<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for cyberwart</title>
	<atom:link href="http://www.cyberwart.com/blog/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cyberwart.com/blog</link>
	<description>Cyber Warfare Technologies</description>
	<pubDate>Tue, 06 Jan 2009 04:18:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
		<item>
		<title>Comment on Mixing File Types by Sky</title>
		<link>http://www.cyberwart.com/blog/2008/08/01/mixing-file-types/#comment-1924</link>
		<dc:creator>Sky</dc:creator>
		<pubDate>Tue, 05 Aug 2008 14:13:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=43#comment-1924</guid>
		<description>Prove it. for spaming a site and having very little to say, you do sound pretty stupid. there are security features like Security Settings for AX controls in Word. and the same goes for the HTML pull down, it only allows picture pull downs on trusted or "ok'd" docs.... so if you click ok its your own stupid fault.</description>
		<content:encoded><![CDATA[<p>Prove it. for spaming a site and having very little to say, you do sound pretty stupid. there are security features like Security Settings for AX controls in Word. and the same goes for the HTML pull down, it only allows picture pull downs on trusted or &#8220;ok&#8217;d&#8221; docs&#8230;. so if you click ok its your own stupid fault.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mixing File Types by Anon H4ck3r</title>
		<link>http://www.cyberwart.com/blog/2008/08/01/mixing-file-types/#comment-1914</link>
		<dc:creator>Anon H4ck3r</dc:creator>
		<pubDate>Sat, 02 Aug 2008 12:01:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/?p=43#comment-1914</guid>
		<description>AWESOME STUFF
thanx so much</description>
		<content:encoded><![CDATA[<p>AWESOME STUFF<br />
thanx so much</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ripped from the Headlines: Antiforensics by Daniel</title>
		<link>http://www.cyberwart.com/blog/2007/05/31/ripped-from-the-headlines-antiforensics/#comment-300</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Thu, 11 Oct 2007 13:34:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/05/31/ripped-from-the-headlines-antiforensics/#comment-300</guid>
		<description>I couldn't understand some parts of this article Ripped from the Headlines: Antiforensics, but I guess I just need to check some more resources regarding this, because it sounds interesting.</description>
		<content:encoded><![CDATA[<p>I couldn&#8217;t understand some parts of this article Ripped from the Headlines: Antiforensics, but I guess I just need to check some more resources regarding this, because it sounds interesting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ripped from Elsewhere: Requirements for Effective Fuzzing by anonymous</title>
		<link>http://www.cyberwart.com/blog/2007/06/30/ripped-from-elsewhere-requirements-for-effective-fuzzing/#comment-245</link>
		<dc:creator>anonymous</dc:creator>
		<pubDate>Thu, 30 Aug 2007 22:02:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/06/30/ripped-from-elsewhere-requirements-for-effective-fuzzing/#comment-245</guid>
		<description>Actually there is an Ida plugin that will map code coverag.</description>
		<content:encoded><![CDATA[<p>Actually there is an Ida plugin that will map code coverag.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How Hacking Dies&#8230;. to thunderous applause by xs</title>
		<link>http://www.cyberwart.com/blog/2007/08/10/how-hacking-dies-to-thunderous-applause/#comment-143</link>
		<dc:creator>xs</dc:creator>
		<pubDate>Mon, 13 Aug 2007 06:11:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/08/10/how-hacking-dies-to-thunderous-applause/#comment-143</guid>
		<description>The HEAP talk was "Understanding the HEAP by breaking it". Very good technical paper to read when jacked up on Monster and Penguins. :)

I also agree that alot of the scene is move to more of a side channel. People meeting and talking. Same kind of stuff in our crew. Talking about new code, 0-days or just drinking and having fun.

We are going to hit shmoo next year and see what it is like. I think alot of people want to work with shmoo, it's just getting them to respond to you and work with ya. Good luck with that.

Maybe we can find some sexy girls before next year and get them in our crew so we can go to the hacker pimps and the ninja parties. I have been going to Defcon and BH for fours years and have never been invited. Maybe we lack foo. :)

BH and DC seem to be selling out there talk spots to the highest vendor. Just look at who is speaking at BH this year. All of the major speakers were major sponsors to the con. HUMMM.... so DT sold it and then sold out.

xs</description>
		<content:encoded><![CDATA[<p>The HEAP talk was &#8220;Understanding the HEAP by breaking it&#8221;. Very good technical paper to read when jacked up on Monster and Penguins. <img src='http://www.cyberwart.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I also agree that alot of the scene is move to more of a side channel. People meeting and talking. Same kind of stuff in our crew. Talking about new code, 0-days or just drinking and having fun.</p>
<p>We are going to hit shmoo next year and see what it is like. I think alot of people want to work with shmoo, it&#8217;s just getting them to respond to you and work with ya. Good luck with that.</p>
<p>Maybe we can find some sexy girls before next year and get them in our crew so we can go to the hacker pimps and the ninja parties. I have been going to Defcon and BH for fours years and have never been invited. Maybe we lack foo. <img src='http://www.cyberwart.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>BH and DC seem to be selling out there talk spots to the highest vendor. Just look at who is speaking at BH this year. All of the major speakers were major sponsors to the con. HUMMM&#8230;. so DT sold it and then sold out.</p>
<p>xs</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How Hacking Dies&#8230;. to thunderous applause by mjw</title>
		<link>http://www.cyberwart.com/blog/2007/08/10/how-hacking-dies-to-thunderous-applause/#comment-129</link>
		<dc:creator>mjw</dc:creator>
		<pubDate>Sat, 11 Aug 2007 04:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/08/10/how-hacking-dies-to-thunderous-applause/#comment-129</guid>
		<description>I thought HD's talk was alright. It's the style of pen-testing that I prefer. Far too many people perform a "vulnerability assessment" and call it a pen test. I think there's an important difference in that a VA is essentially scanning a network for a known vulnerability. It's pretty much just auditing the patch management system. Pen testing, hacking to me, is right on with what HD was talking about. However, as that's what I do all the time the talks seemed rather slow to me (not to mention they took up 2 blocks). 

