<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-9133539773684103848</id><updated>2012-01-28T17:40:48.387+01:00</updated><category term='esteganografía'/><category term='vulnerabilidades'/><category term='flash'/><category term='amenazas'/><category term='gadgets'/><category term='apple'/><category term='malware'/><category term='técnicas'/><category term='curiosidades'/><category term='cracking'/><category term='libros'/><category term='recursos'/><category term='pwned'/><category term='encuestas'/><category term='foca'/><category term='tutoriales'/><category term='seguridad gestionada'/><category term='dos'/><category term='retos'/><category term='fortificación'/><category term='recomendaciones'/><category term='redes'/><category term='hardware'/><category term='humor'/><category term='linux'/><category term='criptografía'/><category term='ingeniería inversa'/><category term='lock picking'/><category term='entrevistas'/><category term='metodologías'/><category term='videos'/><category term='trivial'/><category term='normativas'/><category term='forense'/><category term='herramientas'/><category term='contramedidas'/><category term='metadatos'/><category term='legislación'/><category term='off-topic'/><category term='android'/><category term='antivirus'/><category term='programación'/><category term='certificaciones'/><category term='defaces'/><category term='exploits'/><category term='recopilatorios'/><category term='wireless'/><category term='noticias'/><category term='magazines'/><category term='eventos'/><category term='hacktivismo'/><category term='maps'/><category term='pentest'/><category term='web recomendada'/><category term='infografías'/><category term='ipv6'/><title type='text'>hackplayers</title><subtitle type='html'>Computer security, ethical hacking and more!</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.hackplayers.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default?start-index=101&amp;max-results=100'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>548</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-639230472577480568</id><published>2012-01-27T23:08:00.008+01:00</published><updated>2012-01-27T23:35:28.427+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='criptografía'/><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><title type='text'>Script para identificar hashes de contraseñas</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-hvttfbsbpLg/TyMltPPTIGI/AAAAAAAAC5Y/d7ePCCpjINQ/s1600/hashid.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 320px; height: 253px;" src="http://1.bp.blogspot.com/-hvttfbsbpLg/TyMltPPTIGI/AAAAAAAAC5Y/d7ePCCpjINQ/s320/hashid.png" alt="" id="BLOGGER_PHOTO_ID_5702443012296220770" border="0" /&gt;&lt;/a&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Seguro que más de una vez, en una auditoría, en un CTF o en cualquier prueba o test de intrusión, habéis obtenido un hash que no habéis podido identificar fácilmente antes de intentar crackearlo.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Hash-identifier&lt;/span&gt; es un script en Python de Zion3R de &lt;a href="http://www.blackploit.com/"&gt;Blackploit&lt;/a&gt; que nos ayudará a identificar los diferentes tipos de hashes usados para cifrar datos y especialmente contraseñas.&lt;br /&gt;&lt;br /&gt;La web del proyecto la podremos encontrar en &lt;a href="https://code.google.com/p/hash-identifier"&gt;https://code.google.com/p/hash-identifier&lt;/a&gt; y los formatos soportados son los siguientes:&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;* ADLER-32&lt;/span&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;  * CRC-32&lt;br /&gt;* CRC-32B&lt;br /&gt;* CRC-16&lt;br /&gt;* CRC-16-CCITT&lt;br /&gt;* DES(Unix)&lt;br /&gt;* FCS-16&lt;br /&gt;* GHash-32-3&lt;br /&gt;* GHash-32-5&lt;br /&gt;* GOST R 34.11-94&lt;br /&gt;* Haval-160&lt;br /&gt;* Haval-192 110080 ,Haval-224 114080 ,Haval-256&lt;br /&gt;* Lineage II C4&lt;br /&gt;* Domain Cached Credentials&lt;br /&gt;* XOR-32&lt;br /&gt;* MD5(Half)&lt;br /&gt;* MD5(Middle)&lt;br /&gt;* MySQL&lt;br /&gt;* MD5(phpBB3)&lt;br /&gt;* MD5(Unix)&lt;br /&gt;* MD5(Wordpress)&lt;br /&gt;* MD5(APR)&lt;br /&gt;* Haval-128&lt;br /&gt;* MD2&lt;br /&gt;* MD4&lt;br /&gt;* MD5&lt;br /&gt;* MD5(HMAC(Wordpress))&lt;br /&gt;* NTLM&lt;br /&gt;* RAdmin v2.x&lt;br /&gt;* RipeMD-128&lt;br /&gt;* SNEFRU-128&lt;br /&gt;* Tiger-128&lt;br /&gt;* MySQL5 - SHA-1(SHA-1($pass))&lt;br /&gt;* MySQL 160bit - SHA-1(SHA-1($pass))&lt;br /&gt;* RipeMD-160&lt;br /&gt;* SHA-1&lt;br /&gt;* SHA-1(MaNGOS)&lt;br /&gt;* Tiger-160&lt;br /&gt;* Tiger-192&lt;br /&gt;* md5($pass.$salt) - Joomla&lt;br /&gt;* SHA-1(Django)&lt;br /&gt;* SHA-224&lt;br /&gt;* RipeMD-256&lt;br /&gt;* SNEFRU-256&lt;br /&gt;* md5($pass.$salt) - Joomla&lt;br /&gt;* SAM - (LM_hash:NT_hash)&lt;br /&gt;* SHA-256(Django)&lt;br /&gt;* RipeMD-320&lt;br /&gt;* SHA-384&lt;br /&gt;* SHA-256&lt;br /&gt;* SHA-384(Django)&lt;br /&gt;* SHA-512&lt;br /&gt;* Whirlpool&lt;br /&gt;* Y más…&lt;br /&gt;&lt;br /&gt;Nota: En algunos casos existen muchas posibilidades de hashes, por ejemplo, no se puede saber si un hash es MD5, MD5 doble o MD5(Sha1) hasta que es descifrado.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-639230472577480568?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/639230472577480568/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=639230472577480568' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/639230472577480568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/639230472577480568'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/script-para-identificar-hashes-de.html' title='Script para identificar hashes de contraseñas'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-hvttfbsbpLg/TyMltPPTIGI/AAAAAAAAC5Y/d7ePCCpjINQ/s72-c/hashid.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4089596040677282578</id><published>2012-01-27T14:12:00.017+01:00</published><updated>2012-01-27T23:56:08.102+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><category scheme='http://www.blogger.com/atom/ns#' term='pwned'/><title type='text'>Vulnerabilidad XSS en Google, Orange, Forbes, MySpace, MTV y Ferrari (y en blogger??)</title><content type='html'>&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Ucha Gobejishvili, también conocido como &lt;span style="font-weight: bold;"&gt;longrifle0x&lt;/span&gt;, ha encontrado una vulnerabilidad de Cross Site Scripting en Google Apps. Aunque el fallo fue reportado el 21 de enero a los expertos de seguridad de Google y el riesgo se considera bajo, la vulnerabilidad todavía se puede explotar y podría permitir a un atacante robar cookies e incluso secuestrar cuentas.&lt;br /&gt;&lt;br /&gt;La prueba de concepto es muy sencilla:&lt;br /&gt;&lt;br /&gt;- Abre &lt;a href="https://www.google.com/a/cpanel/premier/new3?hl=en"&gt;https://www.google.com/a/cpanel/premier/new3?hl=en&lt;/a&gt; y haz clic en 'Find Domain'.&lt;br /&gt;- Pon el siguiente código: &amp;lt;&lt;span style="font-weight: bold;"&gt;1&lt;/span&gt;frame src="javascript:alert('XSS');"&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-oVmd74WRJL4/TyKj86JfoAI/AAAAAAAAC5A/GG8S2pamFa0/s1600/xss_google.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 244px;" src="http://3.bp.blogspot.com/-oVmd74WRJL4/TyKj86JfoAI/AAAAAAAAC5A/GG8S2pamFa0/s400/xss_google.png" alt="" id="BLOGGER_PHOTO_ID_5702300345001025538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Además, longrifle0x ha reportado recientemente otros XSS en sitios tan conocidos como los de Orange, Forbes, Myspace, MTV y Ferrari: &lt;a href="http://xssed.com/archive/author=longrifle0x/special=1/"&gt;http://xssed.com/archive/author=longrifle0x/special=1/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt; &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;Update1:&lt;/span&gt; WTF! ¿por qué Blogger no filtra el código del IFRAME? ¿otro XSS en Blogger?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe src="javascript:alert('XSS persistente en Blogger');"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span style="font-style: italic;"&gt;Fecha: 27/01/2012&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://2.bp.blogspot.com/-bxFU7k8yTME/TyKnFy-OluI/AAAAAAAAC5M/WvVOIiUNyX8/s1600/xss_blogger_hackplayers.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 400px; height: 256px;" src="http://2.bp.blogspot.com/-bxFU7k8yTME/TyKnFy-OluI/AAAAAAAAC5M/WvVOIiUNyX8/s400/xss_blogger_hackplayers.png" alt="" id="BLOGGER_PHOTO_ID_5702303796228429538" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe src="javascript:alert(document.cookie);"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(153, 0, 0);"&gt;Update2:&lt;/span&gt; Una vez reportado, el &lt;span style="font-style: italic;"&gt;Google Security Team&lt;/span&gt; confirma que sólo lo considerarían una vulnerabilidad si fuera posible ejecutar JS en el contexto de los dominios *.blogspot.com de otros usuarios o en blogger.com:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Since the script is executing on a domain that does not have any sensitive&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; content, I can confirm the ability to include JavaScript on this page is&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; intentional; if you see any way in which this causes problems for other&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; Google services, please let us know.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; Especially, please let us know if you find a way to execute JS in context&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; of other user's *.&lt;/span&gt;&lt;a style="font-style: italic;" href="http://blogspot.com/" target="_blank"&gt;blogspot.com&lt;/a&gt;&lt;span style="font-style: italic;"&gt; domain or in the context of &lt;/span&gt;&lt;a style="font-style: italic;" href="http://blogger.com/" target="_blank"&gt;blogger.com&lt;/a&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; domain - you can check this by displaying document.domain.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; You can read more about bugs that qualify for a reward here:&lt;/span&gt;&lt;br /&gt;&lt;a style="font-style: italic;" href="http://www.google.com/corporate/rewardprogram.html" target="_blank"&gt;http://www.google.com/&lt;wbr&gt;corporate/rewardprogram.html&lt;/a&gt;&lt;/span&gt;  &lt;span style="font-style: italic;"&gt; "&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-weight: bold;"&gt;Totalmente de acuerdo, ¡muchas gracias a los expertos de Google por la rápida respuesta!&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-4089596040677282578?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/4089596040677282578/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=4089596040677282578' title='3 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4089596040677282578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4089596040677282578'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/vulnerabilidad-xss-en-google-orange.html' title='Vulnerabilidad XSS en Google, Orange, Forbes, MySpace, MTV y Ferrari (y en blogger??)'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-oVmd74WRJL4/TyKj86JfoAI/AAAAAAAAC5A/GG8S2pamFa0/s72-c/xss_google.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-7077246919687428565</id><published>2012-01-26T13:14:00.008+01:00</published><updated>2012-01-26T13:42:53.737+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='infografías'/><title type='text'>El futuro de compartir archivos tras el cierre de MegaUpload</title><content type='html'>&lt;span style="font-family: verdana;font-size:85%;" &gt;Tras el rápido cierre de Megaupload hemos podido ver como ha ido afectando estos días al mundo de Internet dicho cierre, desde &lt;a href="http://www.portalprogramas.com/milbits/informatica/futuro-compartir-archivos-tras-cierre-megaupload.html"&gt;Portal Programas&lt;/a&gt; han creado una interesante &lt;span style="font-weight: bold;"&gt;infografía &lt;/span&gt;que quiero compartir con vosotros.&lt;br /&gt;&lt;br /&gt;Gracias a ella, podemos tener una rápida visión en cuanto a datos de la empresa, opiniones varias y como no las posibles "alternativas" tras este duro suceso, pero más vale una imagen que mil palabras...&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.portalprogramas.com/milbits/informatica/futuro-compartir-archivos-tras-cierre-megaupload.html" title="futuro de megaupload"&gt;&lt;img src="http://www.portalprogramas.com/imagenes/paginas/futuro-compartir-archivos-tras-megaupload.jpg" alt="Futuro de MegaUpload" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-7077246919687428565?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/7077246919687428565/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=7077246919687428565' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7077246919687428565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7077246919687428565'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/el-futuro-de-compartir-archivos-tras-el.html' title='El futuro de compartir archivos tras el cierre de MegaUpload'/><author><name>Ignacio Martin</name><uri>http://www.blogger.com/profile/01835450220315492500</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://1.bp.blogspot.com/-pxw1dxi-W-c/TVaRFxBR0JI/AAAAAAAAAI8/7QhkdzzMPhc/s220/WindowsVista.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8319982935238299724</id><published>2012-01-24T11:59:00.006+01:00</published><updated>2012-01-24T12:09:16.497+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='exploits'/><title type='text'>Escalado de privilegios en Linux mediante escritura en memoria (CVE-2012-0056)</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-GNIauGBcD_w/Tx6Q6TZBZTI/AAAAAAAAC4k/x2bQ8a-VXpA/s1600/Mempodipper.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 237px; height: 112px;" src="http://3.bp.blogspot.com/-GNIauGBcD_w/Tx6Q6TZBZTI/AAAAAAAAC4k/x2bQ8a-VXpA/s320/Mempodipper.png" alt="" id="BLOGGER_PHOTO_ID_5701153509609661746" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El mismísimo &lt;span style="font-weight: bold;"&gt;Linus Torvalds&lt;/span&gt; publicó este fin de semana una &lt;a href="http://git.kernel.org/?p=linux%2Fkernel%2Fgit%2Ftorvalds%2Flinux-2.6.git&amp;amp;a=commitdiff&amp;amp;h=e268337dfe26dfc7efd422a804dbb27977a3cccc"&gt;actualización de kernel&lt;/a&gt; que corregía un fallo en el control de acceso a la memoria. Poco después y como muchos ya conocéis, han aparecido exploits como &lt;a href="http://git.zx2c4.com/CVE-2012-0056/tree/mempodipper.c?h=fedora"&gt;&lt;span style="font-weight: bold;"&gt;Mempodipper&lt;/span&gt;&lt;/a&gt; que se aprovechan de este error para obtener privilegios de root.&lt;br /&gt;&lt;br /&gt;Desde la versión 2.6.39 el dump de cada proceso puede verse en &lt;span style="font-weight: bold;"&gt;/proc/pid&lt;pid&gt;/mem&lt;/pid&gt;&lt;/span&gt; e incluso ser escrito. Antes de esa versión, un &lt;span style="font-style: italic;"&gt;#ifdef&lt;/span&gt; en el código prevenía la escritura, pero decidió quitarse debido a que se establecieron otros controles para asegurar que sólo los procesos con los permisos correctos pudieran escribir en la memoria.&lt;br /&gt;Sin embargo, dichos controles resultan ser insuficientes y pueden evadirse fácilmente.&lt;br /&gt;&lt;br /&gt;Después de la publicación del artículo de &lt;a href="http://blog.zx2c4.com/749"&gt;&lt;span style="font-weight: bold;"&gt;Nerdling Sapple&lt;/span&gt;&lt;/a&gt;, otros coders han usado esta información para crear otros exploits y ya podemos encontrar varios funcionales en Internet. Estos exploits manipulan la memoria virtual de un programa con el &lt;span style="font-weight: bold;"&gt;setuid &lt;/span&gt;para &lt;span style="font-weight: bold;"&gt;root &lt;/span&gt;activado y consiguen que un usuario regular del sistema pueda elevar privilegios. Incluso Jay Freeman, conocido como Saurik en la comunidad de jailbreaking para iPhone, ha desarrollado una &lt;a href="https://github.com/saurik/mempodroid"&gt;versión para Android&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Distribuciones como Ubuntu ya han facilitado parche y otras como Red Hat están todavía preparándolo y han publicado algunas &lt;a href="https://lists.ubuntu.com/archives/ubuntu-security-announce/2012-January/001557.html"&gt;contramedidas&lt;/a&gt; para esta vulnerabilidad, la &lt;a style="font-weight: bold;" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0056"&gt;CVE-2012-0056&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8319982935238299724?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8319982935238299724/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8319982935238299724' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8319982935238299724'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8319982935238299724'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/escalado-de-privilegios-en-linux.html' title='Escalado de privilegios en Linux mediante escritura en memoria (CVE-2012-0056)'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-GNIauGBcD_w/Tx6Q6TZBZTI/AAAAAAAAC4k/x2bQ8a-VXpA/s72-c/Mempodipper.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5791011386523965029</id><published>2012-01-24T11:21:00.006+01:00</published><updated>2012-01-24T17:35:55.577+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='noticias'/><category scheme='http://www.blogger.com/atom/ns#' term='defaces'/><title type='text'>Zone-h hackeado</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;No es la primera vez pero siempre llama la atención que &lt;a href="http://www.zone-h.org/"&gt;Zone-h&lt;/a&gt;, el mayor mirror de web defacements, sea hackeado. Más aún cuando es un sitio bastante fortificado dada su naturaleza, ya que recibe diariamente miles de visitas y reportes de hackers. De hecho, los &lt;span style="font-weight: bold;"&gt;6 hackers que han desfigurado el sitio esta madrugada&lt;/span&gt; muestran, además de su mensaje de queja, la versión del kernel del servidor comprometido, un kernel actualizado del 2011.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://4.bp.blogspot.com/-CSEZgkcQiTc/Tx6GuU9uwYI/AAAAAAAAC4Y/dalLkrvsjv8/s1600/Zone-h_2012_defacement.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 196px;" src="http://4.bp.blogspot.com/-CSEZgkcQiTc/Tx6GuU9uwYI/AAAAAAAAC4Y/dalLkrvsjv8/s400/Zone-h_2012_defacement.jpg" alt="" id="BLOGGER_PHOTO_ID_5701142308757356930" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Esperamos más información ya que, en anteriores ocasiones, incluso el propio Zone-h ha facilitado detalles de la intrusión :)&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5791011386523965029?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5791011386523965029/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5791011386523965029' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5791011386523965029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5791011386523965029'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/zone-h-hackeado.html' title='Zone-h hackeado'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-CSEZgkcQiTc/Tx6GuU9uwYI/AAAAAAAAC4Y/dalLkrvsjv8/s72-c/Zone-h_2012_defacement.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5435355906881384016</id><published>2012-01-23T22:44:00.004+01:00</published><updated>2012-01-23T22:55:49.633+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='web recomendada'/><title type='text'>Web recomendada: Seguridad Informatica "A lo Jabali ..."</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-ijO11l3n_mQ/Tx3WMFuIJNI/AAAAAAAAC4M/qDDF015Jdq0/s1600/Jabali%2BDoctor.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 283px; height: 210px;" src="http://4.bp.blogspot.com/-ijO11l3n_mQ/Tx3WMFuIJNI/AAAAAAAAC4M/qDDF015Jdq0/s320/Jabali%2BDoctor.jpg" alt="" id="BLOGGER_PHOTO_ID_5700948206503339218" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Desde hace tiempo tenía pendiente hablaros de &lt;a href="http://seguridadalojabali.blogspot.com/"&gt;Seguridad Informatica "A lo Jabali …"&lt;/a&gt; que, más que una deuda, es una recomendación objetiva, y es que el blog de Ángel Villaveiran fue para mi una de las sorpresas más agradables del año pasado.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Como os comento, nació en agosto del 2011, su nombre hace honor a uno de los “bichos” con más mala leche que rondan por la naturaleza envidiable de Asturias y el objetivo principal de este blog es que sea una referencia de seguridad informática orientada a usuarios sin demasiados conocimientos técnicos; aunque ya os digo que es un blog recomendado para todos los públicos.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;El resultado: entradas desenfadadas con grandes dosis de humor y geniales fotomontajes, con las que además aprenderemos muchas cosas de seguridad informática con un lenguaje sencillo y directo. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Como dice Ángel: &lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;Seguridad a lo Jabalí para Todos!!!!&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5435355906881384016?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5435355906881384016/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5435355906881384016' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5435355906881384016'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5435355906881384016'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/web-recomendada-seguridad-informatica.html' title='Web recomendada: Seguridad Informatica &quot;A lo Jabali ...&quot;'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-ijO11l3n_mQ/Tx3WMFuIJNI/AAAAAAAAC4M/qDDF015Jdq0/s72-c/Jabali%2BDoctor.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4343807894213477432</id><published>2012-01-23T11:35:00.022+01:00</published><updated>2012-01-23T22:04:56.549+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ingeniería inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='recopilatorios'/><category scheme='http://www.blogger.com/atom/ns#' term='programación'/><title type='text'>De 0x90 a 0x4c454554, un viaje dentro de la explotación</title><content type='html'>&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Hoy vamos a rescatar una entrada un poco antigua pero genial para todos aquellos que quieren aprender a desarrollar exploits.&lt;br /&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-hYwkTCR_7ns/Tx1EElXADVI/AAAAAAAAC4A/HgUZjKDkgzo/s1600/ninja3.png"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-hYwkTCR_7ns/Tx1EElXADVI/AAAAAAAAC4A/HgUZjKDkgzo/s1600/ninja3.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 220px; height: 194px;" src="http://2.bp.blogspot.com/-hYwkTCR_7ns/Tx1EElXADVI/AAAAAAAAC4A/HgUZjKDkgzo/s320/ninja3.png" alt="" id="BLOGGER_PHOTO_ID_5700787548859665746" border="0" /&gt;&lt;/a&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;'&lt;a href="http://myne-us.blogspot.com/2010/08/from-0x90-to-0x4c454554-journey-into.html"&gt;From 0x90 to 0x4c454554, a journey into exploitation&lt;/a&gt;' contiene una lista de recursos ordenados que describen el camino que se ha de seguir para llegar a ser un auténtico &lt;span style="font-style: italic;"&gt;ninja &lt;/span&gt;en este arte, una estructura jerárquica en la que habrá que ir entendiendo y profundizando en cada sección antes de saltar a la siguiente.&lt;br /&gt;&lt;br /&gt;Además se incluyen &lt;span style="color: rgb(51, 0, 153);"&gt;temas de aprendizaje paralelos&lt;/span&gt; para evitar la monotonía.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:100%;"  &gt;Parte 1: Programación&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);font-family:verdana;font-size:85%;"  &gt;Aprendizaje paralelo # 1: (completa esta sección antes de llegar a la lectura del libro "Hacking Art of exploitation")&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;Aprender a programar es fundamental para escribir exploits. Es imprescindible dominar algún lenguaje de scripting. A continuación se enumeran algunos de los lenguajes de programación más populares y que se consideran más útiles.&lt;br /&gt;&lt;/span&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-weight: bold;"&gt;- Python:&lt;/span&gt; uno de los lenguajes que más popularidad está ganando. Es potente, fácil de usar y está bien documentado.&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://learnpythonthehardway.org/book/"&gt;Learn Python the hard way&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikibooks.org/wiki/Subject:Python_programming_language"&gt;Wikibooks Python&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://docs.python.org/"&gt;http://docs.python.org/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.onlinecomputerbooks.com/free-python-books.php"&gt;onlinecomputerbooks.com&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://oreilly.com/catalog/9781593271923"&gt;Grey hat python&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;- Ruby&lt;/span&gt;: si lo que quieres es trabajar fundamentalmente con Metasploit entonces debes empezar con Ruby.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikibooks.org/wiki/Subject:Ruby_programming_language"&gt;Wikibooks Ruby&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.sapphiresteel.com/IMG/pdf/LittleBookOfRuby.pdf"&gt;LittleBookOfRuby&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.ruby-doc.org/docs/ProgrammingRuby/"&gt;Ruby Programmers Guide&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.onlinecomputerbooks.com/free-ruby-books.php"&gt;onlinecomputerbooks.com&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;- Perl:&lt;/span&gt; aunque es más antiguo continua siendo uno de los lenguajes de scripting más extendidos y por lo tanto utilizados en numerosos exploits.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[libro] &lt;a href="http://www.amazon.com/Learning-Perl-5th-Randal-Schwartz/dp/0596520107/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1280901933&amp;amp;sr=8-1"&gt;O'Reilly Learning Perl&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.onlinecomputerbooks.com/free-perl-books.php"&gt;onlinecomputerbooks.com&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt; &lt;span style="font-weight: bold;"&gt;- C y C++: &lt;/span&gt;tener un buen conocimiento de estos lenguajes es muy importante para entender como funcionan muchos exploits.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.cprogramming.com/"&gt;Cprogramming.com&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.java2s.com/Tutorial/C/CatalogC.htm"&gt;http://www.java2s.com/Tutorial/C/CatalogC.htm&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://beej.us/guide/bgc/"&gt;http://beej.us/guide/bgc/&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.onlinecomputerbooks.com/free-c-books.php"&gt;onlinecomputerbooks.com&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt; &lt;span style="font-weight: bold;"&gt;- Ensamblador x86:&lt;/span&gt; conocer el lenguaje máquina nos ayudará a comprender lo que el ordenador lee a la hora de compilar C y C++.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.skullsecurity.org/wiki/index.php/Fundamentals"&gt;Skullsecurity: Assembly&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.acm.uiuc.edu/sigwin/old/workshops/winasmtut.pdf"&gt;Windows Assembly Programming Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikibooks.org/wiki/X86_Assembly"&gt;http://en.wikibooks.org/wiki/X86_Assembly&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[libro]&lt;a href="http://homepage.mac.com/randyhyde/webster.cs.ucr.edu/index.html"&gt;The Art of Assembly&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.securitytube.net/Assembly-Primer-for-Hackers-%28Part-1%29-System-Organization-video.aspx"&gt;Assembly primer for hackers&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.drpaulcarter.com/pcasm/"&gt;PC Assembly Language&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;- Programación en Windows:&lt;/span&gt; para explotar los sistemas de Microsoft es necesario entender la estructura y las bibliotecas del sistema operativo.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikibooks.org/wiki/Windows_Programming"&gt;http://en.wikibooks.org/wiki/Windows_Programming&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.relisoft.com/win32/index.htm"&gt;http://www.relisoft.com/win32/index.htm&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[libro]&lt;a href="http://www.amazon.com/s/ref=nb_sb_noss?url=search-alias%3Dstripbooks&amp;amp;field-keywords=windows+sysinternals&amp;amp;x=0&amp;amp;y=0"&gt;Windows Internals 5&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[libro]&lt;a href="http://www.amazon.com/Microsoft-Windows-Internals-4th-Server/dp/0735619174"&gt;Windows Internals 4&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;- Desensamblado:&lt;/span&gt; más que programación se trata de comprender lo que el ordenador entiende y la forma que es interpretado por la CPU y la memoria. Aquí empieza lo bueno.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikibooks.org/wiki/X86_Disassembly"&gt;http://en.wikibooks.org/wiki/X86_disassembly&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://tuts4you.com/download.php?view.187"&gt;The Art of Disassembly&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:100%;"  &gt;Parte 2: Iniciación&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;br /&gt;Ahora que tenemos una buena comprensión de los lenguajes de programación y de lo que la máquina está haciendo podemos empezar a trabajar en la tarea que nos ocupa, la explotación.&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.phrack.org/issues.html?issue=49&amp;amp;id=14#article"&gt;Smash the stack for fun and profit (Phrack 49)&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://cs.umbc.edu/%7Echang/cs313.s02/stack.shtml"&gt;C function call conventions and the stack&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://duartes.org/gustavo/blog/post/anatomy-of-a-program-in-memory"&gt;Anatomy of a program in memory&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.codeguru.com/cpp/misc/misc/assemblylanguage/article.php/c14641"&gt;Function Calls, Part 1 (the Basics)&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.sandpile.org/ia32/index.htm"&gt;IA-32 Architecture&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[videos]&lt;a href="http://pentest.cryptocity.net/code-audits/"&gt;Code Audit from cryptocity.net&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="color: rgb(51, 0, 153);"&gt;(&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);font-family:verdana;font-size:85%;"  &gt;Aprendizaje paralelo# 1 terminado:&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="color: rgb(51, 0, 153);"&gt; &lt;span style="font-weight: bold;"&gt;ahora deberías tener un buen conocimiento de uno de los tres lenguajes de scripting listados)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ref=sr_1_fkmr1_1?ie=UTF8&amp;amp;qid=1280905635&amp;amp;sr=1-1-fkmr1"&gt;Hacking art of exploitation [Chapter 1&amp;amp;2]&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/07/19/exploit-writing-tutorial-part-1-stack-based-overflows/"&gt;Corelan T1&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/07/23/writing-buffer-overflow-exploits-a-quick-and-basic-tutorial-part-2/"&gt;Corelan T2&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);"&gt;Aprendizaje paralelo # 2: (completa esta sección antes de finalizar la parte 2)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;(lee primero algunas entradas de este blog)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://blog.ksplice.com/2010/03/"&gt;Kspice blog&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;(este blog contiene información muy útil para empezar con fuzzers)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.nullthreat.net/"&gt;Nullthreat's blog&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;(el siguiente enlace es una demo, pero en este blog también encontrarás muchas cosas interesantes)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.darklevel.org/index.php?option=com_content&amp;amp;task=view&amp;amp;id=54&amp;amp;Itemid=89"&gt;A demo exploit&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.tenouk.com/Bufferoverflowc/stackbasedbufferoverflow.html"&gt;tenouk.com: Buffer overflow intro&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.cultdeadcow.com/cDc_files/cDc-351/index.html"&gt;The Tao of Windows Buffer Overflow&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://nsfsecurity.pr.erau.edu/bom/index.html"&gt;nsfsecurity on BOF&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.hackerscenter.com/index.php?/Downloads/Library/Application-Security/View-category.html"&gt;Hacker center: BOF&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video]&lt;a href="http://www.securitytube.net/Buffer-Overflow-Primer-Part-1-%28Smashing-the-Stack%29-video.aspx"&gt;Buffer overflow Primer&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Shellcoders-Handbook-Discovering-Exploiting-Security/dp/047008023X/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1282450549&amp;amp;sr=8-1"&gt;Shellcoder's Handbook Ch1&amp;amp;2&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ref=sr_1_fkmr1_1?ie=UTF8&amp;amp;qid=1280905635&amp;amp;sr=1-1-fkmr1"&gt;Hacking art of exploitation [Chapter 3]&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/07/25/writing-buffer-overflow-exploits-a-quick-and-basic-tutorial-part-3-seh/"&gt;Corelan T3A&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/07/28/seh-based-exploit-writing-tutorial-continued-just-another-example-part-3b/"&gt;Corelan T3B&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.ethicalhacker.net/content/view/309/2/"&gt;SEH Based Exploits and the development process&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.shell-storm.org/papers/files/405.pdf"&gt;SEH overwrite simplified&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;     &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;(papers de &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.overflowedminds.net/"&gt;overflowedminds&lt;/a&gt;&lt;span style="font-family:verdana;"&gt; recomendados por &lt;/span&gt;&lt;a style="font-family: verdana;" href="https://twitter.com/#%21/BorjaMerino"&gt;Borja Merino&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.overflowedminds.net/Papers/vlan7/0x01_local_linux_x86_shellcoding_without_any_high_level_language.pdf"&gt;Local Linux x86 Shellcoding without any high-level language&lt;/a&gt; y &lt;a href="http://www.overflowedminds.net/Papers/vlan7/0x01_shellcoding.mp4"&gt;video&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.overflowedminds.net/Papers/vlan7/0x02_bypassing_local_Linux_x86_ASLR_protection.pdf"&gt;Bypassing local Linux x86 ASLR protection&lt;/a&gt; y &lt;a href="http://www.overflowedminds.net/Papers/vlan7/Shellcoding_y_Urban_Dogs.mp4"&gt;video&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.overflowedminds.net/Papers/Newlog/Introduccion-Explotacion-Software-Linux.pdf"&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Introducción a la explotación de software en sistemas Linux&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="color: rgb(51, 0, 153);"&gt;(&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);font-family:verdana;font-size:85%;"  &gt;Aprendizaje paralelo# 2 terminado)&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:100%;"  &gt;Parte 3: Herramientas comerciales&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;A continuación se listan algunas herramientas útiles&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.immunityinc.com/products-immdbg.shtml"&gt;Immunity Debugger&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.ollydbg.de/"&gt;Ollydbg&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.microsoft.com/whdc/devtools/debugging/installx86.mspx"&gt;Windbg&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.hex-rays.com/idapro/"&gt;IDA Pro&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://myne-us.blogspot.com/2010/08/from-0x90-to-0x4c454554-journey-into.html"&gt;explorer suite&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb795533.aspx"&gt;Sysinternals&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/09/05/exploit-writing-tutorial-part-5-how-debugger-modules-plugins-can-speed-up-basic-exploit-development/"&gt;Corelan T5&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2010/01/26/starting-to-write-immunity-debugger-pycommands-my-cheatsheet/"&gt;Corelan: Immunity debugger cheatsheet&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:100%;"  &gt;&lt;span style="font-size:100%;"&gt;Parte 4: Networking y Metasploit&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;(Networking)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://beej.us/guide/bgnet/output/html/multipage/index.html"&gt;Beej.us network programming&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ref=sr_1_fkmr1_1?ie=UTF8&amp;amp;qid=1280905635&amp;amp;sr=1-1-fkmr1"&gt;Hacking art of exploitation [Chapter 4]&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="https://www6.software.ibm.com/developerworks/education/l-rubysocks/l-rubysocks-a4.pdf"&gt;Socket Programming in ruby&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;(Metasploit)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Video]&lt;a href="http://www.securitytube.net/Metasploit-Megaprimer-%28Exploitation-Basics-and-need-for-Metasploit%29-Part-1-video.aspx"&gt;Security Tube: Metasploit Megaprimer&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.metasploit.com/"&gt;Metasploit.com&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.offensive-security.com/metasploit-unleashed/"&gt;Metasploit Unleashed&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video]&lt;a href="http://www.irongeek.com/i.php?page=videos/metasploit-class"&gt;Metasploit Louisville Class&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://blog.metasploit.com/2010/05/introducing-metasploitable.html"&gt;Metasploitable (a target)&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/08/12/exploit-writing-tutorials-part-4-from-exploit-to-metasploit-the-basics/"&gt;Corelan T4&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://guides.intern0t.net/msf2.php"&gt;intern0t: developing my first exploit&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video]&lt;a href="http://www.youtube.com/user/DHAtEnclaveForensics#p/u/9/rGlvgeeU0vQ"&gt;DHAtEnclaveForensics: Exploit Creation in Metasploit&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikibooks.org/wiki/Metasploit/WritingWindowsExploit"&gt;Wikibooks Metasploit/Writing Windows Exploit&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:130%;"&gt;Parte 5: Shellcode&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2010/02/25/exploit-writing-tutorial-part-9-introduction-to-win32-shellcoding/"&gt;Corelan T9&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://projectshellcode.com/?q=node/12"&gt;projectShellcode: Shellcode Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Shellcoders-Handbook-Discovering-Exploiting-Security/dp/047008023X/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1282450549&amp;amp;sr=8-1"&gt;Shellcoder's