<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Erich sieht &#187; IT</title>
	<atom:link href="http://erichsieht.wordpress.com/category/it/feed/" rel="self" type="application/rss+xml" />
	<link>http://erichsieht.wordpress.com</link>
	<description>Sicherheit anders</description>
	<lastBuildDate>Sun, 27 Dec 2009 09:00:44 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='erichsieht.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/d87a86636cd5c8d33f36a74cc4b11ea4?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Erich sieht &#187; IT</title>
		<link>http://erichsieht.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://erichsieht.wordpress.com/osd.xml" title="Erich sieht" />
		<item>
		<title>Cold boot attacks on steroids</title>
		<link>http://erichsieht.wordpress.com/2009/12/23/cold-boot-attacks-on-steroids/</link>
		<comments>http://erichsieht.wordpress.com/2009/12/23/cold-boot-attacks-on-steroids/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 05:15:54 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Trusted Computing]]></category>
		<category><![CDATA[BootJacker]]></category>
		<category><![CDATA[evil maid]]></category>
		<category><![CDATA[physical access]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2430</guid>
		<description><![CDATA[BootJacker puts malware underneath the running operating system:

Force reboot
Boot malware
Resume OS session preserved in memory

(found here)
Posted in English, IT, Security, Trusted Computing Tagged: BootJacker, evil maid, physical access      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2430&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://srgsec.cs.illinois.edu/bootjacker.pdf">BootJacker</a> puts malware underneath the running operating system:</p>
<ol>
<li>Force reboot</li>
<li>Boot malware</li>
<li>Resume OS session preserved in memory</li>
</ol>
<p>(found <a href="http://www.schneier.com/blog/archives/2009/12/defeating_micro.html#c403740">here</a>)</p>
Posted in English, IT, Security, Trusted Computing Tagged: BootJacker, evil maid, physical access <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2430/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2430/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2430/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2430/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2430/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2430/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2430/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2430/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2430/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2430/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2430&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/12/23/cold-boot-attacks-on-steroids/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Moderne Welt</title>
		<link>http://erichsieht.wordpress.com/2009/12/17/moderne-welt/</link>
		<comments>http://erichsieht.wordpress.com/2009/12/17/moderne-welt/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 23:26:51 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Fundbüro]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Internetzeitalter]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2375</guid>
		<description><![CDATA[
Posted in Fundbüro, IT Tagged: Internetzeitalter      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2375&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://erichsieht.files.wordpress.com/2009/12/postausgang.jpg"><img class="alignnone size-full wp-image-2374" title="Postausgang" src="http://erichsieht.files.wordpress.com/2009/12/postausgang.jpg?w=450&#038;h=337" alt="Postausgang: ein Kabel, das im Boden verschwindet" width="450" height="337" /></a></p>
Posted in Fundbüro, IT Tagged: Internetzeitalter <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2375/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2375/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2375/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2375&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/12/17/moderne-welt/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>

		<media:content url="http://erichsieht.files.wordpress.com/2009/12/postausgang.jpg" medium="image">
			<media:title type="html">Postausgang</media:title>
		</media:content>
	</item>
		<item>
		<title>Sven vs. McAfee — 1:0</title>
		<link>http://erichsieht.wordpress.com/2009/12/13/sven-vs-mcafee-%e2%80%94-10/</link>
		<comments>http://erichsieht.wordpress.com/2009/12/13/sven-vs-mcafee-%e2%80%94-10/#comments</comments>
		<pubDate>Sun, 13 Dec 2009 18:33:37 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Geschäft]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Zahlenspiele]]></category>
		<category><![CDATA[Aberglaube]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[dreckstool]]></category>
		<category><![CDATA[Drive-by-Download]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[PDF]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2357</guid>
		<description><![CDATA[Wozu schleppe ich eigentlich seit Jahren zwangsweise ein Dreckstool von Virenscanner auf meinem PC mit mir herum, wenn er im − äußerst seltenen − Ernstfall nichts tut? Zugegeben, ich brauche keine Softwareunterstützung, um mich über eine unaufgefordert heruntergeladene PDF-Datei und die Fehlermeldung bei deren Interpretation zu wundern. Nur ist es dann, wenn ich etwas bemerke, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2357&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Wozu schleppe ich eigentlich seit Jahren zwangsweise ein Dreckstool von Virenscanner auf meinem PC mit mir herum, wenn er im − äußerst seltenen − Ernstfall nichts tut? Zugegeben, ich brauche keine Softwareunterstützung, um mich über eine unaufgefordert heruntergeladene PDF-Datei und die Fehlermeldung bei deren Interpretation zu wundern. Nur ist es dann, wenn ich etwas bemerke, für die Abwehr schon zu spät. Falls die PDF-Datei bösartig ist, wird sie nämlich versuchen, Fehler im PDF-Betrachter auszunutzen.</p>
<p>Na ja, immerhin liefert der Vorfall einen Datenpunkt für die empirische Forschung. McAfee hat mir auf diesem Rechner noch nie irgend etwas gemeldet und liegt damit klar im Rückstand.</p>
<p><em><strong>P.S.:</strong> Heise meldet zwei Tage später <a href="http://www.heise.de/newsticker/meldung/Angriffe-auf-ungepatchte-Luecke-in-Adobe-Reader-und-Acrobat-Update-885980.html">das hier</a>.</em></p>
Posted in Geschäft, IT, Security, Zahlenspiele Tagged: Aberglaube, Antivirus, dreckstool, Drive-by-Download, McAfee, PDF <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2357/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2357/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2357/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2357&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/12/13/sven-vs-mcafee-%e2%80%94-10/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>TR-Mail</title>
