<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-27774445</id><updated>2011-11-27T15:46:40.857-08:00</updated><category term='biological'/><category term='computer security'/><category term='cache'/><category term='web'/><category term='HTTPS'/><category term='San Antonio'/><category term='SHA1'/><category term='perl'/><category term='malware'/><category term='hash'/><category term='Ed Skoudis'/><category term='ordo'/><category term='to die for'/><category term='Larry Pesce'/><category term='SANS2009'/><category term='medical records'/><category term='Johannes Ullrich'/><category term='SANSFIRE'/><category term='mccain maverick'/><category term='creativity'/><category term='medical'/><category term='firefox'/><category term='Incident Handling'/><category term='Skoudis'/><category term='information security'/><category term='smooth'/><category term='IOS'/><category term='mango'/><category term='analysis'/><category term='infosec'/><category term='browser'/><category term='infragard'/><category term='reconstruct'/><category term='class'/><category term='repair'/><category term='Alan Paller'/><category term='SSL'/><category term='pauldotcom'/><category term='MD5'/><category term='training'/><category term='phoenix'/><category term='graduation speech'/><category term='fragment'/><category term='teaching'/><category term='Eric Cole'/><category term='broken'/><category term='exploit framework'/><category term='silky'/><category term='Downadup'/><category term='SEC504'/><category term='April 1st'/><category term='security'/><category term='lime'/><category term='Stephen Northcutt'/><category term='Hacker'/><category term='SANS'/><category term='Microsoft Word'/><category term='safe'/><category term='XML'/><category term='penetration test'/><category term='metasploit'/><category term='Jeff Frisk'/><category term='April Fools'/><category term='mojito'/><category term='Alamo'/><category term='forensics'/><category term='Royal Society'/><category term='adblock'/><category term='Queen'/><category term='chao'/><category term='Conficker'/><category term='food'/><category term='noscript'/><category term='delicious'/><category term='juicy'/><category term='project management'/><category term='Masters'/><category term='evilgrade'/><category term='MGT525'/><category term='Wren'/><category term='pentest'/><category term='mike poor'/><category term='security conference'/><category term='google'/><title type='text'>Perpetual Soapbox</title><subtitle type='html'>This site is my little soapbox on current affairs, information security, and anything else that strikes my fancy or lights my ire.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>33</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-27774445.post-2879296906146207770</id><published>2011-07-23T10:06:00.000-07:00</published><updated>2011-07-23T12:43:44.198-07:00</updated><title type='text'>Orion 0.4 Squirrel Edition Released</title><content type='html'>The Orion Live CD is an Ubuntu-based environment for computer security analysts and incident responders to acquire and analyze data, track case information, and collaborate securely over SSH tunnels.&lt;br /&gt;&lt;br /&gt;I started Orion as the last project for my Masters of Information Security Engineering degree with the SANS Technology Institute.  The Orion project team is small right now (there are three of us), but we're always on the lookout for the right new members to add.&lt;br /&gt;&lt;br /&gt;Please check out version 0.4 (AKA the “Squirrel Edition”) at the sourceforge site:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://orionlivecd.sourceforge.net/" target="_blank"&gt;http://orionlivecd.sourceforge.net&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-2879296906146207770?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/2879296906146207770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=2879296906146207770' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/2879296906146207770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/2879296906146207770'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2011/07/orion-04-squirrel-edition-released.html' title='Orion 0.4 Squirrel Edition Released'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-3725169145977772510</id><published>2011-04-01T06:11:00.000-07:00</published><updated>2011-04-01T06:19:33.393-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='Incident Handling'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='Ed Skoudis'/><category scheme='http://www.blogger.com/atom/ns#' term='SEC504'/><title type='text'>SANS Community Albuquerque:  Come learn current hacker techniques!</title><content type='html'>I keep having this conversation with former students: "Hey John, remember that thing we talked about in class?  It's just like what was in the news the other day!"&lt;br /&gt;&lt;br /&gt;Exactly.&lt;br /&gt;&lt;br /&gt;The SANS &lt;span style="font-weight: bold;"&gt;Hacker Techniques, Exploits, and Incident Handling&lt;/span&gt; class (&lt;a href="http://www.sans.org/albuquerque-2011-cs/"&gt;SEC 504&lt;/a&gt;) has one goal:  Teach defenders how attackers are breaking into systems and how to defend against those attacks.&lt;br /&gt;&lt;br /&gt;I am pleased to announce that I will be teaching SEC 504 at &lt;a href="http://www.sans.org/albuquerque-2011-cs/"&gt;SANS Community Albuquerque April 25-30&lt;/a&gt;.  We'll cover the material written by the visionary Ed Skoudis and his co-authors.  We'll also discuss current news and what's going on behind the scenes.  And, we'll end the week with a rockin' cool Capture the Flag contest to test your new and existing skillz.&lt;br /&gt;&lt;br /&gt;Come join me!  I  guarantee a fun and informative week.  :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-3725169145977772510?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/3725169145977772510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=3725169145977772510' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3725169145977772510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3725169145977772510'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2011/04/sans-community-albuquerque-come-learn.html' title='SANS Community Albuquerque:  Come learn current hacker techniques!'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-6566113258730838565</id><published>2011-01-09T12:15:00.000-08:00</published><updated>2011-01-09T13:34:18.409-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wren'/><category scheme='http://www.blogger.com/atom/ns#' term='creativity'/><category scheme='http://www.blogger.com/atom/ns#' term='phoenix'/><category scheme='http://www.blogger.com/atom/ns#' term='ordo'/><category scheme='http://www.blogger.com/atom/ns#' term='Royal Society'/><category scheme='http://www.blogger.com/atom/ns#' term='chao'/><title type='text'>Lector, si monumentum requiris, circumspice</title><content type='html'>When Christopher Wren died in 1723, this epitaph was inscribed on his tombstone at St. Paul's Cathedral in London:  Reader, if you seek his memorial, look around you.&lt;br /&gt;&lt;br /&gt;As one of the most noted English architects, and founder of the Royal Society, the monument to his memory was wrought by his own hands over many years before his mortal end.