<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Delta Xi.</title>
    <link>http://blog.delta-xi.net/</link>
    <description>Beyond security.</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.1.2 - http://www.s9y.org/</generator>
    <pubDate>Fri, 10 Apr 2009 12:57:27 GMT</pubDate>

    <image>
        <url>http://blog.delta-xi.net/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Delta Xi. - Beyond security.</title>
        <link>http://blog.delta-xi.net/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Master thesis revealed: Owership-based PAM with tons of new features</title>
    <link>http://blog.delta-xi.net/index.php?/archives/29-Master-thesis-revealed-Owership-based-PAM-with-tons-of-new-features.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/29-Master-thesis-revealed-Owership-based-PAM-with-tons-of-new-features.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=29</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=29</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img width=&quot;195&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;182&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://blog.wired.com/gadgets/tux_machine_gun.jpg&quot; /&gt;&lt;br /&gt;
The thesis which served as basis for my Master&#039;s Degree in Networks &amp;amp; Security is now freely available for download &lt;a href=&quot;http://data.delta-xi.net/doc/masterthesis-sonnleitner09-authentication.pdf&quot;&gt;here&lt;/a&gt;, and has been entitled &lt;b&gt;Strong interface-independent authentication enforcement through commidity storage devices under GNU/Linux&lt;/b&gt;. The project&#039;s source-code is downloadable via &lt;a href=&quot;http://data.delta-xi.net/usbng-new-git02.2009.tar.bz2&quot;&gt;this link&lt;/a&gt;, and represents the latest snapshot from the git repository. These documents and codes are delivered as-is.&lt;br /&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 11 Mar 2009 23:01:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/29-guid.html</guid>
    
</item>
<item>
    <title>Data recovery in Linux systems</title>
    <link>http://blog.delta-xi.net/index.php?/archives/27-Data-recovery-in-Linux-systems.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/27-Data-recovery-in-Linux-systems.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=27</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=27</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://www.hakin9.org/files/haking/Cover/mini/pomniejszone.jpg&quot; /&gt;An article from the DX maintainer about data recovery in Linux systems has recently been released in the german &lt;a href=&quot;http://hakin9.org/de/&quot;&gt;hakin9&lt;/a&gt; print magazine 01/2009, covering file-system reconstruction, forensic imaging, string-analysis, file-carving, slack observation and more.&lt;br /&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Sat, 03 Jan 2009 12:37:00 +0100</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/27-guid.html</guid>
    
</item>
<item>
    <title>New Release: pam_usbng</title>
    <link>http://blog.delta-xi.net/index.php?/archives/24-New-Release-pam_usbng.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/24-New-Release-pam_usbng.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=24</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=24</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://usbng.delta-xi.net/data/media/usblock.png&quot; style=&quot;width: 122px; height: 149px;&quot; /&gt;The direct successor to USBAuth (pam_usbauth) is called pam_usbng and represents a complete rewrite with many enhancements. It&#039;s much easier to get the module up and running, and offers new nice features. You may have a look to the project page &lt;a title=&quot;usbng&quot; href=&quot;http://usbng.delta-xi.net&quot;&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The paper according to this new release is found &lt;a href=&quot;http://download.delta-xi.net/doc/usbauth-ng_beta.pdf&quot;&gt;here&lt;/a&gt; as PDF.&lt;br /&gt;&lt;br /&gt;Source-browsing is done at the &lt;a href=&quot;http://svn.delta-xi.net/listing.php?repname=pam_usbng+-+An+PAM+module+for+authentication+through+USB+storage+devices&amp;path=%2F&amp;sc=0&quot;&gt;SVN web interface&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Mon, 16 Jun 2008 19:47:20 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/24-guid.html</guid>
    
</item>
<item>
    <title>Mysql Remote Authentication Bypassing Exploit</title>
    <link>http://blog.delta-xi.net/index.php?/archives/26-Mysql-Remote-Authentication-Bypassing-Exploit.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/26-Mysql-Remote-Authentication-Bypassing-Exploit.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=26</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=26</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img width=&quot;161&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;135&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/hack_mysql.jpg&quot; /&gt;As MySQL versions 4.1, 4.2 and early builds of 5.0 are vulnerable to a simple but devastating bug in the source code of the database server for which I couldn&#039;t find any exploit, here&#039;s a short description how to code it on your own.&lt;br /&gt;&lt;br /&gt;You may have a look on the &lt;a href=&quot;http://download.delta-xi.net/public/doc/MySQL.Authentication.bypassing.pdf&quot;&gt;paper&lt;/a&gt;, as well as on the &lt;a href=&quot;http://download.delta-xi.net/public/doc/MySQL.Authentication.bypassing_slides.pdf&quot;&gt;presentation slides&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Tue, 10 Jun 2008 16:43:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/26-guid.html</guid>
    