		<link>http://erichsieht.wordpress.com/2009/12/05/tr-mail/</link>
		<comments>http://erichsieht.wordpress.com/2009/12/05/tr-mail/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 10:14:47 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Regierungsviertel]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[De-Mail]]></category>
		<category><![CDATA[nationale Sicherheit]]></category>
		<category><![CDATA[Türkei]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2341</guid>
		<description><![CDATA[E-Mail vom Staat, das löst hierzulande einiges Misstrauen aus. Woanders fragt man gar nicht erst:
»Ab nächstem Jahr bekommen alle türkischen Neugeborenen eine E-Mail-Adresse vom Staat. Diese Adresse wird von einer Behörde verwaltet und in den Pass gedruckt. Zugleich soll die Verwendung ausländischer Dienste wie Google und Yahoo verboten werden. Das Projekt dient der nationalen Sicherheit.«
(Welt [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2341&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>E-Mail vom Staat, das löst hierzulande einiges Misstrauen aus. Woanders fragt man gar nicht erst:</p>
<blockquote><p>»Ab nächstem Jahr bekommen alle türkischen Neugeborenen eine E-Mail-Adresse vom Staat. Diese Adresse wird von einer Behörde verwaltet und in den Pass gedruckt. Zugleich soll die Verwendung ausländischer Dienste wie Google und Yahoo verboten werden. Das Projekt dient der nationalen Sicherheit.«</p>
<p style="text-align:right;">(Welt Online: <a href="http://www.welt.de/webwelt/article5428461/Jeder-Tuerke-erhaelt-eine-E-Mail-Adresse-vom-Staat.html">Nationale Sicherheit: Jeder Türke erhält eine E-Mail-Adresse vom Staat</a>)</p>
</blockquote>
Posted in IT, Regierungsviertel, Security Tagged: De-Mail, nationale Sicherheit, Türkei <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2341/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2341&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/12/05/tr-mail/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>The Evil Jan Attack</title>
		<link>http://erichsieht.wordpress.com/2009/12/03/the-evil-jan-attack/</link>
		<comments>http://erichsieht.wordpress.com/2009/12/03/the-evil-jan-attack/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 19:40:22 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Hackmeck]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Testlabor]]></category>
		<category><![CDATA[Trusted Computing]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[BitLocker]]></category>
		<category><![CDATA[evil maid]]></category>
		<category><![CDATA[Fraunhofer]]></category>
		<category><![CDATA[janitor]]></category>
		<category><![CDATA[physical access]]></category>
		<category><![CDATA[secure boot]]></category>
		<category><![CDATA[SIT]]></category>
		<category><![CDATA[Skimming]]></category>
		<category><![CDATA[TPM]]></category>
		<category><![CDATA[Video]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2323</guid>
		<description><![CDATA[[See only posts in English]
Microsoft&#8217;s BitLocker is, for all we know, a proper disk encryption software. It encrypts data at rest against attacks originating outside the running system. If you use BitLocker and your computer is stolen while turned off, there is essentially no way of reading data from the disk without having the proper [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2323&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p style="text-align:right;">[<a href="/category/english/">See only posts in English</a>]</p>
<p>Microsoft&#8217;s BitLocker is, for all we know, a proper disk encryption software. It encrypts data at rest against attacks originating outside the running system. If you use BitLocker and your computer is stolen while turned off, there is essentially no way of reading data from the disk without having the proper key(s)—your BitLocker PIN, a key file on a USB stick, or both. If an attacker gets access to the machine while it is running, there may be ways of compromising it through Windows or <a href="http://en.wikipedia.org/wiki/Cold_boot_attack">in other ways</a>, but such attacks are clearly outside the scope of disk encryption.</p>
<p>We know, however, another class of attacks against disk encryption: <em><a href="http://theinvisiblethings.blogspot.com/2009/10/evil-maid-goes-after-truecrypt.html">evil</a> <a href="http://www.schneier.com/blog/archives/2009/10/evil_maid_attac.html">maid </a>attacks</em>. This term describes a general strategy rather than a particular implementation. If you leave your computer unattended, let&#8217;s say in a hotel room, an attacker, let&#8217;s say an evil maid, might manipulate it such that your data will be compromised as soon as you return and provide it with your encryption keys. There are various ways of doing so, for instance installing a hardware keylogger if your keys are based on passwords, or altering the unencrypted boot code to install a Trojan horse that will leak your keys later. <span id="more-2323"></span></p>
<p>BitLocker is different from other software-based disk encryption products, such as TrueCrypt, in that it supports <a href="http://en.wikipedia.org/wiki/Trusted_Computing">Trusted Computing technology</a> for added security. If used with a Trusted Platform Module (TPM)—a small chip inside your computer—BitLocker needs not only your key(s) but also another key stored inside the TPM to decrypt your data. First and foremost this implies that stealing just your disk is futile if the target is your data, since without the TPM part of the key will be missing.</p>
<p>But this is not all the TPM does. It also watches the boot process to ensure your system hasn&#8217;t been tampered with before releasing its part of the encryption key. This won&#8217;t solve the hardware keylogger problem, but many people seem to believe that this would be sufficient to prevent software-based variants of evil maid attacks. After all, you can either boot the unaltered system and get your data encrypted or boot a system that has been tampered with, which will fail to obtain the key from the TPM, right?</p>
<p>Well, almost. BitLocker needs to interact with you, the user, to obtain its keys. As the TPM merely records properties of boot components, it will not prevent the software asking for your keys from being altered, or the altered software from being executed. This means that an attacker <em>can</em> alter code on your computer to obtain your PIN or USB key. The TPM only ensures that the cannot boot right into Windows in its altered state. But if the attacker can get away with a single forced reboot—think bluescreen—the malicious code may remove itself before and just leave your keys somewhere on the disk for later retrieval.</p>
