<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-38158647</id><updated>2011-11-27T15:21:30.138-08:00</updated><category term='Photos'/><category term='Security'/><title type='text'>Matcha's Security Blog</title><subtitle type='html'>i post security topics in Japan which i interest.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>30</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-38158647.post-682665213776883128</id><published>2008-04-06T11:20:00.000-07:00</published><updated>2008-04-06T11:31:00.819-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>HDRI photos are get into the news in geek in japan.</title><content type='html'>@&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;takesako&lt;/span&gt; who is popular engineer in japan.&lt;br /&gt;he start &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;HDRI&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;photosHigh&lt;/span&gt; dynamic range imaging few days ago.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;HDRI&lt;/span&gt; photos are composite photograph with changing 2-4 leaves of photos iris.&lt;br /&gt;you can see &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;HDRI&lt;/span&gt; detail at &lt;a href="http://en.wikipedia.org/wiki/High_dynamic_range_imaging"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;wikipedia&lt;/span&gt;.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I create few leaves of HDRI photos.&lt;br /&gt;SAKURA with blue sky.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080407/20080407021947.jpg"&gt;&lt;img style="cursor: pointer; width: 320px;" src="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080407/20080407021947.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;SAKURA&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080406/20080406085853.jpg"&gt;&lt;img style="cursor: pointer; width: 320px;" src="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080406/20080406085853.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;and SAKURA SAKURA SAKURA :-)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080406/20080406085924.jpg"&gt;&lt;img style="cursor: pointer; width: 320px;" src="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080406/20080406085924.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-682665213776883128?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/682665213776883128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=682665213776883128' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/682665213776883128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/682665213776883128'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2008/04/hdri-photos-are-get-into-news-in-geek.html' title='HDRI photos are get into the news in geek in japan.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-6539125670606932067</id><published>2008-04-06T10:57:00.000-07:00</published><updated>2008-12-10T11:13:09.820-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Spring has come to kyoto and cherry blossomed!!!</title><content type='html'>Spring has come! every spring &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;Japanese&lt;/span&gt; love to see cherry blossomed.&lt;br /&gt;cherry blossomed  flower are very short life like 1week.&lt;br /&gt;and gone like flower shower.&lt;br /&gt;&lt;br /&gt;these cherry blossomed compared to human life.&lt;br /&gt;&lt;br /&gt;Anyway this year's Cherry is so &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;beautiful&lt;/span&gt;.&lt;br /&gt;Blue sky and pink flower and white flower shower.&lt;br /&gt;We love &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;SAKURA&lt;/span&gt;!&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_UTNqB6ppCWU/R_kSxKJxWaI/AAAAAAAAAHY/mXXdy-MvA7E/s1600-h/0804060011.JPG"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_UTNqB6ppCWU/R_kSxKJxWaI/AAAAAAAAAHY/mXXdy-MvA7E/s320/0804060011.JPG" alt="" id="BLOGGER_PHOTO_ID_5186197081642064290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;SAKURA with Blue sky&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/R_kSxaJxWbI/AAAAAAAAAHg/Au_XAnz_pa0/s1600-h/0804060017.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/R_kSxaJxWbI/AAAAAAAAAHg/Au_XAnz_pa0/s320/0804060017.JPG" alt="" id="BLOGGER_PHOTO_ID_5186197085937031602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_UTNqB6ppCWU/R_kSyKJxWcI/AAAAAAAAAHo/Fzl8OS9RfrQ/s1600-h/0804060062.JPG"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_UTNqB6ppCWU/R_kSyKJxWcI/AAAAAAAAAHo/Fzl8OS9RfrQ/s320/0804060062.JPG" alt="" id="BLOGGER_PHOTO_ID_5186197098821933506" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Dandelion and Cherry Blossom&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080406/20080406152034.jpg"&gt;&lt;img style="cursor: pointer; width: 320px;" src="http://f.hatena.ne.jp/images/fotolife/r/ripjyr/20080406/20080406152034.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-6539125670606932067?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/6539125670606932067/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=6539125670606932067' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/6539125670606932067'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/6539125670606932067'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2008/04/spring-has-come-to-kyoto-and-cherry.html' title='Spring has come to kyoto and cherry blossomed!!!'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_UTNqB6ppCWU/R_kSxKJxWaI/AAAAAAAAAHY/mXXdy-MvA7E/s72-c/0804060011.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-74335850698256823</id><published>2008-03-12T00:31:00.001-07:00</published><updated>2008-03-12T01:21:23.210-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Trendmicro Virus Infomation pages are Hacked(falsificated).</title><content type='html'>&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Trendmicro&lt;/span&gt; Virus &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;information&lt;/span&gt; page was modified by hacker.&lt;br /&gt;And they insert &lt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;iframe&gt;&lt;/span&gt; tags to download &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;malware&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;JS&lt;/span&gt;_&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;DLOADER&lt;/span&gt;.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;TZE&lt;/span&gt; is the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;malware&lt;/span&gt; which download from &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;falsificated&lt;/span&gt; pages.&lt;br /&gt;Anti virus &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_10"&gt;vendor&lt;/span&gt; &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_11"&gt;spread&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;malware&lt;/span&gt;...&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_13"&gt;really&lt;/span&gt;?!&lt;br /&gt;&lt;br /&gt;Virus infomation on these are falsificated virus infomation pages.&lt;br /&gt;&lt;br /&gt;Trendmicro US does not release News anything.&lt;br /&gt;There is Japanese release News page(see google translated page Below )&lt;br /&gt;&lt;a href="http://translate.google.com/translate?u=http%3A%2F%2Fjp.trendmicro.com%2Fjp%2Fabout%2Fnotice%2F0312%2Findex.html&amp;amp;langpair=ja%7Cen&amp;amp;hl=ja&amp;amp;ie=UTF8"&gt;http://translate.google.com/translate?u=http%3A%2F%2Fjp.trendmicro.com%2Fjp%2Fabout%2Fnotice%2F0312%2Findex.html&amp;amp;langpair=ja%7Cen&amp;amp;hl=ja&amp;amp;ie=UTF8&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;&lt;strong&gt;English virus infomation pages.&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;ADWARE_BHO_WEBDIR&lt;/li&gt;&lt;li&gt;ADWARE_BHO_WSTART&lt;/li&gt;&lt;li&gt;HKTL_MDBEXP.A&lt;/li&gt;&lt;li&gt;POSSIBLE_OTORUN3&lt;/li&gt;&lt;li&gt;SPYWARE_TRAK_RADMIN&lt;/li&gt;&lt;li&gt;TROJ_ARTIEF-1&lt;/li&gt;&lt;li&gt;TROJ_CLAGGER.D&lt;/li&gt;&lt;li&gt;TSPY_BANKER-2.002&lt;/li&gt;&lt;li&gt;TSPY_BANKRYPT.N&lt;/li&gt;&lt;li&gt;TSPY_GAMANIA.CI&lt;/li&gt;&lt;li&gt;TSPY_GOLDUN.GEN&lt;/li&gt;&lt;li&gt;TSPY_LINEAGE&lt;/li&gt;&lt;li&gt;TSPY_ONLINEG.DAU&lt;/li&gt;&lt;li&gt;TSPY_ONLINEG.OAX&lt;/li&gt;&lt;li&gt;TSPY_ONLINEG.OAX&lt;/li&gt;&lt;li&gt;TSPY_QQPASS&lt;/li&gt;&lt;li&gt;TSPY_SDBOT.BTI&lt;/li&gt;&lt;li&gt;W97M_DLOADER.BKV&lt;/li&gt;&lt;li&gt;WORM_IRCBOT.JK&lt;/li&gt;&lt;li&gt;WORM_NYXEM.E&lt;/li&gt;&lt;li&gt;WORM_SOBER.AG&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;Japanese virus infomation pages.&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ADW_BRUNME.A&lt;/li&gt;&lt;li&gt;ADW_ZANGO.A&lt;/li&gt;&lt;li&gt;ADWARE_ADBLASTER &lt;/li&gt;&lt;li&gt;ADWARE_EXACTADVERTISING&lt;/li&gt;&lt;li&gt;ADWARE_EZULA.ILOOKUP&lt;/li&gt;&lt;li&gt;TSPY_AGENT.HS&lt;/li&gt;&lt;li&gt;TSPY_ANICMOO&lt;/li&gt;&lt;li&gt;TSPY_GOLDUN.GEN&lt;/li&gt;&lt;li&gt;TSPY_HUPIGON.ZY&lt;/li&gt;&lt;li&gt;TSPY_Lmir TSPY_Tiny&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-74335850698256823?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/74335850698256823/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=74335850698256823' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/74335850698256823'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/74335850698256823'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2008/03/trendmicro-virus-infomation-pages-are.html' title='Trendmicro Virus Infomation pages are Hacked(falsificated).'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-5847033826448460508</id><published>2008-01-31T22:49:00.000-08:00</published><updated>2008-01-31T23:34:25.563-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Cross Site Scripting(XSS) Challenges by yamagata21h</title><content type='html'>&lt;p&gt;Japanese IT Security technical expert yamagata21h has made Cross Site Scripting(XSS) challenging site.&lt;br /&gt;-&gt; &lt;a href="http://xss-quiz.int21h.jp/"&gt;http://xss-quiz.int21h.jp/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Yamagata21h is Japanese famous technical Security expert.&lt;br /&gt;Yamagata21h was impressed by "XSS Workshop" &lt;a href="http://blogged-on.de/xss/"&gt;http://blogged-on.de/xss/&lt;/a&gt;.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;This page was written by yamagata21, inspired by &lt;a href="http://blogged-on.de/xss/"&gt;http://blogged-on.de/xss/&lt;/a&gt;. &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;but "XSS Workshop" is not so covering various of type of XSS he said.&lt;br /&gt;so yamagata21h makes "XSS Challenges" him self. &lt;/p&gt;&lt;p&gt;Please Challenge it!!!&lt;br /&gt;if you interesting on Development Security.&lt;br /&gt;and feed back yamagata21h more XSS question if you have.&lt;br /&gt;&lt;a href="http://xss-quiz.int21h.jp/"&gt;http://xss-quiz.int21h.jp/&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-5847033826448460508?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/5847033826448460508/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=5847033826448460508' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/5847033826448460508'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/5847033826448460508'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2008/01/cross-site-scriptingxss-challenges-by.html' title='Cross Site Scripting(XSS) Challenges by yamagata21h'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-1456307970748965054</id><published>2007-12-28T13:09:00.000-08:00</published><updated>2008-12-10T11:13:10.826-08:00</updated><title type='text'>[security] Microsoft Security Advisory (945713) can open arbitrary pages.</title><content type='html'>In &lt;a href="http://www.microsoft.com/technet/security/advisory/945713.mspx"&gt;Microsoft Security Advisory (945713): Vulnerability in Web Proxy Auto-Discovery (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;WPAD&lt;/span&gt;) Could Allow Information Disclosure.&lt;/a&gt;&lt;br /&gt;They said that "man-in-the-middle attacks" is threat. but is this vulnerability is &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;realy&lt;/span&gt; only man-in-the-middle???&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;What causes this threat?