&lt;br /&gt;&lt;br /&gt;It is telling that part of Wren's material legacy included the rebuilding of &lt;a href="http://maps.google.co.uk/maps/mm?hl=en&amp;amp;ie=UTF8&amp;amp;ll=51.512589,-0.095744&amp;amp;spn=0.013007,0.027466&amp;amp;z=15&amp;amp;msa=0&amp;amp;msid=115784177921406587387.0004676262a9f91faf177"&gt;50 churches&lt;/a&gt; and St. Paul's Cathedral after the Great Fire of London in 1666. From chaos, order.  Now, just in case I have piqued the interest of freemasons and occultists -- I really mean this in the most literal sense:  the destruction wrought by nature (or even not by nature) has always become an opportunity for creative minds to build something from the ashes.&lt;br /&gt;&lt;br /&gt;This cycle of destruction and rebirth is the true human condition, but the detail we often forget is that we create the order &lt;span style="font-style: italic;"&gt;and&lt;/span&gt; the chaos.&lt;br /&gt;&lt;br /&gt;Every day, look around and ask what your monument will be.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-6566113258730838565?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/6566113258730838565/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=6566113258730838565' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6566113258730838565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6566113258730838565'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2011/01/lector-si-monumentum-requiris.html' title='Lector, si monumentum requiris, circumspice'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-6221200560237307698</id><published>2010-11-30T20:47:00.001-08:00</published><updated>2010-11-30T20:56:48.586-08:00</updated><title type='text'>You keep using that word...</title><content type='html'>A few weeks ago I found myself at a vendor presentation by a well-known  physical security vendor.  I was looking forward to the discussion on  "advanced video analytics" and other cutting edge developments.   Unfortunately, this was a pure sales pitch... and the "advanced  technology" was primarily focused on how this vendor could help scale the  customers' security camera video storage by placing it on a "secure  server in the cloud."&lt;br /&gt;&lt;br /&gt;I was quiet up to this point in the  presentation.  But, I had to ask:  "What do you mean by, a 'secure  server' in the cloud?"  The room got a little quieter.  The sales guy,  his pace interrupted, looked at me with complete sincerity and said: "I  mean we secure it for you."&lt;br /&gt;&lt;br /&gt;I didn't think he meant that he, himself, was hardening the OS and running assessments against it.  Even so, with security cameras and alarms as their forte, I couldn't understand how it made sense for &lt;span style="font-style: italic;"&gt;anyone&lt;/span&gt; at his company to provide such a service.&lt;br /&gt;&lt;br /&gt;The morale of this story is:  Question everything.&lt;br /&gt;&lt;br /&gt;I would never trust my security camera video data to a company storing it in the cloud -- at least not until I had a chance to check it thoroughly (yes, myself).  Believe me, I've recently checked other products thoroughly and found them -- let's just say -- not quite meeting expectations.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-6221200560237307698?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/6221200560237307698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=6221200560237307698' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6221200560237307698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6221200560237307698'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2010/11/you-keep-using-that-word.html' title='You keep using that word...'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-3833749168530901324</id><published>2010-06-12T11:24:00.000-07:00</published><updated>2010-06-12T12:01:04.640-07:00</updated><title type='text'>Orion Lucid 0.1 RELEASED!</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://sourceforge.net/projects/orionlivecd/"&gt;&lt;img style="float: right; margin: 0pt 0pt 10px 10px; cursor: pointer; width: 320px; height: 199px;" src="http://4.bp.blogspot.com/_37_HFRs63M0/TBPY6i7oZUI/AAAAAAAAACY/asP9YbBO69g/s320/orion-lucid.png" alt="" id="BLOGGER_PHOTO_ID_5481963671760954690" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The Orion Incident Response LiveCD (okay, LiveDVD) has been released at:&lt;br /&gt;&lt;br /&gt;http://sourceforge.net/projects/orionlivecd/&lt;br /&gt;&lt;br /&gt;This is the first public release, and is based on Ubuntu Lucid Lynx.  The original alpha version was based on BackTrack 4, but we decided to switch for a variety of reasons.  Because of this, there are a few bugs that need working out.&lt;br /&gt;&lt;br /&gt;To read the paper that goes with it, see:&lt;br /&gt;&lt;br /&gt;http://bit.ly/cFWFSQ&lt;br /&gt;&lt;br /&gt;--john&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-3833749168530901324?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/3833749168530901324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=3833749168530901324' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3833749168530901324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3833749168530901324'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2010/06/orion-lucid-01-released.html' title='Orion Lucid 0.1 RELEASED!'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_37_HFRs63M0/TBPY6i7oZUI/AAAAAAAAACY/asP9YbBO69g/s72-c/orion-lucid.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-5202631306156425049</id><published>2010-06-12T04:59:00.000-07:00</published><updated>2010-06-12T11:23:14.628-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='Stephen Northcutt'/><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='Masters'/><category scheme='http://www.blogger.com/atom/ns#' term='Ed Skoudis'/><category scheme='http://www.blogger.com/atom/ns#' term='Johannes Ullrich'/><category scheme='http://www.blogger.com/atom/ns#' term='computer security'/><category scheme='http://www.blogger.com/atom/ns#' term='SANSFIRE'/><category scheme='http://www.blogger.com/atom/ns#' term='Eric Cole'/><category scheme='http://www.blogger.com/atom/ns#' term='graduation speech'/><category scheme='http://www.blogger.com/atom/ns#' term='Alan Paller'/><title type='text'>SANS Technical Institute Masters Graduation</title><content type='html'>Last night I received my Master of Science in Information Security Engineering degree from the SANS Technology Institute (STI) at the &lt;a href="http://www.sans.org/sans-2010/"&gt;SANSFIRE 2010&lt;/a&gt; conference in Balitmore.  I was also asked to give a speech.  A few people have asked for a copy, so I am posting it here:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;&lt;/span&gt;&lt;blockquote&gt;&lt;span style="font-family:times new roman;"&gt;Good evening, and thank you for attending.&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;If I seem a bit nervous, it's because I don't normally read speeches -- I prefer "winging it."  But I won't waste your time today with extemporaneous rambling.  Besides, I have a few important things I want to say.&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;I especially want to thank the families and friends of the graduates who were able to make it today.  My own family traveled from California, Texas, and New Mexico to be with us.  I am very thankful that you could all be here today, and I deeply appreciate the support and sacrifices of my wife and two daughters over the last few years while I was working nights and weekends toward this goal.  