<p>The TPM as it is and as it is being used by BitLocker is therefore not sufficient to fend off evil maid attacks, not even the software-based subset. We discussed such and similar attacks <a title="Attacking the BitLocker Boot Process " href="http://testlab.sit.fraunhofer.de/downloads/Publications/Attacking_the_BitLocker_Boot_Process_Trust2009.pdf">in a paper</a> published <a href="/2009/04/01/how-much-security-do-we-gain-from-trusted-computing/">earlier this year</a>. Now we also demonstrate the BitLocker version of an evil maid attack <a title="Video: Attacking the BitLocker Boot Process" href="http://testlab.sit.fraunhofer.de/bitlocker-skimming/">in a short video starring two of my Fraunhofer colleagues</a>, Jan and Jan. Hence we call this attack the <em>evil Jan attack</em>.</p>
<p>The evil Jan attack does not imply that the BitLocker is broken as a disk encryption scheme. It does not even imply that the TPM would be entirely useless. Our attack has a particular objective, getting unauthorized access to encrypted data in a targeted attack. We show that this remains quite feasible despite the use of the TPM. Attacks with different objectives and side conditions may still get considerably harder due to Trusted Computing. For instance it seems no longer possible for an attacker with physical access to the computer to install malicious software into the running operating system in a single pass.</p>
Posted in English, Hackmeck, IT, Security, Testlabor, Trusted Computing Tagged: attack, BitLocker, evil maid, Fraunhofer, janitor, physical access, secure boot, SIT, Skimming, TPM, Video, Windows <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2323/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2323/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2323/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2323&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/12/03/the-evil-jan-attack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Herr, schmeiß Hirn vom Himmel!</title>
		<link>http://erichsieht.wordpress.com/2009/12/03/herr-schmeis-hirn-vom-himmel/</link>
		<comments>http://erichsieht.wordpress.com/2009/12/03/herr-schmeis-hirn-vom-himmel/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 16:07:48 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Begriffe]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[Datenbank]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[GreenSQL]]></category>
		<category><![CDATA[Security-Theater]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2320</guid>
		<description><![CDATA[Nach der WAF nun also die Datenbank-Firewall. Weil dämliche PHP-Programmierer nicht in der Lage sind, sicher auf Datenbanken zuzugreifen, soll GreenSQL zwischen Anwendung und Datenbank heuristisch SQL Injection erkennen. Die Idee ist so blöd, dass ich nicht mal beim szenetypischen Herumalbern darauf gekommen wäre.
Kernproblem bei Injection-Lücken ist die ungenügende Trennung zwischen Daten und Code in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2320&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Nach der WAF nun also die <a href="http://www.heise.de/ix/meldung/Freie-Datenbank-Firewall-schuetzt-PostgreSQL-und-MySQL-875681.html">Datenbank-Firewall</a>. Weil dämliche PHP-Programmierer nicht in der Lage sind, sicher auf Datenbanken zuzugreifen, soll <a href="http://www.greensql.net/">GreenSQL</a> zwischen Anwendung und Datenbank heuristisch SQL Injection erkennen. Die Idee ist so blöd, dass ich nicht mal beim szenetypischen Herumalbern darauf gekommen wäre.</p>
<p>Kernproblem bei Injection-Lücken ist die ungenügende Trennung zwischen Daten und Code in Verbindung mit dem Impedance Mismatch zwischen Programmier- und Datenbanksprache. Die kanonische Lösung besteht darin, eben diese Trennung zuverlässig aufrechtzuerhalten. Das lässt sich recht einfach bewerkstelligen, indem man eine geeignete Programmierschnittstelle − Prepared Statements statt Stringverkettung zu SQL-Statements − verwendet. Das kann zwar auch noch schiefgehen, wenn die Bibliotheksfunktion Fehler hat, aber wenigstens kann man sich selbst nicht mehr in den Fuß schießen.</p>
<p>Ist die Grenze zwischen Code und Daten einmal verwischt, steht die Datenbankfirewall vor exakt demselben Problem wie die Datenbank selbst: sie kann diese Grenze nicht mehr zuverlässig bestimmen. Konzeptionell ist die Datenbankfirewall deswegen genauso machtlos wie die Zugriffskontrolle der Datenbank. Sie versucht es nur mit einer anderen Strategie. Klüger wäre es, den Entwicklern ausschließlich sichere Schnittstellen zur Verfügung zu stellen.</p>
<p>Als Security-Theater allerdings dürfte so eine Datenbankfirewall hervorragend funktionieren, spuckt sie doch am laufenden Band Meldungen aus, die MovieOS alle Ehre machen würden: <em>Hilfe, wir werden angegriffen!</em></p>
Posted in Begriffe, IT, Security Tagged: Datenbank, Firewall, GreenSQL, Rant, Security-Theater, SQL injection <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2320/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2320/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2320/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2320&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/12/03/herr-schmeis-hirn-vom-himmel/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>In einem Wort</title>
		<link>http://erichsieht.wordpress.com/2009/11/26/in-einem-wort-48/</link>
		<comments>http://erichsieht.wordpress.com/2009/11/26/in-einem-wort-48/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 12:07:07 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[In einem Wort]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Authentisierung]]></category>
		<category><![CDATA[Nötigung]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1971</guid>
		<description><![CDATA[Panic Password
Posted in In einem Wort, IT, Security Tagged: Authentisierung, Nötigung      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1971&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://www.usenix.org/event/hotsec08/tech/full_papers/clark/clark_html/">Panic Password</a></p>
Posted in In einem Wort, IT, Security Tagged: Authentisierung, Nötigung <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1971/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1971/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1971/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1971&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/11/26/in-einem-wort-48/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Gewagt</title>
		<link>http://erichsieht.wordpress.com/2009/11/13/gewagt/</link>
		<comments>http://erichsieht.wordpress.com/2009/11/13/gewagt/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 10:07:30 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2231</guid>
		<description><![CDATA[IT-Sicherheit auf einem Bierdeckel. Am schönsten finde ich Aufpassen. Dieser Empfehlung kann nun wirklich niemand widersprechen.
