<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Tools/Scripts</title>
	<atom:link href="http://blog.c22.cc/toolsscripts/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.c22.cc</link>
	<description>Because we&#039;re damned if we do, and we&#039;re damned if we don&#039;t!</description>
	<lastBuildDate>Thu, 04 Mar 2010 04:51:21 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Scripto</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-458</link>
		<dc:creator>Scripto</dc:creator>
		<pubDate>Sun, 06 Dec 2009 09:32:10 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-458</guid>
		<description>Nice post..Keep them coming :) Thanks for sharing.</description>
		<content:encoded><![CDATA[<p>Nice post..Keep them coming <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Thanks for sharing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChrisJohnRiley</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-265</link>
		<dc:creator>ChrisJohnRiley</dc:creator>
		<pubDate>Sun, 19 Jul 2009 08:44:21 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-265</guid>
		<description>Ok, I&#039;ve not tested the script under Windows. Shoot me the test string (hide the domain as in your above posts) and I&#039;ll take a look and see if it runs on my test rig.

contact [AT] c22 [DOT] cc</description>
		<content:encoded><![CDATA[<p>Ok, I&#8217;ve not tested the script under Windows. Shoot me the test string (hide the domain as in your above posts) and I&#8217;ll take a look and see if it runs on my test rig.</p>
<p>contact [AT] c22 [DOT] cc</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jim</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-262</link>
		<dc:creator>jim</dc:creator>
		<pubDate>Sun, 19 Jul 2009 01:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-262</guid>
		<description>now I had used a double quote. IT seems to work better on XP

 Data extracted from URL .:

 Base URL &#124;  http://mydomain.de/index.php?eID=tx_cms_showpic
     file &#124;  uploads%2Ftx_mmdamfilelist%2Ftemp_63662056a4.jpg
    width &#124;  400
     wrap &#124;  %3CA%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2FA%
3E
      md5 &#124;  0602930af0dd42d6d998080e120a848e

--------------------------------------------------------------------------------

 Attempting to find a matching MD5
--------------------------------------------------------------------------------

 Test string &#124;  uploads/tx_mmdamfilelist/temp_63662056a4.jpg&#124;400&#124;&#124;&#124;&#124;&#124;&lt;a href=&quot;close();&quot; rel=&quot;nofollow&quot;&gt; &#124; &lt;/A&gt;&#124;&#124;
--------------------------------------------------------------------------------

 Desired MD5 &#124;  0602930af0dd42d6d998080e120a848e
--------------------------------------------------------------------------------

Traceback (most recent call last):
  File &quot;TYPO3EncKeyTool.py&quot;, line 238, in 
    main()
  File &quot;TYPO3EncKeyTool.py&quot;, line 88, in main
    if default == True: # Attempt to check default Typo3 Encryption keys
NameError: global name &#039;default&#039; is not defined</description>
		<content:encoded><![CDATA[<p>now I had used a double quote. IT seems to work better on XP</p>
<p> Data extracted from URL .:</p>
<p> Base URL |  <a href="http://mydomain.de/index.php?eID=tx_cms_showpic" rel="nofollow">http://mydomain.de/index.php?eID=tx_cms_showpic</a><br />
     file |  uploads%2Ftx_mmdamfilelist%2Ftemp_63662056a4.jpg<br />
    width |  400<br />
     wrap |  %3CA%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2FA%<br />
3E<br />
      md5 |  0602930af0dd42d6d998080e120a848e</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p> Attempting to find a matching MD5<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p> Test string |  uploads/tx_mmdamfilelist/temp_63662056a4.jpg|400|||||<a href="close();" rel="nofollow"> | </a>||<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p> Desired MD5 |  0602930af0dd42d6d998080e120a848e<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Traceback (most recent call last):<br />
  File &#8220;TYPO3EncKeyTool.py&#8221;, line 238, in<br />
    main()<br />
  File &#8220;TYPO3EncKeyTool.py&#8221;, line 88, in main<br />
    if default == True: # Attempt to check default Typo3 Encryption keys<br />
NameError: global name &#8216;default&#8217; is not defined</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-261</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Sat, 18 Jul 2009 19:22:41 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-261</guid>
		<description>no, i had tried this at the beginning of testing. When i use the  single quotes I get the Message in the script: 

