<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Guymon &#187; Security</title>
	<atom:link href="http://www.guymon.de/wordpress/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.guymon.de/wordpress</link>
	<description>Unwissenheit ist Stärke
</description>
	<lastBuildDate>Wed, 08 Feb 2012 12:28:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>NSA: Security Configuration&#160;Guides</title>
		<link>http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/</link>
		<comments>http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/#comments</comments>
		<pubDate>Fri, 20 May 2011 07:14:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Mac OS X]]></category>
		<category><![CDATA[Privatsphäre]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[nsa]]></category>
		<category><![CDATA[os x]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=6076</guid>
		<description><![CDATA[Ich hatte mir vor einigen Jahren schon mal die NSA Vorschl&#228;ge f&#252;r sichere Computer Konfiguration angesehen und gerade entdeckt, dass die Vorschl&#228;ge weiterhin aktualisiert werden. Es gibt unter anderem: Hardening Tips for MAC OS X 10.6 Snow Leopard und Security Highlights of Windows 7 Possibly related posts (automatically generated)daily linksMac OS X vulnerabilitySandboxed SafariDisable ssh [...]]]></description>
			<content:encoded><![CDATA[<p>Ich hatte mir vor einigen Jahren schon mal die NSA Vorschl&#228;ge f&#252;r sichere Computer Konfiguration angesehen und gerade entdeckt, dass die Vorschl&#228;ge weiterhin <a href="http://www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml">aktualisiert</a> werden.</p>
<p>Es gibt unter anderem: <a href="http://www.nsa.gov/ia/_files/factsheets/macosx_10_6_hardeningtips.pdf" title="pdf">Hardening Tips for MAC OS X 10.6 Snow Leopard</a> und <a href="http://www.nsa.gov/ia/_files/os/win7/win7_security_highlights.pdf" title="pdf">Security Highlights of Windows 7</a> </p><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2010/11/29/daily-links-203/" title="daily links">daily links</a></li><li><a href="http://www.guymon.de/wordpress/2009/01/25/mac-os-x-vulnerability/" title="Mac OS X vulnerability">Mac OS X vulnerability</a></li><li><a href="http://www.guymon.de/wordpress/2009/01/05/sandboxed-safari/" title="Sandboxed Safari">Sandboxed Safari</a></li><li><a href="http://www.guymon.de/wordpress/2008/10/18/disable-ssh-access-for-password-guessing-bots/" title="Disable ssh access for password-guessing bots">Disable ssh access for password-guessing bots</a></li><li><a href="http://www.guymon.de/wordpress/2008/06/25/find-personal-data/" title="Find Personal Data">Find Personal Data</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Basic Internet&#160;Security</title>
		<link>http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/</link>
		<comments>http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/#comments</comments>
		<pubDate>Mon, 09 May 2011 10:31:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Privatsphäre]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=6053</guid>
		<description><![CDATA[Basic Internet Security via Floss Manuals: When verbally passing a message you usually need to know your contact persons to know if you can trust them, but you also have to know your technology a little to know if you can trust it. Technologies can leak or distort your message just as humans can. Technologies [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.flossmanuals.net/basic-internet-security/index/">Basic Internet Security</a> via Floss Manuals:</p>
<blockquote cite="http://en.flossmanuals.net/basic-internet-security/index/"><p>When verbally passing a message you usually need to know your contact persons to know if you can trust them, but you also have to know your technology a little to know if you can trust it. Technologies can leak or distort your message just as humans can. Technologies are invested in types of trust relations: some devices are safer than others, some can be modified, and some are better avoided. </p>
<p>This book tries to address these different layers by giving hands-on explanations on how to make your digital communication and data more secure and by providing the reader with a basic understanding of the concepts of digital communication and data security. It derives from the following principles:</p>
<ol>
<li>No method is entirely secure;
</li>
<li>You need to have a basic understanding on how and why technology works to make it work for you;
</li>
