<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6952221109868791960</id><updated>2011-10-02T00:29:14.935+08:00</updated><category term='tools'/><category term='Books I Read'/><category term='Security Management'/><category term='Application Security'/><category term='password'/><category term='SQL Server'/><category term='Vulnerability'/><title type='text'>Sinbad Security Blog</title><subtitle type='html'>Information Security Management &amp;amp; Technology</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>14</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-6893190862888321327</id><published>2009-04-30T12:36:00.007+08:00</published><updated>2009-04-30T14:16:47.483+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security Management'/><title type='text'>10 Security Tips When Traveling with Your Laptop</title><summary type='text'>I wrote these 10 tips with reference from Internet sources and my personal experience. When I did security consulting I traveled a lot, the best tip I can recall is that I wrote something in the default paper card inside my laptop bag: "If you get this laptop, please call xxxxxx (my cell number), I will give you CNY1500 in cash face-to-face!" -- enough money for an old IBM R51. But fortunately my</summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/6893190862888321327/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/04/10-security-tips-when-traveling-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/6893190862888321327'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/6893190862888321327'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/04/10-security-tips-when-traveling-with.html' title='10 Security Tips When Traveling with Your Laptop'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-8863271092442043854</id><published>2009-03-17T10:19:00.003+08:00</published><updated>2009-03-17T10:26:14.424+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Books I Read'/><title type='text'>Book: Hacking Exposed, 6th Edition</title><summary type='text'>Best hacking book by former Foundstone guys just released the sixth edition!Updates:New chapter on hacking hardware, including lock bumping, access card cloning, RFID hacks, USB U3 exploits, and Bluetooth device hijackingUpdated Windows attacks and countermeasures, including new Vista and Server 2008 vulnerabilities and Metasploit exploitsThe latest UNIX Trojan and rootkit techniques and dangling</summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/8863271092442043854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/03/book-hacking-exposed-6th-edition.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/8863271092442043854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/8863271092442043854'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/03/book-hacking-exposed-6th-edition.html' title='Book: Hacking Exposed, 6th Edition'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_t8ZtGu4djBI/Sb8ImaRy5cI/AAAAAAAAALw/bZ__FJR0F7c/s72-c/Capture_730.gif.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-8441061544268453964</id><published>2009-03-16T16:03:00.002+08:00</published><updated>2009-03-16T16:06:15.061+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>Using WebGoat to promote awareness of web/app security</title><summary type='text'>WebGoat by OWASP is a good platform to learn and practice web application security. For me, I just used it in a meeting with our app development and operation teams to show how a web app could easily be compromised due to lacking of security consideration in design and maintenance phase.As far as I know, the feedback is good, and they started to show interests and ask questions on web/app </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/8441061544268453964/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/03/using-webgoat-to-promote-awareness-of.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/8441061544268453964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/8441061544268453964'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/03/using-webgoat-to-promote-awareness-of.html' title='Using WebGoat to promote awareness of web/app security'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-3990089480045527001</id><published>2009-03-13T13:03:00.001+08:00</published><updated>2009-03-13T13:04:50.768+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>Is patch severity rating worthy of accuracy?</title><summary type='text'>In security community, there is a common used standard to evaluate a patch or a vulnerability called CVSS. Many product vendors such as Cisco use it to give a score for patch of their product, and also security service vendors such as Nessus, Qualys and IBM ISS also use CVSS to calculate a score for patch when supporting their vulnerability scanner, IDS, or patch notification service delivery.So </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/3990089480045527001/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/03/is-patch-severity-rating-worthy-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/3990089480045527001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/3990089480045527001'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/03/is-patch-severity-rating-worthy-of.html' title='Is patch severity rating worthy of accuracy?'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-4392599861136572716</id><published>2009-01-06T17:23:00.005+08:00</published><updated>2009-04-30T13:32:22.685+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>CVSS2 Base Score Offline Calculator</title><summary type='text'>On FiRST site only v1 offline calc can be found, and all v2 calc are provided as online now. So I modified the v2 excel calc from the v1 one with new equation, but it still took me 2 hours to make it.Click here to download!</summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/4392599861136572716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/01/cvss2-base-score-offline-calculator.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/4392599861136572716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/4392599861136572716'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2009/01/cvss2-base-score-offline-calculator.html' title='CVSS2 Base Score Offline Calculator'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_t8ZtGu4djBI/SWMjnwgVB4I/AAAAAAAAAK4/CQ-B3xV-NQc/s72-c/cvss2%20calc.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-7410136723885443279</id><published>2008-12-31T18:05:00.004+08:00</published><updated>2008-12-31T18:15:08.989+08:00</updated><title type='text'>Happy Niu Year!</title><summary type='text'></summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/7410136723885443279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/12/happy-niu-year.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/7410136723885443279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/7410136723885443279'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/12/happy-niu-year.html' title='Happy Niu Year!'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_t8ZtGu4djBI/SVtF4nksCtI/AAAAAAAAAKY/1ZFNLFfgGBA/s72-c/happy%20niu%20year.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-3198708207765633652</id><published>2008-12-30T13:56:00.006+08:00</published><updated>2008-12-30T14:28:22.125+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Books I Read'/><title type='text'>Book: The Best Damn IT Security Management Book Period</title><summary type='text'>This is a huge book with 958 pages! I only finished reading Part1: From Vulnerability to Patch, which includes 11 chapters and 200 pages. The rest parts are only for reference when needed.The following is six stages of a Vulnerability Management plan cut from the book. This is what the Part 1 tells, and introduces some free and commerical tools for implementation.</summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/3198708207765633652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/12/book-best-damn-it-security-management.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/3198708207765633652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/3198708207765633652'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/12/book-best-damn-it-security-management.html' title='Book: The Best Damn IT Security Management Book Period'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_t8ZtGu4djBI/SVm8tFR6L9I/AAAAAAAAAJU/OOtfAgF0Hcs/s72-c/the%20best%20damn%20it%20security%20book%20cover.gif.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-1483583578339006937</id><published>2008-12-03T11:08:00.008+08:00</published><updated>2008-12-03T11:28:29.351+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>McAfee Foundstone Enterprise Tryout</title><summary type='text'>Foundstone is famous for its free security tools, such as fport, superscan and sqlscan. Long time ago the company started providing assessment service with their own assessment software, but even after it was acquired by McAfee, this software was not available on public.Now McAfee are selling their appliance with vulnerability scanning and management software preinstalled, it’s impossible for a </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/1483583578339006937/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/12/mcafee-foundstone-enterprise-tryout.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/1483583578339006937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/1483583578339006937'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/12/mcafee-foundstone-enterprise-tryout.html' title='McAfee Foundstone Enterprise Tryout'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_t8ZtGu4djBI/STX4LP-AL-I/AAAAAAAAAIM/s2VTaPpP-mE/s72-c/Capture_529.gif.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-7828013094333451528</id><published>2008-11-11T12:35:00.004+08:00</published><updated>2008-12-30T14:25:30.560+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Books I Read'/><title type='text'>Book: Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research</title><summary type='text'>This book is a detailed user manual for Metaploit Framework except case studies on vulnerability research, but to me the most interesting part is appendix B: Building a Test Lab for Penetration Testing. The author has shared much experience about this, which deserves a read.</summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/7828013094333451528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/11/book-metasploit-toolkit-for-penetration.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/7828013094333451528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/7828013094333451528'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/11/book-metasploit-toolkit-for-penetration.html' title='Book: Metasploit Toolkit for Penetration Testing, Exploit Development, and Vulnerability Research'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_t8ZtGu4djBI/SVm8skSdkEI/AAAAAAAAAJE/FG3OUytCn9Q/s72-c/metasploit%20ebook%20cover.gif.