<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-7468008418270845225</atom:id><lastBuildDate>Sat, 19 May 2012 06:02:59 +0000</lastBuildDate><category>Wireless</category><category>hip-hop</category><category>mullet</category><category>movies</category><category>passwords</category><category>perl</category><category>comic</category><category>duel</category><category>piracy</category><category>privacy</category><category>hacking</category><category>wow</category><category>geocaching</category><category>open source</category><category>censorship</category><category>product</category><category>biking</category><category>San Diego</category><category>psychology</category><category>iphone</category><category>shell</category><category>python</category><category>spam</category><category>setups</category><category>internet</category><category>debian</category><category>email</category><category>lockpicking</category><category>sexuality</category><category>SSL</category><category>evil</category><category>firewall</category><category>nonsense</category><category>solaris</category><category>Religion</category><category>rant</category><category>science</category><category>lame</category><category>linux</category><category>racism</category><category>idea</category><category>research</category><category>lost</category><category>social engineering</category><category>video games</category><category>photography</category><category>security</category><category>politics</category><category>programming</category><category>xoom</category><category>random</category><category>graffiti</category><category>music</category><category>geek</category><category>schizophrenia</category><category>depression</category><category>terrorism</category><category>go</category><category>apartment</category><category>BP</category><category>kde</category><category>gps</category><category>Denial of Service</category><category>WEP</category><category>copyright</category><category>android</category><category>anonyimizer</category><category>wildfires</category><category>hacks</category><category>software</category><category>food</category><category>tech support</category><category>entertainment</category><category>Verizon</category><category>weird</category><category>career</category><category>paranoia</category><category>failure</category><category>incredible</category><category>blogging</category><category>stupid</category><category>pet</category><title>Clinically Awesome</title><description>Jason Mansfield is a software engineer, security enthusiast, and crazy thinker living in Silicon Valley.</description><link>http://www.clinicallyawesome.com/</link><managingEditor>noreply@blogger.com (Jason Mansfield)</managingEditor><generator>Blogger</generator><openSearch:totalResults>177</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-7739133470457008334</guid><pubDate>Thu, 01 Mar 2012 18:30:00 +0000</pubDate><atom:updated>2012-03-01T10:30:18.734-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>movies</category><category domain='http://www.blogger.com/atom/ns#'>piracy</category><title>Movie Quality, Piracy, and the Cinema Experience</title><description>Movie theaters are way too expensive. Ticket prices, concessions, the whole nine. I deal with the cost of concessions by not buying them. I deal with the cost of tickets by being very picky about which movies I'll see in the theater.&lt;br /&gt;&lt;br /&gt;I used to download movies on bit torrent a lot. Despite being able to download movies for free, eat my own food, sit on the comfort of my couch and pause it when I wanted I would still go to the theater a couple times a month.&lt;br /&gt;&lt;br /&gt;I stopped torrenting movies when Netflix came into my life. A lot of people say that piracy is really a content-delivery problem and there's definitely some truth there. As Netflix's streamable library has grown, torrents have gotten further from my mind. To be clear, I would rather pay for access to Netflix than torrent movies for free.&lt;br /&gt;&lt;br /&gt;Netflix fills several roles for me:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Killing time: I will not buy a movie ticket for this&lt;/li&gt;&lt;li&gt;Television shows: I can't buy a movie ticket for this, nor would I&lt;/li&gt;&lt;li&gt;Movies I missed in the theater&lt;/li&gt;&lt;li&gt;Movies long out of the theater&lt;/li&gt;&lt;li&gt;Movies I don't think are worth seeing in the theater&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;If Netflix disappeared with no replacement I still wouldn't go to the theater for any of the above reasons. What &lt;i&gt;does&lt;/i&gt;&amp;nbsp;bring me into the theater? A good movie on a big screen with great sound. If the reviews for a movie are mixed I'll usually wait to watch it via Netflix. A key point to emphasize is that "new release" is not something that brings me to the theater.