<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for Neohapsis Labs</title>
	<atom:link href="http://labs.neohapsis.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://labs.neohapsis.com</link>
	<description>Managing Risk and Security since 1998</description>
	<lastBuildDate>Wed, 15 Feb 2012 23:07:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Pass the iOS Privacy Salt &#8211; Hashing Does NOT Guarantee Privacy. by again</title>
		<link>http://labs.neohapsis.com/2012/02/15/pass-the-ios-privacy-salt-hashing-does-not-guarantee-privacy/#comment-1867</link>
		<dc:creator><![CDATA[again]]></dc:creator>
		<pubDate>Wed, 15 Feb 2012 23:07:51 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=1228#comment-1867</guid>
		<description><![CDATA[cf. http://dnscurve.org/nsec3walker.html]]></description>
		<content:encoded><![CDATA[<p>cf. <a href="http://dnscurve.org/nsec3walker.html" rel="nofollow">http://dnscurve.org/nsec3walker.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keychain Dumper Updated for iOS 5 by iPhone: keychain dumper &#8211; killed 9 problem &#171; SECURITYLEARN</title>
		<link>http://labs.neohapsis.com/2012/01/25/keychain-dumper-updated-for-ios-5/#comment-1781</link>
		<dc:creator><![CDATA[iPhone: keychain dumper &#8211; killed 9 problem &#171; SECURITYLEARN]]></dc:creator>
		<pubDate>Tue, 31 Jan 2012 17:39:48 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=1153#comment-1781</guid>
		<description><![CDATA[[...] has released. So you will not face killed 9 problem any more. More details are available at &#8211; http://labs.neohapsis.com/2012/01/25/keychain-dumper-updated-for-ios-5/ Rate this:  Share this:EmailFacebookLinkedInTwitterLike this:LikeBe the first to like this post. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] has released. So you will not face killed 9 problem any more. More details are available at &#8211; <a href="http://labs.neohapsis.com/2012/01/25/keychain-dumper-updated-for-ios-5/" rel="nofollow">http://labs.neohapsis.com/2012/01/25/keychain-dumper-updated-for-ios-5/</a> Rate this:  Share this:EmailFacebookLinkedInTwitterLike this:LikeBe the first to like this post. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Keychain Dumper Updated for iOS 5 by Satish</title>
		<link>http://labs.neohapsis.com/2012/01/25/keychain-dumper-updated-for-ios-5/#comment-1766</link>
		<dc:creator><![CDATA[Satish]]></dc:creator>
		<pubDate>Fri, 27 Jan 2012 01:40:02 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=1153#comment-1766</guid>
		<description><![CDATA[Thanks for updating the tool. Great work &amp; nice write up.]]></description>
		<content:encoded><![CDATA[<p>Thanks for updating the tool. Great work &amp; nice write up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Updated iPhone Keychain Dumper by UmZ</title>
		<link>http://labs.neohapsis.com/2011/05/06/updated-iphone-keychain-dumper/#comment-1759</link>
		<dc:creator><![CDATA[UmZ]]></dc:creator>
		<pubDate>Wed, 25 Jan 2012 19:39:55 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=978#comment-1759</guid>
		<description><![CDATA[Hey thanks for replying I was able to dump the data from other tables. I was thinking if we can take the certificates out of keychain along with private key. Would it be possible from cert table ??]]></description>
		<content:encoded><![CDATA[<p>Hey thanks for replying I was able to dump the data from other tables. I was thinking if we can take the certificates out of keychain along with private key. Would it be possible from cert table ??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Updated iPhone Keychain Dumper by Patrick Toomey</title>
		<link>http://labs.neohapsis.com/2011/05/06/updated-iphone-keychain-dumper/#comment-1758</link>
		<dc:creator><![CDATA[Patrick Toomey]]></dc:creator>
		<pubDate>Wed, 25 Jan 2012 15:24:15 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=978#comment-1758</guid>
		<description><![CDATA[Which table are you interested in dumping?]]></description>
		<content:encoded><![CDATA[<p>Which table are you interested in dumping?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Updated iPhone Keychain Dumper by UmZ</title>
		<link>http://labs.neohapsis.com/2011/05/06/updated-iphone-keychain-dumper/#comment-1736</link>
		<dc:creator><![CDATA[UmZ]]></dc:creator>
		<pubDate>Mon, 16 Jan 2012 21:12:57 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=978#comment-1736</guid>
		<description><![CDATA[Hey Patrick,
I have seen another table for keys in keychain-2.db. I tired modifying  your code but looks like it doesn&#039;t dump anything from that table. Do you know how can we dump data from that table as well ??/

Thanks]]></description>
		<content:encoded><![CDATA[<p>Hey Patrick,<br />
