<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-647648746783162534.comments</id><updated>2009-09-19T08:18:49.682-07:00</updated><title type='text'>Boken's Blog</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://boken00.blogspot.com/feeds/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/comments/default'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/comments/default?start-index=26&amp;max-results=25'/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>40</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-3712724762061088595</id><published>2009-09-19T08:18:49.682-07:00</published><updated>2009-09-19T08:18:49.682-07:00</updated><title type='text'>Hola!!

La verdad es que nos tomamos un descanso y...</title><content type='html'>Hola!!&lt;br /&gt;&lt;br /&gt;La verdad es que nos tomamos un descanso y aprovechamos para investigar otros temas, que tu ya sabes ;D. No obstante a la pre-release le quedaban 2 cositas tontas.&lt;br /&gt;&lt;br /&gt;Por mi parte, en cuanto me asiente en mi nuevo trabajo estas 2 semanas, retomaremos el tema con fuerza.&lt;br /&gt;&lt;br /&gt;Gracias por tu interes.&lt;br /&gt;Saludos.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/175441872150336552/comments/default/3712724762061088595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/175441872150336552/comments/default/3712724762061088595'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/08/web-del-proyecto-eew.html?showComment=1253373529682#c3712724762061088595' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/08/web-del-proyecto-eew.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-175441872150336552' source='http://www.blogger.com/feeds/647648746783162534/posts/default/175441872150336552' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-5474353275034935440</id><published>2009-09-09T06:22:46.260-07:00</published><updated>2009-09-09T06:22:46.260-07:00</updated><title type='text'>Hola Ruben!, 

Hay alguna novedad con respecto al ...</title><content type='html'>Hola Ruben!, &lt;br /&gt;&lt;br /&gt;Hay alguna novedad con respecto al EEW?.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/175441872150336552/comments/default/5474353275034935440'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/175441872150336552/comments/default/5474353275034935440'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/08/web-del-proyecto-eew.html?showComment=1252502566260#c5474353275034935440' title=''/><author><name>+NCR/CRC! [ReVeRsEr]</name><uri>http://www.blogger.com/profile/04319168277281996009</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/08/web-del-proyecto-eew.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-175441872150336552' source='http://www.blogger.com/feeds/647648746783162534/posts/default/175441872150336552' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-3662032783519148594</id><published>2009-08-05T11:31:23.347-07:00</published><updated>2009-08-05T11:31:23.347-07:00</updated><title type='text'>Grosos!!!</title><content type='html'>Grosos!!!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/3662032783519148594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/3662032783519148594'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html?showComment=1249497083347#c3662032783519148594' title=''/><author><name>tena</name><uri>http://www.blogger.com/profile/07497129275663687683</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2962154144415661154' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2962154144415661154' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-8464111690895165756</id><published>2009-08-05T07:08:04.459-07:00</published><updated>2009-08-05T07:08:04.459-07:00</updated><title type='text'>Muy bueno!!! Felicitaciones a los dos!!!.</title><content type='html'>Muy bueno!!! Felicitaciones a los dos!!!.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/8464111690895165756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/8464111690895165756'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html?showComment=1249481284459#c8464111690895165756' title=''/><author><name>+NCR/CRC! [ReVeRsEr]</name><uri>http://www.blogger.com/profile/04319168277281996009</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2962154144415661154' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2962154144415661154' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-8960167559054750468</id><published>2009-08-05T03:51:47.382-07:00</published><updated>2009-08-05T03:51:47.382-07:00</updated><title type='text'>Y lo que queda.... Muchas gracias!!</title><content type='html'>Y lo que queda.... Muchas gracias!!