&lt;/span&gt;&lt;br /&gt;A malicious user could host a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;WPAD&lt;/span&gt; server, &lt;b style="color: rgb(255, 0, 0);"&gt;potentially establishing it as a proxy server to conduct man-in-the-middle attacks against customers&lt;/b&gt; whose domains are registered as a &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;subdomain&lt;/span&gt; to a second-level domain (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;SLD&lt;/span&gt;). For customers with a primary &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;DNS&lt;/span&gt; suffix configured, the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;DNS&lt;/span&gt; resolver in Windows will attempt to resolve an unqualified “&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;wpad&lt;/span&gt;” &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;hostname&lt;/span&gt; using each sub-domain in the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;DNS&lt;/span&gt; suffix until a second-level domain is reached. For example, if the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;DNS&lt;/span&gt; suffix is corp.contoso.co.us and an attempt is made to resolve an unqualified &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;hostname&lt;/span&gt; of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;wpad&lt;/span&gt;, the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;DNS&lt;/span&gt; resolver will try wpad.corp.contoso.co.us. If that is not found, it will try, via &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;DNS&lt;/span&gt; devolution, to resolve wpad.contoso.co.us. If that is not found, it will try to resolve wpad.co.us, which is outside of the contoso.co.us domain.&lt;/blockquote&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;I verify using malicious proxy.pac(wpad.dat) to open arbitrary malicious pages as real pages.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For Example put proxy.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;pac&lt;/span&gt; as below.&lt;br /&gt;&lt;blockquote&gt;function &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;FindProxyForURL&lt;/span&gt;(&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;url&lt;/span&gt;,host)&lt;br /&gt;{&lt;br /&gt;return "PROXY www.yahoo.co.jp:80";&lt;br /&gt;}&lt;/blockquote&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;By setting in Internet Explorer 6.&lt;/span&gt;&lt;br /&gt;sorry for Japanese version of IE.&lt;br /&gt;The setting file is located in local disk for convenience.&lt;br /&gt;(but no matter for putting in wpad.consolto.co.us.)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_UTNqB6ppCWU/R3VngZ5fEmI/AAAAAAAAAGE/CQ8xQflNRf0/s1600-h/pac-setting.ie.jpeg"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_UTNqB6ppCWU/R3VngZ5fEmI/AAAAAAAAAGE/CQ8xQflNRf0/s320/pac-setting.ie.jpeg" alt="" id="BLOGGER_PHOTO_ID_5149135555373503074" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;And then browse "http://www.microsoft.com/".&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;but shown "http://www.yahoo.co.jp/".&lt;br /&gt;(Look at the URL of browser.)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_UTNqB6ppCWU/R3Vngp5fEnI/AAAAAAAAAGM/fIcusD_zHrk/s1600-h/ms-yahoo.ie.jpeg"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_UTNqB6ppCWU/R3Vngp5fEnI/AAAAAAAAAGM/fIcusD_zHrk/s320/ms-yahoo.ie.jpeg" alt="" id="BLOGGER_PHOTO_ID_5149135559668470386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;br /&gt;Next how about FireFox2.&lt;/span&gt;&lt;br /&gt;sorry for Japanese version of FireFox.&lt;br /&gt;The setting file is located in local disk for convenience.&lt;br /&gt;(but no matter for putting in wpad.consolto.co.us.)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_UTNqB6ppCWU/R3VnhJ5fEpI/AAAAAAAAAGc/6lni8hDtybM/s1600-h/pac-setting.ff.jpeg"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/R3VnhJ5fEpI/AAAAAAAAAGc/6lni8hDtybM/s320/pac-setting.ff.jpeg" alt="" id="BLOGGER_PHOTO_ID_5149135568258405010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;And then browse "http://www.microsoft.com/".&lt;/span&gt;&lt;br /&gt;Again but shown "http://www.yahoo.co.jp/".&lt;br /&gt;(Look at the URL of browser.)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/R3Vng55fEoI/AAAAAAAAAGU/F0swE3_PU-M/s1600-h/ms-yahoo.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/R3Vng55fEoI/AAAAAAAAAGU/F0swE3_PU-M/s320/ms-yahoo.JPG" alt="" id="BLOGGER_PHOTO_ID_5149135563963437698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;This is "by design" of proxy.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;pac&lt;/span&gt;. And hijacking of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;wpad&lt;/span&gt;(or proxy.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_20"&gt;pac&lt;/span&gt;) &lt;span style="color: rgb(255, 0, 0);"&gt;can open arbitrary  malicious pages&lt;span style="color: rgb(0, 0, 0);"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Not only man-in-the-middle attack.&lt;/span&gt;&lt;br /&gt;take care your self! :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-1456307970748965054?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/1456307970748965054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=1456307970748965054' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1456307970748965054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1456307970748965054'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/12/security-microsoft-security-advisory.html' title='[security] Microsoft Security Advisory (945713) can open arbitrary pages.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_UTNqB6ppCWU/R3VngZ5fEmI/AAAAAAAAAGE/CQ8xQflNRf0/s72-c/pac-setting.ie.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-8199853277680475383</id><published>2007-12-25T12:09:00.000-08:00</published><updated>2007-12-25T16:28:57.104-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Cross site scripting in year 2007.(Blog by Hasegawa Yosuke)</title><content type='html'>Hasegawa yosuke wrote about Cross site scripting in Year 2007.&lt;br /&gt;ripjyr translate this post to English.&lt;br /&gt;Original post is &lt;a href="http://d.hatena.ne.jp/hasegawayosuke/20071226/p1"&gt;http://d.hatena.ne.jp/hasegawayosuke/20071226/p1&lt;/a&gt; (Japanese)&lt;br /&gt;-----&lt;br /&gt;I wrote about XSS(Cross site scripting) I found in year 2007.&lt;br /&gt;someone wrote "hasegawa cut to write Blog :-)" someplace.&lt;br /&gt;I didn't cut to write blog ,but noting to write.....&lt;br /&gt;so I force look back XSS in year 2007 :-)&lt;br /&gt;&lt;br /&gt;below are XSS found on a famous site I found.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li style="FONT-WEIGHT: bold"&gt;&lt;span style="font-size:130%;"&gt;XSS in &lt;/span&gt;&lt;a href="http://www.aist.go.jp/index_en.html"&gt;&lt;span style="font-size:130%;"&gt;National Institute of Advanced Industrial Science and Technology (AIST)&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;UTF-7 XSS was enabled because charset was not set in 404 response page.&lt;br /&gt;Session Cookie can stolen if already logined&lt;br /&gt;Reported:2007/04/16&lt;br /&gt;Fixed:2007/05/16&lt;/li&gt;&lt;/ul&gt;&lt;li style="FONT-WEIGHT: bold"&gt;&lt;span style="font-size:130%;"&gt;XSS in &lt;/span&gt;&lt;a href="http://sourceforge.jp/"&gt;&lt;span style="font-size:130%;"&gt;sourceforge.jp&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;UTF-7 XSS was enabled because charset was not set in 404 response page.&lt;br /&gt;Session Cookie can stolen if already logined&lt;br /&gt;Reported:2007/04/16&lt;br /&gt;Fixed:2007/05/16&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;XSS in &lt;/span&gt;&lt;/strong&gt;&lt;a href="http://www.ibm.com/search/help/"&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;IBM search page&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;.&lt;/span&gt;&lt;/strong&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;UTF-7 XSS was enabled because HTML character encoding as MS932 can use if specify like "&amp;amp;cs=MS932" in the query on IBM search page.&lt;br /&gt;Reported:2007/04/19&lt;br /&gt;Fixed:2007/08/30&lt;/li&gt;&lt;/ul&gt;&lt;li style="FONT-WEIGHT: bold"&gt;&lt;span style="font-size:130%;"&gt;XSS in &lt;/span&gt;&lt;a href="http://www.mizuhobank.co.jp/english/"&gt;&lt;span style="font-size:130%;"&gt;MizuhoBank&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;UTF-7 XSS was enabled because HTML character encoding as jis can use if specify like "&amp;amp;oe=jis" in the query on MizuhoBank search page.&lt;br /&gt;Reported:2007/04/26&lt;br /&gt;Fixed:2007/12/25&lt;/li&gt;&lt;/ul&gt;&lt;li style="FONT-WEIGHT: bold"&gt;&lt;span style="font-size:130%;"&gt;XSS in&lt;/span&gt;&lt;a href="http://www.f5networks.co.jp/"&gt;&lt;span style="font-size:130%;"&gt; F5 Networks&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:130%;"&gt; search page&lt;/span&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;XSS was enabled Search page in F5 Networks.&lt;br /&gt;Query like below.&lt;br /&gt;http://www.f5networks.co.jp/cgi-bin/search/search.pl?query=abcd%22onload=%22alert(document.location)%22%20&lt;br /&gt;Reported:2007/07/31&lt;br /&gt;Fixed:2007/10/29&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;XSS in &lt;/span&gt;&lt;/strong&gt;&lt;a href="http://www.oracle.co.jp/"&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Oracle &lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;search page&lt;/span&gt;&lt;/strong&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;"%22" was not escaped so XSS was enabled in search page at oracle.co.jp.&lt;br /&gt;Reported:2007/08/28&lt;br /&gt;Fixed:2007/09/21&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;XSS in &lt;/span&gt;&lt;/strong&gt;&lt;a href="http://www.meti.go.jp/english/index.html"&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;METI Ministry of Economy, Trade and Industry&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;UTF-7 XSS was enabled because charset was not set in www.meti.go.jp pages.&lt;br /&gt;Reported:2007/10/10&lt;br /&gt;Fixed:2007/12/05&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;XSS in &lt;/strong&gt;&lt;/span&gt;&lt;a href="http://miau.jp/"&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;MIAU(Movements for Internet Active Users)&lt;/strong&gt;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;XSS was enabled at Subscription in MIAU Mail magazines page, Query like below.&lt;br /&gt;http://miau.jp/miaumailmagsubmit.phtml?miaumgreg=test%40example.com%22%20style=%22xss%3aexpression(alert(1))&amp;amp;userevent=mag-reg&lt;br /&gt;Reported:2007/10/24&lt;br /&gt;Fixed:2007/10/31&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;Shown fake information considerable threat by XSS was already &lt;span style="font-size:130%;"&gt;&lt;span style="FONT-WEIGHT: bold; COLOR: rgb(255,0,0)"&gt;easily found&lt;/span&gt;&lt;/span&gt; in co.jp(like .com) or go.jp(like .gov).&lt;br /&gt;So take care of yourself(who take cares and what cares :-)&lt;br /&gt;&lt;br /&gt;Especially XSS in Image file , I contact &lt;a href="http://www.ipa.go.jp/index-e.html"&gt;IPA(INFORMATION-TECHNOLOGY PROMOTION AGENCY, JAPAN) &lt;/a&gt;and &lt;a href="http://www.microsoft.com/"&gt;Microsoft&lt;/a&gt; contacts I knew for three years...&lt;br /&gt;Though a considerable communication was done but every time finally said "by specification"....;-&amp;lt;&lt;br /&gt;I wish to be fixed XSSed(not still fixed) pages here and there in 2008 :-)&lt;br /&gt;&lt;span style="FONT-WEIGHT: bold"&gt;Then, everybody have a good holidays.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-8199853277680475383?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/8199853277680475383/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=8199853277680475383' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/8199853277680475383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/8199853277680475383'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/12/cross-site-scripting-in-year.html' title='Cross site scripting in year 2007.