<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" version="2.0">
  <channel>
    <title>blog.ActiveServers</title>
    <link>http://blog.activeservers.com/</link>
    <description>ActiveServers Support Blog</description>
    <copyright>Activeservers</copyright>
    <lastBuildDate>Mon, 01 Sep 2008 02:49:47 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 1.8.5223.0</generator>
    <managingEditor>blog@activeservers.com</managingEditor>
    <webMaster>blog@activeservers.com</webMaster>
    <item>
      <trackback:ping>http://blog.activeservers.com/Trackback.aspx?guid=5207124d-148e-4522-bec4-62153a4ccad8</trackback:ping>
      <pingback:server>http://blog.activeservers.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.activeservers.com/PermaLink,guid,5207124d-148e-4522-bec4-62153a4ccad8.aspx</pingback:target>
      <dc:creator>
      </dc:creator>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
      The European Court of Human Rights has refused U.K. hacker Gary McKinnon's appeal
      against demands for his extradition to the U.S.
   </p>
        <p>
      McKinnon stands accused of breaking into computers belonging to NASA and the U.S.
      military, and had appealed against his extradition under Article 3 of the European
      Convention on Human Rights. He had claimed that the conditions of detention he would
      face if convicted in the U.S. would breach a European prohibition on inhumane or degrading
      treatment.
   </p>
        <p>
      The court said Thursday it had refused his appeal, and will not prevent his extradition.
      The court had previously ordered that his extradition be delayed until midnight Friday
      while it considered his request. 
   </p>
        <p>
      It was in 2002 that a U.S. court first indicted McKinnon for the offenses, committed
      in 2001, although he was not arrested by U.K. police until 2005. The U.K. government
      first approved his extradition in 2006.
   </p>
        <p>
      McKinnon has never visited the U.S., and the offenses of which McKinnon is accused
      were committed in the U.K., his lawyers at Kaim Todner LLP said.
   </p>
        <p>
      "We maintain that any prosecution of our client ought therefore to be carried out
      by the appropriate British authorities," the London law firm said. "U.K. citizens
      are at the mercy of the ever-increasing tendency of overseas prosecutors to extend
      their jurisdiction to crimes allegedly committed in this country."
   </p>
        <p>
      The message is clear -- if you hack into computers you have to realize that the legal
      consequences could be severe. Others should take note of McKinnon's predicament!<br /></p>
        <img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=5207124d-148e-4522-bec4-62153a4ccad8" />
        <br />
        <hr />
   ActiveServers Support<a href="http://blog.activeservers.com">ActiveServers</a>. 
</body>
      <title>Gary McKinnon extradition looks likely</title>
      <guid>http://blog.activeservers.com/PermaLink,guid,5207124d-148e-4522-bec4-62153a4ccad8.aspx</guid>
      <link>http://blog.activeservers.com/PermaLink,guid,5207124d-148e-4522-bec4-62153a4ccad8.aspx</link>
      <pubDate>Mon, 01 Sep 2008 02:49:47 GMT</pubDate>
      <description>&lt;p&gt;
   The European Court of Human Rights has refused U.K. hacker Gary McKinnon's appeal
   against demands for his extradition to the U.S.
&lt;/p&gt;
&lt;p&gt;
   McKinnon stands accused of breaking into computers belonging to NASA and the U.S.
   military, and had appealed against his extradition under Article 3 of the European
   Convention on Human Rights. He had claimed that the conditions of detention he would
   face if convicted in the U.S. would breach a European prohibition on inhumane or degrading
   treatment.
&lt;/p&gt;
&lt;p&gt;
   The court said Thursday it had refused his appeal, and will not prevent his extradition.
   The court had previously ordered that his extradition be delayed until midnight Friday
   while it considered his request. 
&lt;/p&gt;
&lt;p&gt;
   It was in 2002 that a U.S. court first indicted McKinnon for the offenses, committed
   in 2001, although he was not arrested by U.K. police until 2005. The U.K. government
   first approved his extradition in 2006.
&lt;/p&gt;
&lt;p&gt;
   McKinnon has never visited the U.S., and the offenses of which McKinnon is accused
   were committed in the U.K., his lawyers at Kaim Todner LLP said.
