<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alt+Ctrl+Supr</title>
	<atom:link href="http://altctrlsupr.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://altctrlsupr.net</link>
	<description>Weblog de un hacklab desubicado</description>
	<lastBuildDate>Thu, 11 Jun 2009 15:49:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Summer Camp Garrotxa 2009</title>
		<link>http://altctrlsupr.net/summer-camp-garrotxa-2009/</link>
		<comments>http://altctrlsupr.net/summer-camp-garrotxa-2009/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 15:49:41 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Hacktivisme]]></category>
		<category><![CDATA[talleres]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1089</guid>
		<description><![CDATA[Pues parece que ya esta lista la parrilla de contenidos y la logistica general del evento. Estara interesante, nos veremos por alla!!!
Mas informacion
]]></description>
			<content:encoded><![CDATA[<p>Pues parece que ya esta lista la parrilla de contenidos y la logistica general del evento. Estara interesante, nos veremos por alla!!!</p>
<p><a href="http://blackhold.blogspot.com/2009/06/summer-camp-garrotxa-2009.html">Mas informacion</a></p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/summer-camp-garrotxa-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacktitud 2009</title>
		<link>http://altctrlsupr.net/hacktitud-2009/</link>
		<comments>http://altctrlsupr.net/hacktitud-2009/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 15:36:56 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[Hacklabs]]></category>
		<category><![CDATA[cultura libre]]></category>
		<category><![CDATA[cultura lliure]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1080</guid>
		<description><![CDATA[Los compañeros del Null-Lab estan preparando para las fiestas de su pueblo unas jornadas repletas de talleres y actividades, enmarcadas en las III Jornades de Programari Lliure i Societat en Xarxa a Cerdanyola del Vallès.
Sera los dias 26, 27 y 28 de junio al Casal de Joves Altimira (Cerdanyola del Vallès)
Mas informacion
]]></description>
			<content:encoded><![CDATA[<p>Los compañeros del Null-Lab estan preparando para las fiestas de su pueblo unas jornadas repletas de talleres y actividades, enmarcadas en las III Jornades de Programari Lliure i Societat en Xarxa a Cerdanyola del Vallès.</p>
<p>Sera los dias 26, 27 y 28 de junio al Casal de Joves Altimira (Cerdanyola del Vallès)</p>
<p><a href="http://null-lab.hacklabs.org/mediaw/index.php/Preproducci%C3%B3_2009">Mas informacion</a></p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/hacktitud-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>W3af Ninja Training Class</title>
		<link>http://altctrlsupr.net/w3af-ninja-training-class/</link>
		<comments>http://altctrlsupr.net/w3af-ninja-training-class/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 14:50:48 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[HowTo]]></category>
		<category><![CDATA[pentest]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1075</guid>
		<description><![CDATA[NopSec and Bonsai Information Security presents &#8220;w3af Ninja Training Class&#8221;
June 17th / 18th 2009
NopSec, Inc. SOC
155 Water St., Brooklyn, NY 11201 USA
For Information and Registration visit:
http://tinyurl.com/w3afnyctraining

Introduction
Internet security threats are migrating from pure network-level attacks  to web server and web application attacks. The web application itself  has become the new security perimeter, and is [...]]]></description>
			<content:encoded><![CDATA[<p>NopSec and Bonsai Information Security presents &#8220;w3af Ninja Training Class&#8221;</p>
<p>June 17th / 18th 2009</p>
<p>NopSec, Inc. SOC</p>
<p>155 Water St., Brooklyn, NY 11201 USA</p>
<p>For Information and Registration visit:</p>
<p><a class="moz-txt-link-freetext" href="http://tinyurl.com/w3afnyctraining">http://tinyurl.com/w3afnyctraining</a></p>
<p><span id="more-1075"></span></p>
<p>Introduction</p>
<p>Internet security threats are migrating from pure network-level attacks  to web server and web application attacks. The web application itself  has become the new security perimeter, and is wide open to the new  generation of attacks. That&#8217;s the reason why is very important for IT  security staff to have cutting- edge knowledge of web application  security vulnerability testing techniques and tools.</p>
<p>Overview</p>
<p>w3af is a Web Application Attack and Audit Framework. The project goal  is to create a framework to find and exploit web application  vulnerabilities that are both easy to use and extend. The project  started back in 2006 with only one developer but it is now developed and  supported by a team of Web Application Hackers and Open Source experts  around the world. The w3af ninja training course is focused on manual  and automated discovery and exploitation of web application  vulnerabilities using w3af. During this course you&#8217;ll also learn how to  write your own exploits and customized plugins in order to achieve your  goals during a web application penetration test.</p>
<p>This course is an intense hands-on class in which you won&#8217;t stop  learning for a minute. In each practice we&#8217;ll focus on a particular type  of web application vulnerability which will be analyzed and understood  manually and then it&#8217;s detection and exploitation is automated using w3af.</p>
<p>All around the training interesting plugin code snippets will be subject  to analysis and modification, which will give you great understanding of  the framework and will also give you the means to automate your future  web application penetration tests.</p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/w3af-ninja-training-class/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IMF 2009</title>
		<link>http://altctrlsupr.net/imf-2009/</link>
		<comments>http://altctrlsupr.net/imf-2009/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 14:48:38 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1073</guid>
		<description><![CDATA[                         3rd CALL FOR PAPERS

                           [...]]]></description>
			<content:encoded><![CDATA[<pre>                         3rd CALL FOR PAPERS

                              IMF 2009

                     5th International Conference
          on IT Security Incident Management &amp; IT Forensics

                     September 15th - 17th, 2009
                          Stuttgart, Germany

                          DEADLINE EXTENSION 

<span id="more-1073"></span>

PAPER SUBMISSION
================
The deadline for paper submissions has been extended to June 8th, 2009.
Notification of acceptance will be sent on June 22nd.
Camera ready paper copies must be submitted until June 26th, 2009.

