ev

Sri Lanka Rupee(LKR)/Bulgarian Lev(BGN)

1 Sri Lanka Rupee = 0.0097 Bulgarian Lev



  • Sri Lanka Rupee

ev

Algerian Dinar(DZD)/Peruvian Nuevo Sol(PEN)

1 Algerian Dinar = 0.0265 Peruvian Nuevo Sol




ev

Algerian Dinar(DZD)/Bulgarian Lev(BGN)

1 Algerian Dinar = 0.0141 Bulgarian Lev




ev

Indonesian Rupiah(IDR)/Peruvian Nuevo Sol(PEN)

1 Indonesian Rupiah = 0.0002 Peruvian Nuevo Sol




ev

Indonesian Rupiah(IDR)/Bulgarian Lev(BGN)

1 Indonesian Rupiah = 0.0001 Bulgarian Lev




ev

Lithuanian Lita(LTL)/Peruvian Nuevo Sol(PEN)

1 Lithuanian Lita = 1.1511 Peruvian Nuevo Sol




ev

Lithuanian Lita(LTL)/Bulgarian Lev(BGN)

1 Lithuanian Lita = 0.6115 Bulgarian Lev




ev

Nigerian Naira(NGN)/Peruvian Nuevo Sol(PEN)

1 Nigerian Naira = 0.0087 Peruvian Nuevo Sol




ev

Nigerian Naira(NGN)/Bulgarian Lev(BGN)

1 Nigerian Naira = 0.0046 Bulgarian Lev




ev

Czech Republic Koruna(CZK)/Peruvian Nuevo Sol(PEN)

1 Czech Republic Koruna = 0.1352 Peruvian Nuevo Sol



  • Czech Republic Koruna

ev

Czech Republic Koruna(CZK)/Bulgarian Lev(BGN)

1 Czech Republic Koruna = 0.0718 Bulgarian Lev



  • Czech Republic Koruna

ev

Bolivian Boliviano(BOB)/Peruvian Nuevo Sol(PEN)

1 Bolivian Boliviano = 0.4929 Peruvian Nuevo Sol




ev

Bolivian Boliviano(BOB)/Bulgarian Lev(BGN)

1 Bolivian Boliviano = 0.2618 Bulgarian Lev




ev

Japanese Yen(JPY)/Peruvian Nuevo Sol(PEN)

1 Japanese Yen = 0.0319 Peruvian Nuevo Sol




ev

Japanese Yen(JPY)/Bulgarian Lev(BGN)

1 Japanese Yen = 0.0169 Bulgarian Lev







ev

Survey Reveals Culture Of IT Admin Snooping




ev

Opera Update Draws The Curtain On Seven Security Vulns




ev

Opera Bitten By Extremely Severe Browser Bug




ev

Opera Releases Update For Extremely Severe Vulns




ev

Opera Plugs Severe Browser Hole




ev

Opera 9.64 Update Fixes Several Security Issues




ev

Book Review: 'The Tangled Web' By Michal Zalewski

No Starch Press: $49.95

If you are a security engineer, a researcher, a hacker or just someone who keeps your ear to the ground when it comes to computer security, chances are you have seen the name Michal Zalewski. He has been responsible for an abundance of tools, research, proof of concepts and helpful insight to many over the years. He recently released a book called "The Tangled Web - A Guide To Securing Modern Web Applications".

Normally, when I read books about securing web applications, I find many parallels where authors will give an initial lay of the land, dictating what technologies they will address, what programming languages they will encompass and a decent amount of detail on vulnerabilities that exist along with some remediation tactics. Such books are invaluable for people in this line of work, but there is a bigger picture that needs to be addressed and it includes quite a bit of secret knowledge rarely divulged in the security community. You hear it in passing conversation over beers with colleagues or discover it through random tests on your own. But rarely are the oddities documented anywhere in a thorough manner.

Before we go any further, let us take a step back in time. Well over a decade ago, the web was still in its infancy and an amusing vulnerability known as the phf exploit surfaced. It was nothing more than a simple input validation bug that resulted in arbitrary code execution. The average hacker enjoyed this (and many more bugs like it) during this golden age. At the time, developers of web applications had a hard enough time getting their code to work and rarely took security implications into account. Years later, cross site scripting was discovered and there was much debate about whether or not a cross site scripting vulnerability was that important. After all, it was an issue that restricted itself to the web ecosystem and did not give us a shell on the server. Rhetoric on mailing lists mocked such findings and we (Packet Storm) received many emails saying that by archiving these issues we were degrading the quality of the site. But as the web evolved, people starting banking online, their credit records were online and before you knew it, people were checking their social network updates on their phone every five minutes. All of a sudden, something as small as a cross site scripting vulnerability mattered greatly.

