<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Airport Kiosks Security</title>
	<atom:link href="http://www.gnucitizen.org/blog/airport-kiosks-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/airport-kiosks-security/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 14:36:09 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: cybergoth</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-77742</link>
		<dc:creator>cybergoth</dc:creator>
		<pubDate>Tue, 27 Nov 2007 16:29:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-77742</guid>
		<description>n, try some asp tricks like &#124; and ~ , example: login&#124;.aspx</description>
		<content:encoded><![CDATA[<p>n, try some asp tricks like | and ~ , example: login|.aspx</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-77739</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Tue, 27 Nov 2007 16:27:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-77739</guid>
		<description>@n - just click on "Show Complete Compilation Source" on the .NET error page (see screenshot).</description>
		<content:encoded><![CDATA[<p>@n - just click on &#8220;Show Complete Compilation Source&#8221; on the .NET error page (see screenshot).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sws</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-77606</link>
		<dc:creator>sws</dc:creator>
		<pubDate>Tue, 27 Nov 2007 11:12:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-77606</guid>
		<description>oh no... so great ;) funny article...</description>
		<content:encoded><![CDATA[<p>oh no&#8230; so great ;) funny article&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: n</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-77600</link>
		<dc:creator>n</dc:creator>
		<pubDate>Tue, 27 Nov 2007 11:03:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-77600</guid>
		<description>Nice, how did you use the debug functionality to get the source code listing?</description>
		<content:encoded><![CDATA[<p>Nice, how did you use the debug functionality to get the source code listing?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: cybergoth</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-76892</link>
		<dc:creator>cybergoth</dc:creator>
		<pubDate>Sun, 25 Nov 2007 18:32:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-76892</guid>
		<description>Some sitekiosks are connected to company's lan, few times I have successfully found intranet sites using your javascript port scanner.</description>
		<content:encoded><![CDATA[<p>Some sitekiosks are connected to company&#8217;s lan, few times I have successfully found intranet sites using your javascript port scanner.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-76679</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 25 Nov 2007 08:15:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-76679</guid>
		<description>Daniel, this section of the UK law should get a lot more specific. Otherwise, the bad guys can use it for their own good. First of all how do we know that this is not the intendet feature when the only input device that was used was the m-pointer. In USA for example, if u r hiding drugs in your car and u get caught when being searched by a cop who did not had any reason to, then you can get away and attack back the legal system. Same with IT. The law is vague but often based on case studies, which are even more vague. In IT sec we are constantly playing with fire even when all the work we do is legal. I can get into a lot more details but I will stop here.</description>
		<content:encoded><![CDATA[<p>Daniel, this section of the UK law should get a lot more specific. Otherwise, the bad guys can use it for their own good. First of all how do we know that this is not the intendet feature when the only input device that was used was the m-pointer. In USA for example, if u r hiding drugs in your car and u get caught when being searched by a cop who did not had any reason to, then you can get away and attack back the legal system. Same with IT. The law is vague but often based on case studies, which are even more vague. In IT sec we are constantly playing with fire even when all the work we do is legal. I can get into a lot more details but I will stop here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-76659</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Sun, 25 Nov 2007 07:20:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-76659</guid>
		<description>Don't forget, under UK law you would have been persecuted for doing what you did. 

The issue isn't you just pressing buttons, but the fact you never had permission to make that computer perform that function, which is the crux of section 1a of the computer misuse act.

Good to see kiosk security is still as crap as ever though :)</description>
		<content:encoded><![CDATA[<p>Don&#8217;t forget, under UK law you would have been persecuted for doing what you did. </p>
<p>The issue isn&#8217;t you just pressing buttons, but the fact you never had permission to make that computer perform that function, which is the crux of section 1a of the computer misuse act.</p>
<p>Good to see kiosk security is still as crap as ever though :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: naom</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-76577</link>
		<dc:creator>naom</dc:creator>
		<pubDate>Sun, 25 Nov 2007 01:23:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-76577</guid>
		<description>3 minutes killed out of 3 hours. Not bad.</description>
		<content:encoded><![CDATA[<p>3 minutes killed out of 3 hours. Not bad.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sam</title>
		<link>http://www.gnucitizen.org/blog/airport-kiosks-security/comment-page-1/#comment-76539</link>
		<dc:creator>Sam</dc:creator>
		<pubDate>Sat, 24 Nov 2007 23:31:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/airport-kiosks-security#comment-76539</guid>
		<description>Interesting stuff. Reminds me of the time I saw the BoSoD on an ATM and the Windows XP desktop on a scan yourself checkout.</description>
		<content:encoded><![CDATA[<p>Interesting stuff. Reminds me of the time I saw the BoSoD on an ATM and the Windows XP desktop on a scan yourself checkout.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
