<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[blog.rayfoo] &#187; TODO</title>
	<atom:link href="http://blog.rayfoo.info/tag/todo/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rayfoo.info</link>
	<description>Infosec, DFIR, tech geekery, thoughts and whatnot</description>
	<lastBuildDate>Wed, 25 Jan 2012 00:36:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Visualizing Data (using Processing)</title>
		<link>http://blog.rayfoo.info/2010/11/visualizing-data-using-processing</link>
		<comments>http://blog.rayfoo.info/2010/11/visualizing-data-using-processing#comments</comments>
		<pubDate>Sun, 07 Nov 2010 14:05:42 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[Ben Fry]]></category>
		<category><![CDATA[books]]></category>
		<category><![CDATA[data mining]]></category>
		<category><![CDATA[data visualization]]></category>
		<category><![CDATA[O'Reilly]]></category>
		<category><![CDATA[Processing]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[Raffael Marty]]></category>
		<category><![CDATA[TODO]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=756</guid>
		<description><![CDATA[Visualizing Data, by Ben Fry (O'Reilly) [Amazon] [Google Books] [O'Reilly] [Google Search] One of my interests has always been in data visualization (makes data more understandable, and is one step towards easier interaction with it). Chanced upon this book at the library today, certainly one thing I'd like to look into in more detail at [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.google.com/search?q=%22visualizing+data%22+%22ben+fry%22"><img class="alignright size-full wp-image-757" title="visualizing-data-ben-fry" src="http://blog.rayfoo.info/wp-content/uploads/2010/11/visualizing-data-ben-fry.gif" alt="" width="180" height="236" /></a>Visualizing Data, by Ben Fry (O'Reilly)<br />
[<a href="http://www.amazon.com/Visualizing-Data-Explaining-Processing-Environment/dp/0596514557">Amazon</a>] [<a href="http://books.google.com.sg/books?id=6jsVAiULQBgC&amp;printsec=frontcover&amp;dq=%22visualizing+data%22+%22ben+fry%22&amp;source=bl&amp;ots=2wv_X7hfMW&amp;sig=ejxLWK1fnLIFIMVT6ji4v0EZdFY&amp;hl=en&amp;ei=86nWTOTBC4K0lQez2ZCVCQ&amp;sa=X&amp;oi=book_result&amp;ct=result&amp;resnum=4&amp;ved=0CC0Q6AEwAw">Google Books</a>] [<a href="http://oreilly.com/catalog/9780596514556">O'Reilly</a>] [<a href="http://www.google.com/search?q=%22visualizing+data%22+%22ben+fry%22">Google Search</a>]</p>
<p>One of my interests has always been in data visualization (makes data more understandable, and is one step towards easier interaction with it).  Chanced upon this book at the library today, certainly one thing I'd like to look into in more detail at a later point in time.</p>
<p>Why this book caught my interest was the fact that there was another book on such a topic in itself.  Other than <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100">Applied Security Visualization</a> by <a href="http://raffy.ch/blog/">Raffael Marty</a>, I've yet to chance upon anything else.</p>
<p>A quick browse of the book showed that it's very possible to use <a href="http://processing.org/">Processing</a> (yet another good reason to take up this book: simple programming!) to implement many of the data visualization concepts.  Though many people would say that this is "raw" and "slow" as compared to having a tool to do this simply and quickly, I'd say that doing it this way would certainly give the user a great understanding of the data visualization process itself.  Furthermore, who's to say that Processing's not the tool itself! <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />   Also, the author has helpfully made the <a href="http://benfry.com/writing/archives/3">source code examples</a> available online at his blog too.</p>
<p>Will keep this book in mind to look at later.  Have other books to go through first... :}</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2010/11/visualizing-data-using-processing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interesting scanner</title>
		<link>http://blog.rayfoo.info/2010/07/interesting-scanner</link>
		<comments>http://blog.rayfoo.info/2010/07/interesting-scanner#comments</comments>
		<pubDate>Sat, 17 Jul 2010 16:26:26 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[information gathering]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[scanners]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[TODO]]></category>
		<category><![CDATA[web application]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=652</guid>
		<description><![CDATA[I know I'm probably the only one in this island that thinks this as interesting, but nevertheless... It's normal for the web server to get scanned by other "inquisitive" people/machines/bots, but this tool looks pretty interesting...  Will dig deeper into this later. The scanners typically try to detect whether I'm running certain vulnerable versions of [...]]]></description>
			<content:encoded><![CDATA[<p>I know I'm probably the only one in this island that thinks this as interesting, but nevertheless...</p>
<p>It's normal for the web server to get scanned by other "inquisitive" people/machines/bots, but this tool looks pretty interesting...  Will dig deeper into this later.</p>
<p>The scanners typically try to detect whether I'm running certain vulnerable versions of web apps for them to exploit.  So when the web app does not exist, guess what happens? <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>This particular scan was interesting, because of the <span style="color: #ff0000;">user agent</span> field.  Check it out:</p>
<p>200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /roundcubemail-0.1//bin/msgimport HTTP/1.1" 404 136 "-" "<span style="color: #ff0000;">Toata dragostea mea pentru diavola</span>"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /wm//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /webmail//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:06 +0800] "GET /webmail2//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /rms//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /roundcubemail//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /mail2//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:05 +0800] "GET /mail//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:04 +0800] "GET /mss2//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"<br />
200.6.121.56 - - [17/Jul/2010:14:51:04 +0800] "GET /rc//bin/msgimport HTTP/1.1" 404 136 "-" "Toata dragostea mea pentru diavola"</p>
<p>If anyone knows more about this particular scanner, feel free to comment and share!</p>
<p>Edit (19 Jul): it seems that I've joined <a href="http://www.google.com/search?q=Toata+dragostea+mea+pentru+diavola">the ranks</a> of those who've been scanned one way or another.  Apparently <a href="http://translate.google.com/#auto|en|Toata%20dragostea%20mea%20pentru%20diavola">it is in Romanian</a>, meaning "All my love for the devil".</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2010/07/interesting-scanner/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More automation needed</title>
		<link>http://blog.rayfoo.info/2010/07/more-automation-needed</link>
		<comments>http://blog.rayfoo.info/2010/07/more-automation-needed#comments</comments>
		<pubDate>Wed, 14 Jul 2010 15:25:04 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server administration]]></category>
		<category><![CDATA[TODO]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=641</guid>
		<description><![CDATA[Although I've managed to configure the server such that there's a fair amount of automation for appropriate tasks (phone homes, automated monitoring and basic defenses), the time needed daily to monitor/maintain it still adds up...and is unreasonable collectively. Looks like I'll have to look into further automating some of the tasks...]]></description>
			<content:encoded><![CDATA[<p>Although I've managed to configure the server such that there's a fair amount of automation for appropriate tasks (phone homes, automated monitoring and basic defenses), the time needed daily to monitor/maintain it still adds up...and is unreasonable collectively.</p>
<p>Looks like I'll have to look into further automating some of the tasks...</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2010/07/more-automation-needed/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