</item>
<item>
    <title>Collaboration with OWASP</title>
    <link>http://blog.delta-xi.net/index.php?/archives/25-Collaboration-with-OWASP.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/25-Collaboration-with-OWASP.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=25</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=25</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/owasp.jpg&quot; /&gt; The leader of the Backend Security Project of &lt;a title=&quot;OWASP&quot; href=&quot;http://www.owasp.org/index.php/Main_Page&quot;&gt;OWASP&lt;/a&gt; (Open Web Application Security Project), Carlo Pelliccioni, asked me for collaboration as he took a look into the Delta Xi &lt;a title=&quot;Hardening MySQL&quot; href=&quot;http://download.delta-xi.net/public/doc/Hardening.MySQL.pdf&quot;&gt;MySQL hardening paper&lt;/a&gt;.&lt;br /&gt;&lt;a&gt;&lt;carlo.pelliccioni@gmail.com /&gt;&lt;/a&gt;&lt;br /&gt;The resulting article (still under construction) can be found &lt;a href=&quot;http://www.owasp.org/index.php/OWASP_Backend_Security_Project_MySQL_Hardening&quot;&gt;directly at OWASP&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 30 May 2008 20:00:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/25-guid.html</guid>
    
</item>
<item>
    <title>Hardening MySQL on Unix-like systems</title>
    <link>http://blog.delta-xi.net/index.php?/archives/23-Hardening-MySQL-on-Unix-like-systems.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/23-Hardening-MySQL-on-Unix-like-systems.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=23</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=23</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img width=&quot;123&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;92&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/mysql.jpg&quot; /&gt;&lt;br /&gt;
I decided to take a look in hardening MySQL on Unix-like systems. The resulting paper includes some information about securing the operating system behind, secure local databases and network traffic by using cryptography and some other hints. The paper can be downloaded &lt;a href=&quot;http://dl.delta-xi.net/doc/Hardening.MySQL.pdf&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Sat, 22 Dec 2007 22:39:55 +0100</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/23-guid.html</guid>
    
</item>
<item>
    <title>Randomness in cryptography</title>
    <link>http://blog.delta-xi.net/index.php?/archives/22-Randomness-in-cryptography.html</link>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/22-Randomness-in-cryptography.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=22</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=22</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; style=&quot;width: 122px; height: 126px;&quot; src=&quot;http://download.delta-xi.net/images/crypto.jpg&quot; /&gt;Cryptographic routines and algorithms often rely on randomness, which is an essential fundament, especially in key-generation applications. This paper discusses how pseudo and real random numbers may be generated and how threatening unconcerness due to lack of entropy may seriously risk security. In addition, a brief overview of well-known and massively-used RNGs like Linux /dev/random are presented.&lt;br /&gt;&lt;br /&gt;You may download the &lt;a title=&quot;Randomness in cryptography&quot; href=&quot;http://dl.delta-xi.net/doc/Randomness.in.cryptography.pdf&quot;&gt;paper&lt;/a&gt;, as well as the &lt;a title=&quot;Randomness in cryptography Slides&quot; href=&quot;http://dl.delta-xi.net/doc/Randomness.in.cryptography_slides.pdf&quot;&gt;presentation slides&lt;/a&gt;.&lt;/p&gt;&lt;p /&gt; 
    </content:encoded>

    <pubDate>Wed, 17 Oct 2007 16:19:25 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/22-guid.html</guid>
    
</item>
<item>
    <title>X11 Keylogger w/o root-permissions</title>
    <link>http://blog.delta-xi.net/index.php?/archives/21-X11-Keylogger-wo-root-permissions.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/21-X11-Keylogger-wo-root-permissions.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=21</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=21</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img width=&quot;146&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;151&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/schluesselloch.jpg&quot; /&gt;Most keylogging solutions deserve to be called as root-user; Userspace-Loggers as well as Kernelspace-Loggers. This simple piece of code shows you how you can use X11 to get a nice workaround for keylogging X-sessions.&lt;br /&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://blog.delta-xi.net/index.php?/archives/21-X11-Keylogger-wo-root-permissions.html#extended&quot;&gt;Continue reading &quot;X11 Keylogger w/o root-permissions&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Sun, 23 Sep 2007 15:17:30 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/21-guid.html</guid>
    