&lt;br /&gt;&lt;br /&gt;I'm optimistic that theaters are starting to get that last point. Locally, "Titanic" and "Star Wars Episode I (in what's-the-fucking-point 3D)" have made trips back through the theaters. Say what you want about the films, if you're going to see them at all, the big screen is the way. We need lots more of this with cheaper ticket prices.&lt;br /&gt;&lt;br /&gt;Dear Hollywood,&lt;br /&gt;&lt;br /&gt;You don't have to lose money by making another shitty romantic comedy or Resident Evil movie. You can show us movies we've already seen and if you pick good ones we'll pay to see them. We will &lt;i&gt;pay&lt;/i&gt; to come to theaters to see movies &lt;i&gt;we already own&lt;/i&gt;. You can even draw people in by showing director's cuts and the like. Bring the older movies in a series back into theaters before the next sequel comes out. Put "The Godfather", the Indiana Jones movies, "Blade Runner", or "Airplane!" in theaters and I'll see them all in a week.&lt;br /&gt;&lt;br /&gt;What's critical is that you stop making terrible movies. Instead, give us consumers real reasons to come to the theater and make the theater experience something meaningful. Given the digital projection systems it seems unlikely to me that distribution is a significant hurdle to this. If bandwidth is a concern for getting the extremely high resolution movies out to theaters perhaps you can utilize something bandwidth-efficient for the distributor... like bit torrent.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-7739133470457008334?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2012/03/movie-quality-piracy-and-cinema.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-4344918338349124637</guid><pubDate>Fri, 11 Nov 2011 20:13:00 +0000</pubDate><atom:updated>2011-11-11T12:27:06.703-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>xoom</category><category domain='http://www.blogger.com/atom/ns#'>android</category><title>Xoom LTE Upgrade</title><description>A bought a Motorola Xoom android tablet the day it came out and from the beginning there was the promise that it would be upgraded for free to 4G LTE. Last week I got the notice that I could upgrade. Here's how it went:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="background-color: transparent;"&gt;I signed up on Nov 2nd and quickly got a shipment traffic email from Motorola.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="background-color: transparent;"&gt;Nov 3rd I received a pre-labeled FedEx box with instructions and packing materials.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="background-color: transparent;"&gt;Nov 7th I got around to shipping it out.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="background-color: transparent;"&gt;Nov 10th I received the upgraded tablet.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;The turnaround time for this was pretty staggering. I'm guessing the recognize that a lot of people depend on these things and wouldn't be happy having to be without their's for long.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The instructions with the returned tablet said I would have to turn it on and when I got logged in I would get a prompt for turning on 4G LTE after a few minutes. Somehow I had cancelled the prompt when it appeared. I found the settings (clearly indicated in the instructions had I cared to look) and then it was a waiting game.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The instructions said it might take a few hours for OTA registration to complete. I was occasionally checking the network connectivity indicator in the lower right to say "4G" instead of "3G". After three hours nothing happened so I went to reboot the device to try again. When it booted back up it immediately said "4G". It worked!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I haven't really played with the 4G much yet as I'm pretty much in WiFi range all the time during my week. I did turn WiFi off for a few and pulled up maps just to see if it was fast. &lt;i&gt;Man those map tiles loaded fast&lt;/i&gt;. I even got a free OEM standard dock (power and audio connectivity, no speakers, USB, or HDMI) as a "while supplies last" deal. In theory they could have upgraded my Android Market to a newer version but my tablet was encrypted so I had to do it myself. I'm more comfortable with the encryption and an extra upgrade step.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Overall, Motorola did a fantastic job with this. The instructions they provided were clear and described exactly what would happen with the upgrade process. I was pretty floored by how fast I got my upgraded device back. If you bought a 3G Xoom from Verizon you should definitely take advantage of this.