&lt;/p&gt;
&lt;p&gt;
   "We maintain that any prosecution of our client ought therefore to be carried out
   by the appropriate British authorities," the London law firm said. "U.K. citizens
   are at the mercy of the ever-increasing tendency of overseas prosecutors to extend
   their jurisdiction to crimes allegedly committed in this country."
&lt;/p&gt;
&lt;p&gt;
   The message is clear -- if you hack into computers you have to realize that the legal
   consequences could be severe. Others should take note of McKinnon's predicament!&lt;br&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=5207124d-148e-4522-bec4-62153a4ccad8" /&gt;
&lt;br /&gt;
&lt;hr /&gt;
ActiveServers Support&lt;a href="http://blog.activeservers.com"&gt;ActiveServers&lt;/a&gt;. </description>
      <category>hack</category>
    </item>
    <item>
      <trackback:ping>http://blog.activeservers.com/Trackback.aspx?guid=164c1cef-0bbb-42e3-886c-2028429f8110</trackback:ping>
      <pingback:server>http://blog.activeservers.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.activeservers.com/PermaLink,guid,164c1cef-0bbb-42e3-886c-2028429f8110.aspx</pingback:target>
      <dc:creator>
      </dc:creator>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
        </p>
        <p align="center">
          <img src="http://blog.activeservers.com/content/binary/dns-test.jpg" border="0" />
        </p>
        <h3>
          <font size="3">How do I read the results table?</font>
        </h3>
        <p>
          <strong>Scatterplots:</strong>
          <br />
      The scatterplots are provided as an additional safety check. Even if the tests show
      that the server passes, the values may still be easy to predict. If so, the graph
      may show patterns that are easy for human eyes to recognize. If you see an obvious
      pattern in either of the images, your DNS server has a poor or nonexistant source
      of randomness. 
   </p>
        <p>
          <strong>Based on the results, a DNS server is vulnerable if:</strong>
          <br />
      The query source ports or the query IDs from a given server match or are easily predictable.
      Matching query source ports make it easier to spoof results to the DNS server, poisoning
      its cache. Matching query IDs are usually an indication of a misconfigured DNS server,
      while changing query IDs that are predictable also make DNS cache poisoning easier. 
   </p>
        <p id="vuln.desc">
          <strong>
            <sup>*</sup>Vulnerability:</strong>
          <br />
        </p>
        <p>
      A server that is subtly vulnerable is making an attempt to randomize or otherwise
      change its source port and query IDs, but it appears that the source it uses for random
      numbers is weak or predictable. Fixing this problem will most likely require patching
      the operating system the DNS server is running on. If the server is under your control,
      please apply any security patches it has available. If the server is not under your
      control, contact the owner and inform them of the issue, or switch to a different
      DNS provider, such as <a title="Link SOADNS" href="http://www.soadns.com/" target="new">SOADNS</a>. 
   </p>
        <img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=164c1cef-0bbb-42e3-886c-2028429f8110" />
        <br />
        <hr />
   ActiveServers Support<a href="http://blog.activeservers.com">ActiveServers</a>. 
</body>
      <title>Our CDNS test results</title>
      <guid>http://blog.activeservers.com/PermaLink,guid,164c1cef-0bbb-42e3-886c-2028429f8110.aspx</guid>
      <link>http://blog.activeservers.com/PermaLink,guid,164c1cef-0bbb-42e3-886c-2028429f8110.aspx</link>
      <pubDate>Thu, 07 Aug 2008 15:15:43 GMT</pubDate>
      <description>&lt;p&gt;
&lt;/p&gt;
&lt;p align=center&gt;
   &lt;img src="http://blog.activeservers.com/content/binary/dns-test.jpg" border=0&gt;
&lt;/p&gt;
&lt;h3&gt;&lt;font size=3&gt;How do I read the results table?&lt;/font&gt;
&lt;/h3&gt;
&lt;p&gt;
   &lt;strong&gt;Scatterplots:&lt;/strong&gt;
   &lt;br&gt;
   The scatterplots are provided as an additional safety check. Even if the tests show
   that the server passes, the values may still be easy to predict. If so, the graph
   may show patterns that are easy for human eyes to recognize. If you see an obvious
   pattern in either of the images, your DNS server has a poor or nonexistant source
   of randomness. 
