<?xml version="1.0"?>
<rss version="2.0.">
  <channel>
    <title>Advogato blog for metaur</title>
    <link>http://www.advogato.org/person/metaur/</link>
    <description>Advogato blog for metaur</description>
    <language>en-us</language>
    <generator>mod_virgule</generator>
    <pubDate>Fri, 16 May 2008 13:48:40 GMT</pubDate>
    <item>
      <pubDate>Sat, 5 Jan 2008 22:31:15 GMT</pubDate>
      <title>5 Jan 2008</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=62</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=62</guid>
      <description>&lt;p&gt;&#xD;
Here is a little status report, for those who wonder where I&#xD;
went off to. I have worked at&#xD;
&lt;a href="http://secunia.com/" &gt;Secunia&lt;/a&gt; for a year and two&#xD;
months so far, and I have done&#xD;
tasks that hopefully were helpful to my beloved open source&#xD;
community:&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;wrote hundreds of &lt;a&#xD;
href="http://secunia.com/advisories/23528/"&gt;security&#xD;
advisories&lt;/a&gt; (many of them for open-source applications)&#xD;
&lt;li&gt;performed my own &lt;a&#xD;
href="http://secunia.com/secunia_research/"&gt;security&#xD;
research&lt;/a&gt; and found vulnerabilities in evolution,&#xD;
sylpheed/sylpheed-claws/claws mail, vim and others&#xD;
&lt;/ul&gt;&#xD;
&#xD;
&lt;p&gt; &lt;p&gt;&#xD;
Recently I have visited &lt;a&#xD;
href="http://events.ccc.de/congress/2007/Main_Page"&gt;The 24th&#xD;
Chaos Communication Congress (24C3)&lt;/a&gt; in &lt;a&#xD;
href="http://wikitravel.org/en/Berlin"&gt;Berlin&lt;/a&gt;, I have&#xD;
seen other things in Berlin for a few days, I have read&#xD;
non-fiction books about astronomy and the history of ideas,&#xD;
and listened to popular music performed by &lt;a&#xD;
href="http://www.fridaybridge.net/"&gt;Friday Bridge&lt;/a&gt; and &lt;a&#xD;
href="http://en.wikipedia.org/wiki/Evert_Taube"&gt;Evert&#xD;
Taube&lt;/a&gt; (which is nice to indulge in, since those fields&#xD;
of endeavour basically are my interests with some room for&#xD;
variation). After returning from Berlin, I have a really&#xD;
horrible cold (which is not one of my bigger interests).&#xD;
&#xD;
&lt;p&gt; &lt;a href="http://www.handgranat.org/Horace" &gt;Ulf kan l&amp;auml;sa&lt;/a&gt;</description>
    </item>
    <item>
      <pubDate>Sun, 18 Mar 2007 21:23:30 GMT</pubDate>
      <title>18 Mar 2007</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=61</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=61</guid>
      <description>"Hell is other people." -- Jean-Paul Sartre&#xD;
&#xD;
&lt;p&gt; &lt;ul&gt;&#xD;
&lt;li&gt;&lt;a&#xD;
href="http://bugzilla.elinks.cz/show_bug.cgi?id=869"&gt;ELinks&lt;/a&gt;&#xD;
|| &lt;a&#xD;
href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/afs/src/milko/bos/bosserver.c"&gt;bosserver&#xD;
in OpenBSD&lt;/a&gt;&#xD;
&lt;li&gt;Speaking of which: &lt;a href="http://www.openbsd.org/" &gt;Only&#xD;
&lt;i&gt;two&lt;/i&gt; remote holes in the default install, in more than&#xD;
10 years!&lt;/a&gt; (Great work, Core!)&#xD;
&lt;li&gt;more than halfway through improving the Wikitravel&#xD;
entries for midsized Swedish towns (Helsingborg with its&#xD;
harbour and ferries is especially recommended)&#xD;
