<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Carpe Teknus</title>
	<atom:link href="http://www.carpeteknus.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.carpeteknus.com</link>
	<description>[lang_es]Aprovecha la tecnología[/lang_es][lang_en]Seize Technology[/lang_en]</description>
	<lastBuildDate>Thu, 14 Jan 2010 23:13:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>6 Months Later</title>
		<link>http://www.carpeteknus.com/2010/01/14/6-months-later/</link>
		<comments>http://www.carpeteknus.com/2010/01/14/6-months-later/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 23:13:16 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=55</guid>
		<description><![CDATA[ My last post oulined my next goal within the next 6 months. And that was 6 months ago ( well, sort of). Not it&#8217;s time to look back and do a check up.
Did I get the CAPM credentials? No. Total failure. I did accomplish some goals on the personal level, but this one that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="/wp-content/uploads/2010/01/checklist.jpg"><img src="/wp-content/uploads/2010/01/checklist-225x300.jpg" alt="" title="Checklist" width="225" height="300" class="alignleft size-medium wp-image-54" style="margin:15px"/></a> My last post oulined my next goal within the next 6 months. And that was 6 months ago ( well, sort of). Not it&#8217;s time to look back and do a check up.</p>
<p>Did I get the CAPM credentials? No. Total failure. I did accomplish some goals on the personal level, but this one that I set for my career path wasn&#8217;t done. Heck, I haven&#8217;t even finish the book!. I&#8217;m about 20% done with it, and at this pace I&#8217;ll finish it in 2 months. </p>
<p>I guess I&#8217;ll have to take some time off and use it exclusively to study. Anybody with a good study group? <br />
One of my strategies is to force myself to do things is by paying something towards it. Like a gym mebership, wich I used for about a year regulary. So, I guess I&#8217;ll have to pay for a 1 month course CAPM cert preparation. Any other ideas?</p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2010/01/14/6-months-later/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Project Management</title>
		<link>http://www.carpeteknus.com/2009/06/11/project-management/</link>
		<comments>http://www.carpeteknus.com/2009/06/11/project-management/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 18:17:59 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=46</guid>
		<description><![CDATA[One of the first things I want to improve is in Project Management.
Being in the tech field for almost 10 years I&#8217;ve seen many projects being sunk by bad &#8220;PM&#8217;ing&#8221;. Also many of them saved from disaster because of PM. PM as I see it goes beyond the administrative part of the projects that I [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.pmi.org/" target="_blank"><img src="/wp-content/uploads/2009/06/pmilogo.gif" alt="pmilogo" title="pmilogo" width="164" height="52" class="alignleft size-full wp-image-47" style="margin:15px" /></a>One of the first things I want to improve is in Project Management.<br />
Being in the tech field for almost 10 years I&#8217;ve seen many projects being sunk by bad &#8220;PM&#8217;ing&#8221;. Also many of them saved from disaster because of PM. PM as I see it goes beyond the administrative part of the projects that I was lead to believe in college. I see it now as a discipline that involves many skills, ranging from personal skills such as organization, negotiation, empathy, adaptation, to technical skills such as monitoring, planning, delivering, etc.<br />
As a first step to improve myself on this area, I&#8217;ve decided to get involved with the organization recognized as the worldwide authority in Project Management: The <a href="http://www.pmi.org/" target="_blank">PMI</a>.<br />
I&#8217;ve just got the membership and will be pursuing the <a href="http://www.pmi.org/CareerDevelopment/Pages/AboutCredentialsCAPM.aspx" target="_blank">CAPM®</a> credentials as my first objective for the next 6 months.</p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2009/06/11/project-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Me, Revisited.</title>
		<link>http://www.carpeteknus.com/2009/06/10/me-revisited/</link>
		<comments>http://www.carpeteknus.com/2009/06/10/me-revisited/#comments</comments>
		<pubDate>Wed, 10 Jun 2009 21:46:10 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=44</guid>
		<description><![CDATA[
(Me 2.0 was already taken when I thought about it!)
