<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9111337</id><updated>2011-09-01T22:19:22.113+02:00</updated><category term='prog'/><category term='Fr'/><category term='Nessus'/><category term='En'/><category term='IRL'/><category term='cyberspace'/><title type='text'>Michel A's troll blog</title><subtitle type='html'>Another blog from Michel A.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>65</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9111337.post-7790949432131443975</id><published>2011-04-06T20:46:00.004+02:00</published><updated>2011-04-06T21:05:13.751+02:00</updated><title type='text'>[en] a portscanner killer</title><content type='html'>Here is a small tool I wrote a while ago: &lt;a href="http://michel.arboi.free.fr/download/ipqRST2.pl"&gt;ipqRST&lt;/a&gt;&lt;br /&gt;To use it, rewrite your iptables rules and replace &lt;span style="font-family:courier new;"&gt;-j DROP&lt;/span&gt; or &lt;span style="font-family:courier new;"&gt;-j REJECT&lt;/span&gt; on closed ports by &lt;span style="font-family:courier new;"&gt;-j QUEUE&lt;/span&gt; and make sure that you run &lt;span style="font-family:courier new;"&gt;ipqRST2.&lt;/span&gt;pl as root somewhere (screen or nohup will help you).&lt;br /&gt;Do not use it on open ports as you might disrupt your applications or open holes in your filtering policy!&lt;br /&gt;&lt;br /&gt;How it works: when packets are received, the tool delays them a little before letting them go. Little by little, the RTT between the scanner and the target seems to increase.&lt;br /&gt;It severely disrupts several known portscanners which slow down to a crawl.&lt;br /&gt;Nessus is immune to that, by the way...&lt;br /&gt;&lt;br /&gt;You should not use this toy in production. Firewalls that return rate limited ICMP packets are already very efficient against portscanners . i.e. you should prefer &lt;span style="font-family:courier new;"&gt;iptables -j REJECT&lt;/span&gt; to &lt;span style="font-family:courier new;"&gt;iptables -j DROP&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-7790949432131443975?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/7790949432131443975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=7790949432131443975&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7790949432131443975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7790949432131443975'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2011/04/en-portscanner-killer.html' title='[en] a portscanner killer'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-2206787859448132266</id><published>2011-01-26T12:53:00.014+01:00</published><updated>2011-01-26T13:11:00.355+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IRL'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>Ordinateur fou</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_mQV1IEgQVR8/TUAOwUWTNjI/AAAAAAAAACI/n15_t26z7DM/s1600/debitel0187.jpg"&gt;&lt;img style="cursor: pointer; width: 233px; height: 320px;" src="http://3.bp.blogspot.com/_mQV1IEgQVR8/TUAOwUWTNjI/AAAAAAAAACI/n15_t26z7DM/s320/debitel0187.jpg" alt="" id="BLOGGER_PHOTO_ID_5566465362688685618" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_mQV1IEgQVR8/TUAOwy-KV8I/AAAAAAAAACQ/pK2a6jUdgdQ/s1600/debitel0188.jpg"&gt;&lt;img style="cursor: pointer; width: 233px; height: 320px;" src="http://4.bp.blogspot.com/_mQV1IEgQVR8/TUAOwy-KV8I/AAAAAAAAACQ/pK2a6jUdgdQ/s320/debitel0188.jpg" alt="" id="BLOGGER_PHOTO_ID_5566465370908940226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Simplicime, anciennement Débitel, était un opérateur téléphonique de bon goût: un poil moins cher que les trois grands, mais surtout, leurs contrats étaient compréhensibles. Je n'ai pas signé avec mon sang un engagement de 42 ans, je ne leur sacrifierai pas mon premier né, et je n'ai pas eu à vendre mon âme pour envoyer une demie douzaine SMS par mois.&lt;br /&gt;Et puis, début 2010, ils ont eu la mauvaise idée de changer de système informatique qui fonctionnait jusqu'alors. "If it ain't broken, don't fix it". À partir de ce moment là, le service commercial est parti en vrille.&lt;br /&gt;J'ai commencé à recevoir des relances pour une facture impayée "de euros", et puis, comme je n'ai pas envoyé un chèque vide, j'ai reçu une mise en demeure avec inscription au GIE Préventel (le genre de truc dont on sort très difficilement). Allez savoir pourquoi, ça ne m'a pas fait rire et je me suis fendu d'un mel assassin au service commercial leur conseillant vivement de mettre ce logiciel de daube sur le trottoir avant qu'il coule leur boite. Je n'ai jamais eu de réponse mais le système est retombé en marche. Aurait-il écouté mes suggestions?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-2206787859448132266?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/2206787859448132266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=2206787859448132266&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2206787859448132266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2206787859448132266'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2011/01/ordinateur-fou.html' title='Ordinateur fou'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_mQV1IEgQVR8/TUAOwUWTNjI/AAAAAAAAACI/n15_t26z7DM/s72-c/debitel0187.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-8847440115387499557</id><published>2010-12-05T01:15:00.003+01:00</published><updated>2010-12-05T01:21:39.390+01:00</updated><title type='text'>[en] Watchdog on Jetway NC9C-550-LF mobo</title><content type='html'>A watchdog is available on the Jetway &lt;a href="http://www.jetway.com.tw/jw/ipcboard_view.asp?productid=781&amp;amp;proname=NC9C-550-LF"&gt;NC9C-550-LF&lt;/a&gt; mini-ITX motherboard. It is managed by the super IO chip, which appears to be a Fintech F71869.&lt;br /&gt;Linux 2.6.36 has support for some Fintech watchdogs. This small patch adds the F71869.&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;--- ./drivers/watchdog/f71808e_wdt.c 2010-10-20 22:30:22.000000000 +0200&lt;br /&gt;+++ /tmp/f71808e_wdt.c 2010-12-05 01:19:48.819567802 +0100&lt;br /&gt;@@ -52,6 +52,8 @@&lt;br /&gt; #define SIO_F71882_ID  0x0541 /* Chipset ID */&lt;br /&gt; #define SIO_F71889_ID  0x0723 /* Chipset ID */&lt;br /&gt; &lt;br /&gt;+#define SIO_F71869_ID  0x0814&lt;br /&gt;+&lt;br /&gt; #define F71882FG_REG_START  0x01&lt;br /&gt; &lt;br /&gt; #define F71808FG_REG_WDO_CONF  0xf0&lt;br /&gt;@@ -98,7 +100,7 @@&lt;br /&gt; MODULE_PARM_DESC(start_withtimeout, "Start watchdog timer on module load with"&lt;br /&gt;  " given initial timeout. Zero (default) disables this feature.");&lt;br /&gt; &lt;br /&gt;-enum chips { f71808fg, f71858fg, f71862fg, f71882fg, f71889fg };&lt;br /&gt;+enum chips { f71808fg, f71858fg, f71862fg, f71882fg, f71889fg, f71869 };&lt;br /&gt; &lt;br /&gt; static const char *f71808e_names[] = {&lt;br /&gt;  "f71808fg",&lt;br /&gt;@@ -106,6 +108,7 @@&lt;br /&gt;  "f71862fg",&lt;br /&gt;  "f71882fg",&lt;br /&gt;  "f71889fg",&lt;br /&gt;+ "f71869",&lt;br /&gt; };&lt;br /&gt; &lt;br /&gt; /* Super-I/O Function prototypes */&lt;br /&gt;@@ -308,6 +311,10 @@&lt;br /&gt;   superio_set_bit(watchdog.sioaddr, 0x29, 1);&lt;br /&gt;   break;&lt;br /&gt; &lt;br /&gt;+ case f71869:&lt;br /&gt;+  /* GPIO14 --&gt; WDTRST# */&lt;br /&gt;+  superio_clear_bit(watchdog.sioaddr, 0x29, 4);&lt;br /&gt;+  break;&lt;br /&gt;  default:&lt;br /&gt;   /*&lt;br /&gt;    * 'default' label to shut up the compiler and catch&lt;br /&gt;@@ -708,6 +715,9 @@&lt;br /&gt;  case SIO_F71882_ID:&lt;br /&gt;   watchdog.type = f71882fg;&lt;br /&gt;   break;&lt;br /&gt;+ case SIO_F71869_ID:&lt;br /&gt;+  watchdog.type = f71869;&lt;br /&gt;+  break;&lt;br /&gt;  case SIO_F71862_ID:&lt;br /&gt;  case SIO_F71889_ID:&lt;br /&gt;   /* These have a watchdog, though it isn't implemented (yet). */&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-8847440115387499557?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/8847440115387499557/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=8847440115387499557&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/8847440115387499557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/8847440115387499557'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/12/en-watchdog-on-jetway-nc9c-550-lf-mobo.html' title='[en] Watchdog on Jetway NC9C-550-LF mobo'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-2867475388872814237</id><published>2010-09-01T10:10:00.002+02:00</published><updated>2010-09-01T10:12:15.981+02:00</updated><title type='text'>[en] Nessus "local checks" for Cisco IOS</title><content type='html'>Parsing the advisories in HTML was a huge pain in the back, but we have the scripts, at last.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-2867475388872814237?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/2867475388872814237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=2867475388872814237&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2867475388872814237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2867475388872814237'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/09/en-nessus-local-checks-for-cisco-ios.html' title='[en] Nessus &quot;local checks&quot; for Cisco IOS'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3232460282232302660</id><published>2010-07-26T23:21:00.003+02:00</published><updated>2010-07-27T11:51:39.036+02:00</updated><title type='text'>[en] new web app application tests</title><content type='html'>New web application tests for Nessus:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=47832"&gt;on site request forgery&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=47834"&gt;malicious redirections&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=47830"&gt;Injectable parameters&lt;/a&gt; (this is a weakness only)&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Quicker tests based upon the result of &lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=47830"&gt;torture_cgi_injectable_param.nasl&lt;/a&gt;:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Cross site scripting&lt;/li&gt;&lt;li&gt;Cookie manipulation&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Header injections&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3232460282232302660?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/3232460282232302660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=3232460282232302660&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3232460282232302660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3232460282232302660'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/07/en-new-web-app-application-tests.html' title='[en] new web app application tests'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-9202442519760160413</id><published>2010-06-19T18:33:00.006+02:00</published><updated>2010-06-19T18:39:17.038+02:00</updated><title type='text'>[en] nmap on a  multihomed machine with "Linux advanced routing" -&gt; fail</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;# nmap -sS scanme.insecure.org&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Starting Nmap 5.21 ( http://nmap.org ) at 2010-06-19 18:34 CEST&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nexthost: failed to determine route to scanme.insecure.org (64.13.134.52)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;QUITTING!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;# nmap -sT scanme.insecure.org&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Starting Nmap 5.21 ( http://nmap.org ) at 2010-06-19 18:34 CEST&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; nexthost: failed to determine route to scanme.insecure.org (64.13.134.52)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; QUITTING!&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;# route -n &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Kernel IP routing table&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; Destination     Gateway         Genmask         Flags Metric Ref    Use Iface&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 192.168.4.2     0.0.0.0         255.255.255.255 UH    0      0        0 tun0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 192.168.4.0     192.168.4.2     255.255.255.0   UG    0      0        0 tun0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 192.168.1.0     0.0.0.0         255.255.255.0   U     0      0        0 eth2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 192.168.0.0     0.0.0.0         255.255.255.0   U     0      0        0 eth1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 81.57.108.0     0.0.0.0         255.255.255.0   U     0      0        0 eth0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt; 127.0.0.0       0.0.0.0         255.0.0.0       U     0      0        0 lo &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;# &lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-9202442519760160413?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/9202442519760160413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=9202442519760160413&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/9202442519760160413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/9202442519760160413'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/06/en-nmap-multihome-machine.html' title='[en] nmap on a  multihomed machine with &quot;Linux advanced routing&quot; -&gt; fail'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-6573365099032986477</id><published>2010-05-14T16:15:00.005+02:00</published><updated>2011-06-27T21:43:35.462+02:00</updated><title type='text'>Vodafone Greece "Mobile Broadband on Demand"</title><content type='html'>Vodafone sells USB keys with a 10 days "unlimited" 3G access (fair use 10 GB).You'll have only GPRS in remote locations (like small islands).&lt;br /&gt;Linux is unsupported, officially.&lt;br /&gt;On my Gentoo, the key was recognized by the system and I did not even have to configure usb_modeswitch. Just in case, this cannot hurt:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;in /etc/usb_modeswitch.conf&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;# Vodafone Mobile&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;DefaultVendor=  0x19d2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;DefaultProduct= 0x2000&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;TargetVendor=   0x19d2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;TargetProduct=  0x0063&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;MessageEndpoint=0x01&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;MessageContent="5553424308E0CC852400000080000C85000000240000000000000000000000"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;in /etc/udev/rules.d/91-usb_modeswitch.rules&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family: courier new;"&gt;# Vodafone Mobile &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: courier new;"&gt;SUBSYSTEMS=="usb", ATTRS{idVendor}=="19d2", ATTRS{idProduct}=="2000", RUN+="/usr/sbin/usb_modeswitch"&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;All you need is the PAN. I googled for it and found "internet" or "internet.vodafone.gr". None of them work.&lt;br /&gt;The right PAN is &lt;span style="font-weight: bold;"&gt;web.session&lt;/span&gt; in fact. No username/password.&lt;br /&gt;&lt;br /&gt;The key behavior is erratic, even under Windows. Once, I had to unplug it half a dozen times before it worked. I do not know which is responsible, of the phone network or the hardware.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-6573365099032986477?