<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-36902659</id><updated>2011-07-30T11:10:43.426-07:00</updated><title type='text'>Public Soliloquy</title><subtitle type='html'>The view of the world through the eyes of a security researcher.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>18</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-36902659.post-8734580564081199817</id><published>2011-05-27T05:57:00.000-07:00</published><updated>2011-05-27T06:03:15.685-07:00</updated><title type='text'>What is a curmudgeon?</title><content type='html'>"&lt;a href="http://attrition.org/~jericho/works/security/curmudgeon.html"&gt;A Curmudgeonly Reply to an Anti-Curmudgeon Rant&lt;/a&gt;" &lt;br /&gt;&lt;br /&gt;"At some point, a curmudgeon may be born; but only if the person still genuinely cares in some fashion." -jericho (attrition.org)&lt;br /&gt;&lt;br /&gt;I was going to say something nice about this quote via twitter but after reading it 10 or 15 times started to realize the wider implications couldn’t be summarized within 140 characters.  So, here goes...&lt;br /&gt;&lt;br /&gt;I was struck by the vulnerability in that statement.  It says that one becomes bitter (a curmudgeon) toward something for as long as they still care about it.  The state of being a curmudgeon is really one of a cynic boldly and resiliently expressing hope in the only way that they can.  A curmudgeon is twisted, harsh, and can be damaging to those around them but their unforgiving methods could also be exactly what’s necessary to impact change.   &lt;br /&gt;&lt;br /&gt;Those words have far reaching implications much beyond the security industry.  It has reminded me of many things about human nature and complacency.  Thanks for this.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-8734580564081199817?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/8734580564081199817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=8734580564081199817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/8734580564081199817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/8734580564081199817'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2011/05/my-response-to-curmudgeonly-reply-to.html' title='What is a curmudgeon?'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-2889394224063079391</id><published>2010-05-13T06:59:00.000-07:00</published><updated>2010-05-13T07:01:16.029-07:00</updated><title type='text'>Metasploit Class Videos posted</title><content type='html'>Thanks again Adrian "Irongeek" Crenshaw for arranging this.  It was great!&lt;br /&gt;&lt;br /&gt;Email from Irongeek:&lt;br /&gt;----------------&lt;br /&gt;In case you missed something, wish to review, or could not make it, here are the videos from the Metasploit class we held last Saturday:&lt;br /&gt;&lt;br /&gt;http://www.irongeek.com/i.php?page=videos/metasploit-class&lt;br /&gt;&lt;br /&gt;After cutting out the stops, it's about 4hrs long.&lt;br /&gt;&lt;br /&gt;Thanks to David "ReL1K" Kennedy, Martin "PureHate" Bos, Elliott "Nullthreat" Cutright, Pwrcycle for teaching.&lt;br /&gt;--------------------&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-2889394224063079391?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/2889394224063079391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=2889394224063079391' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/2889394224063079391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/2889394224063079391'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/05/metasploit-class-videos-posted.html' title='Metasploit Class Videos posted'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-8207479695712582658</id><published>2010-05-12T18:14:00.000-07:00</published><updated>2010-05-12T19:03:58.129-07:00</updated><title type='text'>Indiana Cyber Security Conference</title><content type='html'>Today I attended the Indiana Cyber Security Conference in Indianapolis.  Upon seeing the agenda several weeks ago I was impressed that the participating local organizations were able to garner such an impressive list of speakers: Eugene Spafford, Howard Schmidt, and Dan McWhorter to name a few.  &lt;br /&gt;&lt;br /&gt;While much of the day was spent beating the same old dead horses - APT, China, overall doom-n-gloom, there were several points that caught my attention that I would like to relate here.  &lt;br /&gt;&lt;br /&gt;Howard Schmidt mentioned .gov’s desire to increase transparency for the private sector.  It was refreshing to come away thinking that gov is finally starting to realize that setting on information doesn’t help those of us manning the front lines.  It will be interesting to see how this unfolds. &lt;br /&gt;&lt;br /&gt;Mr. Schmidt also mentioned the need for “trusted internet connections” and to collapse disparate endnotes into a smaller number of more manageable connections.  