Papers can be submitted via the page found at:
<a class="moz-txt-link-freetext" href="http://www.imf-conference.org/imf2009/submission.html">http://www.imf-conference.org/imf2009/submission.html</a>

Accepted papers will be published in IEEE Computer Society's Conference
Proceedings Series and be available in the IEEE online Digital Library.

CONFERENCE BACKGROUND
=====================
Information and communication technology is more and more becoming an
integral and in most cases even a vital part of life.  The worldwide
economy, public administration, health care, education and even personal
life depend on working IT.  Constriction of the availability of its
service, loss of confidentiality or alteration of data processed, or
loss of integrity of the IT infrastructure usually lead to serious or
disastrous consequences.  Hence security plays an increasingly important
role for operators and users of IT systems and infrastructures.

The establishment of static security measures like policies, standards,
and guidelines slowly but steadily is getting more common amongst IT
operators.  Nevertheless in the vast majority of cases operators do not
have the capability to detect and respond to security incidents or do a
forensic analysis of its traces that can be used in a lawsuit.
Jurisdiction in most countries is starting to change and applies
regulations on legal duty to maintain safety on operators of IT.  Hence
incident response capabilities become indispensable to avoid successful
assertion of claims for damages caused by compromised or misused
systems.

CONFERENCE GOALS
================
IMF's intent is to gather experts from throughout the world in order to
present and discuss recent technical and methodical advances in the
fields of IT security incident response and management and IT forensics.
The conference provides a platform for collaboration and exchange of
ideas between industry, academia, law-enforcement and other government
bodies.

CONFERENCE TOPICS
=================
The scope of IMF 2009 is broad and includes, but is not limited to the
following areas:

IT Incident Response
--------------------
* Procedures and Methods of Incident Response
* Formats and Standardization for Incident Response
* Tools Supporting Incident Response
* Incident Analysis
* CERTs/CSIRTs
* Sources of Information, Information Exchange, Communities
* Dealing with Vulnerabilities (Vulnerability Response)
* Monitoring and Early Warning
* Education and Training
* Organizations
* Legal Aspects (Jurisdiction, Applicable Laws and Regulations)

IT Forensics
------------
* Trends and Challenges in IT Forensics
* Techniques, Tools in Procedures IT Forensics
* Methods for the Gathering, Handling, Processing and Analysis of
  Digital Evidence
* Evidence Protection in IT Environments
* Standardization in IT Forensics
* Education and Training
* Organizations
* Legal Aspects (Jurisdiction, Applicable Laws and Regulations)

Submission Details
==================
IMF invites to submit full papers of up to 20 pages, presenting novel
and mature research results as well as practice papers of up to 20
pages, describing best practices, case studies or lessons learned.
Proposals for workshops, discussion and presentation on practical methods
and challenges are also welcome.

All submissions must be written in English (see below), and either in
postscript or PDF format.  Authors of accepted papers must ensure that
their papers will be presented at the conference.

Submitted full papers must not substantially overlap papers that have
been published or that are simultaneously submitted to a journal or a
conference with proceedings.

All submissions will be reviewed by the program committee and papers
accepted to be presented at the conference will be included in the
conference proceedings.

Papers can be submitted via the page found at:
<a class="moz-txt-link-freetext" href="http://www.imf-conference.org/imf2009/submission.html">http://www.imf-conference.org/imf2009/submission.html</a>

Details on the electronic submission procedure as well as detailed
registration information and formatting instructions are provided on
the conference web site (<a class="moz-txt-link-freetext" href="http://www.imf-conference.org/">http://www.imf-conference.org</a>).

Language
========
IMF 2009's scope is international hence all submissions must be written
in English. Presentations of accepted papers must be done in English.

Publication
===========
Accepted papers will be published in IEEE Computer Society's Conference
Proceedings Series and be available in the IEEE online Digital Library
as well as the IEEE Index.  Each participant of the conference will
receive a printed copy.

Dates and Deadlines
===================
The deadline for paper submissions is June 8th, 2009.  Notification of
acceptance will be sent on June 22nd, 2009.
Camera ready paper copies are due on June 26th, 2009.

June 8th, 2009: Deadline for submissions
June 22nd, 2009: Notification of acceptance or rejection
June 26th, 2009: Final paper camera ready copy due
September 15th through 17th, 2009: IMF 2009 Conference

PROGRAM COMMITTEE
=================
Susan Brenner		University of Dayton, USA
Jack Cole		US Army Research Laboratory, USA
Andrew Cormack		JANET, UK
Ralf Doerrie		Germany
Ralf Ehlert		Universitaet Magdeburg, Germany
Felix Freiling		Universitaet Mannheim, Germany
Sandra Frings		Fraunhofer IAO, Germany
Oliver Goebel		Universitaet Stuttgart, Germany
Detlef Guenther		Corporate Internal Audit, Volkswagen AG, Germany
Vijay K. Gurbani	Bell Labs, USA
Bernhard M. Haemmerli	ACRIS GmbH, Switzerland
Jim Lyle		NIST, USA
Robert Martin		MITRE Corp., USA
Holger Morgenstern	gutachten.info, Germany
Henning Pagnia		Berufsakademie Mannheim, Germany
Dirk Schadt		SPOT, Germany
Albert Schaenzle	Landeskriminalamt Baden Wuerttemberg, Germany
Mark Schiller		Statton Security Ltd, UK
Andreas Schuster	Deutsche Telekom, Germany
Marco Thorbruegge	ENISA, EU
Stephen D. Wolthusen	Royal Holloway, Univ. of London, UK
Steven W. Wood		Alste Technologies GmbH, Germany