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/6573365099032986477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=6573365099032986477&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/6573365099032986477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/6573365099032986477'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/05/vodafone-greece-mobile-connect.html' title='Vodafone Greece &quot;Mobile Broadband on Demand&quot;'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-2148982647870199811</id><published>2010-05-03T17:53:00.004+02:00</published><updated>2010-05-03T17:58:21.787+02:00</updated><title type='text'>[en] New Nessus web app tests</title><content type='html'>Four new web application tests:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=46196"&gt;XML injection&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=46194"&gt;Path traversal: write access&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=46195"&gt;More path traversal (vicious) attacks&lt;/a&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=46193"&gt;Another XSS test&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-2148982647870199811?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/2148982647870199811/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=2148982647870199811&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2148982647870199811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2148982647870199811'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/05/en-new-web-app-tests.html' title='[en] New Nessus web app tests'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-6634428670908513179</id><published>2010-03-02T20:01:00.003+01:00</published><updated>2010-03-02T20:03:51.052+01:00</updated><title type='text'>[en] HMAP</title><content type='html'>HMAP is an HTTP fingerprinting tool that was written by Dustin Lee.&lt;br /&gt;I slightly changed &lt;span style="font-family: courier new;"&gt;hmap.py&lt;/span&gt; (it raised an exception if the Server field was void) and collected several new signatures.&lt;br /&gt;&lt;a href="http://michel.arboi.free.fr/download/hmap.tar.gz"&gt;http://michel.arboi.free.fr/download/hmap.tar.gz&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-6634428670908513179?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/6634428670908513179/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=6634428670908513179&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/6634428670908513179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/6634428670908513179'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2010/03/en-hmap.html' title='[en] HMAP'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-8748334817155987176</id><published>2009-12-14T23:07:00.004+01:00</published><updated>2009-12-14T23:49:01.842+01:00</updated><title type='text'>[en] SQL injection test</title><content type='html'>Another &lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=43160"&gt;blind SQL injector&lt;/a&gt; for Nessus.&lt;br /&gt;It implements an old technique, but it may still be useful.&lt;br /&gt;Unfortunately, it is limited to MS SQL, not too old MySQL, and very new PostgreSQL.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-8748334817155987176?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/8748334817155987176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=8748334817155987176&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/8748334817155987176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/8748334817155987176'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/12/en-sql-injection-test.html' title='[en] SQL injection test'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-317689563708242868</id><published>2009-11-30T18:13:00.004+01:00</published><updated>2009-12-14T23:05:13.112+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Yet another Mantis XSS</title><content type='html'>&lt;a href="http://host/mantis/view_all_bug_page.php?tag_string=%3C/td%3E%3Cscript%3Ealert%2842%29;%3C/script%3E%3Ctd%3E"&gt;&lt;span style="font-size:85%;"&gt;http://HOST/mantis/view_all_bug_page.php?tag_string=%3C/td%3E%3Cscript%3Ealert%2842%29;%3C/script%3E%3Ctd%3E&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Found by Nessus &lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=39466"&gt;torture_cgi_cross_site_scripting.nasl&lt;/a&gt;, again...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-317689563708242868?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/317689563708242868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=317689563708242868&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/317689563708242868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/317689563708242868'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/11/yet-another-mantis-xss_30.html' title='[en] Yet another Mantis XSS'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-394008071840949817</id><published>2009-11-15T20:21:00.002+01:00</published><updated>2009-12-14T23:05:38.043+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Nessus: 1 / Mantis: 0</title><content type='html'>&lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=39466"&gt;torture_cgi_cross_site_scripting.nasl&lt;/a&gt; found that against Mantis 1.1.8:&lt;br /&gt;&lt;a href="http://HOST//mantis/view_filters_page.php?target_field=%22%3C/script%3E%3Cscript%3Ealert%2842%29;%3C/script%3E"&gt;http://HOST//mantis/view_filters_page.php?target_field=%22%3C/script%3E%3Cscript%3Ealert%2842%29;%3C/script%3E&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-394008071840949817?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/394008071840949817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=394008071840949817&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/394008071840949817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/394008071840949817'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/11/en-nessus-1-mantis-0.html' title='[en] Nessus: 1 / Mantis: 0'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-7422831642246314461</id><published>2009-07-27T15:41:00.002+02:00</published><updated>2009-12-14T23:06:10.327+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Nmap 5.0 est sorti</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mQV1IEgQVR8/Sm2ml_bSWLI/AAAAAAAAABE/VFudD6Hc-oM/s1600-h/nmap50.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 255px;" src="http://1.bp.blogspot.com/_mQV1IEgQVR8/Sm2ml_bSWLI/AAAAAAAAABE/VFudD6Hc-oM/s320/nmap50.png" alt="" id="BLOGGER_PHOTO_ID_5363125902879381682" border="0" /&gt;&lt;/a&gt;Je suis embêté: cette carte mère &lt;grin&gt;ne sait gérer que 4 Go de RAM. Comment faire?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Rouge: RAM en Ko (RSS)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Bleu: mémoire virtuelle en Ko (MEM)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Le temps est en secondes.&lt;/span&gt;&lt;br /&gt;&lt;/grin&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-7422831642246314461?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/7422831642246314461/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=7422831642246314461&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7422831642246314461'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7422831642246314461'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/07/fr-nmap-50-est-sorti.html' title='[fr] Nmap 5.0 est sorti'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mQV1IEgQVR8/Sm2ml_bSWLI/AAAAAAAAABE/VFudD6Hc-oM/s72-c/nmap50.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-7241696847326992309</id><published>2009-07-27T15:06:00.004+02:00</published><updated>2009-12-14T23:05:50.949+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] nmap 5.0 is out</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mQV1IEgQVR8/Sm2ml_bSWLI/AAAAAAAAABE/VFudD6Hc-oM/s1600-h/nmap50.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 320px; height: 255px;" src="http://1.bp.blogspot.com/_mQV1IEgQVR8/Sm2ml_bSWLI/AAAAAAAAABE/VFudD6Hc-oM/s320/nmap50.png" alt="" id="BLOGGER_PHOTO_ID_5363125902879381682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Looks like it slightly leaks memory &lt;grin&gt;.&lt;br /&gt;Here it is on a 64 bits system with 4 GB of RAM.&lt;br /&gt;Red: real memory in KB (RSS)&lt;br /&gt;Blue: virtual memory in KB (MEM)&lt;br /&gt;Time is in seconds.&lt;/grin&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-7241696847326992309?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/7241696847326992309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=7241696847326992309&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7241696847326992309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7241696847326992309'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/07/en-nmap-50-is-out.html' title='[en] nmap 5.0 is out'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mQV1IEgQVR8/Sm2ml_bSWLI/AAAAAAAAABE/VFudD6Hc-oM/s72-c/nmap50.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3287571636673448262</id><published>2009-06-20T01:07:00.005+02:00</published><updated>2009-12-14T23:05:50.949+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] webmasters, tonight, ye dine in hell!</title><content type='html'>&lt;span style="font-family:courier new;"&gt;An updated plugin feed has successfuly been pushed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Serial : 200906191634&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;Changes : &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P DDI_Directory_Scanner.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U display_http_cookies.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P find_service.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U http_audit_settings.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P open_nntp_server.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P opera_925.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P os_fingerprint_http.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U pci_compliance.nbin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U pci_compliance_test_req.nbin&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P scan_info.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P sql_injection.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P tomcat_error_version.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi.inc&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi_command_exec.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi_cross_site_scripting.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi_directory_traversal.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi_header_injection.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi_remote_file_inclusion.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U torture_cgi_timeout.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P torturecgis.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;U web_app_test_settings.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P webmirror.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P websphere_6_1_0_25.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P www_too_long_cookie.nasl&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;P www_too_long_header.nasl&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The old &lt;span style="font-family:courier new;"&gt;torturecgis.nasl&lt;/span&gt; has been deprecated and replaced by &lt;span style="font-family:courier new;"&gt;torture_cgi_*.nasl&lt;/span&gt;.&lt;br /&gt;As far as I know, the new scripts are more efficient, especially the XSS detector.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://discussions.nessus.org/message/2760#2760"&gt;Nessus forum&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blog.tenablesecurity.com/2009/06/enhanced-web-application-attacks-added-to-nessus.html"&gt;Tenable blog&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3287571636673448262?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/3287571636673448262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=3287571636673448262&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3287571636673448262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3287571636673448262'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/06/en-webmasters-tonight-ye-dine-in-hell.html' title='[en] webmasters, tonight, ye dine in hell!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3502511211756167220</id><published>2009-05-04T19:10:00.000+02:00</published><updated>2010-05-04T19:34:15.168+02:00</updated><title type='text'>[en] Calling Nikto from Nessus</title><content type='html'>&lt;a href="http://www.cirt.net/nikto2"&gt;Nikto&lt;/a&gt; is a small and fast web scanner written by Sullo. It is based on RFP's &lt;a href="http://www.wiretrip.net/rfp/lw.asp"&gt;LibWhisker&lt;/a&gt;.&lt;br /&gt;The nikto.nasl plugin can call it from Nessus. I updated it  four months ago to support Nikto2.&lt;br /&gt;The latest Nikto version is 2.02 and it "works for me" with the standard distribution.&lt;br /&gt;&lt;br /&gt;Several Nessus users have reported problems running the plugin. Here are the critical points:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;First you need to run the Nessus daemon on Unix. &lt;span style="font-family:courier new;"&gt;nikto.nasl&lt;/span&gt; will not run on Nessus for Windows.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;nikto.pl&lt;/span&gt; has to be found in &lt;span style="font-family:courier new;"&gt;$PATH&lt;/span&gt; when &lt;span style="font-family:courier new;"&gt;nessusd&lt;/span&gt; is run, i.e. when the plugins are compiled &lt;span style="font-weight: bold;"&gt;and&lt;/span&gt; when the daemon is started. Nessus does not look for any other command name (nikto, nikto.sh, etc.) that may be installed by any distro-tuned package.&lt;br /&gt;The file (under &lt;span style="font-family:courier new;"&gt;/opt/nessus/lib/nessus/plugins&lt;/span&gt;) is &lt;span style="font-family:courier new;"&gt;nikto.nasl&lt;/span&gt;, the script ID is 14260, the name is "Nikto (NASL wrapper)", you should find in the "CGI abuses" family. If you do not see it, fix your &lt;span style="font-family:courier new;"&gt;$PATH&lt;/span&gt;, make sure that &lt;span style="font-family:courier new;"&gt;nikto.pl&lt;/span&gt; is executable, rerun &lt;span style="font-family:courier new;"&gt;nessusd -R&lt;/span&gt; and restart the daemon.&lt;br /&gt;A good place to set up&lt;span style="font-family:courier new;"&gt; $PATH&lt;/span&gt; is your Nessus start-up script; try &lt;span style="font-family:courier new;"&gt;/etc/init.d/nessusd&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/span&gt; or &lt;span style="font-family:courier new;"&gt;/etc/init.d/rc&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Some people/distros install &lt;span style="font-family:courier new;"&gt;nikto.pl&lt;/span&gt; into a specific directory like &lt;span style="font-family:courier new;"&gt;/opt/nikto-2.02/&lt;/span&gt; and add a link &lt;span style="font-family:courier new;"&gt;/usr/local/bin/nikto.pl&lt;/span&gt;. This will not work as you need to go into the Nikto directory before launching the command; otherwise, Nikto will not find its data files. Nessus does not read the link and would chdir to &lt;span style="font-family:courier new;"&gt;/usr/local/bin&lt;/span&gt; instead of &lt;span style="font-family:courier new;"&gt;/opt/nikto-2.02&lt;/span&gt;.&lt;br /&gt;If the plugin is listed, it is run (according to &lt;span style="font-family:courier new;"&gt;/opt/nessus/var/nessus/nessusd.messages&lt;/span&gt;) but it does not produce any output, you may well be in this bad configuration.