I’m a little unclear if this extends to both gov and ISPs.  The overall idea reinforced by this is one that I too share: the more complex a system, the more difficult it is to secure. &lt;br /&gt;&lt;br /&gt;Mr. Schmidt also talked about something called “CyberScope.”  I quick search turned up: “Ultimately CyberScope will result in a “cybersecurity dashboard,” not unlike the IT Dashboard (it.usaspending.gov) that currently tracks federal spending on IT projects.”&lt;br /&gt;Read more here: http://csis.org/blog/fisma-cyberscope-and-federal-it-security&lt;br /&gt;&lt;br /&gt;Dan McWhorter of Mandiant discussed his experiences in incident response.  He said that attackers have a hierarchical structure much like we see in normal business with higher valued targets being assigned to teams with more competence.  I had always assumed attacker organizational sophistication was increasing, but having no direct exposure to large scale incident response I had no idea as to what level it had grown.  He reviewed a case study covering an attack where data was being exfiltrated that I found immensely interesting.  &lt;br /&gt;&lt;br /&gt;He also said that company’s need to redefine the “win.”  I find this of particular interest being employed by a medium sized business that has never seen a large scale breach.  Because of that lack of exposure when it eventually occurs management can react unpredictably because their definition of a win differs from reality. &lt;br /&gt;&lt;br /&gt;Overall, it was an informative day.  Thanks to all the organizers and sponsors.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-8207479695712582658?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/8207479695712582658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=8207479695712582658' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/8207479695712582658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/8207479695712582658'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/05/indiana-cyber-security-conference.html' title='Indiana Cyber Security Conference'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-3382741079430071361</id><published>2010-05-12T08:36:00.001-07:00</published><updated>2010-05-12T08:36:33.271-07:00</updated><title type='text'></title><content type='html'>Today I am attending the Indiana Cyber Security Conference being held downtown at Indiana government center south.  I&amp;#39;ll recap the material tonight.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-3382741079430071361?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/3382741079430071361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=3382741079430071361' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/3382741079430071361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/3382741079430071361'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/05/today-i-am-attending-indiana-cyber.html' title=''/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-4193945613497399544</id><published>2010-05-08T16:41:00.000-07:00</published><updated>2010-05-08T16:45:01.577-07:00</updated><title type='text'>Louisville Metro Metasploit #sploit502</title><content type='html'>Thanks to all who contributed to today's Metasploit class in Louisville.  &lt;br /&gt;&lt;br /&gt;David "ReL1K" Kennedy   http://www.secmaniac.com/&lt;br /&gt;Martin "PureHate" Bos   http://tools.question-defense.com&lt;br /&gt;Elliott "Nullthreat" Cutright  http://twitter.com/Nullthreat&lt;br /&gt;pwrcycle          http://twitter.com/pwrcycle&lt;br /&gt;Adrian "Irongeek" Crenshaw  http://irongeek.com&lt;br /&gt;&lt;br /&gt;I had a great time and learned a lot.  I'll have plenty of new material to digest and read up on over the coming weeks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-4193945613497399544?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/4193945613497399544/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=4193945613497399544' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/4193945613497399544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/4193945613497399544'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/05/louisville-metro-metasploit-sploit502.html' title='Louisville Metro Metasploit #sploit502'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-5990455373049290621</id><published>2010-05-01T17:17:00.000-07:00</published><updated>2010-05-11T19:37:21.158-07:00</updated><title type='text'>OSSEC autoshun script</title><content type='html'>Greetings!  &lt;br /&gt;&lt;br /&gt;I recently found a decent IP blacklist.  Having spent quite a lot of time working with OSSEC recently, I thought it only fitting to use OSSEC to automagically block attackers based on the blacklist.  