&lt;/p&gt;
&lt;p&gt;
   &lt;strong&gt;Based on the results, a DNS server is vulnerable if:&lt;/strong&gt;
   &lt;br&gt;
   The query source ports or the query IDs from a given server match or are easily predictable.
   Matching query source ports make it easier to spoof results to the DNS server, poisoning
   its cache. Matching query IDs are usually an indication of a misconfigured DNS server,
   while changing query IDs that are predictable also make DNS cache poisoning easier. 
&lt;/p&gt;
&lt;p id=vuln.desc&gt;
   &lt;strong&gt;&lt;sup&gt;*&lt;/sup&gt;Vulnerability:&lt;/strong&gt;
   &lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
   A server that is subtly vulnerable is making an attempt to randomize or otherwise
   change its source port and query IDs, but it appears that the source it uses for random
   numbers is weak or predictable. Fixing this problem will most likely require patching
   the operating system the DNS server is running on. If the server is under your control,
   please apply any security patches it has available. If the server is not under your
   control, contact the owner and inform them of the issue, or switch to a different
   DNS provider, such as &lt;a title="Link SOADNS" href="http://www.soadns.com/" target=new&gt;SOADNS&lt;/a&gt;. 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=164c1cef-0bbb-42e3-886c-2028429f8110" /&gt;
&lt;br /&gt;
&lt;hr /&gt;
ActiveServers Support&lt;a href="http://blog.activeservers.com"&gt;ActiveServers&lt;/a&gt;. </description>
      <category>hack</category>
    </item>
    <item>
      <trackback:ping>http://blog.activeservers.com/Trackback.aspx?guid=ceaf98c5-89fe-4142-ac51-95d8c5522b17</trackback:ping>
      <pingback:server>http://blog.activeservers.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.activeservers.com/PermaLink,guid,ceaf98c5-89fe-4142-ac51-95d8c5522b17.aspx</pingback:target>
      <dc:creator>
      </dc:creator>
      <title>Hack Train-Station TV N95 Nokia</title>
      <guid>http://blog.activeservers.com/PermaLink,guid,ceaf98c5-89fe-4142-ac51-95d8c5522b17.aspx</guid>
      <link>http://blog.activeservers.com/PermaLink,guid,ceaf98c5-89fe-4142-ac51-95d8c5522b17.aspx</link>
      <pubDate>Tue, 08 Jul 2008 20:53:37 GMT</pubDate>
      <description>&lt;p&gt;
   &lt;object width="425" height="344"&gt;
      &lt;param name="movie" value="http://www.youtube.com/v/K2y4lujgEVs&amp;hl=en&amp;fs=1"&gt;&gt;
      &lt;param name="allowFullScreen" value="true"&gt;&gt;&lt;embed src="http://www.youtube.com/v/K2y4lujgEVs&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;
   &lt;/object&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=ceaf98c5-89fe-4142-ac51-95d8c5522b17" /&gt;
&lt;br /&gt;
&lt;hr /&gt;
ActiveServers Support&lt;a href="http://blog.activeservers.com"&gt;ActiveServers&lt;/a&gt;. </description>
      <category>hack</category>
    </item>
    <item>
      <trackback:ping>http://blog.activeservers.com/Trackback.aspx?guid=853e35a8-b4a7-4511-8d55-106936f5c344</trackback:ping>
      <pingback:server>http://blog.activeservers.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.activeservers.com/PermaLink,guid,853e35a8-b4a7-4511-8d55-106936f5c344.aspx</pingback:target>
      <dc:creator>
      </dc:creator>
      <title>Hacking Hiway Signs</title>
      <guid>http://blog.activeservers.com/PermaLink,guid,853e35a8-b4a7-4511-8d55-106936f5c344.aspx</guid>