&lt;br /&gt;Either remove the link or make sure that &lt;span style="font-family:courier new;"&gt;/opt/nikto-2.02&lt;/span&gt; appears &lt;span style="font-weight: bold;"&gt;before&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;/usr/local/bin&lt;/span&gt; in  $PATH.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Last but not least, &lt;span style="font-family:courier new;"&gt;nikto.nasl&lt;/span&gt; is disabled by default. You'll have to change its preferences (if you are running NessusClient3, edit your policy, click on the "Advanced" tab and select "Nikto (NASL wrapper)"). Change "Enable Nikto" from "no" to "yes".&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;This installation sequence should work:&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;cd /opt&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tar jxvf ..../nikto-2.02.tar.bz2 &lt;/span&gt;&lt;br /&gt;# This will create a nikto-2.02 directory&lt;br /&gt;# make sure that /opt/nikto-2.02/nikto.pl exists and is executable&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PATH=/opt/nikto-2.02:$PATH; export PATH&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nessusd -R&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;killall nessusd&lt;/span&gt;        # if necessary&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nessusd -D&lt;/span&gt;                        # add other options if necessary&lt;br /&gt;&lt;br /&gt;The plugin automatically selects some options, like SSL support or virtual host name (which is supported by HTTP/1.1 only). It will not run against web server that do not send back a 404 code on non existent pages, because Nikto is prone to verbose false alerts in that case.&lt;br /&gt;I did not play with all options, some of them may be broken or incompatible with Nessus. Feel free to e-mail me if you find such cases.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3502511211756167220?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3502511211756167220'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3502511211756167220'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/05/en-calling-nikto-from-nessus.html' title='[en] Calling Nikto from Nessus'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-514274411872645432</id><published>2009-01-17T14:00:00.004+01:00</published><updated>2009-01-17T16:03:54.518+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberspace'/><title type='text'>DNS... WTF?</title><content type='html'>&lt;preformatted&gt;&lt;span style="font-size:85%;"&gt;Jan 17 13:53:33 [named] client 69.50.142.11#8500: query (cache) './NS/IN' denied&lt;br /&gt;Jan 17 13:53:34 [named] client 69.50.142.11#62054: query (cache) './NS/IN' denied&lt;br /&gt;Jan 17 13:53:34 [named] client 69.50.142.11#50405: query (cache) './NS/IN' denied&lt;br /&gt;Jan 17 13:53:37 [named] client 69.50.142.11#38682: query (cache) './NS/IN' denied&lt;br /&gt;Jan 17 13:53:39 [named] client 69.50.142.11#47266: query (cache) './NS/IN' denied&lt;br /&gt;&lt;br /&gt;# bzgrep -l "client 69.50.142.11#" log-2009-*.bz2&lt;br /&gt;log-2009-01-08-14:01:54.bz2&lt;br /&gt;log-2009-01-16-20:01:54.bz2&lt;br /&gt;log-2009-01-16-23:01:42.bz2&lt;br /&gt;log-2009-01-17-02:01:49.bz2&lt;br /&gt;log-2009-01-17-05:01:55.bz2&lt;br /&gt;log-2009-01-17-08:01:50.bz2&lt;br /&gt;log-2009-01-17-11:01:04.bz2&lt;br /&gt;# bzgrep "client 69.50.142.11#" log-2009-*.bz2 | wc -l&lt;br /&gt;33464&lt;br /&gt;#&lt;br /&gt;&lt;/span&gt;&lt;/preformatted&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update&lt;/span&gt;&lt;br /&gt;I got a quick answer from their hosting company. According to them, the source IP is fake and this is a DOS.&lt;br /&gt;Rather lame, IMHO: a DNS answer is small. If the cracker can fake the source IP, he can directly flood the victim with more data than my DNS server...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-514274411872645432?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/514274411872645432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=514274411872645432&amp;isPopup=true' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/514274411872645432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/514274411872645432'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2009/01/dns-wtf.html' title='DNS... WTF?'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3770234184154063382</id><published>2008-08-23T17:48:00.006+02:00</published><updated>2008-08-23T18:02:00.781+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] le lièvre, la tortue et le portscanner</title><content type='html'>Je loue depuis peu un petit serveur disposant d'une connexion à 100 Mb/s sur Internet. J'ai scanné ma connexion ADSL depuis la bête. Le RTT fluctue entre 35 et 70 ms environ.&lt;br /&gt;nessus_tcp_scanner: 15 ports ouverts, 1 port rejeté, 3 ports silencieux, 65516 ports fermés. Tout ça en 101 s.&lt;br /&gt;nmap v4.53, aggressive timing (-T 4): 15 ports ouverts,4 ports filtrés, 65516 ports fermés. En 658 s.&lt;br /&gt;Répétez après moi: "nmap est le meilleur scanner du marché".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3770234184154063382?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/3770234184154063382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=3770234184154063382&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3770234184154063382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3770234184154063382'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/08/fr-le-livre-la-tortue-et-le-portscanner.html' title='[fr] le lièvre, la tortue et le portscanner'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-4512305679978472553</id><published>2008-08-04T21:29:00.005+02:00</published><updated>2008-12-03T21:08:50.634+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberspace'/><title type='text'>[fr] Chi va piano va sano et va lontano</title><content type='html'>Dimanche, en sirotant mon café matinal, je mets à jour l'arbre des portages Gentoo et je suis étonné de voir passer une mise à jour de BIND, alors que je crois vaguement me souvenir d'en avoir vu passer une ultra-importante (bien qu'ultra-secrète et totalement obfusquée &amp;lt;grin&amp;gt;) peu de temps auparavant. Mon café fini et mon cerveau plus en marche, ça se confirme: bind 9.4.2_p2 veut s'installer sur mes pingouins.&lt;br /&gt;Allons donc chercher le Changelog du monstre.&lt;br /&gt;Pour la 9.4.2_p1, c'est vite vu:&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;2375.   [security]      Fully randomize UDP query ports to improve forgery resilience. [RT #17949]&lt;/blockquote&gt;&lt;br /&gt;Simple, net, et même sans café, j'arrive à m'en souvenir tellement j'en ai entendu parler.&lt;br /&gt;Pour la 9.4.2_p2, accrochez-vous!&lt;br /&gt;&lt;blockquote&gt;2406.   [bug]           Some operating systems have FD_SETSIZE set to a low value by default, which can cause resource exhaustion when many simultaneous connections are open.  Linux in particular makes it difficult to increase this value.  To use more sockets with select(), set ISC_SOCKET_FDSETSIZE.  Example:&lt;br /&gt;STD_CDEFINES="-DISC_SOCKET_FDSETSIZE=4096" ./configure&lt;br /&gt;(This should not be necessary in most cases, and never for an authoritative-only server.) [RT #18328]&lt;br /&gt;2404.    [port]        hpux: files unlimited support.&lt;br /&gt;2403.    [bug]        TSIG context leak. [RT #18341]&lt;br /&gt;2402.    [port]        Support Solaris 2.11 and over. [RT #18362]&lt;br /&gt;2401.    [bug]        Expect to get E[MN]FILE errno internal_accept() (from accept() or fcntl() system calls). [RT #18358]&lt;br /&gt;2399.    [bug]        Abort timeout queries to reduce the number of open UDP sockets. [RT #18367]&lt;br /&gt;2398.    [bug]           Improve file descriptor management.  New, temporary, named.conf option reserved-sockets, default 512. [RT #18344]&lt;br /&gt;2396.    [bug]        Don't set SO_REUSEADDR for randomized ports. [RT #18336]&lt;br /&gt;2395.    [port]        Avoid warning and no effect from "files unlimited" on Linux when running as root. [RT #18335]&lt;br /&gt;2394.    [bug]        Default configuration options set the limit for open files to 'unlimited' as described in the documentation. [RT #18331]&lt;br /&gt;2392.    [bug]        remove 'grep -q' from acl test script, some platforms don't support it. [RT #18253]&lt;br /&gt;2322.    [port]        MacOS: work around the limitation of setrlimit() for RLIMIT_NOFILE. [RT #17526]&lt;br /&gt;&lt;/blockquote&gt;Je vous laisse compter les termes "limit" et "exhaustion" puis élaborer des hypothèses fumeuses sur la sortie en catastrophe de ce patch.&lt;br /&gt;Je vous rappelle que si Deputy Dan a caché les détails de son attaque, c'était pour laisser aux vendeurs le temps de se retourner et de nous préparer des beaux patchs bien testés, mais pour faire sa pub, hein?&lt;br /&gt;J'espère sincèrement qu'il aura son &lt;a href="http://pwnie-awards.org/2008/awards.html#overhypedbug"&gt;pwnie award&lt;/a&gt;!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-4512305679978472553?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/4512305679978472553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=4512305679978472553&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/4512305679978472553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/4512305679978472553'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/08/chi-va-piano-va-sano-et-va-lontano.html' title='[fr] Chi va piano va sano et va lontano'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-7234219010133241947</id><published>2008-05-12T16:38:00.005+02:00</published><updated>2008-08-04T21:55:05.123+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberspace'/><title type='text'>[fr] Du bon usage du conditionnel</title><content type='html'>Quand on est un gentil youzeur qui a acheté (cher) son Windows, on a droit aux mises à jour qui protègent des haX0rz, des virus et du phyloxéra. Microsoft, dans sa grande bonté, et dans le souci de protéger Internet et ses fidèles clients des script kiddies distribue depuis quelque temps le Service Pack3 de Windows XP.&lt;br /&gt;Avant d'appuyer sur "Installer", on voit ceci:&lt;br /&gt;&lt;blockquote&gt;Windows XP Service Pack 3 (SP3) est une mise à jour de Windows XP qui intègre les principaux commentaires transmis par nos clients. Cette mise à jour cumulative inclut toutes les mises à jour publiées précédemment pour Windows XP, y compris les mises à jour de sécurité. Windows XP SP3 comprend un petit nombre de nouvelles mises à jour, mais ne &lt;span style="font-weight: bold;"&gt;devrait&lt;/span&gt; pas modifier de manière &lt;span style="font-weight: bold;"&gt;significative&lt;/span&gt; les fonctionnalités de ce système d'exploitation. Une fois cette installation terminée, vous serez &lt;span style="font-weight: bold;"&gt;peut-être&lt;/span&gt; amené à &lt;span style="font-weight: bold;"&gt;redémarrer&lt;/span&gt; l'ordinateur. &lt;/blockquote&gt;Un lecteur averti aura remarqué les précautions oratoires dont s'entoure Microsoft pour annoncer la sortie du petit dernier. Mais voila: le youzeur de base n'est pas averti, il clique sur "Yes", "Oui", "Da", "Ja", "Si"..., dès qu'on lui demande s'il veut installer un screensaver, un spyware, un cheval de Troie, un antivirus ou un patch. Ensuite il gueule et ça donne du grain à moudre aux journalistes compatissants: &lt;a href="http://www.informationweek.com/news/windows/operatingsystems/showArticle.jhtml?articleID=207600950"&gt;Windows XP SP3 sows Havoc, users complain&lt;/a&gt;.&lt;br /&gt;Il s'avère que les fonctionnalités du dit système d'exploitation sont modifiées de manière &lt;span style="font-weight: bold;"&gt;significative&lt;/span&gt; (ça ne marche plus), ou que les youzeurz auraient bien été contents d'être amenés à &lt;span style="font-weight: bold;"&gt;redémarrer&lt;/span&gt; l'ordinateur, parce que justement, il ne démarre plus.&lt;br /&gt;Étant joueur mais pas complètement  cinglé non plus, j'ai pris un snapshot de ma &lt;a href="http://www.vmware.com/"&gt;machine virtuelle&lt;/a&gt; avant d'installer cette saleté, pour voir, des fois que le patch &lt;span style="font-weight: bold;"&gt;affecterait&lt;/span&gt; de manière &lt;span style="font-weight: bold;"&gt;significative&lt;/span&gt; (voire &lt;span&gt;délètère)&lt;/span&gt; le fonctionnement de &lt;strike&gt;cette poubelle&lt;/strike&gt; ce système.&lt;br /&gt;Ça s'estbien terminé, il n'y a de la chance que pour la canaille.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-7234219010133241947?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/7234219010133241947/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=7234219010133241947&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7234219010133241947'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7234219010133241947'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/05/fr-du-bon-usage-du-conditionnel.html' title='[fr] Du bon usage du conditionnel'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3381778407520233164</id><published>2008-05-01T12:53:00.011+02:00</published><updated>2009-05-20T11:10:03.833+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Calling Nikto from Nessus</title><content type='html'>&lt;a href="http://www.cirt.net/nikto2"&gt;Nikto&lt;/a&gt; is a small and fast web scanner written by Sullo. It is based on RFP's &lt;a href="http://www.wiretrip.net/rfp/lw.asp"&gt;LibWhisker&lt;/a&gt;.&lt;br /&gt;The nikto.nasl plugin can call it from Nessus. I updated it  four months ago to support Nikto2.&lt;br /&gt;The latest Nikto version is 2.02 and it "works for me" with the standard distribution.&lt;br /&gt;&lt;br /&gt;Several Nessus users have reported problems running the plugin. Here are the critical points:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;First you need to run the Nessus daemon on Unix. &lt;span style="font-family:courier new;"&gt;nikto.nasl&lt;/span&gt; will not run on Nessus for Windows.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:courier new;"&gt;nikto.pl&lt;/span&gt; has to be found in &lt;span style="font-family:courier new;"&gt;$PATH&lt;/span&gt; when &lt;span style="font-family:courier new;"&gt;nessusd&lt;/span&gt; is run, i.e. when the plugins are compiled &lt;span style="font-weight: bold;"&gt;and&lt;/span&gt; when the daemon is started. Nessus does not look for any other command name (nikto, nikto.sh, etc.) that may be installed by any distro-tuned package.&lt;br /&gt;The file (under &lt;span style="font-family:courier new;"&gt;/opt/nessus/lib/nessus/plugins&lt;/span&gt;) is &lt;span style="font-family:courier new;"&gt;nikto.nasl&lt;/span&gt;, the script ID is 14260, the name is "Nikto (NASL wrapper)", you should find in the "CGI abuses" family. If you do not see it, fix your &lt;span style="font-family:courier new;"&gt;$PATH&lt;/span&gt;, make sure that &lt;span style="font-family:courier new;"&gt;nikto.pl&lt;/span&gt; is executable, rerun &lt;span style="font-family:courier new;"&gt;nessusd -R&lt;/span&gt; and restart the daemon.