Today, in my 31st birthday, I decided to start again on the things I&#8217;ve left aside. Change is always good. Painful most of the times, but good at the end. Specially when that change involves better things. So first things first, I&#8217;m gonna state 3 main [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/wp-content/uploads/2009/06/fund_objective-300x295.gif" alt="Goal" title="Goal" width="300" height="295" class="alignnone size-medium wp-image-43"  style="margin: 15px" align="left" /><br />
(Me 2.0 was already taken when I thought about it!)<br />
Today, in my 31st birthday, I decided to start again on the things I&#8217;ve left aside. Change is always good. Painful most of the times, but good at the end. Specially when that change involves better things. So first things first, I&#8217;m gonna state 3 main goals: 1 year, 5 years and 10 years. Then I&#8217;ll draw objectives for each one in order to measure progress. Finally, biweekly or monthly review will take place.<br />
Stay tuned, good things are on the way!</p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2009/06/10/me-revisited/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>New Windows unveiled</title>
		<link>http://www.carpeteknus.com/2008/10/27/new-windows-unveiled/</link>
		<comments>http://www.carpeteknus.com/2008/10/27/new-windows-unveiled/#comments</comments>
		<pubDate>Tue, 28 Oct 2008 00:53:09 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[New Stuff]]></category>
		<category><![CDATA[[lang_es]Eventos[/lang_es][lang_en]Events[/lang_en]]]></category>
		<category><![CDATA[Azure]]></category>
		<category><![CDATA[pdc]]></category>
		<category><![CDATA[pdc2008]]></category>
		<category><![CDATA[windows azure]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=35</guid>
		<description><![CDATA[
The wait is over and we have the new windows novelty: Windows Azure. It&#8217;s Microsoft&#8217;s approach to the &#8220;new&#8221; could computing.
Will continue posting about it as soon as i finish some sessions I&#8217;m attending (bt not putting too much attention thou).
Still Azure will be in Beta (CTP) stage until late 2009 possibly, but we the [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.azure.com/" title="Windows Azure"><img src="http://www.carpeteknus.com///mnt/w0704/d35/s33/b027a463/www/carpeteknus.com///wp-content/uploads/2008/10/azure.jpg" alt="azure.jpg" /></a></p>
<p>The wait is over and we have the new windows novelty: Windows Azure. It&#8217;s Microsoft&#8217;s approach to the &#8220;new&#8221; could computing.<br />
Will continue posting about it as soon as i finish some sessions I&#8217;m attending (bt not putting too much attention thou).</p>
<p>Still Azure will be in Beta (CTP) stage until late 2009 possibly, but we the fortunate attendees of PDC2008 will be the first ones to get an account to test. I&#8217;ll be posting about that too (hopefully the accounts will be ready next week).</p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2008/10/27/new-windows-unveiled/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting ready for PDC2008</title>
		<link>http://www.carpeteknus.com/2008/10/26/getting-ready-for-pdc2008/</link>
		<comments>http://www.carpeteknus.com/2008/10/26/getting-ready-for-pdc2008/#comments</comments>
		<pubDate>Sun, 26 Oct 2008 20:12:59 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=31</guid>
		<description><![CDATA[ For the first time I&#8217;ll be attending one of Microsoft&#8217;s biggest event, PDC2008.
I&#8217;ll be in LA from monday to thursday trying to get a grip of the newest MS gossip Microsoft Strata.
