<?xml version="1.0"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/">

  <channel rdf:about="http://www.csnc.ch/blog/">
    <title>Ivan Buetler</title>
    <link>http://www.csnc.ch/blog/</link>
    <description>Ivan Buetler - Blog</description>
    <items>
      <rdf:Seq>
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/07/02/1278073320000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/06/25/1277470080000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/06/13/1276449660000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/06/09/1276061880000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/05/26/1274850540000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/05/23/1274619300000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/05/17/1274118360000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/05/07/1273222140000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/05/04/1272970200000.html" />
        
        <rdf:li resource="http://www.csnc.ch/blog/2010/04/29/1272543060000.html" />
        
      </rdf:Seq>
    </items>
  </channel>

  
  <item rdf:about="http://www.csnc.ch/blog/2010/07/02/1278073320000.html">
    <title>OWASP Guide Online</title>
    <link>http://www.csnc.ch/blog/2010/07/02/1278073320000.html</link>
    
      
        <description>
          &lt;br /&gt;
Ever wanted to know how to defeat web hacking attacks - what to do with the identified OWASP TOP 10 vulnerabilities? I really much appreciate the OWASP TOP 10 papers, but when it comes to mitigation and remediation, everything is deeply hidden somewhere. &lt;br /&gt;
&lt;br /&gt;
That&#039;s why I like the following OWASP page - clear and simple to use&lt;br /&gt;
&lt;a href=&#034;http://code.google.com/p/owasp-development-guide/wiki/Guide&#034;&gt;http://code.google.com/p/owasp-development-guide/wiki/Guide&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
Ivan
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/06/25/1277470080000.html">
    <title>Singapore and Asia</title>
    <link>http://www.csnc.ch/blog/2010/06/25/1277470080000.html</link>
    
      
        <description>
          &lt;br /&gt;
I am impressed! I was having a very good time here in Singapore. The course &amp;quot;mobile payment systems&amp;quot; is history. I very much appreciate the participants and their patience with me. Accidentally I was in front of the brand new convention centre at the opening ceremony. See the pics if interested. &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://www.but.ch/root/singapore/index.html&#034;&gt;http://www.but.ch/root/singapore/index.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Hey - I am shortly before take off home. See you in Switzerland&lt;br /&gt;
&lt;br /&gt;
Regards&lt;br /&gt;
&lt;br /&gt;
Ivan&lt;br /&gt;
&lt;br /&gt;
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/06/13/1276449660000.html">
    <title>Mobile Payment Systems - Workshop in Singapore</title>
    <link>http://www.csnc.ch/blog/2010/06/13/1276449660000.html</link>
    