I've had the "autoshun" rules in place for a couple of months with great success.  &lt;br /&gt;&lt;br /&gt;The script below creates ~900 rules in a file called shunlist.xml.  All you have to do is add that xml file to your list of rules and a cron job to run this script and you should be set.  &lt;br /&gt;&lt;br /&gt;The validation that occurs after the wget is to make sure the file is simple ascii.  If it's a binary or some other nasty the script will end.  Feel free to play with the two commented out lists.  In my experience those lists occasionally block legit traffic thus were removed.  I'm working with Daniel Cid (OSSEC creator) to make active response work with this script.  I’ll update here once I get it working.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;rm /var/ossec/logs/blacklists/cleaned.lst&lt;br /&gt;touch /var/ossec/logs/blacklists/cleaned.lst&lt;br /&gt;&lt;br /&gt;wget http://www.autoshun.com/files/shunlist.csv -O /var/ossec/logs/blacklists/shunlist.lst&lt;br /&gt;file=$(file -ib /var/ossec/logs/blacklists/shunlist.lst)&lt;br /&gt;if [ "$file" == "text/plain; charset=us-ascii" ]; then&lt;br /&gt;cat /var/ossec/logs/blacklists/shunlist.lst | awk 'FNR&gt;1' | cut -d ',' -f1 &gt;&gt; /var/ossec/logs/blacklists/cleaned.lst&lt;br /&gt;else exit&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;#wget http://sucuri.net/blacklist/MS-iplist.txt -O /var/ossec/logs/blacklists/shunlist2.lst&lt;br /&gt;#file2=$(file -ib /var/ossec/logs/blacklists/shunlist2.lst)&lt;br /&gt;#if [ "$file2" == "text/plain; charset=us-ascii" ]; then&lt;br /&gt;#cat /var/ossec/logs/blacklists/shunlist2.lst  &gt;&gt; /var/ossec/logs/blacklists/cleaned.lst&lt;br /&gt;#else exit&lt;br /&gt;#fi&lt;br /&gt;&lt;br /&gt;#wget https://zeustracker.abuse.ch/blocklist.php?download=ipblocklist --no-check-certificate -O /var/ossec/logs/blacklists/shunlist3.lst&lt;br /&gt;#file3=$(file -ib /var/ossec/logs/blacklists/shunlist3.lst)&lt;br /&gt;#if [ "$file3" == "text/plain; charset=us-ascii" ]; then&lt;br /&gt;#cat /var/ossec/logs/blacklists/shunlist3.lst | awk 'FNR&gt;6' &gt;&gt; /var/ossec/logs/blacklists/cleaned.lst&lt;br /&gt;#else exit&lt;br /&gt;#fi&lt;br /&gt;&lt;br /&gt;sort -u /var/ossec/logs/blacklists/cleaned.lst &gt; /var/ossec/logs/blacklists/sorted.lst&lt;br /&gt;/var/ossec/scripts/script.sh &gt; /var/ossec/rules/shunlist.xml&lt;br /&gt;/etc/init.d/ossec restart&lt;br /&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-5990455373049290621?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/5990455373049290621/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=5990455373049290621' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/5990455373049290621'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/5990455373049290621'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/05/ossec-autoshun-script.html' title='OSSEC autoshun script'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-6384152091026774875</id><published>2010-04-24T19:37:00.000-07:00</published><updated>2010-05-11T19:43:43.241-07:00</updated><title type='text'>Mod Security - OWA sanitation</title><content type='html'>The post variable "destination" within OWA is vulnerable to XSS.  To prevent attackers from altering this value, use the following mod security rule. &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;LocationMatch "^/exchweb/bin/auth/owaauth.dll$"&gt;&lt;br /&gt;SecRule REQUEST_METHOD !POST "log,deny"&lt;br /&gt;SecRule ARGS:destination "!(?:http|https)://(?:outlook.&lt;yourdomain&gt;.com/exchange/" "log,deny,t:urlDecode,t:lowercase"&lt;br /&gt;SecRule ARGS:flags "[0-9]{1,2}"&lt;br /&gt;SecRule ARGS:username "[0-9a-zA-Z].{256,}"&lt;br /&gt;SecRule ARGS:password ".{256,}"&lt;br /&gt;SecRule ARGS:SubmitCreds "!Log.On"&lt;br /&gt;SecRule ARGS:trusted "!(0|4)"&lt;br /&gt;&lt;/LocationMatch&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-6384152091026774875?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/6384152091026774875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=6384152091026774875' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/6384152091026774875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/6384152091026774875'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/05/mod-security-owa-sanitation.html' title='Mod Security - OWA sanitation'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-6013698316351181866</id><published>2010-03-07T19:44:00.000-08:00</published><updated>2010-05-11T19:45:24.734-07:00</updated><title type='text'>mod security - block php requests</title><content type='html'>Tired of scanners requesting php from your non-php site?  Block them with this simple mod security entry:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;SecRule REQUEST_URI     "php$" "phase:2,deny,status:404"&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-6013698316351181866?