To make the situation worse, many programs were developed to support web-related technologies. In the corporate world, being first to market or putting out a new feature in a timely fashion trumphs security. Backwards compatibility that feeds poor design became a must for any of the larger browser vendors. The "browser wars" began and everyone had different ideas on how to solve different issues. To say web-related technologies brought many levels of complexity to the modern computing experience is a great understatement. Browser-side programming languages, such as JavaScript, became a playground for hackers. Understanding the Document Object Model (DOM) and the implications of poorly coded applications became one of those lunch discussions that could cause you to put your face into your mashed potatoes. Enter "The Tangled Web".

This book puts some very complicated nuances in plain (enough) english. It starts out with Zalewski giving a brief synopsis of the security industry and the web. Breakdowns of the basics are provided and it is written in a way that is inviting for anyone to read. It goes on to cover a wide array of topics inclusive to the operation of browsers, the protocols involved, the various types of documents handled and the languages supported. Armed with this knowledge, the reader is enabled to tackle the next section detailing browser security features. As the author puts it, it covers "everything from the well-known but often misunderstood same-origin policy to the obscure and proprietary zone settings of Internet Explorer". Browsers, it ends up, have a ridiculous amount of odd dynamics for even the simplest acts. The last section wraps things up with upcoming security features and various browser mechanisms to note.

I found it a credit to the diversity of the book that technical discussion could also trail off to give historical notes on poor industry behavior. When it noted DNS hijacking by various providers it reminded me of the very distinct and constantly apparent disconnect between business and knowledge of technology. When noting how non-HTTP servers were being leveraged to commit cross site scripting attacks, Zalewski also made it a point to note how the Internet Explorer releases only have a handful of prohibited ports but all other browsers have dozens that they block. The delicate balance of understanding alongside context is vital when using information from this book and applying it to design.

Every page offers some bit of interesting knowledge that dives deep. It takes the time to note the odd behaviors small mistakes can cause and also points out where flawed security implementations exist. This book touches on the old and the new and many things other security books have overlooked. Another nice addition is that it provides security engineering cheatsheets at the end of each chapter. To be thorough, it explains both the initiatives set out by RFCs while it also documents different paths various browser vendors have taken in tackling tricky security issues. Google's Chrome, Mozilla's Firefox, Microsoft's Internet Explorer, Apple's Safari and Opera are compared and contrasted greatly throughout this book.

In my opinion, the web has become a layer cake over the years. New shiny technologies and add-ons have been thrown into the user experience and with each of them comes a new set of security implications. One-off findings are constantly discovered and documented (and at Packet Storm we try to archive every one of them), but this is the first time I have seen a comprehensive guide that focuses on everything from cross-domain content inclusion to content-sniffing. It is the sort of book that should be required reading for every web developer.

 -Todd








ev

NIELD (Network Interface Events Logging Daemon) 0.10

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache(ARP,NDP), IP address(IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.11

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache(ARP,NDP), IP address(IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.20

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.21

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.22

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.23

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.3.0

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.4.0

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.5.0

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the rtnetlink socket, and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules.




ev

NIELD (Network Interface Events Logging Daemon) 0.5.1

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the netlink socket and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules, and traffic control.




ev

NIELD (Network Interface Events Logging Daemon) 0.6.0

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the netlink socket and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules, and traffic control.




ev

NIELD (Network Interface Events Logging Daemon) 0.6.1

Network Interface Events Logging Daemon is a tool that receives notifications from the kernel through the netlink socket and generates logs related to link state, neighbor cache (ARP,NDP), IP address (IPv4,IPv6), route, FIB rules, and traffic control.







ev

Unpublished Iraq War Logs Trigger Internal WikiLeaks Revolt





ev

Electrifying Keyna: How One African Country is Approaching Renewable Energy Development

Kenya’s renewable energy ambitions have attracted growing attention in recent months. There has been a strong uptick in interest in the country’s wind energy potential in particular. Last year, Kenya’s Ministry of Energy and Petroleum said in an investment prospectus for 2013-2016 that it plans to boost wind power generation by 630 MW as part of its target to increase electricity levels by 5,000 MW by 2016. In March, the Kenyan government also signed a financing document for the largest private investment in Kenya.




ev

The Next Revolution: Discarding Dangerous Fossil Fuel Accounting Practices

The green revolution and, in particular, renewable energy products such as solar power, wind turbines, geothermal and algae-based fuels are not waiting for viable technology — it already exists in many forms. What they are waiting for is a massive sea change in our antiquated financial accounting systems.





ev

UN Sees Irreversible Damage to Climate Caused by Fossil Fuels

Humans are causing irreversible damage to the planet from burning fossil fuels, the biggest ever study of the available science concluded in a report designed to spur the fight against climate change.