&lt;li&gt;&lt;a href="http://www.handgranat.org/Horace" &gt;Veckans l&amp;aring;t&#xD;
(enligt U.)&lt;/a&gt;&#xD;
&lt;/ul&gt;&#xD;
</description>
    </item>
    <item>
      <pubDate>Sat, 9 Dec 2006 21:21:52 GMT</pubDate>
      <title>9 Dec 2006</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=60</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=60</guid>
      <description>&lt;a href="http://secunia.com/advisories/22638/" &gt;ELOG Multiple&#xD;
Vulnerabilities&lt;/a&gt; (my last security audit for Debian)&lt;br&gt;&#xD;
two new &lt;a href="http://www.gnupg.org/" &gt;GnuPG&lt;/a&gt; vulns&#xD;
(found by other people), so make sure that you upgrade&lt;br&gt;&#xD;
$NEWJOB is good but takes most of my energy, some edits for&#xD;
Wikitravel though&lt;br&gt;&#xD;
Malm&amp;ouml; is nice because it's different from Stockholm or&#xD;
Link&amp;ouml;ping&lt;br&gt;&#xD;
Hesse's "Steppenwolf" seems like a good and true novel so far&lt;p&gt;&#xD;
&amp;lt;/blog&amp;gt;&#xD;
</description>
    </item>
    <item>
      <pubDate>Sun, 15 Oct 2006 20:38:57 GMT</pubDate>
      <title>15 Oct 2006</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=59</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=59</guid>
      <description>&lt;b&gt;(webbsurven) Apache modules non-security &#xD;
segfaults&lt;/b&gt;&lt;br&gt;&#xD;
&lt;a href="http://issues.apache.org/bugzilla/show_bug.cgi?&#xD;
id=40733" &gt;mod_proxy_ftp: segfaults (NULL deref.) when FTP &#xD;
server sends back no spaces in LIST reply&lt;/a&gt;&lt;br&gt;&#xD;
&lt;a href="http://issues.apache.org/bugzilla/show_bug.cgi?&#xD;
id=40749" &gt;mod_mime_magic: magic file with string and "%n" &#xD;
causes Apache child to crash&lt;/a&gt;&#xD;
&#xD;
&lt;p&gt; &lt;p&gt; &lt;b&gt;two requests from Debian&lt;/b&gt;&lt;br&gt;&#xD;
&lt;a href="http://secunia.com/advisories/22313/" &gt;zabbix&lt;/a&gt; -&#xD;
 &#xD;
&lt;a href="http://secunia.com/advisories/21579/" &gt;streamripper&lt;/a&gt;&#xD;
&#xD;
&lt;p&gt; &lt;p&gt; &lt;b&gt;misc.&lt;/b&gt;&lt;br&gt;&#xD;
&lt;a href="http://www.netadmin.se/" &gt;old job&lt;/a&gt; =&amp;gt; new &#xD;
job&lt;br&gt;&#xD;
general elections 2006 - voted for &lt;a href="http://www.folkpartiet.se/" &gt;these guys&lt;/a&gt;&#xD;
&#xD;
&lt;p&gt; &lt;p&gt; &lt;b&gt;Ulf's YouTube top 6 music video countdown, week &#xD;
41&lt;/b&gt; (lots of italodisco)&lt;br&gt;&#xD;
1. &lt;a href="http://www.youtube.com/watch?&#xD;
v=uJ4nmG39QXo" &gt;Digital Emotion - Go Go Yellow &#xD;
Screen&lt;/a&gt;&lt;br&gt;&#xD;
2. &lt;a href="http://www.youtube.com/watch?&#xD;
v=8KF9tQ0uwns" &gt;Lucia - Marinero&lt;/a&gt;&lt;br&gt;&#xD;
3. &lt;a href="http://www.youtube.com/watch?v=-&#xD;
pKxVXuDk7I" &gt;Squash Gang - I Want An Illusion&lt;/a&gt;&lt;br&gt;&#xD;
4. &lt;a href="http://www.youtube.com/watch?&#xD;
v=EOVajiocC4Q" &gt;Plastic Bertrand - Ca Plane Pour Moi&lt;/a&gt;&lt;br&gt;&#xD;
5. &lt;a href="http://www.youtube.com/watch?v=ouXcB6Kve-&#xD;
c" &gt;Via &#xD;
Verdi - Diamond&lt;/a&gt;&lt;br&gt;&#xD;
6. &lt;a href="http://www.youtube.com/watch?&#xD;
v=kcahxye2Urw" &gt;Wish Key - Orient Express&lt;/a&gt;&#xD;
</description>
    </item>
    <item>
      <pubDate>Mon, 7 Aug 2006 21:30:52 GMT</pubDate>