I know I share this sentiment with my fellow graduates.&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;Thank you also to the SANS Community.  Without you, none of this would be possible.  From the excellent instructors and gifted students to the SANS Forensics blog team and active SANS mailing lists, you continue to create the most productive and inquisitive organization of network security experts in the world.&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;The SANS Technical Institute leaders and staff also deserve a huge Thank You today.  Stephen Northcutt, Alan Paller, Eric Cole, Johannes Ullrich, Ed Skoudis, and others have put forth a vision, and have applied all their formidable talents to turn it into a reality.  STI, if you haven't heard, has achieved candidacy status -- an impressive accomplishment in such a short time.  And Dean Debbie Svoboda, perhaps more than anyone else, deserves our appreciation -- as the rudder (and sometimes even the sails) to make this ship go.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;I also want to congratulate my fellow graduates:  John, Rob, Rodney, and Tim.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;As graduates, our work on our masters degree programs is now complete.  However, the real work has only just begun.  &lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;Recently I re-read my student outcome statement.  In it I wrote I was inspired by the sci-fi/cyberpunk author William Gibson, who coined the term Cyberspace in the 1980's.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;Gibson painted a fascinating, but dark, picture of the future where technology leads to black market cybernetic augmentation, pervasive surveillance, Console Cowboys controlling cyberspace, the blurring of government and mega-corporations, and blended military operations of electronic and conventional warfare.&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;Here is a passage:&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;"You're a console cowboy.  The prototypes of the programs you use to crack industrial banks were developed for Screaming Fist.  For the assault on the Kirensk computer nexus.  Basic module was a Nightwing microlight, a pilot, a matrix deck, a jockey.  We were running a virus called Mole.  The Mole series was the first generation of real intrusion programs."&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;Now, just as in the real world, a lot of that sounds simultaneously scary and exciting.  But, our goal, as leaders, should be to guide us to the brighter, rather than the darker, aspects of that future.  As you know, cyberspace has already become the New Arms Race.  As SANS graduates, instructors, and students... we each have a larger role to play.  In Randy Marchany's recent blog posting ("&lt;a href="http://randymarchany.blogspot.com/2010/05/building-skynet-beginning.html"&gt;Building Skynet -- The Beginning&lt;/a&gt;"), he states that we are the Builders in this arms race, but we are not the Controllers.  We understand things, and think we have a handle on them, but we are not always making the decisions.  Randy concludes with two "Ugly Secrets" that most of us here know very well:  ONE) We know we are becoming a surveillance society, because we are helping to build it, and TWO) The Controllers trump the Builders.  Some of these controllers are the management and government officials who might, say, turn things we build into weapons of mass destruction, BUT ... more insidiously ... sometimes we hand Control over to automation.  You know this is true if you simply recall the last time you were told, with a shrug of resignation:&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;"I'm sorry, there is nothing I can do, it's the computer."&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;So, this is my challenge to you:  While you are building -- build integrity and checks-and-balances into your creations.  Make sure, to the best of your abilities, that you are not enabling the leverage for oppression or creating the surveillance state.  And, be very, very careful about ceding the Controller position to automated software.  We write the software, and we know it can make mistakes, because WE make mistakes.  Bake this thinking in to what you do, who you know, and what you teach.  You are leaders, and this is your... And my... Responsibility.  This is the challenge I issue to you: the graduates of STI -- and the entire SANS community.   And... I am heartened, as I look around the room, because I know we have the right people to do the job.  It's not an easy job, but I am still inspired by the words of a certain dead president, that we do these things:&lt;/span&gt;&lt;span style="font-family:times new roman;"&gt;&lt;br /&gt;&lt;br /&gt;"not because they are easy, but because they are hard, because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are &lt;span style="font-size:100%;"&gt;willing to accept, one we are unwilling to postpone, and one which we intend to win."&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;Thank you.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-5202631306156425049?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/5202631306156425049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=5202631306156425049' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/5202631306156425049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/5202631306156425049'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2010/06/sans-technical-institute-masters.html' title='SANS Technical Institute Masters Graduation'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-6386323185163435996</id><published>2010-05-18T22:57:00.000-07:00</published><updated>2010-05-18T23:32:21.807-07:00</updated><title type='text'>You ate... what?</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_37_HFRs63M0/S_N_zCHbR9I/AAAAAAAAACA/cjNwd258ZRA/s1600/2010-05-18+20.54.18.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 320px; height: 239px;" src="http://1.bp.blogspot.com/_37_HFRs63M0/S_N_zCHbR9I/AAAAAAAAACA/cjNwd258ZRA/s320/2010-05-18+20.54.18.jpg" alt="" id="BLOGGER_PHOTO_ID_5472858486903359442" border="0" /&gt;&lt;/a&gt;Tonight a friend and I shared a dessert that is positively the strangest one I've ever had.  We went to Layang Layang, a Malaysian restaurant in Cupertino.  Our food was excellent -- and exactly what I was craving.&lt;br /&gt;&lt;br /&gt;But, the star of the meal was this dessert, the &lt;a href="http://en.wikipedia.org/wiki/Ais_kacang"&gt;Ice Kacang&lt;/a&gt; (aka, "A.B.C.").  I saw a picture in the menu and read a description before we ordered it.  It didn't matter.  I still wasn't prepared for the mountain of shaved ice mixed with a bizarre (yet, excellent) combination of ingredients.  It arrived to at our table looking like an icy volcano drizzled with caramel.  Digging into the center brought more surprises in the form of sweet corn kernels, palm seeds, and little green jelly cubes. Two of us could not finish it, but it had a fascinating array of flavors -- including some that our palettes had absolutely no reference for.&lt;br /&gt;&lt;br /&gt;I'm definitely glad we decided to be adventurous.  I recommend &lt;a href="http://www.layanglayang.us/images-dessert/slides/Dessert%20-%20126%20-%20ABC.html"&gt;trying it&lt;/a&gt; if you find yourself in the Cupertino area.