<li>You need technology for safer communication: either some basic tools, or more sophisticated equipment, depending on where you&#8217;re at and where you go.</li>
</ol>
</blockquote><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/23/off-the-grid-password-generator/" title="Off The Grid Password Generator">Off The Grid Password Generator</a></li><li><a href="http://www.guymon.de/wordpress/2011/09/21/browser-exploit-against-ssltls/" title="Browser Exploit Against SSL/TLS">Browser Exploit Against SSL/TLS</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/" title="NSA: Security Configuration Guides">NSA: Security Configuration Guides</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/06/website-security/" title="Website Security">Website Security</a></li><li><a href="http://www.guymon.de/wordpress/2011/03/21/gesprachs-rekonstruktion-aus-verschlusselten-voip-paketen/" title="Gesprächs-Rekonstruktion aus verschlüsselten VoIP Paketen">Gesprächs-Rekonstruktion aus verschlüsselten VoIP Paketen</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Einbruch bei&#160;LastPass?</title>
		<link>http://www.guymon.de/wordpress/2011/05/06/einbruch-bei-lastpass/</link>
		<comments>http://www.guymon.de/wordpress/2011/05/06/einbruch-bei-lastpass/#comments</comments>
		<pubDate>Fri, 06 May 2011 08:06:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Kryptographie]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=6048</guid>
		<description><![CDATA[Ups… &#8220;Anomalien im Netzwerkverkehr&#8221; der Datenbanken des Passwortspeicherdienstes LastPass lassen den Dienstleister vermuten, dass unter Umst&#228;nden Einbrecher an vertrauliche Informationen gelangt sind – darunter m&#246;glicherweise einige Masterpassw&#246;rter von Kunden. Desktop L&#246;sungen wie KeePass oder 1Password sind eventuell doch sinnvoller, und man braucht weniger Vertrauen den den Online Dienstleiter.Possibly related posts (automatically generated)Off The Grid Password [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.heise.de/security/meldung/Moeglicher-Einbruch-bei-Passwortspeicherdienst-LastPass-1237975.html">Ups</a>…</p>
<blockquote cite="http://www.heise.de/security/meldung/Moeglicher-Einbruch-bei-Passwortspeicherdienst-LastPass-1237975.html"><p>&#8220;Anomalien im Netzwerkverkehr&#8221; der Datenbanken des Passwortspeicherdienstes LastPass lassen den Dienstleister vermuten, dass unter Umst&#228;nden Einbrecher an vertrauliche Informationen gelangt sind – darunter m&#246;glicherweise einige Masterpassw&#246;rter von Kunden.</p>
</blockquote>
<p>Desktop L&#246;sungen wie <a href="http://keepass.info/">KeePass</a> oder <a href="http://agilebits.com/onepassword">1Password</a> sind eventuell doch sinnvoller, und man braucht weniger Vertrauen den den Online Dienstleiter.</p><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/23/off-the-grid-password-generator/" title="Off The Grid Password Generator">Off The Grid Password Generator</a></li><li><a href="http://www.guymon.de/wordpress/2011/01/20/firefox-passwoerter-aus-bildern-oder-text-erstellen/" title="Firefox: Passwörter aus Bildern oder Text erstellen">Firefox: Passwörter aus Bildern oder Text erstellen</a></li><li><a href="http://www.guymon.de/wordpress/2010/07/31/password-manager-fuer-alle-situationen/" title="Password Manager für alle Situationen">Password Manager für alle Situationen</a></li><li><a href="http://www.guymon.de/wordpress/2010/07/15/password-strength-checker/" title="Password Strength Checker ">Password Strength Checker </a></li><li><a href="http://www.guymon.de/wordpress/2010/05/21/1password-fuer-chrome/" title="1Password für Chrome">1Password für Chrome</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/05/06/einbruch-bei-lastpass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website&#160;Security</title>
		<link>http://www.guymon.de/wordpress/2011/05/06/website-security/</link>
		<comments>http://www.guymon.de/wordpress/2011/05/06/website-security/#comments</comments>
		<pubDate>Fri, 06 May 2011 07:22:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[SQL-Injection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=6047</guid>
		<description><![CDATA[Ein &#8220;Schnupperkurs&#8221; in Sachen Website Security gibt es im Webmaster Central Blog: Today we’ll show you some examples of how a web application can be exploited so you can learn from them; for this we’ll use Gruyere, an intentionally vulnerable application we use for security training internally, too. Do not probe others’ websites for vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>Ein &#8220;<a href="http://googlewebmastercentral.blogspot.com/2011/05/website-security-for-webmasters.html">Schnupperkurs</a>&#8221; in Sachen Website Security gibt es im Webmaster Central Blog:</p>