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/6013698316351181866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=6013698316351181866' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/6013698316351181866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/6013698316351181866'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2010/03/mod-security-block-php-requests.html' title='mod security - block php requests'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-4786315475987239736</id><published>2009-07-17T10:21:00.000-07:00</published><updated>2009-07-17T10:24:57.524-07:00</updated><title type='text'>Critical Firefox Vuln Part 2</title><content type='html'>I needed to undo the previous post and only deploy firefox to those that already have it.&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------------------&lt;br /&gt;update.bat&lt;br /&gt;&lt;br /&gt;@ECHO OFF&lt;br /&gt;&lt;br /&gt;if exist "C:\Program Files\Mozilla Firefox\firefox.exe" GOTO installed&lt;br /&gt;if errorlevel 1 GOTO END&lt;br /&gt;&lt;br /&gt;:installed&lt;br /&gt;type "C:\Program Files\Mozilla Firefox\install.log"|findstr 3.5.1&lt;br /&gt;if errorlevel 1 GOTO update&lt;br /&gt;&lt;br /&gt;GOTO END&lt;br /&gt;&lt;br /&gt;:update&lt;br /&gt;cls&lt;br /&gt;"&lt;path&gt;Firefox Setup 3.5.1.exe" -ms&lt;br /&gt;for /f %%a in ('dir /B "%APPDATA%\Mozilla\firefox\Profiles\*.default"') do rm "%APPDATA%\Mozilla\firefox\Profiles\%%a\user.js"&lt;br /&gt;:END&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-4786315475987239736?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/4786315475987239736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=4786315475987239736' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/4786315475987239736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/4786315475987239736'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2009/07/critical-firefox-vuln-part-2.html' title='Critical Firefox Vuln Part 2'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-948348804382562747</id><published>2009-07-14T13:46:00.000-07:00</published><updated>2009-07-14T14:16:19.548-07:00</updated><title type='text'>Critical JavaScript vulnerability in Firefox 3.5</title><content type='html'>I just finished writing a batch file and user.js file to mitigate yesterday's Firefox vuln. I didn't see where one had been previously written.&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;firefox.bat&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;for /f %%a in ('dir /B "%APPDATA%\Mozilla\firefox\Profiles\*.default"') do xcopy /y user.js "%APPDATA%\Mozilla\firefox\Profiles\"%%a&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;You will need to put the user.js file somewhere accessible and change the path for the xcopy accordingly. The batch file also assumes that your users don't already have a user.js file. If they do it'll be overwritten.&lt;br /&gt;&lt;br /&gt;MUAHAHAH! *ahem*&lt;br /&gt;&lt;br /&gt;OHH! Why the FOR loop?  Well, because Ed Skoudis is my hero and because I dunno how many uniquely named folders exist within my users profile directories. &lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------&lt;br /&gt;&lt;strong&gt;user.js&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;//Firefox 3.5’s Just-in-time (JIT) JavaScript Vulnerability - 7.14.09&lt;br /&gt;user_pref("javascript.options.jit.content", false);&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;I've not tested this too much yet so don't blame me if your clients can't access lolcats anymore after applying the change. Also once Mozilla fixes this issue you'll need to switch it back.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-948348804382562747?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/948348804382562747/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=948348804382562747' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/948348804382562747'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/948348804382562747'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2009/07/critical-javascript-vulnerability-in.html' title='Critical JavaScript vulnerability in Firefox 3.5'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-399027700331358395</id><published>2007-03-29T04:18:00.000-07:00</published><updated>2007-03-29T04:20:21.517-07:00</updated><title type='text'>ShmooCon 2007</title><content type='html'>Landon over at Digital Bond wrote a great &lt;a href="http://www.digitalbond.com/index.php/2007/03/26/back-from-shmoocon-07/"&gt;post&lt;/a&gt; about ShmooCon this year and since I still haven't had time to write my own, I'll just hijack his.&lt;br /&gt;&lt;br /&gt;Thanks Landon!  See ya at the next IndySec meeting! ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-399027700331358395?