      <title>7 Aug 2006</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=58</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=58</guid>
      <description>&lt;a href="http://www.debian.org/security/2006/dsa-1129" &gt;osiris format string
bugs&lt;/a&gt;
( &lt;a href="http://secunia.com/advisories/21257/" &gt;s&lt;/a&gt; +
&lt;a href="http://www.frsirt.com/english/advisories/2006/3072" &gt;f&lt;/a&gt; +
&lt;a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-3120" &gt;nvd&lt;/a&gt; )
remote vulnerabilities in security-improving server, popular enough to have
&lt;a href="http://books.slashdot.org/article.pl?sid=05/08/16/0455224" &gt;half
a book&lt;/a&gt; written about it&lt;br&gt;
old freshclam bug updated in
&lt;a href="http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html" &gt;Mac
OS X&lt;/a&gt; + there is a
&lt;a href="http://www.kb.cert.org/vuls/id/599220" &gt;US-CERT Vulnerability Note&lt;/a&gt; about
it&lt;br&gt;
&lt;a href="http://browserfun.blogspot.com/" &gt;Browser Fun&lt;/a&gt; (by HD Moore),
&lt;a href="http://secunia.com/advisories/20686/" &gt;Microsoft Excel fun&lt;/a&gt;
(by lots of people) -- isn't it great how the security of really critical programs
used by many millions of people world-wide daily suck horribly?&lt;br&gt;
&lt;a href="http://www.sitic.se/" &gt;gimme gimme gimme the style police&lt;/a&gt;&lt;p&gt;
&lt;a href="http://wikitravel.org/en/Tokyo" &gt;&lt;b&gt;Tokyo highlights:&lt;/b&gt;&lt;/a&gt;
(I'm not going to write any descriptions, because I'm really not a travel writer,
but these places and activities are heartily recommended)&lt;br&gt;
Tokyo Metropolitan Government Office and nearby buildings -
Fuji Television Japan Broadcast Center observatory (great architecture) -
eating very fresh sushi in a restaurant next to Tsukiji Central Fish Market -
Golden Gai -
Ueno-koen with its various museums and a zoo -
a live show in Roppongi with &lt;a href="http://www11.plala.or.jp/piana/" &gt;Piana&lt;/a&gt;
and other artists (found &lt;a href="http://www.tokyogigguide.com/" &gt;here&lt;/a&gt;) -
a live show in Shibuya with &lt;a href="http://www.ymck.net/" &gt;YMCK&lt;/a&gt;
and other bands (found there as well) -
Senso-ji and Asakusa-jinja -
Love Hotel Hill -
Takeshita st. and Harajuku st. -
Design Festa -
Roppongi Hills -
Shibuya -
Yoyogi-koen -
National Museum of Emerging Science and Innovation -
Imperial Palace East Garden -
Yasukuni-jinja -
Sony Building -
Piss Alley -
Akihabara (somewhat overrated) -
and much more.&lt;br&gt;
&lt;a href="http://www.wikitravel.org/en/Kyoto" &gt;&lt;b&gt;Kyoto:&lt;/b&gt;&lt;/a&gt;
Nanzen-ji -
Nijo-jo -
Kyoto train station (huge and modern).&lt;p&gt;
&amp;lt;bevara till efterv&#xE4;rlden&amp;gt;&lt;br&gt;
mrx: - De f&#xF6;rsta 33 &#xE5;ren gick jag mest i skolan samt att jag mobbade de flesta
m&#xE4;nniskor jag tr&#xE4;ffade offentligt. Sj&#xE4;lv d&#xE5;?&lt;br&gt;
&amp;lt;/bevarle eftv&#xE4;rldle&amp;gt;&lt;p&gt;
Both Shakira and Liv Str&#xF6;mquist are computer generated, BTW (by AI researchers who
sold out to the man). It's all a trick to keep people from rioting in the streets.
</description>
    </item>
    <item>
      <pubDate>Mon, 8 May 2006 18:09:32 GMT</pubDate>