<blockquote cite="http://googlewebmastercentral.blogspot.com/2011/05/website-security-for-webmasters.html"><p>Today we’ll show you some examples of how a web application can be exploited so you can learn from them; for this we’ll use <a href="http://google-gruyere.appspot.com/">Gruyere</a>, an intentionally vulnerable application we use for security training internally, too. Do not probe others’ websites for vulnerabilities without permission as it may be perceived as hacking; but you’re welcome—nay, encouraged—to run tests on Gruyere.</p>
</blockquote><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2010/01/24/website-security-basics/" title="Website Security Basics">Website Security Basics</a></li><li><a href="http://www.guymon.de/wordpress/2010/05/06/web-application-exploits-and-defenses/" title="Web Application Exploits and Defenses ">Web Application Exploits and Defenses </a></li><li><a href="http://www.guymon.de/wordpress/2009/10/20/webscarab-paros-tutorial/" title="WebScarab, Paros Tutorial">WebScarab, Paros Tutorial</a></li><li><a href="http://www.guymon.de/wordpress/2009/05/13/xss/" title="XSS">XSS</a></li><li><a href="http://www.guymon.de/wordpress/2009/03/27/xss-rays/" title="XSS Rays">XSS Rays</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/05/06/website-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenPGP Encryption in&#160;JavaScript</title>
		<link>http://www.guymon.de/wordpress/2011/03/22/openpgp-encryption-in-javascript/</link>
		<comments>http://www.guymon.de/wordpress/2011/03/22/openpgp-encryption-in-javascript/#comments</comments>
		<pubDate>Tue, 22 Mar 2011 08:26:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Javascript]]></category>
		<category><![CDATA[Kryptographie]]></category>
		<category><![CDATA[Privatsphäre]]></category>
		<category><![CDATA[Programmierung]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[pgp]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=5917</guid>
		<description><![CDATA[OpenPGP Encryption in JavaScript Public key encryption in Javascript encrypts form data at the client side for the whole transfer from sender to the final receiver. Form data can be transferred without using an SSL connection and is stored encrypted on the server. Only the final receiver can decrypt it. Sicherlich nicht f&#252;r jeden Einsatz [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hanewin.net/encrypt/">OpenPGP Encryption in JavaScript </a></p>
<blockquote cite="http://www.hanewin.net/encrypt/"><p>Public key encryption in Javascript encrypts form data at the client side for the whole transfer from sender to the final receiver. Form data can be transferred without using an SSL connection and is stored encrypted on the server. Only the final receiver can decrypt it. </p>
</blockquote>
<p>Sicherlich nicht f&#252;r jeden Einsatz sinnvoll, aber trotzdem sehr spannend!</p><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2012/02/08/turn-js/" title="turn.js">turn.js</a></li><li><a href="http://www.guymon.de/wordpress/2012/01/14/prasentationen-mit-impress-js/" title="Präsentationen mit impress.js">Präsentationen mit impress.js</a></li><li><a href="http://www.guymon.de/wordpress/2011/12/02/performance-delayed-content/" title="Performance: Delayed Content">Performance: Delayed Content</a></li><li><a href="http://www.guymon.de/wordpress/2011/11/04/alicejs/" title="AliceJS">AliceJS</a></li><li><a href="http://www.guymon.de/wordpress/2011/11/01/interaktive-webseiten-mit-tangle/" title="Interaktive Webseiten mit Tangle">Interaktive Webseiten mit Tangle</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/03/22/openpgp-encryption-in-javascript/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enable https on&#160;twitter</title>
		<link>http://www.guymon.de/wordpress/2011/03/16/enable-https-on-twitter/</link>
		<comments>http://www.guymon.de/wordpress/2011/03/16/enable-https-on-twitter/#comments</comments>
		<pubDate>Wed, 16 Mar 2011 08:09:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Privatsphäre]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=5904</guid>
		<description><![CDATA[Twitter erlaubt es nun alle Verbindungen &#252;ber https laufen zu lassen. Go to your Twitter settings page. Tick the Always use HTTPS checkbox. Click Save and re-enter your password when prompted. Possibly related posts (automatically generated)Off The Grid Password GeneratorBrowser Exploit Against SSL/TLSNSA: Security Configuration GuidesBasic Internet Security Website Security]]></description>