No Tags]]></description>
			<content:encoded><![CDATA[<p><img src="http:/wp-content/uploads/2008/10/pdc.png" alt="PDc2008" style="margin: 15px" align="left" /> For the first time I&#8217;ll be attending one of Microsoft&#8217;s biggest event, <a href="http://microsoftpdc.com/Default.aspx" title="PDC Website" target="_blank">PDC2008</a>.</p>
<p>I&#8217;ll be in LA from monday to thursday trying to get a grip of the newest MS gossip <a href="http://wordpress.com/tag/microsoft-strata/" title="Strata">Microsoft Strata</a>.</p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2008/10/26/getting-ready-for-pdc2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Art of Presentation</title>
		<link>http://www.carpeteknus.com/2008/01/25/the-art-of-presentation/</link>
		<comments>http://www.carpeteknus.com/2008/01/25/the-art-of-presentation/#comments</comments>
		<pubDate>Sat, 26 Jan 2008 00:42:44 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=29</guid>
		<description><![CDATA[There hasn&#8217;t been any fear as spread as speaking in public. I remember my days in college struggling with simple presentations to get a good score in a course. But in real life, there are no such things a simple presentations. Wether is a job interview or an investors meeting, everyone is involved several times [...]]]></description>
			<content:encoded><![CDATA[<p><img align="left" src="http:/wp-content/uploads/2008/01/jobs.jpg" alt="Steve Jobs with MacBook Air" style="margin: 15px" />There hasn&#8217;t been any fear as spread as speaking in public. I remember my days in college struggling with simple presentations to get a good score in a course. But in real life, there are no such things a simple presentations. Wether is a job interview or an investors meeting, everyone is involved several times in one kind of presentation.</p>
<p>In the last years there has been some key presentations that have changed, and amazed, the world of technology. And Steve Jobs has been present in many of them, from the Mac redesign, the iPhone, and the latest MacBook Air. He is simply a master of presentations, and here is a very interesing article about simple elements he use to amaze the masses and deliver a great presentation:</p>
<p><a target="_blank" href="http://www.businessweek.com/smallbiz/content/jan2008/sb20080125_269732.htm" title="Deliver a Presentation like Steve Jobs">Deliver a Presentation like Steve Jobs</a></p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2008/01/25/the-art-of-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MSDN Events : Visual Studio 2008/MSSQL Server 2008/Windows 2008</title>
		<link>http://www.carpeteknus.com/2008/01/23/msdn-events-visual-studio-2008mssql-server-2008windows-2008/</link>
		<comments>http://www.carpeteknus.com/2008/01/23/msdn-events-visual-studio-2008mssql-server-2008windows-2008/#comments</comments>
		<pubDate>Wed, 23 Jan 2008 18:49:26 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[[lang_es]Eventos[/lang_es][lang_en]Events[/lang_en]]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=27</guid>
		<description><![CDATA[Heroes Happen Here.
That&#8217;s the new slogan for the launch of the new 2008 products.
Launch events schedule is already here, and by attending any event you&#8217;ll receive a free personal copy of all products.
 For registration go to:
http://www.microsoft.com/heroeshappenhere/default.mspx
See you in San Diego&#8217;s!
No Tags]]></description>
			<content:encoded><![CDATA[<p><img align="left" src="/wp-content/uploads/2008/01/hero_event.jpg" alt="hero_event.jpg" />Heroes Happen Here.<br />
That&#8217;s the new slogan for the launch of the new 2008 products.<br />
Launch events schedule is already here, and by attending any event you&#8217;ll receive a free personal copy of all products.</p>
<p> For registration go to:</p>
<p><a href="http://www.microsoft.com/heroeshappenhere/default.mspx">http://www.microsoft.com/heroeshappenhere/default.mspx</a></p>
<p>See you in San Diego&#8217;s!</p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2008/01/23/msdn-events-visual-studio-2008mssql-server-2008windows-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Drive/Device Encryption: TrueCrypt</title>
		<link>http://www.carpeteknus.com/2007/12/14/drivedevice-encryption-truecrypt/</link>
		<comments>http://www.carpeteknus.com/2007/12/14/drivedevice-encryption-truecrypt/#comments</comments>
		<pubDate>Fri, 14 Dec 2007 23:12:46 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[[lang_es]Seguridad[/lang_es][lang_en]Security[/lang_en]]]></category>

		<guid isPermaLink="false">http://www.carpeteknus.com/?p=23</guid>
		<description><![CDATA[During this week I&#8217;ve been trying TrueCrypt(http://www.truecrypt.org/) for file/drive encryption and here are my observations:
The best feature of this software is that is the price: free, zero, nada,  nulo, nitchs. Thank God for open source programmers.