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-6386323185163435996?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/6386323185163435996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=6386323185163435996' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6386323185163435996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6386323185163435996'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2010/05/you-ate-what.html' title='You ate... what?'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_37_HFRs63M0/S_N_zCHbR9I/AAAAAAAAACA/cjNwd258ZRA/s72-c/2010-05-18+20.54.18.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-7649580393261417088</id><published>2009-06-18T22:21:00.000-07:00</published><updated>2009-06-18T22:26:19.886-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='to die for'/><category scheme='http://www.blogger.com/atom/ns#' term='silky'/><category scheme='http://www.blogger.com/atom/ns#' term='delicious'/><category scheme='http://www.blogger.com/atom/ns#' term='mango'/><category scheme='http://www.blogger.com/atom/ns#' term='smooth'/><category scheme='http://www.blogger.com/atom/ns#' term='lime'/><category scheme='http://www.blogger.com/atom/ns#' term='juicy'/><category scheme='http://www.blogger.com/atom/ns#' term='food'/><title type='text'>Juicy, juicy mangoes!</title><content type='html'>I used to like mangoes okay.  They were good, but a little over-sweet and a little stringy.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It turns out... I really, really like mangoes.  It's just that I hadn't had a very good one until this week.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;My wife orders a box of organic produce every other week, and we got two slender, yellow mangoes.  These are from Mexico, are organic (obviously), but I don't know the name.  They are INCREDIBLE.  Juicy, smooth-as-silk, and sweet with a little bit of limey tartness.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I just cut one up for lunches tomorrow, and I'm already obsessing over how to get more.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you have any recommendations, please send them to me! &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-7649580393261417088?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/7649580393261417088/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=7649580393261417088' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/7649580393261417088'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/7649580393261417088'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/06/juicy-juicy-mangoes.html' title='Juicy, juicy mangoes!'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-24962633805646076</id><published>2009-06-18T19:29:00.000-07:00</published><updated>2009-06-18T22:28:59.724-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft Word'/><category scheme='http://www.blogger.com/atom/ns#' term='repair'/><category scheme='http://www.blogger.com/atom/ns#' term='reconstruct'/><category scheme='http://www.blogger.com/atom/ns#' term='XML'/><category scheme='http://www.blogger.com/atom/ns#' term='fragment'/><title type='text'>Recreating XML files from fragments</title><content type='html'>I'm working on an interesting problem right now.  Occasionally I acquire fragments of files that I would like to re-create as much as possible.  Many of these are Microsoft Word 2007 files.  MS Word 2007 uses an XML format, so it would seem possible to parse the file to detect tags that were ended, but don't have a matching opening (because the beginning was cut off).&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I figured that I'm probably not the first one to think about this problem, so I went trolling the intertubes for ready-made solutions.  Since perl is my glueware language of choice, I searched until I found the following handy snippet from &lt;a href="http://prlmnks.org/html/427666.html"&gt;prlmnks.org&lt;/a&gt;:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style=" ;font-family:Helvetica;"&gt;&lt;pre class="block_code" style="padding-top: 0.2em; padding-right: 0.2em; padding-bottom: 0.2em; padding-left: 1em; "&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica; font-size: 16px; white-space: normal; "&gt;&lt;pre class="block_code" style="padding-top: 0.2em; padding-right: 0.2em; padding-bottom: 0.2em; padding-left: 1em; "&gt;use XML::LibXML;&lt;br&gt;my $parser = XML::LibXML-&gt;new();&lt;br&gt;$parser-&gt;recover(1);&lt;br&gt;my $doc = $parser-&gt;parse_file($ARGV[0]);&lt;br&gt;print $doc-&gt;toString(1);&lt;/pre&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Very, very nice!  Now I am part of the way there.  Next, I took a pre-existing MS Word document of similar make and model, and prepended it.  With a little manual massaging, I got the script above to parse it, and even pretty-print it (a nice bonus).  Unfortunately, Microsoft Word still doesn't like the resultant "document."&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I'm still working on this problem, but that's decent progress for an hour of work.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-24962633805646076?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/24962633805646076/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=24962633805646076' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/24962633805646076'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/24962633805646076'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/06/recreating-xml-files-from-fragments.html' title='Recreating XML files from fragments'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-6783486556426669068</id><published>2009-04-30T21:39:00.001-07:00</published><updated>2009-04-30T21:39:39.995-07:00</updated><title type='text'>Ubiquity</title><content type='html'>At first I was stunned at just how much I liked my iPod Touch. I just wanted a replacement for my 5th gen iPod, that stopped working when it mysteriously acquired a dent in its formerly pristine stainless steel back.&lt;br /&gt;&lt;br /&gt;It didn't take long for it to turn into my most indispensible tool.  Place to eat? UrbanSpoon. Reservation? OpenTable. And the list goes on: calculators, converters, levels, action games, puzzles, wikipedia apps, ebook readers, and even a way to read books from my Safari account.&lt;br /&gt;&lt;br /&gt;If the kid is bored... a bit of Shrek.  Long flight?A pithy podcast is the trick. Can't sleep? Ambient noise generator FTW!&lt;br /&gt;&lt;br /&gt;In short, this little glass and steel box has become utterly indispensible.&lt;br /&gt;&lt;br /&gt;This post, of course... composed, in bed, one thumb at a time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-6783486556426669068?