			<content:encoded><![CDATA[<p>Twitter <a href="http://lifehacker.com/#!5782300/enable-the-https-setting-in-your-twitter-account-now-for-improved-security">erlaubt</a> es nun alle Verbindungen &#252;ber https laufen zu lassen.</p>
<ol>
<li>Go to <a href="https://twitter.com/settings/account">your Twitter settings page</a>.</li>
<li>Tick the Always use HTTPS checkbox.</li>
<li>Click Save and re-enter your password when prompted.</li>
</ol><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/23/off-the-grid-password-generator/" title="Off The Grid Password Generator">Off The Grid Password Generator</a></li><li><a href="http://www.guymon.de/wordpress/2011/09/21/browser-exploit-against-ssltls/" title="Browser Exploit Against SSL/TLS">Browser Exploit Against SSL/TLS</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/" title="NSA: Security Configuration Guides">NSA: Security Configuration Guides</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/" title="Basic Internet Security ">Basic Internet Security </a></li><li><a href="http://www.guymon.de/wordpress/2011/05/06/website-security/" title="Website Security">Website Security</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/03/16/enable-https-on-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wipe clean&#160;SSDs</title>
		<link>http://www.guymon.de/wordpress/2011/03/02/wipe-clean-ssds/</link>
		<comments>http://www.guymon.de/wordpress/2011/03/02/wipe-clean-ssds/#comments</comments>
		<pubDate>Wed, 02 Mar 2011 10:34:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Computer]]></category>
		<category><![CDATA[Privatsphäre]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[recovery]]></category>
		<category><![CDATA[ssd]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=5859</guid>
		<description><![CDATA[&#220;ber das &#8220;richtige&#8221; L&#246;schen von Daten wurde ja schon viel geschrieben, jetzt haben sich Forscher der University of California in San Diego mal die Ergebnisse der &#252;blichen Methoden bei SSDs angesehen: The researchers found that as much 67 percent of data stored in a file remained even after it was deleted from an SSD using [...]]]></description>
			<content:encoded><![CDATA[<p>&#220;ber das &#8220;richtige&#8221; L&#246;schen von Daten wurde ja schon viel geschrieben, jetzt haben sich Forscher der University of California in San Diego mal die Ergebnisse der &#252;blichen Methoden bei SSDs <a href="http://www.theregister.co.uk/2011/02/21/flash_drive_erasing_peril/">angesehen</a>:</p>
<blockquote cite="http://www.theregister.co.uk/2011/02/21/flash_drive_erasing_peril/"><p>The researchers found that as much 67 percent of data stored in a file remained even after it was deleted from an SSD using the secure erase feature offered by Apple&#8217;s Mac OS X. Other overwrite operations – which securely delete files by repeatedly rewriting the data stored in a particular disk location – failed by similarly large margins when used to erase a single file on an SSD. Pseudorandom Data operations, for instance, allowed as much as 75 percent of data to remain, while the British HMG IS5 technique allowed as much as 58 percent.</p>
</blockquote>
<p>Eine (naheligende) L&#246;sung:</p>
<blockquote cite="http://www.theregister.co.uk/2011/02/21/flash_drive_erasing_peril/"><p>The researchers found the most effective way to sanitize data on SSDs was to use devices that encrypted their contents. Wiping happens by deleting the encryption keys from what&#8217;s known as the key store, effectively ensuring that the data will remain encrypted forever.</p>
</blockquote><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/23/off-the-grid-password-generator/" title="Off The Grid Password Generator">Off The Grid Password Generator</a></li><li><a href="http://www.guymon.de/wordpress/2011/09/21/browser-exploit-against-ssltls/" title="Browser Exploit Against SSL/TLS">Browser Exploit Against SSL/TLS</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/" title="NSA: Security Configuration Guides">NSA: Security Configuration Guides</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/" title="Basic Internet Security ">Basic Internet Security </a></li><li><a href="http://www.guymon.de/wordpress/2011/05/06/website-security/" title="Website Security">Website Security</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/03/02/wipe-clean-ssds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Embed a TrueCrypt Volume Video&#160;File</title>
