<?xml version="1.0" encoding="utf-8"?>
<!-- generator="wordpress/2.0.11" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>The Turkey Curse</title>
	<link>http://blog.fukami.io</link>
	<description>fukamis terror chatroom</description>
	<pubDate>Mon, 24 Nov 2008 23:20:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.11</generator>
	<language>en</language>
			<item>
		<title>25C3: Schedule online</title>
		<link>http://blog.fukami.io/archives/2008/11/25/25c3-schedule-online/</link>
		<comments>http://blog.fukami.io/archives/2008/11/25/25c3-schedule-online/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 23:20:44 +0000</pubDate>
		<dc:creator>fukami</dc:creator>
		
		<category>Events</category>

		<guid isPermaLink="false">http://blog.fukami.io/archives/2008/11/25/25c3-schedule-online/</guid>
		<description><![CDATA[We just published the so-called &#8220;Fahrplan&#8221; for 25C3. Take a look.

Tags: Events,  CCC,  25C3,  Schedule,  Fahrplan
]]></description>
			<content:encoded><![CDATA[<p>We just published the so-called &#8220;Fahrplan&#8221; for 25C3. <a href="http://events.ccc.de/congress/2008/Fahrplan/">Take a look</a>.</p>

<div class="tags">Tags: <a href="http://technorati.com/tag/Events" rel="tag">Events</a>, <a href="http://technorati.com/tag/CCC" rel="tag"> CCC</a>, <a href="http://technorati.com/tag/25C3" rel="tag"> 25C3</a>, <a href="http://technorati.com/tag/Schedule" rel="tag"> Schedule</a>, <a href="http://technorati.com/tag/Fahrplan" rel="tag"> Fahrplan</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.fukami.io/archives/2008/11/25/25c3-schedule-online/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Deepsec, 25C3, CGNSec and everything else</title>
		<link>http://blog.fukami.io/archives/2008/11/06/deepsec-25c3-cgnsec-and-everything-else/</link>
		<comments>http://blog.fukami.io/archives/2008/11/06/deepsec-25c3-cgnsec-and-everything-else/#comments</comments>
		<pubDate>Thu, 06 Nov 2008 09:48:29 +0000</pubDate>
		<dc:creator>fukami</dc:creator>
		
		<category>General</category>

		<category>Events</category>

		<category>Security</category>

		<guid isPermaLink="false">http://blog.fukami.io/archives/2008/11/06/deepsec-25c3-cgnsec-and-everything-else/</guid>
		<description><![CDATA[Next week I will stay in Vienna to join Deepsec. Last year the conference was just amazing and I&#8217;m also looking forward to visit Metalab, one of my favorite hacker spaces. BeF and me will have a talk about ActionScript 3 obfuscation/de-obfuscation and other fun stuff with byte code. BeF released a new version of [...]]]></description>
			<content:encoded><![CDATA[<p>Next week I will stay in Vienna to join <a href="http://deepsec.net">Deepsec</a>. Last year the conference was just amazing and I&#8217;m also looking forward to visit <a href="http://metalab.at/">Metalab</a>, one of my favorite hacker spaces. <a href="http://pentaphase.de/">BeF</a> and me will have a talk about ActionScript 3 obfuscation/de-obfuscation and other fun stuff with byte code. BeF released a new version of <a href="http://code.google.com/p/erlswf/">erlswf</a> which is capable of disassembling AS3 and returning this disassembly as JSON. If you are interesting in those things you should check it out. BeF will hopefully blog about erlswf in detail (hinthint :)</p>

<p>During the last weeks I was one of the persons who looked through all the submissions (nearly 300!) for the <a href="https://events.ccc.de/congress/2008">25C3</a>. I was also involved into the decisions what talks will take place. I won&#8217;t tell much, but I think it will be interesting and much more focussed on technical topics rather than meta-blabla like the last years. BeF and me are going to speak about Flash stuff at 25C3 as well and we will also release a paper for the conference proceedings.</p>

<p>In November I will be at <a href="http://www.owasp.org/index.php/OWASP_Germany_2008_Conference">OWASP Germany 2008</a> in Frankfurt and talk about RIA security. I&#8217;m still not 100% sure what I will exactly talk about, but I think I will focus on difficulties one has to face when auditing complex RIA applications. Most people already know that I&#8217;m not a big fan of OWASP since it&#8217;s much to much vendor centric in my point of view (but, well, I don&#8217;t like to start a big rant here right now). Anyways, I&#8217;m looking forward to meet Alexios from n.runs and <a href="http://shampoo.antville.org/">Martin</a> at the conference.</p>