CONFERENCE CHAIR
================
Dirk Schadt
SPOT Consulting
mailto: chair-2009 @ imf-conference.org

PROGRAM CHAIR
=============
Oliver Goebel
RUS-CERT
Universitaet Stuttgart
mailto: pc-chair-2009 @ imf-conference.org

ORGANIZING COMMITTEE
====================
Ralf Ehlert
Sandra Frings
Oliver Goebel
Detlef Guenther
Holger Morgenstern
Dirk Schadt

STEERING COMMITTEE
==================
Sandra Frings
Oliver Goebel
Detlef Guenther
Jens Nedon
Dirk Schadt

PROGRAM COMMITTEE
=================
see: <a class="moz-txt-link-freetext" href="http://www.imf-conference.org/">http://www.imf-conference.org</a>

UNDER THE AUSPICES OF
=====================
German Informatics Society (GI e.V.)
Wissenschaftszentrum Ahrstr. 45, 53175 Bonn, Germany
Tel.: +49 228 302 145, Fax: +49 228 302 167
Special Interest Group SIDAR
<a class="moz-txt-link-freetext" href="http://www.gi-ev.de/allgemeines/index-english.html">http://www.gi-ev.de/allgemeines/index-english.html</a>

IN CO-OPERATION WITH
====================
IEEE Computer Society
SPOT Consulting
Fraunhofer Institut fuer Arbeitswirtschaft und Organisation IAO
Universitaet Stuttgart, RUS-CERT

SPONSORSHIP
===========
We invite interested organizations to serve as sponsors for
IMF 2009; please contact the Sponsor Chair, Detlef Guenther,
for information regarding corporate sponsorship
mailto: sponsor-chair-2009 @ imf-conference.org

------------------------------------------------------------------------

Best wishes
Ollie
<div>--
Oliver Goebel                        <a class="moz-txt-link-freetext" href="mailto:Goebel@CERT.Uni-Stuttgart.DE">mailto:Goebel@CERT.Uni-Stuttgart.DE</a>
Stabsstelle DV-Sicherheit (RUS-CERT) Tel:+49 711 685 1 CERT
Universitaet Stuttgart               Tel:+49 711 685 8-3678 / Fax:-3688
Breitscheidstr. 2, 70174 Stuttgart   <a class="moz-txt-link-freetext" href="http://cert.uni-stuttgart.de/">http://CERT.Uni-Stuttgart.DE/</a></div>
</pre>
<table class="header-part1" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td></td>
</tr>
<tr>
<td></td>
</tr>
<tr>
<td></td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/imf-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>26C3</title>
		<link>http://altctrlsupr.net/26c3/</link>
		<comments>http://altctrlsupr.net/26c3/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 13:25:50 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[CCC]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[international hack]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1069</guid>
		<description><![CDATA[26C3: Here Be Dragons
  26th Chaos Communication Congress
  December 27th to 30th, 2009
  Berlin, Germany http://events.ccc.de/congress/2009/


Overview
========

is the annual four-day conference organized by the Chaos Computer Club
(CCC) in Berlin, Germany.First held in 1984, it since has established
itself as "the European Hacker Conference" attracting a diverse
audience of thousands of hackers, scientists, artists, and utopists
from [...]]]></description>
			<content:encoded><![CDATA[<pre>26C3: Here Be Dragons
  26th Chaos Communication Congress
  December 27th to 30th, 2009
  Berlin, Germany <a class="moz-txt-link-freetext" href="http://events.ccc.de/congress/2009/">http://events.ccc.de/congress/2009/</a>
<span id="more-1069"></span>

Overview
========

is the annual four-day conference organized by the Chaos Computer Club
(CCC) in Berlin, Germany.First held in 1984, it since has established
itself as "the European Hacker Conference" attracting a diverse
audience of thousands of hackers, scientists, artists, and utopists
from all around the world.

We want you to join and be a part of this unique event which serves as
a public platform for cross-culture inspiration and borderless
networking. 26C3 is fun!

Topics
======

The 26C3 conference program is roughly divided into six general
categories. These categories serve as guidelines for your submissions
(and later as a means of orientation for your prospective audience).
However, it is not mandatory for your talk to exactly match the
descriptions below. Anything that is interesting and/or funny will be
taken into consideration.

Society
-------
Technology development causes great changes in society and will
determine our future. This category is for all talks on subjects like
surveillance practices, censorship, hacker tools and the law,
intellectual property and copyright issues, data retention, software
patents, effects of technology on kids, and the impact of technology
on society in general.

Hacking
-------
The "Hacking" category addresses topics dealing with technology,
concentrating on current research with high technical merit.
Traditionally, the majority of all lectures at 26C3 revolve around
hacking.

Topics in this domain include but are in no way limited to:
programming, hardware hacking, cryptography, network and system
security, security exploits, and creative use of technology.