All the feature list can be found at the website, so I won&#8217;t go deep on explanations. I&#8217;ll just [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/wp-content/uploads/2007/12/truecrypt.gif" alt="truecrypt.gif" />During this week I&#8217;ve been trying TrueCrypt(<a href="http://www.truecrypt.org/">http://www.truecrypt.org/</a>) for file/drive encryption and here are my observations:</p>
<p>The best feature of this software is that is the price: free, zero, nada,  nulo, nitchs. Thank God for open source programmers.<BR><br />
All the feature list can be found at the website, so I won&#8217;t go deep on explanations. I&#8217;ll just say that is a very robust software offering several encryption algorithms (<a href="http://www.truecrypt.org/docs/?s=aes"><span style="color: #006699">AES-256</span></a>, <a href="http://www.truecrypt.org/docs/?s=serpent"><span style="color: #006699">Serpent</span></a>, and <a href="http://www.truecrypt.org/docs/?s=twofish"><span style="color: #006699">Twofish</span></a>) and three hash functions (RIPEMD-160, SAH-1, Whirlpool) all of them yet to be broken (rumors about SAH-1 being compromised have circulated the net but no practical example yet, mathematical and conspiration theories only). Additinally, you can stack the algorithms to create a more complex result (slower process but theorically more secure), so the possible combinations with the corresponding benchmark in my machine are:<BR><br />
<img src="/wp-content/uploads/2007/12/benchmark1.JPG" alt="benchmark1.JPG" /><br />
(For comparison, unencrypted IDE drives range from 60 to 90MB/s, SATA150 from 90 to 130MB/s and SATA300 from 120 to 200MB/s)<BR><br />
 But what concern us about it is the next two features: real time encryption and virtual disk/device configuration.<BR><br />
 Virtual disk encryption means you can create a file and mount it as a volume that creates a new drive in windows. While device encryption means you can configure the whole storage device (disk, volume, usb drive, et al) to be encrypted.<BR><br />
 Real time encryption means that all encryption work is done on memory, and transparent for the user. You just configure the disk and voila! you have a new drive letter where you can read/write without noticing it&#8217;s being encrypted.<BR><br />
 I tested with one virtual disk (Quang didn;t allow me to format the disk I borrowed) and here are my impressions:<BR><br />
 I created a 10GB virtual file with the AES-Twofish encryption and whirlpool hash and tested the following scenarios:<BR><br />
<UL><br />
<LI>big files read/write<br />
<LI>network read/write<br />
<LI>VPN accessed (mounted the file located @ the office in my home computer )<br />
<LI>Media play (mp3, video)<br />
</UL><br />
 Locally I didn&#8217;t notice any slowness in the system. Also file access was very quick (22 MB/s is more than needed for file storage) no more noticeable slowness than any other of my drives. Where i found it &#8220;slow&#8221; was thru the vpn. And that&#8217;s due to the network for sure (around 2MB/min transfer speed)<BR><br />
 The virtual file gives the flexibility to move around the file and mount it wherever it&#8217;s needed. But since I was greedy enough to create a 10GB file I couldn&#8217;t put it in a DVD to mount it from there (yes, suposeddly you can mount files from DVD)<BR><br />
 So, in conclusion, I consider this a very good candidate to encrypt our backups and/or personal/proyect folders. This software doesn&#8217;t encrypt OS drives because it can&#8217;t be booted, but there is a work around using bootable CDs wich aren&#8217;t very useful for our case.<BR><br />
 Next time I&#8217;ll review another free software that encrypts all drives an boot the OS, thus having all data in the machine encrypted.<BR></p>
No Tags]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2007/12/14/drivedevice-encryption-truecrypt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Security: Salting, #2 &#8211; Securing User Passwords</title>
		<link>http://www.carpeteknus.com/2007/09/28/password-security-salting-2-securing-user-passwords/</link>
