<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>evcz.tk &#187; Uncategorized</title>
	<atom:link href="http://evcz.tk/blog/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://evcz.tk/blog</link>
	<description>my own pastebin :P</description>
	<lastBuildDate>Fri, 18 May 2012 11:19:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>È successo: fastweb + ip bogon (5.0.0.0/8) = EPIC FAIL</title>
		<link>http://evcz.tk/blog/2012/05/18/e-successo-fastweb-ip-bogon-5-0-0-08-epic-fail/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=e-successo-fastweb-ip-bogon-5-0-0-08-epic-fail</link>
		<comments>http://evcz.tk/blog/2012/05/18/e-successo-fastweb-ip-bogon-5-0-0-08-epic-fail/#comments</comments>
		<pubDate>Fri, 18 May 2012 00:24:18 +0000</pubDate>
		<dc:creator>EvolutionCrazy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://evcz.tk/blog/?p=144</guid>
		<description><![CDATA[http://www.hostingtalk.it/forum/server-dedicati-colocation-connettivita-e-scelta-data-center/25527-hetzner-fastweb.html http://www.webhostingtalk.com/showthread.php?p=8130717#post8130717 AHAHAHAHAH EDIT: per una spiegazione più completa: http://blog.grg-web.eu/2012/05/rfc-ignorate-la-fine-del-mondo-inizia-con-fastweb/]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.hostingtalk.it/forum/server-dedicati-colocation-connettivita-e-scelta-data-center/25527-hetzner-fastweb.html" title="http://www.hostingtalk.it/forum/server-dedicati-colocation-connettivita-e-scelta-data-center/25527-hetzner-fastweb.html" target="_blank">http://www.hostingtalk.it/forum/server-dedicati-colocation-connettivita-e-scelta-data-center/25527-hetzner-fastweb.html</a></p>
<p><a href="http://www.webhostingtalk.com/showthread.php?p=8130717#post8130717" title="http://www.webhostingtalk.com/showthread.php?p=8130717#post8130717" target="_blank">http://www.webhostingtalk.com/showthread.php?p=8130717#post8130717</a></p>
<p>AHAHAHAHAH</p>
<p>EDIT: per una spiegazione più completa:<br />
<a href="http://blog.grg-web.eu/2012/05/rfc-ignorate-la-fine-del-mondo-inizia-con-fastweb/" title="RFC Ignorate, la Fine del Mondo Inizia con Fastweb" target="_blank">http://blog.grg-web.eu/2012/05/rfc-ignorate-la-fine-del-mondo-inizia-con-fastweb/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://evcz.tk/blog/2012/05/18/e-successo-fastweb-ip-bogon-5-0-0-08-epic-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chargen (UDP port 19) &#8211; Reflected ddos</title>
		<link>http://evcz.tk/blog/2012/05/06/chargen-udp-port-19-reflecte-ddos/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=chargen-udp-port-19-reflecte-ddos</link>
		<comments>http://evcz.tk/blog/2012/05/06/chargen-udp-port-19-reflecte-ddos/#comments</comments>
		<pubDate>Sun, 06 May 2012 12:32:27 +0000</pubDate>
		<dc:creator>EvolutionCrazy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://evcz.tk/blog/?p=133</guid>
		<description><![CDATA[Lately I&#8217;m seeing chargen service being abused a lot to execute distributed denial of service attacks. It&#8217;s not just &#8220;standard ddos&#8221;&#8230; it&#8217;s a reflected ddos with a massive aplification rate!!! (Amplification rate can be as high as 512x&#8230; that means with that just a 100mbit pipe a malicius attacker could easely accomplish a 10gbit+ ddos!) [...]]]></description>
			<content:encoded><![CDATA[<p>Lately I&#8217;m seeing chargen service being abused a lot to execute distributed denial of service attacks.<br />
It&#8217;s not just &#8220;standard ddos&#8221;&#8230; it&#8217;s a <strong>reflected ddos</strong> with a <strong>massive aplification rate</strong>!!!<br />
(Amplification rate can be as high as 512x&#8230; that means with that just a 100mbit pipe a malicius attacker could easely accomplish a 10gbit+ ddos!)</p>
<p><strong>What is chargen?</strong></p>
<p>From <a href="http://en.wikipedia.org/wiki/Character_Generator_Protocol" title="wikipedia" target="_blank">wikipedia</a>:<br />
<<<strong>In the UDP implementation of the protocol, the server sends a UDP datagram containing a random number (between 0 and 512) of characters every time it receives a datagram from the connecting host.</strong>>></p>
<p>Apparently there&#8217;s absolutely no handshake at all with chargen&#8230; only the TCP version (obviously) requires handshake&#8230;</p>
<p><strong>How are hosts running chargen (UDP) used as botnets?</strong></p>