<p>Last month <a href="http://www.suspekt.org/">Stefan</a> and me founded <a href="http://cgnsec.de">CGNSec</a>. The idea is to meet security people and researchers from the Cologne/Bonn area to talk about unfinished ideas and projects as well as having some beers. Yesterday there was the second meeting and it was real fun. There were even some EZB guys from Frankfurt and we had some interesting conversations. I hope we will have some presentations from time to time, since there are quite some people with interesting stuff. I also hope that the MWCollect guys from Bonn are joining us next time.</p>

<p>Some personal notes: I got engaged with my girlfriend. Since she&#8217;ll go to Hamburg beginning of next year to join <a href="http://www.journalistenschule.de/">Henri Nannen Journalist School</a> I will probably leave the Rhineland in between the next two years (well, not before she will finish). I really feel sad somehow, since I feel home here. But after her studies she will probably not coming back, so I will follow her sooner or later.</p>

<p>I joined a carnival society some months ago called <a href="http://beueler-stadtsoldaten.de/">&#8220;Beueler Stadtsoldaten&#8221;</a>. The Rhenish Carneval is starting in a couple of days and I will have quite a couple of events where I will do some dancing (nothing to complicate really) - and I&#8217;m thinking about starting a blog or Soup where I like write about some experiences, post some photos and tell about all the dirty little things happen there. I will probably announce it using <a href="http://twitter.com/fukami">my Twitter account</a>. </p>

<p>Last but not least a little advertising: End of November the book of Mario Heiderich, Christian Matthies, Johannes Dahse and me will be published by <a href="http://www.galileo-press.com/">Galileo Press</a>. It&#8217;s in German and it calls <a href="http://www.amazon.de/Sichere-Webanwendungen-Flash-Sicherheit-Session-Hijacking-Web-2-0-Sicherheit/dp/3836211947">&#8220;Sichere Webanwendungen&#8221;</a> (secure web applications). I was only responsible for everything related to Flash, so most of the work was done by the others. The nice thing is that it will be published only using my nick, not my real name :)</p>

<div class="tags">Tags: <a href="http://technorati.com/tag/Events" rel="tag">Events</a>, <a href="http://technorati.com/tag/Security" rel="tag"> Security</a>, <a href="http://technorati.com/tag/Deepsec" rel="tag"> Deepsec</a>, <a href="http://technorati.com/tag/OWASP" rel="tag"> OWASP</a>, <a href="http://technorati.com/tag/25C3" rel="tag"> 25C3</a>, <a href="http://technorati.com/tag/CGNSec" rel="tag"> CGNSec</a>, <a href="http://technorati.com/tag/Beuel" rel="tag"> Beuel</a>, <a href="http://technorati.com/tag/Stadtsoldaten" rel="tag"> Stadtsoldaten</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.fukami.io/archives/2008/11/06/deepsec-25c3-cgnsec-and-everything-else/feed/</wfw:commentRss>
		</item>
		<item>
		<title>re:publica, Bluehat and PH-Neutral</title>
		<link>http://blog.fukami.io/archives/2008/03/26/re-publica-bluehat-ph-neutral/</link>
		<comments>http://blog.fukami.io/archives/2008/03/26/re-publica-bluehat-ph-neutral/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 10:50:30 +0000</pubDate>
		<dc:creator>fukami</dc:creator>
		
		<category>Events</category>

		<category>Security</category>

		<guid isPermaLink="false">http://blog.fukami.io/archives/2008/03/26/re-publica-bluehat-ph-neutral/</guid>
		<description><![CDATA[The next couple of weeks I&#8217;m going to speak at some interesting and completely different events. Next week I will be at re:publica in Berlin doing a tunneling workshop. Last year there was a screen at the entrance of re:publica showing the output of dnsniff. Some people got very pissed because of their passwords turning [...]]]></description>
			<content:encoded><![CDATA[<p>The next couple of weeks I&#8217;m going to speak at some interesting and completely different events. Next week I will be at <a href="http://re-publica.de/08/">re:publica</a> in Berlin doing a tunneling workshop. Last year there was a screen at the entrance of re:publica showing the output of dnsniff. Some people got very pissed because of their passwords turning up in full HD quality. So Markus had the idea of this workshop and asked to do that in order to give the attendees a possibility to protect themself. The re:publica is going to be very big this year (800 attendees all together as far as I know) and a lot of old friends will show up I haven&#8217;t seen in a while.</p>

