<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Code in my Bug! &#187; life</title>
	<atom:link href="http://projectbee.org/blog/archive/category/life/feed/" rel="self" type="application/rss+xml" />
	<link>http://projectbee.org/blog</link>
	<description>Bipin&#039;s experiments with life, society, programming, hacking, &#38; other stuff</description>
	<lastBuildDate>Wed, 28 Mar 2012 09:20:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>How my Kindle cover saved my Kindle, OR How I got robbed of my DSLR and laptop</title>
		<link>http://projectbee.org/blog/archive/how-my-kindle-cover-saved-my-kindle-or-how-i-got-robbed-of-my-dslr-and-laptop/</link>
		<comments>http://projectbee.org/blog/archive/how-my-kindle-cover-saved-my-kindle-or-how-i-got-robbed-of-my-dslr-and-laptop/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 18:50:09 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[humour]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=241</guid>
		<description><![CDATA[&#8216;Robbed&#8217; not in the strictest sense, but yes there was theft at my house yesterday. The lovely dudes took away my Nikon D90 along with the 18-105 lens, and Dell XPS (my lovely old wife). Yes, I&#8217;d recently ditched my wife for a super hot Macbook Air, but she still was a companion. Polygamy is [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_248" class="wp-caption aligncenter" style="width: 650px"><a href="http://www.flickr.com/photos/zizzy/4582604955/" target="_blank"><img class="size-full wp-image-248 " title="&quot;Scene of Crime&quot; by http://www.flickr.com/photos/zizzy/4582604955/" src="http://projectbee.org/blog/wp-content/uploads/2012/02/4582604955_f34b2202df_z.jpg" alt="&quot;Scene of Crime&quot; by http://www.flickr.com/photos/zizzy/4582604955/" width="640" height="213" /></a><p class="wp-caption-text">&quot;Scene of Crime&quot; by http://www.flickr.com/photos/zizzy/4582604955/</p></div>
<p>&#8216;Robbed&#8217; not in the strictest sense, but yes there was theft at my house yesterday. The lovely dudes took away my Nikon D90 along with the 18-105 lens, and Dell XPS (my lovely old wife). Yes, I&#8217;d recently ditched my wife for a super hot Macbook Air, but she still was a companion. Polygamy is amazing!</p>
<h2>The Prologue</h2>
<p>I come home from office, all hungry and tired, and find the iron gate without a lock. The first thought that hits me is that maybe my cook&#8217;s inside and has forgotten to lock the door. Sigh! If only it was true.<br />
I enter the hall, switch on the lights and find the wash basin broken in pieces and lying on the floor. A whole lot of stuff lying on my study table. Thankfully, my bookshelf seems untouched. My bike is still there. I feel hopeful. I walk with a heavy heart, but high hopes, to Bedroom #2. The camera bag is lying on floor. I pick it up and it feels lighter than ever. I&#8217;ve always wanted it to weigh a little lighter while traveling, and my wish is granted. My Nikon is gone.<br />
Then I remember my roommate&#8217;s camera pouch, which by the way looks like a camera bag unlike my camera-cum-laptop-cum-lenses backpack, and lies next to it. It&#8217;s still there. I lift it. It&#8217;s still heavy. Some joy. Some confusion.</p>
<p>Everything else seems to be in its original place, including the camera&#8217;s battery charger, and our newly washed and ironed clothes. I remember I&#8217;ve a Dell in the other bedroom. I don&#8217;t want to know, but I must. Alas and damn the human inquisitiveness.<br />
Her cooling pad is in place. Her power cord is in place. But she isn&#8217;t. She&#8217;s left me.<br />
Was it me cheating on her with an Air? No no, it can&#8217;t be. She still loved me. She loved my polygamy.</p>
<div class="wp-caption aligncenter" style="width: 650px"><img title="Bittu, in the golden days :(" src="http://farm4.staticflickr.com/3163/2571423177_9bb9b4dbf3_z_d.jpg?zz=1" alt="Bittu, in the golden days :(" width="640" height="480" /><p class="wp-caption-text">Bittu, in the golden days <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p></div>
<h2>O&#8217; 3rd generation kindle-cover-with-light, Thank you!</h2>
<p>I notice my new and shiny, but slightly twisted kindle cover lying between the cooling pad and the new and shiny &#8220;Depths of the Ocean -Sushmit Sen&#8221; music CD (which by the way is as amazing as hyped). My heart sinks little more. I pick it up. It&#8217;s still heavy. It doesn&#8217;t make sense. I open the cover and there&#8217;s &#8220;Jules Verne&#8221; looking as thoughtful as ever (To non-Kindle users, Kindles have standby wallpapers). But he seems a little sad today.<br />
On further investigation, we later realize that they did indeed try to snatch the device out of the cover, and twisted it in the process, but failed. And so they left it. Apparently, they like to travel light. Why else would they leave the laptop&#8217;s power cord, or my awesome camera backpack (which also had my small HD video camera in one of the lens pouches, along with my portable HD and some Macbook Air accessories).</p>
<div id="attachment_246" class="wp-caption aligncenter" style="width: 650px"><img class="size-full wp-image-246" title="Kindle and its cover, twisted but safe" src="http://projectbee.org/blog/wp-content/uploads/2012/02/DSC_0010.jpg" alt="Kindle and its cover, twisted but safe" width="640" height="428" /><p class="wp-caption-text">Kindle and its cover, twisted but safe</p></div>
<h2>Oh the plunder! Oh the horror!</h2>
<p>At some point -I know not when, and for some reason -I know not what, I realize that if they&#8217;ve broken the wash basin in the hall, it is possible that they have made violent love to my other wash basin. Akin to characters who are about to die in horror movies, I open the door of my bathroom adjacent to bedroom #1. These characters in the movies know that what they discover besides the door might get them killed, but they still open the door. And so do I. Alas and damn the human inquisitiveness.</p>
<p>Lo and behold! There&#8217;s huge dirty stone lying on the floor along with the the pieces of my lovely wash basin. The basin which I&#8217;d cleaned and polished and shined just a couple of days ago. Lying on the floor, like a tired prostitute. (Not that I&#8217;d know what a tired prostitute looks like.)</p>
<p>Sadly this isn&#8217;t the end of the terror story. As my gaze rises from the floor and falls upon the walls, my emotions run an all time high. If I weren&#8217;t shocked with what I saw, I would have surely been proud of my emotions which run so fast and so high like a tide.<br />
They have taken away all the water taps and shower knobs and flush pipes and shower thingy and the cloth hanging rod thingy.<br />
And they haven&#8217;t unscrewed them. No sir!. Rather used stones to break them from the walls -an act which as we would later discover, may cost us around 20K. In the end, I do wish they&#8217;d unscrewed the components rather than screwing us like that.<br />
I move to the other bathroom. It&#8217;s confirmed, they&#8217;ve screwed us here as well. Oh yes, how can I forget the kitchen!<br />
Getting screwed at so many different locations in such a short span of time has left me tired. I want to sit down now.</p>
<div id="attachment_244" class="wp-caption aligncenter" style="width: 650px"><img class="size-full wp-image-244 " title="Stone that they used to break it all in the bathroom" src="http://projectbee.org/blog/wp-content/uploads/2012/02/DSC_0004.jpg" alt="Stone that they used to break it all in the bathroom" width="640" height="428" /><p class="wp-caption-text">Stone, which they used to break it all, lying in the bathroom</p></div>
<h2>12 Angry Men (or may be just 5), and their analysis</h2>
<p>So I call my roommate Abhijit, and my friend Dabbu in the meantime. Dabbu also gets his elder brother and roommate with him.<br />
It is important to note that both of these men have had theft at their previous houses. Both have lost their laptops. Yeah, same pinch. I know!</p>
<p>All the five do what any reasonable person who&#8217;s had a theft at his place does. Socialize with neighbors and police, analyze, and bitch about it.<br />
No, none of this matters and it seldom makes any difference. But you must. It&#8217;s a social custom. Ask Dr. Sheldon Cooper.</p>
<p>We talk to neighbors, call police, analyze and discuss and analyze again. The modus operandi is investigated and debated. Police guy, who is a rather soft spoken guy for a change, notes down details in his diary, sympathizes with us, and leaves.</p>
<p>Here&#8217;s how our final analysis looks like:<br />
* It could have be my roommate. After all none of his stuff was stolen<br />
* While we are at it, it may have been Dabbu. Apart from the fact that he loved my camera, he&#8217;s studied in a KV (Kendriya Vidyala), the same school where my younger brother went. And we all know how talented KV products are</p>
<div id="attachment_245" class="wp-caption aligncenter" style="width: 650px"><img class="size-full wp-image-245" title="Abhijit, Dabbu, and the wash basin that was" src="http://projectbee.org/blog/wp-content/uploads/2012/02/DSC_0009.jpg" alt="Abhijit, Dabbu, and the wash basin that was" width="640" height="428" /><p class="wp-caption-text">Abhijit, Dabbu, and the wash basin that was</p></div>
<h2>Reconciliation</h2>
<p>The entire post may present a jovial outlook. Part of it is forced, but mostly natural. I owe the jolly response for materialistic loss to a certain event in my life.</p>
<p>Years ago when I was in B.Tech, one fine evening my hard drive crashed. It wasn&#8217;t out of the blue. Remember the text mode Linux installations? Yes yes, fdisk and stuff. Yeah! So the hard drive crashed and I lost everything. All the songs, and the movies, and the songs, and the software, and the songs. It was the end of my life as I knew it. I crashed on my bed too.</p>
<p>As I was brooding on my cot, trying to analyze my options of data recovery, one question constantly and repeatedly came up -<em>Now what?</em><br />
The question was rather simple, and I didn&#8217;t have any answers, but it did have a profound effect on me.</p>
<p>It&#8217;s funny how we existentialists look around for answers all our lives, and how a simple question can liberate us.<br />
It&#8217;s funny how we brood over our problems, and the acceptance of lack of a solution helps us reconcile.</p>
<p>Yes I loved my Nikon D90. I have been getting better with <a href="http://www.flickr.com/photos/projectbee" target="_blank">every picture I clicked</a>. I loved when my friends smiled at the pictures I&#8217;d taken of them. I was looking forward to handing over the Dell to my brother, who&#8217;s been having problems with his laptop.<br />
But well, it can&#8217;t be anymore. If it can&#8217;t be, it won&#8217;t be. If it won&#8217;t be, what am I going to brood over?</p>
<p>As Ghalib said:</p>
<blockquote><p>Na tha kuchh toh khuda tha, kuchh na hota toh Khuda hota,<br />
Duboya mujhko hone ne, na hota main toh kya hota.</p></blockquote>
<p>[P.S. All said and done, why did those bastards have to take the taps man. There's no water at home. Sigh! :'( ]</p>
<p>Update 1: Apparently, these thieves may have been addicts. It&#8217;s easier and quicker to sell off bathroom accessories.</p>
<p>Update 2: I finally managed to get an FIR filed. One the 11th day, mind you. Yeah, I know. We might be better off without a police department.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/steve-jobs-vs-bill-gates/" rel="bookmark" title="February 17, 2007">Steve Jobs vs Bill Gates.</a></li>