(Blog by Hasegawa Yosuke)'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-457237900561525950</id><published>2007-09-25T18:01:00.000-07:00</published><updated>2007-09-25T18:11:10.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[SECURITY]Hospital biohazard! (Computer) virus spread in hospital.</title><content type='html'>FUJAX virus kills hospital of Chiba national university network. (http://www.ho.chiba-u.ac.jp/)&lt;br /&gt;http://mytown.asahi.com/chiba/news.php?k_id=12000000709130001&lt;br /&gt;Asahi newspaper said that Sep 5 virus spread into network.&lt;br /&gt;And then confusion occurs in hospital.&lt;br /&gt;Can't see last examination record.&lt;br /&gt;Can't account the examination.&lt;br /&gt;&lt;br /&gt;Hospital of Chiba University decides shutdown Web browsing and E-mail.&lt;br /&gt;And so on still shutting down web browsing and E-mail until today (September 26).&lt;br /&gt;Virus was Newly discovered virus and not detected by anti-virus software.&lt;br /&gt;&lt;br /&gt;Discovered virus was newly appeared in china in February.&lt;br /&gt;Perhaps, it is thought as newly appeared type of FUJAX.&lt;br /&gt;Infected route was web browsing.&lt;br /&gt;Hospital staff searching Internet for chart of human body, they infected at site in china.&lt;br /&gt;&lt;br /&gt;Hospital will recover network on end of September. But not recover yet (September 26).&lt;br /&gt;Is this incident one of bio? (Non-bio?) Hazard??? YES!!!&lt;br /&gt;Computer virus spread in hospital and shut hospital system down…&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-457237900561525950?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/457237900561525950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=457237900561525950' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/457237900561525950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/457237900561525950'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/09/securityhospital-biohazard-computer.html' title='[SECURITY]Hospital biohazard! (Computer) virus spread in hospital.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-1637006239272324518</id><published>2007-09-16T14:26:00.000-07:00</published><updated>2007-09-17T14:30:31.886-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>Finally F-Secure Blog to be Weblog2.0 :-p</title><content type='html'>&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;F-Secure Blog to be Weblog2.0!!! they are changing!!!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here is F-Secure Weblog2.0&lt;br /&gt;-&gt; &lt;a href="http://www.f-secure.com/weblog/archives/00001276.html"&gt;http://www.f-secure.com/weblog/archives/00001276.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and this is &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;still&lt;/span&gt; Weblog1.0&lt;br /&gt;-&gt; &lt;a href="http://www.f-secure.com/weblog/archives/archive-092007.html#00001276"&gt;http://www.f-secure.com/weblog/archives/archive-092007.html#00001276&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;What is &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_1"&gt;deference&lt;/span&gt; between Weblog2.0 and Weblog1.0???&lt;br /&gt;Only Permanent link ware made?&lt;br /&gt;&lt;br /&gt;&lt;span class="rss:item"&gt;&lt;blockquote&gt;We'll update the indexes next week. In the meantime, please provide your feedback.&lt;br /&gt;&lt;/blockquote&gt;I thought only two things about F-Secure Weblog2.0.&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span class="rss:item"&gt;Please set indivisual Page title to posted title.&lt;br /&gt;this became weblog or bookmark seen very easily.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Please set category or label of posts.&lt;br /&gt;this became post seen clearly.&lt;/li&gt;&lt;/ol&gt;please Hold out, We will expecting you!&lt;br /&gt;&lt;br /&gt;(18 Sep 2007 update post)&lt;br /&gt;&lt;span style="font-size:130%;"&gt;F-Secure recieve my feedbacks!!! &lt;/span&gt;&lt;br /&gt;1 - We will be adjusting the individual Page Titles soon.&lt;br /&gt;2 - We'll investigate the option.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-1637006239272324518?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/1637006239272324518/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=1637006239272324518' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1637006239272324518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1637006239272324518'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/09/finally-f-secure-blog-to-be-weblog20-p.html' title='Finally F-Secure Blog to be Weblog2.0 :-p'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-3275910747476586716</id><published>2007-07-23T01:45:00.000-07:00</published><updated>2008-12-10T11:13:12.784-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>I went to eat the French cuisine after a long time.</title><content type='html'>Ordovl&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RqUdrdYtj6I/AAAAAAAAAFI/Dyqn0bZm9gs/s1600-h/20070722123703.jpg"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RqUdrdYtj6I/AAAAAAAAAFI/Dyqn0bZm9gs/s320/20070722123703.jpg" alt="" id="BLOGGER_PHOTO_ID_5090507586272071586" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Potage of season&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RqUdrdYtj7I/AAAAAAAAAFQ/B3-wUuGpDnk/s1600-h/20070722124947.jpg"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RqUdrdYtj7I/AAAAAAAAAFQ/B3-wUuGpDnk/s320/20070722124947.jpg" alt="" id="BLOGGER_PHOTO_ID_5090507586272071602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;meat cookery&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_UTNqB6ppCWU/RqUdrtYtj8I/AAAAAAAAAFY/NEomh8Fuq6M/s1600-h/20070722130555.jpg"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/RqUdrtYtj8I/AAAAAAAAAFY/NEomh8Fuq6M/s320/20070722130555.jpg" alt="" id="BLOGGER_PHOTO_ID_5090507590567038914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;dessert&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_UTNqB6ppCWU/RqUdr9Ytj9I/AAAAAAAAAFg/77znyU1wZjw/s1600-h/20070722133410.jpg"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_UTNqB6ppCWU/RqUdr9Ytj9I/AAAAAAAAAFg/77znyU1wZjw/s320/20070722133410.jpg" alt="" id="BLOGGER_PHOTO_ID_5090507594862006226" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-3275910747476586716?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/3275910747476586716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=3275910747476586716' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/3275910747476586716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/3275910747476586716'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/07/i-went-to-eat-french-cuisine-after-long.html' title='I went to eat the French cuisine after a long time.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_UTNqB6ppCWU/RqUdrdYtj6I/AAAAAAAAAFI/Dyqn0bZm9gs/s72-c/20070722123703.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-8712621393540499888</id><published>2007-07-22T21:31:00.000-07:00</published><updated>2007-07-23T14:19:54.331-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Security] Is it now the time to talk about UTF-7? by yosuke.hasegawa in webappsec.jp</title><content type='html'>This story is wrtten by &lt;a href="http://d.hatena.ne.jp/hasegawayosuke/20070717/p1"&gt;hasegawa.yosuke in webappsec.jp&lt;/a&gt;(Japanese only blog).&lt;br /&gt;&lt;br /&gt;It is thought that XSS using UTF-7 is occurs when charset is not specified. However, this is a biggest mistake in Internet Explorer.&lt;br /&gt;Accurately, XSS occurs when not specified charset,Internet Explorer can recognized charset. Even if charset has been added, XSS is occurs when a character encoding name cannot be recognized by Internet Explorer.&lt;br /&gt;&lt;br /&gt;For example,IE cannot correctly recognize the character encoding name to following HTML. Therefore, it is interpreted from the content of HTML as UTF-7 and the script runs. The string "utf8" in charset is not correct charset(hyphen comes off) but used commonly as "UTF-8".&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;head&amp;gt;&lt;br /&gt;&amp;lt;meta http-equiv="Content-Type"&lt;br /&gt;content="text/html;&lt;br /&gt;&lt;font color=red&gt;charset=utf8&lt;/font&gt;"&amp;gt;&lt;br /&gt;&amp;lt;/head&amp;gt;&lt;br /&gt;&amp;lt;body&amp;gt;&lt;br /&gt;+ADw-script+AD4-alert(document.location)+ADsAPA-/script+AD4-&lt;br /&gt;&amp;lt;/body&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;The list of the character encoding name to be able to distinguish IE correctly is being defined in registry at "HKCR\MIME\Database\charset".The attecker could occur XSS by combining with &lt;a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1114"&gt;CVE-2007-1114&lt;/a&gt; if Web Application send these character encoding name.&lt;br /&gt;&lt;p&gt;In the character encoding names tend to be,at the Web application in Japan,other than "utf8" example above, and the character encoding name to which IE cannot be recognized is as follows. &lt;/p&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;B&gt;jis&lt;/B&gt;&lt;br /&gt;  Expression of ISO-2022-JP used commonly&lt;br /&gt;&lt;B&gt;MS932 / CP932 /&lt;br /&gt;CP942C&lt;/B&gt;&lt;br /&gt;  Similar encoding of Shift_JIS in&lt;br /&gt;Java&lt;br /&gt;&lt;B&gt;Windows-31J&lt;/B&gt;&lt;br /&gt;  IANA formal registration name of code page&lt;br /&gt;932 used with Windows. &lt;/blockquote&gt;&lt;br /&gt;&lt;p&gt;I think this cannot be recognized IE is bad no matter how&lt;br /&gt;it thinks.&lt;br /&gt;Sometimes it seen the character encoding is not only hard-coded on the Web application but the character encoding can be specified from the outside according to the parameter like below.&lt;/p&gt;&lt;blockquote&gt;http://example.com/?q=abcd&amp;amp;&lt;FONT COLOR=RED&gt;charset=euc-jp&lt;/FONT&gt;&lt;/blockquote&gt;&lt;p&gt;It is like converting it's character encoding  according to the parameter not only is interpreted according to the specified character encoding but also the output is parameter character encoding specified.When the character encoding name such as CP932 ,above-mentioned , is allowed,  XSS will be occured in such kind of Web application.&lt;/p&gt;&lt;blockquote&gt;http://example.com/?q=%2BADw-script%2BAD4-alert%28document.location%29ADsAPA-/script%2BAD4-&amp;amp;&lt;font color=red&gt;charset=CP932&lt;/FONT&gt;&lt;/blockquote&gt;&lt;p&gt;Use character encoding name without the problem such as "Shift_jis" or "UTF-8" in error pages or all pages, let's bear it in mind. &lt;/p&gt;&lt;p&gt;&lt;B&gt;Good News.&lt;/B&gt;&lt;/p&gt;&lt;p&gt;When I(hasegawa) have submitted Microsoft as a demand of the improvement of the specification of Internet Explorer (*1), the answer was wanting i(hasegawa) to report as a vulnerability report again. Then, when reported again as a c, I got the following answers (excerpt summary). &lt;/p&gt;&lt;blockquote&gt;This phenomenon is same as the content that is already public, and our&lt;br /&gt;company(Microsoft) judges it is vulnerability of Internet Explorer. Our company&lt;br /&gt;recognizes that the modify of this phenomenon is necessary, and is examining the&lt;br /&gt;modification now. &lt;/blockquote&gt;&lt;p&gt;The future, IE will be corrected to the direction to decrease.where the situation of XSS generation like the above-mentioned. It was indeed unexpected.because i(hasegawa) had not been thought that Microsoft judged such behavior of IE as a vulnerability. &lt;/p&gt;&lt;p&gt;*1:I(hasegawa) was thought that it did not apply to the definition of "Security vulnerability" that Microsoft meant, and assumed the demand of the specification improvement. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-8712621393540499888?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/8712621393540499888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=8712621393540499888' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/8712621393540499888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/8712621393540499888'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/07/security-is-it-now-time-to-talk-about.html' title='[Security] Is it now the time to talk about UTF-7? by yosuke.hasegawa in webappsec.jp'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-1859211398543278122</id><published>2007-04-19T09:29:00.000-07:00</published><updated>2007-04-19T17:30:49.958-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Security] APOP for POP3 Mail receives protocol is now vulnerabile.