Making
------
The "Making" category is all about making and breaking things and the
wonderful stuff you can build in your basement or garage. Most welcome
are submissions dealing with the latest in electronics, RepRaps,
lasers, 3D-printing, climate-change survival technology, robots and
flying UAVs, steam machines, alternative transportation tools,
guerilla-style knitting, and wearable hardware hacks.

Science
-------
The "Science" category covers current or future objects of scientific
research that have the potential to radically change our lives, be it
basic research or projects conducted for the industry.

We are looking for talks and papers on the state of the art in this
domain, covering subjects such as nano technology, quantum computing,
high frequency physics, bio-technology, brain-computer interfaces,
genetic hacking and hackteria, automated analysis of surveillance
cctv, map-making, psychogeography etc.

Culture
-------
Shaping the world we live in means making it more interesting,
entertaining and beautiful. The hacker culture has many facets ranging
from electronic art objects, stand-up comedy, geek entertainment,
video game and board game culture, electronically generated music, 3D
art, and everything that bleeps and blinks to e-text literature and
beyond. If you like to show your art and teach others how to make
their lives more enjoyable, this category is for you.

Community
---------
In addition to individual speakers the Chaos Communication Congress is
also inviting groups such as developer teams, projects and activists
to present themselves and their topics.

Developer groups are also encouraged to ask for support to hold
smaller on-site developer conferences and meetings in the course of
the Congress.

Further Information
===================

The Chaos Communication Congress is a non-profit oriented event and
speakers are not paid. However, financial help on travel expenses and
accommodation is possible. It needs to be agreed upon after acceptance
of the submission, though. Don't be shy and state your requirements in
the application when submitting your lecture and we'll work something
out!

You can find the preliminary agenda and additional information on our
26C3 website at <a class="moz-txt-link-freetext" href="http://events.ccc.de/congress/2009/">http://events.ccc.de/congress/2009/</a>.

For further information and questions please feel free to contact 26C3-
content  (at)  cccv.de

Submissions
===========

All proposals must be submitted online using our online lecture
submission system at <a class="moz-txt-link-freetext" href="https://cccv.pentabarf.org/submission/26C3">https://cccv.pentabarf.org/submission/26C3</a>.
Please follow the instructions given there. If you have any questions
regarding your submission, feel free to contact us at 26C3-content
(at)  cccv.de but do NOT submit your lecture via e-mail.

Language
========

26C3 is an international event and we want to have a lot of
interesting talks in English for the benefit of our growing number of
international guests. So ideally we are looking for speakers who can
give lectures and/or workshops in either English or German. But while
we are interested in maximizing the quality of presentations, the
topic and its relevance to our community are our main concern. So
don't worry about your English skills: the language of a submission is
not a criteria for accepting or rejecting it!

If you're a native German speaker and feel insecure about talking in
English, have received criticism on your language skills from your
audience before, or if you just fear that the value and
understandability of your lecture might suffer, please offer your talk
in German.

Lecture Requirements
====================

Lectures should not exceed 45 minutes plus up to 10 minutes for
questions and answers. Longer time slots are possible if we feel the
topic demands it (please tell us if necessary). Workshops should
include a talk on the basic principles in the lecture programm and a
practical hands-on session in the workshop room.

Papers
======

Accepted speakers can optionally hand in a paper which will be
published with an ISBN in the 26C3 Proceedings. Papers will be
accepted in Portable Document Format (PDF) only and should be around
5-10 pages. The PDF file must not be password-protected or contain
other restrictions. Paper size should be DIN A4 (297x210mm) in
portrait orientation. All margins must be set to at least 2 cm (0.78
inches). Pictures should be high-contrasted, greyscaled and up to
300dpi. Apart from that, you are free to use any layout you want.

Slides
======

Accepted speakers are asked to hand in slides used in their talks.
Please use a well-known format for your slides. PDF is a wise choice.

Publication
===========

Audio and video recordings of the lectures will be published online in
various formats. The Chaos Communication Congress Proceedings are
published on paper and online. Only reviewed and accepted talks and
presentations will be published.

All material will be available under the Creative Commons
"Attribution-NonCommercial-NoDerivs 3.0 Germany" (BY-NC-ND) license
allowing free non-commercial redistribution of the material as long as
the original credit to authors and publishers is retained.

Licence URI: <a class="moz-txt-link-freetext" href="http://creativecommons.org/licenses/by-nc-nd/3.0/de/">http://creativecommons.org/licenses/by-nc-nd/3.0/de/</a>

We encourage contributors to publish their work under a more liberal
license; if you wish to do so, please state this with your submission.

Dates and Deadlines
===================

The deadline for submission is October 9th, 2009 Midnight (23:59) UTC.
Notification of acceptance will be sent by e-mail on November 8th,
2009 the latest. However, you may very well get your notification
earlier than that if needed. Final papers or slides are due by
November 27th, 2009.