</item>
<item>
    <title>Secure authentication systems</title>
    <link>http://blog.delta-xi.net/index.php?/archives/20-Secure-authentication-systems.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/20-Secure-authentication-systems.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=20</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=20</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img hspace=&quot;0&quot; height=&quot;199&quot; width=&quot;140&quot; vspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/hakin9.jpg&quot; /&gt;An article about secure authentication systems has recently been released in the &lt;a href=&quot;http://hakin9.org/de/haking/issues/9_2007.html&quot;&gt;hakin9&lt;/a&gt; print magazine, also covering USBAuth, which has been renewed and now also supports additional PIN-based hashed authentication for even more security.&lt;br /&gt;&lt;br /&gt;Also a Gentoo E-Build is finally available, thanks to Hades for these patches. In about one month, I&#039;ll release a paper about Randomness in Cryptography, the needs and behaviours of strong cryptographic algorithms which rely on true randomness and how stary-eyed RNGs can defeat strong encipherment.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Update&lt;/b&gt;: The German article can now be freely downloaded &lt;a href=&quot;http://download.delta-xi.net/public/doc/Sichere.Authentifikationssysteme_Hakin9.pdf&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 05 Sep 2007 15:23:58 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/20-guid.html</guid>
    
</item>
<item>
    <title>Online again</title>
    <link>http://blog.delta-xi.net/index.php?/archives/19-Online-again.html</link>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/19-Online-again.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=19</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=19</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;img width=&quot;144&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;144&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/panicbutton.jpg&quot; /&gt;&lt;/p&gt;&lt;p&gt;Due to contract issues, Delta Xi unfortunately had a downtime for about 6 days. These problems affected not only the HTTP/S service, but also SVN and the USBAuth space. Several updates are to be announced. Thanks to &lt;span&gt;&lt;a href=&quot;http://ph030.de&quot;&gt;ph030&lt;/a&gt;, who&#039;s ideas about using USBAuth with non-usb memory devices (e.g. SD), some bug tracking and a Gentoo ebuild will flow into the main code within the next 3-4 weeks.&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 25 Jun 2007 17:52:40 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/19-guid.html</guid>
    
</item>
<item>
    <title>Diffie-Hellmann via SMTP and a release of USBAuth</title>
    <link>http://blog.delta-xi.net/index.php?/archives/18-Diffie-Hellmann-via-SMTP-and-a-release-of-USBAuth.html</link>
            <category>Linux</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/18-Diffie-Hellmann-via-SMTP-and-a-release-of-USBAuth.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=18</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=18</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/news.png&quot; /&gt;The paper according to the DX article of symmetric mail cryptography is finally done. You may download the (German) paper &lt;a href=&quot;http://download.delta-xi.net/public/doc/Bachelor.thesis_Symmetric.mail.cryptography.pdf&quot;&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;USBAuth has grown very fast, thank all users for reports, testing and feedback. I&#039;ve put a lot of security-concerned stuff into the code, which makes USBAuth quite secure and ready for every-day use. The documentation, as well as the source and a Debian package of release 0.3 can be obtained from &lt;a href=&quot;http://usbauth.delta-xi.net/&quot;&gt;the USBAuth project site&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 02 May 2007 15:29:30 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/18-guid.html</guid>
    
</item>
<item>
    <title>Local PAM authentication for USB storage devices</title>
    <link>http://blog.delta-xi.net/index.php?/archives/17-Local-PAM-authentication-for-USB-storage-devices.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/17-Local-PAM-authentication-for-USB-storage-devices.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=17</wfw:comment>

    <slash:comments>10</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=17</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;img width=&quot;179&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;179&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/wordlock.jpg&quot; /&gt;Security policies commonly don&#039;t fit the laziness of users and system administrators. You shouldn&#039;t be logged in as root directly, you shouldn&#039;t use short and unsafe passwords, and so on.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;&lt;br /&gt;pam_usbauth.so let&#039;s you authenticate yourself on your system, passwordless with just having something like a &amp;quot;crypto USB device&amp;quot; plugged in - without additional uncommon hardware.&lt;/p&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://blog.delta-xi.net/index.php?/archives/17-Local-PAM-authentication-for-USB-storage-devices.html#extended&quot;&gt;Continue reading &quot;Local PAM authentication for USB storage devices&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 25 Apr 2007 10:55:02 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/17-guid.html</guid>
    