</title><content type='html'>&lt;span lang="EN-US"&gt;&lt;a href="http://www.jpcert.or.jp/english/about/"&gt;JPCERT/CC&lt;/a&gt; and &lt;a href="http://www.ipa.go.jp/english/about/index.html"&gt;IPA(&lt;?xml:namespace prefix = st1 /&gt;&lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;INFORMATION-TECHNOLOGY PROMOTION AGENCY&lt;/st1:city&gt;, &lt;st1:country-region st="on"&gt;JAPAN&lt;/st1:country-region&gt;&lt;/st1:place&gt;)&lt;/a&gt; reports APOP encrypted password decrypted vulnerability.&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;APOP is a protocol for authentication for POP3.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;APOP uses md5 hash to check password.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;hash protocol MD5 has collision for his hash.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;If APOP hash tapped and stolen hashes, a malicious person might decipher it.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;This problem causes from MD5 collision not only APOP.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;but also If system uses MD5 same problem occurs.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;------&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;http://d.hatena.ne.jp/shikap/20070419#p1)shikap said that&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Almost everyone is uses POP, and APOP are only encrypting only password.&lt;br /&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;But receiving mail is still plaintext in POP protcol.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;On this occasion, you might be shift to "POP over SSL".&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;Link&lt;br /&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/md5.pdf"&gt;Practical Password Recovery on an MD5 Challenge-Response such as APOP (pdf) (&lt;/a&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/md5.pdf"&gt;FSE2007&lt;/a&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/md5.pdf"&gt;)&lt;br /&gt;&lt;/a&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/apop.pdf"&gt;Extended APOP Password Recovery Attack (pdf) &lt;span style="font-size:+0;"&gt;&lt;/span&gt;(&lt;/a&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/apop.pdf"&gt;FSE2007&lt;/a&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/apop.pdf"&gt;)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://fse2007.uni.lu/slides/rump/apop.pdf"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-1859211398543278122?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/1859211398543278122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=1859211398543278122' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1859211398543278122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1859211398543278122'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/04/security-apop-for-pop3-mail-receives.html' title='[Security] APOP for POP3 Mail receives protocol is now vulnerabile.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-5516581283007319757</id><published>2007-04-10T08:07:00.000-07:00</published><updated>2007-04-10T08:28:15.185-07:00</updated><title type='text'>Ichitaro Zero-Day Exploit and Targeted Attack was Available.</title><content type='html'>Japanese famous word processing software Ichitaro’s Zero-Day Targeted Attack is now in wild.&lt;span lang="EN-US"&gt;&lt;br /&gt;10 Apr Justsystems has released Ichitaropatch of Zero-Day Vulnerabilities&lt;/span&gt;&lt;span lang="EN-US"&gt;.&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.ichitaro.com/history/img/pac5.jpg"&gt;&lt;img style="cursor: pointer; width: 72px; height: 91px;" src="http://www.ichitaro.com/history/img/pac5.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;&lt;a href="http://secunia.com/advisories/24780/"&gt; JustSystems Ichitaro Document Processing Unspecified Code Execution - Advisories - Secunia&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span lang="EN-US"&gt;&lt;a href="http://www.avertlabs.com/research/blog/?p=251"&gt; Exploit-TaroDrop.b   Heuristics vs 0-day Gymnastics（Computer Security Research - McAfee Avert Labs Blog）&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span lang="EN-US"&gt;&lt;span style="color: rgb(51, 51, 255);font-size:130%;" &gt;&lt;span style="font-weight: bold;"&gt;What is Ichitaro?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;In Japan Ichitaro is most famous word processing software from 1985 to 1995.&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;18 million Ichitaro was shipped. (&lt;a href="http://www.justsystems.com/products/consumer.html"&gt;from Justsystems Page&lt;/a&gt;)&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;In 1990’s Ichitaro was famous software according to called as word processor.&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;A lot of government office uses Ichitaro in there office.&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;br /&gt;Recently, Ichitaro is replacing Microsoft Word. But Ichitaro is still using in government.&lt;br /&gt;And there official documents.&lt;/span&gt;&lt;span lang="EN-US"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span lang="EN-US"&gt;&lt;span style="font-weight: bold; color: rgb(51, 51, 255);"&gt;Why Zero-Day Targeted Attack.&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;According to most famous word processor in government in Japan Ichitaro is a target of Targeted attack.&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;And more Ichitaro does not have automatic update for them.&lt;br /&gt;You should download security patch and fix it one by one.&lt;br /&gt;If patch has released but most all of Ichitaro does not patched for long time.&lt;br /&gt;Like Blaster worm in Aug 2003 and Microsoft.&lt;br /&gt;After Blaster worm Microsoft has released automatic update (Windows Update).&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 102, 0);font-size:130%;" &gt;I think Justsytem &lt;span style="font-weight: bold;font-size:180%;" &gt;must have be release automatic update&lt;/span&gt; to there software.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;  &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span lang="EN-US"&gt;A similar weakness of Ichitaro and targeted attack was in wild at Aug 2006.&lt;br /&gt;This is second time to Justsystem.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-5516581283007319757?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/5516581283007319757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=5516581283007319757' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/5516581283007319757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/5516581283007319757'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/04/ichitaro-zero-day-exploit-and-targeted.html' title='Ichitaro Zero-Day Exploit and Targeted Attack was Available.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-685756152163259501</id><published>2007-04-08T20:22:00.000-07:00</published><updated>2008-12-10T11:13:14.492-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Cherry 100% blossomed in Kyoto!</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;Cherrey blossoms in Kyoto!!!&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;A lot of travelers in kyoto. for seeing cherry blossom.&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhmzryZvyVI/AAAAAAAAAEA/SFEupxUSj_A/s1600-h/CA330017.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051266021918230866" style="CURSOR: hand" alt="" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhmzryZvyVI/AAAAAAAAAEA/SFEupxUSj_A/s320/CA330017.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;&lt;a href="http://maps.google.com/maps?f=q&amp;hl=ja&amp;amp;amp;amp;amp;z=19&amp;ll=34.973421,135.734244&amp;amp;spn=0.001059,0.001808&amp;t=h&amp;amp;om=1"&gt;Kissho-in Tenman-gu&lt;/a&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhmzryZvyWI/AAAAAAAAAEI/TXtBC2CQ2FM/s1600-h/CA330021.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051266021918230882" style="CURSOR: hand" alt="" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhmzryZvyWI/AAAAAAAAAEI/TXtBC2CQ2FM/s320/CA330021.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_UTNqB6ppCWU/Rhm2myZvyaI/AAAAAAAAAEo/fKTJtg_9iyU/s1600-h/DSCF0025.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051269234553768354" style="CURSOR: hand" alt="" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/Rhm2myZvyaI/AAAAAAAAAEo/fKTJtg_9iyU/s320/DSCF0025.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_UTNqB6ppCWU/Rhm2nCZvybI/AAAAAAAAAEw/G4ZXdPS-ZVw/s1600-h/CA330019.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051269238848735666" style="CURSOR: hand" alt="" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/Rhm2nCZvybI/AAAAAAAAAEw/G4ZXdPS-ZVw/s320/CA330019.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_UTNqB6ppCWU/Rhm2nSZvydI/AAAAAAAAAFA/MqvkDjp3HZA/s1600-h/CA330016.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051269243143702994" style="CURSOR: hand" alt="" src="http://4.bp.blogspot.com/_UTNqB6ppCWU/Rhm2nSZvydI/AAAAAAAAAFA/MqvkDjp3HZA/s320/CA330016.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://maps.google.com/maps?f=q&amp;hl=ja&amp;amp;amp;amp;amp;t=h&amp;om=1&amp;amp;ie=UTF8&amp;z=19&amp;amp;ll=34.976687,135.767128&amp;amp;spn=0.001059,0.001808"&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Near Kamo-River&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhmzsCZvyXI/AAAAAAAAAEQ/e4NmHVwDEdw/s1600-h/DSCF0074.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051266026213198194" style="CURSOR: hand" alt="" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhmzsCZvyXI/AAAAAAAAAEQ/e4NmHVwDEdw/s320/DSCF0074.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_UTNqB6ppCWU/Rhm2nCZvycI/AAAAAAAAAE4/rmRNgqOkCRQ/s1600-h/CA330026.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5051269238848735682" style="CURSOR: hand" alt="" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/Rhm2nCZvycI/AAAAAAAAAE4/rmRNgqOkCRQ/s320/CA330026.JPG" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-685756152163259501?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/685756152163259501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=685756152163259501' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/685756152163259501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/685756152163259501'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/04/cheree-blossoms-in-kyoto-kissho-in.html' title='Cherry 100% blossomed in Kyoto!'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_UTNqB6ppCWU/RhmzryZvyVI/AAAAAAAAAEA/SFEupxUSj_A/s72-c/CA330017.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-745427122577827710</id><published>2007-04-07T15:29:00.000-07:00</published><updated>2008-12-10T11:13:14.830-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Cherry blossomed but yesterday was rainy day.</title><content type='html'>&lt;strong&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Oh...rainy day...cherry flower falls.&lt;/span&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_UTNqB6ppCWU/RhgbpiZvyQI/AAAAAAAAADY/B-cv_pQJhCo/s1600-h/0704050006.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5050817382519392514" style="CURSOR: hand" alt="" src="http://4.bp.blogspot.com/_UTNqB6ppCWU/RhgbpiZvyQI/AAAAAAAAADY/B-cv_pQJhCo/s320/0704050006.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;This photo was taken 05 April.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-745427122577827710?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/745427122577827710/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=745427122577827710' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/745427122577827710'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/745427122577827710'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/04/cherry-blossomed-but-yesterday-was.html' title='Cherry blossomed but yesterday was rainy day.