<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Wikihead&#039;s Blog</title>
	<atom:link href="http://wikihead.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://wikihead.wordpress.com</link>
	<description>A Crazy head looking to learn everything in world</description>
	<lastBuildDate>Mon, 16 Jan 2012 20:25:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='wikihead.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/d716234cbd3bd0ee9a485cec737277e9?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Wikihead&#039;s Blog</title>
		<link>http://wikihead.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://wikihead.wordpress.com/osd.xml" title="Wikihead&#039;s Blog" />
	<atom:link rel='hub' href='http://wikihead.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Superb Automated Malware Binary Analysis Service &#8211; Figure out what malware does in minutes</title>
		<link>http://wikihead.wordpress.com/2012/01/17/superb-automated-malware-binary-analysis-service-figure-out-what-malware-does-in-minutes/</link>
		<comments>http://wikihead.wordpress.com/2012/01/17/superb-automated-malware-binary-analysis-service-figure-out-what-malware-does-in-minutes/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 20:03:27 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Notes]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[api calls]]></category>
		<category><![CDATA[automated]]></category>
		<category><![CDATA[malware analysis]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/?p=592</guid>
		<description><![CDATA[These days, malware are VM aware to defend against automated analysis tools such as anubis, cukoo. And these automated analysis are based on behaviour analysis of malware that gives only tip of what actually it does as they are now intellegent and donot reveal at one instant. I am not at all satisfied with the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=592&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2012/01/17/superb-automated-malware-binary-analysis-service-figure-out-what-malware-does-in-minutes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>
	</item>
		<item>
		<title>How do you deal forensics with physically damaged harddisk</title>
		<link>http://wikihead.wordpress.com/2012/01/05/how-do-you-deal-forensics-with-physically-damaged-harddisk/</link>
		<comments>http://wikihead.wordpress.com/2012/01/05/how-do-you-deal-forensics-with-physically-damaged-harddisk/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 19:18:45 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[damaged disk]]></category>
		<category><![CDATA[disk imaging]]></category>
		<category><![CDATA[forensics]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/?p=566</guid>
		<description><![CDATA[How do you show up chain of custody for a physically damaged disk that gives different md5sum every time you compute. mahesh@jacksparrow:~#script (saves all the commands and output to file typescript) mahesh@jacksparrow:~#dd if=/dev/dev2 bs=512 &#124; md5sum (1st time) mahesh@jacksparrow:~#dd if=/dev/dev2 bs=512 &#124; md5sum (2nd time) mahesh@jacksparrow:~#dd if=/dev/dev2 bs=512 &#124; md5sum (3rd time) Each instance will [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=566&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2012/01/05/how-do-you-deal-forensics-with-physically-damaged-harddisk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>
	</item>
		<item>
		<title>Data Loss Prevention</title>
		<link>http://wikihead.wordpress.com/2011/10/28/data-loss-prevention/</link>
		<comments>http://wikihead.wordpress.com/2011/10/28/data-loss-prevention/#comments</comments>
		<pubDate>Fri, 28 Oct 2011 05:09:57 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Notes]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/2011/10/28/data-loss-prevention/</guid>
		<description><![CDATA[DLP Technology is just a technology and is effective when implemented with business case driven by specific requirement.     Full notes &#8211; HERE Filed under: Articles, Notes, security<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=577&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/10/28/data-loss-prevention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>

		<media:content url="http://wikihead.files.wordpress.com/2011/10/102811_0509_datalosspre12.png" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/10/102811_0509_datalosspre22.png" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/10/102811_0509_datalosspre32.png" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/10/102811_0509_datalosspre42.png" medium="image" />
	</item>
		<item>
		<title>Oh Shit.Yahoo mail is XSS vulnerable stealing cookies &#8211; zeroday</title>
		<link>http://wikihead.wordpress.com/2011/10/26/oh-shit-yahoo-mail-is-xss-vulnerable/</link>
		<comments>http://wikihead.wordpress.com/2011/10/26/oh-shit-yahoo-mail-is-xss-vulnerable/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 07:46:59 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[yahoo]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/?p=549</guid>
		<description><![CDATA[Just seen a yahoo e-mail exploit stealing yahoo cookie from yahoo email. This is no good.. Yahoo mail is XSS vulnerable as it failed to validate FROM field Email Header You receive a email exploit and you open in it in browser that it, external script runs in current session that sends your cookie. Exploit [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=549&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/10/26/oh-shit-yahoo-mail-is-xss-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>
	</item>
		<item>
		<title>20 Critical Security Controls for Effective Cyber Defense</title>
		<link>http://wikihead.wordpress.com/2011/10/04/20-critical-security-controls-for-effective-cyber-defense/</link>
		<comments>http://wikihead.wordpress.com/2011/10/04/20-critical-security-controls-for-effective-cyber-defense/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 06:45:36 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/2011/10/04/20-critical-security-controls-for-effective-cyber-defense/</guid>
		<description><![CDATA[Wow. Lucky to get this. Thanks SANS.Let me match myself the controls to my organization. The automation of these Top 20 Controls will radically lower the cost of security while improving its effectiveness. The US State Department, under CISO John Streufert, has already demonstrated more than 94% reduction in &#8220;measured&#8221; security risk through the rigorous [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=563&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/10/04/20-critical-security-controls-for-effective-cyber-defense/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>
	</item>
		<item>
		<title>You are compromised if you are not having java version greater than 1.6.0_23</title>
		<link>http://wikihead.wordpress.com/2011/10/04/you-are-compromised-if-you-are-not-having-java-version-greater-than-1-6-0_23/</link>
		<comments>http://wikihead.wordpress.com/2011/10/04/you-are-compromised-if-you-are-not-having-java-version-greater-than-1-6-0_23/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 06:24:49 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/2011/10/04/you-are-compromised-if-you-are-not-having-java-version-greater-than-1-6-0_23/</guid>
		<description><![CDATA[Do you think you will get infected only when visiting porn sites / cracks / malicious sites. LOL you get infected even when you visit yahoo.com, msn.com, 4shared.com Currently blackhole exploit kit is heavily being used to distribute zbot via drives-by download. And blocking the domains is use less as they last only for some [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=558&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/10/04/you-are-compromised-if-you-are-not-having-java-version-greater-than-1-6-0_23/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>