Which talk about heap exploiting are you talking about? The one talking about dereferenced pointers?

I think the real "scene" is moving to the sidelines of BH/Defcon. I got a nice DoS against the iPhone that I'm still playing with and I talked about a few cool topics with some buddies -- but I just have to wonder what's the point if the best part of the conference is talking with friends?


My new goal is to get more involved with the Shmoo group and try to help build up shmoocon. Despite have the same old taste of DC I think it's the best route to having a really meaningful experience.</description>
		<content:encoded><![CDATA[<p>I thought HD&#8217;s talk was alright. It&#8217;s the style of pen-testing that I prefer. Far too many people perform a &#8220;vulnerability assessment&#8221; and call it a pen test. I think there&#8217;s an important difference in that a VA is essentially scanning a network for a known vulnerability. It&#8217;s pretty much just auditing the patch management system. Pen testing, hacking to me, is right on with what HD was talking about. However, as that&#8217;s what I do all the time the talks seemed rather slow to me (not to mention they took up 2 blocks). </p>
<p>Which talk about heap exploiting are you talking about? The one talking about dereferenced pointers?</p>
<p>I think the real &#8220;scene&#8221; is moving to the sidelines of BH/Defcon. I got a nice DoS against the iPhone that I&#8217;m still playing with and I talked about a few cool topics with some buddies &#8212; but I just have to wonder what&#8217;s the point if the best part of the conference is talking with friends?</p>
<p>My new goal is to get more involved with the Shmoo group and try to help build up shmoocon. Despite have the same old taste of DC I think it&#8217;s the best route to having a really meaningful experience.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How Hacking Dies&#8230;. to thunderous applause by xs</title>
		<link>http://www.cyberwart.com/blog/2007/08/10/how-hacking-dies-to-thunderous-applause/#comment-127</link>
		<dc:creator>xs</dc:creator>
		<pubDate>Fri, 10 Aug 2007 21:00:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/08/10/how-hacking-dies-to-thunderous-applause/#comment-127</guid>
		<description>I think day 1 was really good. The HD moore talk, there was a talk on the HEAP which was dry but the content in the paper made up for that. Plus the JS talk (hacking intranet sites from the outside in). Day 2 was very weak. I setup my bluetooth scanner and collect some data for a project I am working on.

I don't want to agree because I have really loved BH in the past, but I would say that another year of the sponsors buying there seats and time to speak at BH and the con will be dead. Go back tot he days of allowing more independant speakers to come in with ideas and content. Not some sales pitch on a product that no one in the room can afford.

Also, more free open source tools or POC code would be cool.

xs</description>
		<content:encoded><![CDATA[<p>I think day 1 was really good. The HD moore talk, there was a talk on the HEAP which was dry but the content in the paper made up for that. Plus the JS talk (hacking intranet sites from the outside in). Day 2 was very weak. I setup my bluetooth scanner and collect some data for a project I am working on.</p>
<p>I don&#8217;t want to agree because I have really loved BH in the past, but I would say that another year of the sponsors buying there seats and time to speak at BH and the con will be dead. Go back tot he days of allowing more independant speakers to come in with ideas and content. Not some sales pitch on a product that no one in the room can afford.</p>
<p>Also, more free open source tools or POC code would be cool.</p>
<p>xs</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Dynamic HTTP Callbacks by Mike</title>
		<link>http://www.cyberwart.com/blog/2007/04/23/dynamic-http-callbacks/#comment-48</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sun, 22 Jul 2007 17:04:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/04/23/dynamic-http-callbacks/#comment-48</guid>
		<description>&lt;strong&gt;Mike...&lt;/strong&gt;

Cool! Its really cool....</description>
		<content:encoded><![CDATA[<p><strong>Mike&#8230;</strong></p>
<p>Cool! Its really cool&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on iPhone hackers disclose vulns and hunt for clues by forum iphone mobile phone</title>
		<link>http://www.cyberwart.com/blog/2007/07/02/iphone-hackers-disclose-vulns-and-hunt-for-clues/#comment-6</link>
		<dc:creator>forum iphone mobile phone</dc:creator>
		<pubDate>Wed, 04 Jul 2007 06:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.cyberwart.com/blog/2007/07/02/iphone-hackers-disclose-vulns-and-hunt-for-clues/#comment-6</guid>
		<description>&lt;strong&gt;iPhone hackers disclose vulns and hunt for clues...&lt;/strong&gt;

Great post. Thanks!...</description>
		<content:encoded><![CDATA[<p><strong>iPhone hackers disclose vulns and hunt for clues&#8230;</strong></p>
<p>Great post. Thanks!&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