		<comments>http://www.carpeteknus.com/2007/09/28/password-security-salting-2-securing-user-passwords/#comments</comments>
		<pubDate>Fri, 28 Sep 2007 21:01:37 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>
<category>password</category><category>salt</category><category>security</category><category>seguridad</category>
		<guid isPermaLink="false">http://www.carpeteknus.com/?p=15</guid>
		<description><![CDATA[In today&#8217;s internet age, the number of user accounts needed for a &#8220;normal&#8221; person is enormous. Think for a moment about all the username/password combinations you use: work , personal email account, personal spammable email account, cable/sat company, phone company, all those forums you read, all of your online banking accounts, and a very long [...]]]></description>
			<content:encoded><![CDATA[<p><img align="left" src="http://www.carpeteknus.com/wp-content/uploads/2007/09/securepass.jpg" alt="Secure your passwords" />In today&#8217;s internet age, the number of user accounts needed for a &#8220;normal&#8221; person is enormous. Think for a moment about all the username/password combinations you use: work , personal email account, personal spammable email account, cable/sat company, phone company, all those forums you read, all of your online banking accounts, and a very long etc. Now think how many of you use the same password for 2 or more accounts? If you use a different one for every account, chances are you are a genius with an IQ higher than the normal user. If not, don&#8217;t worry, you are just a normal person, either very thrustful or very fool, you decide. And also you are in the right place to learn something useful today.</p>
<p>The assumption that people use the same user/password in several accounts gives attackers an advantage: they don&#8217;t have to break into your bank to get your info, they just have to get your username/acount from that shady forum you suscribed 6 months ago.</p>
<p>To prevent this kind of attack, and at the same time prevent our head to explode for all informatino we need to memorize, there is a very simple trick to allow us to use the &#8220;same&#8221; password for every account we have, but having the peace of mind that by subscribing to that forum with lots and lots of torrent files you won&#8217;t be as exposed to account stealing as the normal user.</p>
<p>The solution is to use an algorithm to create our passwords, simple enouhg for us to remember, but giving a complex enough result to have different passwords in every one of our accounts.</p>
<p>First, we start with a &#8220;base&#8221; password. Something we&#8217;ll always remember. It could be your current password you use for all your accounts <img src='/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . Let&#8217;s say for example, that we use &#8220;123mambo&#8221;. That itself could be a very good password: characters and numbers, not relating to anything specific or giving information about us. But you shouldn&#8217;t use it for all of your accounts. So let&#8217;s add a simple process to customize it for all of our accounts.</p>
<p>For every website/place we need a password, we take our &#8220;base&#8221; password, and add some of the letters directly from the name of that site and create something unique for all websites. That&#8217;s it&#8230; simple, right? Let&#8217;s see how it works.<br />
the characters I&#8217;ll use to &#8220;salt&#8221; my password will be the 1st, 2nd and 5th letters of the site&#8217;s name, and the total number of characters in the name.</p>
<p>Let&#8217;s see how it works:<br />
take www.hotmail.com for example. Applying my previously decided algorithm, the pasword for my hotmail account would be:<br />
&#8220;123mambo&#8221; + &#8220;h&#8221; (1st char) + &#8220;o&#8221; (2nd char) + &#8220;a&#8221; (5th char) + 7 (&#8220;hotmail&#8221; = 7 chars) = 123mambohoa7<br />
Now let&#8217;s create the password for a yahoo account:<br />
www.yahoo.com<br />
&#8220;123mambo&#8221; + &#8220;y&#8221; (1st char) + &#8220;a&#8221; (2nd char) + &#8220;o&#8221; (5th char) + 5 (&#8220;yahoo&#8221; = 5 chars) = 123mamboyao5<br />
and what about our newspaper subscription?<br />
