<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>broken blog</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/" />
    <link rel="self" type="application/atom+xml" href="http://www.broken.ch/broken_blog/atom.xml" />
    <id>tag:www.broken.ch,2008-07-22:/broken_blog//1</id>
    <updated>2009-12-22T11:46:59Z</updated>
    <subtitle>it&apos;s broken...</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

<entry>
    <title>Some interesting military stuff</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/12/some-interesting-military-stuf.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.42</id>

    <published>2009-12-21T14:05:23Z</published>
    <updated>2009-12-22T11:46:59Z</updated>

    <summary>Oops, big lag since last entry. That&apos;s just because i lost something very precious in my life.A report about a visit of a ICBM Titan 2 Launch Complex Site, and it&apos;s correlation to computer security, especially &quot;tradeoffs in designing secure...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Wochen Blog" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[Oops, big lag since last entry. That's just because i lost something very precious in my life.<br /><br /><a href="http://www.wired.com/threatlevel/2009/03/spy-system-focu/">A report about a visit</a> of a ICBM Titan 2 Launch Complex Site, and it's correlation to computer security, especially "<i>tradeoffs in designing secure systems: balancing high availability with strong access control</i>". Extremly interesting, not just the security procedures and aspects of it, but also the historic indications of the cold war.<br />"<i>But more importantly, a few hundred of the successors to the Titans,
the "Minuteman III" missiles, remain active in silos
throughout the northern US, run by crews and following procedures essentially
similar to those here.</i>"<br />And another important design decision: "<i>Bombs are also engineered to fail gracefully.</i>" (<a href="http://www.cs.columbia.edu/%7Esmb/nsam-160/pal.html">PAM</a>). Good to know :)<br /><br />In other news, the plans for <a href="http://en.wikipedia.org/wiki/Strategic_Defense_Initiative">Star Wars</a> seem to be <a href="http://www.tagesspiegel.de/politik/international/USA-Raketenschild-Barack-Obama;art123%2C2901881">on ice</a>. This is good news, as the <a href="http://en.wikipedia.org/wiki/Mutual_assured_destruction">MAD</a> doctrin still applies. I wonder if it really didnt work, or if all the failures was just to confuse the russians.<br /><br />Blackwater does it like Diebold - <a href="http://online.wsj.com/article/SB126102247889095011.html">Insurgents Hack U.S. Drones</a>. But they didnt seem to have haxxored them, just intercepting the unencrypted video feed of some of its sensors. Better than google earth! (Update: <a href="http://wikileaks.org/wiki/Reading_mission_control_data_from_Predator_Drone_video_feeds%2C_20_Dec_2009">Manual</a> to intercept the mpeg data)<br /><i>"Fixing the security gap would have caused delays, according to current
and former military officials. It would have added to the Predator's
price. Some officials worried that adding encryption would make it
harder to quickly share time-sensitive data within the U.S. military"</i>. Similar problem like with the ICBM's. <br />Not surprising after all:<i> "After 9/11, it rushed the armed Predator into service without so much
as an instruction manual, and now it's struggling to figure out how to
integrate the UAVs into an increased workload</i>". Again, they like high availability. <br />And the <a href="http://www.popsci.com/drones">newly aquired Reaper Drones</a> share the same vulnerability. <a href="http://www.wired.com/dangerroom/2009/03/obama-may-widen/">Obama likes them all</a>, nevertheles. Maybe <a href="http://www.heise.de/tp/r4/artikel/30/30028/1.html">the Isreali one's</a> are better designed.<br />Developing countrys seem to like to misuse US military equipment: <a href="http://www.wired.com/politics/security/news/2009/04/fleetcom">The Great Brazilian Sat-Hack Crackdown.</a><br /><br />How is this possible? Maaaybe like this...<br /><a href="http://www.nytimes.com/2009/03/29/technology/29spy.html?_r=4&amp;hp">Vast Spy System Loots Computers in 103 Countries</a><br /><a href="http://www.wired.com/threatlevel/2009/03/spy-system-focu/">Electronic Spy Network Focused on Dalai Lama and Embassy Computers</a><br />
<br />In other news, unlike the military, an industry has it's focus more on the former (strong access control) than the latter (high availability):<br /><a href="http://www.heise.de/newsticker/meldung/DRM-Chaos-verhindert-3D-Vorpremieren-von-Avatar-2-Update-888309.html">DRM Chaos verhindert 3D-Vorpremieren von Avatar</a><br /><br />Iran also has its problems with availability: <a href="http://www.debka.com/headline.php?hid=6280">Iran loses its only AWACS</a> (in a parade!)



<br /><br />Better than having malware on board: <a href="http://www.theregister.co.uk/2009/01/15/royal_navy_email_virus_outage/">Royal Navy warship lose email in virus infection</a><br /><br />Despite some <a href="http://www.nytimes.com/2009/11/04/world/middleeast/04sensors.html?_r=4">not so smart</a> inventions, there are some really interesting development in weapon designs, like <a href="http://gizmodo.com/5417079/darpas-iron-curtain-detects-explodes-rpgs-from-a-moving-humvee?autoplay=true">Iron Courtain</a> (not <a href="http://cnc.wikia.com/wiki/Iron_Curtain_%28Tiberium%29">this one</a>).<br /><br />Statistics of the day: <a href="http://www.usacarry.com/forums/general-firearm-discussion/8615-australian-shooter-magazine.html">The US should pull out of Washington</a><br />]]>
        
    </content>
</entry>

<entry>
    <title>Solyaris #13: Fragmentation</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/08/solyaris-13-fragmentation.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.41</id>

    <published>2009-08-12T00:18:46Z</published>
    <updated>2009-08-12T17:36:56Z</updated>