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-4344918338349124637?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/11/xoom-lte-upgrade.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-3258343303880141813</guid><pubDate>Thu, 06 Oct 2011 19:08:00 +0000</pubDate><atom:updated>2011-10-06T12:08:18.291-07:00</atom:updated><title>On Google+</title><description>I'm trying out this &lt;a href="https://plus.google.com/116775222297299631121/posts"&gt;Google+&lt;/a&gt; thing.&lt;br /&gt;&lt;br /&gt;I have a Facebook that I maintain for people to find me. Every time I log in my &lt;i&gt;mind recoils in horror&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;I previously used tumblr for blogging and really liked the asymmetrical sharing model. Hopefully Google+ incorporated the good bits of everything.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-3258343303880141813?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/10/on-google.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-308879172547250287</guid><pubDate>Fri, 01 Jul 2011 19:30:00 +0000</pubDate><atom:updated>2011-07-01T12:30:58.833-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>go</category><category domain='http://www.blogger.com/atom/ns#'>programming</category><title>Go Language Compile/Link/Launch Script</title><description>I've started playing around with the &lt;a href="http://golang.org/"&gt;Go language&lt;/a&gt; and I think it's pretty neat. I have a security-related project I'm working on to help me learn the language that I'll share soon after it's finished.&lt;br /&gt;&lt;br /&gt;I found myself slightly annoyed when I would compile, link, and launch my program while editing it. It was fast but the command line was long:&lt;br /&gt;&lt;blockquote&gt;&lt;code&gt;bin/6g whatever.go &amp;amp;&amp;amp; bin/6l -o whatever whatever.6 &amp;amp;&amp;amp; ./whatever -arg1 blah -arg2&lt;/code&gt;&lt;/blockquote&gt;To make things a little easier when switching between source files I wrote a simple script:&lt;br /&gt;&lt;blockquote&gt;&lt;code&gt;#!/bin/bash&lt;br /&gt;#gogogo.sh &amp;lt;program_name&amp;gt; [&amp;lt;args&amp;gt;]&lt;br /&gt;&lt;br /&gt;progname=${1}&lt;br /&gt;shift&lt;br /&gt;bin/6g ${progname}.go &amp;amp;&amp;amp; bin/6l -o ${progname} ${progname}.6 &amp;amp;&amp;amp; ./${progname} ${@}&lt;/code&gt;&lt;/blockquote&gt;Now just run:&lt;br /&gt;&lt;blockquote&gt;&lt;code&gt;./gogogo.sh whatever -arg1 blah -arg2&lt;/code&gt;&lt;/blockquote&gt;There's probably a smarter way using &lt;i&gt;gomake&lt;/i&gt;&amp;nbsp;or something similar but I haven't dug it up yet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-308879172547250287?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/07/go-language-compilelinklaunch-script.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-6083218264234865462</guid><pubDate>Fri, 18 Feb 2011 02:40:00 +0000</pubDate><atom:updated>2011-02-17T18:40:07.832-08:00</atom:updated><title>evilbitchanger</title><description>I've been learning &lt;a href="http://www.secdev.org/projects/scapy/"&gt;scapy&lt;/a&gt;, which is an awesome tool. I have a colleague who is doing some research and had a need for a tool that could modify IP packets in arbitrary ways either from a pcap file or on packets in real time. The prototype sets the IP &lt;a href="http://en.wikipedia.org/wiki/Evil_bit"&gt;evil bit&lt;/a&gt;, recalculates the checksum and forwards the new packet.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Web page &lt;a href="http://static.clinicallyawesome.com/projects/evilbitchanger/start"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Code hosted &lt;a href="http://code.google.com/p/evilbitchanger/"&gt;here&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-6083218264234865462?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/02/evilbitchanger.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-2957521118028543880</guid><pubDate>Tue, 08 Feb 2011 18:55:00 +0000</pubDate><atom:updated>2011-02-08T10:55:38.405-08:00</atom:updated><title>Management vs Leadership</title><description>Management Skills != Leadership Skills&lt;br /&gt;&lt;br /&gt;IMO:&lt;br /&gt;&lt;br /&gt;People management: concerned with the career growth, compensation, work satisfaction, etc of your reports. In a sense, this is a local extension of HR. Not a technical role. Must be well-versed in the issues related to employee effectiveness.&lt;br /&gt;&lt;br /&gt;Project/Product/Program Management: concerned with planning, development, execution, and maintenance of products, services, etc. Should be technically competent but somewhat isolated from implementation.