<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.1" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Segmentation Fault: Core dumped..;-)</title>
	<link>http://indrayam.com</link>
	<description>Anand Sharma's weblog: A peek into life through "my" bioscope</description>
	<pubDate>Tue, 11 Nov 2008 16:24:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.1</generator>
        <image> 
           <title>Segmentation Fault: Core dumped..;-)</title> 
           <url>http://indrayam.com/images/favicon.gif</url>
           <link>http://indrayam.com</link>
        </image>
	<language>en</language>
			<item>
		<title>Embedding Slides from Slideware</title>
		<link>http://indrayam.com/archives/security/001237.php</link>
		<comments>http://indrayam.com/archives/security/001237.php#comments</comments>
		<pubDate>Mon, 27 Nov 2006 06:08:23 +0000</pubDate>
		<dc:creator>anand</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://indrayam.com/?p=1237</guid>
		<description><![CDATA[<p>
<div align="center"><object type="application/x-shockwave-flash" data="https://s3.amazonaws.com:443/slideshare/ssplayer.swf?id=10501&doc=ddos-attacks-20420" width="425" height="348"><param name="movie" value="https://s3.amazonaws.com:443/slideshare/ssplayer.swf?id=10501&doc=ddos-attacks-20420" /></object></div>
</p><p>
So what's Slideware? Think of it as "YouTube" of all your cool presentations that you ever built and that's currently stashed away on your hard disk. <i>Neat.</i>
</p>]]></description>
			<content:encoded><![CDATA[<p>
<div align="center"><object type="application/x-shockwave-flash" data="https://s3.amazonaws.com:443/slideshare/ssplayer.swf?id=10501&doc=ddos-attacks-20420" width="425" height="348"><param name="movie" value="https://s3.amazonaws.com:443/slideshare/ssplayer.swf?id=10501&doc=ddos-attacks-20420" /></object></div>
</p><p>
So what's Slideware? Think of it as "YouTube" of all your cool presentations that you ever built and that's currently stashed away on your hard disk. <i>Neat.</i>
</p>]]></content:encoded>
			<wfw:commentRss>http://indrayam.com/archives/security/001237.php/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Up and Down and Up&#8230;</title>
		<link>http://indrayam.com/archives/security/001098.php</link>
		<comments>http://indrayam.com/archives/security/001098.php#comments</comments>
		<pubDate>Wed, 31 Aug 2005 06:57:30 +0000</pubDate>
		<dc:creator>anand</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://indrayam.com/?p=1098</guid>
		<description><![CDATA[<p>
I took the liberty of upgrading the Apache/PHP combo that was running this site. Why? Well, since I did not have good visibility into what caused the <a href="http://indrayam.com/archives/security/001094.php" target="_blank">security breach</a> last week, I decided it was time to start plugging all "potential" security holes that might exist on this box. Needless to say, it's a thankless and never-ending job. Too bad I don't get paid to do this <img src="http://indrayam.com/images/wink.gif" align="middle"> 
</p><p>
Bottomline, if the uptime of this site was somewhat erratic for the past few hours, now you know why. Your patience is much appreciated. <img src="http://indrayam.com/images/smile.gif" align="middle"> 
</p>]]></description>
			<content:encoded><![CDATA[<p>
I took the liberty of upgrading the Apache/PHP combo that was running this site. Why? Well, since I did not have good visibility into what caused the <a href="http://indrayam.com/archives/security/001094.php" target="_blank">security breach</a> last week, I decided it was time to start plugging all "potential" security holes that might exist on this box. Needless to say, it's a thankless and never-ending job. Too bad I don't get paid to do this <img src="http://indrayam.com/images/wink.gif" align="middle"> 
</p><p>
Bottomline, if the uptime of this site was somewhat erratic for the past few hours, now you know why. Your patience is much appreciated. <img src="http://indrayam.com/images/smile.gif" align="middle"> 
</p>]]></content:encoded>
			<wfw:commentRss>http://indrayam.com/archives/security/001098.php/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ugh&#8230;</title>
		<link>http://indrayam.com/archives/security/001094.php</link>