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_UTNqB6ppCWU/RhgbpiZvyQI/AAAAAAAAADY/B-cv_pQJhCo/s72-c/0704050006.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-3598800330049105904</id><published>2007-04-04T17:30:00.000-07:00</published><updated>2007-04-04T19:55:54.956-07:00</updated><title type='text'>Windows 2003 Server Service Pack2 Japanese Edition probrem on using icacls.exe.</title><content type='html'>On post in hotfix.jp, &lt;strong&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;Windows 2003 Server SP2 Japanese Edition  has little problem&lt;/span&gt;&lt;/strong&gt;...&lt;br /&gt;&lt;a href="http://bbs.hotfix.jp/ShowPost.aspx?PostID=6624"&gt;http://bbs.hotfix.jp/ShowPost.aspx?PostID=6624&lt;/a&gt; (Japanese Only)&lt;br /&gt;&lt;br /&gt;Uchikoshi as Hotfix.jp Staff said that&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;p&gt;"icacls.exe" can't run in Windows 2003 Server SP2 Japanese edition.&lt;br /&gt;(Both Windows Server 2003 Standard Edition+SP2 and Windows Server 2003 Enterprise Edition＋SP2)&lt;br /&gt;Running icacls.exe ,some unknown word output on cmd.exe.&lt;br /&gt;But nothing happen...&lt;br /&gt;---&lt;br /&gt;C:\&gt;icacls.exe&lt;br /&gt;ICACLS &lt;&lt;br /&gt;C:\&gt;&lt;br /&gt;---&lt;/p&gt;&lt;p&gt;Windows 2003 Server SP2 English Edition of icacls.exe done well.&lt;br /&gt;Running English “icacls.exe” on Windows 2003 Server SP2 Japanese Edition done&lt;br /&gt;well.&lt;br /&gt;(Of course help messages or display messages are English)&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;gentoo post below&lt;br /&gt;&lt;blockquote&gt;&lt;p&gt;Add “_tsetlocale( LC_ALL, _T( ".OCP" ) ); “ to Japanese “icacls.exe” binary&lt;br /&gt;code will shown pretty good.&lt;br /&gt;Thus maybe “icacls.exe” file forgotten LOCALE setting…&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;p&gt;&lt;strong&gt;&lt;span style="font-size:130%;color:#ff0000;"&gt;Maybe Windows 2003 Server 2003 SP2 Japanese Edition will Re release again...&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;I also post at here&lt;br /&gt;&lt;a href="http://www.dozleng.com/updates/index.php?showtopic=13856"&gt;http://www.dozleng.com/updates/index.php?showtopic=13856&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-3598800330049105904?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/3598800330049105904/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=3598800330049105904' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/3598800330049105904'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/3598800330049105904'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/04/windows-2003-server-service-pack2.html' title='Windows 2003 Server Service Pack2 Japanese Edition probrem on using icacls.exe.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-2265695343314139973</id><published>2007-04-01T14:38:00.000-07:00</published><updated>2008-12-10T11:13:16.509-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Cherry Blossomed!!! at kyoto Japan,</title><content type='html'>Cherry Blossomed!!!   a little...&lt;br /&gt;&lt;br /&gt;20% - 50% of flower has blossomed.&lt;br /&gt;these are picture of cherry.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl7I/AAAAAAAAACw/RkGzjk-zRE8/s1600-h/CA330010.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl7I/AAAAAAAAACw/RkGzjk-zRE8/s320/CA330010.JPG" alt="" id="BLOGGER_PHOTO_ID_5048579886540429234" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhAop4Vsl5I/AAAAAAAAACg/M3yGYflaFFE/s1600-h/CA330008.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhAop4Vsl5I/AAAAAAAAACg/M3yGYflaFFE/s320/CA330008.JPG" alt="" id="BLOGGER_PHOTO_ID_5048579882245461906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl8I/AAAAAAAAAC4/K8YJjeFFe9Q/s1600-h/CA330011.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl8I/AAAAAAAAAC4/K8YJjeFFe9Q/s320/CA330011.JPG" alt="" id="BLOGGER_PHOTO_ID_5048579886540429250" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhAow4Vsl9I/AAAAAAAAADA/qOyQ98luDoU/s1600-h/CA330012.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhAow4Vsl9I/AAAAAAAAADA/qOyQ98luDoU/s320/CA330012.JPG" alt="" id="BLOGGER_PHOTO_ID_5048580002504546258" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhAop4Vsl4I/AAAAAAAAACY/CDOKxn-us24/s1600-h/CA330007.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RhAop4Vsl4I/AAAAAAAAACY/CDOKxn-us24/s320/CA330007.JPG" alt="" id="BLOGGER_PHOTO_ID_5048579882245461890" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl6I/AAAAAAAAACo/Ip31BpDovkw/s1600-h/CA330009.JPG"&gt;&lt;img style="cursor: pointer;" src="http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl6I/AAAAAAAAACo/Ip31BpDovkw/s320/CA330009.JPG" alt="" id="BLOGGER_PHOTO_ID_5048579886540429218" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-2265695343314139973?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/2265695343314139973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=2265695343314139973' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/2265695343314139973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/2265695343314139973'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/04/cherry-blossomed-at-kyoto-japan.html' title='Cherry Blossomed!!! at kyoto Japan,'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_UTNqB6ppCWU/RhAoqIVsl7I/AAAAAAAAACw/RkGzjk-zRE8/s72-c/CA330010.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-3996613941586831615</id><published>2007-03-30T14:27:00.000-07:00</published><updated>2007-03-30T14:47:25.134-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>You can't filter .ANI by URLs. Microsoft Animated Cursor vulnerability.</title><content type='html'>There are &lt;a href="http://www.microsoft.com/technet/security/advisory/935423.mspx"&gt;Windows Animated Cursor exploit&lt;/a&gt;(Microsoft Security Advisory 935423) is now wild.&lt;br /&gt;In some japanese security proffessionals has some hypothesis...&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://bakera.jp/hatomaru.aspx/ebi/topic/2833"&gt;http://bakera.jp/hatomaru.aspx/ebi/topic/2833&lt;/a&gt;  (Japanese Only)&lt;/li&gt;&lt;li&gt;&lt;a href="http://d.hatena.ne.jp/hasegawayosuke/20070330/p2"&gt;http://d.hatena.ne.jp/hasegawayosuke/20070330/p2&lt;/a&gt;  (Japanese Only)&lt;/li&gt;&lt;/ul&gt;Exploit with CSS(Cascading Style Sheets)  Animated Cursor properties.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;************************************************&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;THIS IS NOT PROOFED VERIFICATED. BUT POSSIBILITY IDEA.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;************************************************&lt;/span&gt;&lt;br /&gt;In "cursor properties" in CSS can use .ani file from anywhare .&lt;br /&gt;Like this&lt;br /&gt;&lt;blockquote&gt;&amp;lt;body style="cursor: url('http://example.com/cursor.ani')"&amp;gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Internet Explorer shows contents &lt;span style="color: rgb(255, 0, 0);"&gt;NOT filename extention but file's contents&lt;/span&gt;.&lt;br /&gt;Microsoft said "This is by design of Internet Explorer".&lt;br /&gt;&lt;br /&gt;If .ANI file with &lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;faked &lt;a href="http://en.wikipedia.org/wiki/Filename_extension"&gt;filename&lt;/a&gt;&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Filename_extension"&gt; extention&lt;/a&gt; URL, but IE shows .ani contents.&lt;br /&gt;&lt;blockquote&gt;cursor: url(http://example.com/virus.txt);&lt;/blockquote&gt;&lt;br /&gt;In this case &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;URL is virus.txt&lt;/span&gt; not xxx.ani or xxx.cur, so &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;you can't filter by URL&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;So only &lt;/span&gt;&lt;a style="font-weight: bold;" href="http://isc.sans.org/diary.html?storyid=2540"&gt;SANS detection rule &lt;/a&gt;&lt;span style="font-weight: bold;"&gt;can detect this exploit.&lt;br /&gt;Use this to detect Animated Cursor's Exploit....&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;alert tcp $EXTERNAL_NET $HTTP_PORTS -&gt; $HOME_NET any (&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;msg&lt;/span&gt;&lt;/span&gt;:”BLEEDING-EDGE CURRENT EVENTS MS &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;ANI&lt;/span&gt;&lt;/span&gt; exploit”; flow:established,from_server; content:”|54 53 49 4C 03 00 00 00 00 00 00 00 54 53 49 4C 04 00 00 00 02 02 02 02 61 6E 69 68 52|”; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;classtype&lt;/span&gt;&lt;/span&gt;:attempted-admin; reference:url,http://isc.sans.org/diary.html?storyid=2534; reference:url,http://www.avertlabs.com/research/blog/?p=233; reference:url,doc.bleedingthreats.net/2003519; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;sid&lt;/span&gt;&lt;/span&gt;:2003519; rev:1;)&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-3996613941586831615?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/3996613941586831615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=3996613941586831615' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/3996613941586831615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/3996613941586831615'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/03/you-cant-filter-ani-by-urls-microsoft.html' title='You can&apos;t filter .ANI by URLs. Microsoft Animated Cursor vulnerability.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-460022439460149531</id><published>2007-03-29T18:28:00.000-07:00</published><updated>2008-12-10T11:13:16.693-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Cherry blossomed a little....</title><content type='html'>Tokyo cherry blossomed.but kyoto is not.&lt;br /&gt;it blossomed next weekend.&lt;br /&gt;&lt;br /&gt;it like cherry blossoms on &lt;a href="http://photos.si.edu/cherry/cherry.html"&gt;Potomac river in washingon DC.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_UTNqB6ppCWU/Rgxn34VslyI/AAAAAAAAABo/He6MkKu6JHw/s1600-h/KC370005.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5047523492089337634" style="CURSOR: hand" alt="" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/Rgxn34VslyI/AAAAAAAAABo/He6MkKu6JHw/s320/KC370005.jpg" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-460022439460149531?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/460022439460149531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=460022439460149531' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/460022439460149531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/460022439460149531'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/03/cherry-blossomed-little.html' title='Cherry blossomed a little....'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_UTNqB6ppCWU/Rgxn34VslyI/AAAAAAAAABo/He6MkKu6JHw/s72-c/KC370005.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-2542271342540906457</id><published>2007-03-28T13:27:00.000-07:00</published><updated>2008-12-10T11:13:17.049-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Japanese SOBA noodle(Not security blog)</title><content type='html'>I love Japanese Soba noodle!&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_UTNqB6ppCWU/RgrQGIVslwI/AAAAAAAAABY/XCF7q4B4C94/s1600-h/0702260019.JPG"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_UTNqB6ppCWU/RgrQGIVslwI/AAAAAAAAABY/XCF7q4B4C94/s320/0702260019.JPG" alt="" id="BLOGGER_PHOTO_ID_5047075136158340866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Tofu from soba.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_UTNqB6ppCWU/RgrQUYVslxI/AAAAAAAAABg/GX8niSs3Nnc/s1600-h/0702260010.JPG"&gt;&lt;img style="cursor: pointer;" src="http://2.bp.blogspot.com/_UTNqB6ppCWU/RgrQUYVslxI/AAAAAAAAABg/GX8niSs3Nnc/s320/0702260010.JPG" alt="" id="BLOGGER_PHOTO_ID_5047075380971476754" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-2542271342540906457?