<p>The next event I&#8217;m going to visit is <a href="http://blogs.technet.com/bluehat/">Bluehat v7</a> in Seattle. I&#8217;ve never been to the States before, so I&#8217;m really excited going there - especially because Microsoft is the reason which I still find very weird. I&#8217;ll give a presentation together with <a href="http://www.cracking.com.ar/">Manuel Caballero</a> about <a href="http://silverlight.net/">Silverlight</a> and how it compares to Adobe Flash security-wise. Only a few of the speakers of Bluehat are already known to me. Beside <a href="http://doxpara.com/">Lieutenant Dan</a> and <a href="http://kuza55.blogspot.com/">kuza55</a> I&#8217;m looking forward to got to know <a href="http://secway.org/">Sowhat</a>. We tried to invite him to one of the past <a href="https://events.ccc.de/congress/">Chaos Communication Congresses</a> but it was far more complicate than we thought because of problems with the visa. I&#8217;m also looking forward to got to know <a href="http://xs-sniper.com/blog/">Billy Rios</a>. I guess he and <a href="http://dhanjani.com/">Nitesh</a> will talk about <a href="http://www.net-security.org/article.php?id=1110">Phishing</a>.</p>

<p>In May I&#8217;ll be at <a href="http://ph-neutral.darklab.org/">PH-Neutral</a> and give a presentation together with <a href="http://pentaphase.de/">BeF</a> entitled &#8220;SWF and the Malware Tragedy&#8221;. The talk is about static analysis of SWF bytecode and we hopefully have some more time to look into less known SWF bytecode obfuscation techniques. BeF and me also wrote a <a href="https://www.flashsec.org/mediawiki/images/5/57/SWF_and_the_Malware_Tragedy.pdf">paper</a> with the same title which is mainly about using Erlang programming language based <a href="http://code.google.com/p/erlswf/">erlswf</a> for SWF bytecode analysis.</p>

<div class="tags">Tags: <a href="http://technorati.com/tag/Events" rel="tag">Events</a>, <a href="http://technorati.com/tag/Security" rel="tag"> Security</a>, <a href="http://technorati.com/tag/re-publica08" rel="tag"> re-publica08</a>, <a href="http://technorati.com/tag/Bluehat" rel="tag"> Bluehat</a>, <a href="http://technorati.com/tag/PH-Neutral" rel="tag"> PH-Neutral</a>, <a href="http://technorati.com/tag/Flash" rel="tag"> Flash</a>, <a href="http://technorati.com/tag/Silverlight" rel="tag"> Silverlight</a>, <a href="http://technorati.com/tag/SektionEins" rel="tag"> SektionEins</a>, <a href="http://technorati.com/tag/FlashSec" rel="tag"> FlashSec</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.fukami.io/archives/2008/03/26/re-publica-bluehat-ph-neutral/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Controlling access to Local Shared Objects aka Flash Cookies</title>
		<link>http://blog.fukami.io/archives/2007/12/06/controlling-access-to-local-shared-objects-aka-flash-cookies/</link>
		<comments>http://blog.fukami.io/archives/2007/12/06/controlling-access-to-local-shared-objects-aka-flash-cookies/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 19:05:19 +0000</pubDate>
		<dc:creator>fukami</dc:creator>
		
		<category>Security</category>

		<guid isPermaLink="false">http://blog.fukami.io/archives/2007/12/06/controlling-access-to-local-shared-objects-aka-flash-cookies/</guid>
		<description><![CDATA[LSO, also known as Flash Cookies or Flash Shared Objects, are somewhat nasty: There are persistent across browsers, don&#8217;t get deleted on browser exit nor is there an obvious way for viewing and managing them. One possibility is to use NoScript, disable Flash entirely or disable read/write access to the directories where they get stored [...]]]></description>
			<content:encoded><![CDATA[<p><a href="https://www.flashsec.org/wiki/Shared_Objects">LSO</a>, also known as Flash Cookies or Flash Shared Objects, are somewhat nasty: There are persistent across browsers, don&#8217;t get deleted on browser exit nor is there an obvious way for viewing and managing them. One possibility is to use <a href="http://noscript.net/">NoScript</a>, disable Flash entirely or disable read/write access to the directories where they get stored is another. But I personally find it interesting to see what sites are actually using those cookies for tracking. So a good solution for this specific issue would something to take back control and have an overview over those sites without giving them access to LSOs.</p>