&lt;br /&gt;&lt;br /&gt;Leadership: Inspires a team and fosters a culture optimized toward producing the desired result. Leadership skills are independent of other skills but complement them. Sometimes the action indicated by good leadership is contradicted by good management.&lt;br /&gt;&lt;br /&gt;People managers deal in carrots, project managers deal in sticks, leaders deal in aspiration.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-2957521118028543880?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/02/management-vs-leadership.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-8733660479109054242</guid><pubDate>Tue, 01 Feb 2011 16:44:00 +0000</pubDate><atom:updated>2011-02-01T08:44:19.933-08:00</atom:updated><title>PS3 Rootkit</title><description>&lt;a href="http://www.jailbreakscene.com/2011/01/official-ps3-firmware-v356-has-rootkit.html"&gt;Official PS3 firmware v3.56 has a rootkit&lt;/a&gt;&lt;br /&gt;It is imperative that someone create a PS3 worm.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-8733660479109054242?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/02/ps3-rootkit.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-6944316501231629843</guid><pubDate>Tue, 01 Feb 2011 00:48:00 +0000</pubDate><atom:updated>2011-01-31T16:48:38.024-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>security</category><title>Remakes</title><description>There's been a trend over the last couple years where old movies are remade and handed to us as something new.&lt;br /&gt;&lt;br /&gt;When IPv6 becomes common place, the same thing is going to happen with network vulnerabilities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-6944316501231629843?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/01/remakes.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-4700933192931631470</guid><pubDate>Thu, 06 Jan 2011 23:12:00 +0000</pubDate><atom:updated>2011-01-06T15:12:28.489-08:00</atom:updated><title>Altism</title><description>&lt;i&gt;Altism&lt;/i&gt;&amp;nbsp;-noun:&lt;br /&gt;&lt;br /&gt;The mental deficiency wherein on believes that something is superior because it is uncommon.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-4700933192931631470?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2011/01/altism.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-7478520480402145171</guid><pubDate>Wed, 17 Nov 2010 04:28:00 +0000</pubDate><atom:updated>2010-11-16T20:28:56.893-08:00</atom:updated><title>Move Complete</title><description>My blog move has been completed! In the future I'll write up notes about the process and share the python code I used to do the migration.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-7478520480402145171?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/11/move-complete.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-5552169627707450343</guid><pubDate>Tue, 02 Nov 2010 18:54:00 +0000</pubDate><atom:updated>2010-11-04T06:40:40.788-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>nonsense</category><category domain='http://www.blogger.com/atom/ns#'>security</category><title>Adobe Anagram</title><description>&lt;p&gt;Anyone else notice that Adobe is an anagram for &amp;#8220;B O-dae&amp;#8221;?&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-5552169627707450343?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/11/adobe-anagram_4290.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-3451200642952044370</guid><pubDate>Thu, 28 Oct 2010 09:13:00 +0000</pubDate><atom:updated>2010-11-04T06:40:46.806-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>nonsense</category><category domain='http://www.blogger.com/atom/ns#'>security</category><title>Adobe: Productive Media Tools</title><description>&lt;p&gt;Adobe should incorporate some of the security buzz into their marketing:&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;  &lt;p&gt;Adobe media tools increase productivity, giving you 0-day turnaround.&lt;/p&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;The SEO opportunities are endless.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-3451200642952044370?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/10/adobe-productive-media-tools_2318.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-414828184446652193</guid><pubDate>Tue, 26 Oct 2010 17:29:00 +0000</pubDate><atom:updated>2012-03-02T09:08:13.948-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>nonsense</category><category domain='http://www.blogger.com/atom/ns#'>security</category><title>Advanced Evasion Techniques: A Long-Winded Explanation of the Threat</title><description>Recently a company called Stonesoft launched a website called &lt;a href="http://www.antievasion.com/"&gt;&lt;/a&gt;&lt;a href="http://www.antievasion.com/"&gt;http://www.antievasion.com/&lt;/a&gt; with videos warning us about the threat of Advanced Evasion Techniques that can float right through your network security and attack systems you thought were protected. The videos on their site are worth watching, if for no other reason that they approach self-parody.