<?xml version="1.0" encoding="iso-8859-1"?><!-- generator="b2evolution/1.10.2" -->
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:admin="http://webns.net/mvcb/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/">
	<channel>
		<title>Cognitive and Scientific Brainology</title>
						<link>http://andreicostin.com/index.php/brain</link>
				<description>andrei costin andreicostin costinandrei zveriu</description>
				<language>en-US</language>
				<docs>http://backend.userland.com/rss</docs>
				<admin:generatorAgent rdf:resource="http://b2evolution.net/?v=1.10.2"/>
				<ttl>60</ttl>
								<item>
					<title>EuSecWest 2010 - 'Hacking printers for fun and profit'</title>
					<link>http://andreicostin.com/index.php/brain/2010/06/20/eusecwest_2010_hacking_printers_for_fun_</link>
					<pubDate>Sun, 20 Jun 2010 15:44:41 +0000</pubDate>
					<dc:creator>zveriu</dc:creator>
					<category domain="alt">On the web</category>
<category domain="alt">Hardware</category>
<category domain="main">Software</category>
<category domain="alt">Hack</category>
<category domain="alt">Hack</category>					<guid isPermaLink="false">182@http://andreicostin.com/</guid>
					<description>EuSecWest 2010 - &#8216;Hacking printers for fun and profit&#8217;

Most probably you have come to the right place if you were looking for:
 - &#8220;Hacking printers for fun and profit&#8221; paper from EuSecWest 2010
 - Andrei Constin or Andrei Constantin presentation from EuSecWest 2010

Actually, by a mis-fortunate spelling mistake on the initial publication of the speakers list for EuSecWest 2010, which (given the copy-paste and propagation effect of the blogs and mailing-lists) transformed my correct name Andrei Costin to become Andrei Constin which then by Google&#8217;s &#8220;wisdom&#8221; became Andrei Constantin.

Download here: EuSecWest 2010 &#8220;Hacking Printers for fun and profit&#8221; Andrei Costin

Download here: Remote-initiated PPE (printer payload exploit) using Java applets.

ESW10 Feedback
Seems some people really liked the talk, paper and the ideas, while others took their most hilarious laughs ever :) (not sure if it was because of my talk or because of Amsterdam treats =)) ).

Tweetfeeds of the conference can be found here and here.

All in all, the event was very nice. Special thanks to Dragos and all the crew for organizing a great event.

After hearing about hackers on the plane and hackers on the train, we were doing hackers on the boat on Amsterdam&#8217;s canals. Also, it was nice to see that a cool crowd from ESW10 DoS-ed the tram literally on their way to the boats :).
PS: we almost got owned by the boat captain like a group of kindergarten kids =))&#8230; shhhhh and quiet, otherwise get kicked in the ass :P

And yeah, props to Dragos for the pelican case full of beer and to the guys caring the heavy devil of ice and beer :)).</description>
					<content:encoded><![CDATA[<h3>EuSecWest 2010 - &#8216;Hacking printers for fun and profit&#8217;</h3>

<p>Most probably you have come to the right place if you were looking for:<br />
 - &#8220;Hacking printers for fun and profit&#8221; paper from <a href="http://eusecwest.com/">EuSecWest 2010</a><br />
 - Andrei Constin or Andrei Constantin presentation from EuSecWest 2010</p>

<p>Actually, by a mis-fortunate spelling mistake on the initial publication of the <a href="http://eusecwest.com/agenda.html">speakers list for EuSecWest 2010</a>, which (given the copy-paste and propagation effect of the blogs and mailing-lists) transformed <b>my correct name Andrei Costin</b> to become Andrei Constin which then by Google&#8217;s &#8220;wisdom&#8221; became Andrei Constantin.</p>

<p>Download here: <a href="http://andreicostin.com/media/blogs/brain/EuSecWest2010_AndreiCostin_HackingPrintersForFunAndProfit.pdf" title="EuSecWest 2010 &quot;Hacking Printers for fun and profit&quot; Andrei Costin">EuSecWest 2010 &#8220;Hacking Printers for fun and profit&#8221; Andrei Costin</a></p>

<p>Download here: Remote-initiated PPE (printer payload exploit) using Java applets.</p>

<h4>ESW10 Feedback</h4>
<p>Seems some people really liked the talk, paper and the ideas, while others took their most hilarious laughs ever <img src="http://andreicostin.com/rsc/smilies/icon_smile.gif" alt="&#58;&#41;" class="middle" /> (not sure if it was because of my talk or because of Amsterdam treats =)) ).</p>

