Call for Participation – Chaos Communication Camp 2007. Contributions due 2007-05-15.
Archiv der Kategorie: Hackmeck
The Monster Approach to Testing
What’s going on in our security test lab? That’s a long story I cannot tell in a single post. Security testing is a mixture of structured analysis and playful exploration. The latter one boils down to a single rule: try the most irregular, stupid, nonsensical, unexpected action that comes to your mind. Chances are that the developers of a system did not think of it because it’s so irregular, stupid, nonsensical or unexpected. And always question the vendor’s claims – as well as your own assumptions.
The Sesame Street Computer Monster in this video does just that:
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
According to the Motion Picture Association of America (MPAA) this seemingly innocent 32-digit hexadecimal number is verboten. Slashdot reports they sent out DMCA takedown notices (sample at chillingeffects.org) to several sites that spread the number 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0.
The DMCA, or Digital Millennium Copyright Act is a U.S. copyright law. A takedown notice is a letter or other message that a legitimate copyright holder can send to an internet service provider, requesting that specific infringing material be taken off the Net.
So why and how would an association of the motion picture, home video and television industries attempt to maintain and defend their copyright in a 32-digit hexadecimal number, 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0?