<?xml version="1.0" encoding="ISO-8859-1"?><rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments for ha.ckers.org web application security lab</title>
	<link>http://ha.ckers.org/blog</link>
	<description>Web Application Security Blog</description>
	<pubDate>Mon, 12 May 2008 07:11:14 +0000</pubDate>

	<item>
		<title>Comment on DoSing the DDoSer by Odin</title>
		<link>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74388</link>
		<author>Odin</author>
		<pubDate>Sun, 11 May 2008 03:17:09 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74388</guid>
					<description>One more thing: If you have my ip: please report me to the cops :D</description>
		<content:encoded><![CDATA[<p>One more thing: If you have my ip: please report me to the cops <img src='http://ha.ckers.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on DoSing the DDoSer by Odin</title>
		<link>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74387</link>
		<author>Odin</author>
		<pubDate>Sun, 11 May 2008 03:16:36 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74387</guid>
					<description>Haha You guys are pretty dumb. First of all: sykopainkilla is down. 

Abuse mail will do wonders.

Don't fuck with evilzone. We own you. If not through an exploit then we'll find the way to get what we want.

Second: Net's name isn't alexander. I know this because I had the privilege of actually knowing his full name. It's Amurgo Vercetti.</description>
		<content:encoded><![CDATA[<p>Haha You guys are pretty dumb. First of all: sykopainkilla is down. </p>
<p>Abuse mail will do wonders.</p>
<p>Don&#8217;t fuck with evilzone. We own you. If not through an exploit then we&#8217;ll find the way to get what we want.</p>
<p>Second: Net&#8217;s name isn&#8217;t alexander. I know this because I had the privilege of actually knowing his full name. It&#8217;s Amurgo Vercetti.</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on DoSing the DDoSer by Xeross</title>
		<link>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74359</link>
		<author>Xeross</author>
		<pubDate>Sat, 10 May 2008 23:37:43 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74359</guid>
					<description>Also one more thing Turkish_OG is right about the increasing number of skiddies</description>
		<content:encoded><![CDATA[<p>Also one more thing Turkish_OG is right about the increasing number of skiddies</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on DoSing the DDoSer by Xeross</title>
		<link>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74358</link>
		<author>Xeross</author>
		<pubDate>Sat, 10 May 2008 23:35:47 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-74358</guid>
					<description>Ok hey folks and happy to see Turkish_OG again(Sorta), well turkish_og could we get in touch again through mail or something i have important matters to discuss with you.

No evilzone not teaming up with him to take u guys down.</description>
		<content:encoded><![CDATA[<p>Ok hey folks and happy to see Turkish_OG again(Sorta), well turkish_og could we get in touch again through mail or something i have important matters to discuss with you.</p>
<p>No evilzone not teaming up with him to take u guys down.</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on Process Doubling by hybriz</title>
		<link>http://ha.ckers.org/blog/20080127/process-doubling/#comment-74079</link>
		<author>hybriz</author>
		<pubDate>Fri, 09 May 2008 07:55:51 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080127/process-doubling/#comment-74079</guid>
					<description>if proper egress filtering is in order, you might not even be able to SYN out of the box towards the internet... might even not be able to punch through with UDP or even DNS. no worry.

by putting code on IIS (cgi would work), use getpeername(2) to find the socket of the current HTTP/S connection, since it's HTTP/1.1 keepalive is assumed so the connection will not end after the first request. so you find the socket on the server side, spawn a shell and reuse the socket to pipe output dup2()-style.