www.nytimes.com<br />
&#8220;123mambo&#8221; + &#8220;n&#8221; (1st char) + &#8220;y&#8221; (2nd char) + &#8220;m&#8221; (5th char) + 7 (&#8220;nytimes&#8221; = 7 chars) = 123mambonym7</p>
<p><strong>Some other website examples and their results:</strong><br />
www.mymail.com &#8211; &#8220;123mambomyi6&#8243;<br />
www.unitedbank.com &#8211; &#8220;123mamboune10&#8243;<br />
www.bankofcalifornia.com &#8211; &#8220;123mambobao16&#8243;<br />
www.usabank.com &#8211; &#8220;123mambousa7&#8243;<br />
Microsoft Money &#8211; &#8220;123mambomio14&#8243;<br />
Outlook &#8211; &#8220;123mambooul7&#8243;<br />
Time Reporter &#8211; &#8220;123mambotir12&#8243;</p>
<p>So, as you can see, we can get pretty much secure passwords without the hassle of using too much of our memory.</p>
<p>I hope this one was useful for you. Be creative, and please don&#8217;t use 123mambo &#8217;cause I already use it (j/k) but above all, be safe.</p>
<a href="http://www.carpeteknus.com/index.php?tag=password" rel="tag">password</a>, <a href="http://www.carpeteknus.com/index.php?tag=salt" rel="tag">salt</a>, <a href="http://www.carpeteknus.com/index.php?tag=security" rel="tag">security</a>, <a href="http://www.carpeteknus.com/index.php?tag=seguridad" rel="tag">seguridad</a>]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2007/09/28/password-security-salting-2-securing-user-passwords/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Phishing Banamex: How reliable are they?</title>
		<link>http://www.carpeteknus.com/2007/06/05/phishing-banamex-how-reliable-are-they/</link>
		<comments>http://www.carpeteknus.com/2007/06/05/phishing-banamex-how-reliable-are-they/#comments</comments>
		<pubDate>Wed, 06 Jun 2007 00:53:59 +0000</pubDate>
		<dc:creator>Abarajame</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[[lang_es]Seguridad[/lang_es][lang_en]Security[/lang_en]]]></category>
<category>banamex</category><category>bank</category><category>phishing</category><category>security</category><category>seguridad</category>
		<guid isPermaLink="false">http://www.carpeteknus.com/?p=14</guid>
		<description><![CDATA[
Phising is nowadays one of the most effective attack techniques. It consists in obtaining users information thru a fake copy of a real website. Then send messages to users asking to enter their data (login information usually) in that website. That website will allways fail to validate the users, so users try again and again [...]]]></description>
			<content:encoded><![CDATA[<p><a target="_blank" href="http://www.banamex.com" title="banamex.jpg" ><img src="http://www.carpeteknus.com/wp-content/uploads/2007/09/banamex.jpg" alt="banamex.jpg" align="left" border="0" /></a></p>
<p>Phising is nowadays one of the most effective attack techniques. It consists in obtaining users information thru a fake copy of a real website. Then send messages to users asking to enter their data (login information usually) in that website. That website will allways fail to validate the users, so users try again and again until they give up. But by then, users already gave away their info to some stranger just waiting for it to get access to the real websites.</p>
<p>Just last week, I was in my home computer when I realized that something had modified my HOSTS file (see modified content below). That with the intent of getting login information for the online banking system of <a target="_blank" href="http://www.banamex.com.mx">Banamex</a> bank (citi group&#8217;s mexican bank).<br />
If I had any account in <a target="_blank" href="http://www.banamex.com.mx">Banamex</a> and I wouldn&#8217;t realized of the modification, I could&#8217;ve entered my info in that fake website. And then several days later discover some strange transactions in my accounts, starting the lenghty process of recovery from an identity loss (fight with the banks, trying to get the money back, etc).<br />
As that day&#8217;s good action, I decided to inform <a target="_blank" href="http://www.banamex.com.mx">Banamex</a> bank about what happened, waiting at least that they could try to take the fake website down, alert their cusomers, or anything.. but oh deception!<br />