Posted in IT, Security       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2231&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://www.pallas.com/fileadmin/img/content/publikationen/pallas_bierdeckel_selber-drucken.pdf">IT-Sicherheit auf einem Bierdeckel</a>. Am schönsten finde ich <em>Aufpassen</em>. Dieser Empfehlung kann nun wirklich niemand widersprechen.</p>
Posted in IT, Security  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2231/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2231&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/11/13/gewagt/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Epic Fail</title>
		<link>http://erichsieht.wordpress.com/2009/11/04/epic-fail/</link>
		<comments>http://erichsieht.wordpress.com/2009/11/04/epic-fail/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 14:47:42 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Geschäft]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vertrauen]]></category>
		<category><![CDATA[Gütesiegel]]></category>
		<category><![CDATA[TÜV]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2201</guid>
		<description><![CDATA[Unter der Überschrift: Die Illusion von Safer-Shopping nimmt Heise gerade das Online-Gütesiegel eines bekannten Anbieters auseinander:
»Nach der Datenpanne im vom TÜV Süd zertifizierten Online-Shop-System von Libri.de fanden sich nun Sicherheitslücken auf weiteren Sites, die das Safer-Shopping-Siegel tragen – und sogar auf dessen eigener Homepage. Neben Safer-Shopping.de waren Audible.de, ReifenDirekt.de und weg.de betroffen.«
Über Zertifizierung, Gütesiegel und [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2201&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Unter der Überschrift: <a href="http://www.heise.de/security/meldung/Die-Illusion-von-Safer-Shopping-848125.html">Die Illusion von Safer-Shopping</a> nimmt Heise gerade das Online-Gütesiegel eines bekannten Anbieters auseinander:</p>
<blockquote><p>»Nach der Datenpanne im vom TÜV Süd zertifizierten Online-Shop-System von Libri.de fanden sich nun Sicherheitslücken auf weiteren Sites, die das Safer-Shopping-Siegel tragen – und sogar auf dessen eigener Homepage. Neben Safer-Shopping.de waren Audible.de, ReifenDirekt.de und weg.de betroffen.«</p></blockquote>
<p>Über <a href="/2008/07/09/so-funktioniert-zertifizierung/">Zertifizierung</a>, <a href="/2008/12/14/sfer-gambling-tuv-gepruft/">Gütesiegel</a> und den <a href="/2009/03/18/eine-runde-tuv-bashing/">TÜV</a> gab es hier ja schon einiges zu lesen. Als Sekundärliteratur empfehle ich noch: <a href="http://daveshackleford.com/?p=211">10 Things Your Auditor Isn’t Telling You</a>.</p>
Posted in Geschäft, IT, Security, Vertrauen Tagged: Gütesiegel, TÜV <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2201/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2201/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2201/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2201&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/11/04/epic-fail/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>The Cloud Computing Consultant</title>
		<link>http://erichsieht.wordpress.com/2009/10/18/the-cloud-computing-consultant/</link>
		<comments>http://erichsieht.wordpress.com/2009/10/18/the-cloud-computing-consultant/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 18:55:22 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Geschäft]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[consultant]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2136</guid>
		<description><![CDATA[
(video link)
Posted in English, Geschäft, IT Tagged: Cloud Computing, consultant, Video      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2136&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="text-align:center; display: block;"><a href="http://erichsieht.wordpress.com/2009/10/18/the-cloud-computing-consultant/"><img src="http://img.youtube.com/vi/AIrroq5sV84/2.jpg" alt="" /></a></span></p>
<p>(<a title="The Cloud Computing Consultant" href="http://www.youtube.com/watch?v=AIrroq5sV84">video link</a>)</p>
Posted in English, Geschäft, IT Tagged: Cloud Computing, consultant, Video <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2136/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2136&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/10/18/the-cloud-computing-consultant/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/AIrroq5sV84/2.jpg" medium="image" />
	</item>
		<item>
		<title>White Hat Hacker Man</title>
		<link>http://erichsieht.wordpress.com/2009/10/14/white-hat-hacker-man/</link>
		<comments>http://erichsieht.wordpress.com/2009/10/14/white-hat-hacker-man/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 06:46:12 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Testlabor]]></category>
		<category><![CDATA[Paco Hope]]></category>
		<category><![CDATA[song]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2133</guid>
		<description><![CDATA[
(video link, lyrics)
Posted in English, IT, Security, Testlabor Tagged: Paco Hope, song, Video      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2133&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="text-align:center; display: block;"><a href="http://erichsieht.wordpress.com/2009/10/14/white-hat-hacker-man/"><img src="http://img.youtube.com/vi/Luy3P9-UVeI/2.jpg" alt="" /></a></span></p>
<p>(<a title="White Hat Hacker Man" href="http://www.youtube.com/watch?v=Luy3P9-UVeI">video link</a>, <a title="White Hat Hacker Man" href="http://www.cigital.com/justiceleague/2009/10/13/white-hat-hacker-man/">lyrics</a>)</p>
Posted in English, IT, Security, Testlabor Tagged: Paco Hope, song, Video <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2133/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2133/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2133/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2133&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/10/14/white-hat-hacker-man/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/Luy3P9-UVeI/2.jpg" medium="image" />
	</item>
		<item>
		<title>100 Dollar</title>
		<link>http://erichsieht.wordpress.com/2009/10/13/100-dollar/</link>
		<comments>http://erichsieht.wordpress.com/2009/10/13/100-dollar/#comments</comments>
		<pubDate>Tue, 13 Oct 2009 10:22:49 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Geschäft]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Preisschild]]></category>
		<category><![CDATA[Unterwegs]]></category>
		<category><![CDATA[BWL]]></category>
		<category><![CDATA[Gutschein]]></category>
		<category><![CDATA[Kalkulation]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2125</guid>
		<description><![CDATA[Hundert Dollar lässt sich T-Mobile USA den Datenverlust durch Serverausfall pro Kunde kosten. Scheinbar zumindest, denn statt Bargeld gibt es einen Gutschein, einzulösen bei T-Mobile USA. Weiß jemand, wie man die realen Kosten so einer Gutscheinaktion kalkuliert?