    <summary> Fragmentation handling is implemented!This was the last showstoper feature. I now move on the clean and tidy the code, and will release it in some time.On other news, Steffen Wendzel uploaded his Diploma Thesis about Protokollwechsel zur Realisierung von...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="soderberghsolaris2.jpg" src="http://www.broken.ch/broken_blog/soderberghsolaris2.jpg" class="mt-image-none" style="" height="200" width="500" /></span> <div><br />Fragmentation handling is implemented!<br />This was the last showstoper feature. I now move on the clean and tidy the code, and will release it in some time.<br /><br />On other news, Steffen Wendzel uploaded his Diploma Thesis about <a href="http://www.wendzel.de/dr.org/files/Papers/diplomarbeit.pdf">Protokollwechsel zur Realisierung von Covert Channels und Header-Strukturveränderungen zur Vermeidung von Covert Channels</a> (<a href="http://www.wendzel.de/?sub=showpost&amp;blogid=3&amp;postid=238">Blog</a>)<br />Very interesting.<br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Solyaris #12: HTTP Channel &amp; HTTP Proxy</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/04/solyaris-12-http-channel-http.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.35</id>

    <published>2009-04-24T15:24:32Z</published>
    <updated>2009-04-24T17:18:36Z</updated>

    <summary>I implemented the http channel, and the http proxy feature.Let me give you an example of the proxy feature works:First, we open a connection in kelvin to the http channel (the details doesnt interest us here).I also activate the http...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[I implemented the http channel, and the http proxy feature.<br /><br />Let me give you an example of the proxy feature works:<br /><br />First, we open a connection in kelvin to the http channel (the details doesnt interest us here).<br />I also activate the http proxy option ("proxy_on").<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kelvin_open_http_channel.png" src="http://www.broken.ch/broken_blog/2009/04/24/kelvin_open_http_channel.png" class="mt-image-none" style="" height="366" width="617" /></span><br /><br /><br />To illustrate the standard behaviour, lets send a http request to the http server of the rootkitet box (192.168.3.2):<br /><blockquote>dobin@unreal ~ $ export http_proxy="localhost:8080"<br />dobin@unreal ~ $ wget&nbsp; -O - --no-cookies -S http://192.168.3.2:/index.html | cat<br />--2009-04-24 19:33:56--&nbsp; http://192.168.3.2/index.html<br />Resolving localhost... 127.0.0.1, ::1<br />Connecting to localhost|127.0.0.1|:8080... connected.<br />Proxy request sent, awaiting response...<br />&nbsp; HTTP/1.1 200 OK<br />&nbsp; Date: Fri, 24 Apr 2009 15:33:55 GMT<br />&nbsp; Server: Apache/2.2.11 (FreeBSD) mod_ssl/2.2.11 OpenSSL/0.9.7e-p1 DAV/2<br />&nbsp; Last-Modified: Fri, 17 Apr 2009 22:58:53 GMT<br />&nbsp; ETag: "5c220-2c-467c81fe40540"<br />&nbsp; Accept-Ranges: bytes<br />&nbsp; Content-Length: 44<br />&nbsp; Connection: close<br />&nbsp; Content-Type: text/html<br />Length: 44 [text/html]<br />Saving to: `STDOUT'<br /><br />100%[========================================&gt;] 44&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --.-K/s&nbsp;&nbsp; in 0s&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br />2009-04-24 19:33:56 (15.4 MB/s) - `-' saved [44/44]<br /><br />&lt;html&gt;&lt;body&gt;&lt;h1&gt;It works!&lt;/h1&gt;&lt;/body&gt;&lt;/html&gt;<br /><br /></blockquote>As you can see, wget retrieves index.html from the standard apache installation, with cookies disabled, and prints the http header and html sourcecode to stdout. It uses our local rheya proxy (localhost:8080). No cookies sent or received, as this is just a normal .html file.<br /><br />Now, we want to call the "test" method in Kelvin. The "test" commands just transfers 100 bytes of data to rheya, and expects 100 bytes in return in the reply.<br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kelvin_test_start.png" src="http://www.broken.ch/broken_blog/2009/04/24/kelvin_test_start.png" class="mt-image-none" style="" height="366" width="617" /></span><br /><br />Kelvin creates the solyaris request, and is waiting (blocks) to receive an suitable HTTP request. Nothing has been sent for this command until now.<br /><br />We generate the http traffic with the same wget command from earlier:<br /><blockquote>dobin@unreal ~ $ wget&nbsp; -O - --no-cookies -S http://192.168.3.2:/index.html?ABCD | cat<br />--2009-04-24 19:37:24--&nbsp; http://192.168.3.2/index.html?ABCD<br />Resolving localhost... 127.0.0.1, ::1<br />Connecting to localhost|127.0.0.1|:8080... connected.<br />Proxy request sent, awaiting response...<br />&nbsp; HTTP/1.1 200 OK<br />&nbsp; Date: Fri, 24 Apr 2009 15:37:23 GMT<br />&nbsp; Server: Apache/2.2.11 (FreeBSD) mod_ssl/2.2.11 OpenSSL/0.9.7e-p1 DAV/2<br />&nbsp; Last-Modified: Fri, 17 Apr 2009 22:58:53 GMT<br />&nbsp; ETag: "5c220-2c-467c81fe40540"<br />&nbsp; Accept-Ranges: bytes<br />&nbsp; Content-Length: 44<br />&nbsp; Connection: close<br />&nbsp; Content-Type: text/html<br />&nbsp; <b>Set-Cookie: statusCode=1; requestID=0; dataLen=100; data=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA;</b><br />Length: 44 [text/html]<br />Saving to: `STDOUT'<br /><br />100%[========================================&gt;] 44&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; --.-K/s&nbsp;&nbsp; in 0s<br />2009-04-24 19:37:24 (17.0 MB/s) - `-' saved [44/44]<br /><br />&lt;html&gt;&lt;body&gt;&lt;h1&gt;It works!&lt;/h1&gt;&lt;/body&gt;&lt;/html&gt;<br /></blockquote>The only difference between this wget request and the one earlier is the "Set-Cookie:" line.<br /><br />What happened?<br /><br />As you can see, rheya replied with an "Set-Cookie" line, which is the answer for our solyaris request. The line was inserted in the kernel, after apache created its reply (the standard page doesnt include any cookies, of course). <br /><br />The reason it inserted the "Set-Cookie" line was because Kelvin intercepted the http request from wget in its proxy, and transparently added a "Cookie:" line, which's content is the solyaris request it generated.<br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="wireshark_http_request.png" src="http://www.broken.ch/broken_blog/2009/04/24/wireshark_http_request.png" class="mt-image-none" style="" height="150" width="666" /></span><br /><br />Additional to wget, Kelvin also interpreted the http reply, and found the answer for his rheya "test" request:<br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="kelvin_test_reply.png" src="http://www.broken.ch/broken_blog/2009/04/24/kelvin_test_reply.png" class="mt-image-none" style="" height="366" width="617" /></span><br /><br /><br />This is just the PoC. There are a lot of rough edges, which will be cleaned out in the next few weeks.<br /><br />Of course, instead of wget, one can also use a normal browser like firefox, or even a web site crawler, to automate the transfer of data to and from the rootkit.<br /><div><br /></div><div><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Solyaris #11: SNMP Channel and more</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/04/solyaris-11-snmp-channel.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.32</id>