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Their concern lies mostly in Intrusion Detection/Prevention System (IDS/IPS) software and appliances. These devices observe traffic passing through looking for behavior indicative of an attack in a fashion conceptually similar to antivirus/antimalware. IDS systems merely “observe and report” while IPS systems intervene, trying to cut connections or otherwise stop the attack. The limitation of these types of systems is that they’re primarily signature-based; they are looking for a specific set of indicators to determine that something is an &lt;em&gt;attack&lt;/em&gt;. They cannot say with certainty that anything is &lt;em&gt;safe&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Compare this to police mugshots. You can use them to identify known bad guys but you can’t use them to identify unknown bad guys or bad guys with convincing disguises. Modern IDS/IPS (and antivirus) are smarter. They’re better at recognizing fake beards, hats, and changes of clothes. These kinds of attack disguises have often been referred to as “IDS/IPS evasion techniques” and they’re almost as old as IDS/IPS technology itself. As is always the case on the Internet, the good guys cause the bad guys to evolve and vice versa. IDS/IPS technology gets better, IDS/IPS evasion techniques get better.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;These “disguises” involve changing the properties of the transmission in ways that are still valid (enough) but violate the IDS/IPS product’s assumptions about how the data should be transmitted. For example, some IDS/IPS products can only look at one packet at a time. If you break the attack transmission into small enough pieces, the IDS/IPS won’t be able to see the signature. For IDS/IPS products that are a little smarter, transmitting the pieces in the wrong order might fool them. There are lots of permutations at various levels.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To build an analogy, IDS/IPS systems are like TSA personnel. They scan through your luggage looking for things that &lt;em&gt;might&lt;/em&gt; be dangerous. They can’t possibly know every possible threat and disguising a threat, like hiding it in your underpants, can potentially get through the screening process (in all fairness, the underwear bomber didn’t go through TSA screeners, he might have got caught but that demonstrations a point about security; you attack through a channel with weaker defenses).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;TSA screeners could be incredibly effective against a known threat. If we knew attackers were going to carry a weapon onboard a plane in a red stuffed unicorn, TSA personnel would have a clear thing to search for. If the weapon were moved to something else, maybe it would be found, maybe not. In the same vein, when a new vulnerability is discovered, providing a good signature for your IPS could provide adequate detection until a patch becomes available. That is, unless an attacker decides to put a moustache on it.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;So what are Advanced Evasion Techniques? Simply put they are IDS/IPS evasion techniques that are applied at more levels of the network stack. Where previous techniques might manipulate the transmission at the IP and TCP/UDP levels, advanced techniques might also manipulate the application layer. It’s an evolution on the attackers’ part that many vendors didn’t anticipate but it’s not really breaking new ground.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;What does this mean to your network? Hopefully, nothing. The conditions for a successful attack are that a service has to be exploitable &lt;em&gt;and&lt;/em&gt; the attacker has to get the attack passed the IPS &lt;em&gt;and&lt;/em&gt;… it has to get passed the firewall. The inability of your IPS to stop an attack is moot if the target is not vulnerable &lt;em&gt;or&lt;/em&gt; if there is no path from attacker to target. If either of those cases hold you can be pretty confident. The “The Principles of AntiEvasion” video seems to presume that your IPS is the only thing protecting your unpatched services. If you’re relying on your IPS in that fashion then you probably are at risk. If your firewall is configured sanely and your patches and configuration are solid, that video is mostly just FUD.