<li><a href="http://projectbee.org/blog/archive/idle-nights-devils-mind/" rel="bookmark" title="April 12, 2007">Idle Nights: Devil&#8217;s Mind</a></li>

<li><a href="http://projectbee.org/blog/archive/how-about-a-better-cheaper-macbook-air/" rel="bookmark" title="January 31, 2008">How about a Better &#38; Cheaper MacBook Air!</a></li>

<li><a href="http://projectbee.org/blog/archive/bittus-back/" rel="bookmark" title="June 12, 2008">Bittu&#8217;s back :)</a></li>

<li><a href="http://projectbee.org/blog/archive/life-so-far/" rel="bookmark" title="December 13, 2011">Life, so far&#8230;</a></li>
</ul><!-- Similar Posts took 8.823 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/how-my-kindle-cover-saved-my-kindle-or-how-i-got-robbed-of-my-dslr-and-laptop/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Life, so far&#8230;</title>
		<link>http://projectbee.org/blog/archive/life-so-far/</link>
		<comments>http://projectbee.org/blog/archive/life-so-far/#comments</comments>
		<pubDate>Mon, 12 Dec 2011 21:39:12 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[life]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=199</guid>
		<description><![CDATA[Apparently the last time I wrote something here was on Jan&#8217;26th Mar&#8217; 23rd, 2009 -almost 3 years ago. Obviously a lot&#8217;s happened and much has changed in life -or may be nothing&#8217;s changed. I recall lines from a Gulzar saab&#8217;s poem: Pal bhar mein sab kuchh badal gaya, Aur kuchh bhi nahi badla. Jo badla [...]]]></description>
			<content:encoded><![CDATA[<p>Apparently the last time I wrote something here was on <del>Jan&#8217;26th</del> Mar&#8217; 23rd, 2009 -almost 3 years ago. Obviously a lot&#8217;s happened and much has changed in life -or may be nothing&#8217;s changed. I recall lines from a Gulzar saab&#8217;s poem:</p>
<p><em>Pal bhar mein sab kuchh badal gaya,<br />
Aur kuchh bhi nahi badla.<br />
Jo badla tha, woh toh guzar gaya</em></p>
<div class="wp-caption alignnone" style="width: 510px"><a href="https://secure.flickr.com/photos/jenson-lee/4401334015/" target="_blank"><img class=" " title="Life" src="https://farm5.staticflickr.com/4049/4401334015_1135f82487_d.jpg" alt="Life" width="500" height="333" /></a><p class="wp-caption-text">by Jen Son https://secure.flickr.com/photos/jenson-lee/4401334015/</p></div>
<p>In any case, here&#8217;s a few of my experiments I can remember:</p>
<ul>
<li>Left Satyam to join Directi and moved to Bombay  from Bangalore</li>
<li>Satyam went nearly broke and bankrupt, thanks to Mr. Raju, and the overly emotional and messed up capitalist system</li>
<li>Worked on the despicable, and yet vital, online advertisement and traffic monetization business</li>
<li>Learned about the awesome algorithms that go behind powering a beautiful, but annoying, parked page</li>
<li>Learned the art of writing Firefox addons and wrote a couple interesting ones (none open source, sorry)</li>
<li>Joined <a href="http://null.co.in/" target="_blank">null security group&#8217;s</a> core team and played the role of Mumbai chapter&#8217;s moderator</li>
<li>Did something I wanted to do for a long time -an experiment of living alone (for an year). Had the painful realization that human touch is an underrated indulgence.</li>
<li>Met a lot of crazy (and) talented people, and made some friends</li>
<li><a href="https://secure.flickr.com/photos/projectbee/4368857404/" target="_blank">Won an Olympus E450 in a photography contest</a> (Yay!). Sold both cameras and bought a Nikon D90</li>
<li>Became the proud owner of a 3rd generation Amazon Kindle B-)</li>
<li>Became an entrepreneur&#8230; eh, no, not entrepreneur. Rather a startup-businessman. Yeah, better!</li>
<li>Moved (back) to Bhubaneswar to work full time on the product</li>
<li>Volunteered for<a href="http://spicmacay.com/" target="_blank"> SPICMCAY&#8217;s</a> 26th National Convention and worked on the first ever LIVE streaming of performances</li>
<li>Launched two products, including <a href="http://entranceforms.com/?prjb" target="_blank">EntranceForms.com</a></li>
<li>Working on a third product -sort of derivative and related, but the one that&#8217;s got me pretty excited</li>
</ul>
<p>Like any startup guy would tell you, every dawn starts with a bunch of promises and hopes, and you&#8217;d be super lucky if even one of them materializes by sundown. For now, all  can say is life&#8217;s frustrating, irritating, brutal, lonely, rewarding, and fun -in short, <strong>fulfilling</strong>.</p>
<p>Oh by the way, I&#8217;m going to conduct another interesting experiment <a href="https://johnnyjacob.wordpress.com/" target="_blank">with a fellow nerd</a> -<strong>A Road Trip</strong> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/how-my-kindle-cover-saved-my-kindle-or-how-i-got-robbed-of-my-dslr-and-laptop/" rel="bookmark" title="February 17, 2012">How my Kindle cover saved my Kindle, OR How I got robbed of my DSLR and laptop</a></li>

<li><a href="http://projectbee.org/blog/archive/securcamp-and-back/" rel="bookmark" title="July 12, 2008">SecurCamp and back.</a></li>

<li><a href="http://projectbee.org/blog/archive/a-program-called-3-om/" rel="bookmark" title="March 3, 2007">A program called &#34;3~&#34; (Om)</a></li>

<li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/idle-nights-devils-mind/" rel="bookmark" title="April 12, 2007">Idle Nights: Devil&#8217;s Mind</a></li>
</ul><!-- Similar Posts took 6.009 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/life-so-far/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>[OT] The Rant of a &#8220;Republic&#8221; Indian Hacker</title>
		<link>http://projectbee.org/blog/archive/ot-the-rant-of-a-republic-indian-hacker/</link>
		<comments>http://projectbee.org/blog/archive/ot-the-rant-of-a-republic-indian-hacker/#comments</comments>
		<pubDate>Mon, 26 Jan 2009 17:55:24 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[india]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[off-topic]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[rant]]></category>
		<category><![CDATA[corruption]]></category>
		<category><![CDATA[indian constitution]]></category>
		<category><![CDATA[parliament]]></category>
		<category><![CDATA[politicians]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=162</guid>
		<description><![CDATA[For me, the very foundations of Hacker-dom is based on three very fundamental steps: 1. Grasp the fundamentals 2. Question everything 3. Question everything, without being a fanatic As ironical (or rather illuminating, depending on the way you see) it may sound; as I start my very first step to understand the fundamentals of Indian [...]]]></description>
			<content:encoded><![CDATA[<p>For me, the very foundations of Hacker-dom is based on three very fundamental steps:<br />
1. Grasp the fundamentals<br />
2. Question everything<br />
3. Question everything, without being a fanatic</p>
<p><img class="alignnone" title="courtesy http://www.daylife.com/photo/07ox1R804F80k" src="https://projectbee.s3.amazonaws.com/img/PaintedKid.jpg" alt="" width="566" height="322" /></p>
<p>As ironical (or rather illuminating, depending on the way you see) it may sound; as I start my very first step to understand the fundamentals of Indian constitution on the <strong>59th Republic Day</strong>, I also start to learn to question it. It&#8217;s disturbing to learn that the borderline difference between pretending to be a democratic nation, and actually being one, has already depleted. What pains me more is that we &#8220;celebrate&#8221; the Republic day in the form of a &#8220;holiday&#8221;, without actually caring about being sovereign and republic.</p>
<p>I am starting to get fed up of getting used to all the abnormalities in the normal flow of life.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/apache-headache-no-listening-sockets-available/" rel="bookmark" title="August 8, 2007">Apache Headache: &#8220;no listening sockets available&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/" rel="bookmark" title="September 4, 2008">OWASP AppSec Conf Delhi &#8211; Day 2; and more</a></li>

<li><a href="http://projectbee.org/blog/archive/a-new-home-for-us/" rel="bookmark" title="May 6, 2008">A new home for us :)</a></li>

<li><a href="http://projectbee.org/blog/archive/bill-gates-no-more-the-richest/" rel="bookmark" title="July 4, 2007">Bill Gates no more The Richest</a></li>