    <published>2009-04-15T21:19:28Z</published>
    <updated>2009-04-14T20:25:05Z</updated>

    <summary>Rheya: SNMP Channel implementedcleaned node (removed m, static answer)Implemented basic fragmentation handlingFunction names cleanupFixed various crashesCollect port statistics Kelvin: Rudimentary implementation of SNMP Channelremoved anyoption, now use boost::program_optionsVarious updates and bugfixesUpdated and bugfixed DNS ChannelUse Boost::ASIO for SNMP UDP channel...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="snmpboostasioudp" label="snmp boost asio udp" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="soderberghsolaris2.jpg" src="http://www.broken.ch/broken_blog/soderberghsolaris2.jpg" class="mt-image-none" style="" height="200" width="500" /></span><br /><br />Rheya:<br />
<ul><li>SNMP Channel implemented<br /></li><li>cleaned node (removed m, static answer)</li><li>Implemented basic fragmentation handling</li><li>Function names cleanup</li><li>Fixed various crashes</li><li>Collect port statistics<br /></li></ul>
Kelvin:<br />
<ul><li>Rudimentary implementation of SNMP Channel<br /></li><li>removed anyoption, now use boost::program_options</li><li>Various updates and bugfixes</li><li>Updated and bugfixed DNS Channel<br /></li><li>Use Boost::ASIO for SNMP UDP channel in kelvin, instead of packet sniffing</li><li>Works without config file, again</li><li>Works on FreeBSD 6</li><li>ChannelChardev works again</li></ul>There's still lot of things to do. Wont release in the next few months.<br />]]>
        
    </content>
</entry>

<entry>
    <title>Steampunk ?!</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/04/steampunk.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.34</id>

    <published>2009-04-14T20:00:15Z</published>
    <updated>2009-04-14T20:28:07Z</updated>

    <summary>Ein wunderbares Bild des ersten Kampfes von zwei Ironclads Warships (CSS Virginia/Merrimac und USS Monitor). Diese hatten nicht mehr einen Rumpf aus Holz, sondern aus (oder mit) Metall. Man bemerke das grossartige Design der beiden, um möglichst wenig Trefferfläche zu...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Cyberpunk" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Monitorvirginia.jpg" src="http://www.broken.ch/broken_blog/2009/04/14/Monitorvirginia.jpg" class="mt-image-none" style="" height="363" width="500" /></span><div><br />Ein wunderbares Bild des ersten Kampfes von zwei <a href="http://en.wikipedia.org/wiki/Ironclad_warship">Ironclads</a> Warships (CSS Virginia/Merrimac und USS Monitor). Diese hatten nicht mehr einen Rumpf aus Holz, sondern aus (oder mit) Metall. Man bemerke das grossartige Design der beiden, um möglichst wenig Trefferfläche zu exponieren. Das schien auch grossartig zu funktionieren:&nbsp; <br /><blockquote><i>the two ironclads repeatedly tried to ram one another while shells bounced off their armor</i><br /></blockquote>Ein anderes, die USS Cairo:<br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="Uss_Cairo_h61568.jpg" src="http://www.broken.ch/broken_blog/2009/04/14/Uss_Cairo_h61568.jpg" class="mt-image-none" style="" height="325" width="500" /></span><br /></div><div><br /><br />Aber insbesondere ist mir die ähnlichkeit zu heutigen "Stealth" Ships aufgefallen. Back to the roots?<br /><br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="4-swedens-visby.jpg" src="http://www.broken.ch/broken_blog/2009/04/14/4-swedens-visby.jpg" class="mt-image-none" style="" height="333" width="500" /></span><br />Eine <a href="http://en.wikipedia.org/wiki/Visby_class_corvette">Visby Class Corvett</a>, Schweden<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="01-267.jpg" src="http://www.broken.ch/broken_blog/2009/04/14/01-267.jpg" class="mt-image-none" style="" height="266" width="400" /></span><br /><a href="http://www.mshipco.com/military_m80.html">M80 Stiletto</a><br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Solyaris #10: Packet Exchange</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/03/solyaris-10-packet-exchange.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.30</id>