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;To tie this up I’ll return to the “human screener” analogy. An IPS is like a person looking at people entering and leaving a building, trying to guess at motive. The building itself is like a firewall: it limits points of entry with walls and locked doors. Relying on your IPS to protect you is like foregoing walls and trying to guard a valuable resource in the middle of an open field with only a handful of guards.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-414828184446652193?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/10/advanced-evasion-techniques-long-winded_1837.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-6334335436938856021</guid><pubDate>Tue, 05 Oct 2010 07:45:00 +0000</pubDate><atom:updated>2010-11-04T06:40:58.315-07:00</atom:updated><title></title><description>&lt;img src="http://26.media.tumblr.com/tumblr_l9tnnwMsss1qzic40o1_400.jpg" /&gt;&lt;p&gt;On Saturday we adopted our second cat: Sam. Please forgive the mediocre photo. I was thoroughly impressed by the Silicon Valley humane society. Their facilities were excellent and I felt that the staff were genuinely interested in helping us find the right cat. If you&amp;#8217;re thinking of adopting and you&amp;#8217;re in the area I definitely recommend them: &lt;a href="http://hssv.org/"&gt;http://hssv.org/&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-6334335436938856021?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/10/on-saturday-we-adopted-our-second-cat_2025.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-523853697134775757</guid><pubDate>Fri, 01 Oct 2010 22:36:00 +0000</pubDate><atom:updated>2010-11-04T06:41:03.931-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>graffiti</category><title>Graffiti Analysis App</title><description>http://vimeo.com/13327615&lt;br /&gt;&lt;p&gt;Graffiti Analysis App&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-523853697134775757?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/10/graffiti-analysis-app_3605.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-8401605803854379692</guid><pubDate>Tue, 07 Sep 2010 08:37:00 +0000</pubDate><atom:updated>2010-11-04T06:41:09.597-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>photography</category><title>Nikon D90</title><description>&lt;p&gt;I got my first DSLR and I&amp;#8217;m having a blast with it. On my third day with the camera I managed to get some awesome shots:&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;table style="width:auto;"&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://picasaweb.google.com/lh/photo/187ws8NZXJus8TOfwc9s_g?feat=embedwebsite"&gt;&lt;img src="http://lh5.ggpht.com/_cmvxxECce-Q/TIKOYDO-XQI/AAAAAAAAAcY/T9XnJFd_Dpw/s400/DSC_0119.jpg"/&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td style="font-family:arial,sans-serif; font-size:11px; text-align:right"&gt;From &lt;a href="http://picasaweb.google.com/103960423791494394195/Random?feat=embedwebsite"&gt;Random&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;table style="width:auto;"&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://picasaweb.google.com/lh/photo/UJoZrUn1f0eU6cNhZK5oYg?feat=embedwebsite"&gt;&lt;img src="http://lh5.ggpht.com/_cmvxxECce-Q/TIKOYsGUJQI/AAAAAAAAAcc/_Zfn5QD-KmE/s400/DSC_0120.jpg"/&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td style="font-family:arial,sans-serif; font-size:11px; text-align:right"&gt;From &lt;a href="http://picasaweb.google.com/103960423791494394195/Random?feat=embedwebsite"&gt;Random&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;table style="width:auto;"&gt;&lt;br /&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="http://picasaweb.google.com/lh/photo/2sd0fgf5MyFpoiTJ5nXatQ?feat=embedwebsite"&gt;&lt;img src="http://lh4.ggpht.com/_cmvxxECce-Q/TIKObb1U6GI/AAAAAAAAAc0/aTEZvoUamu4/s400/DSC_0139.jpg"/&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;tr&gt;&lt;td style="font-family:arial,sans-serif; font-size:11px; text-align:right"&gt;From &lt;a href="http://picasaweb.google.com/103960423791494394195/Random?feat=embedwebsite"&gt;Random&lt;/a&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;br /&gt;&lt;/table&gt;&lt;br /&gt;&lt;p&gt;I think they&amp;#8217;re awesome, at least. I&amp;#8217;m having fun with it.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-8401605803854379692?