<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for ethicalhack3r</title>
	<atom:link href="http://www.ethicalhack3r.co.uk/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ethicalhack3r.co.uk</link>
	<description></description>
	<lastBuildDate>Sun, 05 Sep 2010 07:09:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
	<item>
		<title>Comment on Hacking DECT by Organic Gardening Tips</title>
		<link>http://www.ethicalhack3r.co.uk/security/hacking-dect/comment-page-1/#comment-111378</link>
		<dc:creator>Organic Gardening Tips</dc:creator>
		<pubDate>Sun, 05 Sep 2010 07:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=137#comment-111378</guid>
		<description>Finally a blog post that&#039;s really worth reading. There&#039;re particular things I disagree although  haha. :)</description>
		<content:encoded><![CDATA[<p>Finally a blog post that&#8217;s really worth reading. There&#8217;re particular things I disagree although  haha. :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on My new Acer Aspire One by reduce belly fat</title>
		<link>http://www.ethicalhack3r.co.uk/security/my-new-acer-aspire-one/comment-page-1/#comment-111131</link>
		<dc:creator>reduce belly fat</dc:creator>
		<pubDate>Fri, 03 Sep 2010 09:38:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=145#comment-111131</guid>
		<description>It is awesome to come across something worth looking at. Seems like everyone is starting a blog and tossing up whatever pops into their head. Most of the time it does not make good sense. I am pleased to see that is not the case here.</description>
		<content:encoded><![CDATA[<p>It is awesome to come across something worth looking at. Seems like everyone is starting a blog and tossing up whatever pops into their head. Most of the time it does not make good sense. I am pleased to see that is not the case here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Using a web bug for information gathering by isaias</title>
		<link>http://www.ethicalhack3r.co.uk/security/using-a-web-bug-for-information-gathering/comment-page-1/#comment-110983</link>
		<dc:creator>isaias</dc:creator>
		<pubDate>Wed, 01 Sep 2010 20:10:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=160#comment-110983</guid>
		<description>&lt;a href=&quot;http://163.23.99.200/php/plog129/index.php?op=ViewArticle&amp;articleId=683&amp;blogId=74&quot; rel=&quot;nofollow&quot;&gt;tiffani amber thiessen hairstyles&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p><a href="http://163.23.99.200/php/plog129/index.php?op=ViewArticle&amp;articleId=683&amp;blogId=74" rel="nofollow">tiffani amber thiessen hairstyles</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DropBox Security by Mr. Shiney</title>
		<link>http://www.ethicalhack3r.co.uk/security/dropbox-security/comment-page-1/#comment-109721</link>
		<dc:creator>Mr. Shiney</dc:creator>
		<pubDate>Wed, 18 Aug 2010 01:49:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=756#comment-109721</guid>
		<description>This is an interesting look at the risks to drop-box. A warning about using TrueCrypt with dropbox -- because of way drop-box works, only syncing the bits of a TC container that have changed, a person may be able to guess your TC secret key by capturing this changed data several times. Another warning about dropbox and danger of public file leaks: http://tgfblogged.blogspot.com/2010/06/dropbox-has-issue-with-way-it-handles.html  

I think DB has some serious security concerns.</description>
		<content:encoded><![CDATA[<p>This is an interesting look at the risks to drop-box. A warning about using TrueCrypt with dropbox &#8212; because of way drop-box works, only syncing the bits of a TC container that have changed, a person may be able to guess your TC secret key by capturing this changed data several times. Another warning about dropbox and danger of public file leaks: <a href="http://tgfblogged.blogspot.com/2010/06/dropbox-has-issue-with-way-it-handles.html" rel="nofollow">http://tgfblogged.blogspot.com/2010/06/dropbox-has-issue-with-way-it-handles.html</a>  </p>
<p>I think DB has some serious security concerns.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Defcon too far? Blackhat too expensive? No problem! by Isa Galapon</title>
		<link>http://www.ethicalhack3r.co.uk/security/defcon-too-far-blackhat-too-expensive-no-problem/comment-page-1/#comment-108641</link>
		<dc:creator>Isa Galapon</dc:creator>
		<pubDate>Fri, 06 Aug 2010 15:35:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=272#comment-108641</guid>
		<description>Yeah, burn an Ubuntu Live CD and run the installer on boot. When it comes to the partitioning step just put that you want to erase the harddrive and install Ubuntu.</description>
		<content:encoded><![CDATA[<p>Yeah, burn an Ubuntu Live CD and run the installer on boot. When it comes to the partitioning step just put that you want to erase the harddrive and install Ubuntu.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DropBox Security by admin</title>
		<link>http://www.ethicalhack3r.co.uk/security/dropbox-security/comment-page-1/#comment-108187</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 03 Aug 2010 14:35:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=756#comment-108187</guid>
		<description>@pento 
There may be some web application vulnerabilities from the OWASP Top 10 that affect the DropBox site. But looking for these intentionally without permission may be considered unethical. 