<p>Tweetfeeds of the conference can be found <a href="http://twitter.com/search?q=%23EUSecWest">here</a> and <a href="http://twitter.com/search?q=%23esw10">here</a>.</p>

<p>All in all, the event was very nice. Special thanks to <a href="http://twitter.com/dragosr">Dragos</a> and all the crew for organizing a great event.</p>

<p>After hearing about hackers on the plane and hackers on the train, we were doing hackers on the boat on Amsterdam&#8217;s canals. Also, it was nice to see that a cool crowd from ESW10 DoS-ed the tram literally on their way to the boats <img src="http://andreicostin.com/rsc/smilies/icon_smile.gif" alt="&#58;&#41;" class="middle" />.<br />
PS: we almost got owned by the boat captain like a group of kindergarten kids =))&#8230; shhhhh and quiet, otherwise get kicked in the ass <img src="http://andreicostin.com/rsc/smilies/graybigrazz.gif" alt="&#58;&#80;" class="middle" /></p>

<p>And yeah, props to Dragos for the <a href="http://www.discountdivers.com/pix/6.pelican.case.black.jpg">pelican case</a> full of beer and to the guys caring the heavy devil of ice and beer <img src="http://andreicostin.com/rsc/smilies/graylaugh.gif" alt="&#58;&#41;&#41;" class="middle" />.</p>]]></content:encoded>
					<comments>http://andreicostin.com/index.php/brain?p=182&amp;c=1&amp;tb=1&amp;pb=1#comments</comments>
				</item>
								<item>
					<title>EUSecWest 2010 is near</title>
					<link>http://andreicostin.com/index.php/brain/2010/05/16/eusecwest_2010_is_near</link>
					<pubDate>Sun, 16 May 2010 17:51:51 +0000</pubDate>
					<dc:creator>zveriu</dc:creator>
					<category domain="alt">In real life</category>
<category domain="alt">On the web</category>
<category domain="alt">Hardware</category>
<category domain="main">Software</category>
<category domain="alt">Hack</category>
<category domain="alt">Hack</category>					<guid isPermaLink="false">179@http://andreicostin.com/</guid>
					<description>EUSecWest 2010 is near

I invite you to take a look at EUSecWest 2010 agenda and register. Perhaps we could meet there, who knows&#8230;</description>
					<content:encoded><![CDATA[<h3>EUSecWest 2010 is near</h3>

<p>I invite you to take a look at EUSecWest 2010 <a href="http://eusecwest.com/agenda.html">agenda</a> and <a href="https://www.eusecwest.com/register">register</a>. Perhaps we could meet there, who knows&#8230;</p>]]></content:encoded>
					<comments>http://andreicostin.com/index.php/brain?p=179&amp;c=1&amp;tb=1&amp;pb=1#comments</comments>
				</item>
								<item>
					<title>"Programmers should be able to program!" program</title>
					<link>http://andreicostin.com/index.php/brain/2010/04/16/programmers_should_be_able_to_program_pr</link>
					<pubDate>Thu, 15 Apr 2010 20:24:57 +0000</pubDate>
					<dc:creator>zveriu</dc:creator>
					<category domain="main">In real life</category>
<category domain="alt">On the web</category>
<category domain="alt">AskAmit</category>					<guid isPermaLink="false">176@http://andreicostin.com/</guid>
					<description>&#8220;Programmers should be able to program!&#8221; program

Well, sad and true in the same time&#8230; It is an entertaining reading and one full of insights&#8230;

Maybe it&#8217;s just one of those reasons why software is getting more crappy, unreliable, insecure, etc.

The non-programming programmers

[...] Read more!</description>
					<content:encoded><![CDATA[<h3>&#8220;Programmers should be able to program!&#8221; program</h3>

<p>Well, sad and true in the same time&#8230; It is an entertaining reading and one full of insights&#8230;</p>

<p>Maybe it&#8217;s just one of those reasons why software is getting more crappy, unreliable, insecure, etc.</p>

<p><a href="http://www.codinghorror.com/blog/2010/02/the-nonprogramming-programmer.html">The non-programming programmers</a></p>