They only let their stupidity arise. And here is the communication I had with them (in spanish because they are a mexican bank, basically I let them know about the attack and they answered me with a customer service phone number so they can give me a better service&#8230; yeah right!):</p>
<p><code><br />
De: Abraham Vargas (XXXXXX@XXXXX.XXX)<br />
Enviado el: Viernes, 25 de Mayo de 2007 01:07 a.m.<br />
Para: Servicio A Clientes (1) [BNMX]<br />
Asunto: Servicio a clientes (Portal 1)<br />
Modulo de Servicio Clientes<br />
Nombre del usuario :ABRAHAM VARGAS<br />
Mail del usuario :XXXX@XXXXXX.XXX<br />
Teléfono del usuario :000<br />
Fax del usuario :000<br />
Dirección del usuario :USA<br />
Colonia del usuario :USA<br />
CP del usuario :92069<br />
Ciudad del usuario :SAN MARCOS CALIFORNIA<br />
Estado del usuario :OTRO<br />
País del usuario :ESTADOS UNIDOS<br />
Tema de contacto :SERVICIOS EN LINEA BANCANET<br />
Comentario del usuario:QUE TAL LES ESCRIBO PORQUE ALGUN VIRUS DE INTERNET CAMBIO LA CONFIGURACION DE MI COMPUTADORA PARA QUE AL INTENTAR ACCESAR EL SITIO DE BANAMEX ACCESARA A LA SIGUIENTE DIRECCION DE IP 189.180.78.75 PARA QUEINVESTIGUEN PORQUE PARECE SER UNA DIRECCION FALSA PARA OBTENER PASSWORDS DE SUS USUARIOS. LA CONFIGURACION COMPLETA QUE CAMBIO FUE EL ARCHIVO HOSTS Y PUSO ESTO EN LUGAR DE MI ARCHIVO ORIGINAL:<br />
189.180.78.75 WWW.BANAMEX.COM<br />
189.180.78.75 BANAMEX.COM<br />
189.180.78.75 WWW.BANCANETEMPRESARIAL.BANAMEX.COM.MX<br />
189.180.78.75 BANCANETEMPRESARIAL.BANAMEX.COM.MX<br />
189.180.78.75 BOVEDA.BANAMEX.COM.MX<br />
189.180.78.75 WWW.BOVEDA.BANAMEX.COM.MX<br />
ESPERO PRONTO PUEDAN ARREGLAR EL PROBLEMA<br />
SALUDOS</code></p>
<p>And the answer was:</p>
<p><code><br />
From: "Atencion Empresarial 3 [BNMX]" (atenempre3@banamex.com)<br />
To: XXXX@XXXXXX.XXX<br />
Subject: SC-Servicio a clientes (Portal 1)<br />
Date: Mon, 28 May 2007 11:30:00 -0500<br />
Estimado Cliente<br />
Buenas tardes, reciba un cordial y afectuoso saludo.<br />
Con el objeto de proporcionarle el mejor servicio , le invitamos a llamar a los teléfonos de atención a clientes (1800 226 2639 (1800 BANAMEX))<br />
Nota:<br />
Este mensaje tiene el carácter de informativo y la falta de recepción de la misma por parte del cliente no implica obligación ni responsabilidad alguna del banco.<br />
** Nota: Le recordamos que Banamex nunca le solicitará información confidencial como su número secreto, password, información personal y de sus cuentas vía correo electrónico. Si recibes un correo solicitando esta información, sospecha de su origen, no conteste o de click en ligas de estos correos y reenvíelo a la dirección de correo electrónico giso@banamex.com<br />
Gracias y Saludos!!<br />
ATENCION EMPRESARIAL 3<br />
Tel.: 1800 226 2639 (1800 BANAMEX)<br />
La información contenida en este mensaje esta destinada únicamente para el uso de la persona o entidad identificada como receptor. Cualquier uso no autorizado es responsabilidad del receptor. Si usted recibe este mensaje por error favor de notificarlo inmediatamente al remitente y hacer caso omiso de la información ahí contenida.<br />
The information contained in this e-mail message is only for purposes of the intended recipient. Any unauthorized use is responsibility of the receiver. If you have received this e-mail message in error, please immediately notify the sender and delete it from your computer.</code><br />
What can we wait from a customer service like that?<br />
Thank you, but that&#8217;s useless to me&#8230; so, do you have an account with Banamex?</p>
<a href="http://www.carpeteknus.com/index.php?tag=banamex" rel="tag">banamex</a>, <a href="http://www.carpeteknus.com/index.php?tag=bank" rel="tag">bank</a>, <a href="http://www.carpeteknus.com/index.php?tag=phishing" rel="tag">phishing</a>, <a href="http://www.carpeteknus.com/index.php?tag=security" rel="tag">security</a>, <a href="http://www.carpeteknus.com/index.php?tag=seguridad" rel="tag">seguridad</a>]]></content:encoded>
			<wfw:commentRss>http://www.carpeteknus.com/2007/06/05/phishing-banamex-how-reliable-are-they/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