I think this is doable in Windows, I'll port my *nix code to win32 and give some feedback later. anyhow in a lot of situations, specially when the point of entry is DMZ's and such, you're only able to do the inbound connection to the box this is one of the few methods I know to reuse the connection in a nice manner without adding much to the existing infrastructure or normal network traffic (since HTTP/S is legit traffic).</description>
		<content:encoded><![CDATA[<p>if proper egress filtering is in order, you might not even be able to SYN out of the box towards the internet&#8230; might even not be able to punch through with UDP or even DNS. no worry.</p>
<p>by putting code on IIS (cgi would work), use getpeername(2) to find the socket of the current HTTP/S connection, since it&#8217;s HTTP/1.1 keepalive is assumed so the connection will not end after the first request. so you find the socket on the server side, spawn a shell and reuse the socket to pipe output dup2()-style.</p>
<p>I think this is doable in Windows, I&#8217;ll port my *nix code to win32 and give some feedback later. anyhow in a lot of situations, specially when the point of entry is DMZ&#8217;s and such, you&#8217;re only able to do the inbound connection to the box this is one of the few methods I know to reuse the connection in a nice manner without adding much to the existing infrastructure or normal network traffic (since HTTP/S is legit traffic).</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on Solving CAPTCHAs for Cash by shakilur rahaman shohel</title>
		<link>http://ha.ckers.org/blog/20070427/solving-captchas-for-cash/#comment-73927</link>
		<author>shakilur rahaman shohel</author>
		<pubDate>Thu, 08 May 2008 17:57:31 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20070427/solving-captchas-for-cash/#comment-73927</guid>
					<description>#shkilur rahaman shohel Says:

Hi!!! Hope you are doing well. We the leading Data processing company in Bangladesh. Presently we are processing 100000+ captcha per day by our 30 operators. We have a well set up and We can give the law rate for the captcha solving.

Our rate $2 per 1000 captcha.yahoo,hotmail,mayspace,gmail, facebook etc.

We just wanna make the relationship for long terms. can we go forward? Thank you.

Best Regards
shakilur rahaman shohe

se.dhrubotara@yahoo .com
se.dhrubotara@gmail.com</description>
		<content:encoded><![CDATA[<p>#shkilur rahaman shohel Says:</p>
<p>Hi!!! Hope you are doing well. We the leading Data processing company in Bangladesh. Presently we are processing 100000+ captcha per day by our 30 operators. We have a well set up and We can give the law rate for the captcha solving.</p>
<p>Our rate $2 per 1000 captcha.yahoo,hotmail,mayspace,gmail, facebook etc.</p>
<p>We just wanna make the relationship for long terms. can we go forward? Thank you.</p>
<p>Best Regards<br />
shakilur rahaman shohe</p>
<p><a href="mailto:se.dhrubotara@yahoo">se.dhrubotara@yahoo</a> .com<br />
<a href="mailto:se.dhrubotara@gmail.com">se.dhrubotara@gmail.com</a></p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on Solving CAPTCHAs for Cash by Mahbubur Rahman</title>
		<link>http://ha.ckers.org/blog/20070427/solving-captchas-for-cash/#comment-73837</link>
		<author>Mahbubur Rahman</author>
		<pubDate>Thu, 08 May 2008 07:49:01 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20070427/solving-captchas-for-cash/#comment-73837</guid>
					<description>Sir,

We interested in captcha entry and can do 15k per day @ 1.5 USD per 1k. mail @mr_asif_bd@yahoo.com</description>
		<content:encoded><![CDATA[<p>Sir,</p>
<p>We interested in captcha entry and can do 15k per day @ 1.5 USD per 1k. mail @mr_asif_bd@yahoo.com</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on DoSing the DDoSer by shwack13</title>
		<link>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-73782</link>
		<author>shwack13</author>
		<pubDate>Thu, 08 May 2008 05:01:49 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080304/dosing-the-ddoser/#comment-73782</guid>
					<description>he has recently try'd to hack www.sykopainkilla.com
and has been unsucsessfull so me and my admin hacked his website .
http://forum.evilzone.org
Connection Problems
Sorry, SMF was unable to connect to the database. This may be caused by the server being busy. Please try again later.
and were also at the moment stealing his latest db. and not giving it back. and the date is may 7 ,08 10:02 pm.</description>
		<content:encoded><![CDATA[<p>he has recently try&#8217;d to hack <a href="http://www.sykopainkilla.com" rel="nofollow">www.sykopainkilla.com</a><br />
and has been unsucsessfull so me and my admin hacked his website .<br />
<a href="http://forum.evilzone.org" rel="nofollow">http://forum.evilzone.org</a><br />
Connection Problems<br />
Sorry, SMF was unable to connect to the database. This may be caused by the server being busy. Please try again later.<br />
and were also at the moment stealing his latest db. and not giving it back. and the date is may 7 ,08 10:02 pm.</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on A Funny Look Into Our Future by RSnake</title>
		<link>http://ha.ckers.org/blog/20080328/a-funny-look-into-our-future/#comment-73640</link>
		<author>RSnake</author>
		<pubDate>Wed, 07 May 2008 15:03:47 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080328/a-funny-look-into-our-future/#comment-73640</guid>
					<description>@Crayon - I get the movie rights!</description>
		<content:encoded><![CDATA[<p>@Crayon - I get the movie rights!</p>
]]></content:encoded>
				</item>
	<item>
		<title>Comment on A Funny Look Into Our Future by Crayon</title>
		<link>http://ha.ckers.org/blog/20080328/a-funny-look-into-our-future/#comment-73639</link>
		<author>Crayon</author>
		<pubDate>Wed, 07 May 2008 15:01:21 +0000</pubDate>
		<guid>http://ha.ckers.org/blog/20080328/a-funny-look-into-our-future/#comment-73639</guid>
					<description>Did I hear movie plot?