<li><a href="http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/" rel="bookmark" title="December 20, 2007">Orkut Latest XSS Worm; and what it means for Indian Orkuteers</a></li>
</ul><!-- Similar Posts took 7.563 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/ot-the-rant-of-a-republic-indian-hacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP AppSec Conf Delhi &#8211; Day 2; and more</title>
		<link>http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/</link>
		<comments>http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 18:37:45 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[education]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[delhi]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owaspbangalore]]></category>
		<category><![CDATA[owaspdelhi]]></category>
		<category><![CDATA[travel]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=130</guid>
		<description><![CDATA[The pictures of Day 2 are here. The second day consisted of 6 workshops &#8211; 3 before lunch and 3 after. I was confused on choosing between Sheeraj Shah and Mano Paul&#8217;s workshops during the first half; and Jason Li&#8217;s talk on &#8220;Web 2.0  Security&#8221; and &#8220;Secure Code Review&#8221; workshop (originally by Dinis Cruz, but [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>The <a href="http://picasaweb.google.com/muxical.geek/OWASPAppSecConfDelhiAug08Day2">pictures of Day 2 are here</a>.</strong></em></p>
<p>The second day consisted of <a href="http://www.owasp.org/index.php/OWASP_AppSec_India_Conference_2008#Day_Two_.5BTrainings.2FWorkshops.5D:__Thursday_21st_August.2C_2008">6 workshops</a> &#8211; 3 before lunch and 3 after. I was confused on choosing between Sheeraj Shah and Mano Paul&#8217;s workshops during the first half; and Jason Li&#8217;s talk on &#8220;Web 2.0  Security&#8221; and &#8220;Secure Code Review&#8221; workshop (originally by Dinis Cruz, but conducted by Gaurav Kumar of Microsoft) on the second half.</p>
<p style="text-align: center;"><img class="aligncenter" title="Threat Modelling - Mano Paul" src="https://projectbee.s3.amazonaws.com/img/ManpPaul.jpg" alt="Threat Modelling - Mano Paul" width="565" height="359" /></p>
<p style="text-align: center;"><strong>Mano Paul</strong></p>
<p>Choosing <strong>Mano Paul&#8217;s</strong> Workshop on <strong>Threat Modelling</strong> was relatively easier because I am trying to push in Threat Modeling in my company. However, the disappointment of missing Sheeraj&#8217;s talk was no less. Although, I must confess Mano Paul is one heck of a presenter. <em>I guess experience always count.</em></p>
<p style="text-align: center;"><img class="aligncenter" title="Code Review - Gaurav Kumar" src="https://projectbee.s3.amazonaws.com/img/GauravKumar.jpg" alt="Code Review - Gaurav Kumar" width="565" height="384" /></p>
<p style="text-align: center;"><strong>Gaurav Kumar</strong></p>
<p>The decision for the second half was pretty tough. I had finally chosen <strong>Secure Code Review</strong> talk over Jason Li&#8217;s talk, because I&#8217;ve a personal interest in Code Review; added by the fact that the workshop was to be conducted by <strong>Dinis Cruz</strong>. Since we had to pre-select the talks, there was no scope to change it later. Needless to say, I was a bit disappointed initially. However, I must also mention that I don&#8217;t regret attending it. It was conducted by <strong>Gaurav Kumar</strong>, Ace Team, Microsoft. The best part about him, apart from the fact that he knows his stuff, is that he took all the M$ jokes sportingly <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p style="text-align: center;"><img class="aligncenter" title="Bipin with Walter and Jordan" src="https://projectbee.s3.amazonaws.com/img/Bipin-Walter-Jordan.jpg" alt="Bipin with Walter and Jordan" width="565" height="430" /></p>
<p style="text-align: center;"><strong>Bipin with Walter and Jordan</strong></p>
<p>I also got to meet <strong>Jordan Forssman </strong>(Armorize) and <strong>Walter Tsai </strong>(CTO, Armorize), although I regret not being able to spend enough time and talk some Geeky stuff. Oh and yes, Walter gifted me and Amit the <em>31337 </em>Armorize T-Shirts <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> . I also got to meet a couple of more like minded people, though very briefly. I couldn&#8217;t share cards with all of them. Today Lava (whom I met during Gaurav&#8217;s workshop), contacted me today via this blog. Feel greats to be in touch with fellow geeks and to be able to share the geekiness. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  I&#8217;d like to be in touch with others too. Please feel free to  <a href="http://projectbee.org/blog/contact/">buzz me</a>.</p>
<p>I must admit, the hangover remained for quite a few days. It had motivated us to evaluate the possibility of another OWASP conf at Banglore. We&#8217;ll be discussing it at the next meet. For now, I have another interesting announcement to make. <strong>OWASP Banglore Chapter is starting Open Workshops for developers, students, and anyone interested to learn about Web Security</strong>. The first one is on Sept. 7th, at Microland, Bellandur. If you are interested kindly <a href="http://projectbee.org/blog/contact/">drop me a mail</a>; or even better, joing the <a href="http://lists.owasp.org/mailman/listinfo/owasp-bangalore">OWASP Bangalore mailing list</a> and put up your details.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/" rel="bookmark" title="August 21, 2008">OWASP AppSec Conf Delhi &#8211; Day 1</a></li>

<li><a href="http://projectbee.org/blog/archive/securcamp-and-back/" rel="bookmark" title="July 12, 2008">SecurCamp and back.</a></li>

<li><a href="http://projectbee.org/blog/archive/securitycamp-is-here-where-are-you/" rel="bookmark" title="June 25, 2008">SecurityCamp is here, where are you?</a></li>

<li><a href="http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/" rel="bookmark" title="June 29, 2008">Reviving OWASP Bangalore Chapter</a></li>

<li><a href="http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/" rel="bookmark" title="May 19, 2007">Rediffmail Bug. Anyone Interested?</a></li>
</ul><!-- Similar Posts took 5.654 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>OWASP AppSec Conf Delhi &#8211; Day 1</title>
		<link>http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/</link>
		<comments>http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 06:41:33 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[hackers]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[delhi]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owaspdelhi]]></category>
		<category><![CDATA[pics]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=125</guid>
		<description><![CDATA[Special Note: I don&#8217;t have my Canon EOS 350D with me nowadays, so I had to borrow my roomates Canon Powershot. The quality sucks, but still, the pictures are here. I&#8217;ll be honest, going by the conf prices and some of the talk titles; I was expecting OWASP AppSec Delhi to be targeted mainly for [...]]]></description>
			<content:encoded><![CDATA[<p><em>Special Note: I don&#8217;t have my Canon EOS 350D with me nowadays, so I had to borrow my roomates Canon Powershot. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  The quality sucks, but still, the <a href="http://picasaweb.google.com/muxical.geek/OWASPAppSecConfDelhiAug08Day1">pictures are here</a>.</em></p>
<p>I&#8217;ll be honest, going by the conf prices and some of the talk titles; I was expecting <a href="http://www.owasp.org/index.php/OWASP_AppSec_India_Conference_2008">OWASP AppSec Delhi </a>to be targeted mainly for managers. Moreover, I didn&#8217;t really have enough hopes for the first day talks, at least. It felt even worse when I realized that Dinis Cruz hasn&#8217;t been able to make it. I was looking forward to his workshop in App Sec Code Review. But boy, what a day! <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>The registration was scheduled to begin at 8:15 AM and I reached at 7:45. As if that was not enough, the registration was delayed by another 40-45 minutes. I like to be punctual, but end up playing the endless wait-game more than often.  However, on the bright side I got to interact with a couple of great guys, like Amit Parekh (MPS). Quite surprisingly, I also came across Manjula (Aujas Networks). I say surprisingly because when we had discussed about the conference at a previous OWASP Bangalore chapter meet, she had no plans to visit. I am glad she decided at the last moment. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Before I mention about the talks, I feel obligated to thank Nitin of OWASP Delhi chapter for letting me attend the conference even though my company has failed to pay the conference fees at the moment due to some strange procedural issues.</p>
<p style="text-align: center;"><img class="aligncenter" title="Bipin &amp; Amit" src="http://s3.amazonaws.com/projectbee/img/OWASP-Delhi-1.JPG" alt="Bipin &amp; Amit" width="584" height="434" /></p>
<p style="text-align: center;"><span style="color: #808000;"><strong>Bipin &amp; Amit</strong></span></p>
<p>The day began with the <strong>keynote</strong> speeches by <strong>Dhruv Soni</strong> and <strong>Puneet Mehta</strong> (OWASP Delhi Chapter), <strong>Murli Krishna</strong>(HP),<strong> Dr. Kamlesh Bajaj</strong> (DSCI), <strong>Jason Li</strong>(OWASP), and <strong>Mano Paul</strong>(ISC^2). The welcome notes by Dhruv and Puneet were followed by Dr. Bajaj and Murli Krishna&#8217;s keynotes. I couldn&#8217;t help but wish I could get seniors from the network management unit of my firm. I would love to believe that they would have had a heart change with respect to application security after the keynote <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  . Jason spoke on behalf of Dinis and introduced the newbies to OWASP and a couple of its projects. In case you are unaware (like me), there has been an interesting addition to the OWASP projects called <a href="http://www.owasp.org/index.php/ESAPI"><strong>ESAPI</strong></a>. It looks good at first glance. Hopefully, I&#8217;ll be having a closer look pretty soon. Finally, Mano Paul provided some interesting metaphors to the security scenario, and also introduced the youngest hacker in the crowd, his two year old son. It&#8217;ll surely be fun to attend his workshop on <strong><em>Advanced Thread Modelling</em></strong>.</p>
<p>Following the Keynote speeches, <strong>Jason Li</strong> introduced the crowd to his <strong>AntiSamy project</strong>. I especially liked the way he&#8217;d organized his talk to compare several XSS mitigation techniques and then prove why AntiSamy&#8217;s (or HTMLPurifier&#8217;s) approach is better <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  . His talk was followed by <strong>Rajesh Nayak&#8217;s</strong> (HP) talk titled <strong>Web App Security: Too costly to ignore</strong>. Although, it was more of a sales pitch, it did have some valid points; and we did manage to have our share of fun. When a certain demo of his failed a couple of times and he had to restart his system, I couldn&#8217;t control my tendency to pass on loud remarks and asked whether it was an HP laptop <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />  .</p>
<p style="text-align: center;"><img class="aligncenter" title="Bipin &amp; Amit" src="http://s3.amazonaws.com/projectbee/img/OWASP-Delhi-2.JPG" alt="Bipin &amp; Amit" width="584" height="434" /></p>
<p style="text-align: center;"><strong>Manjula, Sheeraj, &amp; Amit</strong></p>
<p>The much awaited <strong>Sheeraj Shah&#8217;s</strong> talk on <strong>Web 2.0 Security</strong> came after the lunch. As expected of him, the talk was pretty technical and wasn&#8217;t really for the noobs. He also talked about his home-brewed scripts to analyze Web 2.0 enabled/hyped portals. Later, <strong>Roshan Chandran</strong> of <strong>Paladion</strong> presented a very interesting case study on <strong>Testing 200+ applications in a $10 Billion Enterprise</strong>. This talk provoked a lot of techies in the crowd who were silent till now. Finally, <strong>Nischal Bhalla</strong> delivered a talk on <strong>Building Enterprise AppSec Program</strong>. This is something I&#8217;ve been trying to do at my workplace (with the help of my Bosses) and I guess I&#8217;ll be mailing Nischal for the presentation.</p>
<p>To summarize, none of the talks were any ground breaking research that we were not aware of, but the difference always comes in with experience; and that&#8217;s what made it an amazing day. It was great to look at things from the perception of these uber hackers. I am eagerly looking forward for tomorrows workshop&#8217;s &#8211; <strong>Advanced Threat Modelling</strong> by <strong>Mano Paul</strong>, and <strong>App Sec Code Review</strong> by <strong>Gaurav Kumar</strong> (which was originally scheduled by Dinis Cruz.</p>
<p>Oh and yes! The food was pretty good too. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/" rel="bookmark" title="September 4, 2008">OWASP AppSec Conf Delhi &#8211; Day 2; and more</a></li>