* October 9th, 2009 (Midnight UTC) Submission due
* November 8th, 2009 (Midnight UTC) Final notification of acceptance
(or earlier)
* November 27th, 2009 (Midnight UTC) Final papers due
* December 27th - 30th, 2009 Chaos Communication Congress</pre>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/26c3/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Instalacion de Aircrack-NG-SSE2 en Asus eeePC y otras maquinas</title>
		<link>http://altctrlsupr.net/instalacion-de-aircrack-ng-sse2-en-asus-eeepc-y-otra-maquinas/</link>
		<comments>http://altctrlsupr.net/instalacion-de-aircrack-ng-sse2-en-asus-eeepc-y-otra-maquinas/#comments</comments>
		<pubDate>Sun, 24 May 2009 12:49:41 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[HowTo]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[WEP crack]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[Wireless]]></category>
		<category><![CDATA[WPA/TKIP crack]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1061</guid>
		<description><![CDATA[El trabajo que realizan desde Aircrack-NG esta produciendo diversas ramificaciones que han llevado a facilitar enormemente el descrifrado de claves, sobretodo WEP. Ademas de las diversas livecd especializadas que podemos encontrar que utilizan como base o incluyen Aircrack-NG (Wifiway, BackTrack, ChaoX-NG&#8230;) , desde el website oficial podemos elegir varias formas de instalar o hacer correr [...]]]></description>
			<content:encoded><![CDATA[<p>El trabajo que realizan desde Aircrack-NG esta produciendo diversas ramificaciones que han llevado a facilitar enormemente el descrifrado de claves, sobretodo WEP. Ademas de las diversas livecd especializadas que podemos encontrar que utilizan como base o incluyen Aircrack-NG (<a href="http://foro.seguridadwireless.net/soporte_wifiway_para_netbooks/wifiway_10_final_para_netbooks-t18638.0.html">Wifiway</a>, <a href="http://www.remote-exploit.org/backtrack_download.html">BackTrack</a>, <a href="https://jenux.homelinux.org/~jens/livecd/">ChaoX-NG</a>&#8230;) , desde el website oficial podemos elegir varias formas de instalar o hacer correr la suite. Una seria utilizando <a href="http://www.aircrack-ng.org/doku.php?id=slitaz">Slitaz Aircrack-NG Distribution</a>, <span id="more-1061"></span>version optimizada para los notebooks Acer Aspire One, pero que deberia funcionar en cualquier maquina con GNU/Linux, que podemos descargar desde <a href="ftp://vmware.aircrack-ng.org/slitaz-aircrack-ng-20090505.iso">aqui</a>. Pasamos el fichero iso a un CD o lo utilizamos desde una maquina virtual y nos ahorramos de darles dinero a la innombrable, para disponer de un livecd.<br />
Tambien podemos instalar la suite. Para ello, en primer lugar, nos descargamos la version mas reciente de Aircrack-NG, que incluye <a href="http://es.wikipedia.org/wiki/SSE2">SSE2</a>, que nos permitira aumentar la velocidad de proceso de las claves en relacion a versiones anteriores de la suite.<br />
Podemos elegir entre instalar la version mas reciente mediante <strong>subversion (1)</strong> o el paquete <strong>con las fuentes mas recientes (2)</strong>:</p>
<p><strong>(1) subversion</strong></p>
<p># svn co http://trac.aircrack-ng.org/svn/branch/aircrack-ng<br />
# cd aircrack-ng</p>
<p><strong>(2) http://nightly.aircrack-ng.org/</strong></p>
<p>Podemos descargar las fuentes fresquitas y el airoscript, que facilitara el manejo de <a href="http://nightly.aircrack-ng.org/airoscript/">aircrack-ng</a> (<a href="http://videos.aircrack-ng.org/WEP_Cracking_with_Airoscript.avi">aqui</a> un video de su utilizacion):</p>
<p># tar zvxf aircrack-ng-trunk-2009-05-24-r1544.tar.gz<br />
# cd aircrack-ng-trunk-2009-05-24-r1544/</p>
<p>Instalamos lo necesario para poder compilar software, si no lo tenemos ya:</p>
<p># apt-get install build-essential</p>
<p>Y lo mismo con las dependencias: libtool, autoconf y sqlite3.</p>
<p>En cualquiera de los dos casos, mediante subversion o descargando el ultimo codigo fuente, continuamos la instalacion, con <a href="http://www.aircrack-ng.org/doku.php?id=airolib-ng">soporte para airolib-ng</a> si queremos crear bases de datos sqlite con los ESSIDs y las contraseñas, que posteriormente podran utilizarse para el descifrado de claves de paso WPA/WPA2. Tambien es util el parametro unstable=true para poder compilar tkiptun-ng, easside-ng (y buddy-ng) y wesside-ng, herramientas en pruebas que permiten automatizar el proceso de descifrado WEP.</p>
<p># make sqlite=true unstable=true<br />
# make sqlite=true unstable=true install</p>
<p>Si todo ha salido bien, perfecto, ya podemos comprobar la seguridad de las ondas de nuestro entorno. Es posible que obtengamos algunos errores como estos:</p>
<blockquote><p>gcc -g -W -Wall -Werror -O3 -D_FILE_OFFSET_BITS=64 -D_REVISION=1545  -I/usr/local/include -DHAVE_SQLITE -Iinclude   -c -o aircrack-ng.o aircrack-ng.c<br />
En el archivo incluído de aircrack-ng.c:65:<br />
crypto.h:12:26: error: openssl/hmac.h: No existe el fichero ó directorio<br />
crypto.h:13:25: error: openssl/sha.h: No existe el fichero ó directorio<br />
crypto.h:15:25: error: openssl/rc4.h: No existe el fichero ó directorio<br />
crypto.h:16:25: error: openssl/aes.h: No existe el fichero ó directorio<br />
cc1: warnings being treated as errors<br />
In file included from aircrack-ng.c:69:<br />
sha1-sse2.h: En la función ‘calc_4pmk’:<br />
sha1-sse2.h:143: error: declaración implícita de la función ‘HMAC’<br />
sha1-sse2.h:143: error: declaración implícita de la función ‘EVP_sha1’<br />
aircrack-ng.c:72:21: error: sqlite3.h: No existe el fichero ó directorio<br />
aircrack-ng.c: En el nivel principal:<br />
aircrack-ng.c:73: error: expected ‘=’, ‘,’, ‘;’, ‘asm’ or ‘__attribute__’ before ‘*’ token<br />
aircrack-ng.c: En la función ‘crack_wpa_thread’:<br />
aircrack-ng.c:3916: error: declaración implícita de la función ‘EVP_md5’<br />
aircrack-ng.c: En la función ‘main’:<br />
aircrack-ng.c:4906: error: declaración implícita de la función ‘sqlite3_open’<br />
aircrack-ng.c:4906: error: ‘db’ no se declaró aquí (primer uso en esta función)<br />
aircrack-ng.c:4906: error: (Cada identificador no declarado solamente se reporta una vez<br />
aircrack-ng.c:4906: error: para cada funcion en la que aparece.)<br />
aircrack-ng.c:4907: error: declaración implícita de la función ‘sqlite3_errmsg’<br />
aircrack-ng.c:4907: error: el formato ‘%s’ espera el tipo ‘char *’, pero el argumento 3 es de tipo ‘int’<br />
aircrack-ng.c:4908: error: declaración implícita de la función ‘sqlite3_close’<br />
aircrack-ng.c:5567: error: declaración implícita de la función ‘sqlite3_mprintf’<br />
aircrack-ng.c:5567: error: la asignación crea un puntero desde un entero sin una conversión<br />
aircrack-ng.c:5569: error: declaración implícita de la función ‘sqlite3_exec’<br />
aircrack-ng.c:5570: error: ‘SQLITE_LOCKED’ no se declaró aquí (primer uso en esta función)<br />
aircrack-ng.c:5570: error: ‘SQLITE_BUSY’ no se declaró aquí (primer uso en esta función)<br />
aircrack-ng.c:5576: error: ‘SQLITE_OK’ no se declaró aquí (primer uso en esta función)<br />
aircrack-ng.c:5576: error: ‘SQLITE_ABORT’ no se declaró aquí (primer uso en esta función)<br />
aircrack-ng.c:5578: error: declaración implícita de la función ‘sqlite3_free’<br />
make: *** [aircrack-ng.o] Error 1</p></blockquote>
<p>Este error lo solucionamos instalando el paquete libssl-dev:</p>
<p># apt-get install libssl-dev</p>
<p>Otros errores pueden solucionarse instalando libsqlite-dev.</p>
<p>Una vez instalado, comprobamos si tenemos el soporte SSE2:</p>
<p># aircrack-ng &#8211;cpu-detect</p>
<p>Si habeis llegado hasta aqui del articulo, posiblemente os habreis dado cuenta que el titular es un poco redundante, ya que el proceso de instalacion es identico para un eeePC, un portatil o cualquier otro Linux.</p>
<p>Por ultimo, comentar que recientemente el sitio de Aircrack-ng.org estuvo varios dias fuera de servicio <a href="http://aircrack-ng.blogspot.com/2009/04/finding-author-of-dos.html">debido a un ataque DoS</a>, y que el autor demuestra una actitud bastante etica proponiendo al atacante un plazo de resolucion y aclaracion del tema previo a cualquier denuncia.</p>
<p><strong>Referencias:</strong></p>
<p>http://forum.aircrack-ng.org/</p>
<p>http://www.wifiway.org/sp/articulos/aircrack-ng-rc1-con-sse2.html<br />
http://foro.seguridadwireless.net/soporte-wifiway-para-netbooks/wifiway-1-0-beta2-para-eee-pc-901-904-1000-medion-akoya-mini/<br />
http://airodump.net/aircrack-ng-optimalization-cpu-sse2/</p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/instalacion-de-aircrack-ng-sse2-en-asus-eeepc-y-otra-maquinas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://videos.aircrack-ng.org/WEP_Cracking_with_Airoscript.avi" length="23232570" type="video/x-msvideo" />
		</item>
		<item>
		<title>3ª Party Wifi a Badalona</title>
		<link>http://altctrlsupr.net/3%c2%aa-party-wifi-a-badalona/</link>
		<comments>http://altctrlsupr.net/3%c2%aa-party-wifi-a-badalona/#comments</comments>
		<pubDate>Sun, 17 May 2009 11:19:41 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1057</guid>
		<description><![CDATA[El Departament d&#8217;Electronica i Telecomunicacions de l&#8217;IES La Pineda organitza un any mes la Party Wifi, amb concursos, jocs i premis.
Mes info