Handbook Ch3&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441/ref=sr_1_fkmr1_1?ie=UTF8&amp;amp;qid=1280905635&amp;amp;sr=1-1-fkmr1"&gt;Hacking art of exploitation [Chapter 5]&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.shell-storm.org/papers/files/440.pdf"&gt;Writing small shellcode&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.shell-storm.org/shellcode/"&gt;Shell-storm Shellcode database&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.vividmachines.com/shellcode/shellcode.html#as"&gt;Advanced shellcode&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:130%;"&gt;Parte 6: Ingeniería inversa&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);font-family:verdana;font-size:85%;"  &gt;Aprendizaje paralelo # 3: (sitios de referencia y uso para reversing)&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.reteam.org/papers/e57.pdf"&gt;Understanding Code&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://mattoh.wordpress.com/"&gt;Reverse Engineering the World&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://tuts4you.com/download.php?list.17"&gt;Reversing for Newbies&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.room362.com/blog/2009/6/12/getting-your-fill-of-reverse-engineering-and-malware-analysi.html"&gt;Room362.com reversing blog post&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.ethicalhacker.net/content/view/152/2/"&gt;Ethicalhacker.net intro to reverse engineering&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.acm.uiuc.edu/sigmil/RevEng/"&gt;acm.uiuc.edu Intro to Reverse Engineering software&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[Libro]&lt;a href="http://www.amazon.com/Reversing-Secrets-Engineering-Eldad-Eilam/dp/0764574817/ref=sr_1_1?s=books&amp;amp;ie=UTF8&amp;amp;qid=1280937813&amp;amp;sr=1-1"&gt;Reversing: secrets of reverse engineering&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video]&lt;a href="http://pentest.cryptocity.net/reverse-engineering/"&gt;Reverse Engineering from cryptocity.net&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.woodmann.com/crackz/"&gt;CrackZ's Reverse Engineering Page&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.securitytube.net/Reverse-Engineering-Techniques-to-find-Security-Vulnerabilities-video.aspx"&gt;Reverse engineering techniques&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://dl.dropbox.com/u/5489930/CBM_1_2_2006_Goppit_PE_Format_Reverse_Engineer_View.pdf"&gt;CBM_1_2_2006_Goppit_PE_Format_Reverse_Engineer_View&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://securitylabs.websense.com/content/Assets/HistoryofPackingTechnology.pdf"&gt;HistoryofPackingTechnology&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://marcoramilli.blogspot.com/2010/12/windows-pe-header.html"&gt;Windows PE Header&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.openrce.org/articles/"&gt;OpenRCE Articles&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[GAME]&lt;a href="http://crackmes.de/"&gt;Crackmes.de&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:130%;"&gt;Parte 7: Profundizando un poco en desbordamientos de buffer (BOF)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 0, 153);font-family:verdana;font-size:85%;"  &gt;Aprendizaje paralelo # 4: (para el final del curso y para después)&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;span id="result_box" class="" style=";font-family:verdana;font-size:85%;"  lang="es" &gt;&lt;span class="hps"&gt;Encontrar&lt;/span&gt; &lt;span class="hps"&gt;exploits&lt;/span&gt; &lt;span class="hps"&gt;antiguos en&lt;/span&gt; &lt;span class="hps atn"&gt;Exploit-&lt;/span&gt;&lt;span class=""&gt;db,&lt;/span&gt; &lt;span class="hps"&gt;descargarlos,&lt;/span&gt; &lt;span class="hps"&gt;probarlos&lt;/span&gt;&lt;span class=""&gt;, reescribirlos y&lt;/span&gt; &lt;span class="hps"&gt;entenderlos&lt;/span&gt;&lt;span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;br /&gt;(Parte A: contramedidas)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikipedia.org/wiki/Buffer_overflow_protection"&gt;Buffer overflow protection&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://technet.microsoft.com/en-us/security/dd285253.aspx"&gt;The evolution of Microsoft's Mitigations&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.cs.purdue.edu/homes/mkirkpat/papers/canbit.pdf"&gt;Purdue.edu: Canary Bit&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://blogs.technet.com/b/srd/archive/2009/02/02/preventing-the-exploitation-of-seh-overwrites-with-sehop.aspx"&gt;Preventing the exploitation of SEH Overwrites with SEHOP&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.sysdream.com/articles/sehop_en.pdf"&gt;Bypassing SEHOP&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikipedia.org/wiki/Executable_space_protection"&gt;Wikipedia Executable space protextion&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikipedia.org/wiki/Data_Execution_Prevention"&gt; Wikipedia DEP&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.securestate.com/Docs/Bypassing_Hardware_based_Data_Execution_Prevention.pdf"&gt;Bypassing Hardware based DEP&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://en.wikipedia.org/wiki/ASLR"&gt;Wikipedia ASLR&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.symantec.com/avcenter/reference/Address_Space_Layout_Randomization.pdf"&gt;Symantec ASLR in Vista&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.ngssoftware.com/papers/defeating-w2k3-stack-protection.pdf"&gt;Defeating the Stack Based Buffer Overflow Prevention&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/09/21/exploit-writing-tutorial-part-6-bypassing-stack-cookies-safeseh-hw-dep-and-aslr/"&gt;Corelan T6&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="https://secure.wikimedia.org/wikipedia/en/wiki/Return-to-libc_attack"&gt;Return to libc&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video] &lt;a href="http://technet.microsoft.com/en-us/security/dd285253.aspx"&gt; microsoft protections video &lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;(Parte B: BOF Avanzado)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video]&lt;a href="http://pentest.cryptocity.net/exploitation/"&gt;Exploitation from cryptocity.net&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2009/11/06/exploit-writing-tutorial-part-7-unicode-from-0x00410041-to-calc/"&gt;Corelan T7&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2010/01/09/exploit-writing-tutorial-part-8-win32-egg-hunting/"&gt;Corelan T8&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.corelan.be:8800/index.php/2010/06/16/exploit-writing-tutorial-part-10-chaining-dep-with-rop-the-rubikstm-cube/"&gt;Corelan T10&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.youtube.com/watch?v=UIKy1Shxd6Q&amp;amp;feature=related"&gt;Virtual Worlds - Real Exploits&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[GAME]&lt;a href="http://community.corest.com/%7Egera/"&gt;Gera's Insecure Programming&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[GAME]&lt;a href="http://www.smashthestack.org/"&gt;Smash the stack wargaming network&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:100%;"  &gt;Parte 8: Desbordamientos de cabecera (heap overflow)&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.exploit-db.com/download_pdf/15982"&gt;Heap Overflows for Humans-101&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://pthreads.blogspot.com/2007/04/heap-overflow.html"&gt;rm -rf / on heap overflow&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.w00w00.org/files/articles/heaptut.txt"&gt;w00w00 on heap overflow&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[libro]&lt;a href="http://www.amazon.com/Shellcoders-Handbook-Discovering-Exploiting-Security/dp/047008023X/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1282450549&amp;amp;sr=8-1"&gt;Shellcoder's Handbook Ch4&amp;amp;5&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.h-online.com/security/features/A-Heap-of-Risk-747161.html"&gt;h-online A heap of Risk&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[video]&lt;a href="http://video.google.com/videoplay?docid=1985155227368288256#"&gt;Defcon 15 remedial Heap Overflows&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.thehackerslibrary.com/?p=872"&gt;heap overflow: ancient art of unlink seduction&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://advancedwindowsdebugging.com/ch06.pdf"&gt;Memory corruptions part II -- heap&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;[libro]&lt;a href="http://www.amazon.com/Shellcoders-Handbook-Discovering-Exploiting-Security/dp/047008023X/ref=sr_1_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1282450549&amp;amp;sr=8-1"&gt;Read the rest of Shellcoder's Handbook&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:100%;"  &gt;&lt;span style="font-size:100%;"&gt;Parte 9: Lista de sitios de exploiting&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.exploit-db.com/"&gt;Exploit-DB&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://inj3ct0r.com/"&gt;Injector&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.cvedetails.com/"&gt;CVE Details&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.packetstormsecurity.org/assess/exploits/"&gt;Packetstorm&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.us-cert.gov/cas/techalerts/"&gt;CERT&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://cve.mitre.org/cve/index.html"&gt;Mitre&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://web.nvd.nist.gov/view/vuln/search?cid=3"&gt;National Vulnerability Database&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;br /&gt;(bonus: sitio que lista los tipos de vulnerabilidad e info)&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://cwe.mitre.org/index.html"&gt;Common Weakness Enumberation&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-family:verdana;font-size:85%;"  &gt;&lt;span style="font-size:130%;"&gt;Parte 10: Para añadir...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;1. Fuzzing&lt;br /&gt;2. Formato de ficheros&lt;br /&gt;3. y más&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Y hasta aquí llega el camino. ¿Conocéis algún otro enlace de interés? ¿habéis seguido alguno una senda distinta? ¡Comenta por favor!&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-4343807894213477432?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/4343807894213477432/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=4343807894213477432' title='7 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4343807894213477432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4343807894213477432'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/de-0x90-0x4c454554-un-viaje-dentro-de.html' title='De 0x90 a 0x4c454554, un viaje dentro de la explotación'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-hYwkTCR_7ns/Tx1EElXADVI/AAAAAAAAC4A/HgUZjKDkgzo/s72-c/ninja3.png' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-7286881294816953167</id><published>2012-01-20T13:52:00.009+01:00</published><updated>2012-01-20T14:18:01.722+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><title type='text'>Wake on LAN Explorer: explota WoL en la red</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/-uOjCmjoDaRs/TxlmynNaJDI/AAAAAAAAC3k/pX1EgkVTDUc/s1600/Wake%2Bover%2BLAN.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 229px; height: 183px;" src="http://4.bp.blogspot.com/-uOjCmjoDaRs/TxlmynNaJDI/AAAAAAAAC3k/pX1EgkVTDUc/s320/Wake%2Bover%2BLAN.jpg" alt="" id="BLOGGER_PHOTO_ID_5699699823118787634" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;a href="http://code.google.com/p/wol-e"&gt;WOL-E (Wake on LAN Explorer)&lt;/a&gt; es una suite de herramientas (scripts en Python) que nos ayudará a explotar algunas características Wake-on-LAN en una red. Recordemos que actualmente muchos dispositivos Apple vienen con WoL activado por defecto.&lt;br /&gt;&lt;br /&gt;Es capaz de:&lt;br /&gt;&lt;br /&gt;- Realizar ataques de fuerza bruta para obtener la dirección MAC de los clientes con wake up&lt;br /&gt;- Esnifar los intentos WoL en la red y guardarlos en disco&lt;br /&gt;- Esnifar las contraseñas WoL en la red y guardarlas en disco&lt;br /&gt;- Levantar los clientes (después del sniffing)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;- Escanear la red en busca de dispositivos Apple que tienen activado WoL&lt;br /&gt;- Enviar peticiones de WoL masivamente a todos los clientes de Apple detectados&lt;br /&gt;&lt;/span&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-family: verdana; font-weight: bold;font-size:85%;" &gt;&lt;br /&gt;Capturas de pantalla&lt;/span&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;Fuerza bruta WOL&lt;/span&gt;&lt;br style="font-weight: bold;"&gt;&lt;/span&gt;&lt;p style="font-family: verdana; font-weight: bold;font-family:verdana;" &gt;&lt;span style="font-size:85%;"&gt;&lt;img src="https://lh4.googleusercontent.com/-B1uTFDIEVxg/TxgLx-Pg3UI/AAAAAAAAAEg/ZPhWeX6_EtQ/s512/Bruteforcing.PNG" /&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family: verdana; font-weight: bold;font-size:85%;" &gt;&lt;a name="WOL_Packet_Sniffing"&gt;&lt;/a&gt;Esnifado de paquetes WoL&lt;br /&gt;&lt;/span&gt;&lt;p style="font-family: verdana; font-weight: bold;font-family:verdana;" &gt;&lt;span style="font-size:85%;"&gt;&lt;img src="https://lh3.googleusercontent.com/-McQYw1aW-eQ/TxgBIAHuZ9I/AAAAAAAAAC8/tMTteUnTvo8/s491/WOL%252520Sniffing.PNG" /&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family: verdana; font-weight: bold;font-size:85%;" &gt;&lt;a name="WOL_Detection"&gt;&lt;/a&gt;Detección WoL&lt;br /&gt;&lt;/span&gt;&lt;p style="font-family: verdana; font-weight: bold;font-family:verdana;" &gt;&lt;span style="font-size:85%;"&gt;&lt;img src="https://lh4.googleusercontent.com/-g5ceFtIlBOA/TxgDv-PcJhI/AAAAAAAAADg/hj7VV_8nFYE/s732/WOL%252520Capture.PNG" /&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family: verdana; font-weight: bold;font-size:85%;" &gt;&lt;a name="WOL_Scan_for_Apple_devices"&gt;&lt;/a&gt;Escaneo WoL para dispositivos Apple&lt;br /&gt;&lt;/span&gt;&lt;p style="font-family: verdana; font-weight: bold;font-family:verdana;" &gt;&lt;span style="font-size:85%;"&gt;&lt;img src="https://lh5.googleusercontent.com/-UXus3Wss1Uc/TxgAoET0onI/AAAAAAAAACs/ktq_dELujFc/s825/WOL-E%252520Apple%252520Scan.PNG" /&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family: verdana; font-weight: bold;font-size:85%;" &gt;&lt;a name="WOL_wake_up_all_stored_Apple_devices_from_the_above_scan"&gt;&lt;/a&gt;Levantar todos los dispositivos Apple con WoL detectados anteriormente&lt;br /&gt;&lt;/span&gt;&lt;p style="font-family: verdana; font-weight: bold;font-family:verdana;" &gt;&lt;span style="font-size:85%;"&gt;&lt;img src="https://lh3.googleusercontent.com/-7W1rkYwkXFc/TxgAn3sbyLI/AAAAAAAAACw/HR3O-oCCu9E/s630/WOL-E%252520Apple%252520Targets.PNG" /&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family: verdana; font-weight: bold;font-size:85%;" &gt;&lt;a name="WOL_Single_clients"&gt;&lt;/a&gt;Levantando un cliente único WoL&lt;br /&gt;&lt;/span&gt;&lt;p style="font-family: verdana; font-weight: bold;font-family:verdana;" &gt;&lt;span style="font-size:85%;"&gt;&lt;img src="https://lh3.googleusercontent.com/-_XQXieJ9mXU/TxgFuWj14AI/AAAAAAAAAD0/fejihyzbbVg/s912/Wake%252520Single.PNG" /&gt;&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-7286881294816953167?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/7286881294816953167/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=7286881294816953167' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7286881294816953167'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7286881294816953167'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/wake-on-lan-explorer.html' title='Wake on LAN Explorer: explota WoL en la red'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-uOjCmjoDaRs/TxlmynNaJDI/AAAAAAAAC3k/pX1EgkVTDUc/s72-c/Wake%2Bover%2BLAN.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-2846559416285190341</id><published>2012-01-19T16:17:00.004+01:00</published><updated>2012-01-19T16:37:31.539+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pentest'/><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><category scheme='http://www.blogger.com/atom/ns#' term='recopilatorios'/><title type='text'>Tutoriales de Backtrack 5</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;Mucha gente coincide en que Backtrack 5 es la mejor distribución para tests de intrusión. Tanto si habéis trabajado ya con ella como si no, os recomendamos echar un vistazo a alguno de los numerosos tutoriales del &lt;a href="http://www.ehacking.net/"&gt;blog Ethical Hacking&lt;/a&gt;:&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://3.bp.blogspot.com/-2J4uueicsVQ/Txg2PY1LpOI/AAAAAAAAC3M/1Jl5_LQNXGU/s1600/bt5-teaser02.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 239px; height: 179px;" src="http://3.bp.blogspot.com/-2J4uueicsVQ/Txg2PY1LpOI/AAAAAAAAC3M/1Jl5_LQNXGU/s320/bt5-teaser02.png" alt="" id="BLOGGER_PHOTO_ID_5699364966428812514" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/11/how-to-install-damn-vulnerable-web-app.html" rel="bookmark"&gt;Nessus With Metasploit Tutorial- Backtrack 5 Video Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/11/how-to-install-damn-vulnerable-web-app.html" rel="bookmark"&gt;How to Install Damn Vulnerable Web App in Linux Backtrack 5 R1&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/11/how-to-install-nessus-in-backtrack-5-r1.html" rel="bookmark"&gt;How To Install Nessus In Backtrack 5 R1 Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/11/buffer-overflow-attack-tutorial.html" rel="bookmark"&gt;Buffer Overflow Attack Tutorial - Backtrack 5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/12/armitage-and-metasploit-video-tutorial.html" rel="bookmark"&gt;Armitage and Metasploit Video Tutorial – Hacking Training&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/12/metagoofil-backtrack-5-tutorial.html" rel="bookmark"&gt;Metagoofil Backtrack 5 Tutorial-Metadata Analyzer Information Gathering Tool&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/08/social-engineering-toolkit-tutorial.html"&gt;Social Engineering toolkit Tutorial-Backtrack 5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/08/dns-spoofing-ettercap-backtrack5.html"&gt;DNS Spoofing- Ettercap Backtrack5 Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/07/maltego-information-gathering-backtrack.html"&gt;Maltego Information Gathering Backtrack 5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/07/nessus-setup-on-backtrack-5.html"&gt;Nessus Setup On Backtrack 5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/skipfish-backtrack5-tutorial.html"&gt;Skipfish- Backtrack5 Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/backtrack-5-openvas-tutorial.html"&gt;Backtrack 5- OpenVas Tutorial&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/how-to-install-backtrack5.html"&gt;How TO Install Backtrack5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/how-to-install-backtrack-5-dual-boot.html"&gt;How To Install Backtrack 5 Dual Boot-Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/07/virtualbox-setup-windows-on-linux.html"&gt;Virtualbox- Setup Windows On Linux Backtrack 5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/crack-ssl-using-sslstrip-with.html"&gt;Crack SSL Using SSLStrip With BackTrack5&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/integrate-nmap-with-nessus-tutorial.html"&gt;Integrate Nmap With Nessus- Tutoria&lt;/a&gt;&lt;a href="http://www.ehacking.net/2011/06/integrate-nmap-with-nessus-tutorial.html"&gt;l&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/07/fast-track-hacking-backtrack5-tutorial.html"&gt;Fast Track Hacking-Backtrack5 Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/integrate-nessus-with-metasploit.html"&gt;Integrate Nessus With Metasploit- Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/06/how-to-use-armitage-in-backtrack-5.html"&gt;How To Use Armitage In Backtrack 5- Tutorial&lt;/a&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/07/backtrack-5-dnsenum-information.html"&gt;Backtrack 5- DNSenum Information Gathering Tool&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/07/wordpress-security-scanner-wpscan.html"&gt;WordPress Security Scanner- WPscan&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/08/tips-to-improve-linux-backtrack-5.html"&gt;Tips to Improve Linux Backtrack 5 Performance&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/08/karmetasploit-backtrack-5-tutorial.html"&gt;Karmetasploit- Backtrack 5 Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-size:small;"&gt;&lt;a href="http://www.ehacking.net/2011/08/theharvester-backtrack-5-information.html"&gt;Theharvester Backtrack 5- Information Gathering Tutorial&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-2846559416285190341?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/2846559416285190341/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=2846559416285190341' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/2846559416285190341'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/2846559416285190341'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/tutoriales-de-backtrack-5.html' title='Tutoriales de Backtrack 5'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-2J4uueicsVQ/Txg2PY1LpOI/AAAAAAAAC3M/1Jl5_LQNXGU/s72-c/bt5-teaser02.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5220644240393686913</id><published>2012-01-19T09:37:00.010+01:00</published><updated>2012-01-19T10:13:37.152+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='curiosidades'/><title type='text'>Estrenamos dominio hackplayers.com</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-LW0C5XFIx4c/Txfdg2gu84I/AAAAAAAAC20/za3Vxv2DIEs/s1600/com.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 308px; height: 173px;" src="http://3.bp.blogspot.com/-LW0C5XFIx4c/Txfdg2gu84I/AAAAAAAAC20/za3Vxv2DIEs/s320/com.png" alt="" id="BLOGGER_PHOTO_ID_5699267409919013762" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Hola amigos, después de unirnos ayer al &lt;span style="font-style: italic;"&gt;blackout &lt;/span&gt;en &lt;a href="http://4.bp.blogspot.com/-Rd2zpMacMRk/Txfcr9ArwdI/AAAAAAAAC2Q/q97Ac3D9Lik/s1600/hpys_SOPA_blackout.png"&gt;protesta contra la SOPA, la PIPA y nuestra ley SINDE&lt;/a&gt;, hoy volvemos a habilitar nuestro blog con una novedad: recientemente adquirimos el dominio &lt;span style="font-weight: bold;"&gt;hackplayers.com&lt;/span&gt; y desde hoy podéis acceder también al blog a través de la url &lt;a href="http://www.hackplayers.com/"&gt;http://www.hackplayers.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;De forma similar a lo que le ocurrió a Alejandro y su &lt;a href="http://spamloco.net/2012/01/spamloco-en-wordpress.html"&gt;Spamloco.com&lt;/a&gt;, han liberado nuestro dominio .com y hemos podido comprarlo a un precio razonable. De esta manera nuestro sitio será un poquito más accesible, ya que todo el mundo es propenso a utilizar los .com. Ya le pasó a Chema en &lt;a href="http://www.elladodelmal.com/2010/10/3-blogs-de-seguridad-que-me-gustan.html"&gt;uno de sus posts&lt;/a&gt; (nos faltan palabras para agradecerle todas sus referencias) y a mucha gente en las &lt;a href="http://www.hackplayers.com/2011/11/premios-bitacorascom-2011-al-mejor-blog.html"&gt;votaciones de los últimos premios Bitácora&lt;/a&gt;&lt;a href="http://www.hackplayers.com/2011/11/premios-bitacorascom-2011-al-mejor-blog.html"&gt;s&lt;/a&gt;, donde hackplayers.com se listó también en el puesto 26.&lt;br /&gt;&lt;br /&gt;Sea como fuere, consideramos que con el dominio hackplayers.com damos un pasito más en nuestro camino y afán por compartir con vosotros y seguir aprendiendo todo lo relacionado con la in-seguridad informática y el hacking ético.&lt;br /&gt;&lt;br /&gt;Gracias a todos por estar ahí.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5220644240393686913?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5220644240393686913/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5220644240393686913' title='3 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5220644240393686913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5220644240393686913'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/estrenamos-dominio-hackplayerscom.html' title='Estrenamos dominio hackplayers.com'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-LW0C5XFIx4c/Txfdg2gu84I/AAAAAAAAC20/za3Vxv2DIEs/s72-c/com.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8098905497943711777</id><published>2012-01-17T09:00:00.000+01:00</published><updated>2012-01-17T09:00:02.276+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='infografías'/><category scheme='http://www.blogger.com/atom/ns#' term='lock picking'/><title type='text'>Cómo abrir un candado probando menos de 100 combinaciones</title><content type='html'>&lt;span style="font-family: verdana;font-size:85%;" &gt;Los candados baratos muchas veces son susceptibles a ataques directos mecánicos, tales como el uso de una cuña para liberar el grillete, sin necesidad de averiguar ninguna combinación para la apertura.&lt;br /&gt;&lt;br /&gt;Los primeros candados de combinación hechos por Master Lock podían ser abiertos tirando de la argolla de la cerradura y girando la rueda hasta su detención, de forma que podíamos ir obteniendo cada vez el número correspondiente de la combinación.&lt;br /&gt;&lt;br /&gt;Los modelos más recientes de candados con combinaciones de 40 posiciones tienen una debilidad mecánica que puede permitir la obtención del último número de la combinación, y los dos primeros números tienen una relación matemática con el último número. Esta debilidad reduce el número de combinaciones posibles de 64.000 a apenas 100, permitiendo la apertura de este tipo de candados en muy poco tiempo.&lt;br /&gt;&lt;br /&gt;La siguiente infografía de Mark Edward Campos es de hace casi dos años, pero recoge y resume perfectamente las instrucciones para aprovecharse de esta debilidad:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-YCVretE8fCA/TxQAzGnUKrI/AAAAAAAAC0o/-eJK3gt6340/s1600/infografia_100_combo.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 262px;" src="http://3.bp.blogspot.com/-YCVretE8fCA/TxQAzGnUKrI/AAAAAAAAC0o/-eJK3gt6340/s400/infografia_100_combo.png" alt="" id="BLOGGER_PHOTO_ID_5698180306479360690" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8098905497943711777?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8098905497943711777/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8098905497943711777' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8098905497943711777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8098905497943711777'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/como-abrir-un-candado-probando-menos-de.html' title='Cómo abrir un candado probando menos de 100 combinaciones'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-YCVretE8fCA/TxQAzGnUKrI/AAAAAAAAC0o/-eJK3gt6340/s72-c/infografia_100_combo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-3120583695352160633</id><published>2012-01-16T12:56:00.009+01:00</published><updated>2012-01-16T13:37:41.539+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><title type='text'>Un fallo en Internet Explorer permite ataques de XSS</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-59-xFR76LEg/TxQYWRClT7I/AAAAAAAAC00/BQQOHtdr74w/s1600/internet-explorer_alfileres.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 217px; height: 185px;" src="http://1.bp.blogspot.com/-59-xFR76LEg/TxQYWRClT7I/AAAAAAAAC00/BQQOHtdr74w/s320/internet-explorer_alfileres.jpg" alt="" id="BLOGGER_PHOTO_ID_5698206199340945330" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Según informa Imperva en su &lt;a href="http://blog.imperva.com/2012/01/ie-bug-exposes-its-users-to-xss-attacks-.html"&gt;blog&lt;/a&gt;, un bug en IE puede permitir a un atacante realizar ataques de tipo XSS no persistentes (reflected).&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/-59-xFR76LEg/TxQYWRClT7I/AAAAAAAAC00/BQQOHtdr74w/s1600/internet-explorer_alfileres.jpg"&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El fallo consiste fundamentalmente en que el navegador de Microsoft no codifica correctamente las dobles comillas (") dentro de una dirección o URI de una query. Algunos sitios web pueden asumir que la URI de la solicitud está correctamente codificada por el navegador e incrustada "tal cual" en la respuesta HTML. Sin embargo, si las comillas dobles no están debidamente codificadas por el IE, se podría realizar un ataque XSS que afectara a los usuarios de IE. Este comportamiento no cumple el RFC 3986 que si implementan otros navegadores como Chrome o Firefox.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Veamoslo con un ejemplo. Si se escribe la siguiente URI en la barra de direcciones del Internet Explorer:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;http://example.com/Sea"rch.asp?q"="b"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;la petición será traducida correctamente:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;GET /Sea%22rch.asp?q"="b"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Pero ahora supongamos que el sitio web tiene embebida la petición en el código fuente. Por ej. para cargar una URL como parámetro para mostrar una imágen:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;out.println(" &amp;lt;1mg src=\"http://www.example.com/pic.asp?ref=" + request.getRequestURL() + "?" + request.getQueryString() +"\"&amp;gt;");&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Imaginemos que un atacante crea un XSS reflejado para convencer a la víctima a seguir el siguiente enlace:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;hxxp://vulnerablesite.com/vulnerablepage.jsp?"onmouseover=alert(1)//&lt;/span&gt;&lt;br  style="font-family:courier new;"&gt;&lt;br /&gt;Entonces, en IE, la víctima tendrá el siguiente HTML:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;&amp;lt;1mg src="http://www.example.com/pic.asp?ref=hxxp://vulnerablesite.com/vulnerablepage.jsp?"onmouseover=alert(1)//"&amp;gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;y el javascript se ejecutará en su máquina.&lt;br /&gt;&lt;br /&gt;Aunque Microsoft ha respondido que no considera este fallo una vulnerabilidad y que NO se tratará en una actualización de seguridad, Imperva insiste que actualmente existen numerosas aplicaciones web vulnerables en Internet por lo que la amenaza es real y no teórica, se están reportando problemas de XSS sólo para usuarios de IE y la vulnerabilidad se está empezando a notar en sitios como &lt;a href="http://xssed.com/"&gt;XSSed.com&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-3120583695352160633?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/3120583695352160633/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=3120583695352160633' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3120583695352160633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3120583695352160633'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/un-fallo-en-internet-explorer-permite.html' title='Un fallo en Internet Explorer permite ataques de XSS'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-59-xFR76LEg/TxQYWRClT7I/AAAAAAAAC00/BQQOHtdr74w/s72-c/internet-explorer_alfileres.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-1819166598369938473</id><published>2012-01-16T10:12:00.006+01:00</published><updated>2012-01-16T10:17:39.942+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><category scheme='http://www.blogger.com/atom/ns#' term='tutoriales'/><category scheme='http://www.blogger.com/atom/ns#' term='recopilatorios'/><title type='text'>Recopilatorio de video tutoriales de hacking del 2011</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-J0E7-IKGBTQ/TxPqid6TgvI/AAAAAAAAC0c/IpxAv7KgeBo/s1600/videotuto_wep10minutes.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://2.bp.blogspot.com/-J0E7-IKGBTQ/TxPqid6TgvI/AAAAAAAAC0c/IpxAv7KgeBo/s320/videotuto_wep10minutes.jpg" alt="" id="BLOGGER_PHOTO_ID_5698155831419437810" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Os dejamos un recopilatorio de vídeos de hacking que seguro que serán de vuestro interés:&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;br  style="font-family:verdana;"&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-J0E7-IKGBTQ/TxPqid6TgvI/AAAAAAAAC0c/IpxAv7KgeBo/s1600/videotuto_wep10minutes.jpg"&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;b style="font-family: verdana;"&gt;23 Best Hacking Video Tutorials Complete Collection 2011&lt;/b&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;English | 2011| AVI | 460 MB&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-J0E7-IKGBTQ/TxPqid6TgvI/AAAAAAAAC0c/IpxAv7KgeBo/s1600/videotuto_wep10minutes.jpg"&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;A premium video course which helo you alot in exploiting the network&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;A Penetration Attack Reconstructed&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Bluesnarfing a Nokia 6310i hand set&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Breaking WEP in 10 minutes&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;BufferOverflowPart2-Shellcoding ByIDEspinner&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;BufferOverflowPart3ExploitsByIDEspinner&lt;/span&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Cain to ARP poison and sniff passwords!&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;DoS attack against Windows FTP Server – DoS&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;How to sniff around switches using Arpspoof and Ngrep!&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;IDEspinner Buffer Overflows pt1&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;IDEspinner Feature Addition pt1&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;IDEspinner Feature Addition pt2&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;IDEspinnerDNS-PoisonRouting&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Install VNC Remotely!&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Internet Explorer Remote Command Execution Exploit (CMDExe) Client Side Attack&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;MITM Hijacking.wmv&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Sniffing logins and passwords&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Sniffing Remote Router Traffic via GRE Tunnels (Hi-Res)&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Sniffing Remote Router Traffic via GRE Tunnels (Lo-Res)&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Start a session and get interactive commandline access to a remote Windows box&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Telnet Bruteforce&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Tunneling Exploits through SSH&lt;/span&gt;&lt;br face="verdana"&gt;&lt;span style="font-family:verdana;"&gt;Use Brutus to crack a box running telnet&lt;/span&gt;&lt;br face="verdana"&gt;&lt;br style="font-family: verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Descarga:&lt;/span&gt;&lt;br style="font-family: verdana;"&gt;&lt;a style="font-family: verdana;" href="http://unlimfiles.com/sourceframe/aHR0cDovL3d3dy5maWxlc29uaWMuY29tL2ZpbGUvTHY1cWgyeC9IYWNraW5nLlZpZGVvcy5wYXJ0MS5yYXI%3D" target="_blank" rel="nofollow"&gt;http://www.filesonic.com/file/Lv5qh2x/Hacking.Videos.part1.rar&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br style="font-family: verdana;"&gt;&lt;a style="font-family: verdana;" href="http://unlimfiles.com/sourceframe/aHR0cDovL3d3dy5maWxlc29uaWMuY29tL2ZpbGUva3JCSjRreS9IYWNraW5nLlZpZGVvcy5wYXJ0Mi5yYXI%3D" target="_blank" rel="nofollow"&gt;http://www.filesonic.com/file/krBJ4ky/Hacking.Videos.part2.rar&lt;/a&gt;&lt;/span&gt;  &lt;span style="font-size:85%;"&gt;&lt;br style="font-family: verdana;"&gt;&lt;span style="font-family:verdana;"&gt;o&lt;/span&gt;&lt;br style="font-family: verdana;"&gt;&lt;a style="font-family: verdana;" href="http://unlimfiles.com/sourceframe/aHR0cDovL3VsLnRvL3d0cTQzd3ZzL0hhY2tpbmcuVmlkZW9zLnBhcnQxLnJhcg%3D%3D" target="_blank" rel="nofollow"&gt;http://ul.to/wtq43wvs/Hacking.Videos.part1.rar&lt;/a&gt;&lt;/span&gt;  &lt;span style="font-size:85%;"&gt;&lt;br style="font-family: verdana;"&gt;&lt;a style="font-family: verdana;" href="http://unlimfiles.com/sourceframe/aHR0cDovL3VsLnRvL2Frc3NzM2hxL0hhY2tpbmcuVmlkZW9zLnBhcnQyLnJhcg%3D%3D" target="_blank" rel="nofollow"&gt;http://ul.to/aksss3hq/Hacking.Videos.part2.rar&lt;/a&gt;&lt;/span&gt;  &lt;span style="font-size:85%;"&gt;&lt;br style="font-family: verdana;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-1819166598369938473?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/1819166598369938473/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=1819166598369938473' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/1819166598369938473'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/1819166598369938473'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/recopilatorio-de-video-tutoriales-de.html' title='Recopilatorio de video tutoriales de hacking del 2011'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-J0E7-IKGBTQ/TxPqid6TgvI/AAAAAAAAC0c/IpxAv7KgeBo/s72-c/videotuto_wep10minutes.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8467779438511332937</id><published>2012-01-09T09:00:00.003+01:00</published><updated>2012-01-09T09:00:04.311+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='recopilatorios'/><category scheme='http://www.blogger.com/atom/ns#' term='programación'/><title type='text'>Recopilatorio de libros de programación</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-ksHKkGBg5DU/TwjDLf-T71I/AAAAAAAACqE/XoKwUd0EdE4/s1600/humor-programacion.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 400px; height: 131px;" src="http://3.bp.blogspot.com/-ksHKkGBg5DU/TwjDLf-T71I/AAAAAAAACqE/XoKwUd0EdE4/s400/humor-programacion.jpg" alt="" id="BLOGGER_PHOTO_ID_5695016331138821970" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Gracias a Michael Kohl (aka citizen428) queríamos compartir también con vosotros un &lt;a href="http://citizen428.net/blog/2010/08/12/30-free-programming-ebooks"&gt;excelente recopilatorio&lt;/a&gt; de más de 50 libros de programación on-line gratuitos.&lt;br /&gt;&lt;br /&gt;Espero que los disfrutéis sea cual sea vuestro lenguaje de programación favorito y, por favor, no dudéis en comentar este post para añadir nuevos enlaces a otras obras que quizás conozcáis y sean interesantes.