</item>
<item>
    <title>OTPs: Using s/Key with SSH via OPIE</title>
    <link>http://blog.delta-xi.net/index.php?/archives/16-OTPs-Using-sKey-with-SSH-via-OPIE.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/16-OTPs-Using-sKey-with-SSH-via-OPIE.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=16</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=16</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;img width=&quot;133&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;183&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://blog.delta-xi.net/uploads/onetimepad.jpg&quot; /&gt;&lt;br /&gt;
Passwords are a quite debatable way of authentification. Passwords can be sniffed and widely used with other services, if the same passwords are used on more than one service.&lt;br /&gt;
&lt;br /&gt;
Biometrical identification is another form of authetication, but not quite suitable via remote access. An excellent standard is defined by s/Key. Read how to use this on Linux boxes...&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://blog.delta-xi.net/index.php?/archives/16-OTPs-Using-sKey-with-SSH-via-OPIE.html#extended&quot;&gt;Continue reading &quot;OTPs: Using s/Key with SSH via OPIE&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Wed, 18 Apr 2007 09:27:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/16-guid.html</guid>
    
</item>
<item>
    <title>Centralized logging of multiple servers</title>
    <link>http://blog.delta-xi.net/index.php?/archives/15-Centralized-logging-of-multiple-servers.html</link>
            <category>Linux</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/15-Centralized-logging-of-multiple-servers.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=15</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=15</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;img vspace=&quot;0&quot; hspace=&quot;0&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/logbook.jpg&quot; style=&quot;width: 207px; height: 152px;&quot; /&gt;Syslogd is the friend of all administrators. No serious admin would miss taking a look in /var/log/* consistantly. Reading and working out log files is a very time consuming process, and even more complicated when administrating multiple server boxes.&lt;/p&gt;&lt;p&gt;This mini-howto shows you how to centralize your logs.&lt;/p&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://blog.delta-xi.net/index.php?/archives/15-Centralized-logging-of-multiple-servers.html#extended&quot;&gt;Continue reading &quot;Centralized logging of multiple servers&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Tue, 17 Apr 2007 03:03:00 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/15-guid.html</guid>
    
</item>
<item>
    <title>Featuring a near-HIDS: Mtree for data integrity</title>
    <link>http://blog.delta-xi.net/index.php?/archives/14-Featuring-a-near-HIDS-Mtree-for-data-integrity.html</link>
            <category>Security</category>
    
    <comments>http://blog.delta-xi.net/index.php?/archives/14-Featuring-a-near-HIDS-Mtree-for-data-integrity.html#comments</comments>
    <wfw:comment>http://blog.delta-xi.net/wfwcomment.php?cid=14</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://blog.delta-xi.net/rss.php?version=2.0&amp;type=comments&amp;cid=14</wfw:commentRss>
    

    <author>nospam@example.com (Erik Sonnleitner)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;&lt;img width=&quot;180&quot; vspace=&quot;0&quot; hspace=&quot;0&quot; height=&quot;168&quot; border=&quot;0&quot; align=&quot;right&quot; src=&quot;http://download.delta-xi.net/images/tree.jpg&quot; /&gt;One and a half decades before, firewalls have had an exciting hype towards the whole Internet community. A few years later, numberous companies tried to get customers by releasing (partitally really obscure) security systems by calling them &amp;quot;Intrusion detection&amp;quot;, then, again a few years later, &amp;quot;Intrusion prevention&amp;quot; and nowadays also prevention is not enough, but the software is called &amp;quot;Intrusion Reaction&amp;quot;.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;However, something like a host-based intrusion detection system can be established via a small FreeBSD tool called Mtree.&lt;/p&gt;&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://blog.delta-xi.net/index.php?/archives/14-Featuring-a-near-HIDS-Mtree-for-data-integrity.html#extended&quot;&gt;Continue reading &quot;Featuring a near-HIDS: Mtree for data integrity&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Mon, 16 Apr 2007 12:35:59 +0200</pubDate>
    <guid isPermaLink="false">http://blog.delta-xi.net/index.php?/archives/14-guid.html</guid>
    
</item>

</channel>
</rss>