<li><a href="http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/" rel="bookmark" title="June 29, 2008">Reviving OWASP Bangalore Chapter</a></li>

<li><a href="http://projectbee.org/blog/archive/securitycamp-is-here-where-are-you/" rel="bookmark" title="June 25, 2008">SecurityCamp is here, where are you?</a></li>

<li><a href="http://projectbee.org/blog/archive/securcamp-and-back/" rel="bookmark" title="July 12, 2008">SecurCamp and back.</a></li>

<li><a href="http://projectbee.org/blog/archive/tpm-boys-withdraw-paper-from-blackhat-usa/" rel="bookmark" title="July 5, 2007">TPM Boys withdraw paper from BlackHat USA</a></li>
</ul><!-- Similar Posts took 6.961 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>No more lectures now&#8230;</title>
		<link>http://projectbee.org/blog/archive/no-more-lectures-now/</link>
		<comments>http://projectbee.org/blog/archive/no-more-lectures-now/#comments</comments>
		<pubDate>Sat, 26 Jul 2008 10:36:53 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[hackers]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[death]]></category>
		<category><![CDATA[inspiration]]></category>
		<category><![CDATA[randy pausch]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=119</guid>
		<description><![CDATA[Randy Pausch, fondly known as the Last Lecture Guy, is no more. If you have not heard of him, I suggest you watch his &#8220;last lecture&#8221;. A summary of the lecture and Randy Pausch&#8217;s life can be read here. p.s.: @Johnny: Thanks for updating me. @Slashdot-ters: Thanks for not making stupid and mean remarks this [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Randy Pausch</strong>, fondly known as <strong>the Last Lecture Guy</strong>, is no more.</p>
<p>If you have not heard of him, I suggest you watch his &#8220;last lecture&#8221;. A summary of the lecture and Randy Pausch&#8217;s life can be <a href="http://www.brownalumnimagazine.com/november/december_2007/its_not_time_yet.html">read here</a>.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/ji5_MqicxSo&amp;hl=en&amp;fs=1" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/ji5_MqicxSo&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
<p>p.s.:<br />
@Johnny: Thanks for updating me.<br />
@Slashdot-ters: Thanks for not making stupid and mean remarks this time.<br />
@Randy Pausch: Rest In Peace dude.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/ot-sad-demise-of-guru-ammannur-madhava-chakyar/" rel="bookmark" title="July 2, 2008">[OT] Sad demise of Guru Ammannur Madhava Chakyar</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-headache-no-listening-sockets-available/" rel="bookmark" title="August 8, 2007">Apache Headache: &#8220;no listening sockets available&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/slashdot-uh/" rel="bookmark" title="May 21, 2008">Slashdot, uh! :|</a></li>

<li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/amazing-interrupt-handling/" rel="bookmark" title="April 12, 2007">Amazing Interrupt Handling!</a></li>
</ul><!-- Similar Posts took 5.006 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/no-more-lectures-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SecurCamp and back.</title>
		<link>http://projectbee.org/blog/archive/securcamp-and-back/</link>
		<comments>http://projectbee.org/blog/archive/securcamp-and-back/#comments</comments>
		<pubDate>Sat, 12 Jul 2008 15:25:28 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[hackers]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owaspbangalore]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=113</guid>
		<description><![CDATA[I spent the first half of the day at SecurCamp -1 (or Security Barcamp). It always great to get together with the community and today was no different. It came a sweet surprise to me that I have quite a few acquaintances in the community. The best part of the whole day, however, was getting [...]]]></description>
			<content:encoded><![CDATA[<p>I spent the first half of the day at <a href="http://securitycamp.pbwiki.com/">SecurCamp -1</a> (or Security Barcamp). It always great to get together with the community and today was no different. It came a sweet surprise to me that I have quite a few acquaintances in the community. The best part of the whole day, however, was getting together with <a href="http://reboot.in/">Lucky</a> after a loooong time. It&#8217;s pretty strange that even after being in the same city, we haven&#8217;t been able to meet as often as we could have. So I decided to use the opportunity properly. In fact, I am now at his house, using his 1 mbs line while he&#8217;s away for his dance class (and hoping he doesn&#8217;t keep a sniffer on).</p>
<p><img src="http://s3.amazonaws.com/projectbee/img/Camping2.jpg" alt="By flickr.com/photos/fortphoto/2563803794/" width="609" height="390" /></p>
<p>I presented on &#8220;A conceptual Phishing/Fraud IDS&#8221;, something I had worked in Jan/Feb, but have been sleeping on in for all this while. Thanks to <a href="http://johnnyjacob.wordpress.com/">Johnny&#8217;s</a> pestering, I think I&#8217;ll write a small paper on it and distribute for review. I just hope the increased official workload is minimized by the new members joining the team. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>We also used the opportunity to announce the OWASP Bangalore chapter revival. I have personally been working on identifying ways to ensure OWASP&#8217;s reach to the colleges, and have prepared a list of colleges in Bangalore. Let&#8217;s hope that we make it quick on that front too. Just to re-announce, if you are a student in/around Bangalore, drop me a <a href="http://projectbee.org/blog/contact/">note</a> and we&#8217;ll put your college on top-priority. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I also had a very strange realization today. I have been a member of several communities (security and otherwise) and differences creep-in at some point. However, they are pretty quick (and a little more obvious) in the security communities. Be it mailing lists, blogs or even physical meets, people respond (and then re-respond) pretty loudly. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Is it because security is pretty demanding field where there isn&#8217;t much scope for a mistake, or is it because we all in the field carry a &#8220;I CAN&#8217;T be wrong&#8221; badge, or is it some other reason?</p>
<p>Time to move now. Hancock at 9:45PM <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/" rel="bookmark" title="June 29, 2008">Reviving OWASP Bangalore Chapter</a></li>

<li><a href="http://projectbee.org/blog/archive/securitycamp-is-here-where-are-you/" rel="bookmark" title="June 25, 2008">SecurityCamp is here, where are you?</a></li>

<li><a href="http://projectbee.org/blog/archive/zone-h-deafced-by-saudi-hackers/" rel="bookmark" title="January 23, 2007">Zone-H Deafced by Saudi Hackers.</a></li>

<li><a href="http://projectbee.org/blog/archive/open-javafx-an-alternative-to-ajax/" rel="bookmark" title="May 9, 2007">Open JavaFX, an alternative to AJAX?</a></li>