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Perl:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.perl.org/books/beginning-perl/"&gt;Beginning Perl&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://hop.perl.plover.com/"&gt;Higher-Order Perl&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.perl.org/books/impatient-perl/"&gt;Impatient Perl&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.onyxneon.com/books/modern_perl/"&gt;Modern Perl&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;    &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Python:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://ccn.ucla.edu/tutorials/diveintopython/toc/index.html"&gt;Dive Into Python&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://diveintopython3.ep.io/"&gt;Dive Into Python 3&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.greenteapress.com/thinkpython/thinkCSpy/"&gt;How to Think Like a Computer Scientist – Learning with Python&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://inventwithpython.com/"&gt;Invent Your Own Computer Games with Python&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://learnpythonthehardway.org/"&gt;Learn Python The Hard Way&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://en.wikibooks.org/wiki/Non-Programmer%27s_Tutorial_for_Python_3"&gt;Non-Programmer’s Tutorial for Python 3&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Ruby:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://ruby.bastardsbook.com/"&gt;The Bastards Book of Ruby&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.cleveralgorithms.com/"&gt;Clever Algorithms&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.brpreiss.com/books/opus8/"&gt;Data Structures and Algorithms with Object-Oriented Design Patterns in Ruby&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://ruby.learncodethehardway.org/"&gt;Learn Ruby the Hard Way&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://pine.fm/LearnToProgram/"&gt;Learn to Program&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://macruby.labs.oreilly.com/"&gt;MacRuby: The Definitive Guide&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://humblelittlerubybook.com/"&gt;Mr. Neighborly’s Humble Little Ruby Book&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://ruby-doc.org/docs/ProgrammingRuby/"&gt;Programming Ruby&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://ruby.runpaint.org/"&gt;Read Ruby 1.9&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://rubybestpractices.com/"&gt;Ruby Best Practices&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://railstutorial.org/book"&gt;Ruby on Rails Tutorial Book&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Javascript:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://building-iphone-apps.labs.oreilly.com/"&gt;Building iPhone Apps with &lt;span class="caps"&gt;HTML&lt;/span&gt;, &lt;span class="caps"&gt;CSS&lt;/span&gt;, and JavaScript&lt;/a&gt;&lt;br /&gt;&lt;a href="http://eloquentjavascript.net/"&gt;Eloquent Javascript&lt;/a&gt;&lt;br /&gt;&lt;a href="http://addyosmani.com/resources/essentialjsdesignpatterns/book/"&gt;Essential JavaScript Design Patterns For Beginners&lt;/a&gt;&lt;br /&gt;&lt;a href="http://jqfundamentals.com/book/book.html"&gt;jQuery Fundamentals&lt;/a&gt;&lt;br /&gt;&lt;a href="http://visionmedia.github.com/masteringnode/"&gt;Mastering Node&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.nodebeginner.org/"&gt;The Node Beginner Book&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Lisp/Scheme:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.cs.cmu.edu/%7Edst/LispBook/"&gt;Common Lisp: A Gentle Introduction to Symbolic Computation&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.htdp.org/"&gt;How to Design Programs&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.civilized.com/files/lispbook.pdf"&gt;Interpreting Lisp&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://letoverlambda.com/index.cl"&gt;Let Over Lambda&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.paulgraham.com/onlisptext.html"&gt;On Lisp&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.gigamonkeys.com/book/"&gt;Practical Common Lisp&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.gnu.org/software/emacs/emacs-lisp-intro/html_mono/emacs-lisp-intro.html"&gt;Programming in Emacs Lisp&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.cs.brown.edu/%7Esk/Publications/Books/ProgLangs/"&gt;Programming Languages. Application and Interpretation&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.cs.berkeley.edu/%7Ebh/ss-toc2.html"&gt;Simply Scheme: Introducing Computer Science&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://mitpress.mit.edu/sicp/"&gt;Structure and Interpretation of Computer Programs&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.ccs.neu.edu/home/dorai/t-y-scheme/t-y-scheme.html"&gt;Teach Yourself Scheme in Fixnum Days&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;  &lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Haskell:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://research.microsoft.com/en-us/um/people/simonpj/papers/pj-lester-book/"&gt;Implementing functional languages: a tutorial&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://learnyouahaskell.com/"&gt;Learn You a Haskell for Great Good&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://book.realworldhaskell.org/read/"&gt;Real World Haskell&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://fldit-www.cs.uni-dortmund.de/%7Epeter/PS07/HR.pdf"&gt;The Haskell Road to Logic, Maths and Programming&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Erlang:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://carpanta.dc.fi.udc.es/pf/erlang/doc/concurrent_programming_in_erlang.pdf"&gt;Concurrent Programming in Erlang&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://learnyousomeerlang.com/"&gt;Learn You Some Erlang for Great Good&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Smalltalk:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://book.seaside.st/book"&gt;Dynamic Web Development with Seaside&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://pharobyexample.org/"&gt;Pharo by Example&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://squeakbyexample.org/"&gt;Squeak by Example&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Misc:&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://guideme.itgo.com/atozofc/"&gt;A to Z of C&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://compgeom.cs.uiuc.edu/%7Ejeffe/teaching/algorithms/"&gt;Algorithms&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://homepage.mac.com/randyhyde/webster.cs.ucr.edu/www.artofasm.com/index.html"&gt;The Art of Assembly Language&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://joeclark.org/book/"&gt;Building Accessible Websites&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://publications.gbdirect.co.uk/c_book/"&gt;The C Book&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.robmiles.com/c-yellow-book/"&gt;C# Yellow Book&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.ethoberon.ethz.ch/WirthPubl/CBEAll.pdf"&gt;Compiler Construction&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://diveintohtml5.ep.io/"&gt;Dive Into &lt;span class="caps"&gt;HTML&lt;/span&gt; 5&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://research.microsoft.com/en-us/um/people/simonpj/papers/slpj-book-1987/"&gt;The Implementation of Functional Programming Languages&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://cran.r-project.org/doc/manuals/R-intro.pdf"&gt;An Introduction to R&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.learnprolognow.org/"&gt;Learn Prolog Now!&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://miek.nl/files/go/"&gt;Learning Go&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="https://github.com/karlseguin/the-little-mongodb-book"&gt;The Little MongoDB Book&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.techotopia.com/index.php/Objective-C_2.0_Essentials"&gt;Objective-C 2.0 Essentials&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.dickgrune.com/Books/PTAPG_1st_Edition/"&gt;Parsing Techniques&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://programming-scala.labs.oreilly.com/"&gt;Programming Scala&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://autotelicum.github.com/Smooth-CoffeeScript/"&gt;Smooth CoffeeScript&lt;/a&gt;&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;a href="http://www.cs.kent.ac.uk/people/staff/sjt/TTFP/"&gt;Type Theory and Functional Programming&lt;/a&gt;&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8467779438511332937?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8467779438511332937/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8467779438511332937' title='4 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8467779438511332937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8467779438511332937'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/recopilatorio-de-libros-de-programacion.html' title='Recopilatorio de libros de programación'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-ksHKkGBg5DU/TwjDLf-T71I/AAAAAAAACqE/XoKwUd0EdE4/s72-c/humor-programacion.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5983802549153211801</id><published>2012-01-08T01:01:00.000+01:00</published><updated>2012-01-08T01:01:00.232+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='técnicas'/><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='ingeniería inversa'/><title type='text'>Análisis de shellcodes con Shellcode2Exe</title><content type='html'>&lt;span style="font-family: verdana;font-size:85%;" &gt;Convertir un shellcode en binario o ejecutable es una técnica de análisis que nos permitirá usar nuestro debugger favorito para analizar el código en tiempo real.&lt;br /&gt;&lt;br /&gt;El siguiente vídeo de &lt;/span&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;a href="http://www.securitytube.net/user/dzzie"&gt;dzzie&lt;/a&gt; en &lt;a href="http://www.securitytube.net/video/2674"&gt;SecurityTube&lt;/a&gt; &lt;/span&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;describe los formatos de entrada y salida soportados por la herramienta &lt;a href="http://sandsprite.com/shellcode_2_exe.php"&gt;Shellcode2Exe&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;1) %u urlencoded IE shellcode payloads&lt;br /&gt;2) \x style C strings&lt;br /&gt;3) raw hex strings with no spaces ex. 9090EB15&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="font-family: verdana;font-family:verdana;"  align="center"&gt;&lt;span style="font-size:85%;"&gt;&lt;iframe src="http://www.youtube.com/embed/FTDZyYt7Fqk" allowfullscreen="" frameborder="0" height="345" width="560"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-size:85%;"&gt;Y si lo prefieres puedes también utilizar &lt;a href="http://breakingcode.wordpress.com/2010/01/18/quickpost-converting-shellcode-to-executable-files-using-inlineegg/"&gt;shellcode2exe.py&lt;/a&gt;, un script en python de Mario Vilas, o &lt;a href="http://zeltser.com/reverse-malware/ConvertShellcode.zip"&gt;ConvertShellcode&lt;/a&gt; de Lenny Zeltser.&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5983802549153211801?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5983802549153211801/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5983802549153211801' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5983802549153211801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5983802549153211801'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/analisis-de-shellcodes-con.html' title='Análisis de shellcodes con Shellcode2Exe'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/FTDZyYt7Fqk/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8985679703496983412</id><published>2012-01-07T15:22:00.009+01:00</published><updated>2012-01-07T16:11:16.807+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='legislación'/><category scheme='http://www.blogger.com/atom/ns#' term='humor'/><title type='text'>Próximos estrenos en tu legislación</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-232GldTtxpM/TwhdX7e0aFI/AAAAAAAACoA/UkNBH3z-YPA/s1600/sea_hawk_errol_flynn.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 290px; height: 217px;" src="http://2.bp.blogspot.com/-232GldTtxpM/TwhdX7e0aFI/AAAAAAAACoA/UkNBH3z-YPA/s320/sea_hawk_errol_flynn.jpg" alt="" id="BLOGGER_PHOTO_ID_5694904394495322194" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El despropósito de la ley &lt;/span&gt;&lt;span style="font-weight: bold; font-family:verdana;font-size:85%;"  &gt;Sinde-Wert&lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; puede hacer que el próximo mes de marzo pueda ser un antes y un después para la libertad de muchos. Una comisión administrativa, en concreto la Sección Segunda de la  Comisión de Propiedad Intelectual, podrá decidir el cierre de una página  web sin que ningún juez intervenga de forma efectiva en el proceso.&lt;a href="http://www.siliconnews.es/2012/01/06/estados-unidos-presiono-al-gobierno-para-aprobar-la-ley-sinde/"&gt; El Gobierno, presionado por unos Estados Unidos que quieren enfriar su &lt;span style="font-weight: bold;"&gt;SOPA&lt;/span&gt;&lt;/a&gt;, &lt;a href="http://www.microsiervos.com/archivo/internet/aprobado-reglamento-le-antes-conocida-como-ley-sinde.html"&gt;aprobó el nuevo reglamento el pasado 30 diciembre&lt;/a&gt; y la ley entrara en vigor.&lt;br /&gt;&lt;br /&gt;Sea como fuere, seremos testigos directos de todos los acontecimientos que girarán en torno a esta polémica ley y la de la "vecina" norteamericana. De momento, l&lt;a href="http://www.adslayuda.com/n4005-Operadoras-no-quieren-asumir-costos-por-la-Ley-Sinde.html"&gt;as operadoras se niegan &lt;b&gt; &lt;/b&gt;hacerse cargo de ningún coste&lt;/a&gt; derivado de una decisión del Organismo y se prevén &lt;a href="http://www.elpais.com/articulo/cultura/ley/Sinde/EE/UU/terremoto/elpepicul/20120106elpepicul_2/Tes"&gt;protestas de grandes empresas de Internet que amenazan con un apagón digital coordinado&lt;/a&gt;.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Mientras, ni las leyes ni la crisis nos quitan de momento el buen humor. Hemos recopilado una fantástica cartelera de todos aquellos que, durante más de dos años, han decidido protestar de la forma más simpática y divertida posible. Gracias a todos ellos, toda esta filmoteca está disponible :-)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;table  style="font-family:verdana;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://3.bp.blogspot.com/-JNyTIqtSkyI/TwhdvLbUb4I/AAAAAAAACoM/vz6L7KAE6Xk/s1600/la_lista_de_sinde.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://3.bp.blogspot.com/-JNyTIqtSkyI/TwhdvLbUb4I/AAAAAAAACoM/vz6L7KAE6Xk/s400/la_lista_de_sinde.jpg" alt="" id="BLOGGER_PHOTO_ID_5694904793912602498" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://4.bp.blogspot.com/-egiIbHkyKU8/TwhdvWzgcdI/AAAAAAAACoU/iz8KwTgoW3Q/s1600/el_dia_de_la_sinde.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://4.bp.blogspot.com/-egiIbHkyKU8/TwhdvWzgcdI/AAAAAAAACoU/iz8KwTgoW3Q/s400/el_dia_de_la_sinde.jpg" alt="" id="BLOGGER_PHOTO_ID_5694904796966842834" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://1.bp.blogspot.com/-u-n85sTabs0/Twhdvtr8lcI/AAAAAAAACok/qYdlT2QHuYs/s1600/noespaisparadescargas2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://1.bp.blogspot.com/-u-n85sTabs0/Twhdvtr8lcI/AAAAAAAACok/qYdlT2QHuYs/s400/noespaisparadescargas2.jpg" alt="" id="BLOGGER_PHOTO_ID_5694904803109148098" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://3.bp.blogspot.com/-H36d7jhZCPI/Twhd9rey6YI/AAAAAAAACpI/Lys_E1ra2dk/s1600/sinde_saw4.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://3.bp.blogspot.com/-H36d7jhZCPI/Twhd9rey6YI/AAAAAAAACpI/Lys_E1ra2dk/s400/sinde_saw4.jpg" alt="" id="BLOGGER_PHOTO_ID_5694905043035285890" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://3.bp.blogspot.com/-uGb-VxWnzYg/Twhd-G8Qo6I/AAAAAAAACpg/WOGAUh4qCM0/s1600/sinde%2Bss-2.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 249px;" src="http://3.bp.blogspot.com/-uGb-VxWnzYg/Twhd-G8Qo6I/AAAAAAAACpg/WOGAUh4qCM0/s400/sinde%2Bss-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5694905050406626210" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://4.bp.blogspot.com/-ukpITHYMWK8/Twhd9jrnjmI/AAAAAAAACpU/JDRw6aXiKGM/s1600/sinde_pirates.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://4.bp.blogspot.com/-ukpITHYMWK8/Twhd9jrnjmI/AAAAAAAACpU/JDRw6aXiKGM/s400/sinde_pirates.jpg" alt="" id="BLOGGER_PHOTO_ID_5694905040941583970" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://1.bp.blogspot.com/-yEce4LxnMmA/Twhdv32f7QI/AAAAAAAACos/9hrNvJCuK8k/s1600/sinde_mecanica.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://1.bp.blogspot.com/-yEce4LxnMmA/Twhdv32f7QI/AAAAAAAACos/9hrNvJCuK8k/s400/sinde_mecanica.jpg" alt="" id="BLOGGER_PHOTO_ID_5694904805837761794" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://3.bp.blogspot.com/-GL5baTW7fEk/TwhdwLXs1dI/AAAAAAAACpA/5L0VxpsaUd8/s1600/conlasindeenlostalones.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://3.bp.blogspot.com/-GL5baTW7fEk/TwhdwLXs1dI/AAAAAAAACpA/5L0VxpsaUd8/s400/conlasindeenlostalones.jpg" alt="" id="BLOGGER_PHOTO_ID_5694904811077293522" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://4.bp.blogspot.com/-2c9-NzJ_bP0/TwhfAkgbtEI/AAAAAAAACps/rKBdKmLtAaM/s1600/saw6censored.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 180px; height: 250px;" src="http://4.bp.blogspot.com/-2c9-NzJ_bP0/TwhfAkgbtEI/AAAAAAAACps/rKBdKmLtAaM/s400/saw6censored.jpg" alt="" id="BLOGGER_PHOTO_ID_5694906192214340674" border="0" /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8985679703496983412?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8985679703496983412/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8985679703496983412' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8985679703496983412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8985679703496983412'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/proximos-estrenos-en-tu-legislacion.html' title='Próximos estrenos en tu legislación'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-232GldTtxpM/TwhdX7e0aFI/AAAAAAAACoA/UkNBH3z-YPA/s72-c/sea_hawk_errol_flynn.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4936038097943332610</id><published>2012-01-07T00:01:00.003+01:00</published><updated>2012-01-17T09:28:15.539+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='retos'/><title type='text'>Segunda Copa Hacker de Facebook</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/-e_sHhRc38fo/TxUxE4BSYjI/AAAAAAAAC1Q/k5MAnQaa278/s1600/facebook_hacker_cup_2012.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 192px; height: 128px;" src="http://1.bp.blogspot.com/-e_sHhRc38fo/TxUxE4BSYjI/AAAAAAAAC1Q/k5MAnQaa278/s320/facebook_hacker_cup_2012.jpg" alt="" id="BLOGGER_PHOTO_ID_5698514863334253106" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Facebook ha anunciado la apertura del periodo de inscripción para participar en la &lt;span style="font-weight: bold;"&gt;segunda edición de la 'Hacker Cup'&lt;/span&gt;, donde los participantes tendrán la oportunidad de ser juzgados por su &lt;span style="font-style: italic;"&gt;"precisión y velocidad a la hora de resolver problemas algorítmicos y así avanzar hasta un máximo de cinco rondas de distintos retos de programación"&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;La Hacker Cup 2012 consta de diversas pruebas que irán eliminando a los participantes reduciendo su número sucesivamente a grupos de 500, 100 y 25 "supervivientes". Los 25 mejores 'hackers' se trasladarán hasta la sede de Facebook en California para disputar la ronda final.&lt;br /&gt;&lt;br /&gt;El ganador recibirá 5.000 dólares y el título de 'campeón mundial de hackers'. El segundo clasificado se embolsará 2.000 dólares, el tercero tendrá una compensación de 1.000 dólares y del 4º al 25º recibirán 100 dólares. Además, los 100 primeros clasificados conseguirán una camiseta del evento.&lt;br /&gt;&lt;br /&gt;La inscripción para apuntarse a este concurso está abierta desde el 4 de diciembre y la&lt;span style="font-weight: bold;"&gt; primera fase tendrá lugar el 20 de enero (4:00 PM PT)&lt;/span&gt;, donde los participantes deberán resolver en 72 horas tres problemas algorítmicos. Si pasan todas las rondas, la gran final será el 17 de marzo.&lt;br /&gt;&lt;br /&gt;Desde Facebook han explicado que entienden que &lt;span style="font-style: italic;"&gt;"el hacking es fundamental"&lt;/span&gt; ya que puede ayudar a construir y mejorar aspectos de la red social. No es la primera vez que una compañía busca talento entre los 'hackers', que en muchas ocasiones permiten encontrar fallos de seguridad o son conscientes de las vulnerabilidades más importantes a corregir en sus sistema.&lt;br /&gt;&lt;br /&gt;Más información y detalles en:&lt;br /&gt;&lt;br /&gt;-&lt;a href="https://www.facebook.com/notes/facebook-engineering/announcing-facebooks-2012-hacker-cup/10150468260528920"&gt;Blog de Facebook&lt;/a&gt;.&lt;br /&gt;-&lt;a href="https://www.facebook.com/notes/facebook-engineering/announcing-facebooks-2012-hacker-cup/10150468260528920#%21/hackercup"&gt;Hacker Cup&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-4936038097943332610?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/4936038097943332610/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=4936038097943332610' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4936038097943332610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4936038097943332610'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/segunda-copa-hacker-de-facebook.html' title='Segunda Copa Hacker de Facebook'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-e_sHhRc38fo/TxUxE4BSYjI/AAAAAAAAC1Q/k5MAnQaa278/s72-c/facebook_hacker_cup_2012.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8831467637120126377</id><published>2012-01-06T00:15:00.009+01:00</published><updated>2012-01-06T00:43:54.368+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='noticias'/><category scheme='http://www.blogger.com/atom/ns#' term='antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='pwned'/><title type='text'>Hackers indios podrían filtrar el código fuente de Symantec Norton Antivirus</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-uJUakMkt1nw/TwYyVfpPpWI/AAAAAAAACnQ/Ia9PF1fjjLU/s1600/norton-hacked.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 170px; height: 233px;" src="http://1.bp.blogspot.com/-uJUakMkt1nw/TwYyVfpPpWI/AAAAAAAACnQ/Ia9PF1fjjLU/s320/norton-hacked.jpg" alt="" id="BLOGGER_PHOTO_ID_5694294123709703522" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El grupo de hackers indio conocido como "Los Señores de Dharmaraja" puede haberse hecho con el código fuente de Symantec Norton AntiVirus (NAV).&lt;br /&gt;&lt;br /&gt;Al parecer este grupo ha conseguido &lt;a href="http://indiatoday.intoday.in/story/servers-of-indian-embassy-in-paris-hacked/1/164664.html"&gt;infiltrarse en los servidores de la MEA (Indian Ministry of External Affairs)&lt;/a&gt;, donde se encontraba documentación sobre el Programa Espía Indio del &lt;a href="http://imgur.com/a/8XoGf"&gt;TANCS (TActical Network  for Cellular Surveillance)&lt;/a&gt; y del CBI, incluido el código fuente de empresas de software que habían firmado acuerdos con la Inteligencia Militar India.&lt;br /&gt;&lt;br /&gt;En un principio, los hackers avisaron subiendo a &lt;a href="http://webcache.googleusercontent.com/search?q=cache%3AzTrV7-eEnVQJ%3Apastebin.com%2FciExRzr3+&amp;amp;cd=2&amp;amp;hl=en&amp;amp;ct=clnk"&gt;Pastebin una lista con los ficheros que obtuvieron con el título "Listado completo del código fuente de NAV que está por venir..."&lt;/a&gt;, después publicaron un documento técnico interno de Symantec y hace tan sólo unas horas han subido &lt;a href="http://www.sendspace.com/file/1g8fmk"&gt;algunos ficheros .cpp&lt;/a&gt; para analizar.&lt;br /&gt;&lt;br /&gt;Esto empieza a ponerse muy interesante... Más info y publicaciones en la &lt;a href="https://plus.google.com/116050386311117934760/posts"&gt;página de G+ de Yama Tough&lt;/a&gt;!&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8831467637120126377?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8831467637120126377/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8831467637120126377' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8831467637120126377'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8831467637120126377'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/hackers-indios-podrian-filtrar-el.html' title='Hackers indios podrían filtrar el código fuente de Symantec Norton Antivirus'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-uJUakMkt1nw/TwYyVfpPpWI/AAAAAAAACnQ/Ia9PF1fjjLU/s72-c/norton-hacked.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-961766688470860504</id><published>2012-01-05T13:39:00.007+01:00</published><updated>2012-01-05T14:01:26.605+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>rrhunter: script en Perl para "cazar" rogue routers en IPv6</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-6fvae9nAyuU/TwWdYScyXUI/AAAAAAAACms/bWsB8RCHcfs/s1600/Cazadores%2Bfurtivos.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 154px;" src="http://3.bp.blogspot.com/-6fvae9nAyuU/TwWdYScyXUI/AAAAAAAACms/bWsB8RCHcfs/s320/Cazadores%2Bfurtivos.jpg" alt="" id="BLOGGER_PHOTO_ID_5694130344474860866" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Una de las cosas que hacen especiales a IPv6 es el "descubrimiento de vecinos" o “&lt;span style="font-style: italic;"&gt;Neighbor discovery&lt;/span&gt;”, tal y como se detalla en la RFC4861. Cuando un host que soporta IPv6 se conecta a una red normalmente espera un paquete de anuncio del router, pero también puede generar algunos paquetes de solicitud para descubrir más rápidamente los routers IPv6 que estén conectados a su misma red. Una vez recibido, el router responde y envía la información necesaria al host para que pueda configurar su pila IPv6. Uno de los datos es el prefijo de red (por lo general un /64), que se utiliza para generar las direcciones IPv6. Dichos anuncios o mensajes de solicitud se envían a la dirección especial "ff02:: 1", que representa a todos los hosts conectados en la red.&lt;br /&gt;&lt;br /&gt;Es aquí donde &lt;a href="https://github.com/xme/rrhunter/blob/master/rrhunter.pl"&gt;rrhunter &lt;/a&gt;nos ayudará como una interesante prueba de concepto. Se trata de un script en Perl que transmite paquetes RS y escucha las respuestas de los routers. Si la dirección IP del router cambia o no es la esperada, es posible la presencia de un router falso o rogue.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Ejemplo de uso:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;# ./rrhunter.pl -n fe80::230:48ff:fe27:4e40 -d -i eth1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;+++ Debug enabled.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;+++ Using interface eth1.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;+++ Running with PID 12252.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;+++ Expected IPv6 neighbor: fe80::230:48ff:fe27:4e40&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;+++ Listening on eth1.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;+++ Router Solicitation packet sent!&lt;/span&gt; &lt;span style="font-family:courier new;"&gt;&lt;br /&gt;+++ Detected IPv6 neighbor: fe80::230:48ff:fe27:4e40.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Referencia: &lt;a href="http://www.pentestit.com/rrhunter-perl-script-detecting-rogue-ipv6-routers/"&gt;PenTestIT&lt;/a&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-961766688470860504?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/961766688470860504/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=961766688470860504' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/961766688470860504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/961766688470860504'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/rrhunter-script-en-perl-para-cazar.html' title='rrhunter: script en Perl para &quot;cazar&quot; rogue routers en IPv6'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-6fvae9nAyuU/TwWdYScyXUI/AAAAAAAACms/bWsB8RCHcfs/s72-c/Cazadores%2Bfurtivos.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-384744293472009403</id><published>2012-01-04T22:35:00.013+01:00</published><updated>2012-01-07T16:13:01.929+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='legislación'/><category scheme='http://www.blogger.com/atom/ns#' term='hacktivismo'/><title type='text'>Manual de desobediencia a la Ley Sinde</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-_0HIgNEonKU/TwTMT7s-4yI/AAAAAAAACmg/3QdPPg7JD7k/s1600/manual_desobediencia_ley_Sinde.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 132px; height: 188px;" src="http://4.bp.blogspot.com/-_0HIgNEonKU/TwTMT7s-4yI/AAAAAAAACmg/3QdPPg7JD7k/s320/manual_desobediencia_ley_Sinde.jpg" alt="" id="BLOGGER_PHOTO_ID_5693900471719093026" border="0" /&gt;&lt;/a&gt;&lt;span le="font-family:verdana;font-size:85%;"   style="font-family:verdana;font-size:85%;"&gt;Recientemente recibimos un tweet del &lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: verdana;" href="http://proyectgoliath.wordpress.com/2010/08/04/proyecto-goliath-espanol/"&gt;Proyecto Goliath&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt; &lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;para la redifusión &lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt;de un manual para saltarse la &lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;a style="font-family: verdana;" href="http://es.wikipedia.org/wiki/Ley_de_Econom%C3%ADa_Sostenible"&gt;ley Sinde&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt;.&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt;Se trata de el “&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://proyectgoliath.files.wordpress.com/2012/01/manual_desobediencia.pdf" target="_blank"&gt;&lt;span style="color:#0000ff;"&gt;Manual de desobediencia a la Ley Sinde&lt;/span&gt;&lt;/a&gt;&lt;span style="color:#000000;"&gt;” desarrollado por&lt;/span&gt; &lt;a href="http://hacktivistas.net/content/quienes-somos" target="_blank"&gt;&lt;span style="color:#0000ff;"&gt;Hacktivistas&lt;/span&gt;&lt;/a&gt; &lt;span style="color:#000000;"&gt;y editado por&lt;/span&gt; &lt;a href="http://www.traficantes.net/index.php/libreria/catalogo/libros/Manual-de-desobediencia-a-la-Ley-Sinde" target="_blank"&gt;&lt;span style="color:#0000ff;"&gt;Traficantes de Sueños&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;, un sencillo pero instructivo documento cuyo objetivo es demostrar, desde un punto de vista práctico, lo ineficiente que será la ley cuando se aplique a partir del próximo mes de marzo.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;En este manual, usuarios y webmasters encontrarán los métodos más útiles para sortear las barreras de la censura:&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;-Introducción&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;-I. Posibles métodos de censura&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;-II. Usuarios:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  1. ¿Por qué y cómo debes cambiarte un DNS?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  2. ¿Por qué y cómo configurar un proxy?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  3. ¿Por qué usar Tor y cómo configurarlo?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  4. ¿Qué es un Red Privada Virtual?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  5. ¿Cómo puedes hacer una copia de seguridad de tus webs de enlaces favoritas mediante Httrack?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;-III. Webmasters&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  1. Alojamiento&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  2. Dominios&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  3. Pagos anónimos&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;  4. Otros recursos&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-384744293472009403?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/384744293472009403/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=384744293472009403' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/384744293472009403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/384744293472009403'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/manual-de-desobediencia-la-ley-sinde.html' title='Manual de desobediencia a la Ley Sinde'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-_0HIgNEonKU/TwTMT7s-4yI/AAAAAAAACmg/3QdPPg7JD7k/s72-c/manual_desobediencia_ley_Sinde.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-6363281819882803128</id><published>2012-01-03T12:19:00.005+01:00</published><updated>2012-01-03T12:26:52.637+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='libros'/><title type='text'>Libro: The Database Hacker’s Handbook: Defending Database Servers</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-h2JIvF4o8ns/TwLkjhsXFyI/AAAAAAAACic/gpghlw7BA1I/s1600/dbhackerhandbook.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 210px; height: 268px;" src="http://2.bp.blogspot.com/-h2JIvF4o8ns/TwLkjhsXFyI/AAAAAAAACic/gpghlw7BA1I/s320/dbhackerhandbook.jpg" alt="" id="BLOGGER_PHOTO_ID_5693364177940715298" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Empezamos el año con las mismas ganas de aprender y recomendando una lectura interesante. En esta ocasión, &lt;span style="font-weight: bold;"&gt;The Database Hacker’s Handbook: Defending Database Servers&lt;/span&gt; es un libro que nos ayudará a entender y destripar todos los secretos de las bases de datos.&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: left;"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;Tenemos que tener en cuenta que las bases de datos son el centro neurálgico de nuestra economía. Cada pieza de nuestra información personal se almacena en ellas: registros médicos, cuentas bancarias, historiales de trabajo, pensiones, matriculaciones de automóviles, incluso las calificaciones de nuestros hijos y los alimentos qué tenemos que comprar. Los ataques a las bases de datos son por lo tanto potencialmente peligrosos y paralizantes.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;En este libro, cuatro de expertos de seguridad nos enseñarán a romper y defender los siete servidores de bases de datos más populares. Aprenderemos a identificar las vulnerabilidades y cómo se llevan a cabo los ataques y la forma de detenerlos.&lt;br /&gt;&lt;br /&gt;* Identificar y tapar los bugs nuevos en Oracle y Microsoft SQL Server&lt;br /&gt;* Aprender las mejores defensas para DB2 de IBM, PostgreSQL, Sybase ASE y servidores MySQL&lt;br /&gt;* Descubrir cómo explotar desbordamientos de búfer, escalada de privilegios a través de SQL, procedimientos almacenados, abuso de triggers e inyecciones SQL&lt;br /&gt;* Reconocer las vulnerabilidades particulares de cada base de datos&lt;br /&gt;* Averiguar lo que los atacantes ya saben ;)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.amazon.com/exec/obidos/ASIN/0764578014/ref=nosim/cybe0f8-20#reader_0764578014"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Índice del libro en Amazon.&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-6363281819882803128?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/6363281819882803128/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=6363281819882803128' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6363281819882803128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6363281819882803128'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2012/01/libro-database-hackers-handbook.html' title='Libro: The Database Hacker’s Handbook: Defending Database Servers'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-h2JIvF4o8ns/TwLkjhsXFyI/AAAAAAAACic/gpghlw7BA1I/s72-c/dbhackerhandbook.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-3282794588131482096</id><published>2011-12-31T10:00:00.000+01:00</published><updated>2011-12-31T10:00:02.857+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='curiosidades'/><title type='text'>Lo más visto del 2011 en Hackplayers</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-RTZgO4Y-szQ/Tv2wFoktV0I/AAAAAAAACiQ/6GSagIgvryo/s1600/corona_navidad_geek.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 169px; height: 209px;" src="http://3.bp.blogspot.com/-RTZgO4Y-szQ/Tv2wFoktV0I/AAAAAAAACiQ/6GSagIgvryo/s320/corona_navidad_geek.jpg" alt="" id="BLOGGER_PHOTO_ID_5691899114903394114" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;En esta ocasión finalizamos también el año con un post con las 50 entradas de Hackplayers más vistas durante el 2011, según Google Analytics.&lt;/span&gt;&lt;br  style="font-family:verdana;"&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;Como&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt; siempre, daros las gracias por leernos y participar con vuestros comentarios,  soluciones a  los retos y colaboraciones. No dudéis en contactar con  nosotros si  estáis interesados en algún tema en particular o si queréis  participar  con vuestro artículo. Nos vemos en el 2012. ¡Feliz y próspero  año  nuevo!&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br  style="font-family:verdana;"&gt;&lt;br  style="font-family:verdana;"&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt;1.- Blogroll en &lt;a href="http://hackplayers.blogspot.com/p/blogroll_11.html"&gt;español&lt;/a&gt; y en &lt;a href="http://hackplayers.blogspot.com/p/blogroll-12.html"&gt;inglés &lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;2.- &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://hackplayers.blogspot.com/2010/12/loic-la-herramienta-ddos-utilizada-por.html"&gt;LOIC: la herramienta DDoS utilizada por Anonymous&lt;/a&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;3.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/08/anti-el-pentesting-sencillo-desde.html"&gt;Anti: el pentesting sencillo desde Android&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;4.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/11/evasion-del-limite-de-140-caracteres-de.html"&gt;Evasión del límite de 140 caracteres de Twitter mediante codificación CESU-8&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;5.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/02/metasploit-autopwn.html"&gt;Metasploit Autopwn&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;6.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/02/reto-10-averigua-el-patron-de.html"&gt;Reto 10: averigua el patrón de desbloqueo&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;7.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/p/retos-de-hackplayers_24.html"&gt;Retos de Hackplayers&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;8.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/search/?q=Convierte+tu+Firefox+en+un+keylogger+invisible"&gt;Convierte tu Firefox en un keylogger invisible&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;9.- &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/07/reto-12-encuentra-las-7-diferencias.html"&gt;Reto 12: encuentra las 7 diferencias&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;10.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/05/solucion-al-reto-del-gp-de-bahrein.html"&gt;Solución al reto 3 del GP de Bahrein&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;11.