The internet being run by virus ridden, insane, spamming, malware spreading, malicious computer supervillains going after your computer. Lots of them used to be normal users, driven into rage after their n'th computer meltdown.
The few people left on the internet are paranoid, shifty users hidden behind big ass firewalls. 

Small rebel bands of former /b/ members and other self assigned internet end bosses scurrying across the internet since they got nowhere else to go, shouting meme's at the emptyness and collecting scraps of porn from the ruins of broken firewalls and flooded forums. Original content a thing of the past.
A few brave computer experts trying to fight their way back to the old days, searching for that last spark of hope while knowing that we're really fucked this time.

Gamers are long gone, fleeing to console gaming. MMO's keep growing and growing, but the only players left are bots and chinese farmers, driving GM's insane, launching them into manic depression, so many people and nobody to talk to!
Microsoft will invest all resources in the Xbox 1440, which will eventually be found by virusses and spammers too, leaving a crippled gaming community. 

Eventually this will lead to an explosive grow rate of IRL violence, since the gaming community needs to find another kind of exhaust pipe for their rage. All ugly people hidden behind their computer will come outside of their houses. Seeing the sun for the first time in a long while they walk around in amazement, untill the sun burns them and they grow afraid of it. Watching from their windows they envy the daydwellers, planning sweet revenge on them in the cool shadows of their houses.

Night falls...

From this point, some sequel in the lines of 'I am Legend' takes over</description>
		<content:encoded><![CDATA[<p>Did I hear movie plot?</p>
<p>The internet being run by virus ridden, insane, spamming, malware spreading, malicious computer supervillains going after your computer. Lots of them used to be normal users, driven into rage after their n&#8217;th computer meltdown.<br />
The few people left on the internet are paranoid, shifty users hidden behind big ass firewalls. </p>
<p>Small rebel bands of former /b/ members and other self assigned internet end bosses scurrying across the internet since they got nowhere else to go, shouting meme&#8217;s at the emptyness and collecting scraps of porn from the ruins of broken firewalls and flooded forums. Original content a thing of the past.<br />
A few brave computer experts trying to fight their way back to the old days, searching for that last spark of hope while knowing that we&#8217;re really fucked this time.</p>
<p>Gamers are long gone, fleeing to console gaming. MMO&#8217;s keep growing and growing, but the only players left are bots and chinese farmers, driving GM&#8217;s insane, launching them into manic depression, so many people and nobody to talk to!<br />
Microsoft will invest all resources in the Xbox 1440, which will eventually be found by virusses and spammers too, leaving a crippled gaming community. </p>
<p>Eventually this will lead to an explosive grow rate of IRL violence, since the gaming community needs to find another kind of exhaust pipe for their rage. All ugly people hidden behind their computer will come outside of their houses. Seeing the sun for the first time in a long while they walk around in amazement, untill the sun burns them and they grow afraid of it. Watching from their windows they envy the daydwellers, planning sweet revenge on them in the cool shadows of their houses.</p>
<p>Night falls&#8230;</p>
<p>From this point, some sequel in the lines of &#8216;I am Legend&#8217; takes over</p>
]]></content:encoded>
				</item>
</channel>
</rss>