      
        <description>
          &lt;br /&gt;
Dear Blog Reader,&lt;br /&gt;
I will be in Singapore in June 24th and 25th, 2010! The Singapore company &amp;quot;&lt;a href=&#034;http://www.unistrategic.com/index.php/component/option,com_eventlist/Itemid,4/did,466/func,details/&#034;&gt;Unistrategic&lt;/a&gt;&amp;quot; invited me to be their course facilitator - to introduce risks and phone hacking attacks that could be a threat for the mobile payment systems market. &lt;br /&gt;
&lt;br /&gt;
&lt;p class=&#034;MsoBodyText3&#034;&gt; &lt;strong&gt;&lt;span style=&#034;font-size: 10pt; font-family: verdana,geneva;&#034;&gt;MOBILE  PAYMENT SYSTEMS &amp;ndash; ETHICAL HACKING AND PENETRATION TESTING WILL GIVE YOU  VALUABLE INSIGHTS ON HOW YOU AS A PROFESSIONAL CAN:&lt;/span&gt;&lt;/strong&gt; &lt;/p&gt;
&lt;p class=&#034;MsoBodyText3&#034;&gt; &amp;nbsp; &lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;span style=&#034;font-size: 10pt; font-family: verdana,geneva;&#034;&gt;LEARN  about the risk landscape of mobile payment systems&lt;/span&gt;&lt;/li&gt;
    &lt;li&gt;&lt;span style=&#034;font-size: 10pt;&#034;&gt;&lt;span style=&#034;font-family: verdana,geneva;&#034;&gt;&lt;/span&gt;PARTICIPATE in a state-of-the-art Live-Hacking  demonstrations&lt;/span&gt;&lt;/li&gt;
    &lt;li&gt;&lt;span style=&#034;font-size: 10pt;&#034;&gt;&lt;span style=&#034;font-family: verdana,geneva;&#034;&gt;&lt;/span&gt;EXPERIENCE current hacking and defence  strategies&lt;/span&gt;&lt;/li&gt;
    &lt;li&gt;&lt;span style=&#034;font-size: 10pt;&#034;&gt;&lt;span style=&#034;font-family: verdana,geneva;&#034;&gt;&lt;/span&gt;GAIN insights into the latest hacking methods  and attacks&lt;/span&gt;&lt;/li&gt;
    &lt;li&gt;&lt;span style=&#034;font-size: 10pt;&#034;&gt;&lt;span style=&#034;font-family: verdana,geneva;&#034;&gt;&lt;/span&gt;EXPLORE new forensic analysis methods&lt;/span&gt;&lt;/li&gt;
    &lt;li&gt;&lt;span style=&#034;font-size: 10pt;&#034;&gt;&lt;span style=&#034;font-family: verdana,geneva;&#034;&gt;&lt;/span&gt;EVALUATE security vulnerabilities and handle  incidents&lt;/span&gt;&lt;/li&gt;
&lt;/ul&gt;
I am looking forward to performing the workshop in Singapore. &lt;br /&gt;
&lt;br /&gt;
Have a safe week&lt;br /&gt;
Ivan&lt;br /&gt;
&lt;br /&gt;
Reference: &lt;br /&gt;
&lt;a href=&#034;http://www.unistrategic.com/index.php/component/option,com_eventlist/Itemid,4/did,466/func,details/&#034;&gt;http://www.unistrategic.com/index.php/component/option,com_eventlist/Itemid,4/did,466/func,details/&lt;/a&gt;&lt;br /&gt;
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/06/09/1276061880000.html">
    <title>Apple WebKit Advisories</title>
    <link>http://www.csnc.ch/blog/2010/06/09/1276061880000.html</link>
    
      
        <description>
          &lt;br /&gt;
Dear blog readers,&lt;br /&gt;
&lt;br /&gt;
Yesterday, I was updating my MacBook Pro and later in the afternoon, a bunch of ZDI bugtraq messages appeared. Did you notice the relationsship between the Advisories and the security update? &lt;br /&gt;
&lt;br /&gt;
If not, read my single page paper about the update&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://www.hacking-lab.com/misc/downloads/apple_advisories_june_2010.pdf&#034;&gt;http://www.hacking-lab.com/misc/downloads/apple_advisories_june_2010.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
We can learn from the past, market leading software is always more analyzed by the hacker community than fameless software. The Apple community feels save with their product and OS, but this changes slowely. &lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
Ivan
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/05/26/1274850540000.html">
    <title>Mobile Payment Systems - M-Pesa (Kenya)</title>
    <link>http://www.csnc.ch/blog/2010/05/26/1274850540000.html</link>
    
      
        <description>
          &lt;br /&gt;
In March 2007, Kenya&amp;rsquo;s largest mobile network operator, Safaricom (part of the Vodafone Group) launched M-PESA payment service for the unbanked. With approximately 26 million people in South Africa without official bank accounts, M-PESA enables millions of mobile phone subscribers who have access to a mobile phone, but do not have or have only limited access to a bank account, to send and receive money via their mobile phones. &amp;ldquo;Pesa&amp;rdquo; is the Swahili word for cash; the &amp;ldquo;M&amp;rdquo; is for mobile. M-PESA customer can use his or her mobile phone to move money quickly, securely, and across great distances, directly to another mobile phone user. European financial institutes did not follow the micropayment wave, because most of the European customers have valid bank relationsships, access to credit cards or PayPal. But the Safaricom solution fills the gap for unbanked customers! Africaan people that work in Europe have the need to send money back home. &lt;br /&gt;
&lt;br /&gt;
Technically, the SIM card of Safaricom has it&#039;s own SIM application installed, that is required for the payment process. Financial transactions required the customer to enter the PIN when the transaction is authorized. &lt;br /&gt;
&lt;br /&gt;
I will talk about Mobile Payment Systems, security implications and fraud scenarios in Singapore soon (June 2010). From my previous research with the SmartCard APDU man-in-the-middle attack, the iPhone hacking and SS7 attack scenarios, I will disclose more about security threats of Mobile Payment Systems. &lt;br /&gt;
&lt;br /&gt;
Have a safe day&lt;br /&gt;
&lt;br /&gt;
Ivan&lt;br /&gt;
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/05/23/1274619300000.html">
    <title>Schweizer Bundesrat startet Konsultation zum Überwachungsgesetz</title>
    <link>http://www.csnc.ch/blog/2010/05/23/1274619300000.html</link>
    