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/12/hidden-backdoor-in-windows.html"&gt;Puerta trasera oculta en Windows&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;12.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/09/la-foca-en-linux-2-de-2.html"&gt;La FOCA en Linux [2 de 2]&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;13.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/01/las-10-mejores-tecnicas-de-hacking-web.html"&gt;Las 10 mejores técnicas de hacking web en el 2010&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;14.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/01/mitos-el-caso-tim-lloydomega.html"&gt;Mitos:  el caso Tim Lloyd/Omega&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;15.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/05/cual-es-el-mejor-firewall-de-red.html"&gt;¿Cuál es el mejor firewall de red?&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;16.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/08/taller-de-lock-picking-2-tecnicas-de.html"&gt;Taller de lock picking #2: Técnicas de apertura&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;17.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/04/milw0rm-y-inj3ct0r-se-fusionan-en.html"&gt; Milw0rm y Inj3ct0r se fusionan en 1337db&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;18.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/09/wifite-herramienta-para-cracking-masivo.html"&gt;wifite - Herramienta para cracking masivo de claves WEP/WPA&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;19.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/08/taller-de-lock-picking-1-iniciacion.html"&gt;Taller de lock picking #1: Iniciación&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;20.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/09/taller-de-lock-picking-3-herramientas.html"&gt;Taller de lock picking #3: Herramientas de ganzuado&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;21.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/01/blackbuntu-community-edition-01.html"&gt;Blackbuntu Community Edition 0.1&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;22.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/10/otra-campana-zeus-mediante-correos-de.html"&gt;Otra campaña Zeus mediante correos de DHL falsos&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;23.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/10/recopilatorio-de-soluciones-retos-en.html"&gt;Recopilatorio de soluciones a retos en español&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;24.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/06/paginas-ocultas-about-en-mozilla.html"&gt;Páginas ocultas "about:" en Mozilla Firefox&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;25.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/01/principios-en-ensamblador.html"&gt;Principios en ensamblador&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;26.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/11/probando-la-foca-30-en-linux.html"&gt;Probando la FOCA 3.0 en Linux&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;27.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/10/suben-porno-al-canal-youtube-de-barrio.html"&gt;Suben porno al canal YouTube de Barrio Sésamo&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;28.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/02/5-interesantes-proyectos-de-seguridad.html"&gt;5 interesantes proyectos de seguridad de código abierto&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;29.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/11/anonymous-y-team-poison-se-unen-contra.html"&gt;Anonymous y Team Poison se unen contra los bancos en la Operación Robin Hood&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;30.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/06/explota-inyecciones-sql-facilmente-con.html"&gt;Explota inyecciones SQL fácilmente con Havij&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;31.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/03/libro-la-biblia-del-hacker-2009.html"&gt;Libro: La biblia del Hacker 2009&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;32.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/06/inteco-confianza-online-pwned.html"&gt;Inteco &amp;amp; Confianza Online pwned!&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;33.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/01/guia-de-metasploitable-episodio-2.html"&gt;Guía de Metasploitable - Episodio 2 - PostgreSQL + SSH&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;34.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/01/solucion-al-reto-del-crackme1-para_18.html"&gt;Solución al reto 9 del crackme#1 para Android [2 de 2]&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;35.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/11/katana-20-suite-de-seguridad-portable-y.html"&gt;Katana 2.0: suite de seguridad portable y multi-arranque&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;36.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/01/video-metasploitable-guide-episode-1.html"&gt;Guía de Metasploitable - Episodio 1 - distccd + escalado de privilegios&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;37.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/10/reto-13-examen-sorpresa.html"&gt;Reto 13: ¡examen sorpresa!&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;38.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/04/evasion-de-la-autenticacion-de-dropbox.html"&gt;Evasión de la autenticación de Dropbox&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;39.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/08/killapache-consigue-un-dos-remoto-desde.html"&gt;killapache: consigue un DoS remoto desde un único PC&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;40.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/10/el-maletin-del-investigador-forense.html"&gt;El maletín del investigador forense&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;41.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/04/reto-11-quien-entiende-los-bebes.html"&gt;Reto 11: ¿quién entiende a los bebés?&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;42.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/05/seguridad-en-switches-cisco.html"&gt;Seguridad en switches Cisco&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;43.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/09/las-personas-mas-influyentes-en.html"&gt;Las personas más influyentes en seguridad informática&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;44.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/11/el-cazador-de-vulnerabilidades-en.html"&gt;El cazador de vulnerabilidades en aplicaciones PHP&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;45.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/08/solucion-al-reto-del-bebe-lloron.html"&gt;Solución al reto 6 del bebé llorón&lt;/a&gt;&lt;br  style="font-family:verdana;"&gt;&lt;span style="font-family:verdana;"&gt;46.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/04/enumeracion-ldap.html"&gt;Enumeración LDAP&lt;/a&gt;&lt;br face="verdana"&gt;&lt;span style="font-family:verdana;"&gt;47.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/10/fbpwn-ingenieria-social-en-facebook.html"&gt;fbpwn: ingeniería social en Facebook&lt;/a&gt;&lt;br face="verdana"&gt;&lt;span style="font-family:verdana;"&gt;48.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2010/06/solucion-al-reto-de-analisis-de-malware.html"&gt;Solución al reto 4 de análisis de malware (una ayuda para Juanito)&lt;/a&gt;&lt;br style="font-family: verdana;"&gt;&lt;span style="font-family:verdana;"&gt;49.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/2011/02/metasploit-nessus-xssf.html"&gt;Metasploit + Nessus + XSSF&lt;/a&gt;&lt;br style="font-family: verdana;"&gt;&lt;span style="font-family:verdana;"&gt;50.-&lt;/span&gt;&lt;a style="font-family: verdana;" href="http://hackplayers.blogspot.com/p/participa.html"&gt;Participa en Hackplayers&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-3282794588131482096?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/3282794588131482096/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=3282794588131482096' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3282794588131482096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3282794588131482096'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/lo-mas-visto-del-2011-en-hackplayers.html' title='Lo más visto del 2011 en Hackplayers'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-RTZgO4Y-szQ/Tv2wFoktV0I/AAAAAAAACiQ/6GSagIgvryo/s72-c/corona_navidad_geek.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-1933403788658774429</id><published>2011-12-29T14:11:00.006+01:00</published><updated>2011-12-29T14:29:31.431+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><category scheme='http://www.blogger.com/atom/ns#' term='cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><title type='text'>Reaver-wps: ataques de fuerza bruta contra WPS</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-NuKC_7syY3M/TvxnsCOYyhI/AAAAAAAACh4/ilXUcB-sxAM/s1600/wps_metodolog%25C3%25ADa_fuerza_bruta.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 206px; height: 320px;" src="http://3.bp.blogspot.com/-NuKC_7syY3M/TvxnsCOYyhI/AAAAAAAACh4/ilXUcB-sxAM/s320/wps_metodolog%25C3%25ADa_fuerza_bruta.png" alt="" id="BLOGGER_PHOTO_ID_5691538035298585106" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Hace un par de días, Stefan Viehbock publicó un &lt;a href="http://sviehb.files.wordpress.com/2011/12/viehboeck_wps.pdf"&gt;whitepaper&lt;/a&gt; detallando los fallos en la implementación de &lt;span style="font-weight: bold;"&gt;Wi-Fi Protected Setup (WPS) &lt;/span&gt;que podrían permitir a un atacante realizar un &lt;span style="font-weight: bold;"&gt;ataque de fuerza bruta&lt;/span&gt; para probar todas las combinaciones de &lt;span style="font-weight: bold;"&gt;PIN &lt;/span&gt;posibles con el objetivo de obtener una contraseña &lt;span style="font-weight: bold;"&gt;WPA/WPA2&lt;/span&gt; en cuestión de horas.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-NuKC_7syY3M/TvxnsCOYyhI/AAAAAAAACh4/ilXUcB-sxAM/s1600/wps_metodolog%25C3%25ADa_fuerza_bruta.png"&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Los fallos de implementación residen en que:&lt;br /&gt;&lt;br /&gt;1. la opción de Registro Externo no requiere ningún tipo de autenticación a parte de proveer el PIN correspondiente.&lt;br /&gt;&lt;br /&gt;2. el router valida en PIN en dos partes: responde inmediatamente (mensaje EAP-NACK) si los 4 primeros dígitos del PIN son erróneos, y después hace lo propio con los 3 siguientes (el último dígito es un checksum). Esto reduce significativamente las posibles combinaciones: 10^4 (10,000) y 10^3 (1,000) respectivamente&lt;br /&gt;&lt;br /&gt;Ahora que está vulnerabilidad se ha echo pública, &lt;span style="font-style: italic; font-weight: bold;"&gt;Tactical Network Solutions LLC (TNS)&lt;/span&gt; ha decidido además &lt;a href="http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html"&gt;publicar la herramienta open source Reaver&lt;/a&gt; (&lt;a href="http://code.google.com/p/reaver-wps/"&gt;http://code.google.com/p/reaver-wps&lt;/a&gt;), una herramienta que han ido probando y perfeccionando desde hace casi un año.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Reaver realizará un ataque de fuerza bruta contra el AP, primero con la primera parte del PIN y luego con la segunda, realizando intentos para un espacio de claves de tan sólo 11,000 posibilidades.&lt;br /&gt;&lt;br /&gt;El uso de esta herramienta nos proveerá por tanto la posibilidad de atacar fácilmente WPS, aspecto que nos ofrecerá claras ventajas respecto a la posibilidad de atacar directamente a WPA:&lt;br /&gt;&lt;br /&gt;- Descifrar el PIN WPS es, obviamente, mucho más rápido.&lt;br /&gt;- Una vez que tengamos el PIN WPS inmediatamente podemos recuperar la contraseña WPA, incluso si el propietario    la cambia.&lt;br /&gt;- Los puntos de acceso multifrecuencia (2.4/5GHz) se pueden configurar con varias claves WPA. Dado que el PIN WPS es el mismo en distintas frecuencias, el conocimiento del PIN permite a un atacante recuperar todas las claves WPA.&lt;br /&gt;&lt;br /&gt;De momento, la única recomendación básica es desactivar WPS y activarlo sólo para cuando queramos añadir nuevos dispositivos...&lt;span style="font-style: italic;"&gt;happy hacking!&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-1933403788658774429?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/1933403788658774429/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=1933403788658774429' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/1933403788658774429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/1933403788658774429'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/reaver-wps-ataques-de-fuerza-bruta.html' title='Reaver-wps: ataques de fuerza bruta contra WPS'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-NuKC_7syY3M/TvxnsCOYyhI/AAAAAAAACh4/ilXUcB-sxAM/s72-c/wps_metodolog%25C3%25ADa_fuerza_bruta.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-519279937745499516</id><published>2011-12-29T09:30:00.001+01:00</published><updated>2011-12-29T12:22:35.649+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='técnicas'/><title type='text'>Detección de web shells con NeoPI y técnicas de evasión</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;Hoy en día, muchas aplicaciones web se desarrollan utilizando lenguajes de scripting como PHP, Python, Ruby, Perl, etc. Estos lenguajes pueden ser lo suficientemente complicados para que un pequeño fallo pueda llegar a permitir la ejecución de código arbitrario en el servidor.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-a_xM-l7XaxE/TvtSC5Th2-I/AAAAAAAAChs/3j4y7DYUCOk/s1600/storm7shell.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 288px; height: 201px;" src="http://2.bp.blogspot.com/-a_xM-l7XaxE/TvtSC5Th2-I/AAAAAAAAChs/3j4y7DYUCOk/s320/storm7shell.png" alt="" id="BLOGGER_PHOTO_ID_5691232763808701410" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Cuando una de estas condiciones es identificada por un atacante, casi con total seguridad intentará subir un &lt;span style="font-weight: bold;"&gt;web shell&lt;/span&gt; para mantener el acceso al servidor comprometido, permitiendo normalmente la ejecución de comandos del sistema y el acceso a archivos.&lt;br /&gt;&lt;br /&gt;Pero, ¿cómo detectar el código de estos &lt;span style="font-weight: bold;"&gt;backdoors &lt;/span&gt;en un servidor con cientos o quizás miles de páginas?&lt;br /&gt;&lt;br /&gt;Si la shell no está ofuscada, podremos realizar una búsqueda rápida en base a una serie de patrones aunque, eso sí, obtendremos numerosos falsos positivos. Por ejemplo encontraríamos la mítica &lt;span style="font-weight: bold;"&gt;C99&lt;/span&gt; con:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;grep -RPn "(system|phpinfo|pcntl_exec|python_eval|base64_decode|gzip|mkdir|fopen|fclose|readfile|passthru)" /pathto/webdir/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Otra opción sería utilizar herramientas basadas en firmas como &lt;span style="font-weight: bold;"&gt;Linux Malware Detect (LMD)&lt;/span&gt;, que encontrará algunas de las más típicas web shells. Sin embargo, ¿cómo detectaríamos aquellas shells que hayan sido modificadas/ofuscadas para ocultarse?&lt;br /&gt;&lt;br /&gt;Para ello podemos utilizar &lt;a href="https://github.com/Neohapsis/NeoPI"&gt;&lt;span style="font-weight: bold;"&gt;NeoPI&lt;/span&gt;&lt;/a&gt;, un script en Python que utiliza varios métodos estadísticos para descubrir este tipo de contenido ofuscado o cifrado dentro de scripts y ficheros de texto.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Esta herramienta escaneará recursivamente los ficheros del directorio indicado y los puntuará en base a los resultados de las pruebas. Este ranking nos ayudará a identificar con una alta probabilidad de acierto qué ficheros podrían tener web shells ofuscadas:&lt;br /&gt;&lt;br style="font-family: courier new;"&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style=" ;font-family:courier new;color:red;"  &gt;root@testbed&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;:&lt;/span&gt;&lt;span style=" ;font-family:courier new;color:blue;"  &gt;~&lt;/span&gt;&lt;span style="font-family:courier new;"&gt;# ./neopi.py -z -e -l -i -s /var/www/ \.php$&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;[[ Total files scanned: 10235 ]]&lt;br /&gt;[[ Total files ignored: 0 ]]&lt;br /&gt;[[ Scan Time: 48.170000 seconds ]]&lt;br /&gt;&lt;br /&gt;[[ Top 10 entropic files for a given search ]]&lt;br /&gt;6.1817        /var/www/gallery/lang/chinese_gb.php&lt;br /&gt;6.1784        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/zh-cn.php&lt;br /&gt;6.1710        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/zh-tw.php&lt;br /&gt;5.8753        /var/www/blog/wp-admin/js/revisions-js.php&lt;br /&gt;5.7846        /var/www/gallery/lang/japanese.php&lt;br /&gt;5.7306        /var/www/webacoo.php&lt;br /&gt;5.6484        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/cs.php&lt;br /&gt;5.6296        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/sk.php&lt;br /&gt;5.6203        /var/www/plugins/system/nonumberelements/helper.php&lt;br /&gt;5.6133        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/pl.php&lt;br /&gt;&lt;br /&gt;[[ Top 10 longest word files ]]&lt;br /&gt;  745        /var/www/gallery/include/exif_php.inc.php&lt;br /&gt;  745        /var/www/gallery/exifmgr.php&lt;br /&gt;  741        /var/www/gallery/lang/japanese.php&lt;br /&gt;  728        /var/www/blog/wp-admin/js/revisions-js.php&lt;br /&gt;  522        /var/www/blog/wp-includes/functions.php&lt;br /&gt;  516        /var/www/libraries/tcpdf/tcpdf.php&lt;br /&gt;  474        /var/www/plugins/content/jw_allvideos/includes/sources.php&lt;br /&gt;  456        /var/www/blog/wp-content/plugins/sexybookmarks/includes/html-helpers.php&lt;br /&gt;  436        /var/www/gallery/lang/chinese_gb.php&lt;br /&gt;  354        /var/www/blog/wp-includes/class-simplepie.php&lt;br /&gt;&lt;br /&gt;[[ Average IC for Search ]]&lt;br /&gt;0.0372679517799&lt;br /&gt;&lt;br /&gt;[[ Top 10 lowest IC files ]]&lt;br /&gt;0.0198        /var/www/webacoo.php&lt;br /&gt;0.0206        /var/www/gallery/lang/chinese_gb.php&lt;br /&gt;0.0217        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/zh-tw.php&lt;br /&gt;0.0217        /var/www/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/langs/zh-cn.php&lt;br /&gt;0.0217        /var/www/templates/system/index.php&lt;br /&gt;0.0217        /var/www/administrator/templates/system/index.php&lt;br /&gt;0.0222        /var/www/blog/wp-content/themes/lightword/alternatives/404.php&lt;br /&gt;0.0226        /var/www/blog/wp-admin/js/revisions-js.php&lt;br /&gt;0.0270        /var/www/includes/HTML_toolbar.php&lt;br /&gt;0.0272        /var/www/templates/beez/html/com_user/reset/complete.php&lt;br /&gt;&lt;br /&gt;[[ Top 10 signature match counts ]]&lt;br /&gt;   43        /var/www/gallery/include/themes.inc.php&lt;br /&gt;   43        /var/www/gallery/themes/sample/theme.php&lt;br /&gt;   26        /var/www/blog/wp-admin/includes/class-ftp.php&lt;br /&gt;   19        /var/www/blog/wp-content/plugins/nextgen-gallery/lib/imagemagick.inc.php&lt;br /&gt;   14        /var/www/libraries/geshi/geshi/php.php&lt;br /&gt;   13        /var/www/blog/wp-includes/Text/Diff/Engine/native.php&lt;br /&gt;   10        /var/www/blog/wp-includes/js/tinymce/plugins/spellchecker/classes/PSpellShell.php&lt;br /&gt;    9        /var/www/gallery/include/functions.inc.php&lt;br /&gt;    8        /var/www/blog/wp-includes/js/tinymce/plugins/spellchecker/config.php&lt;br /&gt;    8        /var/www/blog/wp-admin/includes/class-wp-filesystem-ssh2.php&lt;br /&gt;&lt;br /&gt;[[ Top 10 compression match counts ]]&lt;br /&gt;1.0704        /var/www/administrator/templates/system/index.php&lt;br /&gt;1.0704        /var/www/templates/system/index.php&lt;br /&gt;1.0000        /var/www/blog/wp-content/plugins/sexybookmarks/includes/index.php&lt;br /&gt;1.0000        /var/www/blog/wp-content/plugins/sexybookmarks/js/index.php&lt;br /&gt;0.9663        /var/www/blog/wp-content/themes/lightword/alternatives/404.php&lt;br /&gt;0.8958        /var/www/includes/mambo.php&lt;br /&gt;0.8860        /var/www/includes/joomla.php&lt;br /&gt;0.8821        /var/www/includes/vcard.class.php&lt;br /&gt;0.8818        /var/www/includes/PEAR/PEAR.php&lt;br /&gt;0.8796        /var/www/includes/HTML_toolbar.php&lt;br /&gt;&lt;br /&gt;[[ Top cumulative ranked files ]]&lt;br /&gt;  122        /var/www/webacoo.php&lt;br /&gt;  202        /var/www/blog/wp-admin/js/revisions-js.php&lt;br /&gt;  528        /var/www/plugins/content/jw_allvideos/includes/elements/header.php&lt;br /&gt;  912        /var/www/plugins/content/jw_allvideos/includes/helper.php&lt;br /&gt;  984        /var/www/modules/mod_archive/helper.php&lt;br /&gt; 1100        /var/www/libraries/bitfolge/vcard.php&lt;br /&gt; 1210        /var/www/administrator/components/com_content/elements/article.php&lt;br /&gt; 1240        /var/www/gallery/addfav.php&lt;br /&gt; 1246        /var/www/administrator/components/com_installer/admin.installer.php&lt;br /&gt; 1258        /var/www/administrator/components/com_config/views/component/view.php&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;Encontraremos &lt;a href="http://code.google.com/p/emelco/"&gt;emelco&lt;/a&gt;, una &lt;a href="http://xd-blog.com.ar/makeshell/?"&gt;shell osfuscada&lt;/a&gt; y una wso metida al final de una imagen, pero también hay que decir que esta herramienta no es infalible y que, si el atacante pone un poco de empeño, se pueden evavir sus métodos de detección:&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;Strings largas&lt;/span&gt;: NeoPI identifica las cadenas largas que normalmente representan código ofuscado. Se podrían añadir espacios para separar el string (base64_decode los va a ignorar).&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;Entropía&lt;/span&gt;: NeoPI calcula la entropía de &lt;span style="font-style: italic;"&gt;Shannon &lt;/span&gt;de los datos y devuelve un valor float entre 0 y 8. Si metemos espacios despues de cada caracter del string en base64 aumentamos el largo del archivo y la entropia va a ser menor. Tambien se puede agregar un comentario con los caracteres suficientes para que la entropia baje lo suficiente.&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;Índice de coincidencia (I.C.)&lt;/span&gt;: esta técnica se basa en el cálculo de las coincidencias de combinaciones de caracteres comparadas con las de un texto de ejemplo con la misma distribución. Un bajo IC indicará una posible ofuscación o cifrado. Teóricamente se podría intentar modificar el índice añadiendo caracteres basura o junk.&lt;br /&gt;&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;Firmas&lt;/span&gt;: la típica búsqueda de patrones. Evitando el uso de eval(), system() y demás funciones comunes de las webshells. Se pueden usar funciones globales o 'strrev' ($b=strrev("edoced_4"."6esab")).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;Referencias:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://labs.neohapsis.com/2011/12/20/neopi-in-the-wild/"&gt;NeoPI in the Wild - Neohapsis&lt;/a&gt;&lt;br /&gt;&lt;a href="https://elrincondeseth.wordpress.com/2011/08/17/bypasseando-neopi/"&gt;Bypasseando NeoPI - El rincon de seth&lt;/a&gt;&lt;br /&gt;&lt;a href="https://bechtsoudis.com/hacking/maths-behind-web-shell-code-detection/"&gt;Maths behind web shell code detection - Anestis Bechtsoudis&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://resources.infosecinstitute.com/web-shell-detection/"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Web Shell Detection Using NeoPI - InfoSec&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-519279937745499516?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/519279937745499516/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=519279937745499516' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/519279937745499516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/519279937745499516'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/deteccion-de-web-shells-con-neopi-y.html' title='Detección de web shells con NeoPI y técnicas de evasión'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-a_xM-l7XaxE/TvtSC5Th2-I/AAAAAAAAChs/3j4y7DYUCOk/s72-c/storm7shell.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-3528004988010259490</id><published>2011-12-28T10:35:00.004+01:00</published><updated>2011-12-28T10:41:26.564+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><title type='text'>Nuevo 0-day en Windows 7 causa un pantallazo rojo</title><content type='html'>&lt;a href="http://3.bp.blogspot.com/-SkvIOCK8Roo/TvrkCbG9elI/AAAAAAAAChg/noEU6AaAiaI/s1600/28-diciembre-inocente.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 212px; height: 149px;" src="http://1.bp.blogspot.com/-bKoYT7ZlcAc/TvrjVjL247I/AAAAAAAAChU/YEzKLdHFY2g/s320/RSOD.PNG" alt="" id="BLOGGER_PHOTO_ID_5691111038497776562" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Al igual que ya ocurrió con &lt;a href="http://hackplayers.blogspot.com/2011/11/descubren-que-duqu-explota-un-0-day-en.html"&gt;Duqu&lt;/a&gt; hará ya más de dos meses, el grupo de hackers polaco &lt;a href="http://www.couboys.net/media/062010/1275601688.jpg"&gt;R4nd0m&lt;/a&gt; ha publicado el código de lo que sería una nueva vulnerabilidad de tipo 0-day que afecta al kernel de Windows 7 y que provoca la parada del sistema afectado.&lt;br /&gt;&lt;br /&gt;El exploit, escrito en C y en menos de 200 líneas, se aprovecha de un fallo en el API de la librería shlwapi.dll (Shell Lightweight Utility Functions) y causa un pantallazo rojo (RSoD o Red Screen of Death).&lt;br /&gt;&lt;br /&gt;Lo sorprendente es que el rojo no se utilizaba desde versiones preliminares de Windows 98 y Vista (Windows 8 utilizará el negro para sus pantallazos de la muerte), aunque recordemos que cualquiera podría cambiarlo con programas como &lt;a href="http://download.sysinternals.com/Files/Notmyfault.zip"&gt;NotMyFault&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;El código del exploit está disponible &lt;a href="http://3.bp.blogspot.com/-SkvIOCK8Roo/TvrkCbG9elI/AAAAAAAAChg/noEU6AaAiaI/s1600/28-diciembre-inocente.jpg"&gt;aquí&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-3528004988010259490?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/3528004988010259490/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=3528004988010259490' title='3 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3528004988010259490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3528004988010259490'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/nuevo-0-day-en-windows-7-causa-un.html' title='Nuevo 0-day en Windows 7 causa un pantallazo rojo'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-bKoYT7ZlcAc/TvrjVjL247I/AAAAAAAAChU/YEzKLdHFY2g/s72-c/RSOD.PNG' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8336317620107606921</id><published>2011-12-27T10:49:00.007+01:00</published><updated>2011-12-27T11:47:21.663+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='curiosidades'/><category scheme='http://www.blogger.com/atom/ns#' term='humor'/><title type='text'>Caras "cachondas" en el chat de Facebook</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;¿Usas el chat de Facebook para comunicarte con tus conocidos?, ¿tienes algún colega que piensas que es un poco troll?. Gracias a &lt;a href="http://www.reddit.com/r/WTF/comments/np3qi/you_can_make_rage_faces_on_facebook_im_no_shit_im"&gt;reddit&lt;/a&gt; ahora es tu oportunidad de expresarte más gráficamente con estas nuevas caras, simplemente pega en la ventana del chat el código numérico entre corchetes:&lt;br /&gt;&lt;br /&gt;Troll face [[171108522930776]]&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-5X0GlHAPXuY/TvmXUf9CatI/AAAAAAAAChI/qlTo71ha9aA/s1600/ragefaces_facebook.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 349px; height: 400px;" src="http://3.bp.blogspot.com/-5X0GlHAPXuY/TvmXUf9CatI/AAAAAAAAChI/qlTo71ha9aA/s400/ragefaces_facebook.png" alt="" id="BLOGGER_PHOTO_ID_5690745982590020306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;ARE YOU F*CKING KIDDING ME [[143220739082110]]&lt;br /&gt;Not bad Obama [[169919399735055]]&lt;br /&gt;Me Gusta [[211782832186415]]&lt;br /&gt;Mother of God [[142670085793927]]&lt;br /&gt;Cereal Guy [[170815706323196]]&lt;br /&gt;LOL Face [[168456309878025]]&lt;br /&gt;NO Guy [[167359756658519]]&lt;br /&gt;Yao Ming [[218595638164996]]&lt;br /&gt;Derp [[224812970902314]]&lt;br /&gt;Derpina [[192644604154319]]&lt;br /&gt;Forever Alone [[177903015598419]]&lt;br /&gt;Not Bad [[NotBaad]]&lt;br /&gt;Fuck yeah [[105387672833401]]&lt;br /&gt;Challange accepted: [[100002727365206]]&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Okay face [[100002752520227]]&lt;br /&gt;F*ck that guy [[218595638164996]]&lt;br /&gt;Poker face [[129627277060203]]&lt;br /&gt;Socially awkward penguin [[98438140742]]&lt;br /&gt;Rage face [[FUUUOFFICIAL]]&lt;br /&gt;Lamp [[100001256102462]]&lt;br /&gt;Feel like a sir [[168040846586189]]&lt;br /&gt;Forever alone christmas [[125038607580286]]&lt;br /&gt;&lt;br /&gt;Lo dicho, a disfrutarlas y:&lt;br /&gt;&lt;br /&gt;[[161672657237726]] [[140775945956538]] [[111884958838844]] [[111884958838844]] [[140715832616884]]&lt;br /&gt;&lt;br /&gt;[[broughttoyoubytheletter]] [[205082339544090]] [[111884958838844]] [[432883640525]] [[136198113087158]] [[142464449131926]] [[161672657237726]] [[399197913893]] [[136198113087158]]&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8336317620107606921?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8336317620107606921/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8336317620107606921' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8336317620107606921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8336317620107606921'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/caras-cachondas-en-el-chat-de-facebook.html' title='Caras &quot;cachondas&quot; en el chat de Facebook'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-5X0GlHAPXuY/TvmXUf9CatI/AAAAAAAAChI/qlTo71ha9aA/s72-c/ragefaces_facebook.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-891443719628430175</id><published>2011-12-23T16:06:00.010+01:00</published><updated>2011-12-23T17:20:06.165+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ingeniería inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='retos'/><category scheme='http://www.blogger.com/atom/ns#' term='android'/><title type='text'>Solución al reto 14 del crackme#2 para Android</title><content type='html'>&lt;link href="http://alexgorbatchev.com/pub/sh/current/styles/shCore.css" rel="stylesheet" type="text/css"&gt;&lt;link href="http://alexgorbatchev.com/pub/sh/current/styles/shThemeDefault.css" rel="stylesheet" type="text/css"&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shCore.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushBash.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushCss.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushJava.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushJScript.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushPerl.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushPhp.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushSql.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushVb.js" type="text/javascript"&gt;&lt;/script&gt;&lt;script src="http://alexgorbatchev.com/pub/sh/current/scripts/shBrushXml.js" type="text/javascript"&gt;&lt;/script&gt;&lt;link href="http://alexgorbatchev.com/pub/sh/current/styles/shThemeDefault.css" rel="stylesheet" type="text/css"&gt;&lt;script language="javascript" type="text/javascript"&gt;SyntaxHighlighter.config.bloggerMode = true;SyntaxHighlighter.all();&lt;/script&gt; &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-rl7EkqelMdI/TvSi3c1XfUI/AAAAAAAACec/bv50FISL3Wc/s1600/android_puzzle.jpg"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 259px; height: 194px;" src="http://3.bp.blogspot.com/-rl7EkqelMdI/TvSi3c1XfUI/AAAAAAAACec/bv50FISL3Wc/s320/android_puzzle.jpg" alt="" id="BLOGGER_PHOTO_ID_5689351302792314178" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Nuestro &lt;a href="http://hackplayers.blogspot.com/2011/12/reto-14-android-crackme2.html"&gt;segundo crackme para Android&lt;/a&gt; (y último reto del año) consistía en evadir la implementación del proceso de licenciamiento de Android o &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Android License Verification Library (ALVL)&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;. La aplicación era muy sencilla pero, eso sí, tenía alguna trampa ;)&lt;br /&gt;&lt;br /&gt;El ganador del reto, &lt;a href="http://stackoverflow.com/users/382920/necronet"&gt;Jose Ayerdis (Necronet)&lt;/a&gt; de Nicaragua, ha publicado un completo &lt;a href="http://www.necronet.info/2011/12/hacking-android-crackeando-lvl.html"&gt;solucionario&lt;/a&gt; en &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;su &lt;a href="http://www.necronet.info/"&gt;blog&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;, que recomendamos que visitéis para ver más tips adicionales y otros interesantes artículos.&lt;br /&gt;&lt;br /&gt;También quería dar las gracias a todos los que habéis intentado solucionar el reto. Por último, os dejo con el procedimiento seguido por Necronet:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="font-size:large;"&gt;Descarga el APKTool&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El &lt;a href="http://code.google.com/p/android-apktool/"&gt;apktool&lt;/a&gt; es  una herramienta maravillosa, si te quieres hacer de esto de cracking  aplicaciones android el apktool es un fiel compañero, permite realiza  muchas cosas entre ellas:&lt;br /&gt;&lt;/span&gt;&lt;ul  style="font-family: verdana;font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Extraer y decompilar fuentes de empaquetados Android(apktool), esto incluye recursos(res), manifiesto(&lt;a href="http://developer.android.com/guide/topics/manifest/manifest-intro.html"&gt;AndroidManifest&lt;/a&gt;), y fuentes decompiladas.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Recompilar dichas fuentes y volverlas a empaquetar.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;Depurar código decompilado backsmali.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;div  style="font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt; Luego de seguir la instalación del APKTool procede a ejecutar el comando para extraer el APK.&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;  &lt;div&gt;&lt;div id="highlighter_546567" class="syntaxhighlighter  shell "&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="shell plain"&gt;$apktool d cracme2hpys.apk out&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;a href="http://1.bp.blogspot.com/-oPAhOrTRH_w/Tu-PJYpZSdI/AAAAAAAAA7k/UNoAaV943q0/s1600/step1.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://1.bp.blogspot.com/-oPAhOrTRH_w/Tu-PJYpZSdI/AAAAAAAAA7k/UNoAaV943q0/s320/step1.png" border="0" height="116" width="320" /&gt;&lt;/a&gt;&lt;/div&gt; &lt;div  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt; &lt;div  style="font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt; *out es el directorio donde se descomprime el &lt;a href="http://es.wikipedia.org/wiki/APK_%28formato%29"&gt;apk&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt; &lt;b&gt;&lt;span style="font-size:large;"&gt;Husmeando el directorio extraído&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt; &lt;div&gt; &lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt; &lt;div&gt; &lt;span style="font-family:verdana;font-size:85%;"&gt;Lo primero que pensé es bypasear cambiando la clase en el  AndroidManifest.xml que es la que comienza la aplicación, pero no tuve éxito.&lt;br /&gt;&lt;br /&gt;Así que tuve que husmear el código decompilado. El AndroidManifest.xml  siempre te da la pista de donde comenzar en general procuro que sea la  Actividad inicial, por que es donde probablemente se de la invocación  del &lt;a href="http://developer.android.com/guide/publishing/licensing.html"&gt;ALVL&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;a href="http://4.bp.blogspot.com/-DANy3gimJeI/Tu-SCf_biQI/AAAAAAAAA7s/PhVaoeHqjaM/s1600/Screen+Shot+2011-12-19+at+1.30.23+PM.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://4.bp.blogspot.com/-DANy3gimJeI/Tu-SCf_biQI/AAAAAAAAA7s/PhVaoeHqjaM/s320/Screen+Shot+2011-12-19+at+1.30.23+PM.png" border="0" height="78" width="320" /&gt;&lt;/a&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;span style="font-family:verdana;font-size:85%;"&gt;Así que puedes revisar en la carpeta &lt;b&gt;com/hpys/crackmes/LicenseCheck.smali&lt;/b&gt;. Veras mucho código, si tienes alguna experiencia con &lt;a href="http://en.wikipedia.org/wiki/MIPS_architecture#MIPS_assembly_language"&gt;lenguaje ensamblador &lt;/a&gt; no te parecerá tan raro, sino estudia un poco y veras que sencillo que es. &lt;/span&gt; &lt;div  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; Busca en el onCreate de LicenseCheck.smali el código donde revisa la licencia se realiza una invocacion a un metodo doCheck().