Archives for: January 2010

Pasha is my hero! =)) (pamflet)

01/23/10 | by zveriu | Categories: YouTube, Fun, Romanian

Well, Samy is my hero is cool… but Pasha is my hero is hotter now :))

Yes you can Pasha (aka Pavel Turcu, aka Pavel Turkish :) )!

“Top views Moldova Eurovision 2010 on YouTube”

“Pavel Turcu - Hitler scene remix”

Read more! »

1 commentPermalink

Vanya si mai cum? =))

01/23/10 | by zveriu | Categories: YouTube, Fun, Romanian

-Da cum te numesti ?
-Ei cum ma numesc, Vanya
-Pai Vanya si mai cum ?
-Cum si mai cum ? Ap’ Vanya

-Da cel care ti-a dat tigarile e roman sau din Republica Moldova?
-Ti-am spus ca-i moldovan !

1 commentPermalink

Theoretically 1 USD = 1 EUR and 1 EUR = 2 USD is possible!

01/13/10 | by zveriu | Categories: In real life, On the web, AskAmit, Hack

UPDATE 20101012

By a very nice coincidence I have bumped into this interesting paper (dating around 15 Jul 2008) - “BREAKING THE BANK - VULNERABILITIES IN NUMERIC PROCESSING WITHIN FINANCIAL APPLICATIONS” - ENJOY the reading!

Given I currently work in a telecom billing software company - I just cannot find enough words and meanings to confirm with sorrow that pretty-fucking-many of my fellow programmers do not give a shi…ny glass for avoiding this kind of problems. Worst, they don’t even realize it :-S…

PS: …and YES, Bank Of Cyprus (along with its new migrated Java/JSF-based banking application - a special post on this to follow) allows/uses:

  • input like “1E+3″ which gets translated into “1000″
  • “round-to-nearest, ties away from zero” for 3rd decimal, i.e. “0,004″ gets translated to “0,00″ and “0,007″ gets translated to “0,01″

Happy hacking…

Money

When it comes to speaking about money, a lot of people get interested. And nowadays most money discussion evolve around or near-by the EUR-USD exchange rates.

Some people (including me sometime :) ) are unhappy to depend and always lose their honestly earned savings because of some avid and greedy circles of interest are playing with exchange rates and make them uncontrollable

Read more! »

Costica, dormi?

01/11/10 | by zveriu | Categories: YouTube, Fun, Romanian

Costica, dormi?

RUPEEEEEEEEE!

Everything is OK

01/11/10 | by zveriu | Categories: Audio, YouTube, English

Everything is OK - Motivational, thoughtful, courageous…

The Love Police - The Revolution is NOW

1 commentPermalink

Mr Freeman

01/11/10 | by zveriu | Categories: General, YouTube, Fun, Cartoon, Russian

Mr Freeman - (De)Motivational, rhetorical, thoughtful…

UPDATE: 20100110

С новым годом?

“Плодитесь, коровы, жизнь коротка” (с) ГГМ

Pages: 1 2 3

Balet, box si lupte greco-romane... pe gheata :D

01/11/10 | by zveriu | Categories: YouTube, Fun

Balet, box si lupte greco-romane… pe gheata :D

“Astazi” (batalie pe gheata campionatul Kontinental Hockey League 2010 in Chekhov):

“Ieri": (batalie pe gheata Campionatul Mondial 1987 in Cehoslovacia)

Hockey-ul nu s-a schimbat mult la capitolul “dorinta si sete de lupta pana la sange” =))

Cei mai fierbinti hockeyisti par a fi rusii si canadienii :D

Automatic translation fun :)

01/08/10 | by zveriu | Categories: Cyprus notes, Thoughts, Language, English, Romanian, Multi-Lingual

Using Google Translate German-to-English

Even a single marking point on a character makes huge difference.

However, this one, for me as a Moldovan/Romanian, is like winning the lottery - what were the chances I would misspell that character in that phrase?