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/09/nikon-d90_9179.html</link><author>noreply@blogger.com (Jason Mansfield)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_cmvxxECce-Q/TIKOYDO-XQI/AAAAAAAAAcY/T9XnJFd_Dpw/s72-c/DSC_0119.jpg' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-8802133488915455540</guid><pubDate>Thu, 02 Sep 2010 07:54:00 +0000</pubDate><atom:updated>2010-11-04T06:41:15.369-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>incredible</category><category domain='http://www.blogger.com/atom/ns#'>Verizon</category><category domain='http://www.blogger.com/atom/ns#'>android</category><title>Got Froyo on My Incredible</title><description>&lt;p&gt;This morning I found that Froyo was available for my Incredible. =D&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;After the update, I found that the crapware previously available in the Verizon section of the Market was &amp;#8220;preinstalled&amp;#8221;. D=&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Granted, I haven&amp;#8217;t tried VZ Navigator so maybe it&amp;#8217;s super awesome. But the reason I&amp;#8217;ve never tried it is because Maps works great and I have no need&amp;#8230; for &lt;em&gt;any&lt;/em&gt; of this software.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-8802133488915455540?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/09/got-froyo-on-my-incredible_8603.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-6742891747382715921</guid><pubDate>Tue, 31 Aug 2010 13:13:00 +0000</pubDate><atom:updated>2010-11-04T06:41:21.224-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>nonsense</category><category domain='http://www.blogger.com/atom/ns#'>internet</category><title>High-Def for the Internet</title><description>&lt;p&gt;I think I missed my calling in Marketing/PR. If we want to sell people on IPv6, here&amp;#8217;s the slogan:&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;em&gt;IPv6: It&amp;#8217;s High-Def for the Internet.&lt;/em&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;True to the spirit of Marketing/PR, I make no statements about the truth of my slogan.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-6742891747382715921?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/08/high-def-for-internet_2943.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-7813827999944331117</guid><pubDate>Fri, 27 Aug 2010 12:21:00 +0000</pubDate><atom:updated>2010-11-04T06:41:26.893-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>open source</category><category domain='http://www.blogger.com/atom/ns#'>programming</category><title>Guerilla Feature Request</title><description>&lt;p&gt;You want a feature in a piece of software but you don&amp;#8217;t want to implement it yourself. Luckily, you have access to the repository.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Don&amp;#8217;t bother actually working on the feature. Don&amp;#8217;t bother putting in a feature request. Instead, add a unit test that checks for the feature and check &lt;em&gt;that&lt;/em&gt; in. When the software starts failing unit tests the maintainers will have to decide to toss the test or fix the test by implementing the feature. This would be slightly more effective if the checkin included other tests that were actually useful.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;I think this may be apex of Test-Driven Development.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-7813827999944331117?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/08/guerilla-feature-request_6764.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-1816054593735617031</guid><pubDate>Wed, 25 Aug 2010 15:18:00 +0000</pubDate><atom:updated>2010-11-04T06:41:32.684-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>internet</category><title>Web 2.0 has killed all the bullshit gatekeepers and put us directly in
touch with the bullshit authors.</title><description>&lt;em&gt;"Web 2.0 has killed all the bullshit gatekeepers and put us directly in touch with the bullshit authors."&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-1816054593735617031?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/08/web-20-has-killed-all-bullshit_6651.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-5708088630332778625</guid><pubDate>Thu, 15 Jul 2010 08:43:00 +0000</pubDate><atom:updated>2010-11-04T06:41:38.329-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>biking</category><title>Rode to Work</title><description>&lt;p&gt;This time it was 19:40 in to work. I haven&amp;#8217;t been sleeping well so I haven&amp;#8217;t been riding. I need to get back on the horse.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-5708088630332778625?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/07/rode-to-work_478.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-6240370287884758028</guid><pubDate>Thu, 08 Jul 2010 11:33:00 +0000</pubDate><atom:updated>2010-11-04T06:41:44.061-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>random</category><category domain='http://www.blogger.com/atom/ns#'>security</category><title>Bogus Log Generator</title><description>&lt;p&gt;I wonder what the legal implications might be of a framework that makes it easy to create generators for bogus but convincing log data.