I have seen another table for keys in keychain-2.db. I tired modifying  your code but looks like it doesn&#8217;t dump anything from that table. Do you know how can we dump data from that table as well ??/</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on NeoPI in the Wild by Saam</title>
		<link>http://labs.neohapsis.com/2011/12/20/neopi-in-the-wild/#comment-1729</link>
		<dc:creator><![CDATA[Saam]]></dc:creator>
		<pubDate>Sun, 15 Jan 2012 00:04:41 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=1080#comment-1729</guid>
		<description><![CDATA[This may help you in your base64 detection:

&quot;&quot;&quot;
    NAME     : isBase64Encoded
    PARAMS   : string
    RETURN   : bool
    DESC     : Tests input string to see if it is 
               Base64 encoded
    EX       : in:MzAz, out:True
               in:MzAz(), out:False
&quot;&quot;&quot;
def isBase64Encoded(s):
    s = s.strip()
    if len(s) % 4 == 0:
        if re.match(&#039;^[A-Za-z0-9+/]+[=]{0,2}$&#039;, s):
            return True
    return False
# EOF: isBase64Encoded]]></description>
		<content:encoded><![CDATA[<p>This may help you in your base64 detection:</p>
<p>&#8220;&#8221;"<br />
    NAME     : isBase64Encoded<br />
    PARAMS   : string<br />
    RETURN   : bool<br />
    DESC     : Tests input string to see if it is<br />
               Base64 encoded<br />
    EX       : in:MzAz, out:True<br />
               in:MzAz(), out:False<br />
&#8220;&#8221;"<br />
def isBase64Encoded(s):<br />
    s = s.strip()<br />
    if len(s) % 4 == 0:<br />
        if re.match(&#8216;^[A-Za-z0-9+/]+[=]{0,2}$&#8217;, s):<br />
            return True<br />
    return False<br />
# EOF: isBase64Encoded</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook Applications Have Nagging Vulnerabilities by Scott Behrens</title>
		<link>http://labs.neohapsis.com/2012/01/03/facebook-applications-have-nagging-vulnerabilities/#comment-1724</link>
		<dc:creator><![CDATA[Scott Behrens]]></dc:creator>
		<pubDate>Wed, 11 Jan 2012 18:49:33 +0000</pubDate>
		<guid isPermaLink="false">http://neolab.wordpress.com/?p=1119#comment-1724</guid>
		<description><![CDATA[We had a relatively small sample size (10 apps) so there could be some wide variance on other applications assessed.  Even though it was a small sample size, there was a variety of different third party developers that wrote the applications so we weren&#039;t looking at applications that shared the same code base or coding practices.  It would be interesting to gather even more statistics from other consultants in the industry that also assess Facebook applications.]]></description>
		<content:encoded><![CDATA[<p>We had a relatively small sample size (10 apps) so there could be some wide variance on other applications assessed.  Even though it was a small sample size, there was a variety of different third party developers that wrote the applications so we weren&#8217;t looking at applications that shared the same code base or coding practices.  It would be interesting to gather even more statistics from other consultants in the industry that also assess Facebook applications.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Facebook Applications Have Nagging Vulnerabilities by willc</title>
		<link>http://labs.neohapsis.com/2012/01/03/facebook-applications-have-nagging-vulnerabilities/#comment-1712</link>
		<dc:creator><![CDATA[willc]]></dc:creator>
		<pubDate>Sat, 07 Jan 2012 00:35:43 +0000</pubDate>
		<guid isPermaLink="false">http://neolab.wordpress.com/?p=1119#comment-1712</guid>
		<description><![CDATA[Nice article...what was the sample size?]]></description>
		<content:encoded><![CDATA[<p>Nice article&#8230;what was the sample size?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &#8220;Researchers steal iPhone passwords in 6 minutes&#8221;&#8230;true&#8230;but not the whole story by iPhone Forensics &#124;  InfoSec Institute &#8211; IT Training and Information Security Resources</title>
		<link>http://labs.neohapsis.com/2011/02/28/researchers-steal-iphone-passwords-in-6-minutes-true-but-not-the-whole-story/#comment-1711</link>
		<dc:creator><![CDATA[iPhone Forensics &#124;  InfoSec Institute &#8211; IT Training and Information Security Resources]]></dc:creator>
		<pubDate>Fri, 06 Jan 2012 21:49:32 +0000</pubDate>
		<guid isPermaLink="false">http://labs.neohapsis.com/?p=913#comment-1711</guid>
		<description><![CDATA[[...] Keychain dumper http://labs.neohapsis.com/2011/02/28/researchers-steal-iphone-passwords-in-6-minutes-true-but-not-th... [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Keychain dumper <a href="http://labs.neohapsis.com/2011/02/28/researchers-steal-iphone-passwords-in-6-minutes-true-but-not-th" rel="nofollow">http://labs.neohapsis.com/2011/02/28/researchers-steal-iphone-passwords-in-6-minutes-true-but-not-th</a>&#8230; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