Posted in Geschäft, IT, Preisschild, Unterwegs Tagged: BWL, Gutschein, Kalkulation      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2125&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Hundert Dollar lässt sich T-Mobile USA den <a href="http://www.heise.de/mobil/meldung/Sidekick-Kunden-bekommen-100-US-Dollar-Schadenersatz-fuer-Datenverlust-823208.html">Datenverlust durch Serverausfall</a> pro Kunde kosten. Scheinbar zumindest, denn statt Bargeld gibt es einen Gutschein, einzulösen bei T-Mobile USA. Weiß jemand, wie man die realen Kosten so einer Gutscheinaktion kalkuliert?</p>
Posted in Geschäft, IT, Preisschild, Unterwegs Tagged: BWL, Gutschein, Kalkulation <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2125/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2125&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/10/13/100-dollar/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>1 Cent</title>
		<link>http://erichsieht.wordpress.com/2009/10/12/1-cent/</link>
		<comments>http://erichsieht.wordpress.com/2009/10/12/1-cent/#comments</comments>
		<pubDate>Mon, 12 Oct 2009 08:29:55 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Geschäft]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Preisschild]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[account]]></category>
		<category><![CDATA[E-Mail]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2119</guid>
		<description><![CDATA[Für 90 Dollar bekommt man 10.000 geklaute E-Mail-Accounts, ein einzelner Account ist also ungefähr einen Cent wert:
»Unterdessen rückt Rik Ferguson von Trend Micro den Vorfall in die richtige Perspektive. 10.000 gestohlene Account-Daten seien nichts Ungewöhnliches. Die würden auf dem freien Markt etwa 90 Dollar kosten – wenn man die üblichen 10 Prozent Rabatt abzieht.«
(heise Security: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2119&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Für 90 Dollar bekommt man 10.000 geklaute E-Mail-Accounts, ein einzelner Account ist also ungefähr einen Cent wert:</p>
<blockquote><p>»Unterdessen rückt <a href="http://countermeasures.trendmicro.eu/stolen-email-accounts-90-bucks-and-some-chinese-spam/">Rik Ferguson von Trend Micro</a> den Vorfall in die richtige Perspektive. 10.000 gestohlene Account-Daten seien nichts Ungewöhnliches. Die würden auf dem freien Markt etwa 90 Dollar kosten – wenn man die üblichen 10 Prozent Rabatt abzieht.«</p>
<p style="text-align:right;">(heise Security: <a href="http://www.heise.de/security/meldung/Test-fuer-kompromittierte-E-Mail-Accounts-821424.html">Test für kompromittierte E-Mail-Accounts</a>)</p>
</blockquote>
<p>Weiß jemand, wie hoch im Vergleich dazu der Schaden pro Account ist?</p>
Posted in Geschäft, IT, Preisschild, Security Tagged: account, E-Mail <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2119&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/10/12/1-cent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Digital Cold Reading: The CSS History Hack</title>
		<link>http://erichsieht.wordpress.com/2009/09/20/digitalcoldreading/</link>
		<comments>http://erichsieht.wordpress.com/2009/09/20/digitalcoldreading/#comments</comments>
		<pubDate>Sun, 20 Sep 2009 09:47:09 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wahrnehmung]]></category>
		<category><![CDATA[cold reading]]></category>
		<category><![CDATA[CSS history hack]]></category>
		<category><![CDATA[don't worry]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2034</guid>
		<description><![CDATA[[See only posts in English]
Cold reading is a technique used by mentalists to simulate psychic powers and impress people. Essentially, the cold reader is supplying words and the other person supplies their meaning as well as hints for the reader.
The CSS history hack, which seems to impress quite a few people, is nothing more than [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2034&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p style="text-align:right;">[<a href="/category/english/">See only posts in English</a>]</p>
<p><a href="http://en.wikipedia.org/wiki/Cold_reading">Cold reading</a> is a technique used by mentalists to simulate psychic powers and impress people. Essentially, the cold reader is <a href="http://www.youtube.com/watch?v=Xswt8B8-UTM">supplying words</a> and the other person supplies their meaning as well as hints for the reader.</p>
<p>The <a href="http://ha.ckers.org/weird/CSS-history-hack.html">CSS history hack</a>, which seems to impress quite a few people, is nothing more than the Web&#8217;s version of cold reading. Your impression is that any Web site can read your browser history. Now there is indeed an information leak and no Web site should get access to history information. But this leak is very small. It doesn&#8217;t reveal the history altogether to anyone daring to ask. The CSS history issue only gives us an oracle. We can ask the oracle whether a particular URL is in the history or not. So to find out that you&#8217;ve read this blog post we would have to ask the oracle about <a href="http://erichsieht.wordpress.com/2009/09/20/digitalcoldreading/">the precise URL of this post</a>.</p>
<p>Nonetheless demonstrations of the history hack impress people. The trick is simple and similar to the cold reading technique. History hack demos <a href="http://jeremiahgrossman.blogspot.com/2006/08/i-know-where-youve-been.html">use a set of URLs </a>that leads to a hit for almost every Internet user on the world: Google, YouTube, Microsoft, Wikipedia, Flickr, Apple, Slashdot, Amazon, and so on. A mentalist would guess and suggest these until you start giving feedback on which to hook. The CSS history hack replaces this interaction with asking the oracle to avoid wrong guesses. The trick is really to use a set of Web sites that guarantees a hit, and use a minor information leak to remove the wrong guesses from the set that would spoil the effect. This works well with the top 20/top 50/top 1000 sites on the Web, but it won&#8217;t scale to arbitrary URLs.</p>
Posted in English, IT, Phishing, Security, Wahrnehmung Tagged: cold reading, CSS history hack, don't worry <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2034/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2034/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2034/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2034&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/09/20/digitalcoldreading/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Häh?</title>
		<link>http://erichsieht.wordpress.com/2009/09/16/hah/</link>
		<comments>http://erichsieht.wordpress.com/2009/09/16/hah/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 18:02:55 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Freundlich zum Nutzer]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[O-Ton]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Dialogbox]]></category>
		<category><![CDATA[update]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2028</guid>
		<description><![CDATA[Kann mir jemand sagen, ob ich das möchte? Oder weiß wenigstens jemand, unter welchen Umständen so eine Meldung typischerweise zustandekommt? Der Text klingt ein wenig schräg, und der Hilfe-Button ist nur Dekoration.