      
        <description>
          &lt;div class=&#034;paragraphBlock&#034;&gt; Es gibt in der Schweiz einen neuen Gesetzesentwurf &amp;quot;Totalrevision des Bundesgesetzes betreffend die &amp;Uuml;berwachung des Post- und Fernmeldeverkehrs&amp;quot;. Darin soll neu geregelt werden, wie man in Zukunft &amp;uuml;berwachen kann und darf.&lt;br /&gt;
&lt;br /&gt;
Mutmassliche Straft&amp;auml;ter sollen sich nicht durch die Verwendung neuer Kommunikationstechnologien der &amp;Uuml;berwachung durch die Strafverfolgungsbeh&amp;ouml;rden entziehen k&amp;ouml;nnen. Das Bundesgesetz betreffend die &amp;Uuml;berwachung des Post- und Fernmeldeverkehrs wird deshalb an die technische Entwicklung angepasst. Die Totalrevision zielt nicht darauf &lt;em&gt;mehr&lt;/em&gt;, sondern &lt;em&gt;besser &lt;br /&gt;
&lt;/em&gt;&lt;/div&gt;
&lt;!-- ti comp --&gt;
&lt;div class=&#034;paragraphTitle&#034;&gt;&amp;uuml;berwachen zu k&amp;ouml;nnen. &lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;
    &lt;li&gt;Am 19. Mai 2010 schickt der Bundesrat die Totalrevision des Bundesgesetzes betreffend die &amp;Uuml;berwachung des Post- und Fernmeldeverkehrs in die Vernehmlassung&amp;nbsp; (&lt;a id=&#034;/content/bj/de/home/dokumentation/medieninformationen/2010/ref_2010-05-19&#034; class=&#034;ContentPartextimageText&#034; href=&#034;http://www.ejpd.admin.ch/ejpd/de/home/dokumentation/mi/2010/2010-05-19.html&#034;&gt;&lt;img height=&#034;10&#034; border=&#034;0&#034; width=&#034;12&#034; alt=&#034;&#034; src=&#034;http://www.ejpd.admin.ch/img/body/tp.gif&#034; class=&#034;ico_intern&#034; /&gt;&lt;font style=&#034;text-decoration: none;&#034;&gt;&amp;nbsp;&lt;/font&gt;Medienmitteilung&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;a href=&#034;jhttp://www.heise.de/newsticker/meldung/Schweizer-Bundesrat-startet-Konsultation-zum-Ueberwachungsgesetz-1005163.html&#034;&gt;http://www.heise.de/newsticker/meldung/Schweizer-Bundesrat-startet-Konsultation-zum-Ueberwachungsgesetz-1005163.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Ivan&lt;br /&gt;
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/05/17/1274118360000.html">
    <title>CLX.CustomerDay</title>
    <link>http://www.csnc.ch/blog/2010/05/17/1274118360000.html</link>
    