		<media:content url="http://wikihead.files.wordpress.com/2011/10/100411_0624_youarecompr12.png" medium="image" />
	</item>
		<item>
		<title>HomeProxy setup for secure internet over insecure wifi</title>
		<link>http://wikihead.wordpress.com/2011/09/16/homeproxy-setup-for-secure-internet-over-insecure-wifi/</link>
		<comments>http://wikihead.wordpress.com/2011/09/16/homeproxy-setup-for-secure-internet-over-insecure-wifi/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 10:55:11 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/2011/09/16/homeproxy-setup-for-secure-internet-over-insecure-wifi/</guid>
		<description><![CDATA[1) On Ubuntu on my home machine which has internet connection install ssh and running #apt-get install ssh   2) Have a proxy running on your home machine on port 9050(Tor or TinyHttpProxy)   3) On my lapi on wifi #ssh remoteuser@maheshhome.dyndns.com -L 4343:localhost:9050 remoteuser@maheshhome.dyndns.com Password:   4)Configure my browser to use Socks proxy (If [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=556&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/09/16/homeproxy-setup-for-secure-internet-over-insecure-wifi/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>

		<media:content url="http://wikihead.files.wordpress.com/2011/09/091611_1055_homeproxyse1.png" medium="image" />
	</item>
		<item>
		<title>How easy to evade detection by Antivirus</title>
		<link>http://wikihead.wordpress.com/2011/08/31/how-easy-to-evade-detection-by-antivirus/</link>
		<comments>http://wikihead.wordpress.com/2011/08/31/how-easy-to-evade-detection-by-antivirus/#comments</comments>
		<pubDate>Wed, 31 Aug 2011 14:13:47 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/2011/08/31/how-easy-to-evade-detection-by-antivirus/</guid>
		<description><![CDATA[Hi,   Just a few days back there was an infection with a java exploit (on 25/Aug), and we got the signature for that class file. And today we saw another infection which is undetected by Antivirus   And the difference is just a minor variation in original java code. For the one on the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=552&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/08/31/how-easy-to-evade-detection-by-antivirus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>

		<media:content url="http://wikihead.files.wordpress.com/2011/08/083111_1413_howeasytoev11.png" medium="image" />
	</item>
		<item>
		<title>Analyzing Java exploit with deobfuscating Javascript</title>
		<link>http://wikihead.wordpress.com/2011/08/25/analyzing-java-exploit-with-deobfuscating-javascript/</link>
		<comments>http://wikihead.wordpress.com/2011/08/25/analyzing-java-exploit-with-deobfuscating-javascript/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 11:13:21 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Notes]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[deobfuscation]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[java exploit]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[obfuscated]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/2011/08/25/analyzing-java-exploit-with-deobfuscating-javascript/</guid>
		<description><![CDATA[A suspicious .class file download triggered the alert. GET /jb/kukukuk.class HTTP/1.1User-Agent: Mozilla/4.0 (Windows ) Java/1.6.0_22Host: 2374507291Accept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2Connection: keep-alive Now we can observed that Host is an octal host and user agent indicated java and its version. =&#62; A download attempt from an Applet. Now the goal is to identify [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=518&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/08/25/analyzing-java-exploit-with-deobfuscating-javascript/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja13.jpg" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja23.jpg" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja33.jpg" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja42.jpg" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja52.jpg" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja62.jpg" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja71.png" medium="image" />

		<media:content url="http://wikihead.files.wordpress.com/2011/08/082511_1113_analyzingja81.png" medium="image" />
	</item>
		<item>
		<title>A Comparison of 60 Commercial &amp; Open Source Black Box Web Application Vulnerability Scanners</title>
		<link>http://wikihead.wordpress.com/2011/08/03/a-comparison-of-60-commercial-open-source-black-box-web-application-vulnerability-scanners/</link>
		<comments>http://wikihead.wordpress.com/2011/08/03/a-comparison-of-60-commercial-open-source-black-box-web-application-vulnerability-scanners/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 07:29:41 +0000</pubDate>
		<dc:creator>wikihead</dc:creator>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vulnerability scanner]]></category>
		<category><![CDATA[webapp vulnerability scanner]]></category>

		<guid isPermaLink="false">http://wikihead.wordpress.com/?p=505</guid>
		<description><![CDATA[A really good article that compares various feautures and accuracy of commercial and free WebApp Scanners. Unfortunately i didnt include some major ones like Qualys, eEye retina. However its a nice article to keep in mind. &#8211; Here Filed under: Resources, security<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wikihead.wordpress.com&amp;blog=11256766&amp;post=505&amp;subd=wikihead&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://wikihead.wordpress.com/2011/08/03/a-comparison-of-60-commercial-open-source-black-box-web-application-vulnerability-scanners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/d19bcca5ba01a13aeea10b2641bc0379?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">wikihead</media:title>
		</media:content>
	</item>
	</channel>
</rss>
