<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>.:SSLFail:. &#187; SecTor</title>
	<atom:link href="http://www.sslfail.com/tag/sector/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Sat, 24 Jul 2010 14:50:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Server Outage</title>
		<link>http://www.sslfail.com/2009/10/server-outage/</link>
		<comments>http://www.sslfail.com/2009/10/server-outage/#comments</comments>
		<pubDate>Sun, 11 Oct 2009 17:34:01 +0000</pubDate>
		<dc:creator>Tyler</dc:creator>
				<category><![CDATA[Site Related]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[server fail]]></category>
		<category><![CDATA[sslfail.com]]></category>

		<guid isPermaLink="false">http://www.sslfail.com/?p=377</guid>
		<description><![CDATA[Anyone who tried to access SSLFail.com late last night or this morning would have noticed that it was down.  I apparently caused my own server outage with python. Here&#8217;s how it happened.
When sockstress was first discussed I was rather intrigued and thought about it for a bit, but then I quickly abandoned it&#8230; I just [...]]]></description>
			<content:encoded><![CDATA[<p>Anyone who tried to access SSLFail.com late last night or this morning would have noticed that it was down.  I apparently caused my own server outage with python. Here&#8217;s how it happened.</p>
<p>When <a href="http://blog.robertlee.name/2008/08/updates.html">sockstress</a> was first discussed I was rather intrigued and thought about it for a bit, but then I quickly abandoned it&#8230; I just had too many other things on my plate. However discussions at <a href="http://www.sector.ca/">SecTOR</a> renewed my interest in exploring how this tool worked. After a bit of googling, I found <a href="http://www.checkpoint.com/defense/advisories/public/announcement/090809-tcpip-dos-sockstress.html">this page</a> which gives an explanation of what is occurring, although I wasn&#8217;t sure if it was correct. It did, however, fit with the &#8216;TCP/IP Zero Window Size Vulnerability&#8217; in <a href="http://www.microsoft.com/technet/security/Bulletin/ms09-048.mspx">MS09-048</a>.</p>
<p>I decided I would code up the diagram on the Check Point page and see what happened when I tested it. I started writing in python using SOCK_RAW and was ready to send my first packet&#8230; or so I&#8217;d thought. I forgot to send an appropriate Ethernet header, which meant parsing the packet found garbage instead of a valid packet&#8230; and port security on on the switch found an invalid MAC address and quickly disabled the port. Which means no more using the SSLFail.com server for playing with raw sockets.</p>
<p>Anyways, everything is back up and running now.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sslfail.com/2009/10/server-outage/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSLFail Panel Interview on DarkReading</title>
		<link>http://www.sslfail.com/2009/10/sslfail-panel-interview-on-darkreading/</link>
		<comments>http://www.sslfail.com/2009/10/sslfail-panel-interview-on-darkreading/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 21:53:56 +0000</pubDate>
		<dc:creator>Tyler</dc:creator>
				<category><![CDATA[Site Related]]></category>
		<category><![CDATA[DarkReading]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[sslfail.com]]></category>

		<guid isPermaLink="false">http://www.sslfail.com/?p=370</guid>
		<description><![CDATA[I just wanted to point to an awesome article from Kelly Jackson Higgins on DarkReading. I can call it awesome because it&#8217;s about the SSLFail panel at SecTOR and includes quite a bit of the information we shared with attendees, so for anyone not at SecTOR and not wanting to look at the raw data [...]]]></description>
			<content:encoded><![CDATA[<p>I just wanted to point to <a href="http://darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=220301548&amp;cid=RSSfeed">an awesome article</a> from Kelly Jackson Higgins on DarkReading. I can call it awesome because it&#8217;s about the SSLFail panel at <a href="http://www.sector.ca/">SecTOR</a> and includes quite a bit of the information we shared with attendees, so for anyone not at SecTOR and not wanting to look at the raw data (which is coming soon)&#8230; it provides an awesome overview. Mike and I really enjoyed the opportunity to sit down and talk with Kelly and had realized at the end of the call that we had a much better idea of what we were going to discuss on the panel than we did before the interview. So everyone who enjoyed the discussion points on the panel has Kelly to thank for that.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sslfail.com/2009/10/sslfail-panel-interview-on-darkreading/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSLFail @ SecTor</title>
		<link>http://www.sslfail.com/2009/09/sslfail-sector/</link>
		<comments>http://www.sslfail.com/2009/09/sslfail-sector/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 04:21:22 +0000</pubDate>
		<dc:creator>Tyler</dc:creator>
				<category><![CDATA[Site Related]]></category>
		<category><![CDATA[SecTor]]></category>
		<category><![CDATA[sslfail.com]]></category>

		<guid isPermaLink="false">http://www.sslfail.com/?p=366</guid>
		<description><![CDATA[I&#8217;ve been a huge fan of SecTor since the first year it ran and have been fairly vocal about people attending. This year there&#8217;s an extra special reason to attend though, a couple of SSLFail.com bloggers will be doing a panel, we may even have a special guest join us. You&#8217;ll have to attend the [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been a huge fan of <a href="http://www.sector.ca/">SecTor</a> since the first year it ran and have been fairly vocal about people attending. This year there&#8217;s an extra special reason to attend though, a couple of SSLFail.com bloggers will be doing a panel, we may even have a special guest join us. You&#8217;ll have to attend the talk to find out.</p>
<p>As for the subject&#8230; we don&#8217;t really know. In fact we&#8217;re a week away from presenting and it&#8217;s still up in the air to some extent. From what I&#8217;ve heard you can expect Lolcats, interesting information and some survey results. Anyways, if you&#8217;re at SecTor and the Nsploit and Ghostnet talks are full (and I suspect they will be, I wanted to see both of them)&#8230; we&#8217;re the only option you have left &#8212; so come and join us!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sslfail.com/2009/09/sslfail-sector/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