<li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>
</ul><!-- Similar Posts took 5.191 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/securcamp-and-back/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Reviving OWASP Bangalore Chapter</title>
		<link>http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/</link>
		<comments>http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/#comments</comments>
		<pubDate>Sun, 29 Jun 2008 14:23:56 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[life]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[community]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owaspbangalore]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=106</guid>
		<description><![CDATA[The OWASP Bangalore Chapter met after almost an year today, and I was priviledged to be a part of it. As happens often with technical groups, including LUGs (Linux User Groups), they tend to loose participation and go to indefinite hibernation mode. OWASP-Bangalore&#8217;s fate was no different. Anyhoo! The important point is that we finally [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.owasp.org/index.php/Bangalore">OWASP Bangalore Chapter</a> met after almost an year today, and I was priviledged to be a part of it. As happens often with technical groups, including LUGs (Linux User Groups), they tend to loose participation and go to indefinite hibernation mode. OWASP-Bangalore&#8217;s fate was no different.</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-107" title="Meeting room stencil graffiti by -- flickr.com/photos/clagnut/252185030/" src="http://projectbee.s3.amazonaws.com/img/Meeting.jpg" alt="Meeting room stencil graffiti by -- flickr.com/photos/clagnut/252185030/" width="500" height="375" /></p>
<p>Anyhoo! The important point is that we finally met today. There were around 12 peole who turned up, and boy, It&#8217;s always an honour to meet enthusiastic people from the Security community. Minutes of the meeting will be posted by Hari, Chapter coordinator, pretty soon on the OWASP-Bangalore mailing list. To cut things short, we discussed and decided on a couple of points to revive the Bangalore Chapter. I&#8217;ll personally be looking forward to spreading the information to younger audience. So, <strong>just in case you are a part of some College around Bangalore, <a href="http://projectbee.org/blog/contact/">feel free to drop me a note</a></strong>. We&#8217;d love to visit your campus and deliver talks, free of charge. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
As for the regular meetings, we&#8217;ve decided to meet every fourth Wednesday of the month. Venues will of course, keep changing.</p>
<p><em>p.s. I love the song &#8220;Jaane Kya Baat Hai&#8221; from the movie Sunny. But somehow, I am not able to get the other song,&#8221;Aur Kya Ahde Wafaa Hote Hain&#8221;, out of my mind since morning. Not that I am complaining <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </em></p>
<table style="  background-color: #FFFFFF   ;border-color: #cccccc; color:#0000FF ; font-family:Arial, Helvetica, sans-serif; font-size:11px; padding:0px; border-width:1px; border-style:solid" border="0" cellspacing="0" cellpadding="4">
<tbody>
<tr>
<td align="center"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="92" height="140" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="bgcolor" value="#FFFFFF" /><param name="flashvars" value="autoPlay=no&amp;theFile=http://www.esnips.com//nsdoc/25708aa0-66eb-430c-be00-49a660bae4f4&amp;theName=Aur Kya Ahede Wafa Hote Hai - Sunny&amp;thePlayerURL=http://www.esnips.com//escentral/images/widgets/flash/mp3WidgetPlayer.swf" /><param name="src" value="http://www.esnips.com//escentral/images/widgets/flash/candle.swf" /><embed type="application/x-shockwave-flash" width="92" height="140" src="http://www.esnips.com//escentral/images/widgets/flash/candle.swf" flashvars="autoPlay=no&amp;theFile=http://www.esnips.com//nsdoc/25708aa0-66eb-430c-be00-49a660bae4f4&amp;theName=Aur Kya Ahede Wafa Hote Hai - Sunny&amp;thePlayerURL=http://www.esnips.com//escentral/images/widgets/flash/mp3WidgetPlayer.swf" bgcolor="#FFFFFF"></embed></object></td>
</tr>
<tr>
<td style="font-size:11px" align="center" valign="bottom"><a style="color: #0000FF" href="http://www.esnips.com/doc/25708aa0-66eb-430c-be00-49a660bae4f4/Aur-Kya-Ahede-Wafa-Hote-Hai---Sunny/?widget=flash_player_candle">Aur Kya Ahede Wafa&#8230;</a></td>
</tr>
</tbody>
</table>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/securcamp-and-back/" rel="bookmark" title="July 12, 2008">SecurCamp and back.</a></li>

<li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-1/" rel="bookmark" title="August 21, 2008">OWASP AppSec Conf Delhi &#8211; Day 1</a></li>

<li><a href="http://projectbee.org/blog/archive/securitycamp-is-here-where-are-you/" rel="bookmark" title="June 25, 2008">SecurityCamp is here, where are you?</a></li>

<li><a href="http://projectbee.org/blog/archive/owasp-appsec-conf-delhi-day-2-and-more/" rel="bookmark" title="September 4, 2008">OWASP AppSec Conf Delhi &#8211; Day 2; and more</a></li>

<li><a href="http://projectbee.org/blog/archive/http-protocol/" rel="bookmark" title="December 15, 2011">HTTP protocol and other stuff that power the web</a></li>
</ul><!-- Similar Posts took 5.198 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/reviving-owasp-bangalore-chapter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bittu&#8217;s back :)</title>
		<link>http://projectbee.org/blog/archive/bittus-back/</link>
		<comments>http://projectbee.org/blog/archive/bittus-back/#comments</comments>
		<pubDate>Thu, 12 Jun 2008 11:31:15 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=103</guid>
		<description><![CDATA[Bittu, my wife, got revamped. For unemotional people, it simply means I bought a new laptop She is red, and she&#8217;s hot! She&#8217;s a Dell XPS M1330. Other features include: 1. Intel Core-2 Duo, 2.1 GHz (My first intel. I used to be with AMD) 2. 200GB HD , 7200rpm 3. 128 MB Nvidia graphics [...]]]></description>
			<content:encoded><![CDATA[<p>Bittu, my wife, got revamped. <em>For unemotional people, it simply means I bought a new laptop</em> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>She is red, and she&#8217;s hot!</p>
<p><img src="http://farm4.static.flickr.com/3163/2571423177_fdc6c3a8c9_o_d.jpg" alt="Bittu" width="454" height="340" /></p>
<p>She&#8217;s a Dell XPS M1330. Other features include:</p>
<p>1. Intel Core-2 Duo, 2.1 GHz (<em>My first intel. I used to be with AMD</em>)<br />
2. 200GB HD , 7200rpm<br />
3. 128 MB Nvidia graphics card (<em>the games run awesomely, and I have re-entered the gaming arena. Currently re-re-replaying Serious Sam, Second Encounter</em>)<br />
4. Pre-Loaded Vista <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />   (<em>I am still a little confused, whether I go ahead with OpenSuse 10.3 or wait 6 more days for OpenSuse 11 to arrive.</em> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  )<br />
5. and other regular features like DVD writer, fingerprint scanner, built-in webcam, etc. etc. etc.</p>
<p>I should have updated about her by now, but have been very very busy with an official work involving OpenSocial till yesterday. Hoping to publish other draftified articles soon.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/what-a-new-year-gift/" rel="bookmark" title="January 5, 2008">What a new year Gift! :)</a></li>

<li><a href="http://projectbee.org/blog/archive/the-web-is-broken/" rel="bookmark" title="October 12, 2007">The Web is Broken</a></li>

<li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>

<li><a href="http://projectbee.org/blog/archive/securitycamp-is-here-where-are-you/" rel="bookmark" title="June 25, 2008">SecurityCamp is here, where are you?</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-headache-no-listening-sockets-available/" rel="bookmark" title="August 8, 2007">Apache Headache: &#8220;no listening sockets available&#8221;</a></li>
</ul><!-- Similar Posts took 8.177 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/bittus-back/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>iHacker</title>
		<link>http://projectbee.org/blog/archive/ihacker/</link>
		<comments>http://projectbee.org/blog/archive/ihacker/#comments</comments>
		<pubDate>Tue, 29 Apr 2008 20:06:35 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[apple]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://projectbee.org/blog/?p=91</guid>
		<description><![CDATA[I have a special likeness for T-Shirt with quotes. More Geeky the quote, more geekier&#8230; I mean better. I got this T-Shirt made for myself a couple of days ago. I case you didn&#8217;t get, it&#8217;s a mockery of the crippled iPhone. Oh by the way, this is my first post on the new blog, [...]]]></description>
			<content:encoded><![CDATA[<p>I have a special likeness for T-Shirt with quotes. More Geeky the quote, more geekier&#8230; I mean better.<br />
I got this T-Shirt made for myself a couple of days ago.<br />
I case you didn&#8217;t get, it&#8217;s a mockery of the crippled iPhone.</p>
<p style="text-align: center;"><img class="aligncenter" src="http://s3.amazonaws.com/projectbee/img/iHacker.jpg" alt="iHcaker" width="495" height="330" /></p>
<p>Oh by the way, this is my first post on the new blog, and this pic is a response to Swenny&#8217;s post on <strong><a href="http://theaveragelife.wordpress.com/2008/04/28/adding-an-i/">Adding an &#8220;i&#8221;</a> </strong> <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/how-about-a-better-cheaper-macbook-air/" rel="bookmark" title="January 31, 2008">How about a Better &#38; Cheaper MacBook Air!</a></li>

<li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoos-javascript-based-mp3-player/" rel="bookmark" title="January 9, 2008">Yahoo!&#8217;s javascript based media player!</a></li>

<li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/" rel="bookmark" title="January 28, 2006">&#34;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&#34;&#8230;.. aaah Comm&#8217;n Gimme a break.</a></li>
</ul><!-- Similar Posts took 9.447 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/ihacker/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How about a Better &amp; Cheaper MacBook Air!</title>
		<link>http://projectbee.org/blog/archive/how-about-a-better-cheaper-macbook-air/</link>
		<comments>http://projectbee.org/blog/archive/how-about-a-better-cheaper-macbook-air/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 12:34:20 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[apple]]></category>
		<category><![CDATA[humour]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[macbook]]></category>
		<category><![CDATA[macbook air]]></category>
		<category><![CDATA[parody]]></category>
		<category><![CDATA[reality]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/?p=70</guid>
		<description><![CDATA[Those were the days when I used to be a Apple fan. aah.. the harsh reality that they produce nothing more than crippled products at sky-high prices. Moreover, Apple isn&#8217;t just about cut-throat business. It&#8217;s also about making people feel bad about themselves. Don&#8217;t trust me? See here yourself. Similar Posts:iHacker Dreams&#8230; and (huh!) Reality. [...]]]></description>
			<content:encoded><![CDATA[<p>Those were the days when I used to be a Apple fan.<br />
aah.. the harsh reality that they produce nothing more than crippled products at sky-high prices.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="wmode" value="transparent" /><param name="src" value="http://www.youtube.com/v/sQiiszIthx4&amp;hl=en" /><embed type="application/x-shockwave-flash" width="425" height="355" src="http://www.youtube.com/v/sQiiszIthx4&amp;hl=en" wmode="transparent"></embed></object></p>
<p>Moreover, Apple isn&#8217;t just about cut-throat business. It&#8217;s also about making people feel bad about themselves.<br />
Don&#8217;t trust me?<br />
See here yourself.</p>
<p><object width="425" height="355"><param name="movie" value="http://www.youtube.com/v/gQkdVymW8C8&#038;hl=en"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/gQkdVymW8C8&#038;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"></embed></object></p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/ihacker/" rel="bookmark" title="April 30, 2008">iHacker</a></li>

