Tuesday, May 26, 2009

My new rig. Chi chan

I haven`t updated anything for such a long time. Not feeling really well. Life is bit stressful back few weeks and I need a new rig. So went for shopping and thus here is my new Rig, Chi Chan. (since it`s small)




the Specs:

Intel D945GCLF2 (integrated with 1.6Ghz Dual-Core Intel Atom)
2 Gig Ram
60gb hardisk (salvage from the last remaining of Nosferatu )
Intel 954 GPU.

So it`s not exactly what you called the fastest machine on earth nor it`s the slowest. But as the world gets closer to "One degree increment". We cannot depend on Captain Planet anymore to save us .

And yeah oh it`s running on Fedora 10.. rest assure.

Wednesday, May 20, 2009

Another Cimb Pishing/..

Just woke up and yet another pishing...

From: CIMB Bank <alert@alert-firstx11.com>
Date: Wed, May 20, 2009 at 4:27 AM
Subject: Important Notification (Account)
To:


Alert Message - #2605

Dear Valued Customer,

We placed an hold on your account for security reasons as we detected several invalid logon attempts from a blacklisted location. Your immediate attention is required to activate and restore access to your account.

Activate Now
http://www.cimbclicks.com.my/start.html

Note: Your account will be closed if not resolved within 10 minutes of notice.

Sincerely,

CIMB Bank

------------------


What is unique about this email is the hyperlink points to the page is not actually www. cimbclicks.com.my/start.html . It might tricks a lot of people.
Let's have a look



1:Clearly login is using http





2. Login using abc:abc, and prompt a dumb TAC screen



3. Enter any key will bring to Finish page..

Dossier it bring us to:

Domain Name.......... startclicks-net.com
Creation Date........ 2009-05-20
Registration Date.... 2009-05-20
Expiry Date.......... 2010-05-20
Organisation Name.... Jennifer Bhatt
Organisation Address. PO Box 61359
Organisation Address.
Organisation Address. Sunnyvale
Organisation Address. 94088
Organisation Address. CA
Organisation Address. US


So it`s a new phishing site for the day.

Monday, May 18, 2009

Google Native Client.

Link: http://code.google.com/p/nativeclient/

>From the website:

Native Client is an open-source research technology for running x86 native code in web applications, with the goal of maintaining the browser neutrality, OS portability, and safety that people expect from web apps. We've released this project at an early, research stage to get feedback from the security and broader open-source communities. We believe that Native Client technology will someday help web developers to create richer and more dynamic browser-based applications.


My comments:

The ability to execute native codes aren't exactly new idea . Microsoft have attempt it with ActiveX Controller, Sun with Java and of course Macromedia with Shockwave. However most attempt are bit futile in term of scalability , OS compatibility and also Web Browser compatibility.
(Java works well since it doesnt' talk to the machine directly but have it's own VM (so things like Memory Management , etcx3 are taken care well off).


So what exactly is exciting on running a native x86 codes on top of Web Browser?

we can play our favourite game in our web browser (no need to install anymore, we can babo or dota or simply by having a web browser that support it).

The technology is still new by the way

Consequences?

Matasano Security had write up an excellent review from security perspective:

http://www.matasano.com/log/1674/the-security-implications-of-google-native-client