		<link>http://www.guymon.de/wordpress/2011/02/27/embed-a-truecrypt-volume-video-file/</link>
		<comments>http://www.guymon.de/wordpress/2011/02/27/embed-a-truecrypt-volume-video-file/#comments</comments>
		<pubDate>Sun, 27 Feb 2011 17:15:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Kryptographie]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[steganography]]></category>
		<category><![CDATA[TrueCrypt]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=5852</guid>
		<description><![CDATA[lifehacker erkl&#228;rt wie man ein TrueCrypt Volume in einem (abspielbaren) Video versteckt. Cool Stuff! First you need a suitable mp4 file to hide your TrueCrypt container. (…) Really any mp4 file will do, but try to find a file that matches the proportional size of the container you are going to create. Once you have [...]]]></description>
			<content:encoded><![CDATA[<p>lifehacker <a href="http://lifehacker.com/#!5771142/embed-a-truecrypt-volume-in-a-playable-video-file">erkl&#228;rt</a> wie man ein TrueCrypt Volume in einem (abspielbaren) Video versteckt. Cool Stuff!</p>
<blockquote cite="http://lifehacker.com/#!5771142/embed-a-truecrypt-volume-in-a-playable-video-file"><p>First you need a suitable mp4 file to hide your TrueCrypt container. (…) Really any mp4 file will do, but try to find a file that matches the proportional size of the container you are going to create. Once you have your video file, create a TrueCrypt container. Use the &#8220;Hidden Container&#8221; option, this generates a container-inside-a-container. (…) Now that you have your two files, the magic happens. <a href="http://keyj.s2000.at/">Martin Fiedler</a>, a software engineer from Germany, created a Python script named <a href="http://keyj.s2000.at/files/tcsteg.py">tcsteg.py</a> that will now merge these two files together. Execute &#8220;python tcsteg.py Movie.mp4 NameOfTrueCryptVolume.mp4&#8221; from a command line to make the merge.</p>
</blockquote><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/03/stegobot/" title="Stegobot">Stegobot</a></li><li><a href="http://www.guymon.de/wordpress/2010/08/27/social-steganography/" title="Social Steganography">Social Steganography</a></li><li><a href="http://www.guymon.de/wordpress/2009/07/25/hiding-files-in-pdf-documents/" title="Hiding Files in PDF Documents">Hiding Files in PDF Documents</a></li><li><a href="http://www.guymon.de/wordpress/2009/07/02/steganography-tools/" title="Steganography Tools">Steganography Tools</a></li><li><a href="http://www.guymon.de/wordpress/2009/06/03/steganography-3/" title="Steganography">Steganography</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/02/27/embed-a-truecrypt-volume-video-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Socialnetwork&#160;Security</title>
		<link>http://www.guymon.de/wordpress/2011/02/22/socialnetwork-security/</link>
		<comments>http://www.guymon.de/wordpress/2011/02/22/socialnetwork-security/#comments</comments>
		<pubDate>Tue, 22 Feb 2011 07:38:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Social-networks]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=5839</guid>
		<description><![CDATA[socialnetworksecurity.org ver&#246;ffentlicht Sicherheitsl&#252;cken in Sozial Netzwerken. Diese Webseite wurde gegruendet, um Sicherheitsluecken auf Social Network Portalen aufzuzeigen. Der Autor hat in der Vergangenheit vergeblich versucht die entsprechenden Social Networking Betreiber zu kontaktieren, wurde dabei jedoch oftmals mit unzureichender Security Awareness seitens der &#8220;Ticketbearbeiter&#8221; enttaeuscht. (&#8230;) Diese Webseite soll entsprechend die Augen der Verbraucher oeffnen und [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://socialnetworksecurity.org/">socialnetworksecurity.org</a> ver&#246;ffentlicht Sicherheitsl&#252;cken in Sozial Netzwerken.</p>
<blockquote cite="http://socialnetworksecurity.org/"><p>Diese Webseite wurde gegruendet, um Sicherheitsluecken auf Social Network Portalen aufzuzeigen.<br />
Der Autor hat in der Vergangenheit vergeblich versucht die entsprechenden Social Networking Betreiber zu kontaktieren, wurde dabei jedoch oftmals mit unzureichender Security Awareness seitens der &#8220;Ticketbearbeiter&#8221; enttaeuscht. (&#8230;) Diese Webseite soll entsprechend die Augen der Verbraucher oeffnen und durch das Aufdecken von Sicherheitsluecken auf Social-Network Seiten dazu beitragen, dass die Betreiber aktiv reagieren und die entsprechenden Sicherheitsluecken zeitnah schliessen. Die Praxis zeigt das medialer Druck auf die Betreiber einiges bewirken kann&#8230;. </p>
