<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>c0llateral Blog</title>
	<atom:link href="http://c0llateral.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://c0llateral.wordpress.com</link>
	<description>Windows Security Notepad</description>
	<lastBuildDate>Wed, 10 Feb 2010 20:23:36 +0000</lastBuildDate>
	<language></language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='c0llateral.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>c0llateral Blog</title>
		<link>http://c0llateral.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://c0llateral.wordpress.com/osd.xml" title="c0llateral Blog" />
	<atom:link rel='hub' href='http://c0llateral.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Converting shellcode to executable files using InlineEgg</title>
		<link>http://c0llateral.wordpress.com/2010/02/09/converting-shellcode-to-executable-files-using-inlineegg/</link>
		<comments>http://c0llateral.wordpress.com/2010/02/09/converting-shellcode-to-executable-files-using-inlineegg/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 18:20:12 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[shellcode]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=142</guid>
		<description><![CDATA[I like small utils, gadget ones, this article can be found at Breaking Code blog does not have that important functionality but it&#8217;s really cute!. EDITED at 10/2/2010 in order to prevent any misunderstandings. Thanks goes to a visitor&#8217;s comment which alerted me about how to write the reposts in order not to look like [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=142&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/02/09/converting-shellcode-to-executable-files-using-inlineegg/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>

		<media:content url="https://s-ssl.wordpress.com/wp-includes/images/smilies/icon_smile.gif" medium="image">
			<media:title type="html">:)</media:title>
		</media:content>
	</item>
		<item>
		<title>What is IRQL?</title>
		<link>http://c0llateral.wordpress.com/2010/02/09/what-is-irql/</link>
		<comments>http://c0llateral.wordpress.com/2010/02/09/what-is-irql/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 18:04:05 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Windows API]]></category>
		<category><![CDATA[IRQL]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=139</guid>
		<description><![CDATA[I remember 2 years ago I read an article in phrack 65 written  by ivanlef0u. It used the word IRQL it was the first time I was hearing that word and tried to find out what it means. Today looking at my RSS I found this article describing what IRQL really is. The article is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=139&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/02/09/what-is-irql/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>
	</item>
		<item>
		<title>Matching pool tags in Windows drivers</title>
		<link>http://c0llateral.wordpress.com/2010/02/09/matching-pool-tags-in-windows-drivers/</link>
		<comments>http://c0llateral.wordpress.com/2010/02/09/matching-pool-tags-in-windows-drivers/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 17:17:47 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=136</guid>
		<description><![CDATA[I love small posts especially those notes that could help you when banging your head at the wall after facing a strange error on Windows API. When MSDN mentions nothing your last hope is to be in your notes. Original link can be found here. This is a note to myself, mainly. If the PROTECTED_POOL [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=136&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/02/09/matching-pool-tags-in-windows-drivers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>

		<media:content url="http://blog.assarbad.net/wp-includes/images/smilies/icon_wink.gif" medium="image">
			<media:title type="html">;)</media:title>
		</media:content>
	</item>
		<item>
		<title>Ruby, Nmap XML, and Databases</title>
		<link>http://c0llateral.wordpress.com/2010/02/09/ruby-nmap-xml-and-databases/</link>
		<comments>http://c0llateral.wordpress.com/2010/02/09/ruby-nmap-xml-and-databases/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 17:08:18 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Pentesting]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=131</guid>
		<description><![CDATA[Ok it&#8217;s been a while. I found a very useful article when performing large nmap scans. Original article  here So I had a requirement to take some output from nmap scans, shove it into a database and then be able to run some queries on that data. Wait, isn&#8217;t there something that already does that?! [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=131&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/02/09/ruby-nmap-xml-and-databases/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>
	</item>
		<item>
		<title>Windows 7 GodMode</title>
		<link>http://c0llateral.wordpress.com/2010/01/08/windows-7-godmode/</link>
		<comments>http://c0llateral.wordpress.com/2010/01/08/windows-7-godmode/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 22:33:24 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[god mode]]></category>
		<category><![CDATA[windows 7]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=127</guid>
		<description><![CDATA[This on is a cool easter-egg I suppose, from Redmond. It is an about:config (see Firefox) of Windows in a folder. I&#8217;d like to add that this one is know as early as nWin95. Random name.{guid of shell namespace provider} will give you a folder with that namespace. There are many such providers in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=127&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/01/08/windows-7-godmode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>