&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_799668" class="syntaxhighlighter  java"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;2&lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;3&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt;4&lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;5&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt;6&lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;7&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt;8&lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;9&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt;10&lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;11&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt;12&lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;13&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-direct  {v1, p0, v2, v3},  Lcom/android/vending/licensing/LicenseChecker;-&amp;gt;&lt;init&gt;(Landroid/content/Context;Lcom/android/vending/licensing/Policy;Ljava/lang/String;)V&lt;/init&gt;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt; &lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;120&lt;/code&gt;&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt; &lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;iput-object v1, p0, Lcom/hpys/crackmes/LicenseCheck;-&amp;gt;mChecker:Lcom/android/vending/licensing/LicenseChecker;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt; &lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;123&lt;/code&gt;&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt; &lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-direct {p0}, Lcom/hpys/crackmes/LicenseCheck;-&amp;gt;doCheck()V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt; &lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;125&lt;/code&gt;&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt; &lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;return&lt;/code&gt;&lt;code class="java plain"&gt;-&lt;/code&gt;&lt;code class="java keyword"&gt;void&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;/div&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Si miras bien en la linea 123 hay un doCheck este llama a un método en la misma clase &lt;b&gt;LicenseCheck &lt;/b&gt;pero que hace realmente este método veamos:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_243760" class="syntaxhighlighter  java"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;2&lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;3&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt;4&lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;5&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt;6&lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;7&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt;8&lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;9&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt;10&lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;11&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt;12&lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;13&lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt;14&lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;15&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt;16&lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt;17&lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt;18&lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;19&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt;20&lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;21&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt;22&lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;23&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt;24&lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;25&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt;26&lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;27&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="java plain"&gt;.method &lt;/code&gt;&lt;code class="java keyword"&gt;private&lt;/code&gt; &lt;code class="java plain"&gt;doCheck()V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt; &lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.locals &lt;/code&gt;&lt;code class="java value"&gt;2&lt;/code&gt;&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt; &lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt; &lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt; &lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.prologue&lt;/code&gt;&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt; &lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;106&lt;/code&gt;&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt; &lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;iget-object v0, p0, Lcom/hpys/crackmes/LicenseCheck;-&amp;gt;mChecker:Lcom/android/vending/licensing/LicenseChecker;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt; &lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt; &lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt; &lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;iget-object  v1, p0,  Lcom/hpys/crackmes/LicenseCheck;-&amp;gt;mLicenseCheckerCallback:Lcom/android/vending/licensing/LicenseCheckerCallback;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt; &lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt; &lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt; &lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-virtual  {v0, v1},  Lcom/android/vending/licensing/LicenseChecker;-&amp;gt;checkAccess(Lcom/android/vending/licensing/LicenseCheckerCallback;)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt; &lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt; &lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt; &lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;107&lt;/code&gt;&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt; &lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;return&lt;/code&gt;&lt;code class="java plain"&gt;-&lt;/code&gt;&lt;code class="java keyword"&gt;void&lt;/code&gt;&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt; &lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;&lt;code class="java plain"&gt;.end method&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Ahora es claro que el método doCheck hace la revisión, y llama a la  clase LicenseChecker y aparentemente le pasa un callback  LicenseCheckerCallback probablemente para informar que el licensamiento  se realizo de forma correcta. Entonces el paso mas lógico ahora sera ir a  explorar la clase &lt;/span&gt;&lt;b style="font-family: verdana;"&gt;com/android/vending/licensing/LicenseChecker&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size:large;"&gt;Explorando del LicenseChecker&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-size:large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;a href="http://2.bp.blogspot.com/-irXAcdbogls/Tu_4zdF9xkI/AAAAAAAAA70/f01f_8YSwvw/s1600/Screen+Shot+2011-12-19+at+8.53.01+PM.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://2.bp.blogspot.com/-irXAcdbogls/Tu_4zdF9xkI/AAAAAAAAA70/f01f_8YSwvw/s200/Screen+Shot+2011-12-19+at+8.53.01+PM.png" border="0" height="200" width="161" /&gt;&lt;/a&gt;&lt;/div&gt; &lt;b&gt;&lt;span style="font-size:large;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt; &lt;div&gt; &lt;/div&gt; &lt;div&gt; &lt;span style="font-family:verdana;font-size:85%;"&gt;Antes de empezar a leer todo el LicenseChecker y sus derivados, mejor ve  directamente a la invocación del método checkAccess que es el que  invoca la clase LicenseCheck recuerdas?.&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_983785" class="syntaxhighlighter  java"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-virtual  {v0, v1},  Lcom/android/vending/licensing/LicenseChecker;-&amp;gt;checkAccess(Lcom/android/vending/licensing/LicenseCheckerCallback;)V&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Probablemente este método nos proporcione mejores pista que cualquier  otro por que es donde se lleva acabo la revisión de la licencia.&lt;br /&gt;&lt;br /&gt;El método checkAccess, es bastante grande así que procurare resumir las partes relevantes, por ejemplo:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_922203" class="syntaxhighlighter  java"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;2&lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;3&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt;4&lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;5&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt;6&lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;7&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt;8&lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;9&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt;10&lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;11&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt;12&lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;13&lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt;14&lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;15&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt;16&lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt;17&lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt;18&lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;19&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt;20&lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;21&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt;22&lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;23&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt;24&lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;25&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt;26&lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;27&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="java plain"&gt;# virtual methods&lt;/code&gt;&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt; &lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;&lt;code class="java plain"&gt;.method &lt;/code&gt;&lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;declared-&lt;/code&gt;&lt;code class="java keyword"&gt;synchronized&lt;/code&gt; &lt;code class="java plain"&gt;checkAccess(Lcom/android/vending/licensing/LicenseCheckerCallback;)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt; &lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.locals &lt;/code&gt;&lt;code class="java value"&gt;9&lt;/code&gt;&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt; &lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.parameter &lt;/code&gt;&lt;code class="java string"&gt;"callback"&lt;/code&gt;&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt; &lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.prologue&lt;/code&gt;&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt; &lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;133&lt;/code&gt;&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt; &lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;monitor-enter p0&lt;/code&gt;&lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt; &lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;:try_start_0&lt;/code&gt;&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt; &lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;iget-object v1, p0, Lcom/android/vending/licensing/LicenseChecker;-&amp;gt;mPolicy:Lcom/android/vending/licensing/Policy;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt; &lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-&lt;/code&gt;&lt;code class="java keyword"&gt;interface&lt;/code&gt; &lt;code class="java plain"&gt;{v1}, Lcom/android/vending/licensing/Policy;-&amp;gt;allowAccess()Z&lt;/code&gt;&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt; &lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;move-result v1&lt;/code&gt;&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt; &lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;if&lt;/code&gt;&lt;code class="java plain"&gt;-eqz v1, :cond_0&lt;/code&gt;&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt; &lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;134&lt;/code&gt;&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt; &lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;const&lt;/code&gt;&lt;code class="java plain"&gt;-string v1, &lt;/code&gt;&lt;code class="java string"&gt;"LicenseChecker"&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;    &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;if-eqz v1, :cond_0 &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;esta condición es muy importante por que  en caso de cumplirse te envía a cond_0 y mas abajo indica que es la  instanciacion del validador de licencias. Si nos saltamos esta parte  tendremos el ejercicio terminado!!. Es bien fácil de hacer esta condición tiene una operación antagónica la cual es: &lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-family:Arial;font-size:85%;color:white;"   &gt;&lt;b style="color: rgb(0, 0, 0);"&gt;if-nez vx,target&lt;/b&gt; &lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;así que al cambiar las operaciones debería funcionar.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="font-family: verdana;"&gt;Pero no funciona.... ¬¬&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Si, si, cambiamos esta linea y ejecutamos el paso de recompilación de  codigo y reempaquetamiento (lo explicare luego), el reto nos regala un obstáculo adicional,  al pasar la licencia el MyAndroidAppActivity no  parece invocar al metodo onCreate, y te genera el siguiente error en &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://developer.android.com/guide/developing/tools/logcat.html"&gt;logcat&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;a href="http://1.bp.blogspot.com/-zhTnI0YFo3I/TvEdtIT96LI/AAAAAAAAA78/bRLMmt1_rbQ/s1600/Error+crackeado.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://1.bp.blogspot.com/-zhTnI0YFo3I/TvEdtIT96LI/AAAAAAAAA78/bRLMmt1_rbQ/s320/Error+crackeado.png" border="0" height="132" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;¿Así que pasa? ¿por que no funciona?, Bueno la respuesta del por qué no  funciona es clara: la clase MyAndroidAppActivity no tiene la invocación  al metodo onCreate y hará falta agregárselo con &lt;b&gt;backsmali.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_328039" class="syntaxhighlighter  java"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;2&lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;3&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt;4&lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;5&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt;6&lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;7&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt;8&lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;9&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt;10&lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;11&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt;12&lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;13&lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt;14&lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;15&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt;16&lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt;17&lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt;18&lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;19&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt;20&lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;21&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt;22&lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;23&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt;24&lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;25&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt;26&lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;27&lt;/div&gt;&lt;div class="line number28 index27 alt1"&gt;28&lt;/div&gt;&lt;div class="line number29 index28 alt2"&gt;29&lt;/div&gt;&lt;div class="line number30 index29 alt1"&gt;30&lt;/div&gt;&lt;div class="line number31 index30 alt2"&gt;31&lt;/div&gt;&lt;div class="line number32 index31 alt1"&gt;32&lt;/div&gt;&lt;div class="line number33 index32 alt2"&gt;33&lt;/div&gt;&lt;div class="line number34 index33 alt1"&gt;34&lt;/div&gt;&lt;div class="line number35 index34 alt2"&gt;35&lt;/div&gt;&lt;div class="line number36 index35 alt1"&gt;36&lt;/div&gt;&lt;div class="line number37 index36 alt2"&gt;37&lt;/div&gt;&lt;div class="line number38 index37 alt1"&gt;38&lt;/div&gt;&lt;div class="line number39 index38 alt2"&gt;39&lt;/div&gt;&lt;div class="line number40 index39 alt1"&gt;40&lt;/div&gt;&lt;div class="line number41 index40 alt2"&gt;41&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="java plain"&gt;.&lt;/code&gt;&lt;code class="java keyword"&gt;class&lt;/code&gt; &lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;Lcom/hpys/crackmes/MyAndroidAppActivity;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt; &lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;&lt;code class="java plain"&gt;.&lt;/code&gt;&lt;code class="java keyword"&gt;super&lt;/code&gt; &lt;code class="java plain"&gt;Lcom/hpys/crackmes/LicenseCheck;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt; &lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;&lt;code class="java plain"&gt;.source &lt;/code&gt;&lt;code class="java string"&gt;"MyAndroidAppActivity.java"&lt;/code&gt;&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt; &lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;&lt;code class="java plain"&gt;# direct methods&lt;/code&gt;&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt; &lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;&lt;code class="java plain"&gt;.method &lt;/code&gt;&lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;constructor &lt;init&gt;()V&lt;/init&gt;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt; &lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.locals &lt;/code&gt;&lt;code class="java value"&gt;0&lt;/code&gt;&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt; &lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.prologue&lt;/code&gt;&lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt; &lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;6&lt;/code&gt;&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt; &lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-direct {p0}, Lcom/hpys/crackmes/LicenseCheck;-&amp;gt;&lt;init&gt;()V&lt;/init&gt;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt; &lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;return&lt;/code&gt;&lt;code class="java plain"&gt;-&lt;/code&gt;&lt;code class="java keyword"&gt;void&lt;/code&gt;&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt; &lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;&lt;code class="java plain"&gt;.end method&lt;/code&gt;&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt; &lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;&lt;code class="java plain"&gt;# virtual methods&lt;/code&gt;&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt; &lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;&lt;code class="java plain"&gt;.method &lt;/code&gt;&lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;onCreate(Landroid/os/Bundle;)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt; &lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.locals &lt;/code&gt;&lt;code class="java value"&gt;0&lt;/code&gt;&lt;/div&gt;&lt;div class="line number28 index27 alt1"&gt; &lt;/div&gt;&lt;div class="line number29 index28 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.parameter &lt;/code&gt;&lt;code class="java string"&gt;"savedInstanceState"&lt;/code&gt;&lt;/div&gt;&lt;div class="line number30 index29 alt1"&gt; &lt;/div&gt;&lt;div class="line number31 index30 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.prologue&lt;/code&gt;&lt;/div&gt;&lt;div class="line number32 index31 alt1"&gt; &lt;/div&gt;&lt;div class="line number33 index32 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;11&lt;/code&gt;&lt;/div&gt;&lt;div class="line number34 index33 alt1"&gt; &lt;/div&gt;&lt;div class="line number35 index34 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-&lt;/code&gt;&lt;code class="java keyword"&gt;super&lt;/code&gt; &lt;code class="java plain"&gt;{p0, p1}, Lcom/hpys/crackmes/LicenseCheck;-&amp;gt;onCreate(Landroid/os/Bundle;)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number36 index35 alt1"&gt; &lt;/div&gt;&lt;div class="line number37 index36 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;15&lt;/code&gt;&lt;/div&gt;&lt;div class="line number38 index37 alt1"&gt; &lt;/div&gt;&lt;div class="line number39 index38 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;return&lt;/code&gt;&lt;code class="java plain"&gt;-&lt;/code&gt;&lt;code class="java keyword"&gt;void&lt;/code&gt;&lt;/div&gt;&lt;div class="line number40 index39 alt1"&gt; &lt;/div&gt;&lt;div class="line number41 index40 alt2"&gt;&lt;code class="java plain"&gt;.end method&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El código anterior demuestra muchas faltas en la clase  MyAndroidAppActivity, siendo un código pequeño y sencillo es fácil  reconocerlas todas:&lt;br /&gt;&lt;/span&gt;&lt;div&gt; &lt;ul  style="font-family: verdana;font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;El método onCreate no llama al super.onCreate.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;El método onCreate tampoco tiene layout asignado debería tener main.xml con setContentView.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;La clase MyAndroidAppActivity hereda de LicenseCheck en vez de  Activity y tambien en el método init se hace la invocación especial a  este metodo.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Aquí el código del MyAndroidAppActivity con las fallas anteriores resueltas:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt; &lt;/div&gt; &lt;div&gt; &lt;div&gt;&lt;div id="highlighter_422880" class="syntaxhighlighter  java"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;2&lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;3&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt;4&lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt;5&lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt;6&lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;7&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt;8&lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt;9&lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt;10&lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;11&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt;12&lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt;13&lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt;14&lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;15&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt;16&lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt;17&lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt;18&lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;19&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt;20&lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;21&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt;22&lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;23&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt;24&lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;25&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt;26&lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;27&lt;/div&gt;&lt;div class="line number28 index27 alt1"&gt;28&lt;/div&gt;&lt;div class="line number29 index28 alt2"&gt;29&lt;/div&gt;&lt;div class="line number30 index29 alt1"&gt;30&lt;/div&gt;&lt;div class="line number31 index30 alt2"&gt;31&lt;/div&gt;&lt;div class="line number32 index31 alt1"&gt;32&lt;/div&gt;&lt;div class="line number33 index32 alt2"&gt;33&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="java plain"&gt;.&lt;/code&gt;&lt;code class="java keyword"&gt;class&lt;/code&gt; &lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;Lcom/hpys/crackmes/MyAndroidAppActivity;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;&lt;code class="java plain"&gt;.&lt;/code&gt;&lt;code class="java keyword"&gt;super&lt;/code&gt; &lt;code class="java plain"&gt;Landroid/app/Activity;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number3 index2 alt2"&gt;&lt;code class="java plain"&gt;.source &lt;/code&gt;&lt;code class="java string"&gt;"MyAndroidAppActivity.java"&lt;/code&gt;&lt;/div&gt;&lt;div class="line number4 index3 alt1"&gt; &lt;/div&gt;&lt;div class="line number5 index4 alt2"&gt; &lt;/div&gt;&lt;div class="line number6 index5 alt1"&gt;&lt;code class="java plain"&gt;# direct methods&lt;/code&gt;&lt;/div&gt;&lt;div class="line number7 index6 alt2"&gt;&lt;code class="java plain"&gt;.method &lt;/code&gt;&lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;constructor &lt;init&gt;()V&lt;/init&gt;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number8 index7 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.locals &lt;/code&gt;&lt;code class="java value"&gt;0&lt;/code&gt;&lt;/div&gt;&lt;div class="line number9 index8 alt2"&gt; &lt;/div&gt;&lt;div class="line number10 index9 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.prologue&lt;/code&gt;&lt;/div&gt;&lt;div class="line number11 index10 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;6&lt;/code&gt;&lt;/div&gt;&lt;div class="line number12 index11 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-direct {p0}, Landroid/app/Activity;-&amp;gt;&lt;init&gt;()V&lt;/init&gt;&lt;/code&gt;&lt;/div&gt;&lt;div class="line number13 index12 alt2"&gt; &lt;/div&gt;&lt;div class="line number14 index13 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;return&lt;/code&gt;&lt;code class="java plain"&gt;-&lt;/code&gt;&lt;code class="java keyword"&gt;void&lt;/code&gt;&lt;/div&gt;&lt;div class="line number15 index14 alt2"&gt;&lt;code class="java plain"&gt;.end method&lt;/code&gt;&lt;/div&gt;&lt;div class="line number16 index15 alt1"&gt; &lt;/div&gt;&lt;div class="line number17 index16 alt2"&gt; &lt;/div&gt;&lt;div class="line number18 index17 alt1"&gt;&lt;code class="java plain"&gt;# virtual methods&lt;/code&gt;&lt;/div&gt;&lt;div class="line number19 index18 alt2"&gt;&lt;code class="java plain"&gt;.method &lt;/code&gt;&lt;code class="java keyword"&gt;public&lt;/code&gt; &lt;code class="java plain"&gt;onCreate(Landroid/os/Bundle;)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number20 index19 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.locals &lt;/code&gt;&lt;code class="java value"&gt;1&lt;/code&gt;&lt;/div&gt;&lt;div class="line number21 index20 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.parameter &lt;/code&gt;&lt;code class="java string"&gt;"savedInstanceState"&lt;/code&gt;&lt;/div&gt;&lt;div class="line number22 index21 alt1"&gt; &lt;/div&gt;&lt;div class="line number23 index22 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.prologue&lt;/code&gt;&lt;/div&gt;&lt;div class="line number24 index23 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;15&lt;/code&gt;&lt;/div&gt;&lt;div class="line number25 index24 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-&lt;/code&gt;&lt;code class="java keyword"&gt;super&lt;/code&gt; &lt;code class="java plain"&gt;{p0, p1}, Landroid/app/Activity;-&amp;gt;onCreate(Landroid/os/Bundle;)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number26 index25 alt1"&gt; &lt;/div&gt;&lt;div class="line number27 index26 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;17&lt;/code&gt;&lt;/div&gt;&lt;div class="line number28 index27 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;const&lt;/code&gt;&lt;code class="java plain"&gt;/high16 v0, &lt;/code&gt;&lt;code class="java value"&gt;0x7f03&lt;/code&gt;&lt;/div&gt;&lt;div class="line number29 index28 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;invoke-virtual {p0, v0}, Lcom/hpys/crackmes/MyAndroidAppActivity;-&amp;gt;setContentView(I)V&lt;/code&gt;&lt;/div&gt;&lt;div class="line number30 index29 alt1"&gt; &lt;/div&gt;&lt;div class="line number31 index30 alt2"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java plain"&gt;.line &lt;/code&gt;&lt;code class="java value"&gt;20&lt;/code&gt;&lt;/div&gt;&lt;div class="line number32 index31 alt1"&gt;&lt;code class="java spaces"&gt;    &lt;/code&gt;&lt;code class="java keyword"&gt;return&lt;/code&gt;&lt;code class="java plain"&gt;-&lt;/code&gt;&lt;code class="java keyword"&gt;void&lt;/code&gt;&lt;/div&gt;&lt;div class="line number33 index32 alt2"&gt;&lt;code class="java plain"&gt;.end method&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;/div&gt; &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Podemos realizar los siguientes apuntes, como la invocación del método &lt;/span&gt;&lt;b style="font-family: verdana;"&gt;&lt;i&gt;onCreate()&lt;/i&gt;&lt;/b&gt;&lt;span style="font-family:verdana;"&gt; y de &lt;/span&gt;&lt;b style="font-family: verdana;"&gt;&lt;i&gt;setContentView&lt;/i&gt; &lt;/b&gt;&lt;span style="font-family:verdana;"&gt;con la variable &lt;/span&gt;&lt;b style="font-family: verdana;"&gt;&lt;i&gt;v0&lt;/i&gt;&lt;/b&gt;&lt;span style="font-family:verdana;"&gt;, en este tienes que tener sumo cuidado en declarar &lt;/span&gt;&lt;b style="font-family: verdana;"&gt;&lt;i&gt;locals 1&lt;/i&gt;&lt;/b&gt;&lt;span style="font-family:verdana;"&gt; que es el numero de variables que utilizaras.&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;¿Ya terminamos?, algo así lo único que falta es recompilarlo y empaquetarlo para regresarlo a un APK.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:large;"&gt;&lt;b&gt;De regreso a un APK&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;A como mencione inicialmente &lt;b&gt;apktool &lt;/b&gt;también te permite  recompilar la aplicación y regresarla a un APK, pero vas a necesitara un  poco mas de eso para colocarla devuelta en el teléfono. Para recompilar  la aplicación ejecuta el comando:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_46563" class="syntaxhighlighter  shell"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="shell plain"&gt;$ apktool b out crackemecracked.apk&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;span style="font-family:verdana;font-size:85%;"&gt;Tambien necesitas firmarlo, para ello necesitas de un keystore, puedes crearlo facilmente con &lt;b&gt;&lt;a href="http://docs.oracle.com/javase/1.3/docs/tooldocs/win32/keytool.html"&gt;keytool&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_394422" class="syntaxhighlighter  shell"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="shell plain"&gt;$ keytool -genkey -&lt;/code&gt;&lt;code class="shell functions"&gt;v&lt;/code&gt; &lt;code class="shell plain"&gt;-keystore my-release-key.keystore&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;Ahora ya tienes tu keystore para firmar tu aplicación&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_100244" class="syntaxhighlighter  shell"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="shell plain"&gt;jarsigner -verbose -keystore keystore.keystore crackemecracked.apk crackmecracked&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Si deseas saber mas de como firmar aplicaciones android desde consola no te olvides pasar por la &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://developer.android.com/guide/publishing/app-signing.html"&gt;documentación oficial&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;. &lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;Ahora si tenemos la aplicacion firmada, es muy sencillo desintalarla y volverla instalar con el adb.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div id="highlighter_239431" class="syntaxhighlighter  shell"&gt;&lt;div class="toolbar"&gt;&lt;span&gt;&lt;a href="http://hackplayers.blogspot.com/2011/12/solucion-al-reto-14-del-crackme2-para.html#more" class="toolbar_item command_help help"&gt;?&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;table border="0" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="gutter"&gt;&lt;div class="line number1 index0 alt2"&gt;1&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;2&lt;/div&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;div class="container"&gt;&lt;div class="line number1 index0 alt2"&gt;&lt;code class="shell plain"&gt;$ adb uninstall com.hpys.crackmes &lt;/code&gt;&lt;/div&gt;&lt;div class="line number2 index1 alt1"&gt;&lt;code class="shell plain"&gt;$ adb &lt;/code&gt;&lt;code class="shell functions"&gt;install&lt;/code&gt; &lt;code class="shell plain"&gt;crackemecracked-za.apk&lt;/code&gt;&lt;/div&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt; &lt;span style=" white-space: pre;font-family:monospace;" &gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Si todo esta bien, la imagen que debería aparecer es la siguiente:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;a href="http://3.bp.blogspot.com/-LF3EY0KB9jo/TvF3jYmR6EI/AAAAAAAAA8M/rMMIxK654CA/s1600/cracked.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img src="http://3.bp.blogspot.com/-LF3EY0KB9jo/TvF3jYmR6EI/AAAAAAAAA8M/rMMIxK654CA/s320/cracked.png" border="0" height="192" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Y LISTO!! &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt; &lt;a href="http://3.bp.blogspot.com/-R-KFcBC4BNM/TvFwv1CE-qI/AAAAAAAAA8E/S5dG_s0mxIg/s1600/Screen+Shot+2011-12-20+at+11.38.34+PM.png" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;img src="http://3.bp.blogspot.com/-R-KFcBC4BNM/TvFwv1CE-qI/AAAAAAAAA8E/S5dG_s0mxIg/s200/Screen+Shot+2011-12-20+at+11.38.34+PM.png" border="0" height="148" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-891443719628430175?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/891443719628430175/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=891443719628430175' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/891443719628430175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/891443719628430175'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/solucion-al-reto-14-del-crackme2-para.html' title='Solución al reto 14 del crackme#2 para Android'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-rl7EkqelMdI/TvSi3c1XfUI/AAAAAAAACec/bv50FISL3Wc/s72-c/android_puzzle.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-6398734889103991845</id><published>2011-12-22T01:35:00.006+01:00</published><updated>2011-12-22T01:41:44.152+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='libros'/><title type='text'>Libro: Gray Hat Python: Programación en Python para hacking e ingeniería inversa</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-XmNoFOs94Ks/TvJ75yO0H0I/AAAAAAAACeQ/gxSs9NM-Kmc/s1600/gray_hat_python.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 188px; height: 246px;" src="http://4.bp.blogspot.com/-XmNoFOs94Ks/TvJ75yO0H0I/AAAAAAAACeQ/gxSs9NM-Kmc/s320/gray_hat_python.jpg" alt="" id="BLOGGER_PHOTO_ID_5688745511989026626" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Python se está convirtiendo en el lenguaje de programación elegido por muchos que se dedican al hacking, a la ingeniería inversa y a probar software. La razón principal es que es fácil y rápido de escribir, soporta bajo nivel y tiene bibliotecas que nos hacen felices.&lt;br /&gt;&lt;br /&gt;Ya no tendremos que buscar siempre en foros y manuales, &lt;span style="font-weight: bold;"&gt;Gray Hat Python&lt;/span&gt; muestra el uso de Python para una amplia variedad de tareas de hacking. Este libro explica los conceptos detrás de las herramientas de hacking y las técnicas con depuradores, troyanos, fuzzers y emuladores. Pero el autor, Justin Seitz, va más allá de la teoría mostrando cómo aprovechar las herramientas existentes de seguridad basadas en Python - y cómo construir las tuyas propias cuando lo necesites.&lt;br /&gt;&lt;br /&gt;Leyendo este libro aprenderas a:&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Automatizar las tediosas tareas de ingeniería inversa y seguridad&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Diseñar y programar tu propio depurador&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Fuzzear drivers de Windows y a crear potentes fuzzers desde el principio&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Divertirte con la inyección de código y librerías, técnicas de soft y hard hooking y otros trucos con software&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Esnifar tráfico seguro de sesión web cifrada&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;  Usar PyDBG, Immunity Debugger, Sulley, IDAPython, PyEMU y más&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-6398734889103991845?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/6398734889103991845/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=6398734889103991845' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6398734889103991845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6398734889103991845'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/libro-gray-hat-python-programacion-en.html' title='Libro: Gray Hat Python: Programación en Python para hacking e ingeniería inversa'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-XmNoFOs94Ks/TvJ75yO0H0I/AAAAAAAACeQ/gxSs9NM-Kmc/s72-c/gray_hat_python.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-7640931759839870919</id><published>2011-12-21T12:07:00.004+01:00</published><updated>2011-12-21T12:15:54.623+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='curiosidades'/><category scheme='http://www.blogger.com/atom/ns#' term='cracking'/><title type='text'>Las peores 25 contraseñas del 2011</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;SplashData crea anualmente una lista con las peores contraseñas del año basándose en la recolección de las contraseñas que los crackers postean online. Este año son las siguientes:&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;1. password&lt;/span&gt;&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-lT9mphIIpxU/TvG_aF_TWlI/AAAAAAAACeE/t17GuYey6SQ/s1600/postit_password.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 246px; height: 236px;" src="http://3.bp.blogspot.com/-lT9mphIIpxU/TvG_aF_TWlI/AAAAAAAACeE/t17GuYey6SQ/s320/postit_password.png" alt="" id="BLOGGER_PHOTO_ID_5688538259350837842" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;2. 123456&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;3.12345678&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;4. qwerty&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;5. abc123&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;6. monkey&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;7. 1234567&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;8. letmein&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;9. trustno1&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;10. dragon&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;11. baseball&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;12. 111111&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;13. iloveyou&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;14. master&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;15. sunshine&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;16. ashley&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;17. bailey&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;18. passw0rd&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;19. shadow&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;20. 123123&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;21. 654321&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;22. superman&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;23. qazwsx&lt;/span&gt; &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;24. michael&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;25. football&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;Si habéis leido las listas anteriores, estas contraseñas no han cambiado demasiado. "password" sigue apareciendo en el número 1, mientras que si pusieramos "passw0rd" bajaríamos al puesto 18.&lt;br /&gt;&lt;br /&gt;Siguen apareciendo las contraseñas predecibles basadas en secuencias "qwerty" o "123456" y los nombres comunes como "ashley" y "michael".&lt;br /&gt;&lt;br /&gt;También son comunes las elecciones de "abc123" y "trustno1" porque muchos sitios web requieren el uso de contraseñas con combinación de números y caracteres.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-7640931759839870919?