    <published>2009-03-28T12:15:06Z</published>
    <updated>2009-03-31T16:43:10Z</updated>

    <summary>I finally implemented another feature: Stealth Exchange of Packets.When Rheya received commands over the DNS backdoor channel, it can now optionally not drop the packet after processing, but forward it to userspace like every other packet too. To not make...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="soderberghsolaris2.jpg" src="http://www.broken.ch/broken_blog/soderberghsolaris2.jpg" class="mt-image-none" style="" height="200" width="500" /></span><br /><br />I finally implemented another feature: Stealth Exchange of Packets.<br /><br />When Rheya received commands over the DNS backdoor channel, it can now optionally not drop the packet after processing, but forward it to userspace like every other packet too. To not make it obvious they are rootkit packets, we exchenge their content with something unsuspicious.<br /><br />This is a trace of 3 kelvin commands (connect, test, disconnect):<br /><br />attacker, with kelvin client (<span class="mt-enclosure mt-enclosure-file" style="display: inline;"><a href="http://www.broken.ch/broken_blog/rheya-log01.txt">rheya-log01.txt</a></span>):<br /><blockquote>13:59:29.921992 IP 192.168.3.1.1234 &gt; 192.168.3.2.53: 666+ A? <b>ABCD.2.1.0.49967.6.encKey.xxx.ch</b>. (50)<br />13:59:30.025742 IP 192.168.3.2.53 &gt; 192.168.3.1.1234: 666 1/0/0 (88)<br /><br />13:59:30.025874 IP 192.168.3.1.1234 &gt; 192.168.3.2.53: 666+[|domain]<br />13:59:30.121066 IP 192.168.3.2.53 &gt; 192.168.3.1.1234: 666[|domain]<br /><br />13:59:30.121152 IP 192.168.3.1.1234 &gt; 192.168.3.2.53: 666+ A? ABCD.2.2.21845.32219.xxx.ch. (45)<br />13:59:30.211366 IP 192.168.3.2.53 &gt; 192.168.3.1.1234: 666 1/0/0 (72)<br /><br /></blockquote>Owned host with rheya is just seeing the following in his bind-logfile:<br /><blockquote>28-Mar-2009 13:59:27.655 queries: info: client 192.168.3.1#1234: query:<b> www.broken.ch</b> IN A +<br />28-Mar-2009 13:59:27.753 queries: info: client 192.168.3.1#1234: query: www.broken.ch IN A +<br />28-Mar-2009 13:59:27.842 queries: info: client 192.168.3.1#1234: query: www.broken.ch IN A +<br /></blockquote>The standard setting is still to reply the rheya request in the kernel, and not let the packet touch userspace. But it could be suspicious if a proxy/sniffer/ids between the attacker and the real host, and the owned host, dont see the same amount of packets.<br /><br />Todo:<br />I'll implement SNMP channel next, with all the needed features.<br />Then i'll start with a tcp channel.<br />Then it's release time.<br />]]>
        
    </content>
</entry>

<entry>
    <title>Solyaris #9: Update &amp; Code Cleanup</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/03/solyaris-9-update-code-cleanup.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.27</id>

    <published>2009-03-10T18:15:32Z</published>
    <updated>2009-03-10T18:34:23Z</updated>

    <summary>Done:wrote script to compile rheya remotly on vmlistsession command implemented (used primarily for testing purposes) bites data type, i wanted to make clear its just bytes (and not strings, like with char, which end with 0 byte)dns channel: created new...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="SOLARIS.jpg" src="http://www.broken.ch/broken_blog/2009/03/03/SOLARIS.jpg" class="mt-image-none" style="" height="217" width="432" /></span><br /><br />Done:<br /><ul><li>wrote script to compile rheya remotly on vm</li><li>listsession command implemented (used primarily for testing purposes) <br /></li><li>bites data type, i wanted to make clear its just bytes (and not strings, like with char, which end with 0 byte)<br /></li><li>dns channel: created new function to build domain name</li><li>dns channel: base64 encoding for answer data</li><li>implemented disconnect/quit command</li></ul><br /><ul><li>Kelvin: --test command line option</li><li>Kelvin: fixed dns channel if no request data was sent</li><li>Kelvin: quit now leaves the screen in an usable state</li><li>Kelvin: Networking subsystem redesign</li><li><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://www.broken.ch/broken_blog/2009/03/10/rheya-ClassDiagram.png">Beta UML Graph</a></span></li></ul> <div>Code cleanup finished. Will start working on real issues soon (snmp channel, stealth exchange of packets)<br /></div>]]>
        
    </content>
</entry>

<entry>
    <title>Solyaris #8: Update &amp; Code Cleanup</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/03/solyaris-8-update.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.21</id>

    <published>2009-03-03T18:07:36Z</published>
    <updated>2009-03-03T16:29:43Z</updated>

    <summary> Main Page is: www.haking.ch/rootkit Rheya Kernel Rootkit / Server: udp channel erstellt, was ein fake Channel für alle UDP basierten Protokolle ist Für den UDP Channel gibts jetzt eine Protokoll Identifikation durch den Destination Port mögliche UDP/ICMP Protokoll Plugins...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="solyarisupdate" label="solyaris update" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<span class="mt-enclosure mt-enclosure-image" style="display: inline;">
<img alt="SOLARIS.jpg" src="http://www.broken.ch/broken_blog/2009/03/03/SOLARIS.jpg" class="mt-image-none" style="" height="217" width="432" />
</span><br /><br />
Main Page is:<br />
<a href="http://www.haking.ch/rootkit">www.haking.ch/rootkit</a><br /><br />
Rheya Kernel Rootkit / Server:<br />