 Data extracted from URL .:

 Base URL &#124;  http://&#039;http://mydomain.de/index.php?eID=tx_cms_showpic

-------------------------------------------

 Attempting to find a matching MD5
-------------------------------------------

 Test string &#124;  &#124;&#124;&#124;&#124;&#124;&#124;&#124;&#124;
-------------------------------------------

 Desired MD5 &#124;
-------------------------------------------


 Beginning default Encryption Key attack


The  http:// seems to be double....</description>
		<content:encoded><![CDATA[<p>no, i had tried this at the beginning of testing. When i use the  single quotes I get the Message in the script: </p>
<p> Data extracted from URL .:</p>
<p> Base URL |  http://&#8217;http://mydomain.de/index.php?eID=tx_cms_showpic</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p> Attempting to find a matching MD5<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p> Test string |  ||||||||<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p> Desired MD5 |<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p> Beginning default Encryption Key attack</p>
<p>The  http:// seems to be double&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChrisJohnRiley</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-259</link>
		<dc:creator>ChrisJohnRiley</dc:creator>
		<pubDate>Sat, 18 Jul 2009 17:35:06 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-259</guid>
		<description>Ok, I think the issue is that you need to put the URL between single quotes &#039; &#039; to get it fully into the script. If you don&#039;t then it will get splitup into seperate commands due to the pipe and ampersand symbols.</description>
		<content:encoded><![CDATA[<p>Ok, I think the issue is that you need to put the URL between single quotes &#8216; &#8216; to get it fully into the script. If you don&#8217;t then it will get splitup into seperate commands due to the pipe and ampersand symbols.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-258</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Sat, 18 Jul 2009 17:19:50 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-258</guid>
		<description>Hi Chris,

thank for your answer! I have alrady looked in this script, and I see what it is doing. But I&#039;m not able to find the mistake...
Now I tried it with 2.5 on WinXP. I used the command: python TYPO3EncKeyTool.py --default --url http://mydomain.de/index.php?eID=tx_cms_showpic&amp;file=uploads%2Ftx_mmdamfilelist%2Ftemp_63662056a4.jpg&amp;width=400&amp;wrap=%3CA%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2FA%3E&amp;md5=0602930af0dd42d6d998080e120a848e

He splits the first part of the url right (&quot;http://mydomain.de/index.php?eID=tx_cms_showpic&quot;
then he writes: &quot;Test string: &lt;... BRUTE FORCE ....&quot;
the &quot;Desired MD5: &quot; 
&quot;Beginning defaul Entcryton Key attack
Default Hash not found.

The Command &quot;file&quot; is worng or could not be found. 
The Command &quot;width&quot; is worng or could not be found. 
The Command &quot;warp&quot; is worng or could not be found. 
The Command &quot;md5&quot; is worng or could not be found. 

&quot;</description>
		<content:encoded><![CDATA[<p>Hi Chris,</p>
<p>thank for your answer! I have alrady looked in this script, and I see what it is doing. But I&#8217;m not able to find the mistake&#8230;<br />
Now I tried it with 2.5 on WinXP. I used the command: python TYPO3EncKeyTool.py &#8211;default &#8211;url <a href="http://mydomain.de/index.php?eID=tx_cms_showpic&amp;file=uploads%2Ftx_mmdamfilelist%2Ftemp_63662056a4.jpg&amp;width=400&amp;wrap=%3CA%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2FA%3E&amp;md5=0602930af0dd42d6d998080e120a848e" rel="nofollow">http://mydomain.de/index.php?eID=tx_cms_showpic&amp;file=uploads%2Ftx_mmdamfilelist%2Ftemp_63662056a4.jpg&amp;width=400&amp;wrap=%3CA%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2FA%3E&amp;md5=0602930af0dd42d6d998080e120a848e</a></p>
<p>He splits the first part of the url right (&#8220;http://mydomain.de/index.php?eID=tx_cms_showpic&#8221;<br />
then he writes: &#8220;Test string: &lt;&#8230; BRUTE FORCE &#8230;.&quot;<br />
the &quot;Desired MD5: &quot;<br />
&quot;Beginning defaul Entcryton Key attack<br />
Default Hash not found.</p>
<p>The Command &quot;file&quot; is worng or could not be found.<br />
The Command &quot;width&quot; is worng or could not be found.<br />
The Command &quot;warp&quot; is worng or could not be found.<br />
The Command &quot;md5&quot; is worng or could not be found. </p>
<p>&quot;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ChrisJohnRiley</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-255</link>
		<dc:creator>ChrisJohnRiley</dc:creator>
		<pubDate>Thu, 16 Jul 2009 14:54:17 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-255</guid>
		<description>Hi Jim,