Posted in Freundlich zum Nutzer, IT, O-Ton, Security Tagged: Acrobat, Adobe, Dialogbox, update      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2028&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Kann mir jemand sagen, ob ich das möchte? Oder weiß wenigstens jemand, unter welchen Umständen so eine Meldung typischerweise zustandekommt? Der Text klingt ein wenig schräg, und der <em>Hilfe</em>-Button ist nur Dekoration.</p>
<p><img class="alignnone size-full wp-image-2029" title="Ein neues Update für die Sicherheitseinstellungen ist unter Adobe Systems verfügbar. Möchten Sie es jetzt installieren?" src="http://erichsieht.files.wordpress.com/2009/09/ein_neues_update.png?w=450&#038;h=151" alt="Ein neues Update für die Sicherheitseinstellungen ist unter Adobe Systems verfügbar. Möchten Sie es jetzt installieren?" width="450" height="151" /></p>
Posted in Freundlich zum Nutzer, IT, O-Ton, Security Tagged: Acrobat, Adobe, Dialogbox, update <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2028/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2028/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2028/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2028/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2028/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2028/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2028/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2028/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2028/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2028/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2028&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/09/16/hah/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>

		<media:content url="http://erichsieht.files.wordpress.com/2009/09/ein_neues_update.png" medium="image">
			<media:title type="html">Ein neues Update für die Sicherheitseinstellungen ist unter Adobe Systems verfügbar. Möchten Sie es jetzt installieren?</media:title>
		</media:content>
	</item>
		<item>
		<title>Schnäppchenpreis</title>
		<link>http://erichsieht.wordpress.com/2009/09/16/schnappchenpreis/</link>
		<comments>http://erichsieht.wordpress.com/2009/09/16/schnappchenpreis/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 08:25:27 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[Geschäft]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Zahlenspiele]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2023</guid>
		<description><![CDATA[»Ein Botnetz, das zwischen 5000 und 10.000 Bots kontrolliert, kann laut Wüest für 10 US-Dollar pro Woche gemietet werden.«
(Heise online: Spam-Bots werten soziale Netze aus)

Posted in Geschäft, IT, Security, Zahlenspiele       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2023&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote><p>»Ein Botnetz, das zwischen 5000 und 10.000 Bots kontrolliert, kann laut Wüest für 10 US-Dollar pro Woche gemietet werden.«</p>
<p style="text-align:right;">(Heise online: <a href="http://www.heise.de/newsticker/Spam-Bots-werten-soziale-Netze-aus--/meldung/145344">Spam-Bots werten soziale Netze aus</a>)</p>
</blockquote>
Posted in Geschäft, IT, Security, Zahlenspiele  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2023/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2023/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2023/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2023/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2023/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2023/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2023/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2023/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2023/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2023/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2023&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/09/16/schnappchenpreis/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Swiss Cheese Security</title>
		<link>http://erichsieht.wordpress.com/2009/09/08/changing-the-world-or-maybe-not/</link>
		<comments>http://erichsieht.wordpress.com/2009/09/08/changing-the-world-or-maybe-not/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 12:02:07 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Forschung]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Unterwegs]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[NSPW]]></category>
		<category><![CDATA[Oxford]]></category>
		<category><![CDATA[paradigm]]></category>
		<category><![CDATA[security policy]]></category>
		<category><![CDATA[Swiss Cheese]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=2017</guid>
		<description><![CDATA[I&#8217;m off for the New Security Paradigms Workshop in Oxford, where I will present what I currently call the Swiss Cheese security policy model. My idea is to model security mechanisms as classifiers, and security problems in a separate world model as classification problems. In such a model we can (hopefully) analyze how well a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2017&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I&#8217;m off for the <a href="http://www.nspw.org/2009">New Security Paradigms Workshop</a> in <a href="/2008/09/09/oxford/">Oxford</a>, where I will present what I currently call the <em>Swiss Cheese security policy model</em>. My idea is to model security mechanisms as classifiers, and security problems in a separate world model as classification problems. In such a model we can (hopefully) analyze how well a mechanism or a combination of mechanisms solves the actual problem. NSPW is my first test-driving of the general idea. If it survives the workshop I&#8217;m going to work out the details. My paper isn&#8217;t available yet; <a href="/2009/11/27/nspw-2009-papers-online/">final versions of NSPW papers</a> are to be submitted a few weeks after the workshop.</p>
Posted in English, Forschung, IT, Security, Unterwegs Tagged: 2009, NSPW, Oxford, paradigm, security policy, Swiss Cheese <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/2017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/2017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/2017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/2017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/2017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/2017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/2017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/2017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/2017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/2017/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=2017&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/09/08/changing-the-world-or-maybe-not/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>In einem Wort</title>
		<link>http://erichsieht.wordpress.com/2009/09/08/in-einem-wort-31/</link>
		<comments>http://erichsieht.wordpress.com/2009/09/08/in-einem-wort-31/#comments</comments>
		<pubDate>Tue, 08 Sep 2009 09:19:47 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[In einem Wort]]></category>
		<category><![CDATA[Testlabor]]></category>
		<category><![CDATA[software test]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1693</guid>
		<description><![CDATA[C-DLICE
Posted in In einem Wort, IT, Testlabor Tagged: software test      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1693&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://shrinik.blogspot.com/2009/03/c-dliceing-in-software-testing.html">C-DLICE</a></p>