</blockquote><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/23/off-the-grid-password-generator/" title="Off The Grid Password Generator">Off The Grid Password Generator</a></li><li><a href="http://www.guymon.de/wordpress/2011/09/21/browser-exploit-against-ssltls/" title="Browser Exploit Against SSL/TLS">Browser Exploit Against SSL/TLS</a></li><li><a href="http://www.guymon.de/wordpress/2011/07/19/anonplus/" title="AnonPlus">AnonPlus</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/" title="NSA: Security Configuration Guides">NSA: Security Configuration Guides</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/" title="Basic Internet Security ">Basic Internet Security </a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/02/22/socialnetwork-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Silently determine Login&#160;Status</title>
		<link>http://www.guymon.de/wordpress/2011/02/03/silently-determine-login-status/</link>
		<comments>http://www.guymon.de/wordpress/2011/02/03/silently-determine-login-status/#comments</comments>
		<pubDate>Thu, 03 Feb 2011 22:04:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.guymon.de/wordpress/?p=5784</guid>
		<description><![CDATA[Mike Cardwell zeigt wie sich via JavaScript feststellen l&#228;sst ob jemand bei Facebook, twitter, … angemeldet ist: When you visit my website, I can automatically and silently determine if you&#8217;re logged into Facebook, Twitter, GMail and Digg. There are almost certainly thousands of other sites with this issue too, but I picked a few vulnerable [...]]]></description>
			<content:encoded><![CDATA[<p>Mike Cardwell <a href="https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Private_Information">zeigt</a> wie sich via JavaScript feststellen l&#228;sst ob jemand bei Facebook, twitter, … angemeldet ist:</p>
<blockquote cite="https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Private_Information"><p>When you visit my website, I can automatically and silently determine if you&#8217;re logged into Facebook, Twitter, GMail and Digg. There are almost certainly thousands of other sites with this issue too, but I picked a few vulnerable well known ones to get your attention. You may not care that I can tell you&#8217;re logged into GMail, but would you care if I could tell you&#8217;re logged into one or more porn or warez sites? Perhaps http://oppressive-regime.example.org/ would like to collect a list of their users who are logged into http://controversial-website.example.com/?</p>
</blockquote>
<p>Das l&#228;sst sich nat&#252;rlich auch halbwegs sinnvoll nutzen, z.B. um mailto: Links durch einen Gmail Compose Links zu ersetzen:</p>
<pre class="prettyprint">$(&#x27;&lt;img/&gt;&#x27;).hide()
 .attr(&#x27;src&#x27;,&#x27;https://mail.google.com/mail/photos/static/AD34hIhNx1pdsCxEpo6LavSR8dYSmSi0KTM1pGxAjRio47pofmE9RH7bxPwelO8tlvpX3sbYkNfXT7HDAZJM_uf5qU2cvDJzlAWxu7-jaBPbDXAjVL8YGpI&#x27;)
 .load(function(){
 $(&#x27;a[href^=&quot;mailto:&quot;]&#x27;).each(function(){
 var email = $(this).attr(&#x27;href&#x27;).replace(/^mailto:/,&#x27;&#x27;);
 $(this).attr(&#x27;href&#x27;,&#x27;https://mail.google.com/mail/?view=cm&amp;fs=1&amp;tf=0&amp;to=&#x27;+escape(email));
 });
 })
 .appendTo(&#x27;body&#x27;);</pre><h3  class="related_post_title">Possibly related posts (automatically generated)</h3><ul class="related_post"><li><a href="http://www.guymon.de/wordpress/2011/09/23/off-the-grid-password-generator/" title="Off The Grid Password Generator">Off The Grid Password Generator</a></li><li><a href="http://www.guymon.de/wordpress/2011/09/21/browser-exploit-against-ssltls/" title="Browser Exploit Against SSL/TLS">Browser Exploit Against SSL/TLS</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/20/nsa-security-configuration-guides/" title="NSA: Security Configuration Guides">NSA: Security Configuration Guides</a></li><li><a href="http://www.guymon.de/wordpress/2011/05/09/basic-internet-security/" title="Basic Internet Security ">Basic Internet Security </a></li><li><a href="http://www.guymon.de/wordpress/2011/05/06/website-security/" title="Website Security">Website Security</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.guymon.de/wordpress/2011/02/03/silently-determine-login-status/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced

Served from: www.guymon.de @ 2012-02-08 21:23:51 -->
