<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Security and hacking scene in London</title>
	<atom:link href="http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Sat, 30 Aug 2008 10:38:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Paul Guckian</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-119147</link>
		<dc:creator>Paul Guckian</dc:creator>
		<pubDate>Sun, 20 Apr 2008 09:49:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-119147</guid>
		<description>I agree that it is difficult to get the attention of the security community as they have the commerical challenges and priorities. Delaney Consulting have lined up some intermediate level security courses at weekends to try and address the work/life demands. I would be interested in coming along to your meetings...in my experience it can take a long time fo these groups to become popular and then bang, out of nowhere you've the other problem of not having enough room to fit them all. Keep up the good work.</description>
		<content:encoded><![CDATA[<p>I agree that it is difficult to get the attention of the security community as they have the commerical challenges and priorities. Delaney Consulting have lined up some intermediate level security courses at weekends to try and address the work/life demands. I would be interested in coming along to your meetings&#8230;in my experience it can take a long time fo these groups to become popular and then bang, out of nowhere you&#8217;ve the other problem of not having enough room to fit them all. Keep up the good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aramosf</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-116776</link>
		<dc:creator>aramosf</dc:creator>
		<pubDate>Tue, 18 Mar 2008 12:48:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-116776</guid>
		<description>Uhmmm, as i seen you only view bsqlbf1.0, not 1.2 you can optimize to only 7 hits/char (or less if you know the file/string to get is only ascii). Please take a look in the code at www.514.es.

# Wed Jul 12 14:04:33 RST 2006
# + change sql teqneez mcdonalds powah 8) (more than 40% optimization)
#   please, rip me!!, make your own paper!! =]
# + support for windows files (for example: C:\\boot.ini)
# + support for " and 1="1 sql injection
# + -binary and -ascii support
# - -charset option removed
# - -dict option removed
# + upgrade to v1.2

You can use something like:
" and (ord(user()) &#38; 0)=0" and "1"="1



Optimize blind sql injections is nothing new, maybe you read some presentation with this information, i think bh or defcon have some old paper with this.</description>
		<content:encoded><![CDATA[<p>Uhmmm, as i seen you only view bsqlbf1.0, not 1.2 you can optimize to only 7 hits/char (or less if you know the file/string to get is only ascii). Please take a look in the code at <a href="http://www.514.es" rel="nofollow">http://www.514.es</a>.</p>
<p># Wed Jul 12 14:04:33 RST 2006<br />
# + change sql teqneez mcdonalds powah 8) (more than 40% optimization)<br />
#   please, rip me!!, make your own paper!! =]<br />
# + support for windows files (for example: C:\\boot.ini)<br />
# + support for &#8221; and 1=&#8221;1 sql injection<br />
# + -binary and -ascii support<br />
# - -charset option removed<br />
# - -dict option removed<br />
# + upgrade to v1.2</p>
<p>You can use something like:<br />
&#8221; and (ord(user()) &amp; 0)=0&#8243; and &#8220;1&#8243;=&#8221;1</p>
<p>Optimize blind sql injections is nothing new, maybe you read some presentation with this information, i think bh or defcon have some old paper with this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Router Hacking Challenge &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-108564</link>
		<dc:creator>Router Hacking Challenge &#124; GNUCITIZEN</dc:creator>
		<pubDate>Sun, 03 Feb 2008 16:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-108564</guid>
		<description>[...] to map the current state of embedded devices vulnerabilities. GNUCITIZEN members have been actively involved with finding vulnerabilities in routers in the past. We believe that embedded devices hacking is a [...]</description>
		<content:encoded><![CDATA[<p>[...] to map the current state of embedded devices vulnerabilities. GNUCITIZEN members have been actively involved with finding vulnerabilities in routers in the past. We believe that embedded devices hacking is a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-85600</link>
		<dc:creator>Stephen</dc:creator>
		<pubDate>Wed, 12 Dec 2007 22:24:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-85600</guid>
		<description>I'm currently studying in London and want to join in on these type of events, but I to find that they are not normally well advertised.