&lt;br /&gt;A good place to set up&lt;span style="font-family:courier new;"&gt; $PATH&lt;/span&gt; is your Nessus start-up script; try &lt;span style="font-family:courier new;"&gt;/etc/init.d/nessusd&lt;span style="font-family: arial;"&gt;&lt;/span&gt;&lt;/span&gt; or &lt;span style="font-family: courier new;"&gt;/etc/init.d/rc&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Some people/distros install &lt;span style="font-family:courier new;"&gt;nikto.pl&lt;/span&gt; into a specific directory like &lt;span style="font-family:courier new;"&gt;/opt/nikto-2.02/&lt;/span&gt; and add a link &lt;span style="font-family:courier new;"&gt;/usr/local/bin/nikto.pl&lt;/span&gt;. This will not work as you need to go into the Nikto directory before launching the command; otherwise, Nikto will not find its data files. Nessus does not read the link and would chdir to &lt;span style="font-family:courier new;"&gt;/usr/local/bin&lt;/span&gt; instead of &lt;span style="font-family:courier new;"&gt;/opt/nikto-2.02&lt;/span&gt;.&lt;br /&gt;If the plugin is listed, it is run (according to &lt;span style="font-family:courier new;"&gt;/opt/nessus/var/nessus/nessusd.messages&lt;/span&gt;) but it does not produce any output, you may well be in this bad configuration.&lt;br /&gt;Either remove the link or make sure that &lt;span style="font-family:courier new;"&gt;/opt/nikto-2.02&lt;/span&gt; appears &lt;span style="font-weight: bold;"&gt;before&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;/usr/local/bin&lt;/span&gt; in  $PATH.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Last but not least, &lt;span style="font-family:courier new;"&gt;nikto.nasl&lt;/span&gt; is disabled by default. You'll have to change its preferences (if you are running NessusClient3, edit your policy, click on the "Advanced" tab and select "Nikto (NASL wrapper)"). Change "Enable Nikto" from "no" to "yes".&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;This installation sequence should work:&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;cd /opt&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;tar jxvf ..../nikto-2.02.tar.bz2 &lt;/span&gt;&lt;br /&gt;# This will create a nikto-2.02 directory&lt;br /&gt;# make sure that /opt/nikto-2.02/nikto.pl exists and is executable&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;PATH=/opt/nikto-2.02:$PATH; export PATH&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nessusd -R&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;killall nessusd&lt;/span&gt;        # if necessary&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;nessusd -D&lt;/span&gt;                        # add other options if necessary&lt;br /&gt;&lt;br /&gt;The plugin automatically selects some options, like SSL support or virtual host name (which is supported by HTTP/1.1 only). It will not run against web server that do not send back a 404 code on non existent pages, because Nikto is prone to verbose false alerts in that case.&lt;br /&gt;I did not play with all options, some of them may be broken or incompatible with Nessus. Feel free to e-mail me if you find such cases.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3381778407520233164?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/3381778407520233164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=3381778407520233164&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3381778407520233164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3381778407520233164'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/05/en-calling-nikto-from-nessus.html' title='[en] Calling Nikto from Nessus'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-1887517915539248603</id><published>2008-04-12T22:36:00.004+02:00</published><updated>2008-04-12T22:50:36.069+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Does Vista piss you off?</title><content type='html'>If Vista pisses you off, don't worry, that's perfectly normal: it was designed to. That's &lt;a href="http://news.zdnet.com/2424-3515_22-197089.html"&gt;official&lt;/a&gt; now:&lt;b&gt;&lt;br /&gt;&lt;blockquote&gt;SAN FRANCISCO--A Microsoft manager has said that one of the security features in Vista was deliberately designed to "annoy users" to put pressure on third-party software makers to make their applications more secure.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;/b&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;span&gt;Unfortunately, Microsoft software also triggers the PITA  (Pain In The A...) &lt;/span&gt;&lt;span&gt;function.&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;It's not a bug, it's a feature&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-1887517915539248603?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/1887517915539248603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=1887517915539248603&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/1887517915539248603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/1887517915539248603'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/04/en-does-vista-piss-you-off.html' title='[en] Does Vista piss you off?'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3478653431967054092</id><published>2008-04-12T22:33:00.002+02:00</published><updated>2008-04-12T22:48:20.037+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Vista est chiant!</title><content type='html'>Vista est chiant, c'est &lt;a href="http://news.zdnet.com/2424-3515_22-197089.html"&gt;officiel&lt;/a&gt;. Et en plus, c'est fait pour.&lt;br /&gt;&lt;b&gt;&lt;blockquote&gt;SAN FRANCISCO -- Un dirigeant de Microsoft a dit que l'une des fonctions de sécurité de Vista a été délibérément conçue pour "ennuyer les utilisateurs" pour faire pression sur les fabricants de logiciels tiers pour rendre leurs applications plus sûres.&lt;/blockquote&gt;&lt;/b&gt;Ce qui n'est pas dit dans ce beau titre plein de bonnes intentions, c'est que des applications Microsoft déclenchent aussi la fonction chiante.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;It's not a bug, it's a feature&lt;/span&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3478653431967054092?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/3478653431967054092/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=3478653431967054092&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3478653431967054092'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3478653431967054092'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/04/vista-est-chiant.html' title='[fr] Vista est chiant!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-2270968351442548366</id><published>2008-03-15T17:08:00.007+01:00</published><updated>2008-03-22T23:27:41.036+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Nessus 3.2 is out!</title><content type='html'>&lt;a href="http://www.nessus.org/"&gt;Nessus&lt;/a&gt; 3.2 was announced on 2008-03-12. It contains  &lt;a href="http://www.nessus.org/news/index.php#126"&gt;many improvements&lt;/a&gt; for which I have no responsibility, and a new version of nessus_tcp_scanner.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Simplified options&lt;br /&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Two former boolean options (and a new one that was not seen by anybody but me) were merged into a single &lt;span style="font-style: italic;"&gt;Firewall detection&lt;/span&gt; four level cursor:&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;li&gt;Disabled&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Do not detect RST rate limitation&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Normal / automatic&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Ignore closed ports&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Congestion&lt;/span&gt;&lt;span style="font-style: italic;"&gt; detection&lt;/span&gt; was removed, it is now hidden in &lt;span style="font-family:courier new;"&gt;nessusd.conf&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Scan ports in random order&lt;/span&gt; is still here, although I don't think that many people will ever touch it.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Unfiltered ports are regularly probed.&lt;br /&gt;I added that first to get a better RTT (ping time) estimation; this is a crucial parameter for a userland TCP scanner. This feature is also (mainly?) used now to detect congestion.&lt;br /&gt;This piece of code works on any OS and is more sensitive than the previous kernelland (Linux only) detector -- I don't criticize the Penguin, I'm still amazed that this kernelland detector works with a such a psychotic  software; portscan is definitely not a "normal" use of a TCP/IP stack.&lt;br /&gt;As the detector detects rather well, I slightly increased the aggressivity of the cyber-monster.&lt;br /&gt;I hope that very slow links can now be scanned in a reasonable time without being overloaded even in hellish conditions (lost packets, long &amp;amp; changing RTT), at worst by using the most cautious parameters:&lt;/li&gt;&lt;ul&gt;&lt;li&gt;safe_checks=1&lt;/li&gt;&lt;li&gt;max_checks=1&lt;/li&gt;&lt;li&gt;Firewall detection=Disabled&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;To avoid interminable scans (they do not make much sense), the scanner gets restless after 40 minutes (default value). At the first timeout, it moves the aggressivity cursor to the fourth choice (&lt;span style="font-style: italic;"&gt;ignore closed ports&lt;/span&gt;), at the second, it stops at the end of the current phase, at the third, it does sepuku at once.&lt;br /&gt;Finally, for the ones who are eager to shoot themselves in the foot, here are a few hidden option from &lt;span style="font-family:courier new;"&gt;nessusd.conf&lt;/span&gt;, with their default values:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;nessus_tcp_scanner.send_regular_probes=yes&lt;/li&gt;&lt;li&gt;nessus_tcp_scanner.unlimited_rtt=no&lt;/li&gt;&lt;li&gt;nessus_tcp_scanner.portscan_timeout=2400&lt;/li&gt;&lt;li&gt;use_kernel_congestion_detection=no  (was "yes" en 3.0 et 3.1)&lt;/li&gt;&lt;li&gt;stop_scan_on_disconnect=yes&lt;/li&gt;&lt;li&gt;nessus_tcp_scanner.max_pass=16&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-2270968351442548366?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/2270968351442548366/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=2270968351442548366&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2270968351442548366'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/2270968351442548366'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/03/nessus-32-is-out.html' title='[en] Nessus 3.2 is out!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-5074846109114385116</id><published>2008-03-12T23:50:00.006+01:00</published><updated>2008-03-17T23:59:54.275+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Nessus 3.2 est sorti!</title><content type='html'>&lt;a href="http://www.nessus.org/"&gt;Nessus&lt;/a&gt; 3.2 est sorti le 12/03/2008 et outre &lt;a href="http://www.nessus.org/news/index.php#126"&gt;moult améliorations&lt;/a&gt; dans lesquelles je n'ai pas trempé because closed source, il inclut une nouvelle version de nessus_tcp_scanner.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Préférences simplifiées&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Deux anciennes options booléennes (et une nouvelle que personne n'a jamais vue) ont été fusionnées en un seul curseur &lt;span style="font-style: italic;"&gt;Firewall detection&lt;/span&gt;, qui offre 4 niveaux:&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;ul&gt;&lt;li&gt;Disabled&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Do not detect RST rate limitation&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Normal / automatic&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Ignore closed ports&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Congestion&lt;/span&gt;&lt;span style="font-style: italic;"&gt; detection&lt;/span&gt; a été supprimée, elle est maintenant cachée dans &lt;span style="font-family:courier new;"&gt;nessusd.conf&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;L'option &lt;span style="font-style: italic;"&gt;Scan ports in random order&lt;/span&gt; reste, bien que je ne sois pas sûr que grand monde la touche.&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Les ports non filtrés sont régulièrement sondés.&lt;br /&gt;J' avais ajouté ça dans un premier temps pour obtenir une meilleure estimation du RTT (ping time), paramètre crucial pour un TCP scanner en userland. On s'en sert aussi (surtout?) pour détecter la congestion.&lt;br /&gt;Ce code marche sur tous les OS et est plus sensible que le détecteur kernelland de Linux précédemment utilisé (ne critiquons pas le pingouin, que ce détecteur kernel fonctionne avec un logiciel aussi psychopathe qu'un portscanner est miraculeux).&lt;br /&gt;Le détecteur détectant bien, j'ai un peu lâché la bride du monstre.&lt;br /&gt;J'espère que les liens très lents pourront être scannés en un temps raisonnable sans être surchargés même dans des conditions infernales (pertes de paquets, RTT important et fluctuant), en mettant les paramètres au minimum dans le pire des cas:&lt;/li&gt;&lt;ul&gt;&lt;li&gt;safe_checks=1&lt;/li&gt;&lt;li&gt;max_checks=1&lt;/li&gt;&lt;li&gt;Firewall detection=Disabled&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;Pour éviter les scans interminables, qui n'ont pas grand sens, le scanner s'impatiente au bout d'un temps de 40 min par défaut. Au premier coup de gong, il pousse le curseur d'agressivité à fond, au second, il termine la passe en cours et s'arrête, au troisième, il fait sepuku immédiatement.&lt;br /&gt;Enfin, pour ceux qui ont envie de se tirer dans le pied, la bête offre quelques options cachées dans &lt;span style="font-family:courier new;"&gt;nessusd.conf&lt;/span&gt;, dont voici les valeurs par défaut:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;nessus_tcp_scanner.send_regular_probes=yes&lt;/li&gt;&lt;li&gt;nessus_tcp_scanner.unlimited_rtt=no&lt;/li&gt;&lt;li&gt;nessus_tcp_scanner.portscan_timeout=2400&lt;/li&gt;&lt;li&gt;use_kernel_congestion_detection=no  (c'était "yes" en 3.0 et 3.1)&lt;/li&gt;&lt;li&gt;stop_scan_on_disconnect=yes&lt;/li&gt;&lt;li&gt;nessus_tcp_scanner.max_pass=16&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-5074846109114385116?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/5074846109114385116/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=5074846109114385116&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/5074846109114385116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/5074846109114385116'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/03/nessus-32-est-sorti.html' title='[fr] Nessus 3.2 est sorti!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-7968703790838324358</id><published>2008-03-05T00:35:00.004+01:00</published><updated>2008-03-05T00:53:56.490+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><category scheme='http://www.blogger.com/atom/ns#' term='prog'/><title type='text'>[en] Crude port scanner</title><content type='html'>It takes less than 2 pages of code, and on a LAN, it is quick and reliable. On a WAN, it is brutal, not very reliable, but not so awful. Writing a smart portscanner is nothing but a waste of time...&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://michel.arboi.free.fr/download/bourrin1.c"&gt;Unix version&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://michel.arboi.free.fr/download/bourrin2.c"&gt;Linux epoll version&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-7968703790838324358?