      
        <description>
          &lt;br /&gt;
Dear Blog reader,&lt;br /&gt;
&lt;br /&gt;
The CREALOGIX Group is a leading independent software service provider with focus on comprehensive e-business and ERP solutions in Switzerland, Germany and Austria.&lt;br /&gt;
The shares of CREALOGIX Holding AG (CLXN) are traded on the SIX Swiss Exchange.&lt;br /&gt;
&lt;br /&gt;
Next Thursday May 20th, 2010, CLX organizes their annual CLX.CustomerDay! I am invited as a keynote speaker after 5.p.m and I will talk about my recent research results,&amp;nbsp; the combination of web-hacking and illegal trading markets - iPhone attacks and more...&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://www.crealogix.com/crealogix-gruppe/messen-und-events/events-detail.html?tx_cal_controller[getdate]=20100520&amp;amp;tx_cal_controller[lastview]=list-1628&amp;amp;tx_cal_controller[view]=event&amp;amp;tx_cal_controller[type]=tx_cal_phpicalendar&amp;amp;tx_cal_controller[uid]=55&amp;amp;cHash=5d79a488f8&#034;&gt;CLX.CustomerDay&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Hope to see you there. &lt;br /&gt;
&lt;br /&gt;
Regards&lt;br /&gt;
Ivan&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/05/07/1273222140000.html">
    <title>Jailbreaking iPad touch and more </title>
    <link>http://www.csnc.ch/blog/2010/05/07/1273222140000.html</link>
    
      
        <description>
          &lt;br /&gt;
Jailbraking iPhone and iPhad is in the next round. Using Spirit, one can jailbreak (not unlock) all iPhone&amp;rsquo;s (iPhone (Edge), iPhone 3G and iPhone 3GS) and &lt;strong&gt;iPod&lt;/strong&gt; touches (iPod touch 2G and 3G) running on the firmware version 3.1.3/3.1.2, and iPad and iPad 3G on firmware 3.2 &amp;ndash; untethered.&lt;br /&gt;
&lt;br /&gt;
Reference: &lt;a href=&#034;http://www.redmondpie.com/jailbreak-iphone-3gs-3.1.3-untethered-with-spirit-9140719/&#034;&gt;http://www.redmondpie.com/jailbreak-iphone-3gs-3.1.3-untethered-with-spirit-9140719/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
For the end user, Spirit looks and works very much like Geohot&amp;rsquo;s blackra1n, and is available for both Windows and Mac OS X.&lt;br /&gt;
Have a save iPad &amp;amp; iPhone day&lt;br /&gt;
&lt;br /&gt;
Ivan
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/05/04/1272970200000.html">
    <title>DNS Sinkholing - Malware Investigation</title>
    <link>http://www.csnc.ch/blog/2010/05/04/1272970200000.html</link>
    
      
        <description>
          Ever heard about &lt;strong&gt;DNS Sinkholing&lt;/strong&gt; - Through registering expired domain names previously used in cyber espionage attacks as command and control servers, malware hunters were able to observe incoming connections from still-compromised computers. This allowed them to collect information on the methods of the attackers as well as the nature of the victims.&lt;br /&gt;
&lt;br /&gt;
I think this is a smart technique ... dns sinkholing&lt;br /&gt;
&lt;br /&gt;
Ivan&lt;br /&gt;
&lt;br /&gt;
Reference: Shadows in the Cloud Report
        </description>
      
      
    
  </item>
  
  <item rdf:about="http://www.csnc.ch/blog/2010/04/29/1272543060000.html">
    <title>APT - new buzzword - Advanced Persistent Threat</title>
    <link>http://www.csnc.ch/blog/2010/04/29/1272543060000.html</link>
    
      
        <description>
          &lt;br /&gt;
Dear blog reader,&lt;br /&gt;
&lt;br /&gt;
Ever read about APT? -&amp;gt;&lt;strong&gt; Advanced Persistent Threat&lt;/strong&gt; !!! APT  stands for human being or organization, who operates a campaign of  intellectual property theft using cyber mehods. &lt;br /&gt;
&lt;br /&gt;
&lt;img src=&#034;http://www.csnc.ch/blog/images/apt.jpg&#034; alt=&#034;&#034; /&gt;&lt;br /&gt;
&lt;br /&gt;
This is the topic I will investigate. I am currently writing a short  report where I want to be the Advocatus Diaboli - try to write from a  cyber terrorists point of view. It has the title: &amp;quot;How to own the  World&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
Today.... we have our ISSS evening in St.Gallen. Looking forward to  seeing some of you soon. &lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
Ivan
        </description>
      
      
    
  </item>
  

</rdf:RDF>