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/2542271342540906457/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=2542271342540906457' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/2542271342540906457'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/2542271342540906457'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/03/japanese-soba-noodle.html' title='Japanese SOBA noodle(Not security blog)'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_UTNqB6ppCWU/RgrQGIVslwI/AAAAAAAAABY/XCF7q4B4C94/s72-c/0702260019.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-1721371808167232200</id><published>2007-03-28T13:19:00.000-07:00</published><updated>2008-12-10T11:13:17.666-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Photos'/><title type='text'>Spring has soon comes....(Not Security Blog)</title><content type='html'>Spring soon come to Japan. but not yet!&lt;br /&gt;&lt;br /&gt;picture Below is Cherry NOT Blossom :-)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_UTNqB6ppCWU/RgrN_4VsluI/AAAAAAAAABI/LkRr2W-tIB8/s1600-h/0703210010.JPG"&gt;&lt;img style="cursor: pointer;" src="http://4.bp.blogspot.com/_UTNqB6ppCWU/RgrN_4VsluI/AAAAAAAAABI/LkRr2W-tIB8/s320/0703210010.JPG" alt="" id="BLOGGER_PHOTO_ID_5047072829760902882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Picture Below is Kamo-River at Kyoto.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_UTNqB6ppCWU/RgrOAIVslvI/AAAAAAAAABQ/Kk41JdiqaRs/s1600-h/0703210015.JPG"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_UTNqB6ppCWU/RgrOAIVslvI/AAAAAAAAABQ/Kk41JdiqaRs/s320/0703210015.JPG" alt="" id="BLOGGER_PHOTO_ID_5047072834055870194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;soon soon soon be a spring.&lt;br /&gt;Cherry blossom in kyoto are japanese very famous to travelers .&lt;br /&gt;after cherry blossomed i post beautiful cherry blossom. see you next post!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-1721371808167232200?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/1721371808167232200/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=1721371808167232200' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1721371808167232200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/1721371808167232200'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/03/spring-has-soon-comesnot-security-blog.html' title='Spring has soon comes....(Not Security Blog)'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_UTNqB6ppCWU/RgrN_4VsluI/AAAAAAAAABI/LkRr2W-tIB8/s72-c/0703210010.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-2977888519324898923</id><published>2007-03-21T13:37:00.000-07:00</published><updated>2007-03-30T14:47:25.134-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>NoScript for FireFox can stop another site Javascript XSS</title><content type='html'>&lt;a href="http://ha.ckers.org/blog/20070320/noscript-plugin-beta-attempts-to-stop-xss/"&gt;ha.ckers.org web application security lab - Archive ≫ NoScript Plugin Beta Attempts To Stop XSS&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Beta version of &lt;a href="http://noscript.net/"&gt;NoScript&lt;/a&gt;(&lt;a href="http://sla.ckers.org/forum/read.php?13,8551"&gt;Noscript 1.1.4.6.070318&lt;/a&gt;) for FireFox can stops Cross site Scripting(XSS) from other site(like importing js file).&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;We are waiting for NoScript for Internet Explorer!!! :-)&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;Giorgio Maone, the author of the NoScript Firefox plugin has recently been posting to the boards about a new experimental version of the plugin that intends to protect against XSS. &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;The concept of the tool change is to detect when one site is attempting to send you to another site with XSS within the query string.&lt;/span&gt; Obviously there are more ways to XSS sites than the query string, so this mostly relates to certain forms of reflected XSS.&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-2977888519324898923?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/2977888519324898923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=2977888519324898923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/2977888519324898923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/2977888519324898923'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/03/noscript-for-firefox-can-stop-another.html' title='NoScript for FireFox can stop another site Javascript XSS'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-7822042720610847971</id><published>2007-02-22T00:43:00.000-08:00</published><updated>2007-03-30T14:47:25.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Trendmicro] I've joined Calender of Updates!</title><content type='html'>&lt;p&gt;In &lt;a href="http://www.dozleng.com/"&gt;Caleder of Updates&lt;/a&gt; post Trendmicro pattern file updates.&lt;/p&gt;&lt;p&gt;Trendmicro does not open past OPR(Official pattern Release) infomation detail to the public.&lt;br /&gt;(only newest one)&lt;br /&gt;&lt;a href="http://www.trendmicro.com/ftp/products/pattern/whatsnew.txt"&gt;http://www.trendmicro.com/ftp/products/pattern/whatsnew.txt&lt;/a&gt;&lt;/p&gt;&lt;p&gt;System administrator have to know what was changed in OPR.&lt;br /&gt;so i made it :-)&lt;br /&gt; &lt;a href="http://matcha139.hiemalis.org/~isamik/ptn/PATTERN#.txt"&gt;http://matcha139.hiemalis.org/~isamik/ptn/PATTERN#.txt&lt;/a&gt;&lt;br /&gt;ex) &lt;a href="http://matcha139.hiemalis.org/~isamik/ptn/4.287.00.txt"&gt;http://matcha139.hiemalis.org/~isamik/ptn/4.287.00.txt&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;have fun!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-7822042720610847971?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/7822042720610847971/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=7822042720610847971' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/7822042720610847971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/7822042720610847971'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/02/trendmicro-ive-joined-calender-of.html' title='[Trendmicro] I&apos;ve joined Calender of Updates!'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116910227206812314</id><published>2007-01-17T22:26:00.000-08:00</published><updated>2007-03-30T14:47:25.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[workshop] 10th Matcha 139 workshop will held in 17 Feb in Kyoto.</title><content type='html'>Our community workshop with IT security will held in 17 Feb.&lt;br /&gt;In this time &lt;strong&gt;&lt;span style="color:#ff0000;"&gt;"SQL injection" on Web application&lt;/span&gt;&lt;/strong&gt; is thema of workshop.&lt;br /&gt;&lt;br /&gt;Panel discussion with defending of Web application and Attaker.we discuss about HOW TO DEFEND web application from cracker.&lt;br /&gt;&lt;br /&gt;Detail are below.(Japanese Only)&lt;br /&gt;&lt;a href="http://d.hatena.ne.jp/ripjyr/20070217"&gt;http://d.hatena.ne.jp/ripjyr/20070217&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116910227206812314?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116910227206812314/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116910227206812314' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116910227206812314'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116910227206812314'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/01/workshop-10th-matcha-139-workshop-will.html' title='[workshop] 10th Matcha 139 workshop will held in 17 Feb in Kyoto.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116909647587113297</id><published>2007-01-17T20:58:00.000-08:00</published><updated>2007-03-30T14:47:25.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Microsot] MS07-002 Excel patch has probrem at Chinese,Korean and Japanese version of Excel 2000.</title><content type='html'>&lt;p&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;&lt;strong&gt;MS07-002 and Japanese edition of Microsoft Excel 2000 has probrem.&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;If apply MS07-002 with Japanese edition of Excel,&lt;br /&gt;sometime (not always) can't open Excel file.&lt;br /&gt;Probrem is occured Excel files create with  Korean ,Chinese or Japanese version of Excel 2000.&lt;br /&gt;and open with Excel 2000 in these langages.&lt;/p&gt;&lt;blockquote&gt;this probrem occurs in the &lt;strong&gt;&lt;span style="color: rgb(0, 153, 0);"&gt;phonetic information at&lt;br /&gt;Excel 2000 file create&lt;/span&gt;&lt;/strong&gt;.&lt;br /&gt;&lt;a href="http://support.microsoft.com/default.aspx?scid=kb;en-us;931183"&gt;Excel 2000&lt;br /&gt;does not open some files after you install security update 925524 that is&lt;br /&gt;documented in security bulletin MS07-002&lt;/a&gt;&lt;/blockquote&gt;&lt;p&gt;Excel 2000 is not supported in WSUS(Windows Software Update Service) or Microsoft Update.&lt;br /&gt;this reson not so big influence in Japan.So people who patch by hand or Office Updated has occurs this probrem.(but supported in Office Update)&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="color: rgb(255, 0, 0);font-size:130%;" &gt;&lt;strong&gt;Microsoft has *NOT* release patch,but they still open trouble patch in public.Microsoft need to stop providing Office2000 patch! right now and release patch.&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;Microsoft Re-Released MS07-002. After 6hour i post this blog. :-)&lt;br /&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2007/01/18/re-release-of-ms07-002-for-excel-2000.aspx"&gt;Detail are in Microsoft Security Research Center Blog.&lt;/a&gt;&lt;br /&gt;Shown like this.&lt;br /&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2007/01/18/re-release-of-ms07-002-for-excel-2000.aspx"&gt;&lt;/a&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/x/blogger/2009/4267/1600/558561/Excellv2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://photos1.blogger.com/x/blogger/2009/4267/320/444757/Excellv2.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116909647587113297?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116909647587113297/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116909647587113297' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116909647587113297'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116909647587113297'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/01/microsot-ms07-002-excel-patch-has.html' title='[Microsot] MS07-002 Excel patch has probrem at Chinese,Korean and Japanese version of Excel 2000.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116802164411337704</id><published>2007-01-05T10:20:00.000-08:00</published><updated>2007-03-30T14:47:25.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Security] Hijacked community at SNS.</title><content type='html'>&lt;a style="font-weight: bold;" href="http://mixi.jp/"&gt;Mixi &lt;/a&gt;the most populer SNS(Social Network Service) in japan.(Like &lt;a href="https://www.orkut.com/"&gt;Orkut &lt;/a&gt;by Google)&lt;br /&gt;in this SNS some community was hijacked.(community whith huge number of menber joined)&lt;br /&gt;hijacker's technique are Social engineering.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;font-size:130%;" &gt;Three Techniques are below...&lt;/span&gt;&lt;br /&gt;1.hijack community with &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;no owner&lt;/span&gt;(owner has leaved SNS)&lt;br /&gt;&lt;br /&gt;2.&lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;Send message&lt;/span&gt; directly to Owner &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;"I want to be owner"&lt;/span&gt;&lt;br /&gt;(these community are not Active)&lt;br /&gt;&lt;br /&gt;3.Two or more malices members &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;ruins the community&lt;/span&gt;.&lt;br /&gt;Malicious members &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;blame owner&lt;/span&gt; because owner is &lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;not steady&lt;/span&gt;.&lt;br /&gt;The person who runs for a new owner goes out , saying that "&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;I become a owner while it is getting ruin&lt;/span&gt;".