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/7640931759839870919/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=7640931759839870919' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7640931759839870919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7640931759839870919'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/las-peores-25-contrasenas-del-2011.html' title='Las peores 25 contraseñas del 2011'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-lT9mphIIpxU/TvG_aF_TWlI/AAAAAAAACeE/t17GuYey6SQ/s72-c/postit_password.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-7742214900873529598</id><published>2011-12-20T00:58:00.002+01:00</published><updated>2011-12-20T01:03:05.865+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='técnicas'/><category scheme='http://www.blogger.com/atom/ns#' term='noticias'/><title type='text'>Windows 8 incluirá contraseñas mediante gestos en imágenes</title><content type='html'>&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Microsoft está trabajando en la integración de las contraseñas en imágenes en su próximo sistema operativo Windows 8.&lt;br /&gt;&lt;br /&gt;El objetivo de los desarrolladores &lt;span style="font-style: italic;"&gt;"fue la creación de una forma rápida y fluida de inicio de sesión muy personal, por lo que decidieron que los usuarios podrían utilizar una imagen de su colección de fotografías".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/-vQHFENxVxN4/Tu_P-RbOmqI/AAAAAAAACd4/_Qk4mZbvyq0/s1600/win8-picture-pass.jpg"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 398px; height: 222px;" src="http://1.bp.blogspot.com/-vQHFENxVxN4/Tu_P-RbOmqI/AAAAAAAACd4/_Qk4mZbvyq0/s400/win8-picture-pass.jpg" alt="" id="BLOGGER_PHOTO_ID_5687993523128670882" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;Una vez que que se elige la imagen, se pide a los usuarios que dibujen tres gestos dentro de ella (círculos, líneas o trazas), que luego tendrán que recordar y reproducir con el fin de iniciar sesión.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Cuando se dibuja un círculo o una línea en la imagen seleccionada, Windows recuerda cómo lo hizo", &lt;/span&gt;explicó el desarrollador Steven Sinofsky. &lt;span style="font-style: italic;"&gt;"Por lo tanto, alguien que trata de reproducir la contraseña en la imagen debe no sólo conocer las partes de la imagen que puso y el orden en que lo hizo, sino también la dirección y los puntos inicial y final de los círculos y las líneas que ha dibujado".&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Además, Sinofsky señala que la contraseña en imágenes se presenta como un mecanismo de inicio de sesión adicional a la contraseña de texto, no como un sustituto de la misma, y que su uso será opcional.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Además de la cantidad de combinaciones únicas, hemos aumentado la seguridad de la función mediante la introducción de dos salvaguardias contra los ataques de fuerza bruta"&lt;/span&gt;, explicó. &lt;span style="font-style: italic;"&gt;"Es similar a la función de bloqueo de los teléfonos con PIN, cuando se introduce la clave de imagen incorrecta 5 veces, se le impide el uso de la función de nuevo hasta que inicie sesión con su contraseña en texto plano. Además, la contraseña de imagen se desactiva en escenarios remotos para prevenir ataques en red contra esta característica".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Por último y para los que estais pensando que quizás la contraseña se pueda adivinar mediante el examen de las manchas dejadas por los dedos de los usuarios en la pantalla táctil, Microsoft dice que, &lt;span style="font-style: italic;"&gt;"debido al orden de los gestos, su dirección y ubicación, la posibilidad de adivinar el gesto correcto es muy difícil incluso en una pantalla completamente limpia, y mucho menos en una pantalla que se utilice con un contacto regular".&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Fuente: &lt;a href="http://www.net-security.org/secworld.php?id=12121"&gt;Help Net Security&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-7742214900873529598?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/7742214900873529598/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=7742214900873529598' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7742214900873529598'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7742214900873529598'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/windows-8-incluira-contrasenas-mediante.html' title='Windows 8 incluirá contraseñas mediante gestos en imágenes'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-vQHFENxVxN4/Tu_P-RbOmqI/AAAAAAAACd4/_Qk4mZbvyq0/s72-c/win8-picture-pass.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4774585753519121782</id><published>2011-12-16T14:00:00.004+01:00</published><updated>2011-12-16T14:28:19.546+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='recursos'/><category scheme='http://www.blogger.com/atom/ns#' term='eventos'/><title type='text'>Disponible material de la Ruxcon</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-xaupKyibecY/TutB8ah2jdI/AAAAAAAACPs/EUcCFmZn5yE/s1600/ruxcondesignfinal.gif"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 112px; height: 114px;" src="http://1.bp.blogspot.com/-xaupKyibecY/TutB8ah2jdI/AAAAAAAACPs/EUcCFmZn5yE/s200/ruxcondesignfinal.gif" alt="" id="BLOGGER_PHOTO_ID_5686711460654648786" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Hoy (por fin) viernes os dejamos unas interesantes lecturas para el fin de semana. Se trata del material de la conferencia &lt;a href="http://www.ruxcon.org.au/"&gt;Ruxcon&lt;/a&gt; que tuvo lugar el pasado 19 y 20 de noviembre en Melvourne, Australia.&lt;br /&gt;&lt;/span&gt;&lt;h4  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Saturday and Sunday Presentations&lt;/span&gt;&lt;/h4&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;div id="tocTable"  style="font-family:verdana;"&gt; &lt;table class="roundTable" border="0"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;Title&lt;/span&gt;&lt;/th&gt; &lt;th style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;Presenter&lt;/span&gt;&lt;/th&gt; &lt;th style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;Files&lt;/span&gt;&lt;/th&gt; &lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/2011-data-breach-investigations-report"&gt;2011 Data Breach Investigations Report - Verizon, US Secret Service, Dutch High Tech Crime Unit&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Mark Goudie&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/20111107%20DBIR_Goudie.ppt"&gt;.ppt&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/an-embarrassingly-simple-solution-to-the-problem-of-protecting-browser-users"&gt;An Embarrassingly Simple Solution to the Problem of Protecting Browser Users &lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Peter Gutmann&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/prot_browser_users.ppt"&gt;.ppt&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/apco-p25-security-revisited-the-practical-attacks"&gt;APCO P25 Security Revisited - The Practical Attacks! &lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Steve Glass and Matt Robert&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Insecurity_in_APCO25.pdf"&gt;.pdf (paper)&lt;/a&gt; &lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/RUXCON_2011_slides.pdf"&gt;.pdf (slides)&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/automated-detection-of-software-bugs-and-vulnerabilities-in-linux"&gt;Automated Detection of Software Bugs and Vulnerabilities in Linux&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Silvio Cesare&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Automated%20Detection%20of%20Software%20Bugs%20and%20Vulnerabilities%20in%20Linux.pptx"&gt;.pptx&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/digital-forensic-evidence-from-certainty-to-shades-of-grey"&gt;Digital Forensic Evidence: From Certainty to Shades of Grey&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Dr. Bradley Schatz&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Ruxcon-Shaded%20of%20Grey-PUBLIC.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/encyclopaedia-of-windows-privilege-escalation"&gt;Encyclopaedia Of Windows Privilege Escalation&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Brett Moore&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Ruxcon2011.rar"&gt;.rar&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/forensic-timeline-splunking"&gt;Forensic Timeline Splunking&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Nick Klein&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Forensic%20Timeline%20Splunking%20%5BNick%20Klein%20Ruxcon%202011%5D.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/gcc-plugins-die-by-the-sword"&gt;GCC Plugins: Die by the Sword&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Matt Davis&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/ruxcon2011.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/harder-better-faster-stronger"&gt;Harder, Better, Faster, Stronger... &lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Louis Nyffenegger &amp;amp; Luke Jahnke&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/LNLJ-Harder_Better_Faster_Stronger_V1.0.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/malware-mythbusters"&gt;Malware Mythbusters&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Alex Kirk&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/MalwareMythbusting.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/operation-carpo-the-hack-of-an-australian-registrar"&gt;Operation Carpo, The Hack of an Australian Registrar&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Alex Tilley&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/post-memory-corruption-memory-analysis"&gt;Post Memory Corruption Memory Analysis&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Jonathon Brossard&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/ruxcon.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/unusual-and-hilarious-vulnerabilities"&gt;Unusual and Hilarious Vulnerabilities&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;R00t Dude&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/hacking-hollywood"&gt;Hacking Hollywood&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Nick Freeman / vt&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Hacking-Hollywood_Nick-Freeman_Ruxcon2011.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/all-your-rfz-belong-to-me-hacking-the-wireless-world-with-gnu-radio"&gt;All your RFz Belong to Me: Hacking the Wireless World with GNU Radio &lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Balint Seeber&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/BSeeber_Ruxcon2011_HackingTheWirelessWorldWithSDR.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/windows-kernel-vulnerability-research-and-exploitation"&gt;Windows Kernel Vulnerability Research and Exploitation&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Gilad Bakas&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Kernel%20Exploits.ppt"&gt;.ppt&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/4-years-and-4-thousand-websites-worth-of-vulnerability-assessments-what-have-we-learned"&gt;4 Years and 4 Thousand Websites Worth of Vulnerability Assessments: What Have We Learned? &lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Jeremiah Grossman&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Ruxcon%202011.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/jboss-security-penetration-protection-and-patching"&gt;JBoss security: penetration, protection and patching&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;David Jorm&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/ruxcon-2011.odp"&gt;.odp&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;Hacking iPhones and iPads&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Ilja Van Sprundel&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/iPhone%20and%20iPad%20Hacking%20-%20van%20Sprundel.ppt"&gt;.ppt&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/browser-gfx-security"&gt;Browser GFX Security&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Ben Hawkes&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/BrowserGFXSecurity.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/ssl-traffic-analysis-attacks"&gt;SSL Traffic Analysis Attacks&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Vincent Berg&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/ssl_ta_v2.pptx"&gt;.pptx&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/mobile-and-contactless-payment-security"&gt;Mobile and Contactless Payment Security (There’s an App for that!)&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Peter Fillmore&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Peter_Fillmore_Ruxcon_Presentation2011.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/the-security-of-3d-web-extensions"&gt;The Security Of 3D Web Extensions&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;James Forshaw&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Security_of_3D_Web_Browser_Extensions.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/bypassing-and-strengthening-linux-security-controls"&gt;Bypassing and Strengthening Linux Security Controls&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Andrew Griffiths&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Ruxcon_2011_Linux_Security.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;a name="bonus"&gt; &lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;h4  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Bonus Presentations (Friday 18th Professional Delegates Only)&lt;/span&gt;&lt;/h4&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;div id="tocTable"  style="font-family:verdana;"&gt; &lt;table class="roundTable" border="0"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;Title&lt;/span&gt;&lt;/th&gt; &lt;th style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;Presenter&lt;/span&gt;&lt;/th&gt; &lt;th style="text-align: center;"&gt;&lt;span style="font-size:85%;"&gt;Files&lt;/span&gt;&lt;/th&gt; &lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/open-source-intelligence-is-not-just-facebook"&gt;Open Source Intelligence is not just Facebook&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Kayne&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/defiling-macosx"&gt;Defiling MacOSX&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Snare&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Defiling-Mac-OS-X-Ruxcon.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/analysis-avoidance-techniques-of-malicious-software"&gt;Analysis Avoidance Techniques of Malicious Software&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Murray Brand&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Murray%20Brand%20Ruxcon%202011%20Presentation.ppt"&gt;.ppt&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/a-hackers-guide-to-internet-marketing"&gt;A Hackers Guide to Internet Marketing &lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Mark Blaszczyk&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/hackers%20guide%20to%20internet%20marketing%20-%20final%20-%20ruxcon%202011.pptx"&gt;.pptx&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/issues-of-teaching-ethical-hacking-at-the-university-level"&gt;Issues of Teaching Ethical Hacking at the University Level&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Peter Hannay&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Ruxcon2011-Issues_Teaching_Hacking.ppt"&gt;.ppt&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/faster-more-effective-flowgraph-based-malware-classification"&gt;Faster, More Effective Flowgraph-based Malware Classification&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Silvio Cesare&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/Faster,%20More%20Effect%20Flowgraph-based%20Malware%20Classification.pptx"&gt;.pptx&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="oddlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/an-introduction-to-software-defined-radio"&gt;An Introduction to Software Defined Radio&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Balint Seeber&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/assets/Presentations/2011-2/BSeeber_Ruxcon2011_AnIntroductionToSDR.pdf"&gt;.pdf&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr class="evenlnk"&gt;&lt;td&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.ruxcon.org.au/2011-talks/femtocell-security-and-threats-on-telecommunication-infrastructure"&gt;Femtocell Security and Threats on Telecommunication Infrastructure&lt;/a&gt;&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt;Ravi Borgaonk&lt;/span&gt;&lt;/td&gt; &lt;td&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt; &lt;/span&gt;&lt;/p&gt; &lt;h3&gt;&lt;span style="font-size:85%;"&gt;Capture the flag&lt;/span&gt;&lt;/h3&gt; &lt;p&gt;&lt;span style="font-size:85%;"&gt;A write-up about the CTF (so far Unix, Misc, Web levels) is available &lt;a href="http://www.ruxcon.org.au/archive/2011-ctf-writeup"&gt;here&lt;/a&gt;.&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-4774585753519121782?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/4774585753519121782/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=4774585753519121782' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4774585753519121782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4774585753519121782'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/disponible-material-de-la-ruxcon.html' title='Disponible material de la Ruxcon'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-xaupKyibecY/TutB8ah2jdI/AAAAAAAACPs/EUcCFmZn5yE/s72-c/ruxcondesignfinal.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-2530008820636441685</id><published>2011-12-14T10:23:00.008+01:00</published><updated>2011-12-14T11:28:49.564+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ingeniería inversa'/><category scheme='http://www.blogger.com/atom/ns#' term='retos'/><category scheme='http://www.blogger.com/atom/ns#' term='android'/><title type='text'>Reto 14: Android crackme#2</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-AzV543AClVw/Tuhrw-JhVkI/AAAAAAAACPU/FIXB5Ogz5kM/s1600/crackme2hpys.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 258px; height: 381px;" src="http://3.bp.blogspot.com/-AzV543AClVw/Tuhrw-JhVkI/AAAAAAAACPU/FIXB5Ogz5kM/s1600/crackme2hpys.png" alt="" id="BLOGGER_PHOTO_ID_5685913018616075842" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;El siguiente reto es nuestro segundo crackme en Android. En esta ocasión se trata de una simple aplicación que utiliza &lt;span style="font-style: italic;"&gt;Android License Verification Library (ALVL) &lt;/span&gt;para determinar si existe la licencia para el usuario y el terminal específicos a través de una consulta al servidor de licenciamiento del AndroidMarket.&lt;br /&gt;&lt;br /&gt;El objetivo es parchear la aplicación para que evada este mecanismo. El paquete apk podéis descargarlo desde &lt;a href="https://sites.google.com/site/h4ckpl4y3s/crackme2hpys.apk?attredirects=0&amp;amp;d=1"&gt;aquí&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Si lo conseguís, mandarnos el apk parcheado y el procedimiento seguido a nuestra cuenta de correo:&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.blogger.com/goog_823006131"&gt;&lt;img src="http://2.bp.blogspot.com/_BUD45TwOpHY/TOZqck_1BtI/AAAAAAAABAU/PdDTwGq4lZQ/s1600/contacto_correo.jpg" style="margin-left: auto; margin-right: auto; width: 261px; height: 18px;" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;¡Ánimo a todos, el reto es sumamente sencillo!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:85%;"  &gt;&lt;a href="http://www.blogger.com/goog_823006131"&gt;&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-2530008820636441685?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/2530008820636441685/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=2530008820636441685' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/2530008820636441685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/2530008820636441685'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/reto-14-android-crackme2.html' title='Reto 14: Android crackme#2'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-AzV543AClVw/Tuhrw-JhVkI/AAAAAAAACPU/FIXB5Ogz5kM/s72-c/crackme2hpys.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5349991023737603258</id><published>2011-12-13T15:11:00.014+01:00</published><updated>2011-12-23T11:51:00.507+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><category scheme='http://www.blogger.com/atom/ns#' term='esteganografía'/><title type='text'>Recopilatorio de herramientas de esteganografía y estegoanálisis</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-xNVdLYvO0u8/TudemAbPqeI/AAAAAAAACPI/Kja2qZsb8rg/s1600/Steganography.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 200px; height: 134px;" src="http://1.bp.blogspot.com/-xNVdLYvO0u8/TudemAbPqeI/AAAAAAAACPI/Kja2qZsb8rg/s200/Steganography.jpg" alt="" id="BLOGGER_PHOTO_ID_5685617061620853218" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Gracias a un &lt;a href="http://www.pedramhayati.com/images/docs/survey_of_steganography_and_steganalytic_tools.pdf" target="_blank"&gt;paper de Pedram Hayati&lt;/a&gt; podemos recopilar hasta un total de 111 herramientas de esteganografía y estegoanálisis clasificadas por categorías. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div  style="font-family: verdana;font-family:Verdana,sans-serif;"&gt;&lt;span style="font-size:85%;"&gt;Según su autor, el estudio se realizó desde un perspectiva forense para identificar qué herramientas están disponibles en Internet y cuáles de ellas podrían ser utilizadas por organizaciones terroristas. Sea como fuere, es un excelente recurso para tener siempre a mano un listado de estas herramientas: &lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div  style="font-family:Verdana,sans-serif;"&gt;&lt;span style="font-size:small;"&gt;&lt;b&gt;Herramientas de esteganografía en &lt;span style="font-size:large;"&gt;imágenes con código fuente&lt;/span&gt; disponible&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;table style="width: 589px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;&lt;td class="xl66" style="height: 15pt; text-align: right; width: 105pt;" width="140" height="20"&gt;&lt;b&gt;Steganographic&lt;br /&gt;Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;JPEG&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;BMP&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Others&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; text-align: center; width: 97pt;" width="129"&gt;&lt;b&gt;Embedding&lt;br /&gt;Aproach&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Production&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Blindside&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Camera Shy&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;dc-Steganograph&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PCX&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;F5&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;GIF&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 30pt; text-align: right;" height="40"&gt;&lt;b&gt;Gif Shuffle&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;GIF&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; border-top: medium none; text-align: center; width: 97pt;" width="129"&gt;Change&lt;br /&gt;the order of the color map&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hide4PGP&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;JP Hide and&lt;br /&gt;Seek&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Jsteg Jpeg&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Mandelsteg&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;GIF&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;OutGuess&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PNG&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;PGM Stealth&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PGM&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steghide&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;wbStego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;WnStorm&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PCX&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr height="20"&gt;&lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;a href="http://www.securitybydefault.com/2010/12/synde-burlar-la-censura-de-tu-gobierno.html"&gt;&lt;b&gt;SYND(E)&lt;/b&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;br /&gt;&lt;/td&gt;&lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;SDS&lt;br /&gt;&lt;/td&gt;&lt;td class="xl67" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size:85%;"&gt;TDS - Transform Domain Steganography&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size:85%;"&gt;SDS - Spatial Domain Steganography (LSB Replacement and LSB Matching)&lt;/span&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;div  style="font-family:Verdana,sans-serif;"&gt;&lt;b&gt;&lt;span style="font-size:small;"&gt;Herramientas de esteganografía en &lt;span style="font-size:large;"&gt;imágenes sin código fuente&lt;/span&gt; disponible&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;table style="width: 612px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;&lt;td class="xl70" style="height: 15pt; text-align: right; width: 96pt;" width="128" height="20"&gt;&lt;b&gt;Image&lt;br /&gt;Steganographic Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 43pt;" width="57"&gt;&lt;b&gt;BMP&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 43pt;" width="57"&gt;&lt;b&gt;JPEG&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 43pt;" width="57"&gt;&lt;b&gt;GIF&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 43pt;" width="57"&gt;&lt;b&gt;PNG&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 43pt;" width="57"&gt;&lt;b&gt;TGA&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 43pt;" width="57"&gt;&lt;b&gt;Other&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 53pt;" width="71"&gt;&lt;b&gt;Production&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; text-align: center; width: 53pt;" width="71"&gt;&lt;b&gt;License&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Crypto123&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hermetic Stego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;IBM DLS&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Invisible&lt;br /&gt;Secrets&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Info Stego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl69" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Syscop&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;StegMark&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TIF&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Cloak&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;S&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Contraband&lt;br /&gt;Hell&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Contraband&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Dound&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Gif it Up&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Camouflage&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hide and Seek&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;InThePicture&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;S-Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Jpegx&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steganos&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;DIB&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;F&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;BMP Secrets&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;DCT-Steg&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Digital&lt;br /&gt;Picture Envelope&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;EikonAmark&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Empty Pic&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Encrypt Pic&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;EzStego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;BMP Embed&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;BMPTable&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;StegoTif&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TIF&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hide Unhide&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TIF&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;In Plain View&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Invisible&lt;br /&gt;Encryption&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;JK-PGS&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PPM&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Scytale&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PCX&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;appendX&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size:85%;"&gt;S – Shareware License&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: right;"&gt;&lt;span style="font-size:85%;"&gt;F – Freeware License&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size:small;"&gt;&lt;b&gt;Herramientas de esteganografía en &lt;span style="font-size:large;"&gt;audio&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;table style="width: 580px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;colgroup&gt;&lt;col style="mso-width-alt: 6582; mso-width-source: userset; width: 135pt;" width="180"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="width: 60pt;" span="5" width="80"&gt;&lt;/colgroup&gt; &lt;tbody&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="height: 15pt; text-align: right; width: 135pt;" width="180" height="20"&gt;&lt;b&gt;Audio&lt;br /&gt;Steganographic Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;MP3&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;WAV&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Others&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Production&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;License&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Info Stego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;ScramDisk&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;MP3Stego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;StegoWav&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hide4PGP&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;VOC&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steghide&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;AU&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;S-Tool&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Invisible&lt;br /&gt;Secrets&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Commercial&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Paranoid&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Commercial&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steganos&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;VOC&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Commercial&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-size:small;"&gt;&lt;b&gt;Herramientas de esteganografía en &lt;span style="font-size:large;"&gt;texto&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;table style="width: 536px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;tbody&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;&lt;td class="xl65" style="height: 15pt; text-align: right; width: 102pt;" width="136" height="20"&gt;&lt;b&gt;Text&lt;br /&gt;Steganographic Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Plain Text&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Other&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Source Code&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;License&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Production&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;PGPn123&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Nicetext&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Snow&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Texto&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Sam's Big Play&lt;br /&gt;Maker&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steganosaurus&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;FFEncode&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Mimic&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;wbStego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;HTML. PDF&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Spam Mimic&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Not Specified&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Secret Space&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Not Specified&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;WitnesSoft&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No longer in&lt;br /&gt;production&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;MergeStreams&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Hides excel file in&lt;br /&gt;word&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Freeware&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steganos&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;HTML&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Commercial&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Invisible&lt;br /&gt;Secrets&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;HTML&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Commercial&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr height="20"&gt;&lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;a href="http://sourceforge.net/projects/stelin/"&gt;&lt;b&gt;Stelin&lt;/b&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;GNU&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;&lt;/tr&gt;&lt;tr height="20"&gt;&lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right; font-weight: bold;" height="20"&gt;&lt;a href="http://stegosense.sourceforge.net/"&gt;StegoSense&lt;/a&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;GNU&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr height="20"&gt;&lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;a href="http://www.securitybydefault.com/2008/12/como-cruzar-la-frontera-de-arabia-saudi.html"&gt;&lt;b&gt;Fuse&lt;/b&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;PDF&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Freeware&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr height="20"&gt;&lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right; font-weight: bold;" height="20"&gt;&lt;a href="https://github.com/hecky/stegb64/"&gt;StegB64.py&lt;/a&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;bin&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Freeware&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr height="20"&gt;&lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right; font-weight: bold;" height="20"&gt;&lt;a href="http://neobits.org/tools/horrografia.php"&gt;Horrografia&lt;/a&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Freeware&lt;/td&gt;&lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;b  style="font-family:Verdana,sans-serif;"&gt;Herramientas de esteganografía para &lt;span style="font-size:large;"&gt;sistemas de ficheros y discos duros&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;table style="width: 483px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;colgroup&gt;&lt;col style="mso-width-alt: 4534; mso-width-source: userset; width: 93pt;" width="124"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="mso-width-alt: 4352; mso-width-source: userset; width: 89pt;" width="119"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="width: 60pt;" span="3" width="80"&gt;&lt;/colgroup&gt; &lt;tbody&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl67" style="height: 45pt; text-align: right; width: 93pt;" width="124" height="60"&gt;&lt;b&gt;File&lt;br /&gt;System Steganographic Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl67" style="border-left: medium none; text-align: center; width: 89pt;" width="119"&gt;&lt;b&gt;Location of&lt;br /&gt;Embedding&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Source Code&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;License&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Production&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Disk Hide&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Windows Registry&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Drive Hider&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Windows Registry&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl67" style="border-top: medium none; height: 30pt; text-align: right; width: 93pt;" width="124" height="40"&gt;&lt;b&gt;Easy File &amp;amp; Folder Protector&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;VXD driver, Windows&lt;br /&gt;Kernel&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Invisible&lt;br /&gt;Files 2000&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Hard Disk&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Magic Foders&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Dark Files&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;bProtected&lt;br /&gt;2000&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;BuryBury&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;StegFS&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Folder Guard&lt;br /&gt;Jr&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Freeware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Dmagic&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Freeware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;BackYard&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;File System&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Snowdisk&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Disk Space&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 45pt; text-align: right;" height="60"&gt;&lt;b&gt;Masker&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl68" style="border-left: medium none; border-top: medium none; text-align: center; width: 89pt;" width="119"&gt;Any&lt;br /&gt;file (Image, Text, Audio, Video)&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Anahtar&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;3.5-inch diskette&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hide Folders&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hidden&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Paranoid&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Diskhide&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl66" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;No&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;b  style="font-family:Verdana,sans-serif;"&gt;&lt;span style="font-size:large;"&gt;Otras &lt;/span&gt;herramientas de esteganografía&lt;/b&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;table style="width: 