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/6783486556426669068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=6783486556426669068' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6783486556426669068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/6783486556426669068'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/04/ubiquity.html' title='Ubiquity'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-580200594904132832</id><published>2009-03-28T19:14:00.000-07:00</published><updated>2009-03-28T19:28:31.096-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security conference'/><category scheme='http://www.blogger.com/atom/ns#' term='Larry Pesce'/><category scheme='http://www.blogger.com/atom/ns#' term='biological'/><category scheme='http://www.blogger.com/atom/ns#' term='infragard'/><category scheme='http://www.blogger.com/atom/ns#' term='medical records'/><category scheme='http://www.blogger.com/atom/ns#' term='pauldotcom'/><category scheme='http://www.blogger.com/atom/ns#' term='information security'/><category scheme='http://www.blogger.com/atom/ns#' term='medical'/><title type='text'>Securing Our Medical Infrastucture</title><content type='html'>On Friday, April 17th, &lt;a href="http://www.infragardnm.org/"&gt;InfraGard New Mexico&lt;/a&gt; is holding it's annual conference in Albuquerque, NM at the Hilton Garden Inn in Uptown.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The conference is titled:  &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;a href="http://www.infragardnm.org:8080/medsec/"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Securing Our Medical Infrastructure&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;At $175 ($125 for current InfraGard members), the all-day conference is steal!!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The speakers include Larry Pesce (from &lt;a href="http://www.pauldotcom.com/about.html"&gt;PaulDotCom&lt;/a&gt;), &lt;a href="http://www.infragardnm.org:8080/medsec/BioBillTydeman.html"&gt;Bill Tydeman&lt;/a&gt; (computer crime investigator for Health and Human Services), and others.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Visit the conference site for more details on registration and sponsorship.  Hope to see you there!!!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;--john&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-580200594904132832?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/580200594904132832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=580200594904132832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/580200594904132832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/580200594904132832'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/03/securing-our-medical-infrastucture.html' title='Securing Our Medical Infrastucture'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-8468199071433942411</id><published>2009-03-25T19:14:00.000-07:00</published><updated>2009-03-25T19:19:49.332-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Conficker'/><category scheme='http://www.blogger.com/atom/ns#' term='Downadup'/><category scheme='http://www.blogger.com/atom/ns#' term='April Fools'/><category scheme='http://www.blogger.com/atom/ns#' term='April 1st'/><title type='text'>Get ready for Conficker - No April Fools Day Joke</title><content type='html'>Good news:  The patch for this issue came out from Microsoft in October last year.  If you had automatic updates enabled at that time, you were probably already not vulnerable.&lt;br /&gt;&lt;br /&gt;Not so good news:  I can confirm that it is set to become more active again on April 1st.  On that day, if you are infected, you may notice your machine is very slow for the first six hours or so.&lt;br /&gt;&lt;br /&gt;Worse news:  Conficker is suspected to be building the largest "botnet" of computers to date.  These computers are typically used to perform massive spam campaigns, launder money, host illegal or thieving web sites, or even take down computer systems of nation states (such as Estonia).&lt;br /&gt;&lt;br /&gt;What you can do now:&lt;br /&gt;1)  Read the &lt;a href="http://en.wikipedia.org/wiki/Conficker"&gt;Wikipedia article on Conficker&lt;/a&gt;, which provides a lot of good information,&lt;br /&gt;2)  Download the BitDefender Conficker removal tool from &lt;a href="http://bdtools.net/"&gt;http://bdtools.net/&lt;/a&gt; and check/clean your computer.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-8468199071433942411?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/8468199071433942411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=8468199071433942411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8468199071433942411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8468199071433942411'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/03/get-ready-for-conficker-no-april-fools.html' title='Get ready for Conficker - No April Fools Day Joke'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-3250151683409033812</id><published>2009-03-09T21:25:00.000-07:00</published><updated>2009-03-09T21:39:42.566-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mojito'/><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='Queen'/><category scheme='http://www.blogger.com/atom/ns#' term='mike poor'/><title type='text'>Darn it, they got me doing Karaoke again!</title><content type='html'>I met some incredibly talented folks at SANS 2009 this year.  Ryan, Jason, Don, Zoher and I hung out with Ed Skoudis, Mike Poor, Larry Pesce, and others.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ryan truly has an evil mind (this is a good thing, in our field), and I was impressed with Don's massive cahones for his efforts over at &lt;a href="http://www.ethicalhacker.net/"&gt;EthicalHacker.net&lt;/a&gt; (and also for owning a bar while owning a software company!).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;One evening we spent some time chatting with Ed Skoudis after one of his talks at the local Sushi bar.  I didn't have Sushi since I'd just eaten, but somehow (it must have been the mojito), Mike Poor convinced a few of us to join him on stage for a &lt;span class="Apple-style-span" style="font-weight: bold; font-style: italic;"&gt;dead-on&lt;/span&gt; (umm, not) rendition of &lt;a href="http://www.ethicalhacker.net/component/option,com_smf/Itemid,54/topic,3738.msg17507/#msg17507"&gt;Bohemian Rhapsody&lt;/a&gt;.  It was fun, but not to be attempted without some liquid courage (at least not with &lt;span class="Apple-style-span" style="font-style: italic;"&gt;my&lt;/span&gt; singing voice).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;By the way, Jason, thanks for posting the tamer pictures.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-3250151683409033812?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/3250151683409033812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=3250151683409033812' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3250151683409033812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3250151683409033812'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/03/darn-it-they-got-me-doing-karaoke-again.html' title='Darn it, they got me doing Karaoke again!'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-8928710152686568841</id><published>2009-03-09T21:11:00.000-07:00</published><updated>2009-03-13T11:43:29.065-07:00</updated><title type='text'>That'll Do, Donkey, That'll Do</title><content type='html'>&lt;div&gt;[Update 2009-03-13:  Our team received notification yesterday that we Passed this project.]&lt;br /&gt;&lt;br /&gt;I completed my Group Discussion and Written Project for my SANS Masters program while at SANS 2009 last week.  I'm pretty sure the grade will be good, but I won't know for another week or so.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Seth Misenar and Tim Proffitt were my tiger teammates for an assignment that involved researching detective and preventive measures for Downadup/Conficker.  We had 24 hours to do the work and present to the ficticious CIO (played by Stephen Northcutt) of GIAC Enterprises.  