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/399027700331358395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=399027700331358395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/399027700331358395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/399027700331358395'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/shmoocon-2007.html' title='ShmooCon 2007'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-8913281355156473503</id><published>2007-03-28T06:27:00.001-07:00</published><updated>2007-03-28T06:29:17.915-07:00</updated><title type='text'>Spam</title><content type='html'>"He said, "congress hasn't passed anything making spam illegal." I said, "Congress hasn't passed anything requiring the rest of the planet accept your traffic either."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-8913281355156473503?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/8913281355156473503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=8913281355156473503' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/8913281355156473503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/8913281355156473503'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/spam_28.html' title='Spam'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-2118964729458970197</id><published>2007-03-28T06:17:00.000-07:00</published><updated>2007-03-28T06:25:55.943-07:00</updated><title type='text'>Louisiana: SS numbers accessed</title><content type='html'>'These files were previously secure,' Aguillard said..."&lt;br /&gt;&lt;br /&gt;..."previously" apparently meaning "before our web server was booted up".  Obviously the site did not require a password before allowing a web session to 'violate' or 'infiltrate' the records containing the SSNs of the school employees.  Which directives to use in HTML to turn away&lt;br /&gt;web crawlers has been well known to qualified webmasters for years, so that's no excuse either...not that the web crawler should have been able to access employee data without authenticating in the first place.&lt;br /&gt;&lt;br /&gt;Just another example of careless "stewardship" of people's private information?  It goes beyond carelessness when you deliberately put private information on the Web and then don't protect it.&lt;br /&gt;&lt;br /&gt;This sort of blunder becomes more unforgiveable every day, but we have no law under which these willful privacy violations can be prosecuted - until someone's already been harmed.  I'm too discouraged to even rant on about this stuff anymore.  Our country does not take privacy&lt;br /&gt;seriously and apparently has no will to do so in the future either.&lt;br /&gt;&lt;br /&gt;-------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.iberianet.com/articles/2007/03/27/news/news/news15.txt"&gt;&lt;span style="background: transparent none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" id="lw_1175087807_4"&gt;http://www.iberianet.com/articles/2007/03/27/news/news/news15.txt&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Rosters containing information, including Social Security numbers, of about 380 St. Mary Parish public school employees were accessed March 19 by a Yahoo! Web page search engine crawler.&lt;br /&gt;&lt;br /&gt;St. Mary Parish schools Superintendent Donald Aguillard said the crawler violated the school district Web page by accessing a database that&lt;br /&gt;stored 2002 through 2004 staff development rosters.&lt;br /&gt;&lt;br /&gt;"These files were previously secure," Aguillard said. "Yahoo!'s new aggressive Web crawler infiltrated the public server and our technology department responded immediately to the breach in security by addressing the following: Contacting Yahoo! and demanding that our information be stricken from cached files, notified all workshop participants of the possibility that their personal information was revealed, while also contacting the Web page archiving services and demanding the removal of our cached pages."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-2118964729458970197?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/2118964729458970197'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/2118964729458970197'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/louisiana-ss-numbers-accessed.html' title='Louisiana: SS numbers accessed'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-258485976867636038</id><published>2007-03-27T15:57:00.000-07:00</published><updated>2007-03-28T04:11:53.672-07:00</updated><title type='text'>Photos</title><content type='html'>I have my photos hosted.  check them out &lt;a href="http://publicsoliloquy.selfip.com/DC_WEB/index.html"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;That server is password protected.  If you're here then I've probably told you the pass at some time of another.  