417px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;colgroup&gt;&lt;col style="mso-width-alt: 4169; mso-width-source: userset; width: 86pt;" width="114"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="mso-width-alt: 5229; mso-width-source: userset; width: 107pt;" width="143"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="width: 60pt;" span="2" width="80"&gt;&lt;/colgroup&gt; &lt;tbody&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl66" style="height: 45pt; text-align: right; width: 86pt;" width="114" height="60"&gt;&lt;b&gt;Miscellaneous&lt;br /&gt;Steganographic Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 107pt;" width="143"&gt;&lt;b&gt;Cover Media&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Source Code&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;License&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;GZSteg&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;.gz files&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;InfoStego&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Image, audio, video&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;KPK File&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Word, BMP&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;S-Mail&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;.exe and .dll files&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hiderman&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Many different media&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Shareware&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;StegMark&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Image, audio, video&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Steghide&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;JPEG, BMP, WAV, AU&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;S-Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;BMP, GIF, WAV&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Not sure&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Hydan&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Program Binaries&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 15.0pt;" height="20"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 15pt; text-align: right;" height="20"&gt;&lt;b&gt;Covert.tcp&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;TCP/IP Packets&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Yes&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center;"&gt;Open Source&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style=" ;font-family:Verdana,sans-serif;font-size:small;"  &gt;&lt;b&gt;Herramientas de &lt;span style="font-size:large;"&gt;estegoanálisis&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;table style="width: 539px;" border="1" cellpadding="0" cellspacing="0"&gt;&lt;colgroup&gt;&lt;col style="mso-width-alt: 4717; mso-width-source: userset; width: 97pt;" width="129"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="mso-width-alt: 6217; mso-width-source: userset; width: 128pt;" width="170"&gt;&lt;/colgroup&gt; &lt;colgroup&gt;&lt;col style="width: 60pt;" span="3" width="80"&gt;&lt;/colgroup&gt; &lt;tbody&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl65" style="height: 45pt; text-align: right; width: 97pt;" width="129" height="60"&gt;&lt;b&gt;Hard Disk&lt;br /&gt;Steganographic Tools&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 128pt;" width="170"&gt;&lt;b&gt;Tools Analyzed&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Detection&lt;br /&gt;Approach&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Extraction&lt;br /&gt;Approach&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;b&gt;Destruction&lt;br /&gt;Approach&lt;/b&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 30pt; text-align: right; width: 97pt;" width="129" height="40"&gt;&lt;b&gt;2Mosaic&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Removes&lt;br /&gt;stego content from any images&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Break&lt;br /&gt;Apart&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 30pt; text-align: right; width: 97pt;" width="129" height="40"&gt;&lt;b&gt;StirMark Benchmark&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Removes&lt;br /&gt;stego content from any images&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Resample&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 30pt; text-align: right; width: 97pt;" width="129" height="40"&gt;&lt;b&gt;Phototile&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Removes&lt;br /&gt;stego content from any images&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Break&lt;br /&gt;Apart&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 45pt; text-align: right; width: 97pt;" width="129" height="60"&gt;&lt;b&gt;Steganography Analyzer Real-Time Scanner&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Analyzes&lt;br /&gt;Network Packets&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Signature&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 30pt; text-align: right; width: 97pt;" width="129" height="40"&gt;&lt;b&gt;StegBreak&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Jsteg-shell,&lt;br /&gt;JPhide, and Outguess 0.13b&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Dictionary&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 45pt; text-align: right; width: 97pt;" width="129" height="60"&gt;&lt;b&gt;StegDetect&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Jsteg,&lt;br /&gt;JPhide, Invisible Secrets, Outguess 01.3b, F5, appendX, Camouflage&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Statistical&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 45.0pt;" height="60"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 45pt; text-align: right; width: 97pt;" width="129" height="60"&gt;&lt;b&gt;StegSpy&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Hiderman,&lt;br /&gt;JPHIde and Seek, Masker, JPegX, Invisible Secrets&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;tr style="height: 30.0pt;" height="40"&gt;  &lt;td class="xl65" style="border-top: medium none; height: 30pt; text-align: right; width: 97pt;" width="129" height="40"&gt;&lt;b&gt;Stego-Suite&lt;/b&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 128pt;" width="170"&gt;Detects&lt;br /&gt;Stego Image and Audio file&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;Dictionary&lt;/td&gt;  &lt;td class="xl65" style="border-left: medium none; border-top: medium none; text-align: center; width: 60pt;" width="80"&gt;&lt;br /&gt;&lt;/td&gt; &lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5349991023737603258?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5349991023737603258/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5349991023737603258' title='8 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5349991023737603258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5349991023737603258'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/recopilatorio-de-herramientas-de.html' title='Recopilatorio de herramientas de esteganografía y estegoanálisis'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-xNVdLYvO0u8/TudemAbPqeI/AAAAAAAACPI/Kja2qZsb8rg/s72-c/Steganography.jpg' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-92038783814566846</id><published>2011-12-11T12:19:00.005+01:00</published><updated>2011-12-11T12:28:15.603+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='forense'/><category scheme='http://www.blogger.com/atom/ns#' term='retos'/><title type='text'>Resultados del I Reto Forense Digital Sudamericano de ISSA Perú</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/-OeeccOj0aMo/TuSSoz5UNpI/AAAAAAAACNw/aiYeLwqeAiI/s1600/reto_issa_peru.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 298px; height: 231px;" src="http://2.bp.blogspot.com/-OeeccOj0aMo/TuSSoz5UNpI/AAAAAAAACNw/aiYeLwqeAiI/s320/reto_issa_peru.png" alt="" id="BLOGGER_PHOTO_ID_5684829859471439506" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Ya se han publicado los resultados del&lt;span style="font-weight: bold;"&gt; I Reto Forense Digital Sudamericano – Perú Chavín de Huantar&lt;/span&gt;: &lt;a href="http://issaperu.org/?p=538"&gt;http://issaperu.org/?p=538&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-OeeccOj0aMo/TuSSoz5UNpI/AAAAAAAACNw/aiYeLwqeAiI/s1600/reto_issa_peru.png"&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Nuestra más sincera enhorabuena a los ganadores Henry Sánchez (aka g05u) y Daniel Correa (&lt;a href="http://www.sinfocol.org/"&gt;sinfocol.org&lt;/a&gt;). Los dos tienen una amplia experiencia en wargames e incluso ya conocía a Daniel por participar y ganar algunos de nuestros retos. Ambos presentaron unos informes excelentes que podéis descargar junto con los de los segundos y terceros clasificados:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;h2  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Primer Puesto    : Henry Sánchez – Daniel Correa – Perú / Colombia&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Informe Ejecutivo: &lt;a href="http://www.mediafire.com/?lvbu9bagr0uczso"&gt;http://www.mediafire.com/?lvbu9bagr0uczso&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Informe Técnico: &lt;a href="http://www.mediafire.com/?bev78robcbu8u21"&gt;http://www.mediafire.com/?bev78robcbu8u21&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;h2  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Segundo Puesto : Raúl A. Iriberri – Argentina&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Informe Ejecutivo: &lt;a href="http://www.mediafire.com/?fjl32pybshq6qbo"&gt;http://www.mediafire.com/?fjl32pybshq6qbo&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Informe Técnico: &lt;a href="http://www.mediafire.com/?i1d3ghk6d4wc57m"&gt;http://www.mediafire.com/?i1d3ghk6d4wc57m&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;h2  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Tercer Puesto     :  Gabriel Lazo Canazas – Roberto Contreras Diestra – Carlos Luis Vidal – Michael Ocrospoma Heraud – Perú&lt;/span&gt;&lt;/h2&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Informe Ejecutivo: &lt;a href="http://www.mediafire.com/?ewc7yac8pcycuuc"&gt;http://www.mediafire.com/?ewc7yac8pcycuuc&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; &lt;/span&gt;&lt;p  style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;Informe Técnico: &lt;a href="http://www.mediafire.com/?cpk02r3lcrqyiin"&gt;http://www.mediafire.com/?cpk02r3lcrqyiin&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;Como miembro del jurado quiero felicitar también al resto de participantes, que han hecho unos trabajos impresionantes y nos han puesto tan difícil la elección. Tengo que decir que todos los informes presentados podrían exponerse como ejemplos educativos para la realización de un informe forense.&lt;br /&gt;&lt;br /&gt;Por último, quería agradecer a Roberto Puyo Valladares y al resto de organizadores del reto la oportunidad de partipación facilitada. Ha sido un verdadero placer colaborar con ustedes.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-92038783814566846?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/92038783814566846/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=92038783814566846' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/92038783814566846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/92038783814566846'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/resultados-del-i-reto-forense-digital.html' title='Resultados del I Reto Forense Digital Sudamericano de ISSA Perú'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-OeeccOj0aMo/TuSSoz5UNpI/AAAAAAAACNw/aiYeLwqeAiI/s72-c/reto_issa_peru.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4767888414069791088</id><published>2011-12-09T23:37:00.004+01:00</published><updated>2011-12-09T23:45:35.876+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='noticias'/><title type='text'>Google+ incorpora reconocimiento facial en las fotos</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-LwCUAyl48sQ/TuKOmB9SlKI/AAAAAAAACNk/BB09tb1AuDk/s1600/FMF%2B2.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 306px;" src="http://3.bp.blogspot.com/-LwCUAyl48sQ/TuKOmB9SlKI/AAAAAAAACNk/BB09tb1AuDk/s320/FMF%2B2.png" alt="" id="BLOGGER_PHOTO_ID_5684262463706666146" border="0" /&gt;&lt;/a&gt;EUROPA PRESS. &lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;Google+&lt;/span&gt; ha comenzado a ofrecer la nueva aplicación &lt;span style="font-weight: bold;"&gt;'Find my face'&lt;/span&gt;, capaz de reconocer caras en las fotos subidas a la red social, lo que facilita el &lt;span style="font-weight: bold;"&gt;etiquetado de fotos&lt;/span&gt;. &lt;span style="font-style: italic;"&gt;La opción aparecerá en la página de forma progresiva en diferentes países.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Es una aplicación fácil de utilizar, pensada para facilitar el etiquetado de fotografías. Cada usuario debe autorizar de forma explícita y personal el reconocimiento de su rostro en las fotografías. De esta forma, cuando uno de nuestros amigos suba una fotografía a Google+, el sistema le sugerirá que nos etiquete.&lt;br /&gt;&lt;br /&gt;Este tipo de tecnologías suele despertar conflictos de privacidad, por los que Google ha prestado especial cuidado en la aceptación y autorización del servicio y la transparencia de su uso.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;De momento, Google+ presentará un cuadro de diálogo de consentimiento explícito a los usuarios cada vez que el usuario visite cualquier foto en Google+. Para evitar problemas, en los próximos meses aparecerá un recordatorio para aquello usuarios que no hayan elegido dicha opción la puedan seleccionar , así como desactivarla.&lt;br /&gt;&lt;br /&gt;No deja de ser curioso cómo Google está adoptando poco a poco el reconocimiento facial en sus productos, teniendo en cuenta la opinión de Eric Schmidt al respecto. Cuando ostentaba el cargo de consejero delegado, el directivo dijo que consideraba que el reconocimiento facial era "escalofriante".&lt;br /&gt;&lt;br /&gt;El sistema de Google+ debe almacenar los rostros de los usuarios que accedan a usar 'Find my face' para encontrarlas en las fotos de otros.&lt;br /&gt;&lt;br /&gt;Fuente: &lt;a href="http://www.20minutos.es/noticia/1245089/0/google/reconocimiento/facial/"&gt;20 minutos&lt;/a&gt;&lt;br /&gt;Aviso: &lt;a href="https://plus.google.com/110260043240685719403/posts/jKQ35ajJ4EU"&gt;Matt Steiner - Making photo tagging easier with Find My Face&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-4767888414069791088?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/4767888414069791088/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=4767888414069791088' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4767888414069791088'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4767888414069791088'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/google-incorpora-reconocimiento-facial.html' title='Google+ incorpora reconocimiento facial en las fotos'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-LwCUAyl48sQ/TuKOmB9SlKI/AAAAAAAACNk/BB09tb1AuDk/s72-c/FMF%2B2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-615263461973674034</id><published>2011-12-05T16:07:00.006+01:00</published><updated>2011-12-05T16:14:14.599+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><category scheme='http://www.blogger.com/atom/ns#' term='hacktivismo'/><title type='text'>OccupyOS: el SO diseñado para activistas</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-NJgxKXLrdZA/TtzedkKPs5I/AAAAAAAACNY/5Qy0tQcvlLI/s1600/occupyOS.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 208px;" src="http://4.bp.blogspot.com/-NJgxKXLrdZA/TtzedkKPs5I/AAAAAAAACNY/5Qy0tQcvlLI/s320/occupyOS.png" alt="" id="BLOGGER_PHOTO_ID_5682661429338944402" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;OccupyOS es una distribución de Linux basada en Gentoo e inspirada en el movimiento &lt;span style="font-style: italic;"&gt;Occupy Wall Street&lt;/span&gt;, orientada a activistas y diseñada para proveer un entorno seguro para editar y publicar documentos, navegar por la web (administrar sitios, Twitter y páginas de Facebook) y establecer comunicaciones seguras entre el usuario y otros activistas e Internet.&lt;br /&gt;&lt;br /&gt;Todavía está en desarrollo y no se ha publicado un versión oficial estable, pero ya es posible descargar una interesante beta que incluye navegación anónima (Tor o VPNs), chat de voz y conferencia cifrados (Mumble), mensajería instantánea cifrada (Pidgin-OTR y Xchat-OTR), edición de imágenes (Gimp) y herramientas para el borrado seguro del disco.&lt;br /&gt;&lt;br /&gt;Web del proyecto: &lt;a href="http://wiki.gitbrew.org/wikibrew/OccupyOS"&gt;http://wiki.gitbrew.org/wikibrew/OccupyOS&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-615263461973674034?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/615263461973674034/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=615263461973674034' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/615263461973674034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/615263461973674034'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/occupyos-el-so-disenado-para-activistas.html' title='OccupyOS: el SO diseñado para activistas'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-NJgxKXLrdZA/TtzedkKPs5I/AAAAAAAACNY/5Qy0tQcvlLI/s72-c/occupyOS.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5969402455089036991</id><published>2011-12-04T18:54:00.005+01:00</published><updated>2011-12-04T19:13:11.433+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cracking'/><category scheme='http://www.blogger.com/atom/ns#' term='retos'/><title type='text'>Solucionario al reto de la GCHQ CanYouCrackIt</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-RrJXAW1XtFE/Ttu0eiqTIMI/AAAAAAAACNM/-QOc0Wc9whA/s1600/canyoucrackit.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 112px;" src="http://3.bp.blogspot.com/-RrJXAW1XtFE/Ttu0eiqTIMI/AAAAAAAACNM/-QOc0Wc9whA/s200/canyoucrackit.jpg" alt="" id="BLOGGER_PHOTO_ID_5682333791651307714" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Si recordáis, la agencia británica de inteligencia &lt;span style="font-weight: bold;"&gt;GCHQ&lt;/span&gt; publicó y difundió en las redes sociales un reto disponible en &lt;a href="http://www.canyoucrackit.co.uk/"&gt;canyoucrackit.co.uk&lt;/a&gt; con el objetivo de captar nuevos talentos.&lt;br /&gt;&lt;br /&gt;Tras unos &lt;a href="http://100gf.wordpress.com/2011/12/03/gchqs-can-you-crack-it-test-solved-by-a-simple-google-search/"&gt;"problemillas" con las búsquedas de Google&lt;/a&gt; y un mes más tarde de su publicación, un estudiante de la Universidad de Greenwich ha &lt;a href="http://gchqchallenge.blogspot.com/"&gt;publicado &lt;/a&gt;varios vídeos explicando su solución.&lt;br /&gt;&lt;br /&gt;Como veréis el rompecabezas tiene tres etapas y no era para nada simple:&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;font-size:100%;" &gt;Fase 1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;iframe src="http://www.youtube.com/embed/ucrUFIrElKQ?feature=player_embedded" allowfullscreen="" frameborder="0" height="310" width="590"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;iframe src="http://www.youtube.com/embed/myq296Rcw9c?feature=player_embedded" allowfullscreen="" frameborder="0" height="310" width="590"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;Ficheros para descarga:&lt;br /&gt;&lt;a href="http://pastebin.com/bsHXs4PG"&gt;p1-complete.asm&lt;/a&gt; (imprime en pantalla los datos descifrados - no necesita debugger)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Fase 2&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;iframe src="http://www.youtube.com/embed/oV0QOGgu90k?feature=player_embedded" allowfullscreen="" frameborder="0" height="310" width="590"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;Ficheros para descarga:&lt;br /&gt;&lt;a href="http://pastebin.com/Uz8QBFkg"&gt;Python VM Implementation&lt;/a&gt; (por un autor anónimo)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;Fase 3&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;iframe src="http://www.youtube.com/embed/2Ete25C9KUw?feature=player_embedded" allowfullscreen="" frameborder="0" height="310" width="590"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;Ficheros para descarga:&lt;br /&gt;&lt;a href="http://pastebin.com/9XNGs7TB"&gt;C representation of executable&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5969402455089036991?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5969402455089036991/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5969402455089036991' title='5 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5969402455089036991'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5969402455089036991'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/solucionario-al-reto-de-la-gchq.html' title='Solucionario al reto de la GCHQ CanYouCrackIt'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-RrJXAW1XtFE/Ttu0eiqTIMI/AAAAAAAACNM/-QOc0Wc9whA/s72-c/canyoucrackit.jpg' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-7334742304537520761</id><published>2011-12-01T13:25:00.004+01:00</published><updated>2011-12-01T13:42:28.039+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><title type='text'>Exposición de claves del API de Google Translate</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;A partir de hoy 1 de diciembre y desafortunadamente, la &lt;span style="font-weight: bold;"&gt;versión 2 del API de Google Translate&lt;/span&gt; se ha convertido definitivamente en un &lt;span style="font-weight: bold;"&gt;servicio de pago&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-vZxDx4AHxZ0/Ttd1wXl4F4I/AAAAAAAACLw/ooFCqeQpuqc/s1600/google_traductor.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 320px; height: 95px;" src="http://3.bp.blogspot.com/-vZxDx4AHxZ0/Ttd1wXl4F4I/AAAAAAAACLw/ooFCqeQpuqc/s320/google_traductor.png" alt="" id="BLOGGER_PHOTO_ID_5681138928778221442" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Esto significa que si tienes una aplicación que automáticamente traduce textos de un lenguaje a otro mediante e&lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;l API de Google necesitarás obligatoriamente generar y utilizar una clave (&lt;span style="font-weight: bold;"&gt;API key&lt;/span&gt;) mediante una cuenta de Google y pagar según los &lt;a href="http://code.google.com/apis/language/translate/v2/pricing.html"&gt;precios y términos del servicio establecidos&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;El "problema" es que Google Translate usa normalmente JavaScript y el código es visible para todo el mundo simplemente viendo el código HTML de la página. Por ejemplo:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;var source = 'https://www.googleapis.com/language/translate/v2?key=&lt;span style="font-weight: bold;"&gt;INSERT-YOUR-KEY&lt;/span&gt;&amp;amp;source=en&amp;amp;target=de&amp;amp;callback=translateText&amp;amp;q=' + sourceText; newScript.src = source; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;El riesgo es evidente, la clave está expuesta a todos y cualquiera puede reutilizarla en otro sitio, con los consiguientes cargos para su dueño.&lt;br /&gt;&lt;br /&gt;La solución, comentada también por Google, es utilizar proxies inversos u otro código que llame a Google Translate desde el lado del servidor. Pero, ¿cuantos usuarios lo llevaran a cabo?, ¿&lt;a href="http://www.google.es/#q=translate/v2%3Fkey%3D"&gt;cuantas claves&lt;/a&gt; están expuestas?, ¿&lt;a href="http://pastebin.com/search?cx=partner-pub-4339714761096906%3A1qhz41g8k4m&amp;amp;cof=FORID%3A10&amp;amp;ie=UTF-8&amp;amp;q=translate%2Fv2%3F&amp;amp;sa.x=13&amp;amp;sa.y=14#1063"&gt;cuantas&lt;/a&gt;?...&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-7334742304537520761?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/7334742304537520761/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=7334742304537520761' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7334742304537520761'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7334742304537520761'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/12/exposicion-de-claves-de-api-de-google.html' title='Exposición de claves del API de Google Translate'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-vZxDx4AHxZ0/Ttd1wXl4F4I/AAAAAAAACLw/ooFCqeQpuqc/s72-c/google_traductor.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-451148871932025791</id><published>2011-11-29T16:39:00.004+01:00</published><updated>2011-11-29T16:43:54.668+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><category scheme='http://www.blogger.com/atom/ns#' term='hacktivismo'/><title type='text'>Anonymous y Team Poison se unen contra los bancos en la Operación Robin Hood</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-8SP5a4jq9GA/TtT9EByGTiI/AAAAAAAACLE/94EGcNCqG0U/s1600/poisanon.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 244px; height: 166px;" src="http://1.bp.blogspot.com/-8SP5a4jq9GA/TtT9EByGTiI/AAAAAAAACLE/94EGcNCqG0U/s320/poisanon.png" alt="" id="BLOGGER_PHOTO_ID_5680443275660906018" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;Anonymous y Team Poison&lt;/span&gt; se han unido bajo el nombre de &lt;span style="font-weight: bold;"&gt;p0isAnon&lt;/span&gt; y han declarado la guerra a las instituciones financieras que son una interferencia excesiva en las últimas protestas &lt;span style="font-weight: bold;"&gt;'Occupy'&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Robin Hood&lt;/span&gt; es el nombre de la nueva operación, en la que planean robar tarjetas de crédito y donarlas al movimiento &lt;span style="font-weight: bold;"&gt;"99 por ciento"&lt;/span&gt; y a organizaciones benéficas en todo el mundo.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"En lo que respecta a las recientes manifestaciones y protestas en todo el mundo, vamos a devolver la pelota a los bancos. Operación Robin Hood va a devolver el dinero a aquellos que han sido engañados por nuestro sistema y, lo más importante, a aquellos afectados por los bancos"&lt;/span&gt;, reza una declaración en el video.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;La recién formada alianza afirma que ya ha empezado la misión, y sus primeras víctimas serán Chase, Bank of America y Citibank.&lt;br /&gt;&lt;br /&gt;Además de la declaración abierta de guerra contra los bancos, la operación Robin Hood es otra oportunidad para que los hacktivistas insten a la gente a mover su dinero en "uniones de crédito seguro".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"No tenemos miedo de la Policía, de los Servicios Secretos o del FBI. Vamos a demostrar que los bancos no son seguros y a coger nuestro dinero. Vamos a golpear al verdadero mal, sin dañar a los clientes y a ayudar a los demás"&lt;/span&gt;, afirma p0isAnon.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;iframe src="http://www.youtube.com/embed/ix5ZitgE464" allowfullscreen="" width="560" frameborder="0" height="345"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-451148871932025791?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/451148871932025791/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=451148871932025791' title='4 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/451148871932025791'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/451148871932025791'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/anonymous-y-team-poison-se-unen-contra.html' title='Anonymous y Team Poison se unen contra los bancos en la Operación Robin Hood'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-8SP5a4jq9GA/TtT9EByGTiI/AAAAAAAACLE/94EGcNCqG0U/s72-c/poisanon.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-6280527635107960468</id><published>2011-11-28T11:28:00.004+01:00</published><updated>2011-11-28T11:47:35.628+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><category scheme='http://www.blogger.com/atom/ns#' term='exploits'/><title type='text'>Obtención remota de ficheros en versiones Android anteriores a 2.3.4</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;Hoy se ha echo público en Exploit Database código para explotar la vulnerabilidad &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4804"&gt;CVE-2010-4804&lt;/a&gt;, que permitía extraer contenidos de la tarjeta SD a través de direcciones &lt;span style="font-style: italic;"&gt;content:// &lt;/span&gt;en versiones &lt;span style="font-weight: bold;"&gt;Android anteriores a la 2.3.4&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;La vulnerabilidad se hizo pública a finales de noviembre del año pasado, pero ¿cuantos terminales con Froyo, Eclair y anteriores existen todavía en el mercado?&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-1UYg87ahkIQ/TtNi_Mgsw0I/AAAAAAAACK4/kofJDm_oOKg/s1600/android-distribution-11-2011-a-540x224.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 166px;" src="http://2.bp.blogspot.com/-1UYg87ahkIQ/TtNi_Mgsw0I/AAAAAAAACK4/kofJDm_oOKg/s400/android-distribution-11-2011-a-540x224.jpg" alt="" id="BLOGGER_PHOTO_ID_5679992392873984834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Sí, como veis &lt;span style="font-weight: bold;"&gt;aproximadamente&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;el 50% de los smartphones no se han actualizado todavía&lt;/span&gt;, así que todavía es factible publicar en nuestro servidor el &lt;a style="font-weight: bold;" href="http://www.exploit-db.com/exploits/18164/"&gt;código PHP expuesto&lt;/a&gt; y "pescar" los ficheros cuya ruta conocemos, explotando así la vulnerabilidad masivamente.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Os dejo también el video con la PoC:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;iframe src="http://player.vimeo.com/video/17030639?title=0&amp;amp;byline=0&amp;amp;portrait=0" webkitallowfullscreen="" mozallowfullscreen="" allowfullscreen="" width="400" frameborder="0" height="270"&gt;&lt;/iframe&gt;&lt;p&gt;&lt;a href="http://vimeo.com/17030639"&gt;Android Data Stealing Vulnerability&lt;/a&gt; from &lt;a href="http://vimeo.com/thomascannon"&gt;Thomas Cannon&lt;/a&gt; on &lt;a href="http://vimeo.com/"&gt;Vimeo&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-6280527635107960468?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/6280527635107960468/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=6280527635107960468' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6280527635107960468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6280527635107960468'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/obtencion-remota-de-ficheros-en-android.html' title='Obtención remota de ficheros en versiones Android anteriores a 2.3.4'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-1UYg87ahkIQ/TtNi_Mgsw0I/AAAAAAAACK4/kofJDm_oOKg/s72-c/android-distribution-11-2011-a-540x224.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-275655527727105955</id><published>2011-11-25T00:35:00.002+01:00</published><updated>2011-11-25T00:38:11.208+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><title type='text'>Inyección SQL en Zabbix 1.8.4 y 1.8.3</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;Si monitorizáis los sistemas de la empresa con &lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.zabbix.com/"&gt;Zabbix&lt;/a&gt;&lt;/span&gt;&lt;span&gt;,&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;quizás deberíais aseguraros que tiene instalada una de las últimas versiones (la 1.8.9 acaba de salir).&lt;br /&gt;&lt;br /&gt;Marcio Almeida acaba de publicar una &lt;a href="http://www.exploit-db.com/exploits/18155/"&gt;vulnerabilidad crítica de inyección SQL&lt;/a&gt; que afecta a las versiones &lt;span style="font-weight: bold;"&gt;1.8.4 &lt;/span&gt;&lt;span&gt;y &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;1.8.3&lt;/span&gt;, a través de la cual podríamos por ejemplo obtener los logins y sus hashes md5 sin necesidad de autenticación previa.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://4.bp.blogspot.com/-TVNZVKu1wXY/Ts7O_sLZ4EI/AAAAAAAACI0/2baaMSLMH1k/s1600/zabbix_sqlinjection_1.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 663px; height: 127px;" src="http://4.bp.blogspot.com/-TVNZVKu1wXY/Ts7O_sLZ4EI/AAAAAAAACI0/2baaMSLMH1k/s1600/zabbix_sqlinjection_1.png%22" alt="" id="BLOGGER_PHOTO_ID_5678703773746847810" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;Para ello, introducimos la siguiente URL (PoC):&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;http://localhost/zabbix/popup.php?dstfrm=form_scenario&amp;amp;dstfld1=application&amp;amp;srctbl=applications&amp;amp;srcfld1=name&amp;amp;only_hostid=-1))%20union%20select%201,group_concat(surname,0x2f,passwd)%20from%20users%23&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/-EzfGThUiv44/Ts7PUImM32I/AAAAAAAACJA/hOQCn6C8kjE/s1600/zabbix_sqlinjection_2.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 636px; height: 120px;" src="http://1.bp.blogspot.com/-EzfGThUiv44/Ts7PUImM32I/AAAAAAAACJA/hOQCn6C8kjE/s1600/zabbix_sqlinjection_2.png" alt="" id="BLOGGER_PHOTO_ID_5678704124972818274" border="0" /&gt;&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Y miramos el código fuente:&lt;/span&gt;&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://1.bp.blogspot.com/-x8EkTE6ZtDg/Ts7PUdhXfjI/AAAAAAAACJQ/H9pTWrTilzs/s1600/zabbix_sqlinjection_3.png"&gt;&lt;img style="display: block; margin: 0px auto 10px; text-align: center; cursor: pointer; width: 735px; height: 476px;" src="http://1.bp.blogspot.com/-x8EkTE6ZtDg/Ts7PUdhXfjI/AAAAAAAACJQ/H9pTWrTilzs/s1600/zabbix_sqlinjection_3.png" alt="" id="BLOGGER_PHOTO_ID_5678704130589687346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Concretamente, el código vulnerable está en la línea 1513 de popup.php:&lt;br /&gt;&lt;br /&gt;&lt;pre style="font-family: Andale Mono, Lucida Console, Monaco, fixed, monospace; color: #000000; background-color: #eee;font-size: 12px;border: 1px dashed #999999;line-height: 14px;padding: 5px; overflow: auto; width: 100%"&gt;&lt;code&gt;$sql = 'SELECT DISTINCT hostid,host '.&lt;br /&gt;' FROM hosts'.&lt;br /&gt;' WHERE '.DBin_node('hostid', $nodeid).&lt;br /&gt;' AND status IN ('.HOST_STATUS_PROXY_ACTIVE.','.HOST_STATUS_PROXY_PASSIVE.')'.&lt;br /&gt;' ORDER BY host,hostid';&lt;br /&gt;$result = DBselect($sql);&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;Por lo tanto, un atacante podría explotar la vulnerabilidad para acceder a cualquier información de la base de datos accesible por el usuario zabbix y, si a este usuario se le hubiesen asignado más privilegios, su explotación podría incluso dar lugar a una ejecución remota de código en el servidor.&lt;br /&gt;&lt;br /&gt;Y para más inri, la versión 1.8.4 de Zabbix es la que actualmente se instala con el comando apt-get en distribuciones Debian y derivadas, así que imaginad la &lt;a href="https://www.google.com/search?q=%22Zabbix+1.8.4+Copyright+2001-2010+by+SIA+Zabbix%22"&gt;cantidad de servidores vulnerables&lt;/a&gt; ...&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-275655527727105955?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/275655527727105955/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=275655527727105955' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/275655527727105955'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/275655527727105955'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/inyeccion-sql-en-zabbix-184-y-183.html' title='Inyección SQL en Zabbix 1.8.4 y 1.8.3'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-TVNZVKu1wXY/Ts7O_sLZ4EI/AAAAAAAACI0/2baaMSLMH1k/s72-c/zabbix_sqlinjection_1.png%22' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-608771930422137054</id><published>2011-11-23T10:43:00.003+01:00</published><updated>2011-11-23T10:49:55.952+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='técnicas'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><title type='text'>Paper #breaking80211: ataques a redes WiFi</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-tkd5KqrUG9o/TszBMF1WKqI/AAAAAAAACIo/cErEnmslL70/s1600/wifi_rayo.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 200px; height: 106px;" src="http://1.bp.blogspot.com/-tkd5KqrUG9o/TszBMF1WKqI/AAAAAAAACIo/cErEnmslL70/s200/wifi_rayo.jpg" alt="" id="BLOGGER_PHOTO_ID_5678125643675871906" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Hoy queríamos hablar de un magnífico paper publicado en &lt;a href="http://www.exploit-db.com/download_pdf/18144"&gt;Exploit Database&lt;/a&gt; llamado &lt;span style="font-weight: bold;"&gt;#breaking80211&lt;/span&gt;. Este paper de &lt;a href="https://twitter.com/#%21/aetsu"&gt;Aetsu&lt;/a&gt; reune la mayor parte de &lt;span style="font-weight: bold;"&gt;ataques a redes wifi&lt;/span&gt;, mostrando de una forma fácil y práctica todos los pasos necesarios para realizarlos.&lt;br /&gt;&lt;br /&gt;A través de la distribución BackTrack 5 R1, se mostrara el uso de herramientas de la suite aircrack-ng para el ataque a puntos de acceso y otras utilidades como coWPAtty o Pyrit para descifrar la contraseña.&lt;br /&gt;&lt;br /&gt;Además, veremos las consecuencias de conectarnos a puntos de acceso desconocidos, viendo el potencial de programas como Ettercap, Metasploit o SET.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;a title="View #breaking80211 by Aetsu on Scribd" href="http://es.scribd.com/doc/73364142/breaking80211-by-Aetsu" style="margin: 12px auto 6px; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; display: block; text-decoration: underline; font-family: verdana;"&gt;#breaking80211 by Aetsu&lt;/a&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; &lt;/span&gt;&lt;object id="doc_69615" name="doc_69615" type="application/x-shockwave-flash" data="http://d1.scribdassets.com/ScribdViewer.swf" style="outline:none;" width="100%" height="600"&gt;            &lt;param name="movie" value="http://d1.scribdassets.com/ScribdViewer.swf"&gt;             &lt;param name="wmode" value="opaque"&gt;             &lt;param name="bgcolor" value="#ffffff"&gt;             &lt;param name="allowFullScreen" value="true"&gt;             &lt;param name="allowScriptAccess" value="always"&gt;             &lt;param name="FlashVars" value="document_id=73364142&amp;amp;access_key=key-25oq083p5k89h2howump&amp;amp;page=1&amp;amp;viewMode=list"&gt;             &lt;embed id="doc_69615" name="doc_69615" src="http://d1.scribdassets.com/ScribdViewer.swf?document_id=73364142&amp;amp;access_key=key-25oq083p5k89h2howump&amp;amp;page=1&amp;amp;viewMode=list" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" wmode="opaque" bgcolor="#ffffff" width="100%" height="600"&gt;&lt;/embed&gt;         &lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-608771930422137054?