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/7968703790838324358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=7968703790838324358&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7968703790838324358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7968703790838324358'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/03/en-crude-port-scanner.html' title='[en] Crude port scanner'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-7870862654449317505</id><published>2008-03-05T00:27:00.004+01:00</published><updated>2008-03-05T00:40:46.062+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><category scheme='http://www.blogger.com/atom/ns#' term='prog'/><title type='text'>[en] Real men don't scan</title><content type='html'>Port&lt;span style="font-style: italic;"&gt;scan&lt;/span&gt; is for the weak users who cannot open 65535 sockets at once.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://michel.arboi.free.fr/download/nonscanner1.c"&gt;Unix version&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://michel.arboi.free.fr/download/nonscanner2.c"&gt;Linux epoll version&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:78%;"&gt;You'll probably need to be &lt;span style="font-family:courier new;"&gt;root&lt;/span&gt; to run this. And you'd better check that you have enough file descriptors on your operating system.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-7870862654449317505?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/7870862654449317505/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=7870862654449317505&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7870862654449317505'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/7870862654449317505'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/03/en-real-men-dont-scan.html' title='[en] Real men don&apos;t scan'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-933017800668334382</id><published>2008-02-03T23:24:00.000+01:00</published><updated>2008-03-05T00:41:31.459+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] excès de vitesse</title><content type='html'>J'adore quand les journalistes donnent des chiffres précis... mais faux. Lu sur &lt;a href="http://actu.voila.fr/Article/mmd--francais--journal_internet--ins/La-Nasa-fan-des-Beatles-va-diffuser-une-de-leurs-chansons-dans-l-univers.html"&gt;actu.voila.fr&lt;/a&gt;:&lt;br /&gt;&lt;h4&gt;La chanson voyagera dans l'univers à la vitesse de quelque 307.000 km à la seconde.&lt;/h4&gt;Les physiciens ont décidé de leur côté que la &lt;a href="http://fr.wikipedia.org/wiki/Vitesse_de_la_lumi%C3%A8re"&gt;lumière&lt;/a&gt; se trainerait dans le vide à seulement 299792,458 km/s.&lt;br /&gt;À moins qu'il y ait eu une petite inflation lors du passage à l'euro?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-933017800668334382?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/933017800668334382/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=933017800668334382&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/933017800668334382'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/933017800668334382'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/02/fr-excs-de-vitesse.html' title='[fr] excès de vitesse'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-6944434003496666208</id><published>2008-01-20T19:33:00.000+01:00</published><updated>2008-03-05T00:40:46.062+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Medusa</title><content type='html'>&lt;a href="http://www.foofus.net/jmk/medusa/medusa.html"&gt;Medusa&lt;/a&gt; NASL wrappers for &lt;a href="http://www.nessus.org/"&gt;Nessus&lt;/a&gt;...&lt;br /&gt;&lt;a href="http://michel.arboi.free.fr/download/medusa.tgz"&gt;http://michel.arboi.free.fr/download/medusa.tgz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;NB: you'll have to set &lt;span style="font-family:courier new;"&gt;nasl_no_signature_check=yes&lt;/span&gt; in &lt;span style="font-family:courier new;"&gt;/opt/nessus/etc/nessus/nessusd.conf&lt;br /&gt;&lt;/span&gt;or add &lt;a href="http://michel.arboi.free.fr/download/MA.pub.pem"&gt;my key&lt;/a&gt; in &lt;span style="font-family:courier new;"&gt;/opt/nessus/var/nessus/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-6944434003496666208?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/6944434003496666208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=6944434003496666208&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/6944434003496666208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/6944434003496666208'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2008/01/en-medusa.html' title='[en] Medusa'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-3987046885036665204</id><published>2007-11-02T11:54:00.000+01:00</published><updated>2008-03-05T00:41:31.460+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberspace'/><title type='text'>[fr] aïlle spique globiche</title><content type='html'>Voila que je reçois des spams en dialecte &lt;a href="http://fr.wikipedia.org/wiki/Anti-France"&gt;anti-français&lt;/a&gt;. Au secours &lt;a href="http://fr.wikipedia.org/wiki/Superdupont"&gt;super Dupont&lt;/a&gt;!&lt;br /&gt;&lt;a href="http://bogofilter.sourceforge.net/"&gt;bogofilter&lt;/a&gt; n'y a vu que du feu, mais &lt;a href="http://spamassassin.apache.org/"&gt;SpamAssassin&lt;/a&gt; l'a salé -- il aurait dû finir à la poubelle, il faut que je répare mes filtres.&lt;br /&gt;Ça m'aura fait bien ricaner en tout cas.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Bonjour&lt;br /&gt;Mr.Ekoh Joseph&lt;br /&gt;&lt;br /&gt;Je suppose que cette e-mail vous surprise , mais c'est moi est véritablement, pendant une routines de ré-examen dans ma Banque(Standard- une banque de sud Afrique)où  je travaille, sur une compte a été pousséque pas  demandé, où &lt;span style="font-weight: bold;"&gt;derzeit&lt;/span&gt; $12,500,000 (Douze &lt;span style="font-weight: bold;"&gt;millione&lt;/span&gt;, cinq cents mille &lt;span style="font-weight: bold;"&gt;dollard&lt;/span&gt;' États-Unis ) est crédité.a Cette compte Monsieur appartenu&lt;br /&gt;&lt;br /&gt;Manfred Becker qui était un &lt;span style="font-weight: bold;"&gt;Kunde&lt;/span&gt; dans notre banque qui &lt;span style="font-weight: bold;"&gt;estmalheureusement&lt;/span&gt; décédé.Monsieur Becker était un citoyen &lt;span style="font-weight: bold;"&gt;French&lt;/span&gt;. Afin qu'il soit possible pour moi cette argent $12,500,000 j'aimerais avoir la coopération d'un partenaire étranger comme vous qui va m'aider comme l'homme a qui est a&lt;br /&gt;&lt;br /&gt;l'argent.Vous allez aussi utiliser cette argent de faire toutes ce que nous voulons, moi et mes &lt;span style="font-weight: bold;"&gt;colleagues&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;Apres&lt;/span&gt; avoir faire tout, nous puissions prendre l'argent Pour ce soutien, vous recevez 30% et les 70% restants divisez entre moi et mes deux collègues avec qui je travail et qui me soutiennent également pour cette transaction. si vous êtes &lt;span style="font-weight: bold;"&gt;intéressér&lt;/span&gt;, pouvez vous me demandez un e-mail d'envoyer, afin que je puisse vous faire parvenir plus de détails.&lt;br /&gt;&lt;br /&gt;Veuillez envoyer votre réponse à ce adresse E-Mail:jekoh2@aim.com&lt;br /&gt;&lt;br /&gt;Merci beaucoup et salutations distinguées&lt;br /&gt;&lt;br /&gt;Mr.Ekoh Joseph&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-3987046885036665204?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/3987046885036665204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=3987046885036665204&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3987046885036665204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/3987046885036665204'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2007/11/fr-alle-spique-globiche.html' title='[fr] aïlle spique globiche'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-8868918927224443115</id><published>2007-05-12T00:12:00.000+02:00</published><updated>2008-03-05T00:41:31.460+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberspace'/><title type='text'>[fr] abuse</title><content type='html'>J'ai reçu cette semaine un message d'&lt;span style="font-family:courier new;"&gt;abuse@mon_FAI&lt;/span&gt; me demandant de cesser de tenter de pirater le site d'un quidam. J'avais osé envoyé vers ce site ces abomiffreuses requêtes:&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;HEAD / HTTP/1.0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;OPTIONS / HTTP/1.0&lt;/span&gt;&lt;br /&gt;Après un bref échange durant lequel je n'ai pas caché mon agacement, &lt;span style="font-family:courier new;"&gt;abuse&lt;/span&gt; a capitulé et est parti vaquer à d'autres occupations — peut-être lire les RFC &lt;a href="ftp://ftp.rfc-editor.org/in-notes/rfc1945.txt"&gt;1945&lt;/a&gt; et &lt;a href="ftp://ftp.rfc-editor.org/in-notes/rfc2616.txt"&gt;2616&lt;/a&gt; que je lui avais "conseillés"?&lt;br /&gt;&lt;br /&gt;J'ai envoyé ensuite un message assez corrosif au crétin qui s'était plaint. Il a encore trouvé le moyen de ramener sa gueule.&lt;br /&gt;Le problème avec Internet, c'est qu'on a une frontière avec le monde entier. Ça augmente fortement la quantité de cons qu'on peut croiser.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-8868918927224443115?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/8868918927224443115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/8868918927224443115'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2007/05/fr-abuse.html' title='[fr] abuse'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-1306535279708081757</id><published>2006-12-10T00:35:00.000+01:00</published><updated>2008-03-05T00:40:46.063+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Nmap 4.20</title><content type='html'>Nmap 4.20 is out.  I had a look at it, just in case some annoying &lt;strike&gt;bugs&lt;/strike&gt; features  were fixed.&lt;br /&gt;Against my good old BSD, &lt;span style="font-family:courier new;"&gt;nessus_tcp_scanner&lt;/span&gt; ran on 352 s (with max_check=4) or 254 s (max_check=5). &lt;span style="font-family:courier new;"&gt;nmap -T 4 ran&lt;/span&gt; in 774 s without &lt;span style="font-family:courier new;"&gt;--defeat-icmp-rate-limitation&lt;/span&gt;, or in 658 s with it. Similar to the previous 11 minutes; no gain.&lt;br /&gt;&lt;br /&gt;Considering the memory size, I'm afraid that things did not improved.&lt;br /&gt;Here is the result of &lt;span style="font-family:courier new;"&gt;"nmap -sS -sV -O -v -p- ...&lt;/span&gt;" against a vicious configuration.&lt;br /&gt;Memory sizes are in MB, time in seconds. The blue line is the allocated virtual memory, the red line the occupied RAM; the host machine is 32 bits, with 1.5 GB RAM.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_mQV1IEgQVR8/RlAu9T5R7fI/AAAAAAAAAAU/oNMVve2KwvY/s1600-h/nmap2.png"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_mQV1IEgQVR8/RlAu9T5R7fI/AAAAAAAAAAU/oNMVve2KwvY/s320/nmap2.png" alt="" id="BLOGGER_PHOTO_ID_5066601211639229938" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-1306535279708081757?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/1306535279708081757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/1306535279708081757'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2006/12/en-nmap-420.html' title='[en] Nmap 4.20'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_mQV1IEgQVR8/RlAu9T5R7fI/AAAAAAAAAAU/oNMVve2KwvY/s72-c/nmap2.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-115486868981452501</id><published>2006-08-06T14:38:00.000+02:00</published><updated>2008-03-05T00:41:31.461+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IRL'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] l'art de bien emballer</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/7022/649/1600/emballage1.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://photos1.blogger.com/blogger/7022/649/320/emballage1.jpg" alt="" border="0" /&gt;&lt;/a&gt;Non, il ne s'agit pas d'une technique de drague mais d'un vulgaire carton qui va encombrer ma poubelle.&lt;br /&gt;L'object commandé (un Nikon FH-3)  mesure 1 x 5,5 x 27 cm dans son étui; le carton avec les gros autocollants "fragile" fait 12x23x30 cm. L'emballage est donc 55 fois plus gros que l'emballé.&lt;br /&gt;Et on va encore me casser les c... avec des histoires de recyclage et de tri sélectif.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Je dois noter que contrairement à mon étagère en verre trempé livrée "en kit" par Ikéa, le FH-3 est arrivé entier. Encore heureux...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-115486868981452501?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/115486868981452501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=115486868981452501&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/115486868981452501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/115486868981452501'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2006/08/fr-lart-de-bien-emballer.html' title='[fr] l&apos;art de bien emballer'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-115367292012124655</id><published>2006-07-23T18:36:00.001+02:00</published><updated>2008-04-06T02:19:59.342+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IRL'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Get a life!</title><content type='html'>Ça fait un mois queje n'ai pas dit du mal de Nmap, mais je ne suis pas gravement malade. Je suis l'heureux possesseur d'un &lt;a href="http://www.nikonimaging.com/global/products/scanner/coolscan_5/index.htm"&gt;Nikon Coolscan V &lt;/a&gt;. Je reprendrai mes méchancetés quand j'aurai converti mes quelques milliers de photos argentiques en 0 et 1.&lt;br /&gt;J'ai quelques projets pour Nessus, comme le porter sur Zaurus (c'est fait) avec de bonnes performances (ce n'est pas gagné) mais il faudra attendre un peu que le virus photographique me lâche.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-115367292012124655?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/115367292012124655/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=115367292012124655&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/115367292012124655'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/115367292012124655'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2006/07/fr-get-life.html' title='[fr] Get a life!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-115062454429399181</id><published>2006-06-18T11:39:00.000+02:00</published><updated>2008-03-05T00:41:31.461+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Nmap 4.10: la saga continue</title><content type='html'>Fyodor a &lt;a href="http://seclists.org/lists/nmap-hackers/2006/Apr-Jun/0003.html"&gt;annoncé&lt;/a&gt; une nouvelle option dans Nmap 4.10:  &lt;span style="font-weight: bold;"&gt;--defeat-rst-ratelimit&lt;br /&gt;&lt;/span&gt;J'ai recompilé cette merveille, rallumé mon vieux 486 sous OpenBSD, et lancé le scan de 65535 ports.&lt;br /&gt;Bilan: au lieu de mettre 660 secondes, il met maintenant 11 minutes. Je ricane.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;grin&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/grin&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-115062454429399181?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/115062454429399181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=115062454429399181&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/115062454429399181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/115062454429399181'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2006/06/fr-nmap-410-la-saga-continue.html' title='[fr] Nmap 4.10: la saga continue'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-114737277915941050</id><published>2006-05-11T20:33:00.000+02:00</published><updated>2008-03-05T00:40:46.063+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] ssh_get_info + Telnet + SNMP</title><content type='html'>One of my customers never use SSH, but rather Telnet. This is frustrating as ssh_get_info cannot be used. So I patched &lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;id=12634"&gt;ssh_get_info.nasl&lt;/a&gt; to support other protocols: Telnet, rexec, rsh &amp; rlogin. &lt;br /&gt;The code is now cleaner IMHO, and it should be easier to add more protocols, if this is really necessary.