      <link>http://blog.activeservers.com/PermaLink,guid,853e35a8-b4a7-4511-8d55-106936f5c344.aspx</link>
      <pubDate>Tue, 08 Jul 2008 20:49:15 GMT</pubDate>
      <description>&lt;p&gt;
   &lt;object height=344 width=425&gt;
      &lt;param name="movie" value="http://www.youtube.com/v/32JgSJYpL8o&amp;amp;hl=en&amp;amp;fs=1"&gt;
      &lt;param name="allowFullScreen" value="true"&gt;
      &lt;embed src="http://www.youtube.com/v/32JgSJYpL8o&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;
   &lt;/object&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=853e35a8-b4a7-4511-8d55-106936f5c344" /&gt;
&lt;br /&gt;
&lt;hr /&gt;
ActiveServers Support&lt;a href="http://blog.activeservers.com"&gt;ActiveServers&lt;/a&gt;. </description>
      <category>hack</category>
    </item>
    <item>
      <trackback:ping>http://blog.activeservers.com/Trackback.aspx?guid=013e1761-2473-4d47-b15e-de1c32cee2a5</trackback:ping>
      <pingback:server>http://blog.activeservers.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.activeservers.com/PermaLink,guid,013e1761-2473-4d47-b15e-de1c32cee2a5.aspx</pingback:target>
      <dc:creator>
      </dc:creator>
      <title>Hacking Limewire</title>
      <guid>http://blog.activeservers.com/PermaLink,guid,013e1761-2473-4d47-b15e-de1c32cee2a5.aspx</guid>
      <link>http://blog.activeservers.com/PermaLink,guid,013e1761-2473-4d47-b15e-de1c32cee2a5.aspx</link>
      <pubDate>Tue, 08 Jul 2008 20:42:27 GMT</pubDate>
      <description>&lt;p&gt;
   &lt;object height=344 width=425&gt;
      &lt;param name="movie" value="http://www.youtube.com/v/JcuH27IwWVk&amp;amp;hl=en&amp;amp;fs=1"&gt;
      &lt;param name="allowFullScreen" value="true"&gt;
      &lt;embed src="http://www.youtube.com/v/JcuH27IwWVk&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;
   &lt;/object&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=013e1761-2473-4d47-b15e-de1c32cee2a5" /&gt;
&lt;br /&gt;
&lt;hr /&gt;
ActiveServers Support&lt;a href="http://blog.activeservers.com"&gt;ActiveServers&lt;/a&gt;. </description>
      <category>hack</category>
    </item>
    <item>
      <trackback:ping>http://blog.activeservers.com/Trackback.aspx?guid=c7837e20-e489-449a-9759-7b544db0960f</trackback:ping>
      <pingback:server>http://blog.activeservers.com/pingback.aspx</pingback:server>
      <pingback:target>http://blog.activeservers.com/PermaLink,guid,c7837e20-e489-449a-9759-7b544db0960f.aspx</pingback:target>
      <dc:creator>
      </dc:creator>
      <title>Lame DNS Hacking</title>
      <guid>http://blog.activeservers.com/PermaLink,guid,c7837e20-e489-449a-9759-7b544db0960f.aspx</guid>
      <link>http://blog.activeservers.com/PermaLink,guid,c7837e20-e489-449a-9759-7b544db0960f.aspx</link>
      <pubDate>Tue, 08 Jul 2008 20:29:16 GMT</pubDate>
      <description>&lt;p&gt;
   &lt;object height=344 width=425&gt;
      &lt;param name="movie" value="http://www.youtube.com/v/Nd0FtbZAoSI&amp;amp;hl=en&amp;amp;fs=1"&gt;
      &lt;param name="allowFullScreen" value="true"&gt;
      &lt;embed src="http://www.youtube.com/v/Nd0FtbZAoSI&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;
   &lt;/object&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://blog.activeservers.com/aggbug.ashx?id=c7837e20-e489-449a-9759-7b544db0960f" /&gt;
&lt;br /&gt;
&lt;hr /&gt;
ActiveServers Support&lt;a href="http://blog.activeservers.com"&gt;ActiveServers&lt;/a&gt;. </description>
      <category>hack</category>
    </item>
  </channel>
</rss>