Manifest
Amb aquest manifest convoquem a tothom que faci servir“WiFi” a    la festa d’usuaris/es sense fils.
Esteu convidats a venir amb qualsevol aparell que es pugui connectar amb l’estendard    802.11b/g [...]]]></description>
			<content:encoded><![CDATA[<p>El Departament d&#8217;Electronica i Telecomunicacions de l&#8217;IES La Pineda organitza un any mes la Party Wifi, amb concursos, jocs i premis.</p>
<p><a href="http://www.partywifibadalona.net/">Mes info</a></p>
<p><span id="more-1057"></span></p>
<p>Manifest</p>
<p>Amb aquest manifest convoquem a tothom que faci servir“WiFi” a    la festa d’usuaris/es sense fils.</p>
<p>Esteu convidats a venir amb qualsevol aparell que es pugui connectar amb l’estendard    802.11b/g o 802.11a. Tindrem uns quants punts d’accés amb diferents    configuracions on pugueu experimentar les vostres connexions.</p>
<p>També hi haurà la possibilitat de connectar-se a la xarxa lliure    de Badalonawireles, ja integrada a &#8220;guifi.net&#8221;, i fins i tot tocar    un node d’accés a aquesta xarxa.</p>
<p>Per potenciar l’aspecte lúdic, també tindrem demostracions    de jocs en xarxa.</p>
<p>Ens interessa la vostra participació, per tant és molt important    que porteu el vostres equips. L’equip de l’IES La Pineda estarà    a la vostra disposició per ajudar-vos a configurar-lo.</p>
<p>Porteu les vostres consoles portàtils, no donem noms perquè no    ens paguen, tota consola que tingui connexió WiFi la podreu fer servir    per jugar.</p>
<p>Enredarem els alumnes de “telecos” per amenitzar la festa amb música.</p>
<p>En aquesta tercera edició, volem millorar l&#8217;anterior. Per tant esperem    que no sortiu amb les mans buides.</p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/3%c2%aa-party-wifi-a-badalona/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VoIP cifrado y sin intermediarios</title>
		<link>http://altctrlsupr.net/1052/</link>
		<comments>http://altctrlsupr.net/1052/#comments</comments>
		<pubDate>Sat, 16 May 2009 16:24:52 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[Privacitat]]></category>
		<category><![CDATA[cifrado]]></category>
		<category><![CDATA[comunicaciones seguras]]></category>
		<category><![CDATA[P2P]]></category>
		<category><![CDATA[VoIP]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1052</guid>
		<description><![CDATA[Explorando las posibilidades que nos ofrece la VoIP mas alla de Asterisk, me he encontrado con I Hear U (IHU), software libre para poderse comunicar mediante la red sin necesidad de centralitas, servidores, ni protocolos de sesion como SIP o H323.