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;  &lt;p&gt;Prosecution: &amp;#8220;Your honor, I present to the court computer logs that show that the defendant participated in online activities for which he is charged.&amp;#8221;&lt;/p&gt;&lt;br /&gt;  &lt;br /&gt;  &lt;p&gt;Defense: &amp;#8220;Your honor, I present to the court computer logs that are completely falsified but are completely indistinguishable in form from the logs presented by the prosecution.&amp;#8221;&lt;/p&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Flying Monkies, GO!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-6240370287884758028?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/07/bogus-log-generator_7161.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-3372943289472554168</guid><pubDate>Wed, 30 Jun 2010 07:41:00 +0000</pubDate><atom:updated>2010-11-04T06:41:49.807-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>biking</category><title>Rode to Work</title><description>&lt;p&gt;Actually, I&amp;#8217;ve ridden to work about five times since I last posted about it. Totally different route now.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Distance: 4.4 miles&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Moving Time: 18:09&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Riding Music: Bassnectar - Mesmerizing the Ultra&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;p&gt;I think the time is a personal best but I&amp;#8217;ve only tracked it with the GPS twice now. Good riding music, but a little bland for my taste. Would be appropriate to play in a gym where they have that special selection of music that sounds upbeat but isn&amp;#8217;t actually exciting.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;Moving Time Home: 19:45 - stuck behind a couple slowpokes.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-3372943289472554168?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/06/rode-to-work_4918.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-7539297067324595110</guid><pubDate>Tue, 08 Jun 2010 20:10:00 +0000</pubDate><atom:updated>2010-11-04T06:41:55.547-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>anonyimizer</category><category domain='http://www.blogger.com/atom/ns#'>security</category><category domain='http://www.blogger.com/atom/ns#'>android</category><category domain='http://www.blogger.com/atom/ns#'>privacy</category><title>Anonymizer Universal on Anroid</title><description>&lt;P&gt;&lt;a href="http://static.clinicallyawesome.com/projects/au_on_android/start" /&gt;Anonymizer Universal on Anroid&lt;/a&gt;&lt;/P&gt;&lt;br /&gt;&lt;p&gt;While at Anonymizer I got to use Anonymizer Universal and I thought it was pretty sweet. It doesn&amp;#8217;t take long with a packet sniffer on a popular public wireless access point to see that you have little protection if any without some sort of VPN. Anonymizer Universal is a commercial VPN service that protects your traffic on the local network and allows it to exit through Anonymizer. I got it working on my Android phone using a little hand-configuration. This doesn&amp;#8217;t require the phone to be rooted/jailbroken; it&amp;#8217;s part of the standard functionality. Note that while it works, it&amp;#8217;s not a supported platform&amp;#8230;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-7539297067324595110?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/06/anonymizer-universal-on-anroid_7613.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7468008418270845225.post-8540482912141390548</guid><pubDate>Mon, 07 Jun 2010 22:11:00 +0000</pubDate><atom:updated>2010-11-04T06:42:01.295-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>random</category><category domain='http://www.blogger.com/atom/ns#'>BP</category><category domain='http://www.blogger.com/atom/ns#'>hacking</category><title>I'll Be Here All Week</title><description>&lt;blockquote&gt;Raffy: I'm quite surprised BP's networks aren't getting a "Free of charge" penetration test right about now&lt;br /&gt;crunge: maybe they are&lt;br /&gt;crunge: Raffy: however, if there are any security holes....&lt;br /&gt;crunge: anyone?&lt;br /&gt;crunge: not&lt;br /&gt;crunge: getting&lt;br /&gt;crunge: successfully&lt;br /&gt;crunge: plugged.&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7468008418270845225-8540482912141390548?l=www.clinicallyawesome.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.clinicallyawesome.com/2010/06/i-be-here-all-week_7804.html</link><author>noreply@blogger.com (Jason Mansfield)</author><thr:total>0</thr:total></item></channel></rss>