&lt;br /&gt;We have to test all this to check that nothing is broken, do not expect to see this released too soon.&lt;br /&gt;&lt;br /&gt;I also wrote a new snmp_get_info.nasl, but few systems give useful information through the (out of the box) SNMP agent: AIX, SuSE...&lt;br /&gt;Maybe this script will never go into the official repository.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-114737277915941050?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/114737277915941050/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=114737277915941050&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/114737277915941050'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/114737277915941050'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2006/05/en-sshgetinfo-telnet-snmp.html' title='[en] ssh_get_info + Telnet + SNMP'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-113878451865798294</id><published>2006-02-01T08:28:00.000+01:00</published><updated>2008-03-05T00:41:31.462+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Nmap au régime</title><content type='html'>D'après Fyodor, Nmap 3.93 pouvait consommer une mémoire excessive "quand on scannait des centaines de milliers de ports"; c'est-à-dire, comme on me l'avait fort justement fait remarquer... à partir de 2 machines!&lt;br /&gt;C'est censé être corrigé à partir de Nmap 3.95.  Si l'on considère que bouffer 250 Mo est raisonnable, alors oui.&lt;br /&gt;&lt;br /&gt;Voici &lt;span style="font-family:courier new;"&gt;nmap -sS -sV -p- -O 127.0.0.1/8 &lt;/span&gt;à l'oeuvre (en abscisse le temps en secondes, en ordonnées la taille mémoire consommée en kilo-octets).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/7022/649/1600/nmap127.1.png"&gt;&lt;img style="cursor: pointer;" src="http://photos1.blogger.com/blogger/7022/649/320/nmap127.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Pour ceux qui s'imagineraient qu'un tel comportement est normal compte tenu de la taille des bases de fingerprinting, ou bien que Nmap a encore été dégraissé après la 3.95, voici la 3.9999 face à une configuration un peu bizarre. J'ai dû l'arrêter, je n'ai que 1,5 Go de RAM sur mon desktop, et il ne serait pas allé bien plus loin sur une machine 32 bits.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/7022/649/1600/nmap4.png"&gt;&lt;img style="cursor: pointer;" src="http://photos1.blogger.com/blogger/7022/649/320/nmap4.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Je n'ai pas d'explication sur ce bug mystérieux, mais ceux qui comptent faire tourner nmap longtemps face à un gros réseau sont prévenus...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-113878451865798294?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/113878451865798294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=113878451865798294&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113878451865798294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113878451865798294'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2006/02/fr-nmap-au-rgime.html' title='[fr] Nmap au régime'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-113585118232554411</id><published>2005-12-29T10:27:00.000+01:00</published><updated>2008-03-05T00:40:46.063+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Free software &amp; copyrights</title><content type='html'>Quiz: read this page and try to find all errors.&lt;br /&gt;&lt;a href="http://www.webzcan.com/Vulns/WZV11834.html"&gt;http://www.webzcan.com/Vulns/WZV11834.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hint: source routed packets are an old obsession: I wrote &lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;id=11834"&gt;that&lt;/a&gt; Nessus script in 2003.&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;My name does not appear anywhere on this page.&lt;/li&gt;   &lt;li&gt;&lt;a href="http://www.nessus.org/"&gt;"Nessus"&lt;/a&gt; does not appear anywhere on this page.&lt;/li&gt;   &lt;li&gt;As this is an English &lt;span style="font-weight: bold;"&gt;text&lt;/span&gt;, it is not regulated by software licence but by common copyright.&lt;br /&gt;  &lt;/li&gt; &lt;/ol&gt; This is just an example: many companies do this, and nobody cares. But when Renaud tries to protect his intellectual property by closing the source code, everybody whines.&lt;br /&gt;&lt;br /&gt;We definitely need something stronger than GPL. And maybe a couple of trials...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-113585118232554411?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/113585118232554411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=113585118232554411&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113585118232554411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113585118232554411'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/12/en-free-software-copyrights.html' title='[en] Free software &amp; copyrights'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-113165076505297877</id><published>2005-11-11T19:58:00.000+01:00</published><updated>2008-03-05T00:40:46.064+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Ubuntu Security Notices</title><content type='html'>I've converted &lt;a href="http://www.ubuntu-linux.org/"&gt;Ubuntu&lt;/a&gt; &lt;a href="http://www.ubuntu-linux.org/usn/"&gt;security advisories&lt;/a&gt; into &lt;a href="http://www.nessus.org/"&gt;Nessus&lt;/a&gt; "&lt;a href="http://www.nessus.org/documentation/index.php?doc=ssh"&gt;local tests&lt;/a&gt;".&lt;br /&gt;Nice distro, by the way...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="down" style="display: block;" id="formatbar_CreateLink" title="Associer" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-113165076505297877?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/113165076505297877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=113165076505297877&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113165076505297877'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113165076505297877'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/11/en-ubuntu-security-notices.html' title='[en] Ubuntu Security Notices'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-113120936190505229</id><published>2005-11-05T17:48:00.000+01:00</published><updated>2008-03-05T00:40:46.064+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Nessus and the art of bullshit</title><content type='html'>Once upon a time, another of my favourite competitors wanted to check if the Windows machines that he was auditing were up to date with security patches.&lt;br /&gt;For whatever reason, he could not start his laptop on Unix (maybe he just could not install Unix, like so many 3L33T security consultants) so he booted a &lt;a href="http://www.knoppix.org/"&gt;Knoppix&lt;/a&gt; or Auditor Live CD, ran Nessus and said "all clear".&lt;br /&gt;&lt;br /&gt;There is one little problem: GPL live CD use GPL Nessus, and nearly all Windows tests are © &lt;a href="http://www.tenablesecurity.com/"&gt;Tenable&lt;/a&gt;, they are &lt;b&gt;not&lt;/b&gt; included in the GPL Live CDs, as they are available through the &lt;a href="http://www.nessus.org/plugins/index.php?view=feed"&gt;&lt;span style="text-decoration: underline;"&gt;direct feed&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;It was no use running the test, we already know the result: no problem.&lt;br /&gt;&lt;br /&gt;People actually &lt;span style="font-weight: bold;"&gt;pay&lt;/span&gt; for this kind of "audit". Isn't it amazing?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="" style="display: block;" id="formatbar_CreateLink" title="Associer" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmouseup="" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-113120936190505229?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/113120936190505229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=113120936190505229&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113120936190505229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/113120936190505229'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/11/en-nessus-and-art-of-bullshit.html' title='[en] Nessus and the art of bullshit'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-112984835629980674</id><published>2005-11-05T17:44:00.000+01:00</published><updated>2008-03-05T00:41:31.462+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Europa</title><content type='html'>&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;On disait qu'afin d'acquérir cette maîtrise, le signor avait vendu&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;son âme au diable, mais Lord Douglas fit remarquer qu'il y avait&lt;br /&gt;belle &lt;/span&gt;&lt;span style="font-style: italic;"&gt;lurette que le diable avait renoncé à ce genre de marché, vu&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;l'abondance extrême de marchandise qui lui était offerte et qu'il&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;payait à vil prix, avec de la menue monnaie.&lt;br /&gt;&lt;/span&gt;Romain Gary, in Europa&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-112984835629980674?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/112984835629980674/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=112984835629980674&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112984835629980674'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112984835629980674'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/11/fr-europa.html' title='[fr] Europa'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-112980430698106563</id><published>2005-10-20T12:19:00.000+02:00</published><updated>2008-03-05T00:40:46.064+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Nessus licence</title><content type='html'>A while ago, a consultant from a competitor company launched a scan on a live network.&lt;br /&gt;I don't know exactly what tool he used - Nessus or Nmap, I suspect. And I don't know what options he chose.&lt;br /&gt;The main problem is that &lt;span style="font-weight: bold;"&gt;he&lt;/span&gt; probably did not know either.&lt;br /&gt;As a result, the whole network crashed.&lt;br /&gt;&lt;br /&gt;There should be a Nessus licence, just like there are driving licences.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-112980430698106563?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/112980430698106563/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=112980430698106563&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112980430698106563'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112980430698106563'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/10/en-nessus-licence.html' title='[en] Nessus licence'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-112454729411718869</id><published>2005-08-20T16:03:00.001+02:00</published><updated>2008-03-12T15:45:07.831+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] New version of nessus_tcp_scanner</title><content type='html'>The new &lt;a href="http://www.nessus.org/plugins/index.php?view=single&amp;amp;id=10335"&gt;nessus_tcp_scanner&lt;/a&gt; will be quicker but more reliable, I hope. It estimates the Round Trip Time instead of using the default fixed timeout, it runs several passes against a slow target and tries to detect heavily firewalled machines or BSD systems with RST rate limitation. This way, it does a full TCP scan of a BSD system in a couple of minutes instead of eleven.&lt;br /&gt;You'll have to wait for Nessus 2.2.6 to get this marvel.&lt;br /&gt;&lt;br /&gt;OK, I should drop this topic and get a life.&lt;br /&gt;Or at least, instead of practicing witchcraft, I should try to build a model for port scan.&lt;br /&gt;Thinking before doing... Looks like a good idea.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-112454729411718869?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/112454729411718869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=112454729411718869&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112454729411718869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112454729411718869'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/08/en-new-version-of-nessustcpscanner.html' title='[en] New version of nessus_tcp_scanner'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-112004476484156988</id><published>2005-06-29T08:30:00.000+02:00</published><updated>2008-03-05T00:40:46.065+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Port scanning, again</title><content type='html'>I scanned a friend's machine a week ago.&lt;br /&gt;nessus_tcp_scanner took 380 s, "nmap -T aggressive" took more than 1500 s.&lt;br /&gt;&lt;br /&gt;[update 2005-07-27]&lt;br /&gt;Nmap looks badly broken in some cases, but I was unable to reproduce that as the configuration of the target machine was changed since.&lt;br /&gt;Meanwhile, I broke nessus_tcp_scanner... &lt;sigh&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-112004476484156988?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/112004476484156988/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=112004476484156988&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112004476484156988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/112004476484156988'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/06/en-port-scanning-again.html' title='[en] Port scanning, again'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111433621066633218</id><published>2005-04-24T11:45:00.000+02:00</published><updated>2008-03-05T00:41:31.462+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IRL'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Construisons l'Europe</title><content type='html'>Je viens de découvrir un peuple encore plus mauvais que les Français en langues étrangères: les Espagnols.&lt;br /&gt;(les Américains sont hors concours)&lt;br /&gt;Difficile d'en trouver qui causent français ou anglais.&lt;br /&gt;Qu'on ne me fasse pas croire que c'est un problème inhérent aux Latins, les Portugais ou les Roumains se débrouillent fort bien.&lt;br /&gt;&lt;br /&gt;Évidemment, je n'ai qu'à causer Espagnol au lieu d'essayer vainement d'apprendre des langues tordues.&lt;br /&gt;Je crois que je vais me mettre au basque, c'est une langue officielle là bas.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111433621066633218?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111433621066633218/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111433621066633218&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111433621066633218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111433621066633218'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/04/fr-construisons-leurope.html' title='[fr] Construisons l&apos;Europe'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111036072423239432</id><published>2005-03-09T10:25:00.000+01:00</published><updated>2008-03-05T00:40:46.065+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Guillermito vs Tegam</title><content type='html'>At least some excitement in the French computer security little world!