      <title>8 May 2006</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=57</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=57</guid>
      <description>Buffer overflow in ClamAV's freshclam client (&lt;a href="http://www.securityfocus.com/bid/17754/discuss" &gt;Securityfocus&lt;/a&gt; || &lt;a href="http://www.clamav.net/security/0.88.2.html" &gt;ClamAV&lt;/a&gt; || &lt;a href="http://www.heise.de/newsticker/result.xhtml?url=/newsticker/meldung/72578" &gt;Heise&lt;/a&gt;)&lt;br&gt;
Not security related overflows in RRDtool (&lt;a href="http://people.ee.ethz.ch/~oetiker/webtools/rrdtool/pub/CHANGES" &gt;1&lt;/a&gt;, &lt;a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=359071" &gt;2&lt;/a&gt;) and &lt;a href="http://sourceforge.net/project/shownotes.php?release_id=415315&amp;amp;group_id=10706" &gt;SoX&lt;/a&gt; (again)&lt;br&gt;
&lt;a href="http://blogs.securiteam.com/" &gt;Securiteam&lt;/a&gt; and &lt;a href="http://www.osvdb.org/blog/" &gt;OSVDB&lt;/a&gt; :: readable blogs about computer security&lt;p&gt;
I've been playing around with ancient &lt;a href="http://en.wikipedia.org/wiki/Revision_control" &gt;version control programs&lt;/a&gt; like SCCS (in the form of &lt;a href="http://cssc.sourceforge.net/" &gt;GNU CSSC&lt;/a&gt;) and &lt;a href="http://www.gnu.org/software/rcs/" &gt;RCS&lt;/a&gt;, and it's interesting to note how many of the not-so-obvious but still important features were present that early on. Do the current version control systems suffer slightly from &lt;a href="http://www.catb.org/jargon/html/C/creeping-featurism.html" &gt;creeping featurism&lt;/a&gt;? Discuss among yourselves. Rhetorical question - answer within.&lt;p&gt;
The song "Laughter" by &lt;a href="http://www.thefineartsshowcase.se/" &gt;The Fine Arts Showcase&lt;/a&gt; is really, really beautiful.&lt;p&gt;
Apart from that, I've mostly been carrying my briefcase to the office.
</description>
    </item>
    <item>
      <pubDate>Tue, 21 Mar 2006 20:38:23 GMT</pubDate>
      <title>21 Mar 2006</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=56</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=56</guid>
      <description>&lt;a href="http://seclists.org/lists/fulldisclosure/2006/Mar/1335.html" &gt;cURL&lt;/a&gt; 7.15.0, 7.15.1, 7.15.2 (SSAG#001) &lt;a href="http://secunia.com/advisories/19271/" &gt;s&lt;/a&gt; + &lt;a href="http://www.frsirt.com/english/advisories/2006/1008" &gt;f&lt;/a&gt;&lt;br&gt;
&lt;a href="http://wikitravel.org/en/Helsinki" &gt;Helsinki&lt;/a&gt; ( Kiasma - Fazer Caf&amp;eacute; - Stockmann - Tavastia/Semifinal - architecture - design ) -- might sound &lt;a href="http://72.14.207.104/search?q=cache:dLYT1WjaX7QJ:avantgardism.blogspot.com/+%22Maria+%C3%85sberg%22+%2Bblogspot&amp;amp;hl=sv&amp;amp;gl=se&amp;amp;ct=clnk&amp;amp;cd=1" &gt;shallow&lt;/a&gt; but that's part of who I am&lt;br&gt;
metamail &lt;a href="http://www.debian.org/security/2006/dsa-995" &gt;again&lt;/a&gt; &lt;a href="http://secunia.com/advisories/18796/" &gt;and&lt;/a&gt; &lt;a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=353539" &gt;again&lt;/a&gt;&lt;br&gt;
Johnny Cash - Astrud Gilberto - The Ramones (taken over someone's record collection) - italodisco&lt;br&gt;
full sentences = evil