		<comments>http://indrayam.com/archives/security/001094.php#comments</comments>
		<pubDate>Fri, 26 Aug 2005 05:10:48 +0000</pubDate>
		<dc:creator>anand</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://indrayam.com/?p=1094</guid>
		<description><![CDATA[<p>
<div align="center"><a href="http://www.homestarrunner.com/systemisdown.html" target="_blank"><img src="http://indrayam.com/images/system-is-down.jpg" title="" border="1"></a></div>
</p><p>
Got an email from my <a href="http://johncompanies.com" target="_blank">ISP</a> this evening saying that things were not ok with my little "slice" (read, server) on the internet. To make a long story short, this site (and <a href="http://rajesh.induspolis.com" target="_blank">some</a> <a href="http://shephali.induspolis.com" target="_blank">other</a> <a href="http://drishtikona.com" target="_blank">sites</a> <a href="http://zyom.com" target="_blank">that</a> I manage) were all dead as a dodo for the better part of the day. My apologies. <img src="http://indrayam.com/images/sad.gif" align="middle"> 
</p><p>
Since I am pretty good about keeping this site up, here's a little tip for you guys in case something like this happens in the future. If you find this site down for more than an hour at a stretch, you can safely conclude that either me or my server is having a <i>really really</i> bad day. Fortunately (or not), this time it was not me, but my poor server. "She" had to put up with a blind and a rather bad date (read, <a href="http://www.answers.com/hacker" target="_blank">hacker</a>, or should I say <a href="http://www.answers.com/script%20kiddie" target="_blank">"script kiddie"</a>).
</p><p>
Kids...When will they grow up <img src="http://indrayam.com/images/wink.gif" align="middle"> 
</p>]]></description>
			<content:encoded><![CDATA[<p>
<div align="center"><a href="http://www.homestarrunner.com/systemisdown.html" target="_blank"><img src="http://indrayam.com/images/system-is-down.jpg" title="" border="1"></a></div>
</p><p>
Got an email from my <a href="http://johncompanies.com" target="_blank">ISP</a> this evening saying that things were not ok with my little "slice" (read, server) on the internet. To make a long story short, this site (and <a href="http://rajesh.induspolis.com" target="_blank">some</a> <a href="http://shephali.induspolis.com" target="_blank">other</a> <a href="http://drishtikona.com" target="_blank">sites</a> <a href="http://zyom.com" target="_blank">that</a> I manage) were all dead as a dodo for the better part of the day. My apologies. <img src="http://indrayam.com/images/sad.gif" align="middle"> 
</p><p>
Since I am pretty good about keeping this site up, here's a little tip for you guys in case something like this happens in the future. If you find this site down for more than an hour at a stretch, you can safely conclude that either me or my server is having a <i>really really</i> bad day. Fortunately (or not), this time it was not me, but my poor server. "She" had to put up with a blind and a rather bad date (read, <a href="http://www.answers.com/hacker" target="_blank">hacker</a>, or should I say <a href="http://www.answers.com/script%20kiddie" target="_blank">"script kiddie"</a>).
</p><p>
Kids...When will they grow up <img src="http://indrayam.com/images/wink.gif" align="middle"> 
</p>]]></content:encoded>
			<wfw:commentRss>http://indrayam.com/archives/security/001094.php/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Quote of the day&#8230;</title>
		<link>http://indrayam.com/archives/security/000984.php</link>
		<comments>http://indrayam.com/archives/security/000984.php#comments</comments>
		<pubDate>Tue, 10 May 2005 20:21:52 +0000</pubDate>
		<dc:creator>anand</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://indrayam.com/?p=984</guid>
		<description><![CDATA[<p>
<font size=+1 color=#3232cd>The fact is that software isn't secure because it's open source, it's secure because it's secure.</font><br/>
- Jon Udell, <a href="http://weblog.infoworld.com/udell/2005/05/10.html#a1230" target="_blank">"Greasemonkeying Around"</a>
</p>]]></description>
			<content:encoded><![CDATA[<p>
<font size=+1 color=#3232cd>The fact is that software isn't secure because it's open source, it's secure because it's secure.</font><br/>