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/8960167559054750468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/8960167559054750468'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html?showComment=1249469507382#c8960167559054750468' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2962154144415661154' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2962154144415661154' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-1041285491802785543</id><published>2009-08-05T03:38:43.858-07:00</published><updated>2009-08-05T03:38:43.858-07:00</updated><title type='text'>Grosos!!!, los exploits no son lo mio pero se ve e...</title><content type='html'>Grosos!!!, los exploits no son lo mio pero se ve el trabajo duro que han hecho los 2, ¡¡los felicito!! :).&lt;br /&gt;&lt;br /&gt;salu2</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/1041285491802785543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2962154144415661154/comments/default/1041285491802785543'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html?showComment=1249468723858#c1041285491802785543' title=''/><author><name>AmeRiK@nO</name><uri>http://www.blogger.com/profile/12633023812736391713</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/08/del-crash-al-exploit-golpe-de-click.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2962154144415661154' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2962154144415661154' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-8436315352943469545</id><published>2009-06-09T01:06:18.750-07:00</published><updated>2009-06-09T01:06:18.750-07:00</updated><title type='text'>Es extraño, ¿en que fichero te dice que esta infec...</title><content type='html'>Es extraño, ¿en que fichero te dice que esta infectado?&lt;br /&gt;&lt;br /&gt;El .rar solo contiene 2 ficheros .reg, 2 capturas de ethereal y el .doc con el tutorial.&lt;br /&gt;&lt;br /&gt;Es posible que el avast detecte los .reg como virus, pero no lo son, estan hecho por +NCR para poder seguir el tutorial.&lt;br /&gt;&lt;br /&gt;Puedes descargarlo sin problemas.&lt;br /&gt;Saludos.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/3767509794737571121/comments/default/8436315352943469545'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/3767509794737571121/comments/default/8436315352943469545'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/12/desarrollo-de-exploits-con-metasploit-3.html?showComment=1244534778750#c8436315352943469545' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/12/desarrollo-de-exploits-con-metasploit-3.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-3767509794737571121' source='http://www.blogger.com/feeds/647648746783162534/posts/default/3767509794737571121' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-6130475143806120218</id><published>2009-06-01T17:52:03.430-07:00</published><updated>2009-06-01T17:52:03.430-07:00</updated><title type='text'>buenas; al descargar el archivo el avast me dice q...</title><content type='html'>buenas; al descargar el archivo el avast me dice que es un virus y no puedo bajarlo.&lt;br /&gt;&lt;br /&gt;Verifica si tiene virus.&lt;br /&gt;&lt;br /&gt;Gracias,.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/3767509794737571121/comments/default/6130475143806120218'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/3767509794737571121/comments/default/6130475143806120218'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/12/desarrollo-de-exploits-con-metasploit-3.html?showComment=1243903923430#c6130475143806120218' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/12/desarrollo-de-exploits-con-metasploit-3.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-3767509794737571121' source='http://www.blogger.com/feeds/647648746783162534/posts/default/3767509794737571121' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-3565619465389006632</id><published>2009-06-01T17:48:04.933-07:00</published><updated>2009-06-01T17:48:04.933-07:00</updated><title type='text'>te felicito, podrias revisar el enlace que no pued...</title><content type='html'>te felicito, podrias revisar el enlace que no puedo descargarlo.&lt;br /&gt;&lt;br /&gt;gracias.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/3565619465389006632'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/3565619465389006632'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1243903684933#c3565619465389006632' title=''/><author><name>Anonymous</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-2186526507883718840</id><published>2009-05-17T17:11:00.000-07:00</published><updated>2009-05-17T17:11:00.000-07:00</updated><title type='text'>Muy bueno el laburo que venis haciendo relacionado...