<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>onHacks &#187; Paper</title>
	<atom:link href="http://onhacks.org/lang/en/tag/paper/feed/" rel="self" type="application/rss+xml" />
	<link>http://onhacks.org</link>
	<description>On Hacking Across Boundaries</description>
	<lastBuildDate>Wed, 02 Jun 2010 05:48:30 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>OWASP Testing Guide V3 Chinese Version</title>
		<link>http://onhacks.org/lang/en/2010/01/27/owasp-testing-guide-v3-chinese</link>
		<comments>http://onhacks.org/lang/en/2010/01/27/owasp-testing-guide-v3-chinese#comments</comments>
		<pubDate>Tue, 26 Jan 2010 16:17:31 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Testing]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=786</guid>
		<description><![CDATA[OWASP Testing Guide V3 Chinese Version is finally published! You can download in the OWASP China-Mainland chapter page. If you are interested in web application security, it is highly encouraged to check it out. There will be things learnt. OWASP China Research Group To better facilitate the activities of OWASP in China for consistent and [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en"><a href="http://www.owasp.org/images/0/06/OWASP%E6%B5%8B%E8%AF%95%E6%8C%87%E5%8D%97%28%E4%B8%AD%E6%96%87%EF%BC%89.pdf" target="_blank">OWASP Testing Guide V3 Chinese Version</a></span><span lang="en"> is finally published! You can <a href="http://www.owasp.org/images/0/06/OWASP%E6%B5%8B%E8%AF%95%E6%8C%87%E5%8D%97%28%E4%B8%AD%E6%96%87%EF%BC%89.pdf" target="_blank">download</a> in the <a href="http://www.owasp.org/index.php/China-Mainland" target="_blank">OWASP China-Mainland chapter</a> page. If you are interested in web application security, it is highly encouraged to check it out. There will be things learnt.</span></p>
<blockquote><p><span lang="en">OWASP China Research Group</span></p>
<p><span lang="en">To better facilitate the activities of OWASP in China for consistent and perpetual continuity, OWASP China has formed regional groups mainly tasked to support the regional sharing and discussion. We welcome you to recommend an individual to take the lead. OWASP China Research Group currently aims to build upon and go into the depths of the foundation laid out by the OWASP Foundation, plus translation of the OWASP resources ectera. There will be activities such as training in different regions. OWASP China QQ Discussion Group 78238096<br />
</span></p>
<p><span lang="en"><em>(My translation above)</em><br />
</span></p></blockquote>
<p><span lang="en">I hope to improve China&#8217;s internet security. I succeeded Frank and Rip on the last iteration of this project, and that is why my December has been busy all along, and took much of my time.</span></p>
<p><span lang="en">Thanks a lot to the people below, and especially the many Microsoft people who worked so hard even during Christmas to produce this testing guide. Sorted from last name (Mandarin) :</span></p>
<ul>
<li><span lang="en">Aaron (DBAPPSECURITY)</span></li>
<li><span lang="en">Joanne Cheng (Microsoft)</span></li>
<li><span lang="en">Frank Fan (DBAPPSECURITY)</span></li>
<li><span lang="en">Karin He (Microsoft)</span></li>
<li><span lang="en">Adams Li (Microsoft)</span></li>
<li><span lang="en">RIP (OWASP China Chair)</span></li>
<li><span lang="en">Will Shen (Microsoft)</span></li>
<li><span lang="en">Chao Wang (Microsoft)</span></li>
<li><span lang="en">Wei Wei (Microsoft)</span></li>
<li><span lang="en">Pak Ming Cheung (Microsoft)</span></li>
<li><span lang="en">Eric Chio (Microsoft)</span></li>
</ul>
<p><span lang="en">Hope that readers of the guide will benefit much from it!</span></p>












]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2010/01/27/owasp-testing-guide-v3-chinese/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Avert Labs Research Paper &#8211; Inside the Password-Stealing Business: the Who and How of Identity Theft</title>
		<link>http://onhacks.org/lang/en/2009/09/25/avert-labs-research-paper-inside-the-password-stealing-business-the-who-and-how-of-identity-theft</link>
		<comments>http://onhacks.org/lang/en/2009/09/25/avert-labs-research-paper-inside-the-password-stealing-business-the-who-and-how-of-identity-theft#comments</comments>
		<pubDate>Fri, 25 Sep 2009 15:41:04 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=680</guid>
		<description><![CDATA[Avert Labs got a new research paper out : “Inside the Password-Stealing Business: the Who and How of Identity Theft.” . For those interested in the underground economics, you should take a look! Multi-lingual report link doesn&#8217;t seem to work : http://www.avertlabs.com/research/blog/index.php/2009/09/24/inside-the-password-stealing-business/ . Games have always been a big business, just that it&#8217;s the same [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en">Avert Labs got a new research paper out : <a href="http://www.mcafee.com/us/local_content/reports/6622rpt_password_stealers_0709_en.pdf">“Inside the Password-Stealing Business: the Who and How of Identity Theft.”</a> . For those interested in the underground economics, you should take a look! Multi-lingual report link doesn&#8217;t seem to work : http://www.avertlabs.com/research/blog/index.php/2009/09/24/inside-the-password-stealing-business/ .<br />
</span></p>
<p><span lang="en">Games have always been a big business, just that it&#8217;s the same for the underground, too. A lot of money, even if you&#8217;re the good guys. On the other hand, you haven&#8217;t heard people pirating &#8220;Microsoft High Performance Computing Cluster&#8221; CDs, right? =) Oh, and hey, they sell OK, and in China. There&#8217;s really money there. Yada yada&#8230;</span></p>
<p><span lang="en">Another thing though, as if getting infected is not enough, malware (Zbot here) could put you into legally trouble. It is no news that victims are being used as stepping stone for futher crime, and you really need proof that you are not. Zbot goes further by rendering your computertotally unusable by wiping out the registry HKEY root keys. This is enough to force a user to immediately formatting, thus killing all chances for forensics. Behind bars anyone?</span></p>






<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">http://www.mcafee.com/us/local_content/reports/6622rpt_password_stealers_0709_en.pdf</div>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/09/25/avert-labs-research-paper-inside-the-password-stealing-business-the-who-and-how-of-identity-theft/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