<ul><li>udp channel erstellt, was ein fake Channel für alle <span class="caps">UDP </span>basierten Protokolle ist<br /></li>
<li>Für den <span class="caps">UDP</span> Channel gibts jetzt eine Protokoll Identifikation durch den Destination Port</li>
<li>mögliche <span class="caps">UDP</span>/ICMP Protokoll Plugins sind nun einfach zu erstellen; einfach eine Identifikation() Methode schreiben, und ein Handler, welcher bloss auf einer Kopie des Packetes in einem normalen Buffer arbeiten kann und daraus das Reply Packet erzeugt. Alles andere ist nun transparent.<br /></li>
<li>Es ist nun möglich, sicher mehr als 100 Bytes zu übertragen. Sollte nun bis zur <span class="caps">MTU </span>funktionieren (abhängigkeit von <span class="caps">MBUF'</span>s gelöst).</li>
<li>Connections / Sessions implementiert<br /></li>
</ul><br />Client / Kelvin:<br /><ul>
<li>general Code Cleanup</li><li>Request nach Node umbenannt, wie Rheya</li>
<li>Node hat Request und Answer struct</li>
<li>Node speichert nicht mehr den Payload, sondern nur Metadaten</li><li>Connections / Session implementiert</li>
<li>Boost Linked lists anstatt FreeBSD lists</li>
<li>Linux (Gentoo) compatibility</li><li>Networking Thread mit pcap_loop() rausgeworfen, benutze wieder pcap_next(), wass den Client ziemlich vereinfacht</li><li>Code in öffentlichen <a href="http://www.haking.ch/websvn/listing.php?repname=solyaris&amp;path=%2Fkelvin%2F#path_kelvin_"><span class="caps">SVN </span>eingecheckt</a><br /></li></ul><br />Nächste Schritte:<br /><ol><li>Dokumentation</li><li><span class="caps">SNMP</span> Channel<br /></li><li>Stealth exchange of Packet Content, für Networking Channels<br /></li><li><span class="caps">TCP</span> Channels</li><li>Datenmengen, welche grösser als die <span class="caps">MTU </span>ist übertragen</li></ol>]]>
        
    </content>
</entry>

<entry>
    <title>Moviezz</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/02/moviezz-5.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.22</id>

    <published>2009-02-09T18:39:00Z</published>
    <updated>2009-02-09T20:00:49Z</updated>

    <summary>Firefly (9.5) (Serie): Uff, super tolle Science Fiction Serie, aber leider nur eine Staffel :-(Keinohrhasen (7.2): Wieder ein Super Til Schweiger Film. I love it!Eagle Eye (6.7): Da hier 1984 ruft, finde ich ihn gut :-). Unterhaltsam, nice.Appaloosa (7.0): Überzeugender,...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Moviez" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<a href="http://www.imdb.com/title/tt0303461/">Firefly</a> (9.5) (Serie): Uff, super tolle Science Fiction Serie, aber leider nur eine Staffel :-(<br /><a href="http://www.imdb.com/title/tt0960790/">Keinohrhasen</a> (7.2): Wieder ein Super Til Schweiger Film. I love it!<br /><a href="http://www.imdb.com/title/tt1059786/">Eagle Eye</a> (6.7): Da hier 1984 ruft, finde ich ihn gut :-). Unterhaltsam, nice.<br /><a href="http://www.imdb.com/title/tt0800308/">Appaloosa</a> (7.0): Überzeugender, solider Western. Cool.<br /><a href="http://www.imdb.com/title/tt1175491/">W</a> (6.8): Kein Meisterwerk, aber interessant und lehrreich.<br /><a href="http://www.imdb.com/title/tt0910936/">Pineapple Express</a> (7.4): Kein Kiffer Film. Nunja, fast nicht. Aber trotzdem unterhaltsam und lustig.<br /><a href="http://www.imdb.com/title/tt0454987/">Lets go to prison</a> (5.7): Funny. Lustige Geschichte :)<br /><a href="http://www.imdb.com/title/tt1129420/">The Eleventh Hour 2008</a> (4.3): Ein gar nicht mal so schlechter, billig produzierter Action Film. Coole Fight Szenen.<br /><a href="http://www.imdb.com/title/tt1208647/"></a><a href="http://www.imdb.com/title/tt0492881/">The Fifth Commandement</a> (4.6): Ein richtig billiger Actionfilm...<br /><br />Anime:<br /><a href="http://www.imdb.com/title/tt1121794/">Sword of Stranger</a> (7.8): Schön gezeichnet, gute Charaktere, interessante Geschichte, spannende Action... 1A<br /><a href="http://www.imdb.com/title/tt1265998/">Afro Samurai - Resurrection</a> (8.0): Der Nachfolger vom erfolgreichen <a href="http://www.imdb.com/title/tt0465316/">Erstling</a>. Leider auch nicht so gut wie der erste, definitiv immerhin sehenswert. <br /><a href="http://www.imdb.com/title/tt1174954/">Resident Evil Degeneration</a> (6.8): Left 4 Dead als Film :-). Unterhaltsam!<br /><a href="http://www.imdb.com/title/tt0856824/">Gunbuster 2</a> (7.2): Wow, wo sonst wird versucht die Menscheit zu retten, indem man die Erde als Kinetische Waffe auf die ausserirdische Lebensform wirft, wobei diese aber im letzten Moment von einem gigantischen Robo Girl gestoppt wird... (nc)<br /><br /><br />]]>
        
    </content>
</entry>

<entry>
    <title>Various security related stuff</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/01/various-security-related-stuff.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.20</id>

    <published>2009-01-08T21:35:02Z</published>
    <updated>2009-01-08T22:27:05Z</updated>