</title><content type='html'>Muy bueno el laburo que venis haciendo relacionado con los exploits!, me gusta mucho!. Felicitaciones!.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/2186526507883718840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/2186526507883718840'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1242605460000#c2186526507883718840' title=''/><author><name>+NCR/CRC! [ReVeRsEr]</name><uri>http://www.blogger.com/profile/04319168277281996009</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-7890169065019241002</id><published>2009-04-01T07:53:00.000-07:00</published><updated>2009-04-01T07:53:00.000-07:00</updated><title type='text'>Bueno Boken, creo ue el problema es que la funcion...</title><content type='html'>Bueno Boken, creo ue el problema es que la funcion vulnerable se encuentra en una dll, y estas mo las comprueba a no ser que carge la dll y no el ejecutable.&lt;BR/&gt;&lt;BR/&gt;Me lo puedes confirmar?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/7890169065019241002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/7890169065019241002'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1238597580000#c7890169065019241002' title=''/><author><name>yibam</name><uri>http://www.blogger.com/profile/14863821985169075057</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-5884832610992664641</id><published>2009-03-31T06:28:00.000-07:00</published><updated>2009-03-31T06:28:00.000-07:00</updated><title type='text'>Hola Boken, Te escribo aqui porque no se como pill...</title><content type='html'>Hola Boken, Te escribo aqui porque no se como pillarte, je je je.&lt;BR/&gt; &lt;BR/&gt;Tengo una duda conceptual, a ver si me la puedes aclarar, asi como si este no es el mejor medio para comunicarnos dime como lo podemos hacer. (sin ninguna obligacion, je je).&lt;BR/&gt;&lt;BR/&gt;Bueno ya tengo el IDA y el Bindiff y las dos versiones de VLC a comparar, la 0.8.6b y 0.8.6c, ademas se perfectamente donde esta la vulnerabilidad ...&lt;BR/&gt;&lt;BR/&gt;Bueno, he seguido tu tute (te vuelvo a repetir que es excelente la idea de seleccion de los unmatched, plas plas (aplausos)), y me encuentro que evidentemente en el exe no hay apenas funciones modifiadas ya que la funcion vulnerable se encuentra en un modulo que se carga cuando cargas un fichero, por lo que entiendo que ese modulo no se esta comparando ya que no me sale ...&lt;BR/&gt;&lt;BR/&gt;Aunque no puede ser, ya que cuando se carga el ejecutable se cargan en memoria todas sus dlls, arrgg pues hay algo mal, ya que solo me sale una funcion a comparar y no es la vulnerable ... &lt;BR/&gt;&lt;BR/&gt;Se que casca en _vsnprintf() y su wrapper es vasprintf pero no me sale ...&lt;BR/&gt;&lt;BR/&gt;No se, te cuento los pasos:&lt;BR/&gt;&lt;BR/&gt;1. Intsale el VLC vulnerable lo abri con IDA y creo su idb.&lt;BR/&gt;2. Lo desinstale e instale el "posible" no vulnerable.&lt;BR/&gt;3. La carge con IDA ejecute el plugging Bindiff y ...&lt;BR/&gt;&lt;BR/&gt;La verdad es que el orden es el contrario al tuyo yo tengo como primary el no vulnerable y secundary el vulnerable seguro. (Esto tan solo me cambia en el signo de los vectores de sign).&lt;BR/&gt;&lt;BR/&gt;Lo mas curioso es que me da una unica funcion ...&lt;BR/&gt;&lt;BR/&gt;Bueno, killoo, a ver si me das una pista, aunque lo voy a repetir con el orden contrario.&lt;BR/&gt;&lt;BR/&gt;Un cordial saludo.&lt;BR/&gt;&lt;BR/&gt;Yibam desde Madrid.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/5884832610992664641'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/5884832610992664641'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1238506080000#c5884832610992664641' title=''/><author><name>yibam</name><uri>http://www.blogger.com/profile/14863821985169075057</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-603747711220272492</id><published>2009-03-20T06:38:00.000-07:00</published><updated>2009-03-20T06:38:00.000-07:00</updated><title type='text'>Enhorabuena!! Me alegro de que lo hayas explotado....</title><content type='html'>Enhorabuena!! Me alegro de que lo hayas explotado. &lt;BR/&gt;&lt;BR/&gt;Animo con BinDiff es muy potente y bien utilizado te ahorra mucho tiempo localizando bugs.&lt;BR/&gt;&lt;BR/&gt;Saludos.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/603747711220272492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/603747711220272492'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1237556280000#c603747711220272492' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-8171557863464601573</id><published>2009-03-18T11:52:00.000-07:00</published><updated>2009-03-18T11:52:00.000-07:00</updated><title type='text'>Hola BokenHe encontrado tu blog. Enhorabuena !!!Ya...