Perhaps I'm looking in the wrong areas?

Or I find out about them after they happened.</description>
		<content:encoded><![CDATA[<p>I&#8217;m currently studying in London and want to join in on these type of events, but I to find that they are not normally well advertised.</p>
<p>Perhaps I&#8217;m looking in the wrong areas?</p>
<p>Or I find out about them after they happened.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian Pastor</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-85353</link>
		<dc:creator>Adrian Pastor</dc:creator>
		<pubDate>Wed, 12 Dec 2007 13:02:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-85353</guid>
		<description>@pdp - glad you like the slides :) . btw, I talked to R. Marcos yesterday and he said he'd send me the slides. I will add a link ASAP.

@fazed - True they are not advertised enough. I think dc4420 got it right by sending posts to security mailing lists such as Full Disclosure. I think that really helps people remembering the next meeting date.

@Arkan - you just missed the dc4420 drinking party yesterday!</description>
		<content:encoded><![CDATA[<p>@pdp - glad you like the slides :) . btw, I talked to R. Marcos yesterday and he said he&#8217;d send me the slides. I will add a link ASAP.</p>
<p>@fazed - True they are not advertised enough. I think dc4420 got it right by sending posts to security mailing lists such as Full Disclosure. I think that really helps people remembering the next meeting date.</p>
<p>@Arkan - you just missed the dc4420 drinking party yesterday!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-85322</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Wed, 12 Dec 2007 11:28:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-85322</guid>
		<description>Having started the OWASP London chapter and sorted a few london meetings, I can tell you it's a damn hard job.

The problem with london is that everyone is busy, and after a long day you often feel like going home and relaxing with the family/wife/girlfriend/boyfriend etc. 

It sucks, i wish it was more like the US side of things, but it's a price you pay for being in such an aggressive market</description>
		<content:encoded><![CDATA[<p>Having started the OWASP London chapter and sorted a few london meetings, I can tell you it&#8217;s a damn hard job.</p>
<p>The problem with london is that everyone is busy, and after a long day you often feel like going home and relaxing with the family/wife/girlfriend/boyfriend etc. </p>
<p>It sucks, i wish it was more like the US side of things, but it&#8217;s a price you pay for being in such an aggressive market</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Arkan Suleymanovic</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-85317</link>
		<dc:creator>Arkan Suleymanovic</dc:creator>
		<pubDate>Wed, 12 Dec 2007 11:16:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-85317</guid>
		<description>Well, I'm a security professional living in working in London (not getting paid a very good salary though!) My only excuse is that usually we (me and colleagues) are too busy to attend.. We always talk about attending to OWASP and 2600 meetings and we even place it on our schedules but then when the day comes, it's always a client work or a deadline that gets the priority.. 
Still, we would like to join and will try our best to show up in Picadilly for the next 2600 meeting!
Cheers,
Arkan</description>
		<content:encoded><![CDATA[<p>Well, I&#8217;m a security professional living in working in London (not getting paid a very good salary though!) My only excuse is that usually we (me and colleagues) are too busy to attend.. We always talk about attending to OWASP and 2600 meetings and we even place it on our schedules but then when the day comes, it&#8217;s always a client work or a deadline that gets the priority..<br />
Still, we would like to join and will try our best to show up in Picadilly for the next 2600 meeting!<br />
Cheers,<br />
Arkan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fazed</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-85056</link>
		<dc:creator>fazed</dc:creator>
		<pubDate>Wed, 12 Dec 2007 00:17:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-85056</guid>
		<description>I live in england and would love to go to one
of these conventions but they aren't advertised
enough..</description>
		<content:encoded><![CDATA[<p>I live in england and would love to go to one<br />
of these conventions but they aren&#8217;t advertised<br />
enough..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london/#comment-84993</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 11 Dec 2007 21:10:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/security-and-hacking-scene-in-london#comment-84993</guid>
		<description>ap, 10x for putting this presentation together, it is really good...</description>
		<content:encoded><![CDATA[<p>ap, 10x for putting this presentation together, it is really good&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