    <summary>Willste wissen was auf dem Handy von [insert-somebody-here] so drauf ist? Einfach denCSI Stick kaufen. Gewählte Nummern, SMS, Kalender, gelöschte Daten, alles verfügbar nachdem man das Ding kurz angeschlossen hat. Für nur 300$..Dont trust the nice friendly woman voice in...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Security" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="security" label="security" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<br />Willste wissen was auf dem Handy von [insert-somebody-here] so drauf ist? Einfach den<br /><a href="http://www.paraben-forensics.com/catalog/product_info.php?products_id=485">CSI Stick</a> kaufen. Gewählte Nummern, SMS, Kalender, gelöschte Daten, alles verfügbar nachdem man das Ding kurz angeschlossen hat. Für nur 300$..<br /><br />Dont trust the nice friendly woman voice in your car: <a href="http://www.schneier.com/blog/archives/2008/09/gps_spoofing.html">GPS Spoofing</a><br /><br />Damn cool Stuff: <a href="http://addxorrol.blogspot.com/2008/09/improving-binary-comparison-and-its.html">Improving Binary Comparison</a><br /><blockquote>If you have an executable and you suspect that it might contain a
statically linked library for which you have source access (or which
you have analyzed before), we want BinDiff to be able to port the
symbols into the executable you have, <span style="font-weight: bold;">even if the compiler versions and build environments differ</span><span style="font-weight: bold;"> significantly</span>, and <span style="font-weight: bold;">even if the versions of the library are not quite the same</span><br /><br /></blockquote>Dazu passend: <a href="http://www.the-interweb.com/serendipity/index.php?/archives/112-BinNavi-2.0-Preview.html">Binnavi 2.0 Preview</a><br /><br />Major Security Fuckup #1: <a href="http://www.heise.de/security/Spiegel-Telekom-Sicherheitsluecke-offenbart-30-Millionen-Handydaten-Update--/news/meldung/117229">Telekom Sicherheitslücke offenbart 30 Millionen Handydaten</a><br />Major Security Fuckup #2: <a href="http://www.heise.de/security/Hacker-decken-ungesicherte-Tueren-in-Playstation-Home-auf--/news/meldung/120324">Hacker decken ungesicherte Türen in Playstation Home auf</a><br /><br /><a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html">DDoS Attacken</a>, und weitere Informationen zum "Cyberwar" zwischen Russland und Georgien.<br /><br /><a href="http://rdist.root.org/2008/10/24/quantum-cryptography-is-useless/">Quantom cryptography is useless</a>, lol, hat wohl noch niemand bemerkt? ;-)<br /><br />Wow, 2009 ist 1945: <a href="http://www.telegraph.co.uk/news/worldnews/europe/germany/3239289/Adolf-Hitler-planned-propaganda-cable-TV.html">Adolf Hitler planned propaganda cable TV</a><br /><blockquote>The Orwellian screens would have been set up in public places and would
show "people's television", depicting how the Aryan race should live,
with the Nazis focusing on news, sport and education.<br />[...]<br /><p>Prototype programmes included Family Chronicles: An Evening
with Hans and Gelli, which was an early <b>reality TV show depicting a
wholesome Aryan life of a young German couple</b> [GZSZ, anyone?].</p></blockquote><br />Auch cool, dass man das jetzt automatisiert machen kann: <a href="http://www.physorg.com/news144519246.html">A Picture is Worth a Thousand Locksmiths</a><br /><blockquote>software program that can perform key duplication without
having the key. Instead, the computer scientists only need a photograph
of the key.<br /></blockquote>WAP is fsckd: <a href="http://arstechnica.com/articles/paedia/wpa-cracked.ars/1">understanding the WPA Attack</a><br /><br />Und nach dem Debian SSL Debakel: <a href="http://security.freebsd.org/advisories/FreeBSD-SA-08:11.arc4random.asc">FreeBSD PRNG vulnerability</a><br /><blockquote><pre>When the arc4random(9) random number generator is initialized, there may<br />be inadequate entropy to meet the needs of kernel systems which rely on<br />arc4random(9); and it may take up to 5 minutes before arc4random(9) is<br />reseeded with secure entropy from the Yarrow random number generator.<br /></pre></blockquote>Oopsy...<br />Da Lob ich mir <a href="http://www.openbsd.org/">OpenBSD</a> und ihre Philosophie. Man kann nun eben kein sicheres System produzieren, auch wenn man noch so viele Security Layer aufeinanderpappt, wenn das Base broken ist...<br />&nbsp;<br />Wer hat meine Daten? <a href="http://breachblog.com/">Jeder</a><br /><br />LOL, Niederländisches Militär bruzzelt mit dem Zielerfassungslaser eines Apache's die Kamera eines Reporters. Da kann ich nur sagen: wow, respect. <a href="http://fluglaerm-kl.de/aktuelles_einzeln.php?artikel=200811301336">Link</a><br /><br />Auch lolig: <a href="http://www.heise.de/security/Sicherheitsluecke-im-ndiswrapper-fuer-Linux--/news/meldung/118481">owned by a too long ESSID</a><br /><br />Nice Technology: <a href="http://www.heise.de/security/Sicherheitsluecke-im-ndiswrapper-fuer-Linux--/news/meldung/118481">Levelhead</a>, check the movies!<br />]]>
        
    </content>
</entry>

<entry>
    <title>Moviezz</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2009/01/moviezz-4.html" />
    <id>tag:www.broken.ch,2009:/broken_blog//1.19</id>

    <published>2009-01-08T21:08:06Z</published>
    <updated>2009-01-08T21:29:43Z</updated>