Bei verpasstem Anschlusszug bitte ausfullen - In Moldovian Missed connecting train please

Bei verpasstem Anschlusszug bitte ausfüllen - When connecting train, please fill Missed

1 commentPermalink

Learning GSM: USSD fuzzing and attacking the network

01/06/10 | by zveriu | Categories: Hardware, Software, GSM

Learning GSM: USSD fuzzing and attacking the network

Prerequisites of attacks

Some points why USSD is a good choice:
- USSD and USSD replies are free compared to SMS (except special, VAS, etc. numbers)

- USSD and USSD replies interact with 3rd party USSD Gateways software which most probably can be attacked more easy compared to SMSC

- USSD Gateways (if not crashed by a border-case/not-tested/unusual/malformed USSD message or USSD reply), forward the messages to Applications. Most probably “Third party content and application providers” suffer from buffer overflow, script injection, SQL injection, etc.

According to http://www.truteq.com/tips/ussd/:
“The menus are served by applications. This may not be at the GSM network operator, but at a content provider connected to the USSD infrastructure. Applications or content can therefore be served from :
1. Standard supplementary services
2. GSM Network Operators value-added services
3. Third party content and application providers

- USSD sessions implementation mechanisms can be exploited in USSD Gateways (grow huge sessions, open huge number of sessions, etc.)

Means to practically implement attacks

Fuzzing requires a lot of messages/replies back and forth through TELCO’s equipment. Many may say that such activity may not go unnoticed, and this is true.

Read more! »

Learning GSM: Mobile/Cell Phone Power-Off vs Mobile Not-reachable/Battery-discharged

01/06/10 | by zveriu | Categories: Hardware, Software, GSM

Learning GSM: Mobile/Cell Phone Power-Off vs Mobile Not-reachable/Battery-discharged

Power-Off vs Not-reachable/battery-discharged

It was interesting for me to find out and read an old paper called “Forensics and the GSM mobile telephone system” (original article file 03_spring_art1.pdf).

The point I want to discuss here is also somehow related to trust or mis-trust whether a given called subscriber really went out of GSM network reach/had the battery discharged during idle OR the subscriber actually shut-off his phone and pretends he is out of network reach/battery discharched.

This trust/mis-trust often comes as a facade dialogue template:
John: “I tried to called you regarding XYZ”
Bob: “Umm, I am really sorry - I really wanted to talk to you, but I lost network/I had phone battery discharged” (when actually Bob did switch off his phone on purpose not to be reachable specifically by John and/or other calling parties)

Now there is really a way, without having any technical device or very specific knowledge to find out whether a subscriber has shut down his phone or went out of network-reach or had his battery discharched.

Read more! »

26C3 - "Look ma' , I am on TV"

01/03/10 | by zveriu | Categories: In real life, On the web, Software, Hack

26C3 - “Look ma’ , I am on TV”

26C3 is over… It was a fun experience however :)!

Some key points:

Lightning talks

Together with Pavol Luptak (from Nethemba team in Slovakia), had a lightning talk about the MFCUK

Online video / Downloadable video (our talk starts around 00:09:50)

Slides 26C3 Lightning Talk Day2 MFCUK Mifare Classic Toolkit

Open digital radio

Also, I have attended a very nice and neat workshop put up by Mathias Coinchon from OpenDigitalRadio.org

The workshop link is here.

Mathias also have kindly provided the GNU Radio Companion files used in “26C3 Radio Broadcasting Workshop”.

DYI Book scanner

Ever wondered how the thousand pages books are scanned and put online? I was wondering that too.

A nice lecture and slides are here:

How to build your own Book Scanner [in 4 min]

Projects

cetatenie.ro

Blog-o-Mix

Mixing all blogs into a single access point.

January 2010
Sun Mon Tue Wed Thu Fri Sat
 << < Current> >>
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31            

Misc

XML Feeds

What is RSS?

powered by b2evolution free blog software