- Jon Udell, <a href="http://weblog.infoworld.com/udell/2005/05/10.html#a1230" target="_blank">"Greasemonkeying Around"</a>
</p>]]></content:encoded>
			<wfw:commentRss>http://indrayam.com/archives/security/000984.php/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Want to know the default userid/password for a Hardware/Software that you may have?</title>
		<link>http://indrayam.com/archives/security/000833.php</link>
		<comments>http://indrayam.com/archives/security/000833.php#comments</comments>
		<pubDate>Mon, 06 Dec 2004 23:38:24 +0000</pubDate>
		<dc:creator>anand</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://indrayam.com/?p=833</guid>
		<description><![CDATA[[via <a href="http://kottke.org/" target="_blank">Jason Kottke</a>]
<p>
<center><img src="http://indrayam.com/images/password-foot.gif"></center>
<p>
Be my <a href="http://www.phenoelit.de/dpl/dpl.html" target="_blank">guest</a> <img src="http://indrayam.com/images/wink.gif" align="middle">]]></description>
			<content:encoded><![CDATA[[via <a href="http://kottke.org/" target="_blank">Jason Kottke</a>]
<p>
<center><img src="http://indrayam.com/images/password-foot.gif"></center>
<p>
Be my <a href="http://www.phenoelit.de/dpl/dpl.html" target="_blank">guest</a> <img src="http://indrayam.com/images/wink.gif" align="middle">]]></content:encoded>
			<wfw:commentRss>http://indrayam.com/archives/security/000833.php/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Interesting entry in my web server logs. Someone has an infected/hacked computer..:-)</title>
		<link>http://indrayam.com/archives/security/000239.php</link>
		<comments>http://indrayam.com/archives/security/000239.php#comments</comments>
		<pubDate>Thu, 03 Jun 2004 02:59:54 +0000</pubDate>
		<dc:creator>anand</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://indrayam.com/?p=239</guid>
		<description><![CDATA[<p>
Here's what I had in my <b>error_log</b>:
<pre>
[Wed Jun 02 03:30:21 2004] 
[error] [client 69.81.6.80] request failed: URI too long (longer than 8190)
</pre>
<p>
A quick nslookup gave me:
<p>
<pre>
Name:    user-12l21ig.cable.mindspring.com
Address:  69.81.6.80
</pre>
<p>
The <b>access_log</b> had the following (abbreviated version):
<p>
<pre>
69.81.6.80 - - [02/Jun/2004:03:30:21 -0400] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1
...<br/>
...<br/>
0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90" 414 437<br/>
</pre>
<p>
A quick wc -c showed that this crap goes on for <b>29231</b> characters!
<p>
Should I do something about it?
<p>
<div class="note">
<u>Update:</u><br/>
Thanks to Jason, I got this <a href="http://lists.freebsd.org/pipermail/freebsd-questions/2004-March/042170.html" target="_blank">link</a> which basically sums this entry up rather well:
<p>
"It is an IIS WebDAV exploit from April 2003 (?), apache is not affected, its just annoying :) (nachi and agobot use this exploit)"
</div>]]></description>
			<content:encoded><![CDATA[<p>
Here's what I had in my <b>error_log</b>:
<pre>
[Wed Jun 02 03:30:21 2004] 
[error] [client 69.81.6.80] request failed: URI too long (longer than 8190)
</pre>
<p>
A quick nslookup gave me:
<p>
<pre>
Name:    user-12l21ig.cable.mindspring.com
Address:  69.81.6.80
</pre>
<p>
The <b>access_log</b> had the following (abbreviated version):
<p>
<pre>
69.81.6.80 - - [02/Jun/2004:03:30:21 -0400] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\
x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1
...<br/>
...<br/>
0\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90" 414 437<br/>
</pre>
<p>
A quick wc -c showed that this crap goes on for <b>29231</b> characters!
<p>
Should I do something about it?
<p>
<div class="note">
<u>Update:</u><br/>
Thanks to Jason, I got this <a href="http://lists.freebsd.org/pipermail/freebsd-questions/2004-March/042170.html" target="_blank">link</a> which basically sums this entry up rather well:
<p>
"It is an IIS WebDAV exploit from April 2003 (?), apache is not affected, its just annoying :) (nachi and agobot use this exploit)"
</div>]]></content:encoded>
			<wfw:commentRss>http://indrayam.com/archives/security/000239.php/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