    <summary>The Day the Earth Stood Still (5.7): Omg, suckt. Schaut das Original (8.1), das ist 100x besser.Transporter 3 (6.1): Lustig und unterhaltsam, kein schlechter &quot;Transporter&quot; Movie.Behind Enemy Lines: Colombia (5.3): Gar nicht mal so schlecht, gute Action, eine Story die...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Moviez" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<p><a href="http://www.imdb.com/title/tt0970416/">The Day the Earth Stood Still</a> (5.7): Omg, suckt. Schaut das <a href="http://www.imdb.com/title/tt0043456/">Original</a> (8.1), das ist 100x besser.<br /><br /><a href="http://www.imdb.com/title/tt1129442/">Transporter 3</a> (6.1): Lustig und unterhaltsam, kein schlechter "Transporter" Movie.<br /><br /><a href="http://www.imdb.com/title/tt1208647/">Behind Enemy Lines: Colombia</a> (5.3): Gar nicht mal so schlecht, gute Action, eine Story die was hergibt... nice :)<br /><br /><a href="http://www.imdb.com/title/tt0438052/">The Gene Generation</a> (4.2): Billig, aber easy Cyberpunkiger Film. Ganz i.O.<br /><br /><br /><br /></p>]]>
        
    </content>
</entry>

<entry>
    <title>Moviezz</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2008/11/babylon-ad-53-auch-ohne.html" />
    <id>tag:www.broken.ch,2008:/broken_blog//1.18</id>

    <published>2008-11-02T17:34:20Z</published>
    <updated>2008-11-30T15:45:01Z</updated>

    <summary>OK:Babylon A.D (5.3): Auch ohne Plot recht unterhaltsam, da ziemlich Cyberpunkig :-)You dont mess with the Zohan (5.7): muahaha fresh und funnyShaun of Death (8.0): Tolle Zombie Satire. Britischer Humor rockt. Westworld (7.1): Roboter in Vergnügungspark gone mad. Gesellschaftskritisch, Futuristisch...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Moviez" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[OK:<a href="http://www.imdb.com/title/tt0898266/"><br /></a><br /><p><a href="http://www.imdb.com/title/tt0898266/">Babylon A.D</a> (5.3): Auch ohne Plot recht unterhaltsam, da ziemlich Cyberpunkig :-)<br /><a href="http://www.imdb.com/title/tt0960144/">You dont mess with the Zohan</a> (5.7): <em>muahaha</em> fresh und funny<br /><a href="http://www.imdb.com/title/tt0365748/">Shaun of Death</a> (8.0): Tolle Zombie Satire. Britischer Humor rockt.<br />
<a href="http://www.imdb.com/title/tt0070909/">
Westworld</a> (7.1): Roboter in Vergnügungspark gone mad. Gesellschaftskritisch,
Futuristisch und wegweisend. Dank Western Theme wohl DER Prototyp für
japanische Science Fiction schreiber, und für Terminator. Example:<br /></p><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="westworld.jpg" src="http://www.broken.ch/broken_blog/2008/11/30/westworld.jpg" class="mt-image-none" style="" width="487" height="245" /></span><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="innocence-logo.jpg" src="http://www.broken.ch/broken_blog/innocence-logo.jpg" class="mt-image-none" style="" width="490" height="160" /></span>

<p><br />
</p><p>not ok:<br /></p><p><a href="http://www.imdb.com/title/tt1185834/">Star Wars Clone Wars</a> (5.1): Jede Episode der gleichnamigen Serie ist besser als der Film. Und selbst diese sind meist nicht allzu gut.<br />
<a href="http://www.imdb.com/title/tt0467197/">Max Payne</a> (5.7): Hm, ein paar Tolle Action Sequenzen. Story verwirrt. Hat imho nicht viel mit dem Spiel zu tun. Ein wenig enttäuschend.<br /></p><p>Burn after Reading: aha das war eine Komödie?! <em>booring</em> <br />
Get Smart: <em>boring</em><br />
Tropic Thunder: <em>yawn</em><br />
Righeous Kill: <i>zu langweilig um ihn fertig zu schauen</i><br />
Quantum of Solance: <i>Where's Bond?!</i><br />
</p>

<p><br />Coole Serien:</p><p>World Series of Poker<br />Southpark<br /><a href="http://www.imdb.com/title/tt0898266/">The Big Bang Theory</a><br /><a href="http://www.imdb.com/title/tt0458290/">Star Wars Clone Wars</a> <br />House<br />Naruto</p><p><br /></p>
]]>
        

    </content>
</entry>

<entry>
    <title>Solyaris #7: FreeBSD specialities</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2008/11/solyaris-7-freebsd-specialitie.html" />
    <id>tag:www.broken.ch,2008:/broken_blog//1.17</id>

    <published>2008-11-02T16:45:40Z</published>
    <updated>2008-11-02T17:11:31Z</updated>