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/608771930422137054/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=608771930422137054' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/608771930422137054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/608771930422137054'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/paper-breaking80211-ataques-redes-wifi.html' title='Paper #breaking80211: ataques a redes WiFi'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-tkd5KqrUG9o/TszBMF1WKqI/AAAAAAAACIo/cErEnmslL70/s72-c/wifi_rayo.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4931071834232831477</id><published>2011-11-22T11:48:00.004+01:00</published><updated>2011-11-23T10:50:31.246+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><title type='text'>El cazador de vulnerabilidades en aplicaciones PHP</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;PHP Vulnerability Hunter&lt;/span&gt; es un &lt;span style="font-style: italic;"&gt;fuzzer &lt;/span&gt;que puede provocar una amplia gama de fallos explotables en las aplicaciones web PHP. A través de un análisis dinámico escanea la aplicación en busca de los siguientes tipos de vulnerabilidades:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-tQD0kRvzANI/Tst-bLf8plI/AAAAAAAACIc/_DzVc2o4_Eg/s1600/PHP_vulnerability_scanner.png"&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;- Ejecución arbitraria de comandos&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-tQD0kRvzANI/Tst-bLf8plI/AAAAAAAACIc/_DzVc2o4_Eg/s1600/PHP_vulnerability_scanner.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 282px; height: 273px;" src="http://2.bp.blogspot.com/-tQD0kRvzANI/Tst-bLf8plI/AAAAAAAACIc/_DzVc2o4_Eg/s320/PHP_vulnerability_scanner.png" alt="" id="BLOGGER_PHOTO_ID_5677770760638998098" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;- Modificación arbitraria de ficheros (escritura/cambio/renombrado/borrado)&lt;br /&gt;- Inclusión de archivos locales (LFI) y lectura arbitraria de ficheros&lt;br /&gt;- Ejecución de PHP&lt;br /&gt;- Inyección SQL&lt;br /&gt;- Reflected Cross-site Scripting (XSS)&lt;br /&gt;- Redirección abierta&lt;br /&gt;- Descubrimiento de rutas&lt;br /&gt;&lt;br /&gt;Web del proyecto: &lt;a href="http://code.google.com/p/php-vulnerability-hunter/"&gt;http://code.google.com/p/php-vulnerability-hunter/&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-4931071834232831477?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/4931071834232831477/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=4931071834232831477' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4931071834232831477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/4931071834232831477'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/el-cazador-de-vulnerabilidades-en.html' title='El cazador de vulnerabilidades en aplicaciones PHP'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-tQD0kRvzANI/Tst-bLf8plI/AAAAAAAACIc/_DzVc2o4_Eg/s72-c/PHP_vulnerability_scanner.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-5183074770126808711</id><published>2011-11-21T18:57:00.005+01:00</published><updated>2011-11-21T19:08:59.413+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='web recomendada'/><title type='text'>Web recomendada: Segu-Info</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.segu-info.com.ar/"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 253px; height: 208px;" src="http://2.bp.blogspot.com/--qarDMitd9U/TsqTRmSfiZI/AAAAAAAACIQ/1rmHItR2JMM/s320/segu-info.png" alt="" id="BLOGGER_PHOTO_ID_5677512210799102354" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;Segu-Info&lt;/span&gt; es un sitio de Seguridad de la Información que se encuentra en línea desde el año 2001 y actualmente conforma una de las comunidades más grandes de habla hispana con respecto a esta temática, reuniendo aproximadamente 15.000 miembros de distintos países de Iberoamérica en su sitio web, blog y foros de discusiones.&lt;br /&gt;&lt;br /&gt;Su creador y director Cristian F. Borghello contactó recientemente con nosotros y Segu-Info no podia faltar en nuestras webs recomendas, así que no dejéis de visitarlo: &lt;a href="http://www.segu-info.com.ar/"&gt;http://www.segu-info.com.ar&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: italic;"&gt;pd.  Y ya sabes, si tu también tienes un blog, una comunidad, un foro o lo  que sea relacionado con la seguridad informática y hacking ético, ¡te  animamos también a &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;a href="http://hackplayers.blogspot.com/p/participa.html"&gt;compartirlo con nosotros&lt;/a&gt;!.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-5183074770126808711?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/5183074770126808711/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=5183074770126808711' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5183074770126808711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/5183074770126808711'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/web-recomendada-segu-info.html' title='Web recomendada: Segu-Info'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/--qarDMitd9U/TsqTRmSfiZI/AAAAAAAACIQ/1rmHItR2JMM/s72-c/segu-info.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-7530202248641102275</id><published>2011-11-21T15:56:00.004+01:00</published><updated>2011-11-21T16:01:58.760+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='técnicas'/><category scheme='http://www.blogger.com/atom/ns#' term='esteganografía'/><title type='text'>TranSteg: esteganografía por transcodificación en VoIP</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Investigadores del Instituto de Telecomunicaciones de la Universidad Tecnológica de Varsovia han encontrado un nuevo método de esteganografía bautizado como "&lt;span style="font-weight: bold;"&gt;TranSteg&lt;/span&gt;" (esteganografía por transcodificación) para ocultar datos en comunicaciones &lt;span style="font-weight: bold;"&gt;VoIP&lt;/span&gt; (telefonía IP).&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;Esta técnica comprime los datos en &lt;span style="font-weight: bold;"&gt;RTP (Real-Time Transport Protocol)&lt;/span&gt; para insertar información oculta. Lo innovador es que para ello elige un&lt;span style="font-weight: bold;"&gt; códec&lt;/span&gt; que tratará el flujo de datos dando como resultado &lt;span style="font-weight: bold;"&gt;una calidad de voz similar pero de menor tamaño&lt;/span&gt; que la carga útil de voz (payload) originalmente seleccionada.&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://3.bp.blogspot.com/-bBKKzwYvWcY/TspnG2eDsII/AAAAAAAACIE/Vvo48Xrdims/s1600/transteg.jpeg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 194px;" src="http://3.bp.blogspot.com/-bBKKzwYvWcY/TspnG2eDsII/AAAAAAAACIE/Vvo48Xrdims/s400/transteg.jpeg" alt="" id="BLOGGER_PHOTO_ID_5677463647652393090" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:verdana;"&gt;Ya se han desarrollado pruebas de concepto en las que se ha transmitido 2.2MB durante una llamada de 9 minutos introduciendo un retardo máximo de 0,4 ms. Además, teóricamente podría utilizarse también con éxito en transmisiones de vídeo y otros servicios donde sea posible comprimir los datos sin que haya una pérdida de calidad notable.&lt;/span&gt;  &lt;span style="font-family:verdana;"&gt;&lt;br /&gt;&lt;br /&gt;No obstante, para llevar a cabo esta técnica, ambos teléfonos VoIP (emisor y receptor) deben estar configurados, ya que los extremos (o equipos intermedios) deber conocer el códec utilizado en lugar del códec que marcan los paquetes, de tal forma que se pueda extraer y volver a montar el mensaje secreto.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" href="http://arxiv.org/ftp/arxiv/papers/1111/1111.1250.pdf"&gt;Descarga el Paper.&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-7530202248641102275?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/7530202248641102275/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=7530202248641102275' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7530202248641102275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/7530202248641102275'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/transteg-esteganografia-por.html' title='TranSteg: esteganografía por transcodificación en VoIP'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-bBKKzwYvWcY/TspnG2eDsII/AAAAAAAACIE/Vvo48Xrdims/s72-c/transteg.jpeg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-508850085627386187</id><published>2011-11-20T23:29:00.005+01:00</published><updated>2011-11-21T00:02:58.741+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><category scheme='http://www.blogger.com/atom/ns#' term='amenazas'/><title type='text'>Hackeando la democracia</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-dtZmMwypE9c/TsmD86sv0JI/AAAAAAAACH4/cZoNn0N9fJY/s1600/voto%2Belectr%25C3%25B3nico.jpg"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 234px; height: 320px;" src="http://2.bp.blogspot.com/-dtZmMwypE9c/TsmD86sv0JI/AAAAAAAACH4/cZoNn0N9fJY/s320/voto%2Belectr%25C3%25B3nico.jpg" alt="" id="BLOGGER_PHOTO_ID_5677213887849549970" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;¿Podría un ciberataque incurrir en un fraude electoral que cambie los designios políticos y el rumbo entero de una nación?. ¿Podría un hacker llegar a manipular cientos de miles de votos electrónicos o modificar los resultados de los escrutinios?.&lt;br /&gt;&lt;br /&gt;Son cuestiones que me pregunto &lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;hoy&lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt; coinciendo con las elecciones generales en España, preguntas sin embargo casi vacías porque en este país el voto electrónico todavía se limita a &lt;a href="http://www.euskadi.net/botoelek/otros_paises/ve_mundo_est_c.htm#Espa%C3%B1a"&gt;diversas experiencias piloto&lt;/a&gt;. Aunque todo se andará...&lt;br /&gt;&lt;br /&gt;De momento el &lt;span style="font-style: italic;"&gt;e-voto&lt;/span&gt; está &lt;a href="http://www.euskadi.net/botoelek/otros_paises/ve_mundo_impl_c.htm"&gt;implantado en apenas una docena de países&lt;/a&gt;, pero su historia ya registra casos de fallos en el software, conspiraciones, ataques e intrusiones.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;El siguiente vídeo es un apasionante documental llamado &lt;span style="font-weight: bold;"&gt;Hacking Democracy&lt;/span&gt;, rodado en el 2006 y emitido por la HBO, que narra las investigaciones de ciudadanos estadounidenses sobre las anomalías y las irregularidades con el sistema de voto electrónico que ocurrieron durante las elecciones presidenciales a los EEUU en el año 2000 y 2004, especialmente en el Condado de Volusia (Florida)...&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;embed id="VideoPlayback" src="http://video.google.com/googleplayer.swf?docid=3558928184519856419&amp;amp;hl=es&amp;amp;fs=true" style="width:400px;height:326px" allowfullscreen="true" allowscriptaccess="always" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-508850085627386187?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/508850085627386187/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=508850085627386187' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/508850085627386187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/508850085627386187'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/hackeando-la-democracia.html' title='Hackeando la democracia'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-dtZmMwypE9c/TsmD86sv0JI/AAAAAAAACH4/cZoNn0N9fJY/s72-c/voto%2Belectr%25C3%25B3nico.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-8928632533900063778</id><published>2011-11-18T02:04:00.005+01:00</published><updated>2011-11-18T02:22:48.252+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><title type='text'>Evasión del límite de 140 caracteres de Twitter mediante codificación CESU-8</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-Udx-qSh0vzE/TsWw-aNOBDI/AAAAAAAACHo/K1zYUkgIQGI/s1600/twitter-140-character-limit.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 194px; height: 131px;" src="http://3.bp.blogspot.com/-Udx-qSh0vzE/TsWw-aNOBDI/AAAAAAAACHo/K1zYUkgIQGI/s320/twitter-140-character-limit.jpg" alt="" id="BLOGGER_PHOTO_ID_5676137491603522610" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;No es la primera vez que se consigue saltar la restricción de &lt;span style="font-weight: bold;"&gt;140 caracteres&lt;/span&gt; para el envío de &lt;span style="font-weight: bold;"&gt;mensajes en Twitter&lt;/span&gt;, y seguramente no será la última.&lt;br /&gt;&lt;br /&gt;Esta vez, el usuario ruso &lt;a href="https://twitter.com/#%21/LeeA_09"&gt;LeeA_09&lt;/a&gt; consiguió superar ampliamente esta barrera con un tweet de más de 900 caracteres. El "truco", utilizar una codificación &lt;span style="font-weight: bold;"&gt;CESU-8&lt;/span&gt; mediante un cliente o interfaz de Twitter (en su caso &lt;span style="font-weight: bold;"&gt;QIP 2010&lt;/span&gt;) que no valida y permite el envío de estos símbolos.&lt;br /&gt;&lt;br /&gt;El fallo es que no se filtra su entrada a nivel del servidor que además está esperando visualizar una secuencia válida &lt;span style="font-weight: bold;"&gt;UTF-8&lt;/span&gt;, por lo que al final acaba mostrando 12 caracteres por cada símbolo introducido. Es decir, si introducimos 140 símbolos Unicode codificados con CESU-8, Twitter mostrará 1680 caracteres.&lt;br /&gt;&lt;br /&gt;Por lo tanto, con el interfaz adecuado es muy sencillo crear un mensaje como el siguiente:&lt;br /&gt;&lt;a href="https://twitter.com/#%21/hackplayers/status/137321960488189953"&gt;&lt;br /&gt;https://twitter.com/#!/hackplayers/status/137321960488189953&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://4.bp.blogspot.com/-P-pj2IAFhBE/TsWvU0VZOwI/AAAAAAAACHc/OpZp3cGbBf0/s1600/supertweet.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 231px;" src="http://4.bp.blogspot.com/-P-pj2IAFhBE/TsWvU0VZOwI/AAAAAAAACHc/OpZp3cGbBf0/s400/supertweet.jpg" alt="" id="BLOGGER_PHOTO_ID_5676135677551000322" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;br /&gt;pd. ¿Sabrías además decodificar nuestro mensaje? ;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-8928632533900063778?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/8928632533900063778/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=8928632533900063778' title='9 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8928632533900063778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/8928632533900063778'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/evasion-del-limite-de-140-caracteres-de.html' title='Evasión del límite de 140 caracteres de Twitter mediante codificación CESU-8'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Udx-qSh0vzE/TsWw-aNOBDI/AAAAAAAACHo/K1zYUkgIQGI/s72-c/twitter-140-character-limit.jpg' height='72' width='72'/><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-534045386780974344</id><published>2011-11-16T11:53:00.009+01:00</published><updated>2011-11-16T12:01:16.349+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='herramientas'/><title type='text'>Comprueba la seguridad de tus CAPTCHAS con TesserCap</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;span style="font-weight: bold;"&gt;TesserCap&lt;/span&gt; es una herramienta de análisis de &lt;span style="font-weight: bold;"&gt;CAPTCHAs&lt;/span&gt; que incluye las siguientes ca&lt;/span&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;racterísticas:&lt;br /&gt;&lt;/span&gt;&lt;a href="http://2.bp.blogspot.com/-B1CjoeFZeZU/TsOXl0HR0EI/AAAAAAAACHQ/XIqnxYqT7YE/s1600/TesserCap1.0.png"&gt;&lt;img style="float:right; margin:0 0 10px 10px;cursor:pointer; cursor:hand;width: 200px; height: 150px;" src="http://2.bp.blogspot.com/-B1CjoeFZeZU/TsOXl0HR0EI/AAAAAAAACHQ/XIqnxYqT7YE/s200/TesserCap1.0.png" alt="" id="BLOGGER_PHOTO_ID_5675546631317082178" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;- Un motor genérico de preprocesamiento de imágenes que puede ser configurado según el tipo de CAPTCHA que se analiza&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;Tesseract-OCR&lt;/span&gt; como motor OCR para recuperar el texto de los CAPTCHAs preprocesados&lt;br /&gt;- Soporte de proxy Web&lt;br /&gt;- Soporte para cabeceras HTTP para obtener los CAPTCHAS de sitios web que requieren cookies o cabeceras HTTP especiales en las peticiones&lt;br /&gt;- Soporte de análisis estadístico de CAPTCHAs&lt;br /&gt;- Selección de configuración de caracteres para el motor OCR&lt;br /&gt;&lt;br /&gt;Su autor ha usado esta herramienta contra 200 de los &lt;a href="http://www.quantcast.com/top-sites-1"&gt;sitios web con más tráfico en la actualidad&lt;/a&gt; y, junto a &lt;a href="http://cdn.ly.tl/publications/text-based-captcha-strengths-and-weaknesses.pdf"&gt;otros estudios como el de varios estudiantes de la Universidad de Stanford&lt;/a&gt;, se obtiene una conclusión preocupante: &lt;span style="font-weight: bold;"&gt;un número alarmante de CAPTCHAS son vulnerables a ataques automáticos.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Más información en el &lt;a href="http://blog.opensecurityresearch.com/2011/11/captcha-hax-with-tessercap.html"&gt;blog Open Security Research patrocinado por Foundstone&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Descarga:&lt;br /&gt;&lt;/span&gt;&lt;ul  style="font-family:verdana;"&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.opensecurityresearch.com/files/tessercap.zip"&gt;http://www.opensecurityresearch.com/files/tessercap.zip&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.mcafee.com/us/downloads/free-tools/tessercap.aspx"&gt;http://www.mcafee.com/us/downloads/free-tools/tessercap.aspx&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-534045386780974344?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/534045386780974344/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=534045386780974344' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/534045386780974344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/534045386780974344'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/comprueba-la-seguridad-de-tus-captchas.html' title='Comprueba la seguridad de tus CAPTCHAS con TesserCap'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-B1CjoeFZeZU/TsOXl0HR0EI/AAAAAAAACHQ/XIqnxYqT7YE/s72-c/TesserCap1.0.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-2533640814736718775</id><published>2011-11-15T12:23:00.002+01:00</published><updated>2011-11-15T12:29:19.996+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='noticias'/><category scheme='http://www.blogger.com/atom/ns#' term='pwned'/><title type='text'>Facebook se inunda de imágenes porno y gore</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;a href="http://www.elmundo.es/elmundo/2011/11/15/navegante/1321353875.html"&gt;ELMUNDO.es | Madrid &lt;/a&gt;-&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;span style="font-family:verdana;"&gt;Son ya muchos los usuarios de Facebook que se están quejando de la &lt;/span&gt;&lt;strong style="font-family: verdana;"&gt;aparición masiva de imágenes de violencia explícita, automutilación, zoofilia y pornografía&lt;/strong&gt;&lt;span style="font-family:verdana;"&gt;, tras lo que parece un 'ciberataque' a la popular red social.&lt;/span&gt;&lt;/span&gt;&lt;div  id="tamano" style="font-family:verdana;"&gt;&lt;span style="font-family:trebuchet ms;font-size:85%;"&gt; &lt;/span&gt;&lt;p&gt;&lt;span style="font-size:85%;"&gt;Según informa &lt;a href="http://www.zdnet.com/blog/facebook/facebook-hacked-are-you-seeing-images-of-porn-and-violence/5314" target="_blank"&gt;ZDNews&lt;/a&gt;,  las quejas provienen tanto desde aquéllos que han visto su muro  invadido por estas imágenes, como por parte de otros que reciben  peticiones para entrar en enlaces con diversos reclamos. &lt;strong&gt;El tradicional 'spam' de Facebook, solo que esta vez parece más rápido&lt;/strong&gt;.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;a href="http://4.bp.blogspot.com/-Xbb7oApO5v8/TsJMu4SMGAI/AAAAAAAACFw/TtWu9WAF2Iw/s1600/bieber-porn.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://4.bp.blogspot.com/-Xbb7oApO5v8/TsJMu4SMGAI/AAAAAAAACFw/TtWu9WAF2Iw/s320/bieber-porn.jpg" alt="" id="BLOGGER_PHOTO_ID_5675182848706615298" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;El citado medio &lt;a href="https://twitter.com/#%21/search/facebook%20porn" target="_blank"&gt;enlaza a Twitter para demostrar&lt;/a&gt;,  con una simple búsqueda, que existen múltiples quejas al respecto de  particulares y de algunos personajes públicos que utilizan la red  social.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size:85%;"&gt;Por ejemplo, la actriz y directora &lt;strong&gt;Courtney Zito&lt;/strong&gt; declaró a &lt;a href="http://global.christianpost.com/news/facebook-hacked-porn-and-graphic-material-floods-users-accounts-61800/" target="_blank"&gt;The Christian Post&lt;/a&gt;  (el primer medio que se hizo eco de este hecho), que su propio muro  &lt;span style="font-style: italic;"&gt;"está lleno de pornografía"&lt;/span&gt;, así como de imágenes violentas. &lt;span style="font-style: italic;"&gt;"Estoy a  punto de desactivarlo"&lt;/span&gt;, comentó.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size:85%;"&gt;El citado sitio web apunta que &lt;strong&gt;parece un ataque aleatorio&lt;/strong&gt;,  de manera que muchos usuarios no han visto alterados sus perfiles con  pornografía, mientras que otros se han visto inundados por este tipo de  contenidos.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size:85%;"&gt;A pesar de que no hay aún pruebas ni una respuesta oficial por parte  de Facebook, hay ya quien acusa a 'Anonymous' de estar detrás de este  suceso.&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style="font-size:85%;"&gt;Este problema viene sucediendo desde hace un par de días, &lt;a href="http://gawker.com/5859480/facebook-is-drowning-in-a-flood-of-hardcore-porn" target="_blank"&gt;informa Gawker&lt;/a&gt;, que añade que ya empiezan a formarse grupos que claman por un Fabebook más 'limpio', tales como &lt;em&gt;"Recuerdo cuando Facebok NO ERA un sitio porno"&lt;/em&gt;.&lt;/span&gt;&lt;/p&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-2533640814736718775?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/2533640814736718775/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=2533640814736718775' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/2533640814736718775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/2533640814736718775'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/facebook-se-inunda-de-imagenes-porno-y.html' title='Facebook se inunda de imágenes porno y gore'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-Xbb7oApO5v8/TsJMu4SMGAI/AAAAAAAACFw/TtWu9WAF2Iw/s72-c/bieber-porn.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-3325152533542789928</id><published>2011-11-15T11:51:00.002+01:00</published><updated>2011-11-15T11:55:41.629+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='magazines'/><title type='text'>ClubHACK Magazine nº22</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-FGJpvlQZimo/TsJEaGBjPQI/AAAAAAAACFk/wAbfyVUHwfU/s1600/clubhackmag22.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 215px; height: 278px;" src="http://4.bp.blogspot.com/-FGJpvlQZimo/TsJEaGBjPQI/AAAAAAAACFk/wAbfyVUHwfU/s320/clubhackmag22.png" alt="" id="BLOGGER_PHOTO_ID_5675173695524650242" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;El &lt;span style="font-weight: bold;"&gt;número 22&lt;/span&gt; de la revista india &lt;span style="font-weight: bold;"&gt;ClubHACK Magazine&lt;/span&gt; trae en portada &lt;span style="font-weight: bold;"&gt;Ravan&lt;/span&gt;, una herramienta en javascript para cracking distribuido de la que ya os hablamos el año pasado &lt;a href="http://hackplayers.blogspot.com/2010/12/ravan-hash-cracking-distribuido-en.html"&gt;&lt;span style="font-style: italic;"&gt;en Hackplayers&lt;/span&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Además, no os podéis perder el resto de los artículos de este mes, que son los siguientes:&lt;br /&gt;&lt;br /&gt;0x00 Tech Gyan - Looking Into the Eye of the Bits&lt;br /&gt;0x01 Tool Gyan - Ravan – JavaScript Distributed Computing System&lt;br /&gt;0x02 Mom's Guide - Best Practices of Web Application Security&lt;br /&gt;0x03 Legal Gyan - Law relating to Cyberterrorism&lt;br /&gt;0x04 Matriux Vibhag - OWASP Mantra’s MoC Crawler&lt;br /&gt;0x05 Poster - Ravan&lt;br /&gt;&lt;br /&gt;La versión PDF puede descargarse desde: &lt;a href="http://chmag.in/issue/nov2011.pdf"&gt;http://chmag.in/issue/nov2011.pdf&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-3325152533542789928?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/3325152533542789928/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=3325152533542789928' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3325152533542789928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/3325152533542789928'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/clubhack-magazine-n22.html' title='ClubHACK Magazine nº22'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-FGJpvlQZimo/TsJEaGBjPQI/AAAAAAAACFk/wAbfyVUHwfU/s72-c/clubhackmag22.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-6934992465733148152</id><published>2011-11-14T11:05:00.005+01:00</published><updated>2011-11-14T11:33:54.306+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><category scheme='http://www.blogger.com/atom/ns#' term='recursos'/><category scheme='http://www.blogger.com/atom/ns#' term='recopilatorios'/><title type='text'>Cómo convertirte en un cazarecompensas de 0-days</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-rMyuYkhRgTM/TsDp5N-E8TI/AAAAAAAACFY/sKwj-H7utLk/s1600/cazarecompensas.png"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 177px; height: 269px;" src="http://3.bp.blogspot.com/-rMyuYkhRgTM/TsDp5N-E8TI/AAAAAAAACFY/sKwj-H7utLk/s320/cazarecompensas.png" alt="" id="BLOGGER_PHOTO_ID_5674792699698671922" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;¿Has descubierto una vulnerabilidad crítica de tipo 0-day en un producto ampliamente utilizado? ¿Puede ser ese bug "armado" o activamente explotado?&lt;br /&gt;&lt;br /&gt;Si ese es tu caso, podrías ganar cientos de euros o quizás más vendiéndola al ZDI (Zero Day Initiative) de TippingPoint, al Programa de Contribuciones de Vulnerabilidades del iDefense o a otro de los más de 20 programas públicos y legales que recompensan a los cazadores de bugs.&lt;br /&gt;&lt;br /&gt;Dos años después del lanzamiento de la iniciativa "&lt;a href="http://trailofbits.com/2009/03/22/no-more-free-bugs/"&gt;No more free bugs&lt;/a&gt;", varias empresas y proyectos de código abierto están ofreciendo programas destinados a fomentar la investigación de seguridad en sus productos. Además, muchas empresas privadas están ofreciendo públicamente programas de adquisición de vulnerabilidades.&lt;br /&gt;&lt;br /&gt;A continuación y gracias a &lt;a href="http://blog.nibblesec.org/2011/10/no-more-free-bugs-initiatives.html"&gt;NibbleSecurity&lt;/a&gt; podemos ver una interesante lista, por si o animáis. Considerarlo en lugar de pasaros al "lado oscuro" e intentar la venta en el mercado negro ;)&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;span style=""&gt;&lt;span style="font-weight: bold;"&gt;Programas Bug Bounty&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;table style="text-align: left; width: 100%; font-family: verdana;" border="1" cellpadding="2" cellspacing="2"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="background-color: #cccccc; font-weight: bold; text-align: center; vertical-align: top;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span&gt; Patrocinador&lt;/span&gt;&lt;/span&gt;  &lt;/td&gt;&lt;td style="background-color: #cccccc; font-weight: bold; text-align: center; vertical-align: top;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span&gt; Objetivo&lt;/span&gt;&lt;/span&gt;  &lt;/td&gt;&lt;td style="background-color: #cccccc; font-weight: bold; text-align: center; vertical-align: top;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span&gt; Recompensa&lt;/span&gt;&lt;/span&gt;  &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.barracudalabs.com/bugbounty/&amp;amp;usg=ALkJrhiXpAPUc62HxxZIK4z-JWgRRkYyCA"&gt;Barracuda&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt;  &lt;span style="font-size:85%;"&gt;&lt;span&gt;Vulnerabilidades en los dispositivos Barracuda, incluyendo Firewall Spam/Virus, Web Filter, WAF, NG firewall&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 500 - $ 3,133.7&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.ccbill.com/developers/security/vulnerability-reward-program-participation.php&amp;amp;usg=ALkJrhiiDDbMVA5lrGX0Lwhj-BaSpefF9g"&gt;CCBill.com&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Vulnerabilidades de las aplicaciones web&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt; de CCBill &lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 200 - $ 500&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://cr.yp.to/djbdns/guarantee.html&amp;amp;usg=ALkJrhjWh3WHIv_xhCl8PzBUTIUqFHug3A"&gt;Djbdns&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Agujeros de seguridad verificables en la última versión de Djbdns&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 1000&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.facebook.com/whitehat/bounty/&amp;amp;usg=ALkJrhjpHJFImb6hRgWq27EqdTWsHnw1gw"&gt;Facebook&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Bugs en la platataforma web de Facebook.&lt;/span&gt; &lt;span&gt; No incluye aplicaciones de terceros&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; A partir de $ 500&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html&amp;amp;usg=ALkJrhhRqieYJBbAtWyeA3fAfvuBf0aTyw"&gt;Google&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Proyecto &lt;/span&gt;&lt;/span&gt;&lt;small&gt;Chromium &lt;/small&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 500 - $ 3,133.7&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.hex-rays.com/bugbounty.shtml&amp;amp;usg=ALkJrhhXKskliPWdUEgBbjYZjhLRdQIzBQ"&gt;Hex-Rays&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Fallos de seguridad en la última versión pública de Hex-Rays IDA&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Hasta $ 3000&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.mozilla.org/security/bug-bounty.html&amp;amp;usg=ALkJrhgPqvTtgj00yU0aDlnKUIC0VQytsQ"&gt;Mozilla&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Bus en sitios web expuestos de Firefox, Thunderbird y Mozilla&lt;/span&gt;&lt;/span&gt;&lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 500 - $ 3000, además de Mozilla T-shirt&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://piwik.org/security/&amp;amp;usg=ALkJrhgLswYfWrQlA31GQjB25vnDbrMRiw"&gt;Piwik&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Fallos en el software Piwik Web Analytics&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 200 - $ 500&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://cr.yp.to/qmail/guarantee.html&amp;amp;usg=ALkJrhiXZSloTcYQL4ZNugUQzvkH58E9jg"&gt;Qmail&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Agujeros de seguridad verificables en la última versión de Qmail&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 5000&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.tarsnap.com/bugbounty.html&amp;amp;usg=ALkJrhgWWy5RS1TmCqErUnQNou114ck2aA"&gt;Tarsnap&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;Errores en Tarsnap, que afecten a versiones pre-lanzamiento o versiones publicadas&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 1 - $ 2000&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;br /&gt;&lt;span&gt; &lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Programas de adquisición de &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Vulnerabilidad / Exploit &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;table style="text-align: left; width: 100%; font-family: verdana;" border="1" cellpadding="2" cellspacing="2"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="background-color: #cccccc; font-weight: bold; vertical-align: top;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Patrocinador&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;/td&gt;&lt;td style="background-color: #cccccc; font-weight: bold; vertical-align: top;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Objetivo&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;/td&gt;&lt;td style="background-color: #cccccc; font-weight: bold; vertical-align: top;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div style="text-align: center;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Recompensa&lt;/span&gt;&lt;/span&gt; &lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.beyondsecurity.com/ssd.html&amp;amp;usg=ALkJrhhDgEyig8kouJNIzkLON59BjIOmcg"&gt;BeyondSecurity SecuriTeam&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Alto y medio impacto en los errores de software muy extendidos&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.coseinc.com/en/index.php%3Frt%3Dadvisory&amp;amp;usg=ALkJrhg4vE930EqGipxbkBii2Om8Ouap2w"&gt;COSEINC&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Vulnerabilidades no publicadas de seguridad para Windows, Linux y Solaris&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://digitalarmaments.com/index.php/contribute.html&amp;amp;usg=ALkJrhhVNvFEFaXD39-atipjAo1kw_gr3A"&gt;Digital Armamento&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Vulnerabilidad y/o código de explotación de software de alto valor&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="https://www.exploithub.com/request/index/developmentrequests/"&gt;ExploitHub&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt;  &lt;span style="font-size:85%;"&gt;&lt;span&gt;Exploits Metasploit no de día cero&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 50 ~ $ 1000&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="https://gvp.isightpartners.com/program_details.gvp?page=3&amp;amp;title=1&amp;amp;section=0"&gt;iSight Partners&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Errores en las aplicaciones típicas de ambiente corporativo&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://pentest.snosoft.com/netragards-eap/&amp;amp;usg=ALkJrhjvKTwtP7vn7923_1vvZnORq7lPjw"&gt;Netragard&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; 0-day exploits contra el software &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;conocido &lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://secunia.com/community/research/svcrp&amp;amp;usg=ALkJrhiyDkBl8jPBoSdQkRqgjX4YSeip1A"&gt;Secunia&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span style=""&gt; Vulnerabilidades desconocidas que afectan a la versión estable más reciente.&lt;/span&gt; &lt;span&gt; Todas las clases de vulnerabilidades son elegibles.&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Desde la gama superior de merchandising a un pase de seguridad de TI para conferencias y alojamiento en un hotel&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.zerodayinitiative.com/&amp;amp;usg=ALkJrhgcvW_QrD806p0_9dczqW6qPlsB9Q"&gt;TippingPoint ZDI&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; La investigación de vulnerabilidades no divulgada, que afecta a software ampliamente utilizado&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a más premios y beneficios, dependiendo de la situación del contribuyente&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/vulnerability-intelligence/index.xhtml&amp;amp;usg=ALkJrhhLUv6fJZB16ZoWrOLh3NMO9kkEag"&gt;VeriSign iDefence&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Las vulnerabilidades de seguridad en aplicaciones de gran despliegue&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ N / a&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; &lt;a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;amp;rurl=translate.google.com&amp;amp;sl=auto&amp;amp;tl=es&amp;amp;twu=1&amp;amp;u=http://www.whitefirdesign.com/about/wordpress-security-bug-bounty-program.html&amp;amp;usg=ALkJrhjArz6JxNygEXB34SjsU3BiRkmYOQ"&gt;White Fir Diseño&lt;/a&gt;&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 60%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; Errores en el código de WordPress y plugins (con más de 1 millón de descargas y compatible con la más reciente de WordPress)&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;td style="text-align: center; vertical-align: top; width: 20%;"&gt; &lt;span style="font-size:85%;"&gt;&lt;span&gt; $ 50 - $ 500&lt;/span&gt;&lt;/span&gt; &lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/9133539773684103848-6934992465733148152?l=www.hackplayers.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.hackplayers.com/feeds/6934992465733148152/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=9133539773684103848&amp;postID=6934992465733148152' title='1 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6934992465733148152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/9133539773684103848/posts/default/6934992465733148152'/><link rel='alternate' type='text/html' href='http://www.hackplayers.com/2011/11/como-convertirte-en-un-cazarecompensas.html' title='Cómo convertirte en un cazarecompensas de 0-days'/><author><name>Vicente Motos</name><uri>http://www.blogger.com/profile/03053036399006390105</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='24' height='32' src='http://4.bp.blogspot.com/-vOYTWqyujbI/TVRiEhZb0NI/AAAAAAAABTs/Dy1-E5Vl6W4/s220/CameraFun%2B-%2B2011-02-10%2B23.00.34.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-rMyuYkhRgTM/TsDp5N-E8TI/AAAAAAAACFY/sKwj-H7utLk/s72-c/cazarecompensas.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-9133539773684103848.post-4042790662859991130</id><published>2011-11-11T14:32:00.005+01:00</published><updated>2011-11-11T14:49:45.875+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vulnerabilidades'/><title type='text'>MS11-083: la vulnerabilidad de Chuck Norris</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-YpFhXXqSwCM/Tr0nh07B48I/AAAAAAAACEk/1kge4DEtSZs/s1600/chuck_norris.png"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 202px; height: 220px;" src="http://4.bp.blogspot.com/-YpFhXXqSwCM/Tr0nh07B48I/AAAAAAAACEk/1kge4DEtSZs/s320/chuck_norris.png" alt="" id="BLOGGER_PHOTO_ID_5673734567652090818" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;font-size:85%;" &gt;El pasado 8 de Noviembre de 2011, Microsoft hizo pública una vulnerabilidad (&lt;a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-083"&gt;MS11-083&lt;/a&gt;) en la implementación de las librerías que controlan las comunicaciones TCP/IP, mediante la cuál un atacante podría enviar un flujo continuo de paquetes UDP especialmente manipulados para ejecutar remotamente código en los sistemas Microsoft Windows.&lt;br /&gt;&lt;br /&gt;Lo más llamativo de esta vulnerabilidad es que estos &lt;span style="font-weight: bold;"&gt;paquetes UDP&lt;/span&gt; han de enviarse a un &lt;span style="font-weight: bold;"&gt;puerto cerrado&lt;/span&gt; del sistema objetivo, característica que ha hecho comentar con guasa en Twitter que &lt;span style="font-style: italic;"&gt;"MS11-083 fue descubierta por Chuck Norris", "Chuck Norris puede explotar sockets que inc