<p class="bMore"><a href="http://andreicostin.com/index.php/brain/2010/04/16/p176#more176">Read more! &raquo;</a></p>]]></content:encoded>
					<comments>http://andreicostin.com/index.php/brain?p=176&amp;c=1&amp;tb=1&amp;pb=1#comments</comments>
				</item>
								<item>
					<title>Comprehensive list of security and hackers conferences and conventions 2010</title>
					<link>http://andreicostin.com/index.php/brain/2010/04/11/comprehensive_list_of_security_and_hacke_2010</link>
					<pubDate>Sun, 11 Apr 2010 14:41:11 +0000</pubDate>
					<dc:creator>zveriu</dc:creator>
					<category domain="alt">On the web</category>
<category domain="alt">Hardware</category>
<category domain="alt">Software</category>
<category domain="alt">DailySpammer</category>
<category domain="alt">Hack</category>
<category domain="main">Hack</category>					<guid isPermaLink="false">174@http://andreicostin.com/</guid>
					<description>Comprehensive list of security and hackers conferences 2010

Recently, there is a high span of various security and hackers conferences and conventions going on.

Keeping track of them is not as easy as it seems, since there is no central point where to look up their schedules, locations, call for papers, etc.

So I decided to compile a list for my own (well it doesn&#8217;t cover 100% of security related conferences out there, but it tries to cover most of the publicly known/accessible ones).

[...] Read more!</description>
					<content:encoded><![CDATA[<h3>Comprehensive list of security and hackers conferences 2010</h3>

<p>Recently, there is a high span of various security and hackers conferences and conventions going on.</p>

<p>Keeping track of them is not as easy as it seems, since there is no central point where to look up their schedules, locations, call for papers, etc.</p>

<p>So I decided to compile a list for my own (well it doesn&#8217;t cover 100% of security related conferences out there, but it tries to cover most of the publicly known/accessible ones).</p>

<p class="bMore"><a href="http://andreicostin.com/index.php/brain/2010/04/11/p174#more174">Read more! &raquo;</a></p>]]></content:encoded>
					<comments>http://andreicostin.com/index.php/brain?p=174&amp;c=1&amp;tb=1&amp;pb=1#comments</comments>
				</item>
								<item>
					<title>Learning Wireless Power: Part 1 - Security</title>
					<link>http://andreicostin.com/index.php/brain/2010/02/10/learning_wireless_power_part_1_security</link>
					<pubDate>Wed, 10 Feb 2010 14:14:31 +0000</pubDate>
					<dc:creator>zveriu</dc:creator>
					<category domain="main">Hardware</category>
<category domain="alt">Hack</category>					<guid isPermaLink="false">169@http://andreicostin.com/</guid>
					<description>Prolog
Wireless Power is not something new. It&#8217;s an old idea, an old dream, an old demo. However, it now revived with new forces in form of new technology products.

Mainly, there are two camps trying to use magnetic induction to charge things:

  one offering a charging pad
  other trying for over-the-air power


However, the post is not about going over this technology itself - if you want to explore, check the links provided at the end.

To the point
The point of this post is to discuss the security perspective of wireless power transfer, especially for over-the-air type. Several couple of years proved consistently that wireless technologies (WiFi, RFID, remote controls, GSM, etc.) are very prone to security vulnerabilities (sadly, most often by design, rather by implementation).

The types of attack one can envision are:

  wireless power theft[...] Read more!</description>
					<content:encoded><![CDATA[<h4>Prolog</h4>
<p><a href="http://en.wikipedia.org/wiki/Wireless_energy_transfer">Wireless Power</a> is not something new. It&#8217;s an old idea, an old dream, an old demo. However, it now revived with new forces in form of new technology products.</p>

<p>Mainly, there are two camps trying to use magnetic induction to charge things:</p>
<ul>
  <li>one offering a charging pad</li>
  <li>other trying for over-the-air power</li>
</ul>

<p>However, the post is not about going over this technology itself - if you want to explore, check the links provided at the end.</p>

<h4>To the point</h4>
<p>The point of this post is to discuss the <b>security perspective of wireless power transfer, especially for over-the-air type</b>. Several couple of years proved consistently that <a href="http://en.wikipedia.org/wiki/Wireless">wireless technologies (WiFi, RFID, remote controls, GSM, etc.)</a> are very prone to security vulnerabilities (sadly, most often by design, rather by implementation).</p>

<p>The types of attack one can envision are:</p>
<ul>
  <li><p><b>wireless power theft</b></p><p class="bMore"><a href="http://andreicostin.com/index.php/brain/2010/02/10/p169#more169">Read more! &raquo;</a></p>]]></content:encoded>
					<comments>http://andreicostin.com/index.php/brain?p=169&amp;c=1&amp;tb=1&amp;pb=1#comments</comments>
				</item>
					</channel>
</rss>
