<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Blogs @ Balius Inc</title>
	<atom:link href="http://blogs.balius.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.balius.com</link>
	<description>Information Security ramblings and other geek stuff</description>
	<lastBuildDate>Fri, 19 Mar 2010 01:24:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Scary tool &#8211; dnscat</title>
		<link>http://blogs.balius.com/2010/03/18/scary-tool-dnscat/</link>
		<comments>http://blogs.balius.com/2010/03/18/scary-tool-dnscat/#comments</comments>
		<pubDate>Fri, 19 Mar 2010 01:24:26 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[covert channels]]></category>
		<category><![CDATA[dnscat]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=848</guid>
		<description><![CDATA[The idea of this tool is that you can run just about any program and/or copy files to/from the machine, say an ssh session, using DNS packets to/from the client.  In other words, a workstation sitting on a network somewhere, behind the companies firewalls, IPS/IDS, AV, etc., etc. could communicate with a system on the [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/03/18/scary-tool-dnscat/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>FBI Supply chain compromised :)</title>
		<link>http://blogs.balius.com/2010/03/11/fbi-supply-chain-compromised/</link>
		<comments>http://blogs.balius.com/2010/03/11/fbi-supply-chain-compromised/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 12:55:50 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[Blogs]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=845</guid>
		<description><![CDATA[http://blogs.csoonline.com/the_fbi_supply_chain_illustrated Funny!]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/03/11/fbi-supply-chain-compromised/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A great example of why you need&#8230;</title>
		<link>http://blogs.balius.com/2010/03/11/a-great-example-of-why-you-need/</link>
		<comments>http://blogs.balius.com/2010/03/11/a-great-example-of-why-you-need/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 12:06:18 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[ISC]]></category>
		<category><![CDATA[NSM]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=843</guid>
		<description><![CDATA[defense in depth (which includes egress filters) and Network Security Monitoring (NSM).  This diary post on isc.sans.org is a good example of why companies need to practice defense in depth.  I have spent many years involved with messaging, back in 1995 I didn&#8217;t know what SMTP meant, but thanks to a gentleman at then Xerox [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/03/11/a-great-example-of-why-you-need/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google asking NSA for help</title>
		<link>http://blogs.balius.com/2010/02/07/google-asking-nsa-for-help/</link>
		<comments>http://blogs.balius.com/2010/02/07/google-asking-nsa-for-help/#comments</comments>
		<pubDate>Sun, 07 Feb 2010 20:29:55 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[NSA]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=837</guid>
		<description><![CDATA[In this article Google is reportedly asking for assistance from the NSA. From my limited knowledge of the NSA, this sounds like the right thing to do. I have done plenty of work under non-discolure agreements (NDAs). Given the people that work at the NSA, I don&#8217;t see a problem with Google working with them. [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/02/07/google-asking-nsa-for-help/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monitor your traffic and egress filters</title>
		<link>http://blogs.balius.com/2010/02/04/monitor-your-traffic-and-egress-filters/</link>
		<comments>http://blogs.balius.com/2010/02/04/monitor-your-traffic-and-egress-filters/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 12:07:55 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[apt]]></category>
		<category><![CDATA[nms]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=813</guid>
		<description><![CDATA[I&#8217;m reading this story and I quote Last year, for example, an unidentified defense contractor discovered 100 compromised systems on its network, and found that the intruders had been inside since at least 2007. Hopefully now they&#8217;ve come to realize that monitoring your network, as in the traffic patterns, rates, etc. is very important too.  [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/02/04/monitor-your-traffic-and-egress-filters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Forcing ssh login via s/key</title>
		<link>http://blogs.balius.com/2010/02/03/forcing-ssh-login-via-skey/</link>
		<comments>http://blogs.balius.com/2010/02/03/forcing-ssh-login-via-skey/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:16:28 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[authpf]]></category>
		<category><![CDATA[OpenBSD]]></category>
		<category><![CDATA[s/key]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=504</guid>
		<description><![CDATA[In the back of my mind are the recent attacks against Google and others by the Chinese government.  I keep asking myself how I would setup and defend against such attacks, and more importantly mitigate them. The end goal of this exercise for me, is to limit Internet access to devices that have authenticated to [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/02/03/forcing-ssh-login-via-skey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Quick MySQL backup script</title>
		<link>http://blogs.balius.com/2010/01/06/quick-mysql-backup-script/</link>
		<comments>http://blogs.balius.com/2010/01/06/quick-mysql-backup-script/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 01:25:42 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[backups]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[quick n dirty]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=478</guid>
		<description><![CDATA[I now and again add/delete websites and their subsequent databases too my server(s).  I use the following script to backup the databases.  Using this I don&#8217;t have to worry about remembering to change the script to capture a database or to stop looking for a database.  The script (which runs as root) learns the databases [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2010/01/06/quick-mysql-backup-script/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone &#8211; ip forwarding YES</title>
		<link>http://blogs.balius.com/2009/11/27/iphone-ip-forwarding-yes/</link>
		<comments>http://blogs.balius.com/2009/11/27/iphone-ip-forwarding-yes/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 22:07:27 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[IP router]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[TCP/IP]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=469</guid>
		<description><![CDATA[As I tweeted earlier I was poking around my jail broken iPhone and discovered IP forwarding does work.  I&#8217;ve been searching for ways to tether my iPhone to various computers.  I was able to use OpenSSH and establish a SOCKS proxy yesterday.  That works nicely and given the &#8220;Location&#8221; feature of OS X and the [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2009/11/27/iphone-ip-forwarding-yes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>idea for authpf</title>
		<link>http://blogs.balius.com/2009/11/25/idea-for-authpf/</link>
		<comments>http://blogs.balius.com/2009/11/25/idea-for-authpf/#comments</comments>
		<pubDate>Thu, 26 Nov 2009 00:06:44 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[Blogs]]></category>
		<category><![CDATA[authpf]]></category>
		<category><![CDATA[OpenBSD]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=453</guid>
		<description><![CDATA[I know some sites trust their servers and let the servers talk to anywhere on the Internet or internally. Just had a thought, instead all servers should be blocked for all traffic except for business needed traffic. What about updates? The servers need to go fetch updates. (In those cases where the patches/updates are not [...]]]></description>
		<wfw:commentRss>http://blogs.balius.com/2009/11/25/idea-for-authpf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Create an iso image on a Mac</title>
		<link>http://blogs.balius.com/2009/11/25/create-an-iso-image-on-a-mac/</link>
		<comments>http://blogs.balius.com/2009/11/25/create-an-iso-image-on-a-mac/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 21:27:42 +0000</pubDate>
		<dc:creator>Chad Stewart</dc:creator>
				<category><![CDATA[HowTo]]></category>
		<category><![CDATA[how to]]></category>
		<category><![CDATA[Mac]]></category>

		<guid isPermaLink="false">http://blogs.balius.com/?p=451</guid>
		<description><![CDATA[The steps I use to create an ISO image on my Macs. ## make an iso on the command line ## use the exact slice, use df to check drutil status # look for Name: /dev/disk* diskutil unmountDisk /dev/disk dd if=/dev/disk of=/Users/Shared/Software/name-of-iso bs=2048 # then test with finder/disk util/etc.]]></description>
		<wfw:commentRss>http://blogs.balius.com/2009/11/25/create-an-iso-image-on-a-mac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