Seth did an excellent job of presenting, but in the end we were "fired" by the CIO because we commented that he had gotten "too excited" about the possibility of his email being infected.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Later in the week we were asked to present again.  It was suggested that we should rotate the role of presenter, so I volunteered.  We presented a 2nd time on March 7th, and after we were done, Stephen Northcutt didn't say anything.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I got a little nervous at that point and asked, "Do you have any questions?  Or any feedback?"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Stephen's response was a simple:  "No."&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;After a little more prodding he added, "I don't even have any recommendations.  You nailed it."&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Ah.... sweet success.  :-)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-8928710152686568841?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/8928710152686568841/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=8928710152686568841' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8928710152686568841'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8928710152686568841'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/03/thatll-do-donkey-thatll-do.html' title='That&apos;ll Do, Donkey, That&apos;ll Do'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-4093530220381142636</id><published>2009-03-09T20:52:00.000-07:00</published><updated>2009-03-09T21:25:00.152-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='Jeff Frisk'/><category scheme='http://www.blogger.com/atom/ns#' term='SANS2009'/><category scheme='http://www.blogger.com/atom/ns#' term='MGT525'/><category scheme='http://www.blogger.com/atom/ns#' term='project management'/><title type='text'>SANS 2009: MGT 525</title><content type='html'>I'm just back from &lt;a href="http://www.sans.org/info/35964"&gt;SANS 2009 in Orlando&lt;/a&gt; (&lt;a href="http://hashtags.org/search?query=SANS2009&amp;amp;submit=Search"&gt;#SANS2009&lt;/a&gt;).  I took &lt;a href="http://www.sans.org/training/description.php?mid=94"&gt;MGT525&lt;/a&gt; -- yes, the project management class -- with Jeff Frisk.  I signed up for the class because it is a required component of the degree I am working on.  I had actually heard some negative things about the class, so I was dreading it just a little (sorry Jeff).  But, I'm pleased to report that I found it incredibly useful.  I have been running large projects (large information security projects) for awhile, but I haven't really ever had any formal PM training.  We have a Project Management Office, and they provide guidelines and templates, and I know what a &lt;a href="http://en.wikipedia.org/wiki/Work_breakdown_structure"&gt;WBS&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/Gantt_chart"&gt;Gantt&lt;/a&gt; chart are for, but I didn't really know the "proper" way to go from one step to the next.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;My eyes were opened when we worked through labs on taking the WBS and producing a precedence diagram to figure out the actual critical path -- including identifying what activities had how much float time.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now project management seems much less like art and more like science.  This makes me happy.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thanks Jeff!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-4093530220381142636?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/4093530220381142636/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=4093530220381142636' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/4093530220381142636'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/4093530220381142636'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2009/03/sans-2009-mgt-525.html' title='SANS 2009: MGT 525'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-9073043069633331442</id><published>2008-12-31T08:11:00.000-08:00</published><updated>2008-12-31T09:43:58.452-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SSL'/><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='SHA1'/><category scheme='http://www.blogger.com/atom/ns#' term='MD5'/><category scheme='http://www.blogger.com/atom/ns#' term='hash'/><category scheme='http://www.blogger.com/atom/ns#' term='broken'/><category scheme='http://www.blogger.com/atom/ns#' term='HTTPS'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='web'/><title type='text'>MD5 Considered Harmful Today or Don't Put Too Much Faith in PKI</title><content type='html'>A group of 7 security researchers from the United States, Switzerland, and the Netherlands has released details of an exploitation ("&lt;a href="http://www.win.tue.nl/hashclash/rogue-ca/"&gt;MD5 considered harmful today&lt;/a&gt;") in the now well-known &lt;a href="http://www.doxpara.com/md5_someday.pdf"&gt;MD5 Hash Collision vulnerability&lt;/a&gt; that would allow a rogue web site to issue a rogue SSL certificate... as well as a rogue signing certificate that is trusted by a valid root Certificate Authority.&lt;br /&gt;&lt;br /&gt;Putting that all into English (or at least non-geekspeak):&lt;br /&gt;&lt;br /&gt;"Secure" web sites can be impersonated by evildoers, even with the cute little lock icon and a completely "valid" certificate as far as your browser is concerned. This web site could be your bank.&lt;br /&gt;&lt;br /&gt;The paper discusses countermeasures, mostly aimed at Certificate Authorities (CAs) and browser vendors. One thing you can do is look at your certificate chain for critical sites to see if MD5 is used by the CA's signing certificate.&lt;br /&gt;&lt;br /&gt;The Mozilla developers are already working on a patch for Firefox, et al.:&lt;br /&gt;&lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=471539"&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=471539&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--john&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-9073043069633331442?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/9073043069633331442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=9073043069633331442' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/9073043069633331442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/9073043069633331442'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/12/md5-considered-harmful-today-or-dont.html' title='MD5 Considered Harmful Today or Don&apos;t Put Too Much Faith in PKI'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-1489234222897186928</id><published>2008-10-05T20:56:00.000-07:00</published><updated>2008-10-21T19:46:46.447-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mccain maverick'/><title type='text'>We cannot let this man be elected as President</title><content type='html'>I am appalled.  If John McCain has done even one tenth of the things listed in this Rolling Stone article, we cannot let him take the office of the Commander in Chief:&lt;div&gt;&lt;br /&gt;&lt;strike&gt;http://tinyurl.com/3oje6n&lt;/strike&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;Update&lt;/span&gt;:&lt;br /&gt;Scary.  Someone actually went to the trouble of breaking the above URL.  