If you don't remember drop me a message and I'll resend.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-258485976867636038?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/258485976867636038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/258485976867636038'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/photos.html' title='Photos'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-6076813993264784661</id><published>2007-03-26T19:17:00.000-07:00</published><updated>2007-03-26T19:18:53.740-07:00</updated><title type='text'>Day 1</title><content type='html'>The labs began with us gathering our equipment and getting assigned to our future teams.&lt;span&gt;  &lt;/span&gt;&lt;span&gt; &lt;/span&gt;I was first assigned to the Firewall/Intrusion Detection System team that was responsible for setting up and configuring a Cisco ASA firewall device.&lt;span&gt;  &lt;/span&gt;We updated the software on the device to the latest version and commenced configuration.&lt;span&gt;  &lt;/span&gt;We soon realized there really wasn't a need for 6 team members as it only took one guy to configure the firewall and we had two vendors present that were configuring their IDS solutions.&lt;span&gt;  &lt;/span&gt;I offered my hand to the other teams and was soon picked up by the DNS/DHCP team.&lt;span&gt;  &lt;/span&gt;  &lt;p&gt; &lt;/p&gt;  &lt;p&gt;The DNS/DHCP team was tasked with building those services on Linux servers using Bind 9.&lt;span&gt;  &lt;/span&gt;My specific role was to secure those servers from any access other than the specific services offered.&lt;span&gt;  &lt;/span&gt;We had two physical server devices and while one guy configured one server, I worked to secure the other and vise versa.&lt;span&gt;  &lt;/span&gt;All systems used one flavor of Linux or another, there were no Windows servers.&lt;span&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;p&gt;After both machines were configured I (along with several vendors) performed penetration testing and port scanning to verify that the systems were locked down as much as possible.&lt;span&gt;  &lt;/span&gt;&lt;span&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;p&gt;Then, after those servers were deemed secure I was tasked with doing the same on the registration server.&lt;span&gt;  &lt;/span&gt;This was the main server that housed the registration data to which attendees would be verified.&lt;span&gt;  &lt;/span&gt;I performed the same securing process on this system that I had on the pervious ones. &lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;p&gt;At around 9 pm that night after configuration and scanning was complete we called it a day.&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-6076813993264784661?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/6076813993264784661/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=6076813993264784661' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/6076813993264784661'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/6076813993264784661'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/day-1.html' title='Day 1'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-716733717976870239</id><published>2007-03-21T04:24:00.000-07:00</published><updated>2010-05-11T16:48:50.181-07:00</updated><title type='text'>0-Day</title><content type='html'>So, today it begins...&lt;br /&gt;&lt;br /&gt;I plan to update this blog with information as the con progresses as much for my own archival purposes as others.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-716733717976870239?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/716733717976870239/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=716733717976870239' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/716733717976870239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/716733717976870239'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/0-day.html' title='0-Day'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-7666486249624703462</id><published>2007-03-20T20:38:00.000-07:00</published><updated>2007-03-20T20:41:28.057-07:00</updated><title type='text'>ShmooCon Labs</title><content type='html'>&lt;i&gt;I'm in...&lt;br /&gt;&lt;br /&gt;How to kill even more brain cells before a hacker con&lt;/i&gt;      &lt;p&gt;So what happens when you take competing security vendors, con attendees, cutting edge security researchers, put them all in a room and ask them build an enterprise class network? No this is not the beginning of bad joke, it is Shmoocon Labs; a new addition to Shmoocon aiming to provide a very unique educational experience to all involved.