</description>
    </item>
    <item>
      <pubDate>Wed, 28 Dec 2005 19:21:48 GMT</pubDate>
      <title>28 Dec 2005</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=55</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=55</guid>
      <description>I haven't done very much free software work since last time either. I did find some &lt;a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=343877" &gt;buffer overflow bugs in webalizer&lt;/a&gt;, but they are only bugs - no vulnerabilities.

&lt;p&gt; There was a new announcement about &lt;a href="http://lists.debian.org/debian-devel-announce/2005/12/msg00013.html" &gt;the architectures in Debian etch&lt;/a&gt;. It will be interesting to see how things finally turn out.

&lt;p&gt; I forgot to write about it earlier, but the US-CERT published &lt;a href="http://www.kb.cert.org/vuls/id/215006" &gt;a vulnerability note&lt;/a&gt; about my old bugs in unace, after the same guy at Secunia Research found about six other products that were affected by the bugs as they incorporated the unace code. The Secunia guy is obviously my biggest fan, and I'll send him a signed photo real soon..

&lt;p&gt; I've almost finished reading &lt;a href="http://www.amazon.com/gp/product/1594480206/qid=1135796199/sr=2-1/ref=pd_bbs_b_2_1/002-9795367-7097667?s=books&amp;amp;v=glance&amp;amp;n=283155" &gt;Beijing Doll&lt;/a&gt;, which I bought in Minneapolis last summer. It's OK but nothing special. I suppose being a punk rock rebel is more of a new idea in China than here in Europe. She'll probably write something better later on, though.

&lt;p&gt; Apart from that, I've mostly been working and celebrating Christmas.

&lt;p&gt; I'm getting very bored of writing here, so I probably won't update this diary very often in the future. Many thanks to those who rated, voted for and e-mailed me about it! It's nice to know that some people appreciate my work for the free/open source software community.

&lt;p&gt; Happy new year,&lt;br&gt;
Ulf
</description>
    </item>
    <item>
      <pubDate>Thu, 1 Dec 2005 19:52:12 GMT</pubDate>
      <title>1 Dec 2005</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=54</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=54</guid>
      <description>&lt;b&gt;OK, so you're a rocket scientist&lt;/b&gt;

&lt;p&gt; I haven't worked on any big Linux project recently. However, I submitted some &lt;a href="http://issues.apache.org/SpamAssassin/show_bug.cgi?id=4707" &gt;bugs&lt;/a&gt; and &lt;a href="http://svn.apache.org/viewcvs.cgi/spamassassin/branches/3.1/spamc/libspamc.c?rev=349278&amp;amp;r1=224585&amp;amp;r2=349278&amp;amp;diff_format=h" &gt;patches&lt;/a&gt; to spamassassin, and I've found &lt;a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=340842" &gt;a buffer overflow vulnerability in unalz&lt;/a&gt; when it extracts ALZ archives. I haven't seen many of those archives, but I like being thorough and check all programs in a category and not just the most popular ones. The unalz bug got average grades from the security reviewing office workers (none of whom could write a simple C program to save their lives).

&lt;p&gt; In more exciting news, Drupal has &lt;a href="http://drupal.org/node/39353" &gt;started using&lt;/a&gt; an HTML filtering library based on my kses library.