<li><a href="http://projectbee.org/blog/archive/dreams-and-huh-reality/" rel="bookmark" title="June 4, 2007">Dreams&#8230; and (huh!) Reality.</a></li>

<li><a href="http://projectbee.org/blog/archive/bill-gates-wins-me/" rel="bookmark" title="June 19, 2007">Bill Gates wins me!</a></li>

<li><a href="http://projectbee.org/blog/archive/how-my-kindle-cover-saved-my-kindle-or-how-i-got-robbed-of-my-dslr-and-laptop/" rel="bookmark" title="February 17, 2012">How my Kindle cover saved my Kindle, OR How I got robbed of my DSLR and laptop</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>
</ul><!-- Similar Posts took 4.959 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/how-about-a-better-cheaper-macbook-air/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>A Phish floating in Google Survey!</title>
		<link>http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/</link>
		<comments>http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 16:24:26 +0000</pubDate>
		<dc:creator>Bipin Upadhyay</dc:creator>
				<category><![CDATA[demo]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/?p=68</guid>
		<description><![CDATA[Demo 1. Phizy-Phizy-Phizy I have always loved making this phizy-phizy-phizy sound purposelessly, which I once heard in a Rob Schneider movie (which, if I remember correctly, was a pathetic movie). Anyhoo! I, now, have a set of very strong reasons to move around repeating the same lines. First, we received a request to be involved [...]]]></description>
			<content:encoded><![CDATA[<h3><span style="color: #3366ff;"><strong><a href="http://yahoo-survey.99k.org/">Demo</a></strong></span></h3>
<h3><span style="color: #3366ff;"><strong><a href="http://yahoo-survey.99k.org/"></a></strong></span> <span style="color: #3366ff;"><strong>1. Phizy-Phizy-Phizy</strong></span></h3>
<p>I have always loved making this <em>phizy-phizy-phizy</em> sound purposelessly, which I once heard in a <a href="http://www.imdb.com/name/nm0001705/">Rob Schneider</a> movie (which, if I remember correctly, was a pathetic movie). Anyhoo! I, now, have a set of very strong reasons to move around repeating the same lines.<br />
First, we received a request to be involved in a discussion for a Risk Assessment Model for a Banking site. This model had to be focussed on Two Factor Authentication and <strong>Phishing</strong>. This brainstorming gave me a couple of interesting avenues to work on. Hopefully, I&#8217;ll be writing more in this pretty soon.<br />
Secondly, <a href="http://jtrac.info">Peter Thomas</a> (one of my amazing Bosses), forwarded me the link about the <a href="http://www.net-security.org/article.php?id=1110">latest research</a> by <a href="http://www.dhanjani.com/blog/2008/01/bad-sushi-beati.html/">Nitesh Dhanjani</a> &amp; Billy Rios. They virtually infiltrated the Phishers ecosystem and have come up with some very interesting information.<br />
Thirdly, my friend <a href="http://theaveragelife.wordpress.com/">Swen</a> called me up to let me know about a phishing mail, claiming to be a Google survey, that had landed in his mailbox. He was excited for two reasons:<br />
a) He had received a phishing mail for the first time, and I guess you all remember the excitement the first time you discovered your first phishing mail.<br />
b) He is one of the Google fans, and is worried about the safety of the vast majority of user-base Google has. Obviously, his concern isn&#8217;t without reasons.<br />
<img src="http://s3.amazonaws.com/projectbee/img/Phishes.jpg" alt="by-mcbeth www.flickr.com/photos/mcbeth/235875/" width="498" height="368" /></p>
<h3><span style="color: #3366ff;">2. A Phish named GoogleSurvey</span></h3>
<p>As I mentioned Swen informed me about the shiny phish called GoogleSurvey. It presents you a page that looks completely similar to the Google Login page and requests you to login in order to complete the survey. If you login, you are presented with 3 questions on by one. At the end you are thanked for completing the survey.</p>
<h3><span style="color: #3366ff;">3. Anatomy of Google-Survey-Phish gills</span></h3>
<p>The Google Survey Phish isn&#8217;t sophisticated y ANY standards. Clearly, it&#8217;s done by some n00b, and was probably deployed using a very cheap Phishing Kit. However, it&#8217;s really interesting to understand how it works.<br />
The first page the you encounter while analyzing is <a href="http://www.googlesurvey.co.nr/">http://www.googlesurvey.co.nr/</a>, which I must admit, looks very similar to the Google Mail login page. A look at the source code reveals that this is not the original page. The google mail look-alike page is alike page is actually located at <a href="http://googlesurvey.99k.org/">http://googlesurvey.99k.org/</a>. http://www.googlesurvey.co.nr/ only frames the page at with 100% width and 0px border.</p>
<p>Another interesting point to note is that the phisher used a free hosting service http://www.zymic.com/free-web-hosting/. Thus, theoretically he/she cannot be traced. Not via the hosting service, at least. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now, when you enter your id and password, the data is sent to a php script on the server located at http://googlesurvey.99k.org/LoginAuth.php. Quite obviously, this script stores/mails your credentials for someone who&#8217;s not a very pleasing person.</p>
<h3><span style="color: #3366ff;">4. <a href="http://yahoo-survey.99k.org/">Demo: Farming your own Phishes for fun &amp; profit *cough*</a></span></h3>
<p>The world of Phishing is so dark, deep, safe, easy, and seductive that a person with even a slight malign would be tempted to this farm his/her own phishes and make easy money. I <a href="http://yahoo-survey.99k.org/">set up my phishing domain for educational purposes</a>. It also shows how quickly you can setup your very own phishing portal, sometimes even without a phishing kit. The domain I&#8217;ve setup has the following flaws (introduced to prevent me getting screwed by some half-witted law enforcer) :<br />
1. The domain points at Yahoo!, while the page displayed is similar to the GMail login page.<br />
2. The information entered is NOT stored. You can check it by entering garbage data.</p>
<p>I have used the same page used by the GoogleSurvey Phish, and also used the same free hosting service.</p>
<h3><span style="color: #3366ff;">5. Conclusion</span></h3>
<p>It&#8217;s almost impossible to prevent users from getting Phished. People will continue to click on links they receive in their inbox and &lt;/sarcasm&gt; proceed to win an ipod &lt;/sarcasm&gt;. Reducing phishing requires a number of things to be in place -sensible developers, well informed end user, smart browsers with phishing aware features (IE7, Fx2 etc.), a few toolbars like NetCraft to be installed, etc. etc. And even doing all this doesn&#8217;t guarantee to save a user ignorant of phshing. I mean how do you save a person who doesn&#8217;t even know that such a kind of fraud exists.<br />
Moreover, the URI vulnerabilities have added another dimension to the whole phishing scene. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/colukabki-aol-msn-yahoo-red-cross-aaah-commn-gimme-a-break/" rel="bookmark" title="January 28, 2006">&#34;COLUKABKI &#8211; AOL &#8211; MSN &#8211; YAHOO &#8211; RED CROSS&#34;&#8230;.. aaah Comm&#8217;n Gimme a break.</a></li>

<li><a href="http://projectbee.org/blog/archive/rediffmail-bug-anyone-interested/" rel="bookmark" title="May 19, 2007">Rediffmail Bug. Anyone Interested?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/google-bomb-update-diffused/" rel="bookmark" title="January 22, 2007">Google Bomb! [Update: Diffused]</a></li>

<li><a href="http://projectbee.org/blog/archive/top-rating-in-google-d/" rel="bookmark" title="January 18, 2007">Top Rating in Google :D</a></li>
</ul><!-- Similar Posts took 6.703 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Yahoo!&#8217;s javascript based media player!</title>
		<link>http://projectbee.org/blog/archive/yahoos-javascript-based-mp3-player/</link>
		<comments>http://projectbee.org/blog/archive/yahoos-javascript-based-mp3-player/#comments</comments>
		<pubDate>Wed, 09 Jan 2008 10:45:55 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[demo]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[yahoo]]></category>
		<category><![CDATA[hindi]]></category>
		<category><![CDATA[malgudi days]]></category>
		<category><![CDATA[mp3]]></category>
		<category><![CDATA[songs]]></category>
		<category><![CDATA[surabhi]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2008/01/09/yahoos-javascript-based-mp3-player/</guid>
		<description><![CDATA[Yahoo! launched it browser based media player written in javascript. All you have to do is link the javascript code (located at http://mediaplayer.yahoo.com/js) in a web page having links to audio file(s) . Although it takes a while for the &#8220;player&#8221; to load completely, yet I am pretty okay with it (for now). Moreover, it&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://developer.yahoo.com/mediaplayer/">Yahoo! launched it browser based media player</a> written in javascript. All you have to do is link the javascript code (located at <a href="http://mediaplayer.yahoo.com/js">http://mediaplayer.yahoo.com/js</a>) in a web page having links to audio file(s) .</p>
<p>Although it takes a while for the &#8220;player&#8221; to load completely, yet I am pretty okay with it (for now). Moreover, it&#8217;s in beta. I, however, sincerely hope that it doesn&#8217;t follow GMail beta path. urghh!</p>
<p><strike>Check back again in a few hours. I&#8217;ll posting a demo of the player on my portal.</strike> <a href="http://projectbee.org/demos/YMusic.html">A demo is here. </a><strike>The demo would have</strike> This demo has a special meaning for the Indians of my age (or older than) because the songs I&#8217;ll be using will be the one we all grew up with, viz. Jungle Book, Mile Sur Mera Tumhara, Baje Sargam, Byomkesh Bakshi, Malgudi Days, Surabhi, Tipu Sultan &amp; Mahbharat. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Special thanks to Madhav for sharing them.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/grabbing-video-from-youtube/" rel="bookmark" title="January 6, 2007">Grabbing Video from Youtube.</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoo-gone-insane/" rel="bookmark" title="August 11, 2007">Yahoo! gone Insane!</a></li>