    <summary>Ich habe endlich wieder mal Zeit gefunden, daran weiterzuprogrammieren, und diese dann prompt auch wegen einer FreeBSD Eigenheit verpulvert.Beim Cleanup des ICMP Channels hatte ich seltsame Bugs. In der Funktion, die die ICMP Packete verarbeitet, brauchte ich die Länge des...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Solyaris" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="bug" label="bug" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[Ich habe endlich wieder mal Zeit gefunden, daran weiterzuprogrammieren, und diese dann prompt auch wegen einer FreeBSD Eigenheit verpulvert.<br /><br />Beim Cleanup des ICMP Channels hatte ich seltsame Bugs. In der Funktion, die die ICMP Packete verarbeitet, brauchte ich die Länge des Packetes, welches in ip-&gt;ip_len steht:<br /><br />von /usr/src/sys/netinet/ip.h:<br /><blockquote>struct ip {<br />&nbsp;&nbsp; ...<br />&nbsp;&nbsp; u_short ip_len; /* total length */<br />&nbsp;&nbsp; ...<br />}<br /></blockquote>Nach dem RFC ist die Total Length so definiert:<br />
<blockquote><p>Total Length: 16 Bit breit. Gibt die Länge des gesamten Pakets (inkl. Kopfdaten) in Bytes an</p></blockquote>Also <i>inklusiv</i> des IP Headers. Wie ich aber schmerzhaft herausfinden sollte, ist beim Aufruf von icmp_input() ip-&gt;ip_len nur noch die grösse des IP Payloads, <i>ohne</i> länge des IP Headers. Das gleiche bei udp_input(). Das scheint aber eine Ausnahme zu sein, denn für icmp_send() muss ip-&gt;ip_len wieder den standardkonformen Wert beinhalten.<br /><br />Danke liebe FreeBSD Kernel Entwickler für das undokumentierte verhalten, einfach IP Header Werte mitten in deren verarbeitung zu verändern!<br /><br />]]>
        
    </content>
</entry>

<entry>
    <title>Moviezz</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2008/10/moviezz-3.html" />
    <id>tag:www.broken.ch,2008:/broken_blog//1.16</id>

    <published>2008-10-04T10:04:45Z</published>
    <updated>2008-10-04T12:33:06Z</updated>

    <summary>Jim Jarmusch - Dead Man (7.7): Schwarz-Weiss, seltsam, und mit Johnny Depp. Auf eine seltsame weise ein wirklich guter, packender Film.Sky Fighters (5.3): Französischer I-Love-Mirage Film ala Top Gun. Cool, und schöne Bilder (vorallem in 720p). Gegen Ende verliert sich...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Moviez" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="moviesreview" label="Movies Review" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[<a href="http://www.imdb.com/title/tt0112817/">Jim Jarmusch - Dead Man</a> (7.7): Schwarz-Weiss, seltsam, und mit Johnny Depp. Auf eine seltsame weise ein wirklich guter, packender Film.<br /><br /><a href="http://www.imdb.com/title/tt0421974/">Sky Fighters</a> (5.3): Französischer I-Love-Mirage Film ala Top Gun. Cool, und schöne Bilder (vorallem in 720p). Gegen Ende verliert sich die Story, aber das ist egal. <br /><br /><a href="http://www.imdb.com/title/tt0893401/">Daylight Robbery</a> (6.2): Nicht sehr spektakulär, aber solider Bankraub Film.<br /><br /> <a href="http://www.imdb.com/title/tt0451079/">Horton Hears a Who</a> (7.4): Hehe, lustig und unterhaltsam. Mir gefällt die Message.<br /><br /><a href="http://www.imdb.com/title/tt0443274/">Vantage Point </a>(6.7): Kurzweiliger Action Film.<br /><br /><a href="http://www.imdb.com/title/tt1086340/">Mr. Untouchable</a> (6.7): Naja, war mehr oder weniger interesting.<br />]]>
        
    </content>
</entry>

<entry>
    <title>Panasonic - eine Hass Liebe</title>
    <link rel="alternate" type="text/html" href="http://www.broken.ch/broken_blog/2008/09/panasonic-eine-hass-liebe.html" />
    <id>tag:www.broken.ch,2008:/broken_blog//1.15</id>

    <published>2008-09-22T16:49:48Z</published>
    <updated>2009-04-05T14:54:31Z</updated>

    <summary>Ich habe mir letztes Jahr einen 720p HD Beamer (PT-AX100E) bei Digitec gekauft, für den stolzen Preis von etwa 2000SFr (passend zu der PS3). Schon nach 2 Monaten hat er nicht mehr richtig funktioniert, und schaltete nach 5 Minuten betrieb...</summary>
    <author>
        <name>dobin</name>
        <uri>http://www.broken.ch</uri>
    </author>
    
        <category term="Review" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.broken.ch/broken_blog/">
        <![CDATA[Ich habe mir letztes Jahr einen 720p HD Beamer (<a href="http://www.cnet.com.au/projectors/lcd/0,239035421,339272267,00.htm">PT-AX100E</a>) bei <a href="http://www.digitec.ch/">Digitec</a> gekauft, für den stolzen Preis von etwa 2000SFr (passend zu der PS3). Schon nach 2 Monaten hat er nicht mehr richtig funktioniert, und schaltete nach 5 Minuten betrieb einfach wieder aus. Anstatt Digitec oder Panasonic war aber die <a href="http://www.johnlay.ch/">John Lay Electronics AG</a> für die Reperatur zuständig. Nach einem Mail sagten die mir, dass ihnen den Fehler bekannt wäre und ich solle ihnen den Beamer zuschicken. Eine Woche bangte ich darum, ob ich das Ding jemals wieder sehen werde, Geschichten aus der C't ("Achtung Kunde!") im Hinterkopf . Ich sah ihn auch nicht wieder, sondern war nach der besagten Woche im Besitz eines brandneuen Austauschgerätes. w00t!<br /><br />Nun, etwa 1 1/2 Jahre später, hatte dieses Gerät fast den gleichen Fehler. Ich schrieb wieder ein Mail, ala "Beamer putt", sie "schicken!", ich "ok!", nach 2 Tagen sie "Gerät in Kulanz repariert, ist auf der Post". Woooow!<br /><br />Der Beamer ist Top, aber dieser Bug nervt doch ungemein. Normalerweise würde ich kein Panasonic mehr kaufen, bei einem so fehlerhaft produziertem Gerät. <br />Bei so einem schnellen, freundlichen und effizientem Support könnte ich aber das nächste mal wieder auf Panasonic setzen. <br /><br />Danke, John Lay!<br />]]>
        
    </content>
</entry>

</feed>