@Andrew
Great idea! 

@Marc
I wrote a quick Python script to brute force the Public folder file names. So far I have only found a couple of index.html files, nothing too interesting, but with more time and refinement I&#039;m sure something would pop up. Of course this is ethical and legal as DropBox state that the information in users Public files are, well, public.</description>
		<content:encoded><![CDATA[<p>@pento<br />
There may be some web application vulnerabilities from the OWASP Top 10 that affect the DropBox site. But looking for these intentionally without permission may be considered unethical. </p>
<p>@Andrew<br />
Great idea! </p>
<p>@Marc<br />
I wrote a quick Python script to brute force the Public folder file names. So far I have only found a couple of index.html files, nothing too interesting, but with more time and refinement I&#8217;m sure something would pop up. Of course this is ethical and legal as DropBox state that the information in users Public files are, well, public.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DropBox Security by Marc Ruef</title>
		<link>http://www.ethicalhack3r.co.uk/security/dropbox-security/comment-page-1/#comment-108182</link>
		<dc:creator>Marc Ruef</dc:creator>
		<pubDate>Tue, 03 Aug 2010 14:05:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=756#comment-108182</guid>
		<description>Hello,

Nice article! Especially the guessing of public folder names is going to be interesting. I think in a few days/weeks someone is coming up with a crawler ...

Regards,

Marc</description>
		<content:encoded><![CDATA[<p>Hello,</p>
<p>Nice article! Especially the guessing of public folder names is going to be interesting. I think in a few days/weeks someone is coming up with a crawler &#8230;</p>
<p>Regards,</p>
<p>Marc</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DropBox Security by Andrew Waite</title>
		<link>http://www.ethicalhack3r.co.uk/security/dropbox-security/comment-page-1/#comment-108179</link>
		<dc:creator>Andrew Waite</dc:creator>
		<pubDate>Tue, 03 Aug 2010 13:29:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=756#comment-108179</guid>
		<description>Nice write-up.

For the overly paranoid (like me), turn your DropBox folder into a TrueCrypt container and store your files in there. This way if someone (DropBox employee or third party) does gain access to your account they still can&#039;t access your actual data without either breaking the crypto or gaining your (hopefully complex) TrueCrypt password. Of course if they&#039;ve compromised your machine and installed keylogger your still in trouble; but as you say, you&#039;ve probably got bigger problems.

--Andrew

P.S. thanks to @baconzombie for suggesting the combination to me a while back.</description>
		<content:encoded><![CDATA[<p>Nice write-up.</p>
<p>For the overly paranoid (like me), turn your DropBox folder into a TrueCrypt container and store your files in there. This way if someone (DropBox employee or third party) does gain access to your account they still can&#8217;t access your actual data without either breaking the crypto or gaining your (hopefully complex) TrueCrypt password. Of course if they&#8217;ve compromised your machine and installed keylogger your still in trouble; but as you say, you&#8217;ve probably got bigger problems.</p>
<p>&#8211;Andrew</p>
<p>P.S. thanks to @baconzombie for suggesting the combination to me a while back.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on DropBox Security by Pento</title>
		<link>http://www.ethicalhack3r.co.uk/security/dropbox-security/comment-page-1/#comment-108176</link>
		<dc:creator>Pento</dc:creator>
		<pubDate>Tue, 03 Aug 2010 12:52:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=756#comment-108176</guid>
		<description>Most of items are looks like farfetched.
But idea to review Dropbox security controls is really interesting. You also forget that Dropbox as usual webapp may have something from OWASP Top 10 like xss =)</description>
		<content:encoded><![CDATA[<p>Most of items are looks like farfetched.<br />
But idea to review Dropbox security controls is really interesting. You also forget that Dropbox as usual webapp may have something from OWASP Top 10 like xss =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Glastopf &#8211; Web Application Honeypot by Panix</title>
		<link>http://www.ethicalhack3r.co.uk/security/glastopf-web-application-honeypot/comment-page-1/#comment-106728</link>
		<dc:creator>Panix</dc:creator>
		<pubDate>Fri, 23 Jul 2010 23:43:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=496#comment-106728</guid>
		<description>Oh yeah, the web interface for glastopf (GlasIF) is pretty sweet as well.  Make sure you log to a MySQL database! :)</description>
		<content:encoded><![CDATA[<p>Oh yeah, the web interface for glastopf (GlasIF) is pretty sweet as well.  Make sure you log to a MySQL database! :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