IHU establece la comunicacion entre dos maquinas punto a punto (p2p) y unicamente empleando el [...]]]></description>
			<content:encoded><![CDATA[<p>Explorando las posibilidades que nos ofrece la VoIP mas alla de Asterisk, me he encontrado con I Hear U (IHU), software libre para poderse comunicar mediante la red sin necesidad de centralitas, servidores, ni protocolos de sesion como SIP o H323.</p>
<p><span id="more-1052"></span><br />
IHU establece la comunicacion entre dos maquinas punto a punto (p2p) y unicamente empleando el protocolo UDP (por defecto), aunque tambien podemos configurarlo para utilizar TCP, y ofrece la posibilidad de cifrar el flujo de audio mediante un sistema criptografico hibrido (RSA+Blowfish). Para informacion completa sobre todas las opciones (en ingles) podeis dirigiros al <a href="http://ihu.sourceforge.net/doc/manual.html">manual</a>.<br />
En cuanto a las dependencias, necesitamos tener instaladas las librerias QT, el controlador de sonido ALSA, el codec Speex, la libreria Soundtouch y la libreria OGG, todo software libre como podeis comprobar.<br />
La instalacion en Debian GNU/Linux es bien sencilla:<br />
apt-get install ihu<br />
Ahora vamos a lo que nos interesa, que es poder hacer y recibir llamadas.<br />
Si nos conectamos desde un equipo con conexion directa a Internet (sin pasarelas ni cortafuegos), deberiamos directamente poder hacer ambas cosas, solamente necesitamos saber la IP o nombre DNS de quien queremos llamar.<br />
En caso de que la maquina este conectada a una pasarela (router,&#8230;) deberemos redirigir y/o abrir en el cortafuegos el puerto 1793 TCP/UDP para entrada y salida.<br />
Si activamos la opcion de cifrar el flujo de salida (&#8221;Encrypt outgoing stream&#8221;), el audio se descifrara en el IHU del otro extremo, ya que el intercambio de claves es automatico. En una misma conversacion se puede activar/desactivar el cifrado cuando se quiera, asi como cambiar la clave de cifrado (modo paranoico).</p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/1052/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking At Random 2009</title>
		<link>http://altctrlsupr.net/hacking-at-random-2009/</link>
		<comments>http://altctrlsupr.net/hacking-at-random-2009/#comments</comments>
		<pubDate>Fri, 15 May 2009 20:21:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Eventos]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[international hack]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1048</guid>
		<description><![CDATA[Algo justita me llega esta informacion (el call for papers tiene fecha limite hoy), pero parece que con el buen tiempo comienzan a brotar los eventos de hacking, como si se tratase de plantitas vigorosas recien sembradas (mmm, en que estare pensando?).