<p>There is one simple solution and it is even supplied by <a href="http://www.adobe.com/">Adobe</a> itself: The <a href="http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager06.html">Flash Player Settings Manager</a>. It&#8217;s actually a Flash movie which is able to access the file system and store the settings. </p>

<p>I know, it is weird that it resides on Adobes website and it is far from being perfect at all since it would be much nice to have a real interface to it.</p>

<div class="tags">Tags: <a href="http://technorati.com/tag/flash" rel="tag">flash</a>, <a href="http://technorati.com/tag/adobe" rel="tag"> adobe</a>, <a href="http://technorati.com/tag/lso" rel="tag"> lso</a>, <a href="http://technorati.com/tag/shared_object" rel="tag"> shared_object</a>, <a href="http://technorati.com/tag/security" rel="tag"> security</a>, <a href="http://technorati.com/tag/tracking" rel="tag"> tracking</a>, <a href="http://technorati.com/tag/cookie" rel="tag"> cookie</a>, <a href="http://technorati.com/tag/persistent" rel="tag"> persistent</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.fukami.io/archives/2007/12/06/controlling-access-to-local-shared-objects-aka-flash-cookies/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Deepsec in Vienna</title>
		<link>http://blog.fukami.io/archives/2007/11/19/deepsec-in-vienna/</link>
		<comments>http://blog.fukami.io/archives/2007/11/19/deepsec-in-vienna/#comments</comments>
		<pubDate>Mon, 19 Nov 2007 12:08:30 +0000</pubDate>
		<dc:creator>fukami</dc:creator>
		
		<category>Events</category>

		<category>Security</category>

		<guid isPermaLink="false">http://blog.fukami.io/archives/2007/11/19/deepsec-in-vienna/</guid>
		<description><![CDATA[This week my workmate Stefan and me are going to join Deepsec,  an &#8220;in-depth security conference&#8221; in Vienna. Deepsec looks very promising to me since there are a lot of talks I like to attend to, like the talks from Halvar Flake, Dave Aitel, Martin Johns, Alexander Kornbrust, David Litchfield or from Melanie Rieback. [...]]]></description>
			<content:encoded><![CDATA[<p>This week my workmate <a href="http://blog.php-security.org/">Stefan</a> and me are going to join <a href="http://www.deepsec.net/">Deepsec</a>,  an &#8220;in-depth security conference&#8221; in Vienna. Deepsec looks very promising to me since there are a lot of talks I like to attend to, like the talks from Halvar Flake, Dave Aitel, Martin Johns, Alexander Kornbrust, David Litchfield or from Melanie Rieback. I will also give a talk, once again on Adobe Flash Security.</p>

<p>Beside the conference there will be another nice great event in Vienna called <a href="http://www.roboexotica.org/">Roböxotica</a>, a festival for cocktail robotics. I am also looking forward to visit <a href="http://metalab.at/">Metalab</a> and meet some friends. </p>

<p>Last but not least we will visit <a href="http://www.figlmueller.at/">Figlmüller</a> to eat Wiener Schnitzel :)</p>

<div class="tags">Tags: <a href="http://technorati.com/tag/deepsec" rel="tag">deepsec</a>, <a href="http://technorati.com/tag/vienna" rel="tag"> vienna</a>, <a href="http://technorati.com/tag/wien" rel="tag"> wien</a>, <a href="http://technorati.com/tag/security" rel="tag"> security</a>, <a href="http://technorati.com/tag/event" rel="tag"> event</a>, <a href="http://technorati.com/tag/roboexotica" rel="tag"> roboexotica</a>, <a href="http://technorati.com/tag/metalab" rel="tag"> metalab</a>, <a href="http://technorati.com/tag/sektioneins" rel="tag"> sektioneins</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.fukami.io/archives/2007/11/19/deepsec-in-vienna/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