Glad you liked the demo/tool. It was developed using Python 2.5.1 and tested on Debian / SuSE and Backtrack 3. Can you give me details of the error message and I&#039;ll see if I can troubleshoot.

The URL should look something like this .:

http://localhost:8503/index.php?eID=tx_cms_showpic&amp;file=uploads%2Fpics%2Fjonathan.jpg&amp;width=800m&amp;height=600m&amp;bodyTag=%3Cbody%20bgcolor%3D%22black%22%3E&amp;wrap=%3Ca%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2Fa%3E&amp;md5=78f4d21442cb4dc8281f6585adaee960

If you take a look into the script it&#039;s pretty easy to see what it&#039;s doing.

Checkout http://storage.c22.cc/TYPO3-InsecureRandomness.txt for a breakdown of the problem if you&#039;ve not already seen it.</description>
		<content:encoded><![CDATA[<p>Hi Jim,</p>
<p>Glad you liked the demo/tool. It was developed using Python 2.5.1 and tested on Debian / SuSE and Backtrack 3. Can you give me details of the error message and I&#8217;ll see if I can troubleshoot.</p>
<p>The URL should look something like this .:</p>
<p><a href="http://localhost:8503/index.php?eID=tx_cms_showpic&amp;file=uploads%2Fpics%2Fjonathan.jpg&amp;width=800m&amp;height=600m&amp;bodyTag=%3Cbody%20bgcolor%3D%22black%22%3E&amp;wrap=%3Ca%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2Fa%3E&amp;md5=78f4d21442cb4dc8281f6585adaee960" rel="nofollow">http://localhost:8503/index.php?eID=tx_cms_showpic&amp;file=uploads%2Fpics%2Fjonathan.jpg&amp;width=800m&amp;height=600m&amp;bodyTag=%3Cbody%20bgcolor%3D%22black%22%3E&amp;wrap=%3Ca%20href%3D%22javascript%3Aclose%28%29%3B%22%3E%20%7C%20%3C%2Fa%3E&amp;md5=78f4d21442cb4dc8281f6585adaee960</a></p>
<p>If you take a look into the script it&#8217;s pretty easy to see what it&#8217;s doing.</p>
<p>Checkout <a href="http://storage.c22.cc/TYPO3-InsecureRandomness.txt" rel="nofollow">http://storage.c22.cc/TYPO3-InsecureRandomness.txt</a> for a breakdown of the problem if you&#8217;ve not already seen it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jim</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-254</link>
		<dc:creator>Jim</dc:creator>
		<pubDate>Wed, 15 Jul 2009 19:13:45 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-254</guid>
		<description>Thx for the demonstration! But what version of Python is requiered for the script? I tried 2.5,2.6 and 3.1.... I always get some error, it seems that that the script could not split the string. The best version with the less errors was 2.5. greetings jim</description>
		<content:encoded><![CDATA[<p>Thx for the demonstration! But what version of Python is requiered for the script? I tried 2.5,2.6 and 3.1&#8230;. I always get some error, it seems that that the script could not split the string. The best version with the less errors was 2.5. greetings jim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Typo3 Weak Encryption Key &#171; Ramblings of the änal security guy</title>
		<link>http://blog.c22.cc/toolsscripts/#comment-168</link>
		<dc:creator>Typo3 Weak Encryption Key &#171; Ramblings of the änal security guy</dc:creator>
		<pubDate>Tue, 20 Jan 2009 17:22:37 +0000</pubDate>
		<guid isPermaLink="false">http://c22blog.wordpress.com/?page_id=288#comment-168</guid>
		<description>[...] Tools/Scripts [...]</description>
		<content:encoded><![CDATA[<p>[...] Tools/Scripts [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