Es un evento abierto (que no es lo mismo que gratuito, a menos que [...]]]></description>
			<content:encoded><![CDATA[<p>Algo justita me llega esta informacion (el <a title="HAR2009 - Call4Papers" href="https://har2009.org/post/call-for-papers">call for papers</a> tiene fecha limite hoy), pero parece que con el buen tiempo comienzan a brotar los eventos de hacking, como si se tratase de plantitas vigorosas recien sembradas (mmm, <a href="http://aclec.tripod.com/cogollo10.JPG">en que</a> estare pensando?).</p>
<p><span id="more-1048"></span></p>
<p>Es un evento abierto (que no es lo mismo que gratuito, a menos que hayais nacido despues del 16 de agosto de 2003), dedicado al hacking en sus mas amplias concepciones, que se viene celebrando cada cuatro años desde 1989 en los Paises Bajos.</p>
<p>Se celebrara los dias 13 a 16 de agosto 2009 en <a title="Localizacion HAR2009" href="http://www.openstreetmap.org/?lat=52.331810000000004&amp;lon=5.828385&amp;zoom=15&amp;layers=B000FTFT">Vierhouten</a>.</p>
<p><em>Informacion ampliada:</em></p>
<p><a href="https://wiki.har2009.org/">Wiki</a></p>
<p><a href="irc://open.ircnet.net/har">IRC</a></p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/hacking-at-random-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vigilancia centralizada de la seguridad de varios servidores</title>
		<link>http://altctrlsupr.net/vigilancia-centralizada-de-la-seguridad-de-varios-servidores/</link>
		<comments>http://altctrlsupr.net/vigilancia-centralizada-de-la-seguridad-de-varios-servidores/#comments</comments>
		<pubDate>Mon, 11 May 2009 12:05:50 +0000</pubDate>
		<dc:creator>altctrlsupr</dc:creator>
				<category><![CDATA[CopyLeft]]></category>
		<category><![CDATA[Seguretat]]></category>
		<category><![CDATA[HIDS]]></category>
		<category><![CDATA[HowTo]]></category>
		<category><![CDATA[seguridad]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://altctrlsupr.net/?p=1041</guid>
		<description><![CDATA[Existe una herramienta que facilitara bastante la compleja labor de monitorizacion continua de varios servidores: OSSEC HIDS.

Explicaremos la instalacion del servidor y el cliente (agente) OSSEC para entornos GNU/Linux:
Instalacion de OSSEC:
Descargamos el codigo fuente http://www.ossec.net/files/ossec-hids-2.0.tar.gz
Lo descomprimimos y entramos en el directorio:
# tar zvxf ossec-hids-2.0.tar.gz
# cd ossec-hids-2.0
# ./install.sh
Le indicamos el idioma y el tipo de instalacion [...]]]></description>
			<content:encoded><![CDATA[<p>Existe una herramienta que facilitara bastante la compleja labor de monitorizacion continua de varios servidores: OSSEC HIDS.</p>
<p><span id="more-1041"></span></p>
<p>Explicaremos la instalacion del servidor y el cliente (agente) OSSEC para entornos GNU/Linux:</p>
<p>Instalacion de OSSEC:<br />
Descargamos el codigo fuente http://www.ossec.net/files/ossec-hids-2.0.tar.gz<br />
Lo descomprimimos y entramos en el directorio:</p>
<p># tar zvxf ossec-hids-2.0.tar.gz<br />
# cd ossec-hids-2.0<br />
# ./install.sh</p>
<p>Le indicamos el idioma y el tipo de instalacion (local, servidor, agente). Le indicamos la ubicacion de la instalacion y a que direccion de correo electronico deberan enviarse las alertas. Le indicamos si queremos instalar la comprobacion de integridad del sistema y la deteccion de rootkits, asi como la respuesta activa automatica ante problemas, el modo de rechazar las conexiones (bloqueando usuarixs en hosts.deny o en iptables), y la habilitacion de syslog remoto (en el puerto 514 UDP).<br />
Por defecto si lo instalamos como servidor se configura el analisis de los siguientes registros:</p>
<p>/var/log/messages<br />
/var/log/auth.log<br />
/var/log/syslog<br />
/var/log/mail.info<br />
/var/log/dpkg.log<br />
/var/log/apache2/error.log<br />
/var/log/apache2/access.log</p>
<p>Si lo instalamos en modo cliente (agente) analizara:</p>
<p>/var/log/messages<br />
/var/log/auth.log<br />
/var/log/syslog<br />
/var/log/mail.info<br />
/var/log/dpkg.log</p>
<p>Para añadir algun otro registro se deben añadir al archivo /var/ossec/etc/ossec.conf como entradas del tipo localfile.</p>
<p>Para añadir agentes al servidor:</p>
<p># /var/ossec/bin/manage_agents</p>
<p>Primero añadimos el nuevo agente, introduciendo el nombre, IP e ID, y seguidamente extraemos la clave que se genero en el agente, con la opcion e y respondiendo a la ID del cliente.<br />
Ahora debemos importar la clave del servidor desde el cliente. Para ello ejecutamos manage_agents en la maquina cliente:</p>
<p># /var/ossec/bin/manage_agents</p>
<p>Una vez terminada la instalacion, solamente nos queda iniciar OSSEC HIDS, primero en el servidor y despues en los clientes:</p>
<p>/var/ossec/bin/ossec-control start</p>
<p>Al iniciarlo (si lo hemos instalado como servidor) se inician los siguientes demonios:</p>
<p>ossec-maild<br />
ossec-execd<br />
ossec-analysisd<br />
ossec-logcollector<br />
ossec-remoted<br />
ossec-syscheckd<br />
ossec-monitord</p>
<p>Y en modo cliente:</p>
<p>ossec-execd<br />
ossec-agentd<br />
ossec-logcollector<br />
ossec-syscheckd</p>
<p>Para detenerlo:</p>
<p>/var/ossec/bin/ossec-control stop</p>
<p>Ahora probamos que funciona correctamente, provocando una alerta, que por defecto ira a parar a /var/ossec/logs/alerts/, donde automaticamente se organizan por año, mes y un log cada dia.</p>
]]></content:encoded>
			<wfw:commentRss>http://altctrlsupr.net/vigilancia-centralizada-de-la-seguridad-de-varios-servidores/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