&lt;/p&gt;     &lt;h2&gt;How It Works&lt;/h2&gt; &lt;p&gt;Every year at Shmoocon we put a ton of work into the design and setup of our conference network. This year our NOC team is opening up this project as a pre conference event. As a participant you will get hands on time implementing cutting edge security tools in a real world environment. As a vendor you will get a chance to implement your gear in an untrusted, potentially hostile environment of 1000+ hackers. &lt;/p&gt; &lt;p&gt;This is not your normal vendor dog and pony show. We are building a network that needs to be up and running in time for the conference so be prepared to jump in the fire. During Shmoocon various aspects of the network will be made available for attendees to hack on and all vendors should expect their products to get looked over with a fine tooth comb or a 20 pound hammer.&lt;/p&gt; &lt;p&gt;Shmoocon labs will run for the day and half prior to the start of Shmoocon. Shmoocon starts in earnest on the afternoon of March 23rd. The labs will start at the crack of dawn on the 22nd and have 32 hours to get the network up and running.&lt;/p&gt; &lt;h2&gt;The Network&lt;/h2&gt; &lt;p&gt;We are open to implementing almost anything network and security related, some things we plan on implementing are:&lt;/p&gt; &lt;ol&gt;&lt;li&gt;802.11 network access&lt;/li&gt;&lt;li&gt;High availability firewalls&lt;/li&gt;&lt;li&gt;VoIP implementation and security&lt;/li&gt;&lt;li&gt;Intrusion detection and intrusion prevention&lt;/li&gt;&lt;li&gt;Wireless intrusion detection&lt;/li&gt;&lt;li&gt;Network access control&lt;/li&gt;&lt;li&gt;Network and host monitoring&lt;/li&gt;&lt;li&gt;Centralized logging&lt;/li&gt;&lt;li&gt;Traffic analyzers&lt;/li&gt;&lt;li&gt;Vulnerability assessment&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;Keep in mind this network will be in production so as a vendor if you cannot get your products playing nicely on the network we wont hold any punches about keeping it off network. &lt;/p&gt; &lt;h2&gt;Registration&lt;/h2&gt; &lt;p&gt; Registration is open to conference attendees but we are limiting attendance to 30 people. Also, note that there will be a $50 charge to help us There are no hard and steadfast prerequisites, however we expect this event to be best suited towards people with background as Network Engineers, System Adminisrators and Security Engineers. We are looking for individuals who either are experts in one of the areas outlined above or people that are interested in learning more through hands on design, configuration, and deploying of these technologies. &lt;/p&gt; &lt;p&gt;This is not a "first come, first served" event... rather we are trying to find the right mix of individuals to make the network usable and help as many people learn from this process as possible. There is an application process for attending. If you are interested in attending, please send the following information to shmooconlabs@shmoocon.org:&lt;/p&gt; &lt;ol&gt;&lt;li&gt;Summary of work/academic experience&lt;/li&gt;&lt;li&gt;Why you are interested in attending the labs&lt;/li&gt;&lt;li&gt;If you feel you are able to serve as a lead in one of the technology areas&lt;/li&gt;&lt;li&gt;If you are able to show up a day early to help stage the lab&lt;/li&gt;&lt;/ol&gt; &lt;p&gt;In order to cover our costs of running the lab, there will be a $50 fee for each attendee. This basically will pay for space, food, and incidentals (zipties, cables, etc). &lt;/p&gt; &lt;p&gt;On Feb 15th, we will finalize the attendee list for the labs.  If you have any question please email shmooconlabs@shmoocon.org.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-7666486249624703462?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/7666486249624703462/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=7666486249624703462' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/7666486249624703462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/7666486249624703462'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2007/03/shmoocon-labs.html' title='ShmooCon Labs'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-36902659.post-116231492145142844</id><published>2006-10-31T09:14:00.000-08:00</published><updated>2006-10-31T09:15:21.460-08:00</updated><title type='text'>First post</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/36902659-116231492145142844?l=publicsoliloquy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://publicsoliloquy.blogspot.com/feeds/116231492145142844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=36902659&amp;postID=116231492145142844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/116231492145142844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/36902659/posts/default/116231492145142844'/><link rel='alternate' type='text/html' href='http://publicsoliloquy.blogspot.com/2006/10/first-post.html' title='First post'/><author><name>Chad Robertson</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