<li><a href="http://projectbee.org/blog/archive/drive-by-download-where-network-security-meets-webappsec/" rel="bookmark" title="November 2, 2007">Drive-by Download: Where Network Security Meets WebAppSec</a></li>

<li><a href="http://projectbee.org/blog/archive/a-new-home-for-us/" rel="bookmark" title="May 6, 2008">A new home for us :)</a></li>

<li><a href="http://projectbee.org/blog/archive/m-windowsxp-just-got-a-newer-version-of-update-with-new-components/" rel="bookmark" title="August 21, 2007">M$ WindowsXP just got a newer version of Update with new Components!</a></li>
</ul><!-- Similar Posts took 7.723 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/yahoos-javascript-based-mp3-player/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>AdSense exploited by malware (Trojan.Qhost.WU)</title>
		<link>http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/</link>
		<comments>http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/#comments</comments>
		<pubDate>Sat, 22 Dec 2007 14:27:14 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[bug]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[loophole]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[fraud]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/12/22/adsense-exploited-by-malware-trojanqhostwu/</guid>
		<description><![CDATA[1. Life &#38; Code (The title of this section is taken from Johnny&#8217;s blog of the same name, Life and Code. Although my implementation of the phrase isn&#8217;t in terms with Johnny&#8217;s, yet I could resist using it. ) Life: Three days ago I found that there are some strange entries in my local Apache [...]]]></description>
			<content:encoded><![CDATA[<h3><span style="color: #3366ff;"><strong>1. Life &amp; Code</strong></span></h3>
<p><img class="alignleft" style="float: left;" src="http://projectbee.org/blog/wp-content/uploads/2007/12/malware.jpg" alt="By http://www.flickr.com/photos/13798876@N02/1466880287/" width="187" height="184" align="left" /></p>
<p>(The title of this section is taken from Johnny&#8217;s blog of the same name, <a href="http://johnnyjacob.wordpress.com/">Life and Code</a>. Although my implementation of the phrase isn&#8217;t in terms with Johnny&#8217;s, yet I could resist using it. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  )</p>
<p><strong>Life:</strong> Three days ago I found that there are some strange entries in my local Apache web server logs. Something like:<br />
<code>127.0.0.1 - - [18/Dec/2007:19:39:26 +0530] "GET /iview/msnnkhac001160x600Xdig1600000185msn/direct;wi.160;hi.600/01 HTTP/1.1" 404 352<br />
127.0.0.1 - - [18/Dec/2007:19:42:19 +0530] "GET /pagead/show_ads.js HTTP/1.1" 404 320<br />
</code><br />
<strong>Code:</strong> <a href="http://www.bitdefender.com/VIRUS-1000239-en--Trojan.Qhost.WU.html">Bitdefender informs of a malware</a>, termed as Trojan.Qhost.WU, is redirecting all the requests made to the Google&#8217;s ad server (<em>page2.googlesyndication.com</em>) by the victims browser to a rougue ad server.</p>
<h3><span style="color: #3366ff;">2. Impact of the issue:</span></h3>
<p>Reportedly, a big part of Google&#8217;s earnings comes from it&#8217;s Ad services. Thus this trojan is not only depriving Google of it&#8217;s earning&#8217;s, but also the publishers who work hard and hope to make some quick buck for their evening coffee.</p>
<h3><span style="color: #3366ff;">3. The enigmatic &#8220;hosts&#8221; file:</span></h3>
<p>You all know that every system connected directly to the internet is assigned a unique IP address. The domain name (viz. <a href="http://projectbee.org">http://projectbee.org</a>) is nothing but a unique name assigned to a unique IP (although more than one domain name can  be mapped to an ip address, that is not our concern right now). This mapping is stored in DNS servers. Each time the browser tries to open up a site, a nearby DNS server is queried to find the ip address.<br />
However,  before all this, the <em>DNS server</em> of your local system, <strong><em>hosts</em></strong> file, is queried. (Don&#8217;t mistake me, this DNS server is just a metaphor <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). The hosts file stores a domain name to ip address mapping for domains that don&#8217;t need a query to DNS server. e.g., <strong>localhost</strong> is mapped to <strong>127.0.0.1</strong>, the loopback ip, i.e. the ip of local system.<br />
On your windows 2000/NT onwards system, it&#8217;s located at <em>%systemroot%\system32\drivers\etc\hosts</em> and on your *nix systems at <em>/etc/hosts</em>. More info on location can <a href="http://en.wikipedia.org/wiki/Hosts_file#Location_and_default_content">be found here</a>.</p>
<p>Now coming back to my problem; unable to find any satisfactory answer, I <a href="http://sla.ckers.org/forum/read.php?11,18461">posted it on Slackers</a>. (Giorgio) Maone, better known as author of the awesome <a href="http://noscript.net">NoScript plugin</a> for Fx, immediately responded, and asked me to check my hosts file.<br />
I had added a number of entries of ad serving sites to point to the local ip in my hosts file and forgotten. I did this to prevent ads from being loaded. Hence, each time any of these sites were called, the hosts file redirected the requests to my local server.<br />
So pretty obviously, I was/am not infected.<br />
&#8220;Why do you post the junk about your issue then?&#8221;, you ask.<br />
&#8220;Because it was a strange coincidence, and because I can, honey <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> &#8221;</p>
<h3><span style="color: #3366ff;">4. How the exploit works?</span></h3>
<p>It&#8217;s fairly simple, the malware modifies your hosts file and adds an entry for <em>page2.googlesyndication.com</em> to prevent DNS lookups and direct all the requests to the malicious server.</p>
<h3><span style="color: #3366ff;">5. How do I protect myself?</span></h3>
<p>1. Locate your hosts file and remove any entry for <em>page2.googlesyndication.com</em>. Alternately, you can even modify the entry to point to your local ip, in case you don&#8217;t wish to see those ads.<br />
2. Let your Antivirus/AntiSpyware do it for you.</p>
<h3><span style="color: #3366ff;">6. Conclusion</span></h3>
<p>What! Dump M$ Windows for Linux. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /><br />
Seriously, &#8220;Linux ain&#8217;t easy to use&#8221; is a myth. Moreover, if you are into flashy looks, try compiz-beryl package. It IS Awesome&#8230; (and consumes amazingly less resources than&#8230;uh Vista.)</p>
<h3><span style="color: #3366ff;">7. Bonus Tip</span></h3>
<p>In case you wish to prevent your kids, partner, (or even parents) from visiting some sites; or do not wish to see those crappy ads from being loaded, you might consider editing your hosts file. For more information or even sample hosts files, use <a href="http://search.yahoo.com/search;_ylt=A0oGknBwFW1HZj4B0StXNyoA?p=block+sites+with+hosts+file&amp;y=Search">Yahoo! search</a>.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/a-phish-floating-in-google-survey/" rel="bookmark" title="January 29, 2008">A Phish floating in Google Survey!</a></li>

<li><a href="http://projectbee.org/blog/archive/month-of-search-engine-bugs-mission-accomplished/" rel="bookmark" title="July 3, 2007">Month of Search Engine Bugs: &#8220;Mission Accomplished&#8221;</a></li>

<li><a href="http://projectbee.org/blog/archive/amazing-interrupt-handling/" rel="bookmark" title="April 12, 2007">Amazing Interrupt Handling!</a></li>

<li><a href="http://projectbee.org/blog/archive/google-lost-me/" rel="bookmark" title="June 17, 2007">Google Lost Me!</a></li>

<li><a href="http://projectbee.org/blog/archive/apache-mysqlphp-installation-configuration-tutorial-for-beginners/" rel="bookmark" title="February 25, 2006">Apache-MySQLPHP Installation &#038; Configuration Tutorial for Beginners :)</a></li>
</ul><!-- Similar Posts took 8.980 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Orkut Latest XSS Worm; and what it means for Indian Orkuteers</title>
		<link>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/</link>
		<comments>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/#comments</comments>
		<pubDate>Thu, 20 Dec 2007 10:14:39 +0000</pubDate>
		<dc:creator>Bipin 3 Upadhyay</dc:creator>
				<category><![CDATA[cyberlaw]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[guide]]></category>
		<category><![CDATA[irony]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[reality]]></category>