&lt;br /&gt;&lt;a href="http://www.tegam.fr/"&gt;Tegam&lt;/a&gt; has found a new protection against security holes: they do not patch, they bring the &lt;a href="http://www.guillermito2.net/"&gt;publisher&lt;/a&gt; to justice. As far as I know, they never  did the same against virus writers. Isn't it odd?&lt;br /&gt;Finally, Guillermito was &lt;a href="http://maitre.eolas.free.fr/journal/index.php?2005/03/08/87-guillermito-condamne-mais-tres-legerement"&gt;lightly condemned&lt;/a&gt; because he used a pirated copy of Viguard. The court did not even judge that Guillermito had defamed their software.&lt;br /&gt;All this is not so important, even for Frenchmen: Tegam is a small company, virtually unknown outside of the country.&lt;br /&gt;Anyway, if you intend to buy their products, you'd better read the contract several times.&lt;br /&gt;&lt;br /&gt;&lt;span class="down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111036072423239432?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111036072423239432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111036072423239432&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111036072423239432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111036072423239432'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2005/03/en-guillermito-vs-tegam.html' title='[en] Guillermito vs Tegam'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-110310739280623081</id><published>2004-12-15T11:32:00.000+01:00</published><updated>2008-03-05T00:40:46.065+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] There shall be weeping and gnashing of teeth</title><content type='html'>&lt;a href="http://www.tenablesecurity.com/"&gt;Tenable Security&lt;/a&gt; has changed the way Nessus plugins are distributed.  There are now two feed:&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;one for the ~ 3000 GPL plugins: they are available freely and can be redistributed freely.&lt;br /&gt; &lt;/li&gt;   &lt;li&gt;one for the ~ 3000 Tenable plugins. To get them, you have to register, and pay if you want them at once, or get them with a delay of one week.&lt;/li&gt; &lt;/ul&gt; This modification is not a licence change: Renaud has been warning for years on the mailing lists that some plugins were not necessarily GPLed.&lt;br /&gt;It is not really a surprise either: Tenable is a privately owned company and has to make money. This move clearly targets ASP which resell Nessus and the plugins without authorization, often violating the GPL and intellectual property of C code or plugins contributers.&lt;br /&gt;&lt;br /&gt;As usual, some people were pissed off by this move and yelled on the mailing list, mostly for bad reasons.&lt;br /&gt;I did not hear them when ASP violated &lt;span style="font-weight: bold;"&gt;my&lt;/span&gt; intellectual property.&lt;br /&gt;Strange, isn't it?&lt;br /&gt;&lt;br /&gt;&lt;span class="" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-110310739280623081?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/110310739280623081/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=110310739280623081&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110310739280623081'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110310739280623081'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/12/en-there-shall-be-weeping-and-gnashing.html' title='[en] There shall be weeping and gnashing of teeth'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-110217754605583486</id><published>2004-12-04T17:24:00.000+01:00</published><updated>2008-03-05T00:40:46.065+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Slackware "local tests"</title><content type='html'>I have finished my conversion tool from SSA to NASL. Nessus will be able to do "local tests" on Slackware (i.e. check through an SSH connection that all patches are applied)&lt;br /&gt;Once again, parsing English in Perl was easier than processing XML.&lt;br /&gt;What's the use of this buzzword compliant crap? Can anybody tell?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-110217754605583486?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/110217754605583486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=110217754605583486&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110217754605583486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110217754605583486'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/12/en-slackware-local-tests.html' title='[en] Slackware &quot;local tests&quot;'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357570334788585</id><published>2004-12-04T16:34:00.000+01:00</published><updated>2008-03-05T00:41:31.463+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Slackware Security Advisories</title><content type='html'>J'ai écrit une moulinette de conversion des avis de sécurité Slackware en NASL (nessus Attack Script Language). Une fois encore, parser de l'anglais a été plus rapide que traiter du XML.&lt;br /&gt;&lt;br /&gt;En résumé, au cas où vous n'auriez pas compris, XML c'est gros, c'est moche et ça ne sert à rien.&lt;br /&gt;Ça va mieux en le disant.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357570334788585?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357570334788585/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357570334788585&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357570334788585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357570334788585'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/12/fr-slackware-security-advisories.html' title='[fr] Slackware Security Advisories'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-110207698409860428</id><published>2004-12-03T13:45:00.000+01:00</published><updated>2008-03-05T00:40:46.066+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Zen and the art of automation</title><content type='html'>I dislike doing a silly job.  And I really hate doing it twice.&lt;br /&gt;Whenever I have to do such a f*ing job, I give it to a robot. Robots do not complain, never get tired and are usually better than me for any task that do not require a brain.&lt;br /&gt;Working on robots is more fun than doing silly jobs.&lt;br /&gt;That's why I work on Nessus. Not the only reason, but the main one: looking for security patches on a server is definitely stupid, 150000 lines of C will do it well.&lt;br /&gt;(some stupid tasks need a little subtlety and more than one page of Perl)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.nessus.org/"&gt;Nessus&lt;/a&gt; is working, and rather well (much better than its competitors in my humble but biaised opinion) and anybody who'd want to spend a little energy could write patches or test plugins, or concentrate on higher level tasks, like deciding if the whole IT system is vulnerable, to which threat, which sensitive data is exposed, etc.&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Nessus scans each machine independantly of the others, and it does not know your network architecture or the sensitivity of your data or servers; in fact, it is not &lt;span style="font-style: italic;"&gt;his&lt;/span&gt; job, it is &lt;span style="font-style: italic;"&gt;ours&lt;/span&gt;&lt;span style="font-style: italic;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It seems that I overestimate human beings. I know that &lt;span style="font-style: italic;"&gt;homo sapiens sapiens&lt;/span&gt; is not that &lt;span style="font-style: italic;"&gt;sapiens&lt;/span&gt;, but I have not lost all hope that people sometimes wants to improve, some way or another.&lt;br /&gt;Many people have improved indeed: they were lusers, they became "security consultants". They run Nessus and sell the raw report.&lt;br /&gt;Added value: none.&lt;br /&gt;&lt;br /&gt;After WW3, only robots will survive.&lt;br /&gt;Good.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-110207698409860428?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/110207698409860428/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=110207698409860428&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110207698409860428'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110207698409860428'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/12/en-zen-and-art-of-automation.html' title='[en] Zen and the art of automation'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-110185231303827516</id><published>2004-11-30T22:50:00.000+01:00</published><updated>2008-03-05T00:40:46.066+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Automatic updates</title><content type='html'>Unless you have been living under a rock, you know that Microsoft published Windows XP SP2 and made a lot of fuzz about it. If you are not masochist enough to run Windows, maybe you do not know that one of the new "features" is that you are strongly advised to enable the automatic Windows Update. If you disable it, the "security center" will warn you that your system may be at risk, and that you really should enable Windows Update back.&lt;br /&gt;If you are masochist enough to run Windows, I guess you also have an antivirus scanner. And the gizmo updates itself regularly, and warns you when its signature database is out of date.&lt;br /&gt;&lt;br /&gt;I have good news and bad news:&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;The number of security advisories is still climbing, watching them takes more and more time. Some people are taking care of your computer security, you don't have to read Bugtraq.&lt;/li&gt;   &lt;li&gt;The price you pay is that you are losing control of this f*ing machine. You did not control it much, but it is definitely going to be worse.&lt;br /&gt;&lt;/li&gt; &lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-110185231303827516?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/110185231303827516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=110185231303827516&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110185231303827516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110185231303827516'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/11/en-automatic-updates.html' title='[en] Automatic updates'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357566300175078</id><published>2004-11-27T16:34:00.000+01:00</published><updated>2008-03-05T00:41:31.463+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Rions avec Systran</title><content type='html'>Un client a tenté de traduire les premières lignes de mon dernier rapport d'anglais en français avec SYSTRAN.&lt;br /&gt;"A remote cracker could deface the web server"&lt;br /&gt;est devenu :&lt;br /&gt;"Un biscuit à distance pourrait défigurer le serveur web".&lt;br /&gt;&lt;br /&gt;Appliquez toujours les patchs de sécurité, sinon ça va laisser des miettes partout !&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357566300175078?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357566300175078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357566300175078&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357566300175078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357566300175078'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/11/fr-rions-avec-systran.html' title='[fr] Rions avec Systran'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-110090191161175079</id><published>2004-11-19T22:58:00.000+01:00</published><updated>2008-03-05T00:40:46.066+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='En'/><title type='text'>[en] Yet Another TCP Scanner</title><content type='html'>I wrote a new TCP scanner, at last.&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;It was easy.&lt;/li&gt;&lt;li&gt;It is simple (less than two pages of C)&lt;/li&gt;    &lt;li&gt;It is quick, even against a firewalled machine&lt;/li&gt;   &lt;li&gt;It grabs banners, and save times for the service identification phases later.&lt;/li&gt;    &lt;/ul&gt; Of course, it doesn't have all the bells &amp;amp; whistles of more advanced scanners like Nmap, but in most cases, we don't need them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-110090191161175079?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/110090191161175079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=110090191161175079&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110090191161175079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/110090191161175079'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/11/en-yet-another-tcp-scanner.html' title='[en] Yet Another TCP Scanner'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357563077480642</id><published>2004-11-17T16:33:00.000+01:00</published><updated>2008-03-05T00:41:31.463+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Port scanner...</title><content type='html'>J'ai écrit un port scanner TCP ce week-end. J'aurais dû le faire plus tôt.&lt;br /&gt;- il va vite, même contre une machine méchamment firewallée&lt;br /&gt;- il ramasse aussi les bannières des services, ce qui économise moult opérations nessussiennes par la suite.&lt;br /&gt;- il fait moins de deux pages de code, parce qu'il s'appuie sur le noyau pour ouvrir des connexions TCP. Mais c'est un peu le boulot du noyau, non ?&lt;br /&gt;- il n'est pas discret et c'est tant mieux.&lt;br /&gt;&lt;br /&gt;Évidemment, il ne ressemble pas à un outil de hacker (non, je n'ai cité personne).&lt;br /&gt;Tant mieux, ça m'évitera de prendre des coups de botin dans les bureaux de la DST.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357563077480642?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357563077480642/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357563077480642&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357563077480642'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357563077480642'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/11/fr-port-scanner.html' title='[fr] Port scanner...'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357557469882229</id><published>2004-11-11T16:32:00.000+01:00</published><updated>2008-03-05T00:41:31.464+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Comment faire fonctionner le driver nVidia sous Linux</title><content type='html'>nVidia fait d'excellentes cartes graphiques 3D, idéales pour votre simulateur de vol préféré, surtout quand il a été écrit avec les pieds et part du principe que vous avez une carte 3D kivabien.&lt;br /&gt;Ils en ont tellement vendues qu'elles ne coûtent plus rien.&lt;br /&gt;nVidia, comme Matrox à son époque de gloire, a décidé que ses drivers étaient très secrets et qu'ils ne dévoileraient pas ce que leurs concurrents savent probablement déjà.&lt;br /&gt;Mais, ô joie, ils pensent aux gentils pingouins et distribuent un driver partiellement binaire, qu'ils tiennent à jour en plus. C'est sympa.&lt;br /&gt;Seules petites ombres au tableau, 1) la puce est munie d'un petit ventilateur qui est parfois terriblement bruyant... 2) et le driver Linux est parfois pris de folie.&lt;br /&gt;Le bug est connu depuis belle lurette, existe avec toutes les versions de cartes, a été abondamment décrit (le serveur X part dans une boucle sans fin de gettimeofday en bouffant toute la CPU) et la réponse de nVidia est invariablement "impossible à reproduire".&lt;br /&gt;J'ai décidé de résoudre le problème. J'ai commencé par trifouiller toutes les options (la méthode hamster), puis je me suis souvenu d'un de mes vieux trucs de développeurs : ne jamais forcer un logiciel malade à tomber en marche. Ne pas hésiter à abréger ses souffrances.&lt;br /&gt;J'ai acheté une Matrox G550.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357557469882229?