<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Moonlight Blog &#187; security</title>
	<atom:link href="http://www.moon-blog.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.moon-blog.com</link>
	<description></description>
	<lastBuildDate>Thu, 20 May 2010 08:12:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Z-Blog URL Redirect Security Affected Spam Attacks</title>
		<link>http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html</link>
		<comments>http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html#comments</comments>
		<pubDate>Mon, 24 Nov 2008 09:28:34 +0000</pubDate>
		<dc:creator>William Long</dc:creator>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html</guid>
		<description><![CDATA[Z-Blog system contain a security issue that allows spam attack to Wikipedia by using url redirect. The design of Z-Blog anti-spam encrypts the URL before redirect it. The name of the redirected file is c_urlredirect.asp. With the parameter of this page Z-Blog kann redirect to various pages. Sorrowfully the used encryption is very simple. One [...]]]></description>
			<content:encoded><![CDATA[<p>Z-Blog system contain a security issue that allows spam attack to Wikipedia by using url redirect.</p>
<p>The design of Z-Blog anti-spam encrypts the URL before redirect it. The name of the redirected file is c_urlredirect.asp. With the parameter of this page Z-Blog kann redirect to various pages. Sorrowfully the used encryption is very simple. One just need to put the odd characters together. With this methode blackhat SEO manipulates redirects from other Z-Blog websites to call its own website. Thus even if the original address is listed on the blacklist by Wikipedia, the manipulated redirect would still work and be used as spam.</p>
<p>The solution for this problem is not easy. The most simple way is to delete c_urlredirect.asp. But this method would also prevent the blogger himself make redirects.</p>
<p><a rel="nofollow" href="http://www.williamlong.info/archives/1584.html">Source</a> . thanks for <a rel="nofollow" href="http://meta.wikimedia.org/wiki/User:Wing">Wing</a> translation</p>
<a href="http://clickserve.cc-dt.com/link/tplclick?lid=41000000026645013&pubid=21000000000198404" rel="nofollow"><img src="http://clickserve.cc-dt.com/link/tplimage?lid=41000000026645013&pubid=21000000000198404" border=0 alt="
Subscribe to The South China Morning Post Online Edition today and get 30 days FREE!!"></a>
<hr />
<p><small>© William Long for <a href="http://www.moon-blog.com">Moonlight Blog</a>, 2008. |
<a href="http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html">Permalink</a> |
<a href="http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html#comments">2 comments</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html&title=Z-Blog URL Redirect Security Affected Spam Attacks">del.icio.us</a>
<br/>
Post tags: <a href="http://www.moon-blog.com/tag/security" rel="tag">security</a><br/>
</small></p>
	<h1>Related posts</h1>
	<ul class="st-related-posts">
	<li><a href="http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html" title="MSN and Gtalk Local Password Hacking (September 20, 2008)">MSN and Gtalk Local Password Hacking</a> (0)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>MSN and Gtalk Local Password Hacking</title>
		<link>http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html</link>
		<comments>http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html#comments</comments>
		<pubDate>Sun, 21 Sep 2008 01:39:11 +0000</pubDate>
		<dc:creator>William Long</dc:creator>
				<category><![CDATA[internet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html</guid>
		<description><![CDATA[I have to tell the true that local password of MSN &#38; GTalk can be easily hacked. You can even find the local password directly by using a hack tool named MessenPass. This means it is high risky if you save the password of MSN or GTalk in the local PC. MessenPass can be used [...]]]></description>
			<content:encoded><![CDATA[<p>I have to tell the true that local password of MSN &amp; GTalk can be easily hacked. You can even find the local password directly by using a hack tool named MessenPass. This means it is high risky if you save the password of MSN or GTalk in the local PC.</p>
<p>MessenPass can be used to get the passwords for the current logged-on user on your local computer, and it works if you chose the remember your password in one of the above programs.</p>
<p>Password hashing is a way of encrypting a password before it&#8217;s stored so that if local computer gets into the wrong hands, the damage is limited. Hashing is nothing new &#8211; it&#8217;s been in use in Unix system password files since long before my time, and quite probably in other systems long before that.</p>
<p>A hash (also called a hash code, digest, or message digest) can be thought of as the digital fingerprint of a piece of data. You can easily generate a fixed length hash for any text string using a one-way mathematical process. It is next to impossible to (efficiently) recover the original text from a hash alone. It is also vastly unlikely that any different text string will give you an identical hash &#8211; a &#8216;hash collision&#8217;. These properties make hashes ideally suited for storing your application&#8217;s passwords. Why? Because although an attacker may compromise a part of your system and reveal your list of password hashes, they can&#8217;t determine from the hashes alone what the real passwords are.</p>
<p>We&#8217;ve established that it&#8217;s incredibly difficult to recover the original password from a hash, so how will the application know if a user has entered the correct password or not? Quite simply &#8211; by generating a hash of the user-supplied password and comparing this &#8216;fingerprint&#8217; with the hash stored in your user profile, you&#8217;ll know whether or not the passwords match.</p>
<a href="http://clickserve.cc-dt.com/link/tplclick?lid=41000000026645013&pubid=21000000000198404" rel="nofollow"><img src="http://clickserve.cc-dt.com/link/tplimage?lid=41000000026645013&pubid=21000000000198404" border=0 alt="
Subscribe to The South China Morning Post Online Edition today and get 30 days FREE!!"></a>
<hr />
<p><small>© William Long for <a href="http://www.moon-blog.com">Moonlight Blog</a>, 2008. |
<a href="http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html">Permalink</a> |
<a href="http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html#comments">No comment</a> |
Add to
<a href="http://del.icio.us/post?url=http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html&title=MSN and Gtalk Local Password Hacking">del.icio.us</a>
<br/>
Post tags: <a href="http://www.moon-blog.com/tag/security" rel="tag">security</a><br/>
</small></p>
	<h1>Related posts</h1>
	<ul class="st-related-posts">
	<li><a href="http://www.moon-blog.com/2008/11/z-blog-url-redirect-security-affected-spam-attacks.html" title="Z-Blog URL Redirect Security Affected Spam Attacks (November 24, 2008)">Z-Blog URL Redirect Security Affected Spam Attacks</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.moon-blog.com/2008/09/msn-and-gtalk-local-password-hacking.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