&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;A tired owner&lt;/span&gt; is cheated and &lt;span style="font-weight: bold;"&gt;transfers the management right&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 51, 255); font-weight: bold;"&gt;After hijacked they modify content of community.and delete Bulletin board messages...they renew community.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold; color: rgb(255, 0, 0);font-size:130%;" &gt;they enjoys the reaction of the member who is from the origin.&lt;br /&gt;or&lt;br /&gt;It enjoys counting the seceding number of people.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;Real Example is...&lt;br /&gt;&lt;blockquote&gt;"Mos Burger" (hamburger shop's community) was hijacked and community contents has been changed to tavern community.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;And now Mixi created &lt;/span&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;sub-owner function&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; to defend community to hijack.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;A sub-owner might be able to &lt;span style="color: rgb(255, 0, 0);"&gt;obstruct the hijack&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;blockquote&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-weight: normal;"&gt;infomation from &lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;&lt;a href="http://translate.google.com/translate?u=http%3A%2F%2Fsky.geocities.jp%2Fsakujo_shinken%2F&amp;langpair=zh-CN%7Cen&amp;amp;amp;hl=ja&amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;prev=%2Flanguage_tools"&gt;Mixi community Hijacker's infomation site&lt;/a&gt;.(Japanese)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116802164411337704?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116802164411337704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116802164411337704' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116802164411337704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116802164411337704'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2007/01/security-hijacked-community-at-sns.html' title='[Security] Hijacked community at SNS.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116671683128816147</id><published>2006-12-21T07:41:00.000-08:00</published><updated>2007-03-30T14:47:25.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Security] NISSAN leaks 5.3Million customers personal  infomation...</title><content type='html'>&lt;span style="font-weight: bold;font-size:130%;" &gt;&lt;a href="http://www.nissan-global.com/EN/NEWS/2006/_STORY/061221-02-e.html"&gt;NISSAN   leaks 5.3Million customers Personal infomation.&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;about &lt;span style="font-weight: bold;"&gt;5.3Million data&lt;/span&gt; was leaked.&lt;br /&gt;Nissan send apologized Letters to 5.3Million people.&lt;br /&gt;Letter fee: 0.5$ x 5.3Million = $2,650,000&lt;br /&gt;&lt;br /&gt;I was surprised to Nissan collect 5.3 million information in one year.&lt;br /&gt;5.3Millon / 365Day = &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;about 15000 People / Day&lt;/span&gt;&lt;br /&gt;Nissan collect 15000People data per day!&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;The following is a summary of the key findings:  &lt;ul&gt;&lt;li&gt;Based on the limited information supplied by the magazine, Nissan has been unable to match that database with one that exists inside the company.&lt;/li&gt;&lt;li&gt;Although the alleged outside database does not match with our own internal database, our investigation has &lt;span style="font-weight: bold;"&gt;identified certain matching items that could have only been &lt;span style="color: rgb(255, 102, 102);"&gt;sourced from inside the company&lt;/span&gt;&lt;/span&gt;.&lt;/li&gt;&lt;li&gt;Based on our extensive research, Nissan has been able to identify that certain internal &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;data may have been sourced from an old customer database&lt;/span&gt;. These findings are supported through vehicle model codes (model type, base, class etc.) that are exclusively used inside the company.&lt;/li&gt;&lt;li&gt;From the data investigations, we have concluded that the most likely timing for the leak to have occurred was &lt;span style="font-weight: bold; color: rgb(255, 102, 102);"&gt;between May 2003 and February 2004&lt;/span&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;&lt;ul&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116671683128816147?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116671683128816147/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116671683128816147' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116671683128816147'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116671683128816147'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2006/12/security-nissan-leaks-53million.html' title='[Security] NISSAN leaks 5.3Million customers personal  infomation...'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116659463304030639</id><published>2006-12-19T22:02:00.000-08:00</published><updated>2007-03-30T14:47:25.136-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Security] Do that with Unicode!!</title><content type='html'>&lt;span style="font-weight: bold;"&gt;In Dec 9 2006 at hiroshima 10 TEXT HACK was Presentation by &lt;/span&gt;&lt;a style="font-weight: bold;" href="http://d.hatena.ne.jp/hasegawayosuke/"&gt;Yosuke Hasegawa&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; who also &lt;/span&gt;&lt;a style="font-weight: bold;" href="https://mvp.support.microsoft.com/profile=D43C974C-960A-48D3-9C44-CD457531FE2D"&gt;Microsoft MVP for Windows-Security&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;He Presented in &lt;a href="http://d.hatena.ne.jp/sec-momiji/"&gt;Security-Momiji&lt;/a&gt;(IT Security Workshop in Hiroshima) .&lt;br /&gt;document are below(Japanese Only)&lt;br /&gt;-&gt;  &lt;a href="http://openmya.hacker.jp/hasegawa/public/20061209/momiji.html"&gt;http://openmya.hacker.jp/hasegawa/public/20061209/momiji.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;---&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-weight: bold;font-size:180%;" &gt;TEXT HACKS,Useless 10 technique after another.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #1 XSS it! (&lt;span style="font-size:130%;"&gt;UTF-7)&lt;/span&gt;&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Script with UTF-7&lt;br /&gt;Ex) script with UTF-7&lt;br /&gt;+ADw-SCRIPT+AD4-alert(\'XSS\');+ADw-+AC8-SCRIPT+AD4-&lt;/li&gt;&lt;li&gt;Internet Explorer can't set  Encoding .And Internet Explorer is UTF-7  LIKELY Character automatic distinction to UTF-7.&lt;br /&gt;Ex) &lt;a href="http://www.watchfire.com/securityzone/advisories/12-21-05.aspx"&gt;Google Search replies "404 not found"&lt;/a&gt;. (2005.12)&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms06-053.mspx"&gt;IIS error page XSS in MS06-053&lt;/a&gt; (2006.10)&lt;/li&gt;&lt;li&gt;Specify encoding from outside.&lt;br /&gt;Ex) &lt;a href="http://www.nist.org/news.php?extend.184"&gt;Google Appliance XSS&lt;/a&gt; (2006.11)&lt;/li&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #2 more XSS it!(US-ASCII)&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Internet Explorer Disregard first bits in 7bit character set(ex.US-ASCII or  ISO-2022-JP...)&lt;br /&gt;Ex) both 0x73 and 0xF3 are same "s" in IE on using US-ASCII.&lt;br /&gt;s : 0x73 01110011&lt;br /&gt;0xF3 11110011&lt;br /&gt;Both 0x3C and 0xBC are same "&lt;" in IE on using US-ASCII.  &amp;lt; : 0x3C 00111100                              0xBC 10111100 &lt;/li&gt;&lt;li&gt;above can bypass META characters detection.&lt;br /&gt;Ex) &lt;span style="font-style: italic;"&gt;ｼscr iptｾalert(｢XSS｢)ｼ/scriptｾ&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;ｼ : 0xBC(7bit) -&gt; 0x3C(first bit on) -&gt; same as &amp;lt;&lt;br /&gt;ｾ : 0xBE(7bit) -&gt; 0x3E(first bit on) -&gt; same as &amp;gt;&lt;br /&gt;&lt;script&gt;alert('X&lt;/script&gt;｢ : 0xA2(7bit) -&gt; 0x22(first bit on) -&gt; same as '&lt;br /&gt;&lt;br /&gt;These mean "&amp;lt;sctipt&amp;gt;alert('XSS')&amp;lt;/script&amp;gt;" on US-ASCII.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;HACK #3 XSS by Japanese(&lt;/span&gt;&lt;http: style="font-weight: bold;" oe="utf-7&amp;q=%2badw-script%20src%2b..."&gt;Multi Byte Characters)&lt;/http:&gt;&lt;/li&gt;&lt;ol&gt;&lt;li&gt;"first byte" of Shift_jis or EUC-JP Can destroy HTML.&lt;br /&gt;&lt;div style=""&gt;&lt;div style=""&gt;&lt;div style=""&gt;Use 0x82(first byte of Shift_JIS) to next " (double quote) as force 2nd byte of Shift_JIS to Intenet Blowser.&lt;br /&gt;---&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;input type=text value="(0x82)"&gt;&amp;lt;br&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;input type=text value=" onmuseover=alert('xss');(0x82)"&gt;&amp;lt;br&gt;&lt;/span&gt;&lt;br /&gt;---&lt;br /&gt;(Source from http://www.atmarkit.co.jp/fsecurity/rensai/hoshino10/hoshino02.html (Only Japanese))&lt;br /&gt;&lt;br /&gt;Ex2) Yahoo Mail (2005.11)&lt;br /&gt;---&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Content-Type: text/html; charset=GB2312&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Subject: example&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;span&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;style='width:expr/*[0x81]*/*/ession(alert())'&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;exploited&amp;lt;/span&gt;&lt;/span&gt;&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;Ex2) Hotmail (2006.8)&lt;br /&gt;---&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Content-Type: text/html; charset=SHIFT_JIS&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Subject: example&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;font &gt;&amp;lt;/font&gt;&amp;lt;font face="&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; onmouseover=alert() s=[0x81]"&gt;exploited&amp;lt;/font&gt;&lt;/span&gt;&lt;br /&gt;---&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #4 More more XSS (Do that with expression!)&lt;/li&gt;&lt;ol&gt;&lt;li&gt; Internet Explorer can use UNICODE or Double Byte to write "expression( )" or "url()"&lt;br /&gt;---&lt;br /&gt;Ex) Double Byte&lt;br /&gt;&lt;span style="font-style: italic;"&gt;     &amp;lt;div style="{left:expression(alert('xss'))}"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;     &amp;lt;div style="{left:ｅｘｐｒｅｓｓｉｏｎ(alert('xss'))}"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;     &amp;lt;div style="{background:ＵＲＬ(javascript:alert('xss'))}"&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Ex) Unicode&lt;br /&gt;You can use Character to write expression or url.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;     R - U+0280 ()&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;     N - U+0274(t)、U+207F( )&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;     L - U+029F(・)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Hatena Diary (2005.12)&lt;br /&gt;Hotmail、Windows Live Mail (2006.11)&lt;br /&gt;SquirrelMail (2006.12)&lt;/li&gt;&lt;/ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;HACK #5 more and more XSS (Do that with unvisible charactors)&lt;/span&gt;&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Internet Explorer all Disregard Null Charactor in HTML.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;s(0x00)cript&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Internet Explorer  0x0B or 0x0C treated as SPACE in HTML.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;script(0x0B)&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;s (0x0C)onmouseover="..."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Mozilla FireFox 1.5.0.4 and Prior version disregard BOM (U+FEFF; ZERO WIDTH NO-BREAK SPACE).&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&amp;lt;s(BOM)cript&gt;&lt;/span&gt;&lt;/li&gt;&lt;ol&gt;&lt;li&gt;MFSA 2006-42: Web site XSS using BOM on UTF-8 pages&lt;http:&gt;&lt;/http:&gt;&lt;br /&gt;&lt;http:&gt;&lt;/http:&gt;&lt;http:&gt;&lt;/http:&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #6 bypass mail contents filter.