Posted in In einem Wort, IT, Testlabor Tagged: software test <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1693/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1693/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1693/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1693/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1693/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1693/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1693/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1693/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1693/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1693/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1693&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/09/08/in-einem-wort-31/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Production-safe Testing</title>
		<link>http://erichsieht.wordpress.com/2009/09/01/production-safe-testing/</link>
		<comments>http://erichsieht.wordpress.com/2009/09/01/production-safe-testing/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 17:58:48 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Safety]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Testlabor]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[precautions]]></category>
		<category><![CDATA[production]]></category>
		<category><![CDATA[ScanAuth]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[TAIC-PART]]></category>
		<category><![CDATA[Test]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1994</guid>
		<description><![CDATA[[See only posts in English]
Software testers increasingly have to deal with production systems. Some tests make sense only with production systems, such as Nessus-style vulnerability scanning. And an increasing number of systems is hard to reproduce in a test bed as the system is really a mashup of services, sharing infrastructure with other systems on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1994&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p style="text-align:right;">[<a href="/category/english/">See only posts in English</a>]</p>
<p>Software testers increasingly have to deal with production systems. Some tests make sense only with production systems, such as Nessus-style vulnerability scanning. And an increasing number of systems is hard to reproduce in a test bed as the system is really a mashup of services, sharing infrastructure with other systems on various levels of abstraction.</p>
<p>Testing production systems imposes an additional requirement upon the tester, production safety. Testing is production-safe if it does not cause undesired side-effects for the users of the tested or any other system. Potential side effects are manifold: denial of service, information disclosure, real-world effects caused by test inputs, or alteration of production data, to name just a few. Testers of production systems therefore must take precautions to limit the risks of their testing.</p>
<p>Unfortunately it is not yet very clear what this means in practice. Jeremiah Grossman unwittingly <a href="http://jeremiahgrossman.blogspot.com/2009/08/website-va-vendor-comparison-chart.html">started</a> a <a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/08/24/asc-products-are-quot-production-ready-quot.aspx">discussion</a> when he made production-saftey a criterion in his comparison of Website vulnerability assessment vendors. Yesterday he followed up on this matter with a <a href="http://jeremiahgrossman.blogspot.com/2009/08/production-safe-website-scanning.html">questionnaire</a>, which is supposed to help vendors and their clients to discuss production-safety.</p>
<p>The time is just right to point to our own contribution to this discussion. We felt a lack of documented best practice for production-safe testing, so we documented what we learned over a few years of security testing. The result is a short paper, which my colleague and co-author Jörn is going to present this weekend at the <a href="http://www2009.taicpart.org/">TAIC PART 2009</a> conference: <a href="http://testlab.sit.fraunhofer.de//downloads/Publications/tuerpe_eichler_Testing_production_systems_safely_-_Common_precautions_in_penetration_testing_TAIC_PART_2009.pdf">Testing Production Systems Safely: Common Precautions in Penetration Testing</a>. In this paper we tried to generalize our solutions to the safety problems we encountered.</p>
<p>The issue is also being discussed in the cloud computing community, but their starting point is slightly different. Service providers might want to ban activities such as automated scanning, and deploy technical and legal measures to enforce such a ban. They have good reason to do so, but their users may have equally good reason to do security testing. One proposal being discussed is a <a href="http://cloudsecurity.org/2009/06/28/vulnerability-scanning-and-clouds-an-attempt-to-move-the-dialog-on/"><em>ScanAuth API</em> to separate legitimate from rogue scans</a>. Such an API will, however, only solve the formal part of the problem. Legitimate testing still needs to be production-safe.</p>
Posted in English, IT, Safety, Security, Testlabor Tagged: 2009, precautions, production, ScanAuth, Software, TAIC-PART, Test <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1994/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1994&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/09/01/production-safe-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Management ohne Metriken</title>
		<link>http://erichsieht.wordpress.com/2009/08/23/management-ohne-metriken/</link>
		<comments>http://erichsieht.wordpress.com/2009/08/23/management-ohne-metriken/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 11:07:44 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[IT]]></category>
		<category><![CDATA[O-Ton]]></category>
		<category><![CDATA[Risiko]]></category>
		<category><![CDATA[DeMarco]]></category>
		<category><![CDATA[Guru]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[Metrik]]></category>
		<category><![CDATA[Risikomanagement]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1963</guid>
		<description><![CDATA[Der eine oder andere dürfte es mitbekommen haben. Tom DeMarco, dem wir die Manager-Faustregel: “You can’t control what you can’t measure.” verdanken, macht einen Rückzieher. An Software Engineering will er nicht mehr so recht glauben, und an Metriken auch nicht. In seinem Artikel Software Engineering: An Idea Whose Time Has Come and Gone? erläutert er [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1963&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Der eine oder andere dürfte es mitbekommen haben. Tom DeMarco, dem wir die Manager-Faustregel: “You can’t control what you can’t measure.” verdanken, macht einen Rückzieher. An Software Engineering will er nicht mehr so recht glauben, und an Metriken auch nicht. In seinem Artikel <a href="http://www2.computer.org/cms/Computer.org/ComputingNow/homepage/2009/0709/rW_SO_Viewpoints.pdf">Software Engineering: An Idea Whose Time Has Come and Gone?</a> erläutert er seinen Sinneswandel unter anderem an diesem Beispiel:</p>
<blockquote><p>»Imagine you’re trying to control a teenager’s upbringing. The very idea of controlling your child ought to make you at least a little bit queasy. Yet the stakes for control couldn’t be higher.<br />
(&#8230;)<br />