Here is the new one:&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;a href="http://tinyurl.com/mcmaverick"&gt;http://tinyurl.com/mcmaverick&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-style: italic;"&gt;Or, just google for "mccain maverick rolling stone".&lt;/span&gt;&lt;b&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-1489234222897186928?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/1489234222897186928/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=1489234222897186928' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/1489234222897186928'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/1489234222897186928'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/10/we-cannot-let-this-man-be-elected-as.html' title='We cannot let this man be elected as President'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-8191456754265462699</id><published>2008-09-14T13:15:00.000-07:00</published><updated>2008-09-16T09:19:34.519-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='noscript'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='cache'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='safe'/><category scheme='http://www.blogger.com/atom/ns#' term='adblock'/><category scheme='http://www.blogger.com/atom/ns#' term='browser'/><title type='text'>strip=1 ftw</title><content type='html'>I use lots of browser flame-retardant suit layers these days... &lt;a href="http://noscript.net/"&gt;NoScript&lt;/a&gt;, &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/10"&gt;AdBlock&lt;/a&gt;, etc.  I even tend to NoScript google.com by default.  If you only go to "normal" web sites this might seem extreme, but if you are poking around the seedy back streets of the &lt;a href="http://www.urbandictionary.com/define.php?term=intertubes"&gt;intertubes&lt;/a&gt;, you probably know what I mean.&lt;br /&gt;&lt;br /&gt;Here is another good pair of tips for safer browsing:&lt;br /&gt;&lt;br /&gt;1.  &lt;span style="font-style: italic;"&gt;Use the cache, Luke&lt;/span&gt;, and&lt;br /&gt;2.  Always use strip=1&lt;br /&gt;&lt;br /&gt;You can use the google cache to search for your topic of interest, and the oracle will return some hits (e.g., "100th monkey"):&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;ol&gt;&lt;li class="g"&gt;&lt;h3 class="r"&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Hundredth_Monkey" class="l" onmousedown="return clk(this.href,'','','res','1','')"&gt;Hundredth &lt;em&gt;Monkey&lt;/em&gt; Effect - Wikipedia, the free encyclopedia&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class="s"&gt;&lt;span style="font-size:85%;"&gt;The “Hundredth &lt;em&gt;Monkey&lt;/em&gt; Effect” is a supposed phenomenon in which a learned behaviour spreads instantaneously from one group of monkeys to all related monkeys &lt;b&gt;...&lt;/b&gt;&lt;br /&gt;&lt;cite&gt;en.wikipedia.org/wiki/Hundredth_&lt;b&gt;Monkey&lt;/b&gt; - 32k - &lt;/cite&gt;&lt;span class="gl"&gt;&lt;a href="http://72.14.205.104/search?q=cache:qAqrudt9CQEJ:en.wikipedia.org/wiki/Hundredth_Monkey+100th+monkey&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=1&amp;amp;gl=us&amp;amp;client=firefox-a" onmousedown="return clk(this.href,'','','clnk','1','')"&gt;Cached&lt;/a&gt; - &lt;a href="http://www.google.com/search?hl=en&amp;amp;client=firefox-a&amp;amp;rls=com.ubuntu:en-US:unofficial&amp;amp;hs=RFy&amp;amp;q=related:en.wikipedia.org/wiki/Hundredth_Monkey"&gt;Similar pages&lt;/a&gt; - &lt;span class="bl"&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;client=firefox-a&amp;amp;rls=com.ubuntu%3Aen-US%3Aunofficial&amp;amp;hs=sZd&amp;amp;q=100th+monkey&amp;amp;btnG=Search#" id="gnl1" onclick="return google.x(this,function(){return gnb._add(this,'http://en.wikipedia.org/wiki/Hundredth_Monkey')})"&gt;Note this&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display: none;"&gt;gqqw9kMHZRoFt8OyvG9JlHlDgwW5sgV299RIBg3DVr8DolLpJiLqsJelqosQMCWJe3ghxm2XTUvAtSU1k0AvRYTKu3ZWsO88HHco&lt;/span&gt;&lt;/div&gt;&lt;!--n--&gt;&lt;!--m--&gt;&lt;/li&gt;&lt;li class="g"&gt;&lt;h3 class="r"&gt;&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.the100thmonkeystudio.com/" class="l" onmousedown="return clk(this.href,'','','res','2','')"&gt;The &lt;em&gt;100th Monkey&lt;/em&gt; Studio&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;div class="s"&gt;&lt;span style="font-size:85%;"&gt;An open art studio using art therapy and creativity in Portland Oregon.&lt;br /&gt;&lt;cite&gt;www.the&lt;b&gt;100thmonkey&lt;/b&gt;studio.com/ - 14k - &lt;/cite&gt;&lt;span class="gl"&gt;&lt;a href="http://72.14.205.104/search?q=cache:494I_o1YhsIJ:www.the100thmonkeystudio.com/+100th+monkey&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;cd=2&amp;amp;gl=us&amp;amp;client=firefox-a" onmousedown="return clk(this.href,'','','clnk','2','')"&gt;Cached&lt;/a&gt; - &lt;a href="http://www.google.com/search?hl=en&amp;amp;client=firefox-a&amp;amp;rls=com.ubuntu:en-US:unofficial&amp;amp;hs=RFy&amp;amp;q=related:www.the100thmonkeystudio.com/"&gt;Similar pages&lt;/a&gt; - &lt;span class="bl"&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;client=firefox-a&amp;amp;rls=com.ubuntu%3Aen-US%3Aunofficial&amp;amp;hs=sZd&amp;amp;q=100th+monkey&amp;amp;btnG=Search#" id="gnl2" onclick="return google.x(this,function(){return gnb._add(this,'http://www.the100thmonkeystudio.com/')})"&gt;Note this&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/blockquote&gt;Then, click on the "Cached" link to view the page from the &lt;span style="font-style: italic;"&gt;Google servers&lt;/span&gt; -- and avoid nastiness that might be found and the listed web sites themselves.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;However...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;That little trick doesn't completely protect you.  Don't believe me?  Just start up your favorite network sniffer (&lt;a href="http://www.tcpdump.org/"&gt;tcpdump&lt;/a&gt;, &lt;a href="http://www.wireshark.org/"&gt;wireshark&lt;/a&gt;, etc.).  You will see, if the page has certain types of content -- such as images, they will still come from the original web site.  Oops!  You have been identified, and hopefully not served.&lt;br /&gt;&lt;br /&gt;The way to avoid this is to Right Click on that "Cached" link, past it into a browser's URL bar and add "&amp;amp;strip=1" to the end of it, such as...&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:courier new;font-size:78%;"  &gt;http://www.google.com/search?q=cache:en.wikipedia.org\&lt;br /&gt;/wiki/Hundredth_Monkey+100th+monkey&lt;span style="color: rgb(255, 0, 0);"&gt;&amp;amp;strip=1&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now your sniffer will happily report that all information comes only from Google.&lt;br /&gt;&lt;br /&gt;Happy browsing!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-8191456754265462699?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/8191456754265462699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=8191456754265462699' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8191456754265462699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8191456754265462699'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/09/strip1-ftw.html' title='strip=1 ftw'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-4811358772228224567</id><published>2008-08-28T07:18:00.000-07:00</published><updated>2008-08-28T18:49:19.508-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='forensics'/><category scheme='http://www.blogger.com/atom/ns#' term='analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>SANS Forensics Blog is up!