&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Outlook Express is also Disregard first bit of 7bit charactor such US-ASCII or ISO-2022-JP.&lt;br /&gt;&lt;pre class="code"&gt;&lt;span style="font-style: italic;"&gt;MIME-Version: 1.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Content-Type: text/plain; charset=US-ASCII&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Content-Transfer-Encoding: &lt;/span&gt;&lt;span style="font-style: italic;" class="hl"&gt;7bit&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;This is test mail&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;begin 644 eicar.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;" class="hl"&gt;ﾍｶ&lt;/span&gt;&lt;span style="font-style: italic;"&gt;#5/(5`E0$%06S1&lt;4%i8-30h4%xi-t-#*3=])&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;$5)0T%2+5-404Y$05)$+4%.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;75$E625)54RU415-4+49)3$4A)$@K2"I#&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;`&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;end&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;uuencode eicar.com(virus test file) and first bit on.&lt;/pre&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #7 Create same file name(do that with ZERO WIDTH Charactors)&lt;/li&gt;&lt;ol&gt;&lt;li&gt;by using ZERO WIDTH or Control Charactors a part of file name can make looks like same file name.&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Unvisible Charactors.&lt;br /&gt;   - U+200B ( ZERO WIDTH SPACE )&lt;br /&gt;   - U+200C ( ZERO WIDTH NON-JOINER )&lt;br /&gt;   - U+200D ( ZERO WIDTH JOINER )&lt;br /&gt;   - U+FEFF ( ZERO WIDTH NO-BREAK SPACE )&lt;br /&gt;   - U+202A ( LEFT-TO-RIGHT EMBEDDING )&lt;br /&gt;&lt;img src="http://openmya.hacker.jp/hasegawa/public/20061209/momiji7.png" /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #8 Directory Traversal (do that with Yen mark)&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Unicode has backslash (U+005C) and Yen mark(U+00A5).&lt;/li&gt;&lt;li&gt;Yen mark(U+00A5) can use for file name.&lt;/li&gt;&lt;li&gt;Yen mark(U+00A5) convert to Shift-JIS and be backslash(0x5C)&lt;/li&gt;&lt;/ol&gt;&lt;ol&gt;&lt;ol&gt;&lt;li&gt;Therefore, in the application not to treat the file name with Unicode Directory Traversal might be happen.&lt;br /&gt;Ex) DoS might be generated.if application that recurrently enumerates the file .&lt;br /&gt;and If the folder like "..\".&lt;br /&gt;Ex)&lt;br /&gt;   - Namazu 2.0.15 (for Windows) prior&lt;br /&gt;   - Hyper Estraier Version 1.0.2 (for Windows) prior&lt;br /&gt;   - Becky! Ver.2.22 prior&lt;br /&gt;&lt;img src="http://openmya.hacker.jp/hasegawa/public/20061209/momiji8.png" /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;HACK #9 registry key that doesn't &lt;span style="font-weight: bold;"&gt; pretend exist but exist(Do that with ZERO WIDTH&lt;/span&gt; Charactor)&lt;/span&gt;&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Registry entry can use UNICODE,so you can use ZERO WIDTH Charactors to camouflaged by using ZERO WIDTH Charactors ,same as file name HACK #7.&lt;br /&gt;&lt;img src="http://openmya.hacker.jp/hasegawa/public/20061209/momiji10.png" /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;HACK #10 camouflage the file extension (do that with Bidi)&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Unicode has "bidirectional algorithm" function.&lt;br /&gt;show charactors to right directional to left directional.&lt;br /&gt;U+202E(RIGHT-TO-LEFT OVERRIDE; RLO) into file name,file name after RLO,charactors are left side right.&lt;/li&gt;&lt;ol&gt;&lt;li&gt;Ex) RLO with file name&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Real file name: this-(U+202E)txt.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;File name shown:this-exe.txt&lt;/span&gt;&lt;br /&gt;&lt;img src="http://openmya.hacker.jp/hasegawa/public/20061209/momiji9.png" /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;li style="font-weight: bold;"&gt;Summary&lt;/li&gt;&lt;ol&gt;&lt;li&gt;permitted characters are the MANAGED white list.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Character string is inspection are after regularized.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Don't change after regularized.&lt;/li&gt;&lt;li&gt;Dont cheated by Unicode that looks like.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;The behavior of difference between a Browser and MUA.(if possible)&lt;/li&gt;&lt;/ol&gt;&lt;li&gt;Reference&lt;/li&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://d.hatena.ne.jp/hasegawayosuke/"&gt;Hasegawa's Blog(Japanese only)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://slashdot.jp/security/article.pl?sid=05/12/21/2318216"&gt;XSS Vulnerability in UTF-7 encoded tag strings.(Slash dot japan)(Japanese Only)&lt;br /&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://sla.ckers.org/forum/read.php?3,3109"&gt;sla.ckers.org web application security forum :: Full Disclosure :: Widespread XSS for Google Search Appliance&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://ha.ckers.org/blog/20060621/us-ascii-xss-part-2/"&gt;ha.ckers.org web application security lab - Archive ≫ US-ASCII XSS part 2&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://ha.ckers.org/blog/20061108/yahoo-vulnerable-to-selected-encoding-xss/"&gt;ha.ckers.org web application security lab - Archive ≫ Yahoo Vulnerable To Selected Encoding XSS&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.atmarkit.co.jp/fsecurity/rensai/hoshino10/hoshino02.html"&gt;Pitfall of multi byte (Japanese only)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://applesoup.googlepages.com/bypass_filter.txt"&gt;Bypassing script filters with variable-width encodings&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://archive.openmya.devnull.jp/2006.08/msg00369.html"&gt;[openmya:035806] Cause of XSS by excessive detection of "Expression" in IE&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.mozilla.org/security/announce/2006/mfsa2006-42.html"&gt;MFSA 2006-42: Web site XSS using BOM on UTF-8 pages&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.namazu.org/pipermail/namazu-devel-ja/2006-January/000943.html"&gt;[Namazu-devel-ja 944] Japanese full-text search system Namazu 2.0.15 release&lt;/a&gt;}&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116659463304030639?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116659463304030639/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116659463304030639' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116659463304030639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116659463304030639'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2006/12/security-do-that-with-unicode.html' title='[Security] Do that with Unicode!!'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116651991514524546</id><published>2006-12-19T01:04:00.000-08:00</published><updated>2007-03-30T14:47:25.136-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Securiry] Backup product and Vulnerability</title><content type='html'>Recently a lot of vulnerability was found in Backup product.&lt;br /&gt;such as Arcserve and  Netbackup.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Arcserve&lt;/li&gt;&lt;ul&gt;&lt;li&gt;http://isc.sans.org/diary.php?storyid=1876&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Backup Exec&lt;br /&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;http://www.symantec.com/avcenter/security/Content/2006.12.13a.html&lt;/li&gt;&lt;li&gt;http://seer.support.veritas.com/docs/285984.htm&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;Backup product have to use system privileged user for backup system files.&lt;br /&gt;I think only backup (file copy process) have to use system privileged role, and other&lt;br /&gt;process unnecessary to hold system privileged.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Backup vender Should design with secure default!&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116651991514524546?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116651991514524546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116651991514524546' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116651991514524546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116651991514524546'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2006/12/securiry-backup-product-and.html' title='[Securiry] Backup product and Vulnerability'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116643165988875336</id><published>2006-12-18T00:46:00.000-08:00</published><updated>2007-03-30T14:47:25.136-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><title type='text'>[Security]128 bit WEP Key cracked in 81Minitues.so about Nintendo DS Lite.</title><content type='html'>&lt;a href="http://kikuz0u.x0.com/td/?date=20061215#p03"&gt;kikuz0u post&lt;/a&gt; that &lt;span style="font-weight: bold;"&gt;WEP key in Wifi Connection is cracked in 81Minutes&lt;/span&gt;.&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://kikuz0u.x0.com/td/?date=20061215#p03" target="_blank"&gt;&lt;/a&gt;&lt;br /&gt;He uses airsnort, aircrack-ng for crack WEP Key.&lt;br /&gt;&lt;br /&gt;How about Nintendo DS Lite Wifi Connection.&lt;br /&gt;this product  *CAN ONLY* use WEP key.....&lt;br /&gt;AES or TKIP can't use......I can't Believe it.&lt;br /&gt;&lt;br /&gt;many many Nintendo DS Lite owner set weak setting of Wifi to use&lt;br /&gt;Nintendo DS Lite.&lt;br /&gt;however other Wifi product's Default setting are weak too.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116643165988875336?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116643165988875336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116643165988875336' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116643165988875336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116643165988875336'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2006/12/security128-bit-wep-key-cracked-in.html' title='[Security]128 bit WEP Key cracked in 81Minitues.so about Nintendo DS Lite.'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-38158647.post-116642956804146712</id><published>2006-12-18T00:06:00.000-08:00</published><updated>2006-12-21T19:39:40.210-08:00</updated><title type='text'>[BLOG] Security Blog open!</title><content type='html'>In this blog. I'll post  security topics , news and someting like that I interested.&lt;br /&gt;&lt;br /&gt;in my main blog is &lt;a href="http://www.excite.co.jp/world/english/web/?wb_url=http%3A%2F%2Fd.hatena.ne.jp%2Fripjyr%2F&amp;wb_lp=JAEN&amp;amp;wb_dis=2"&gt;here&lt;/a&gt;.(Sorry only Japanese)&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;Q.Who am i?&lt;br /&gt;A.I'm matcha daifuku.&lt;br /&gt;I'am system administrator and security administrator at a company in japan(osaka)&lt;br /&gt;and I operate security community for ITpro in japan.(matcha139).&lt;br /&gt;---Microsoft MVP Windows-Security 2005/10-2007/09---&lt;br /&gt;&lt;br /&gt;Q.what is matcha139?&lt;br /&gt;A.matcha139 is security community. we hold workshop(meeting) 4times a year at kyoto.&lt;br /&gt;&lt;br /&gt;Q.what ripjyr stand for.&lt;br /&gt;A.Nothing (:-D) ripjyr was created by password maker.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/38158647-116642956804146712?l=ripjyr.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ripjyr.blogspot.com/feeds/116642956804146712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=38158647&amp;postID=116642956804146712' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116642956804146712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/38158647/posts/default/116642956804146712'/><link rel='alternate' type='text/html' href='http://ripjyr.blogspot.com/2006/12/blog-security-blog-open.html' title='[BLOG] Security Blog open!'/><author><name>matcha</name><uri>http://www.blogger.com/profile/17984185506222727615</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='26' height='32' src='http://photos1.blogger.com/x/blogger/2009/4267/1600/874234/ripjyr.jpg'/></author><thr:total>0</thr:total></entry></feed>
