/2007/12/26/prodigy-infinitum-smtp-through-port-25-botnets-and-such">points out in a comment</a> that Telmex is willing to remove the block from your account if you are willing to <a href="https://www.beneficios.telmex.com/puerto25Prod/iniciaPuerto25Internet.do">jump through a few hoops</a>. Just go to <a href="http://www.telmex.com/mx/asistencia/correoelectronico/faq_puerto_25.html">http://www.telmex.com/mx/asistencia/correoelectronico/faq_puerto_25.html</a> and follow the instructions there. I registered yesterday and today I can connect back to external SMTP servers again. As mentioned in the comments, YMMV.</p>
]]></content:encoded>
			<wfw:commentRss>http://javier.rodriguez.org.mx/index.php/2007/12/26/prodigy-infinitum-smtp-through-port-25-botnets-and-such/feed</wfw:commentRss>
		<slash:comments>28</slash:comments>
		</item>
		<item>
		<title>09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0</title>
		<link>http://javier.rodriguez.org.mx/index.php/2007/05/01/09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0</link>
		<comments>http://javier.rodriguez.org.mx/index.php/2007/05/01/09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0#comments</comments>
		<pubDate>Tue, 01 May 2007 19:42:18 +0000</pubDate>
		<dc:creator>javier</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Hack!]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://javier.rodriguez.org.mx/index.php/2007/05/01/09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0/</guid>
		<description><![CDATA[What&#8217;s so special about this number? How is it different from -say- 0&#215;09F911029D74E35BD84156C5635688BF or from 0&#215;09F911029D74E35BD84156C5635688C1? More importantly: can someone copyright a freaking number? Read rudd-o&#8217;s Spread this number post and find out why 0&#215;09F911029D74E35BD84156C5635688C0 is so important.
]]></description>
			<content:encoded><![CDATA[<p>What&#8217;s so special about this number? How is it different from -say- 0&#215;09F911029D74E35BD84156C5635688BF or from 0&#215;09F911029D74E35BD84156C5635688C1? More importantly: can someone copyright a freaking <strong>number</strong>? Read <a href="http://rudd-o.com/archives/2007/04/30/spread-this-number/">rudd-o&#8217;s Spread this number post</a> and find out why 0&#215;09F911029D74E35BD84156C5635688C0 is so important.</p>
]]></content:encoded>
			<wfw:commentRss>http://javier.rodriguez.org.mx/index.php/2007/05/01/09-f9-11-02-9d-74-e3-5b-d8-41-56-c5-63-56-88-c0/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mitigate the .WMF vulnerability with Exim, Squid and SquidGuard</title>
		<link>http://javier.rodriguez.org.mx/index.php/2006/01/02/mitigate-the-wmf-vulnerability-with-exim-squid-and-squidguard</link>
		<comments>http://javier.rodriguez.org.mx/index.php/2006/01/02/mitigate-the-wmf-vulnerability-with-exim-squid-and-squidguard#comments</comments>
		<pubDate>Mon, 02 Jan 2006 18:45:34 +0000</pubDate>
		<dc:creator>javier</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SysAdmin]]></category>

		<guid isPermaLink="false">http://javier.rodriguez.org.mx/?p=48</guid>
		<description><![CDATA[Unless you&#8217;ve been on holiday leave you&#8217;ve probably heard about the WMF vulnerability by now. Everything seems to indicate that Microsoft won&#8217;t take action to patch this gaping hole before January 9th, so here are a few measures to be on the safe side.
1. Before you do anything else, go ahead an unregister SHIMGVW.DLL
C:\> regsvr32 [...]]]></description>
			<content:encoded><![CDATA[<p>Unless you&#8217;ve been on holiday leave you&#8217;ve probably heard about the <a href="http://www.microsoft.com/technet/security/advisory/912840.mspx">WMF vulnerability</a> by now. Everything seems to indicate that Microsoft won&#8217;t take action to patch this gaping hole before January 9th, so here are a few measures to be on the safe side.</p>
<p>1. Before you do anything else, go ahead an unregister SHIMGVW.DLL</p>
<div class="codesnip-container" >C:\> regsvr32 -u %windir%\system32\shimgvw.dll</div>
<p>Put this in a login script, and just for good measure go ahead an run it in every Windows box you&#8217;re responsible for. Heck, run it even in those you&#8217;re *not* responsible for as well.</p>
<p>2. I already got quite a few .WMF attachments on the spamtraps. <a href="http://www.f-secure.com/weblog/archives/archive-012006.html">F-Secure has a very interesting specimen</a> and a lot to say about it. So the next step is to block them in exim.conf. Enable the acl_check_content ACL and make sure that you have a rule like this one:</p>
<div class="codesnip-container" >deny  message = This message contains an unwanted file extension ($found_extension)<br />
        demime = scr:vb:vbs:vbe:js:jse:reg:bat:lnk:pif:hlp:dll:com:rar:wmf</div>
<p>3. SquidGuard can filter URLs that match a given regular expression. Add these regexes to a local-blocks/expressions or similar file:</p>
<div class="codesnip-container" >http://.*\.(scr|vb|vbs|vbe|jse|reg|bat|lnk|pif|hlp|com|rar|wmf)($|\?)<br />
ftp://.*\.(scr|vb|vbs|vbe|jse|reg|bat|lnk|pif|hlp|com|rar|dll|js|wmf)($|\?)</div>
<p>Note that the .dll and .js extensions aren&#8217;t blocked for HTTP. That&#8217;s because the lovely IIS uses the .dll suffix for its extensions, and you can&#8217;t block JavaScript for HTTP either unless you want to break 90% of the Internet for all your local clients. I firmly belive that blocking them for FTP is just fine, tough.<br />
<b>Update 20060102 125530:</b> <a href="http://www.jeremygaddis.com/">Jeremy Gaddis</a> shares a <a href="http://www.jeremygaddis.com/2005/12/29/blocking-wmf-at-the-perimeter/">squid recipe</a>.</p>
<p>Of course, this only applies if you use <a href="http://www.exim.org/">exim</a> and <a href="http://www.squid-cache.org/">Squid</a>+<a href="http://www.squidguard.org/">SquidGuard</a> -which by the way are all excellent Open Source products- but the same principle applies to any other mail and proxy servers. If you implement all three recommendations you should be fine. User should not get .WMF files through email or the Web. Even if a clueless user catches it though some other means (IM, external e-mail account, a *ack!* floppy disk/CD-ROM/flash drive, a helpful colleage, etc.) the REGSVR32 workaround should keep the exploit at bay. If you definitely need to work with WMFs, there are <a href="http://taosecurity.blogspot.com/2006/01/power-of-open-source-one-of-criticisms.html">other alternatives</a> as outlined by Richard Bejtlich. Just don&#8217;t hold your breath for a Microsoft-backed patch.</p>
<p>&lt;rant&gt;And about Microsoft&#8217;s &#8220;swift&#8221; response to this issue: The next time that someone gives me the line about not using Open Source because there&#8217;s nobody to take responsibility for problems, I&#8217;ll puch him in the face without further warning.&lt;/rant&gt;</p>
]]></content:encoded>
			<wfw:commentRss>http://javier.rodriguez.org.mx/index.php/2006/01/02/mitigate-the-wmf-vulnerability-with-exim-squid-and-squidguard/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