</title><content type='html'>Hola Boken&lt;BR/&gt;&lt;BR/&gt;He encontrado tu blog. Enhorabuena !!!&lt;BR/&gt;&lt;BR/&gt;Ya he explotado el format string manualmente ... &lt;BR/&gt;&lt;BR/&gt;Me voy a poner con el BinDiff a ver que tal y te cuento ...&lt;BR/&gt;&lt;BR/&gt;Un cordial saludo.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/8171557863464601573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/8171557863464601573'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1237402320000#c8171557863464601573' title=''/><author><name>yibam</name><uri>http://www.blogger.com/profile/14863821985169075057</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-2010868371614677810</id><published>2009-01-28T05:53:00.000-08:00</published><updated>2009-01-28T05:53:00.000-08:00</updated><title type='text'>La verdad es que ver este tipo de fallos a uno le ...</title><content type='html'>La verdad es que ver este tipo de fallos a uno le animan a buscar mas, y para serte sincero, en eso estoy ahora mismo ;D&lt;BR/&gt;&lt;BR/&gt;Estoy haciendome los scripts necesarios, pero aun no tengo del todo claro como atacarlo. Hay bastante faena y me gustaria hacer un trabajo completito.&lt;BR/&gt;&lt;BR/&gt;Si, lo de que este en .rar no lo habia pensado, jejeje bueno el que no arriesga... jejeje&lt;BR/&gt;&lt;BR/&gt;Saludos Nico!!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/2010868371614677810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/2010868371614677810'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1233150780000#c2010868371614677810' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-6784577182361637954</id><published>2009-01-25T13:59:00.000-08:00</published><updated>2009-01-25T13:59:00.000-08:00</updated><title type='text'>Por otro lado, un tutorial de como explotar Winrar...</title><content type='html'>Por otro lado, un tutorial de como explotar Winrar en formato "rar", no creo que muchos se hayan animado a abrir ;)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/6784577182361637954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/6784577182361637954'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1232920740000#c6784577182361637954' title=''/><author><name>Nico Waisman</name><uri>http://www.blogger.com/profile/17467268863787048478</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-8289524934770972951</id><published>2009-01-25T13:54:00.000-08:00</published><updated>2009-01-25T13:54:00.000-08:00</updated><title type='text'>Muy lindo tutorial. Cuanto tiempo te llego el desa...</title><content type='html'>Muy lindo tutorial. &lt;BR/&gt;Cuanto tiempo te llego el desafio?&lt;BR/&gt;&lt;BR/&gt;Ahora el proximo paso es realizarlo Martes de Microsoft, ni bien sale un parche ;)&lt;BR/&gt;&lt;BR/&gt;Cuando encuentro bugs así, me gusta escribir un scriptcito para que automaticamente detecte el bug, por ejemplo en este caso chequear los sprintf y ver si stackvars te puede ayudar a descubrir si el tamaño del primer argumento es una variable en la stack. &lt;BR/&gt;Te animas?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/8289524934770972951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/2133481550654398308/comments/default/8289524934770972951'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html?showComment=1232920440000#c8289524934770972951' title=''/><author><name>Nico Waisman</name><uri>http://www.blogger.com/profile/17467268863787048478</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2009/01/del-parche-al-exploit-con-bindiff-e.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-2133481550654398308' source='http://www.blogger.com/feeds/647648746783162534/posts/default/2133481550654398308' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-6911867929243502714</id><published>2008-12-17T14:19:00.000-08:00</published><updated>2008-12-17T14:19:00.000-08:00</updated><title type='text'>Si empieza a coger fuerza te aconsejo que lo ponga...</title><content type='html'>Si empieza a coger fuerza te aconsejo que lo pongas en cualkier hosting y t crees una web, es muy interesante a mi parecer sise hace eficiente :D</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/123802563800198940/comments/default/6911867929243502714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/123802563800198940/comments/default/6911867929243502714'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/12/desarrollo-de-un-fuzzer-genrico-para.html?showComment=1229552340000#c6911867929243502714' title=''/><author><name>Trancek</name><uri>http://www.blogger.com/profile/02206831101238505779</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/12/desarrollo-de-un-fuzzer-genrico-para.