		<media:content url="http://osnews.com/img/22691/godmodes.png" medium="image">
			<media:title type="html">Gode mode in Windows 7.</media:title>
		</media:content>
	</item>
		<item>
		<title>Safeboot keys</title>
		<link>http://c0llateral.wordpress.com/2010/01/07/safeboot-keys/</link>
		<comments>http://c0llateral.wordpress.com/2010/01/07/safeboot-keys/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 23:46:44 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Windows API]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[safeboot]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=117</guid>
		<description><![CDATA[This one will be quick. I just read in Didier Stevens blog about the SafeBoot key. It seems that some malware removes the specific registry key (HKLM\System\CurrentControlSet\Control\Safeboot)  in order to prevent the system booting in Safe Mode. Didier uploaded some pure SafeBoot reg files from default Windows installations. I have uploaded the files here,  SafeBoot.zip [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=117&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/01/07/safeboot-keys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>
	</item>
		<item>
		<title>PDF file loader to extract and analyse shellcode</title>
		<link>http://c0llateral.wordpress.com/2010/01/07/pdf-file-loader-to-extract-and-analyse-shellcode/</link>
		<comments>http://c0llateral.wordpress.com/2010/01/07/pdf-file-loader-to-extract-and-analyse-shellcode/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 23:19:33 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Reversing]]></category>
		<category><![CDATA[ida]]></category>
		<category><![CDATA[pdf]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=113</guid>
		<description><![CDATA[Ok happy new year! This one is preaty cool I found it in HexBlog, you know the blog about IDA pro. So here it is&#8230; One of the new features in IDA Pro 5.6 is the possibility to write file loaders using scripts such as IDC or Python. To illustrate this new feature, we are [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=113&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2010/01/07/pdf-file-loader-to-extract-and-analyse-shellcode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_loader.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_expl1.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_expl2.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_expl2_js.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_loader2.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_sc2.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_sc1.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_sc2_enc.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_sc2_bochs.gif" medium="image" />

		<media:content url="http://hexblog.com/ida_pro/pix/pdf_sc2_dec.gif" medium="image" />
	</item>
		<item>
		<title>HTTP POST -&gt; HTTPS = Bad Idea®</title>
		<link>http://c0llateral.wordpress.com/2009/12/28/http-post-https-bad-idea%c2%ae/</link>
		<comments>http://c0llateral.wordpress.com/2009/12/28/http-post-https-bad-idea%c2%ae/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 14:38:57 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[sslstrip]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=96</guid>
		<description><![CDATA[Cool taken from Paul Makowski of my 20% blog. This will be a quick post (pun not intended) on why you should never allow anything sensitive to be sent from an unsecured page to an SSL-encrypted page. Many, many websites do this (Digg &#38; Facebook quickly come to mind), and it’s a serious problem that [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=96&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2009/12/28/http-post-https-bad-idea%c2%ae/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>
	</item>
		<item>
		<title>DKOM Opens Door to Malware Rootkits</title>
		<link>http://c0llateral.wordpress.com/2009/12/27/dkom-opens-door-to-malware-rootkits/</link>
		<comments>http://c0llateral.wordpress.com/2009/12/27/dkom-opens-door-to-malware-rootkits/#comments</comments>
		<pubDate>Sun, 27 Dec 2009 12:49:44 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Rootkits]]></category>
		<category><![CDATA[dkom]]></category>
		<category><![CDATA[kernel]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=89</guid>
		<description><![CDATA[I love this one found it in McAfee&#8217;s blog posted by Romain Levy Much malware comes with a kernel rootkit component. Subverting the Windows kernel is indeed the best way to conceal malicious activities on infected systems. To achieve this, many types of malware load malicious device drivers that enjoy full access to all kernel [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=89&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2009/12/27/dkom-opens-door-to-malware-rootkits/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>

		<media:content url="http://vil.nai.com/images/211261a.jpg" medium="image" />

		<media:content url="http://vil.nai.com/images/211261b.jpg" medium="image" />

		<media:content url="http://vil.nai.com/images/211261c.jpg" medium="image" />

		<media:content url="http://vil.nai.com/images/211261g.jpg" medium="image" />

		<media:content url="http://vil.nai.com/images/211261e.jpg" medium="image" />

		<media:content url="http://vil.nai.com/images/211261f.jpg" medium="image" />
	</item>
		<item>
		<title>TCP Portals: The Handshake&#8217;s a Lie!</title>
		<link>http://c0llateral.wordpress.com/2009/12/27/tcp-portals-the-handshakes-a-lie/</link>
		<comments>http://c0llateral.wordpress.com/2009/12/27/tcp-portals-the-handshakes-a-lie/#comments</comments>
		<pubDate>Sun, 27 Dec 2009 12:39:13 +0000</pubDate>
		<dc:creator>c0llateral</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[packetfu]]></category>
		<category><![CDATA[protocols]]></category>
		<category><![CDATA[tcp]]></category>

		<guid isPermaLink="false">http://c0llateral.wordpress.com/?p=82</guid>
		<description><![CDATA[A friend of mine recently demonstrated during a lunch break (two cheeseburgers I think) a tool sending only a SYN as a response to another SYN to initialize a reverse TCP connection. I really hate protocols, I prefer application stuff, exploits or subverting kernel always look like a magic to me, but there is a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=c0llateral.wordpress.com&amp;blog=11111778&amp;post=82&amp;subd=c0llateral&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
		<wfw:commentRss>http://c0llateral.wordpress.com/2009/12/27/tcp-portals-the-handshakes-a-lie/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ea56db0ba10cc187376f14f7430b2311?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">c0llateral</media:title>
		</media:content>

		<media:content url="http://www.breakingpointsystems.com/community/images/3way-handshake.png" medium="image">
			<media:title type="html">3 way handshake</media:title>
		</media:content>

		<media:content url="http://www.breakingpointsystems.com/community/images/4way-handshake.png" medium="image">
			<media:title type="html">4 way handshake</media:title>
		</media:content>
	</item>
	</channel>
</rss>
