<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MattJay Security &#187; Random</title>
	<atom:link href="http://www.mattjaysecurity.com/category/random/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Wed, 02 Feb 2011 17:09:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Missing in Action -&gt; Return to Action</title>
		<link>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 23:56:35 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Random]]></category>
		<category><![CDATA[Web App]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=105</guid>
		<description><![CDATA[So it has been about 6 months since I wrote a blog post and I’ve promised to myself to get back into it for the new year. I miss you all. I guess I should start by explaining my absence from the blogosphere as I had some pretty damn good reasons: I got a new [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.mattjaysecurity.com/wp-content/uploads/2010/12/2010-06-24-13.19.26.jpg#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img class="size-medium wp-image-110 aligncenter" title="2010-06-24 13.19.26" src="http://www.mattjaysecurity.com/wp-content/uploads/2010/12/2010-06-24-13.19.26-e1293754164746-300x195.jpg" alt="" width="300" height="195" /></a>So  it has been about 6 months since I wrote a blog post and I’ve promised  to myself to get back into it for the new year. I miss you all. I guess I  should start by explaining my absence from the blogosphere as I had  some pretty damn good reasons:</p>
<ol>
<li>I got a new job</li>
<li>Said job was 3000 miles away</li>
<li><a href="http://www.google.com/maps?f=d&amp;source=s_d&amp;saddr=new+york,+ny&amp;daddr=San+Francisco,+CA&amp;hl=en&amp;geocode=FXFAbQIdK8KW-yk7CD_TpU_CiTFi_nfhBo8LyA%3BFVJmQAIdKAe0-CkhAGkAbZqFgDH_rXbwZxNQSg&amp;mra=ls&amp;sll=37.0625,-95.677068&amp;sspn=53.741627,95.009766&amp;ie=UTF8&amp;ll=39.774769,-98.173828&amp;spn=52.041139,95.009766&amp;t=h&amp;z=4">I drove the 3000 miles</a></li>
<li>First week in new location my house was broken into and my computers were among the more than $5k worth of stuff stolen.</li>
<li>I had just blown all my money moving 3000 miles =no way to replace computer (or go to BlackHat/Defcon/BSidesLV <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </li>
<li>New job has been keeping me supremely busy in a good way.</li>
</ol>
<p style="text-align: left;">This  whole extravaganza started in May so the summer was kind of a whirlwind  of craziness, the fall was work kicking into overdrive. I’ve kind of  hit my stride at the new job and gotten used to the giant piles of work  so I’m planning on setting aside time to blog again.</p>
<p>The job I started was at <a href="http://www.whitehatsec.com/">WhiteHat Security</a> as a resident appsec bug hunter. Drinking from a fire hose for 6 months  would be no exaggeration as we have a very unique playground of  websites to find/test vulnerabilities on. I’ve found some very high  profile vulnerabilities that I wish I could talk about but I’ll have to  settle for severely obfuscated posts in the future merely describing the  attack vector with all client information withheld.</p>
<p>Since I joined the team we have about doubled in size and gone from the “Operations” department to <a href="http://www.whitehatsec.com/home/services/threat_research.html">WhiteHat’s “Threat Research Center”</a> which just sounds so muchs spiffier and more official.</p>
<p>We also participated pretty avidly in the Google bug bounty program. Mighty successfully I might add: <a href="http://www.google.com/corporate/halloffame.html">Google Security Hall of Fame</a>.  5 people on our team found rewardable bugs in Google apps. I say  rewardable because a number of us found bugs that they didn’t qualify as  rewardable, mostly minor XSS or open redirects.</p>
<p>I might add that this is 5 <strong>so far</strong>, we have a few more emails sitting in their queue and I’ve had a bit of fun with their<a href="http://www.google.com/chromeos/pilot-program-cr48.html"> Cr-48 as a beta tester </a> <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  (more details to come after bug is reported and fixed but this one is a fun one).</p>
<p>So  there is a run down of my absence from the blog world, cliff notes of  course. I did a fair amount of weekend getaways enjoying the west coast  weather.</p>
<p style="text-align: left;">I  hope anybody reading this had a great Christmas and will have a safe  and happy new year. My better half put a grill / smoker under the tree  for me and I’ll be breaking that out to ring in 2011 with some smoked  meat.<br />
So  now that you know one of my resolutions is to start blogging again what  are some of yours? I miss you. You look great by the way.</p>
<p>Cheers,<br />
Matty Jay</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;bodytext=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;notes=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;t=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;annotation=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;t=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;s=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Missing%20in%20Action%20-%3E%20Return%20to%20Action%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Secure Password Win [Random]</title>
		<link>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 22:29:30 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Password]]></category>
		<category><![CDATA[Random]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=98</guid>
		<description><![CDATA[Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh: During a recent password audit at the Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin When Paddy was asked why he had such a [...]]]></description>
			<content:encoded><![CDATA[<p>Usually can&#8217;t stand random chain emails from family/friends but every once in a while there is a good one. Thought I&#8217;d share this laugh:</p>
<blockquote><p>
During a recent password audit at the  Bank of Ireland it was found that Paddy O&#8217;Toole was using the following password: MickeyMinniePlutoHueyLouieDeweyDonaldGoofyDublin</p>
<p>When Paddy was asked why he had such a  long password: he replied &#8221;Bejazus! are yez f*ckin&#8217; stupid? The bank told me password had to be at least 8 characters long and include  one capital&#8221;</p>
<p>Don&#8217;t ever  think you can outwit the Irish!
</p></blockquote>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;bodytext=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;notes=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;t=Secure%20Password%20Win%20%5BRandom%5D" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;annotation=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Secure%20Password%20Win%20%5BRandom%5D&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;title=Secure%20Password%20Win%20%5BRandom%5D" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F&amp;t=Secure%20Password%20Win%20%5BRandom%5D&amp;s=Usually%20can%27t%20stand%20random%20chain%20emails%20from%20family%2Ffriends%20but%20every%20once%20in%20a%20while%20there%20is%20a%20good%20one.%20Thought%20I%27d%20share%20this%20laugh%3A%0D%0A%0D%0ADuring%20a%20recent%20password%20audit%20at%20the%20%20Bank%20of%20Ireland%20it%20was%20found%20that%20Paddy%20O%27Toole%20was%20using%20the%20following" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Secure%20Password%20Win%20%5BRandom%5D%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F02%2Fsecure-password-win-random%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/02/secure-password-win-random/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