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-8275646424292371075</id><published>2008-11-06T16:39:00.003+08:00</published><updated>2008-11-11T10:54:49.969+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Management'/><title type='text'>Vulnerability Management with MS08-067</title><summary type='text'>It’s already 2 weeks since Microsoft released patch for MS08-067. The company I am working for has already patched 88% windows servers in the first week, and till now, 98% servers were patched.This time frame is well compliant with company security policy, and here I have some experience to share after this urgent patching period.First of all, for a vulnerability management program, assets </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/8275646424292371075/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/11/vulnerability-management-with-ms08-067.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/8275646424292371075'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/8275646424292371075'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/11/vulnerability-management-with-ms08-067.html' title='Vulnerability Management with MS08-067'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-6497182154859812453</id><published>2008-10-31T13:50:00.012+08:00</published><updated>2008-10-31T15:12:23.740+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><category scheme='http://www.blogger.com/atom/ns#' term='SQL Server'/><title type='text'>MS SQL Server Password Recovery</title><summary type='text'>For database admins, it is not a nightmare to handle with lost sql server password, which can be easily retrieved from application source code or just reset it in Enterprise Manager.But for a penetration tester, he should know where the passwords store, how to dump hashes, and crack them to gain more information. And it is necessary to audit the strength of sql server passwords, because weak sql </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/6497182154859812453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/ms-sql-server-password-recovery.html#comment-form' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/6497182154859812453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/6497182154859812453'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/ms-sql-server-password-recovery.html' title='MS SQL Server Password Recovery'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_t8ZtGu4djBI/SQqr43YNLbI/AAAAAAAAAEo/3yCRYkCvuLY/s72-c/Capture_457.gif.jpg' height='72' width='72'/><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-5970274293200476159</id><published>2008-10-27T17:51:00.007+08:00</published><updated>2008-10-31T15:10:25.475+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>Test of MS08-067 exploit</title><summary type='text'>The MS08-067 exploit for script kids was released yesterday. I tested it in an unpatched server, it really worked.Compared with DMZ, it's also a big risk for company intranet, patches should be applied to intranet servers running applications with sensitive information such as finance, hr, etc.  </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/5970274293200476159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/test-of-ms08-067-exploit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/5970274293200476159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/5970274293200476159'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/test-of-ms08-067-exploit.html' title='Test of MS08-067 exploit'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_t8ZtGu4djBI/SQquUsUQAYI/AAAAAAAAAGQ/Nia_36zylYc/s72-c/Capture_443.gif.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-4962605421269401646</id><published>2008-10-22T15:58:00.006+08:00</published><updated>2008-10-31T15:08:36.032+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='password'/><title type='text'>Secure Password Generator</title><summary type='text'>This free small password generator can help system administrators to generate complex passwords to fulfill security policy, provided both online and offline.</summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/4962605421269401646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/secure-password-generator.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/4962605421269401646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/4962605421269401646'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/secure-password-generator.html' title='Secure Password Generator'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_t8ZtGu4djBI/SQquTqscATI/AAAAAAAAAGA/OFWNN9L2DAM/s72-c/Capture_441.gif.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6952221109868791960.post-1108752732598039996</id><published>2008-10-22T15:52:00.003+08:00</published><updated>2008-10-22T15:57:32.573+08:00</updated><title type='text'>Sinbad is back!</title><summary type='text'>In the past four years I was involved with security service projects, so I had to travel around the country to stay with various clients. The methodology of such projects was outdated, project managment was what I cared about, not security technology. That's why I am silent in the community, and also with some other interests. But now I joined another company with an in-house security position, </summary><link rel='replies' type='application/atom+xml' href='http://sinbadsecurity.blogspot.com/feeds/1108752732598039996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/sinbad-is-back.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/1108752732598039996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6952221109868791960/posts/default/1108752732598039996'/><link rel='alternate' type='text/html' href='http://sinbadsecurity.blogspot.com/2008/10/sinbad-is-back.html' title='Sinbad is back!'/><author><name>Sinbad</name><uri>http://www.blogger.com/profile/09016215170153313312</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