Now apply “You can’t control what you can’t measure” to the teenager. Most things that really matter—honor, dignity, discipline, personality, grace under pressure, values, ethics, resourcefulness, loyalty, humor, kindness—aren’t measurable.«</p>
<p style="text-align:right;">
</blockquote>
<p>Von der Vorstellung, wir könnten ausgerechnet in der IT-Sicherheit Risiken anhand von Metriken steuern, sollten wird uns schnell verabschieden. Zusätzliche Unbekannte und Rückkopplungen vereinfachen das Problem sicher nicht.</p>
<p>Ach ja, und hört nicht auf Gurus.</p>
Posted in IT, O-Ton, Risiko Tagged: DeMarco, Guru, Management, Metrik, Risikomanagement <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1963/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1963/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1963/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1963/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1963/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1963/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1963/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1963/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1963/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1963/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1963&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/08/23/management-ohne-metriken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>In einem Wort</title>
		<link>http://erichsieht.wordpress.com/2009/08/04/in-einem-wort-38/</link>
		<comments>http://erichsieht.wordpress.com/2009/08/04/in-einem-wort-38/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 18:54:50 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[In einem Wort]]></category>
		<category><![CDATA[Risiko]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Cloud Computing]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1782</guid>
		<description><![CDATA[cloudenfreude (via)
Posted in English, In einem Wort, IT, Risiko, Security Tagged: Cloud Computing      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1782&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://newschoolsecurity.com/2009/05/definitions-cloudenfreude/">cloudenfreude</a> (<a href="http://1raindrop.typepad.com/1_raindrop/2009/05/schadenfreude-in-the-cloud.html">via</a>)</p>
Posted in English, In einem Wort, IT, Risiko, Security Tagged: Cloud Computing <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1782/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1782/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1782/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1782/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1782/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1782/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1782/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1782/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1782/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1782/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1782&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/08/04/in-einem-wort-38/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet helpdesk</title>
		<link>http://erichsieht.wordpress.com/2009/07/31/internet-helpdesk/</link>
		<comments>http://erichsieht.wordpress.com/2009/07/31/internet-helpdesk/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 22:00:40 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Freundlich zum Nutzer]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[helpdesk]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1697</guid>
		<description><![CDATA[
(direct, via)
Posted in English, Freundlich zum Nutzer, IT Tagged: helpdesk, Internet, sysadmin, Video      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1697&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="text-align:center; display: block;"><a href="http://erichsieht.wordpress.com/2009/07/31/internet-helpdesk/"><img src="http://img.youtube.com/vi/1LLTsSnGWMI/2.jpg" alt="" /></a></span></p>
<p>(<a href="http://www.youtube.com/watch?v=1LLTsSnGWMI">direct</a>, <a href="http://itknowledgeexchange.techtarget.com/whatis/wes-borg-internet-help-desk/">via</a>)</p>
Posted in English, Freundlich zum Nutzer, IT Tagged: helpdesk, Internet, sysadmin, Video <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1697/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1697/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1697/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1697/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1697/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1697/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1697/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1697/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1697/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1697/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1697&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/07/31/internet-helpdesk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/1LLTsSnGWMI/2.jpg" medium="image" />
	</item>
		<item>
		<title>50 Ways to Inject Your SQL</title>
		<link>http://erichsieht.wordpress.com/2009/07/05/50-ways-to-inject-your-sql/</link>
		<comments>http://erichsieht.wordpress.com/2009/07/05/50-ways-to-inject-your-sql/#comments</comments>
		<pubDate>Sun, 05 Jul 2009 15:16:22 +0000</pubDate>
		<dc:creator>Sven Türpe</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[Hackmeck]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[Video]]></category>

		<guid isPermaLink="false">http://erichsieht.wordpress.com/?p=1882</guid>
		<description><![CDATA[
(direct link, found here)
Posted in English, Hackmeck, IT, Security Tagged: SQL injection, Video      <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1882&subd=erichsieht&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><span style="text-align:center; display: block;"><a href="http://erichsieht.wordpress.com/2009/07/05/50-ways-to-inject-your-sql/"><img src="http://img.youtube.com/vi/5pSsLnNJIa4/2.jpg" alt="" /></a></span></p>
<p>(<a href="http://www.youtube.com/watch?v=5pSsLnNJIa4">direct link</a>, found <a href="http://www.cigital.com/justiceleague/2009/06/16/50-ways-to-inject-your-sql/">here</a>)</p>
Posted in English, Hackmeck, IT, Security Tagged: SQL injection, Video <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/erichsieht.wordpress.com/1882/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/erichsieht.wordpress.com/1882/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/erichsieht.wordpress.com/1882/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/erichsieht.wordpress.com/1882/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/erichsieht.wordpress.com/1882/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/erichsieht.wordpress.com/1882/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/erichsieht.wordpress.com/1882/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/erichsieht.wordpress.com/1882/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/erichsieht.wordpress.com/1882/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/erichsieht.wordpress.com/1882/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=erichsieht.wordpress.com&blog=2088318&post=1882&subd=erichsieht&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://erichsieht.wordpress.com/2009/07/05/50-ways-to-inject-your-sql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Sven Türpe</media:title>
		</media:content>

		<media:content url="http://img.youtube.com/vi/5pSsLnNJIa4/2.jpg" medium="image" />
	</item>
	</channel>
</rss>