		<guid isPermaLink="false">http://codeinmybug.wordpress.com/2007/12/20/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/</guid>
		<description><![CDATA[Update: Kishor reports a flaw in the implementation of &#8220;private&#8221; videos feature on Orkut. Although I am at office and I haven&#8217;t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. 1. YAWN [Yet Another Worm, Nanny] Orkut (Google&#8217;s MySpace and Facebook for Indian, Pakistan [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #3366ff;"><strong>Update: </strong></span>Kishor reports <a href="http://wasjournal.blogspot.com/2007/12/orkut-private-videos-are-not-private.html">a flaw in the implementation of &#8220;private&#8221; videos feature on Orkut</a>. Although I am at office and I haven&#8217;t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div>
<h3><span style="color: #3366ff;"><strong>1. YAWN [Yet Another Worm, Nanny]</strong></span></h3>
</div>
<h3><img src="http://farm3.static.flickr.com/2084/1735501790_18be4450be_d.jpg" alt="http://flickr.com/photos/aqlott/1735501790/" width="403" height="227" /></h3>
<p>Orkut (Google&#8217;s MySpace and Facebook for Indian, Pakistan and Brazil) has been hit by an XSS worm. It&#8217;s useless to say but I am not able to resist, so I&#8217;ll say it anyways. <em>It&#8217;s not the first time that a Social networking site has been attacked by an XSS worm.</em> In fact these sites are the primary target due to a number of reasons -easier gullibility level, exponential reach, huge amount of data waiting to be harvested, <strong>web 2.0</strong> etc. etc. etc. There&#8217;s good compilation of XSS worms going on <a href="http://sla.ckers.org/forum/read.php?2,14477,18504">at Slackers </a>(Social n/w worm, or no).<br />
Anyhoo. This incident has <a href="http://www.cgisecurity.com/2007/12/17">already been</a> <a href="http://antrix.net/journal/techtalk/orkut_xss.html" target="_blank">reported</a> <a href="http://tkhere.blogspot.com/2007/12/orkut-under-cross-site-scripting-xss.html">by a</a> <a href="http://www.marrowbones.com/commons/technosocial/2007/12/orkut_worm_code_and_why_was_go.html" target="_blank">number of</a> <a href="http://www.gnucitizen.org/blog/the-orkut-xss-worm" target="_blank">bloggers</a>, so I  won&#8217;t dive into the technical details. However, this worm seems to be harmless and fixed for now.</p>
<div>
<h3><span style="color: #3366ff;"><strong>2. What it did?</strong></span></h3>
</div>
<p>If you <strong>view</strong>ed a message <strong><em>2008 vem ai&#8230; que ele comece mto bem para vc</em></strong> in your scrapbook, there is a big probability that you&#8217;re infected. You were added to a community named <em><strong>Infectados pelo Vírus do Orkut</strong></em> at http://www.orkut.com/CommunityJoin.aspx?cmm=44001818. The worm then forwards itself to the scrapbook of all your contacts (on your behalf). Any doubts on it being exponential?</p>
<div>
<h3><span style="color: #3366ff;"><strong>3. </strong><a href="//www.mit.gov.in/download/itbill2000.pdf" target="_blank"><strong>IT Act 2000</strong></a><strong> </strong><strong>[pdf]</strong></span></h3>
</div>
<p>IT Act 2000 is India&#8217;s legal answer to the miscreants on the technological front. (I realize it&#8217;s a pathetic definition, so no flame on it please <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ). The trouble with IT Act 2000 is that the majority of law enforcers aren&#8217;t really aware of the real life scenarios. I&#8217;ll give a real case to support the point, in a while. Although I am no law expert (just a little bit of interest), I guess I can safely say that the Act needs a few amendments to include/modify a number of issues (e.g., SPAM, etc.)</p>
<p>So what happens when the implementation is in nascent stage, and the enforcers  are not completely eductaed?<br />
Things get blown out of proportion. Things get painted in a completely new color. Things get&#8230; uh! fill them up yourself.</p>
<div>
<h3><span style="color: #3366ff;"><strong>4. <a href="http://www.indiacyberlab.in/cyberlaws/chapter11.htm">Chapter 11, IT Act 2000</a></strong></span></h3>
</div>
<p>Chapter 11 of the Act defines the <strong>Offences</strong> &#8211; section 65 to section 78.   For now, let&#8217;s have a look at Sections 65, and 67.<br />
<strong> Section 65: Tampering with computer source documents.</strong></p>
<blockquote><p><em> Whoever knowingly or intentionally conceals, destroys or    alters or intentionally or knowingly causes another to conceal, destroy or    alter any computer source code used for a computer, computer programme,    computer system or computer network, when the computer source code is required    to be kept or maintained by law for the time being in force, shall be    punishable with imprisonment up to three years, or with fine which may extend    up to two lakh rupees, or with both.</em><br />
<em> Explanation: For the purposes of this section, &#8220;computer  source code&#8221; means the listing of programmes, computer commands, <strong>design and  layout and programme analysis of computer resource in any form</strong>.</em></p></blockquote>
<p><strong>Section 67:Publishing of information which is obscene in electronic form.</strong></p>
<blockquote><p><em>Whoever publishes or transmits <strong>or causes to be published in the electronic form</strong>, any material which is lascivious or appeals to the prurient interest or if its effect is such as to tend to deprave and corrupt persons who are likely, having regard to all relevant circumstances, to read, see or hear the matter contained or embodied in it, shall be punished on first conviction with imprisonment of either description for a term which may extend to five years and with fine which may extend to one lakh rupees and in the event of a second or subsequent conviction with imprisonment of either description for a term which may extend to ten years and also with fine which may extend to two lakh rupees.</em></p></blockquote>
<p>I have mostly been interested in section 67 (which according to some in the law indsutry) also extends to sms service <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Anyhoo. If you are interested in punishmentsm, <a href="http://www.indiacyberlab.in/cyberlaws/computer-offenses-punishment.htm" target="_blank">here&#8217;s the link</a>.  Have a look. You might be serving one someday <img src='http://projectbee.org/blog/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div>
<h3><span style="color: #3366ff;"><strong>5. Case Study</strong></span></h3>
</div>
<p>There have been quite a few cases revolving around Orkut, but the one that I&#8217;ll be talking about (and is the most relevant) is the one where <a href="http://timesofindia.indiatimes.com/articleshow/2513737.cms">wrong man (<span style="font-size: 14px; font-weight: normal; line-height: 18px; font-family: Arial,Helvetica,sans-serif; color: #000000;"><span style="font-size:8pt;"> named Lakshmana Kailash K) </span></span>was put behind bars for 50 freakin&#8217; days</a>.  He&#8217;s &#8220;reportedly&#8221;  involved in the defamation of Chhatrapati Shivaji, a highly revered historical figure.<br />
In case you aren&#8217;t aware, Orkut (Google) has <a href="http://economictimes.indiatimes.com/Orkuts_tell-all_pact_with_cops_/RssArticleShow/articleshow/1982584.cms" target="_blank">signed a pact with Indian Law Enforcement.</a> They pledge to &#8220;<em>block any &#8216;defamatory or inflammatory content&#8217;, or hand over IP address information to police if asked&#8221;</em>.</p>
<p>So what happened in the above case?<br />
Law enforcers are reported about the defamation of Shivaji, they contact Orkut, Orkut gives IP, law enforcers run to the ISP (Airtel in this case), Airtel provides address, Guy put in jail.<br />
Simple. Isn&#8217;t it?</p>
<p>The only trouble being that Airtel provided the wrong address.<br />
Whoops! And bang! The dude spends 50 days straight, for something he didn&#8217;t do.<br />
Neha Viswanathan, a blogger based in UK, <a href="http://www.withinandwithout.com/?p=1176" target="_blank">has a very nice write-up</a> on the incident. Further, there&#8217;s a very <a href="http://www.indiacyberlab.in/know_more/copawards2005-legal.htm" target="_blank">nice compilation of some Cyber Crime cases in India at the IndiaCyberLab portal</a>.</p>
<div>
<h3><span style="color: #3366ff;"><strong>6. Putting the pieces of puzzle together</strong></span></h3>
</div>
<p>Let&#8217;s first collect all the pieces together:<br />
1.  Orkut has a pact with Indian law Enforcement.<br />
2. Law enforcers are incompetent *cough*.<br />
3. Orkut (or any other similar site) still has XSS and CSRF flaws in them. Period.<br />
4. XSS and CSRF let you (among other thousand things) manipulate source code (section 65) and/or insert obscene/derogatory (section 67).<br />
5. XSS and CSRF <strong>let you post/manipulate data on some other person&#8217;s behalf</strong>. (Orkut/Samy etc. worms did not  require you to click anywhere. Just load the page and the payload in inserted in your friend&#8217;s scrapbook <strong>on your behalf</strong>).</p>
<p>Now combine them all, and you&#8217;ll realize that there might be a day when you just sent a &#8220;long time no scraps&#8221; scrap in your friends scrapbook and went to bed. The next day, a bunch of Cyber officers wake you up, and arrest you for defaming Bala Saheb Thakrey.</p>
<p>&#8230;and yes! Don&#8217;t talk about Democracy. You&#8217;ve already seen that the politicians can get away with a wrestling in parliament arena that will put WWE stars to shame. On the contrary, a chap is detained for 50 days just because the cops thought that they had enough evidence.</p>
<h3><span style="color: #3366ff;">7. Conclusion</span></h3>
<p>What!<br />
Stay away from social networking sites. Trust me, they are not worth the price.</p>
Similar Posts:<ul><li><a href="http://projectbee.org/blog/archive/iframes-to-be-or-not-to-be/" rel="bookmark" title="September 10, 2007">IFrames &#8211; To be or not to be?</a></li>

<li><a href="http://projectbee.org/blog/archive/adsense-exploited-by-malware-trojanqhostwu/" rel="bookmark" title="December 22, 2007">AdSense exploited by malware (Trojan.Qhost.WU)</a></li>

<li><a href="http://projectbee.org/blog/archive/samy-a-hero-or-a-villian/" rel="bookmark" title="February 5, 2007">Samy: A hero or a villian!</a></li>

<li><a href="http://projectbee.org/blog/archive/yahoo-gone-insane/" rel="bookmark" title="August 11, 2007">Yahoo! gone Insane!</a></li>

<li><a href="http://projectbee.org/blog/archive/vista-3-exclamations-is-here-why/" rel="bookmark" title="February 19, 2007">Vista!!! (3 Exclamations.) is here? (Why :-/)</a></li>
</ul><!-- Similar Posts took 8.654 ms -->]]></content:encoded>
			<wfw:commentRss>http://projectbee.org/blog/archive/orkut-latest-xss-worm-and-what-it-means-for-indian-orkuteers/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