&lt;p&gt; I've mostly been busy with my day job. I really like it, as I get to code networking applications which I find much more exciting than web publishing systems and as the tasks are more challenging than in other companies.


&lt;p&gt; &lt;b&gt;That don't impress me much&lt;/b&gt;

&lt;p&gt; As I'm now gainfully employed, you can't write to me at my @student.uu.se e-mail address anymore. You have to use the one at my person page here at Advogato.

&lt;p&gt; "You keep hangin' 'round me / And I'm not so glad you found me / You're still doing things that I gave up years ago"&lt;br&gt;-- Lou Reed

&lt;p&gt; The new Ladytron record was a disappointment! They have changed their style quite a bit and started playing &lt;a href="http://www.google.se/search?hl=sv&amp;amp;q=%22Amadeus+Liszt%22+%2B%22Win+the+race%22&amp;amp;meta=" &gt;overblown&lt;/a&gt; alternative rock with bad melodies and a slick production that may or may not have anything to do with having signed to a big record label recently. It's OK and everything but it's much worse than the other two albums.

&lt;p&gt; The new alternative comic album by the Swede &lt;a href="http://www.matsjonsson.nu/" &gt;Mats Jonsson&lt;/a&gt; is also a departure - much darker, less humour, different subject matter, less stuff that I could relate to - but I quite liked it, especially the "being scared out in the woods" part.


&lt;p&gt; &lt;b&gt;Computer security for laymen&lt;/b&gt;

&lt;p&gt; A &lt;i&gt;race condition&lt;/i&gt; is what occurs when you leave the washing room, enter the pitch black corridor, and the monsters manage to catch you before you reach the light button (which of course destroys all monsters just milliseconds before turning on the light).
</description>
    </item>
    <item>
      <pubDate>Sat, 22 Oct 2005 14:23:50 GMT</pubDate>
      <title>22 Oct 2005</title>
      <link>http://www.advogato.org/person/metaur/diary.html?start=53</link>
      <guid>http://www.advogato.org/person/metaur/diary.html?start=53</guid>
      <description>I have &lt;a href="http://seclists.org/lists/bugtraq/2005/Oct/0204.html" &gt;found&lt;/a&gt; a pretty serious remote buffer overflow in the good old Lynx browser (plus some not &lt;a href="http://lists.gnu.org/archive/html/lynx-dev/2005-09/msg00027.html" &gt;security&lt;/a&gt;-&lt;a href="http://lists.gnu.org/archive/html/lynx-dev/2005-09/msg00028.html" &gt;related&lt;/a&gt; stuff). I have also found remote format string bugs in &lt;a href="http://seclists.org/lists/fulldisclosure/2005/Oct/0210.html" &gt;xine-lib&lt;/a&gt; and in &lt;a href="http://www.debian.org/security/2005/dsa-855" &gt;weex&lt;/a&gt; (the latter was incorrectly reported to have been found by someone else).

&lt;p&gt; &lt;a href="http://www.crash-override.net/nethacklinux.html" &gt;The Nethack Linux distribution&lt;/a&gt; is definitely ready for the desktop ;)

&lt;p&gt; &lt;a href="http://www.vanheusden.com/Linux/audit.html" &gt;Tools &amp;amp; Tips for auditing code&lt;/a&gt; (not for the clueless JT or P&#xD6; people out there though)

&lt;p&gt; I have a new job! I've been studying literature for a while, and the course was really interesting with good teachers and classic but readable books. I didn't really get to know the other students though - they found me really old and talked to me in that dinner-with-Grandpa tone of voice ("Yes, Grandpa, I go to church every Sunday. No, Grandpa, I never listen to any of that sinful jazz music."). Consequently, I've given up on it to work and earn some money again.

&lt;p&gt; "Winter" from the first Tori Amos record is really moving. I've bought new records from Ladytron (!!), Broadcast and Sibiria, but I haven't listened to them enough yet to have an opinion.
</description>
    </item>
  </channel>
</rss>