<p>To execute the attack people are sending spoofed UDP packets with a forged source IP address to hundreds of hosts running chargen (and there are many of them!).<br />
These hosts just reply to the apparent source of such packet as they are intendend to do&#8230; the problem is that they are replying to the forged IP address&#8230; that host has never requested something to them!</p>
<p><strong>Is my machine vulnerable?</strong></p>
<p>To test if your machine could be exploited just run:<br />
echo t | nc -u X.X.X.X 19</p>
<p>replace X.X.X.X with an IP running chargen&#8230; If you got a reply you just found a host that can be used as part of a ddos botnet&#8230;</p>
<p><strong>How can I make my machine secure?</strong></p>
<p>details on how to disable chargen service:<br />
<a href="http://shalb.com/kb/entry/10043/">http://shalb.com/kb/entry/10043/</a><br />
(on that link they refer to another weak point of chargen: looks like it can also be used to let machines running chargen attack each-other&#8230;)</p>
<p>if you are running chargen on one of your hosts: CLOSE THAT FUCKING PORT (IN UDP 19)!<br />
if you are a carrier/ISP that allows spoofed traffic to leave your network: HOPE YOU GET BANKRUPT AND CLOSE YOUR FUCKING DOORS FOR GOOD!</p>
<p>ktnxbye</p>
]]></content:encoded>
			<wfw:commentRss>http://evcz.tk/blog/2012/05/06/chargen-udp-port-19-reflecte-ddos/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Calendar &#8211; how to fix missing holidays calendar</title>
		<link>http://evcz.tk/blog/2012/04/25/google-calendar-how-to-fix-missing-holidays-calendar/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-calendar-how-to-fix-missing-holidays-calendar</link>
		<comments>http://evcz.tk/blog/2012/04/25/google-calendar-how-to-fix-missing-holidays-calendar/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 22:07:56 +0000</pubDate>
		<dc:creator>EvolutionCrazy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://evcz.tk/blog/?p=130</guid>
		<description><![CDATA[I was missing the holidays calendar into a specific google calendar account&#8230; in order to add it back again this is the calendar address: it.italian#holiday@group.v.calendar.google.com just add it as it was a new calendar you want to link another special calendar you might want to add is: #contacts@group.v.calendar.google.com]]></description>
			<content:encoded><![CDATA[<p>I was missing the holidays calendar into a specific google calendar account&#8230;</p>
<p>in order to add it back again this is the calendar address:</p>
<pre>it.italian#holiday@group.v.calendar.google.com</pre>
<p>just add it as it was a new calendar you want to link </p>
<p>another special calendar you might want to add is:</p>
<pre>#contacts@group.v.calendar.google.com</pre>
]]></content:encoded>
			<wfw:commentRss>http://evcz.tk/blog/2012/04/25/google-calendar-how-to-fix-missing-holidays-calendar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My old projects</title>
		<link>http://evcz.tk/blog/2009/06/11/my-old-projects/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=my-old-projects</link>
		<comments>http://evcz.tk/blog/2009/06/11/my-old-projects/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 20:20:17 +0000</pubDate>
		<dc:creator>EvolutionCrazy</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[php2dns]]></category>
		<category><![CDATA[phpipblocker]]></category>

		<guid isPermaLink="false">http://evcz.tk/blog/?p=61</guid>
		<description><![CDATA[As I&#8217;m going to close down &#8220;evcz.altervista.org&#8221;, will archive here something from my past&#8230; phpipblocker (last version 0.99j) phpipblocker archive php2dns (last version 0.91beta) php2dns archive]]></description>
			<content:encoded><![CDATA[<p>As I&#8217;m going to close down &#8220;evcz.altervista.org&#8221;, will archive here something from my past&#8230;</p>
<p>phpipblocker (last version 0.99j)<br />
<a target="_blank" href="http://evcz.tk/archivio.files/varie/av/files/phpipblocker/">phpipblocker archive</a></p>
<p>php2dns (last version 0.91beta)<br />
<a target="_blank" href="http://evcz.tk/archivio.files/varie/av/files/php2dns/">php2dns archive</a></p>
]]></content:encoded>
			<wfw:commentRss>http://evcz.tk/blog/2009/06/11/my-old-projects/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