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357557469882229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357557469882229&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357557469882229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357557469882229'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/11/fr-comment-faire-fonctionner-le-driver.html' title='[fr] Comment faire fonctionner le driver nVidia sous Linux'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357582821071176</id><published>2004-10-28T16:36:00.000+02:00</published><updated>2008-03-05T00:41:31.464+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Mon premier morceau de bouquin...</title><content type='html'>&lt;p class="summary"&gt;Comme c'est émouvant !&lt;/p&gt;  &lt;p class="summary"&gt;J'ai reçu mes bouquins sur Nessus des USA. J'ai accepté qu'ils reproduisent en appendice mon manuel de référence sur NASL2 en échange de cinq copies -- je suis trop con, je ne savais pas combien facturer un document que j'ai toujours diffusé gratuitement.&lt;br /&gt;&lt;br /&gt;On voit la couverture ici :&lt;br /&gt;&lt;a href="http://www.syngress.com/catalog/sg_main.cfm?pid=2850"&gt;http://www.syngress.com/catalog/sg_main.cfm?pid=2850&lt;/a&gt;&lt;br /&gt;OK, il n'y a même pas mon nom sur la couverture mais je suis dedans, promis juré.&lt;br /&gt;&lt;br /&gt;Si vous voulez lire seulement mon oeuvre, voici comment économiser 50$ :&lt;br /&gt;&lt;a href="http://www.nessus.org/doc/nasl2_reference.pdf"&gt;http://www.nessus.org/doc/nasl2_reference.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357582821071176?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357582821071176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357582821071176&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357582821071176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357582821071176'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/10/fr-mon-premier-morceau-de-bouquin.html' title='[fr] Mon premier morceau de bouquin...'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357577606777659</id><published>2004-10-28T16:35:00.000+02:00</published><updated>2008-03-05T00:41:31.464+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Nessus 2.2 is out!</title><content type='html'>Menu ce soir chez les concurrents commerciaux : soupe à la grimace.&lt;br /&gt;Encore.&lt;br /&gt;Comme tous les jours.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357577606777659?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357577606777659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357577606777659&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357577606777659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357577606777659'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/10/fr-nessus-22-is-out.html' title='[fr] Nessus 2.2 is out!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357550090381053</id><published>2004-10-05T16:29:00.000+02:00</published><updated>2008-03-05T00:41:31.465+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Pourquoi XML ?</title><content type='html'>&lt;a href="http://my.geekstory.net/"&gt;Doug&lt;/a&gt; a peut-être trouvé l'&lt;span style="font-weight: bold;"&gt;Explication Ultime&lt;/span&gt; de l'engouement pour le XML: c'est facile à écrire ou à générer.&lt;br /&gt;&lt;br /&gt;Ensuite, l'autre bout de la communication se débrouille, mais ceci est un autre problème.&lt;br /&gt;"Passe à ton voisin".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357550090381053?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357550090381053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357550090381053&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357550090381053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357550090381053'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/10/fr-pourquoi-xml.html' title='[fr] Pourquoi XML ?'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357532034458936</id><published>2004-10-02T00:00:00.000+02:00</published><updated>2008-03-05T00:41:31.465+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] English vs XML</title><content type='html'>J'aurai mis moins de temps à convertir les avis de sécurité Debian depuis du WML que les avis de sécurité Gentoo depuis XML.&lt;br /&gt;J'admets que les &lt;a href="http://www.debian.org/security/"&gt;DSA&lt;/a&gt; sont un poil plus simples que les &lt;a href="http://www.gentoo.org/security/en/glsa/"&gt;GLSA.&lt;/a&gt; Mais finalement, parser du WML et de l'anglais à grand coups de regex, c'est plus facile que de dépioter des sous-champs optionnels au fin fond d'une structure.&lt;br /&gt;Il me semblait bien qu'il y avait arnaque.&lt;br /&gt;J'avais dit que XML était conçu pour ceux qui ne savaient pas écrire un parser. Je l'ai surestimé : les bonnes vieilles expressions régulières sont plus utiles que ce machin.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357532034458936?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357532034458936/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357532034458936&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357532034458936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357532034458936'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/10/fr-english-vs-xml.html' title='[fr] English vs XML'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357669706428353</id><published>2004-09-29T16:47:00.000+02:00</published><updated>2008-03-05T00:41:31.466+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Debian Security Advisories</title><content type='html'>&lt;p class="summary"&gt;Au menu ce soir chez &lt;a href="http://www.iss.net/"&gt;ISS&lt;/a&gt; et &lt;a href="http://www.eeye.com/"&gt;eEye:&lt;/a&gt; soupe à la grimace.&lt;/p&gt;  &lt;p class="summary"&gt;Je viens de me cogner la conversion des avis de sécurité Debian, les "DSA", en NASL (le langage de Nessus).&lt;br /&gt;Les concurrents commerciaux de Nessus qui ont les yeux rivés sur le nombre de tests vont verdir. Nous sommes à 4700 scripts, et nous allons passer à plus de 5200.&lt;br /&gt;Énervant, hein ? Inquiétant, même...&lt;br /&gt;&lt;span class="" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;span class="down" style="display: block;" id="formatbar_CreateLink" title="Link" onmouseover="ButtonHoverOn(this);" onmouseout="ButtonHoverOff(this);" onmousedown="CheckFormatting(event);FormatbarButton('richeditorframe', this, 8);ButtonMouseDown(this);"&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357669706428353?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357669706428353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357669706428353&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357669706428353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357669706428353'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/09/fr-debian-security-advisories.html' title='[fr] Debian Security Advisories'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357628118928090</id><published>2004-09-19T16:44:00.000+02:00</published><updated>2008-03-05T00:41:31.467+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] G00gl3 rul3z</title><content type='html'>La récente paranoïa d'un pote à propos de Google Mail (*) a fait remonter à la surface de ma pauvre cervelle une vieille interrogation.&lt;br /&gt;Google est le plus gros moteur de recherche existant, et il scanne en permanence le web -- je suis fasciné par la vitesse à laquelle il repasse sur ma misérable page perso.&lt;br /&gt;Leur base contient forcément plus d'informations que ce qui est affiché.&lt;br /&gt;En particulier, une superbe collection de sites web troués et de serveurs web vulnérables, qui pourraient tomber très rapidement sous le contrôle de hackers un peu organisés, sans compter diverses informations confidentielles qui sont filtrées par le moteur.&lt;br /&gt;&lt;br /&gt;La NSA s'intéresse de près à la technologie de Google. Mais c'est un hasard, hein ?&lt;br /&gt;&lt;br /&gt;(*) &lt;a href="http://www.gmail.com/"&gt;http://www.gmail.com&lt;/a&gt; à qui l'on reproche 1. de fouiner dans les messages pour balancer des pubs, 2. d'archiver indéfiniment.&lt;br /&gt;Lire &lt;a href="http://gmail-is-too-creepy.com/"&gt;http://gmail-is-too-creepy.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357628118928090?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357628118928090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357628118928090&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357628118928090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357628118928090'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/09/fr-g00gl3-rul3z.html' title='[fr] G00gl3 rul3z'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357698183755426</id><published>2004-09-05T16:55:00.000+02:00</published><updated>2008-03-05T00:41:31.467+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] XML: parsing for dummies</title><content type='html'>&lt;p class="summary"&gt;Le cerveau du youzeur contient plus de neurones que prévu et il faut une usine à gaz pour le remplacer.&lt;/p&gt;  &lt;p class="summary"&gt;Je me suis longtemps demandé&lt;br /&gt;&lt;/p&gt; &lt;ol&gt;   &lt;li&gt;d'où venait le succès de XML, &lt;/li&gt;   &lt;li&gt;pourquoi je ne le comprenais pas.&lt;/li&gt; &lt;/ol&gt; &lt;p class="summary"&gt;&lt;br /&gt;Je suis convaincu que bricoler un langage adapté à un problème particulier est (i) terriblement rigolo, (ii) très utile. "Languages shape the way we think" (Dijkstra).&lt;br /&gt;&lt;br /&gt;Malheureusement, écrire un parser capable d'avaler le dialecte inventé n'est pas à la portée de n'importe qui, plus par méconnaissance du sujet qu'à cause d'une réelle difficulté technique: les outils existent et il suffit de ne pas se laisser impressionner par le problème.&lt;br /&gt;&lt;br /&gt;Comment éviter à Monsieur Toutlemonde de se blesser en écrivant un parser? Tout simplement en lui amenant un truc tout fait: XML.&lt;br /&gt;Le génie de ce bazar, si l'on peut dire, c'est que le parser est universel. Ça se paie cher: les DTD et autres XBZZZ saletés sont de vrais romans pas bien éloignés d'une grammaire Bison, la moindre bibliothèque XML pèse quelques Mo et son API est un vrai plat de nouille plein d'options, de machins et de sous-trucs.&lt;br /&gt;&lt;br /&gt;Finalement, XML est presque un langage de programmation. Mais les données sont statiques, contrairement au code: on arrive à comprendre son sens en le regardant bouger.&lt;br /&gt;&lt;br /&gt;Autre grand principe méconnu: commenter le code ne sert à rien. Si le code est vraiment illisible, il faut le réécrire. Ce qui est important, c'est d'expliciter la &lt;span style="font-style: italic;"&gt;sémantique&lt;/span&gt; des structures de données.&lt;br /&gt;Et ça, XML ne l'impose pas.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357698183755426?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357698183755426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357698183755426&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357698183755426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357698183755426'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/09/fr-xml-parsing-for-dummies.html' title='[fr] XML: parsing for dummies'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357686821824167</id><published>2004-08-28T16:54:00.000+02:00</published><updated>2008-03-05T00:41:31.467+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Nessus'/><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] Et hop !</title><content type='html'>&lt;p class="summary"&gt;Où l'on découvre en avant première que ça va être la soupe à la grimace Lundi chez ISS et eeye.&lt;/p&gt;  &lt;p class="summary"&gt;Ça y est ! J'ai triomphé du monstre XML ! Nessus est capable de vérifier la liste des packages Gentoo installés.&lt;br /&gt;Les concurrents commerciaux vont tirer une tronche de 6 pieds de longs, ils détestent quand la liste des scripts de test s'allonge brutalement.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357686821824167?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357686821824167/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357686821824167&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357686821824167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357686821824167'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/08/fr-et-hop.html' title='[fr] Et hop !'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357621438574056</id><published>2004-08-27T16:43:00.000+02:00</published><updated>2008-03-05T00:41:31.468+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] XML baaaaaad!</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Plaidoyer pour le logiciel libre et le programmeur en cage.&lt;/span&gt; &lt;p class="summary"&gt;Déjà tout petit, je me méfiais du XML.&lt;br /&gt;Là, je suis en train d'essayer de mouliner automatiquement des avis de sécurité et je commence à détester.&lt;br /&gt;&lt;br /&gt;Le XML, ça permet à n'importe qui de mettre n'importe quoi n'importe où, charge à celui qui lit le fichier de se démerder pour l'interpréter correctement. À partir du moment où la syntaxe est correcte, l'émetteur estime avoir fait son boulot. Fire and forget.&lt;br /&gt;&lt;br /&gt;On retrouve un principe méconnu en informatique: ce qui est important n'est pas ce qu'on autorise mais ce qu'on interdit.&lt;br /&gt;Un logiciel puissant et efficace est un système qui opprime les youzeurz et les programmeurs.&lt;br /&gt;&lt;br /&gt;Je suis un cyberfasciste.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357621438574056?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357621438574056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357621438574056&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357621438574056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357621438574056'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/08/fr-xml-baaaaaad.html' title='[fr] XML baaaaaad!'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9111337.post-111357614982476215</id><published>2004-08-23T16:41:00.000+02:00</published><updated>2008-03-05T00:41:31.468+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Fr'/><title type='text'>[fr] XP SP2 : 1 / Dell : 0</title><content type='html'>&lt;p class="summary"&gt;Où l'on confirme, si besoin était, que l'informatique est vraiment de la sorcellerie&lt;/p&gt;  &lt;p class="summary"&gt;&lt;span style="font-style: italic;"&gt;We installed SP2 on 4 different Dell D600 laptops. One of the laptops&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; experienced a crash that may or may not be related to the service pack.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; Upon reloading the laptop with Windows XP, adding SP2 and all drivers; and adding all necessary applications, it blue screened. We called Dell and they said that if you don't have BIOS version A12 or later, then you can experience hard drive corruption.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9111337-111357614982476215?l=ma75.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://ma75.blogspot.com/feeds/111357614982476215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9111337&amp;postID=111357614982476215&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357614982476215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9111337/posts/default/111357614982476215'/><link rel='alternate' type='text/html' href='http://ma75.blogspot.com/2004/08/fr-xp-sp2-1-dell-0.html' title='[fr] XP SP2 : 1 / Dell : 0'/><author><name>M.A.</name><uri>http://www.blogger.com/profile/12086767873776407757</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