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-123802563800198940' source='http://www.blogger.com/feeds/647648746783162534/posts/default/123802563800198940' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-1888695564886184898</id><published>2008-11-28T04:24:00.000-08:00</published><updated>2008-11-28T04:24:00.000-08:00</updated><title type='text'>queremos mas partes!!! jejej</title><content type='html'>queremos mas partes!!! jejej</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/3789533422593319371/comments/default/1888695564886184898'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/3789533422593319371/comments/default/1888695564886184898'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/11/desarrollo-de-exploits-con-metasploit-3.html?showComment=1227875040000#c1888695564886184898' title=''/><author><name>Trancek</name><uri>http://www.blogger.com/profile/02206831101238505779</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/11/desarrollo-de-exploits-con-metasploit-3.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-3789533422593319371' source='http://www.blogger.com/feeds/647648746783162534/posts/default/3789533422593319371' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-8296693380941548665</id><published>2008-09-05T00:39:00.000-07:00</published><updated>2008-09-05T00:39:00.000-07:00</updated><title type='text'>A mi me parece perfecto que le pongan beta, y que ...</title><content type='html'>A mi me parece perfecto que le pongan beta, y que dure todo lo posible. &lt;BR/&gt;&lt;BR/&gt;Como dice Makarra, la mejor manera de probar algo es que miles/millones de persona lo hagan e incluso mejor si lo hacen con tal "mala fe" o buscando las cosquillas ;D&lt;BR/&gt;&lt;BR/&gt;Eso redunda en que cuando salga la version estable, sea de muy buena calidad.&lt;BR/&gt;&lt;BR/&gt;Google, otra cosa no se, pero lo que hace lo hace de calidad, y como la seguridad 100% no existe, saben que lo mas economico y sencillo es mostrarlo al mundo para que poco a poco vayan saliendo fallos.&lt;BR/&gt;&lt;BR/&gt;Y nosotros mientras tanto si vamos encontrandolos y en ZeroDay o iDefense nos pagan, pues mejor que mejor ;D</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/22580315493770459/comments/default/8296693380941548665'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/22580315493770459/comments/default/8296693380941548665'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/09/si-es-version-beta-por-algo-ser.html?showComment=1220600340000#c8296693380941548665' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/09/si-es-version-beta-por-algo-ser.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-22580315493770459' source='http://www.blogger.com/feeds/647648746783162534/posts/default/22580315493770459' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-1695316681310305749</id><published>2008-09-04T10:24:00.000-07:00</published><updated>2008-09-04T10:24:00.000-07:00</updated><title type='text'>jejeje pues no se, pero eso de BETA...lo ponen en ...</title><content type='html'>jejeje pues no se, pero eso de BETA...lo ponen en todos sus productos parece&lt;BR/&gt;&lt;BR/&gt;Google News, mira a ver cuando se abrio eso, segun lei lleva beta mucho tiempo, demasiado xD</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/22580315493770459/comments/default/1695316681310305749'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/22580315493770459/comments/default/1695316681310305749'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/09/si-es-version-beta-por-algo-ser.html?showComment=1220549040000#c1695316681310305749' title=''/><author><name>Trancek</name><uri>http://www.blogger.com/profile/02206831101238505779</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/09/si-es-version-beta-por-algo-ser.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-22580315493770459' source='http://www.blogger.com/feeds/647648746783162534/posts/default/22580315493770459' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-4091851046142939869</id><published>2008-09-04T04:06:00.000-07:00</published><updated>2008-09-04T04:06:00.000-07:00</updated><title type='text'>Menos mal que alguien denuestra un poco de sentido...