<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Pwned @ hack.lu?</title>
	<atom:link href="http://blog.didierstevens.com/2007/10/19/pwned-hacklu/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/</link>
	<description>(blog \'DidierStevens)</description>
	<lastBuildDate>Mon, 10 Jun 2013 08:49:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-16496</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 29 Oct 2007 11:43:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-16496</guid>
		<description><![CDATA[That&#039;s my Nokia N800, more pics here: http://blog.didierstevens.com/2007/06/05/omg-my-n800-is-infected/]]></description>
		<content:encoded><![CDATA[<p>That&#8217;s my Nokia N800, more pics here: <a href="http://blog.didierstevens.com/2007/06/05/omg-my-n800-is-infected/" rel="nofollow">http://blog.didierstevens.com/2007/06/05/omg-my-n800-is-infected/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: uber</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-16387</link>
		<dc:creator><![CDATA[uber]]></dc:creator>
		<pubDate>Sun, 28 Oct 2007 17:59:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-16387</guid>
		<description><![CDATA[Nice GUI. What&#039;s that? Seems like Vista but...]]></description>
		<content:encoded><![CDATA[<p>Nice GUI. What&#8217;s that? Seems like Vista but&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hackers Blog &#187; Blog Archive &#187; Security conference attendees fall victim to man-in-the-middle hack</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15774</link>
		<dc:creator><![CDATA[Hackers Blog &#187; Blog Archive &#187; Security conference attendees fall victim to man-in-the-middle hack]]></dc:creator>
		<pubDate>Mon, 22 Oct 2007 12:11:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15774</guid>
		<description><![CDATA[[...] witnessed a man-in-the-middle attack on the TLS at hack.lu (a hacker/security conference held in Luxembourg) [...]]]></description>
		<content:encoded><![CDATA[<p>[...] witnessed a man-in-the-middle attack on the TLS at hack.lu (a hacker/security conference held in Luxembourg) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tlr</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15689</link>
		<dc:creator><![CDATA[tlr]]></dc:creator>
		<pubDate>Sun, 21 Oct 2007 09:48:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15689</guid>
		<description><![CDATA[My bet is on ettercap, since the attacker used the default public key that is shipped with that piece of software -- but of course that&#039;s not proof.

Evidence and a bit of analysis are here:
http://log.does-not-exist.org/archives/2007/10/20/2144_hacklu_mitming_a_room_full_of_security_people.html]]></description>
		<content:encoded><![CDATA[<p>My bet is on ettercap, since the attacker used the default public key that is shipped with that piece of software &#8212; but of course that&#8217;s not proof.</p>
<p>Evidence and a bit of analysis are here:<br />
<a href="http://log.does-not-exist.org/archives/2007/10/20/2144_hacklu_mitming_a_room_full_of_security_people.html" rel="nofollow">http://log.does-not-exist.org/archives/2007/10/20/2144_hacklu_mitming_a_room_full_of_security_people.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: achtung!</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15679</link>
		<dc:creator><![CDATA[achtung!]]></dc:creator>
		<pubDate>Sun, 21 Oct 2007 03:10:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15679</guid>
		<description><![CDATA[Yeah, there&#039;s a way to create a fake certificate using Cain &amp; Abel. Then you get a &quot;secure&quot; connection to the owner of the false certificate so you transmit your password :-P]]></description>
		<content:encoded><![CDATA[<p>Yeah, there&#8217;s a way to create a fake certificate using Cain &amp; Abel. Then you get a &#8220;secure&#8221; connection to the owner of the false certificate so you transmit your password <img src='http://s2.wp.com/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benny K</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15666</link>
		<dc:creator><![CDATA[Benny K]]></dc:creator>
		<pubDate>Sat, 20 Oct 2007 23:33:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15666</guid>
		<description><![CDATA[Here is an analysis
http://log.does-not-exist.org/archives/2007/10/20/2144_hacklu_mitming_a_room_full_of_security_people.html]]></description>
		<content:encoded><![CDATA[<p>Here is an analysis<br />
<a href="http://log.does-not-exist.org/archives/2007/10/20/2144_hacklu_mitming_a_room_full_of_security_people.html" rel="nofollow">http://log.does-not-exist.org/archives/2007/10/20/2144_hacklu_mitming_a_room_full_of_security_people.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Noah</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15665</link>
		<dc:creator><![CDATA[Noah]]></dc:creator>
		<pubDate>Sat, 20 Oct 2007 23:01:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15665</guid>
		<description><![CDATA[Someone used Cain &amp; Abel in APR mode between the gateway and it&#039;s users...?]]></description>
		<content:encoded><![CDATA[<p>Someone used Cain &amp; Abel in APR mode between the gateway and it&#8217;s users&#8230;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benny K</title>
		<link>http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15602</link>
		<dc:creator><![CDATA[Benny K]]></dc:creator>
		<pubDate>Fri, 19 Oct 2007 23:36:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.didierstevens.com/2007/10/19/pwned-hacklu/#comment-15602</guid>
		<description><![CDATA[And still a lot of people clicked through (they told me). I also saw it and I checked the name and the CA and it seemed fine. The analysis from someone in the public on the beamer was breathtaking.

And a lot of people in the audience were security professionals. I guess no one is perfect. It was a devious attack.]]></description>
		<content:encoded><![CDATA[<p>And still a lot of people clicked through (they told me). I also saw it and I checked the name and the CA and it seemed fine. The analysis from someone in the public on the beamer was breathtaking.</p>
<p>And a lot of people in the audience were security professionals. I guess no one is perfect. It was a devious attack.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