</title><content type='html'>Menos mal que alguien denuestra un poco de sentido común. Lo digo porque la sensación de que todos los que se hacen eco de las vulnerabilidades, bugs o problemas de diseño, encontrados en chrome  utilizan un tono del tipo "pues vaya", "empezamos bien". No quiero que se me interprete como defensor de google ni mucho menos, pero es que se trata de una versión BETA. Cuando se publica una versión beta se hace con la intención de que los usuarios la evaluen. No hay mejor testeo que ese.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/22580315493770459/comments/default/4091851046142939869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/22580315493770459/comments/default/4091851046142939869'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/09/si-es-version-beta-por-algo-ser.html?showComment=1220526360000#c4091851046142939869' title=''/><author><name>makarra</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/09/si-es-version-beta-por-algo-ser.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-22580315493770459' source='http://www.blogger.com/feeds/647648746783162534/posts/default/22580315493770459' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-3727962110511594247</id><published>2008-08-14T12:56:00.000-07:00</published><updated>2008-08-14T12:56:00.000-07:00</updated><title type='text'>He modificado el post, porque Ricardo lo ha subido...</title><content type='html'>He modificado el post, porque Ricardo lo ha subido a su web, asi que adjunto el link para que podais acceder a el.&lt;BR/&gt;&lt;BR/&gt;Espero vuestros comentarios, dudas, criticas, sugerencias...</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/250990961917198627/comments/default/3727962110511594247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/250990961917198627/comments/default/3727962110511594247'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/08/desarrollo-de-exploits-con-metasploit-3.html?showComment=1218743760000#c3727962110511594247' title=''/><author><name>Boken</name><uri>http://www.blogger.com/profile/13008727550075774684</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='06960367882231167997'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/08/desarrollo-de-exploits-con-metasploit-3.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-250990961917198627' source='http://www.blogger.com/feeds/647648746783162534/posts/default/250990961917198627' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-9130102500625220119</id><published>2008-08-14T04:46:00.000-07:00</published><updated>2008-08-14T04:46:00.000-07:00</updated><title type='text'>Ya era hora, esperaba ese tutorial como agua de ma...</title><content type='html'>Ya era hora, esperaba ese tutorial como agua de mayo. Si puedo ayudarte en el tema del enlace (y alojamiento) lo haré encantado. Un saludo.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/250990961917198627/comments/default/9130102500625220119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/250990961917198627/comments/default/9130102500625220119'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/08/desarrollo-de-exploits-con-metasploit-3.html?showComment=1218714360000#c9130102500625220119' title=''/><author><name>athathel</name><uri>http://blogs.idominiun.com/ciberpensantes</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/08/desarrollo-de-exploits-con-metasploit-3.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-250990961917198627' source='http://www.blogger.com/feeds/647648746783162534/posts/default/250990961917198627' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-647648746783162534.post-576145529218905708</id><published>2008-08-11T02:23:00.000-07:00</published><updated>2008-08-11T02:23:00.000-07:00</updated><title type='text'>Okis. Pensé que el problema afectaba sólo a .NET y...</title><content type='html'>Okis. Pensé que el problema afectaba sólo a .NET y no en cómo Vista lo trata. Gracias por la aclaración.&lt;BR/&gt;&lt;BR/&gt;Pues nada, difícil lo tienen. Aunque creo que hay un parche alternativo para el problema: GNU/Linux. xD.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/133442979798201731/comments/default/576145529218905708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/647648746783162534/133442979798201731/comments/default/576145529218905708'/><link rel='alternate' type='text/html' href='http://boken00.blogspot.com/2008/08/windows-vista-ha-muerto.html?showComment=1218446580000#c576145529218905708' title=''/><author><name>athathel</name><uri>http://blogs.idominiun.com/ciberpensantes</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://boken00.blogspot.com/2008/08/windows-vista-ha-muerto.html' ref='tag:blogger.com,1999:blog-647648746783162534.post-133442979798201731' source='http://www.blogger.com/feeds/647648746783162534/posts/default/133442979798201731' type='text/html'/></entry></feed>