</title><content type='html'>Okay, you heard it here first!  &lt;a href="http://www.sans.org/"&gt;&lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.sans.org/"&gt;SANS&lt;/a&gt; has created a &lt;a href="http://sansforensics.wordpress.com/"&gt;new blog on digital forensics&lt;/a&gt;, and yours truly is the &lt;a href="http://sansforensics.wordpress.com/2008/08/27/known-plaintext-analysis-of-encoded-strings/"&gt;first poster&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;SANS has chosen a team of about 25 contributors to provide the latest news, tips, and techniques on the topic of forensics.  There are some great posts on the way, so enjoy!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-4811358772228224567?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/4811358772228224567/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=4811358772228224567' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/4811358772228224567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/4811358772228224567'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/08/sans-forensics-blog-is-up.html' title='SANS Forensics Blog is up!'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-1128648350480905306</id><published>2008-08-26T19:48:00.000-07:00</published><updated>2008-08-28T18:50:22.437-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='penetration test'/><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='pentest'/><category scheme='http://www.blogger.com/atom/ns#' term='Skoudis'/><category scheme='http://www.blogger.com/atom/ns#' term='San Antonio'/><category scheme='http://www.blogger.com/atom/ns#' term='Alamo'/><title type='text'>PenTest at the Alamo!</title><content type='html'>Last year I took my kids to San Antonio for some fall heat, &lt;a href="http://www.seaworld.com/sanantonio/"&gt;killer whales&lt;/a&gt;, and our first visit to &lt;a href="http://www.thealamo.org/"&gt;The Alamo&lt;/a&gt;.  I eventually had to be dragged away from the Bowie knife collection (note to wives:  &lt;span style="font-style: italic;"&gt;it's a guy thing&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;Now I'm ready to go back.  Not because I need more time with whales or knives, but because &lt;a href="http://www.sans.org/sanantonio08/"&gt;SANS San Antonio&lt;/a&gt; (Nov 8-13), will be featuring the new SEC560 Network Penetration and Ethical Hacking class.&lt;br /&gt;&lt;br /&gt;I have heard &lt;span style="font-style: italic;"&gt;fantastic&lt;/span&gt; things about this new class.  The courseware author, &lt;a href="http://www.counterhack.net/"&gt;Ed Skoudis&lt;/a&gt;, apparently pulled out all the stops putting this one together.  And, for Ed, that's really saying something.&lt;br /&gt;&lt;br /&gt;The class is being taught by Jim Shewmaker.  &lt;a href="http://jimshew.blogspot.com/"&gt;Shew&lt;/a&gt; is a great instructor, and it should be a rockin' fun time.  Also on site will be Tanya Baccam (Oracle-security-guru-extraordinaire) and Jonathan Ham.  I assisted Jonathan with the Google Hacking class in San Diego last year, and it was an excellent class... with attendees from the NSA to keep things extra interesting.&lt;br /&gt;&lt;br /&gt;Think about it... when it's &lt;span style="font-style: italic;"&gt;cold&lt;/span&gt; in November, you could be eating chips and salsa, drinking margaritas, and honing your &lt;a href="http://www.sans.org/sanantonio08/description.php?tid=1717"&gt;pen testing&lt;/a&gt; skills-- what could be better than that!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-1128648350480905306?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/1128648350480905306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=1128648350480905306' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/1128648350480905306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/1128648350480905306'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/08/pentest-at-alamo.html' title='PenTest at the Alamo!'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-3537327470804883722</id><published>2008-08-26T19:23:00.000-07:00</published><updated>2008-08-26T19:46:19.836-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IOS'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit framework'/><category scheme='http://www.blogger.com/atom/ns#' term='evilgrade'/><category scheme='http://www.blogger.com/atom/ns#' term='perl'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><title type='text'>Ah... finally an exploit framework I can sink my teeth into</title><content type='html'>Call me a curmudgeon, but I just cannot make myself learn Ruby.  I know I should, and I know this "&lt;a href="http://www.rubyonrails.org/"&gt;on rails&lt;/a&gt;" stuff is really cool, but days are short and I still haven't invented that cloning machine.  So, I was excited when I heard that Francisco Amato at &lt;a href="http://www.infobyte.com.ar/"&gt;InfoByte Security&lt;/a&gt; had released &lt;a href="http://www.infobyte.com.ar/developments.html"&gt;evilgrade&lt;/a&gt; &lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;-- with support for writing modules in perl.  &lt;span style="font-style: italic;"&gt;This is perl, &lt;a href="http://www.imdb.com/title/tt0107290/quotes"&gt;I know this&lt;/a&gt;!.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Also cool is the IOS-like command line interface.  I must admit I prefer bash or tcsh, but IOS is plenty familiar and easy to settle into.&lt;br /&gt;&lt;br /&gt;Francisco has a very useful &lt;a href="http://www.infobyte.com.ar/down/isr-evilgrade-Readme.txt"&gt;readme&lt;/a&gt; file posted as well as an impressive video &lt;a href="http://www.infobyte.com.ar/demo/evilgrade.htm"&gt;demonstration&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Check it out.  :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-3537327470804883722?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/3537327470804883722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=3537327470804883722' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3537327470804883722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/3537327470804883722'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/08/ah-finally-exploit-framework-i-can-sink.html' title='Ah... finally an exploit framework I can sink my teeth into'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-8665137049173387447</id><published>2008-06-29T21:52:00.000-07:00</published><updated>2008-06-29T21:56:33.711-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SANS'/><category scheme='http://www.blogger.com/atom/ns#' term='class'/><category scheme='http://www.blogger.com/atom/ns#' term='teaching'/><category scheme='http://www.blogger.com/atom/ns#' term='training'/><title type='text'>Teaching SEC401 at SANS Community Albuquerque 2008</title><content type='html'>I will be teaching the SANS Security Essentials (Security 401) class at the University of New Mexico August 11-16.  We'll be doing it  bootcamp-style (yeah, baby!), so sign up if you want to work hard, play hard, and meet some other security geeks.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sans.org/albuquerque08_cs/description.php?tid=1447"&gt;SANS Community Albuquerque 2008&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-8665137049173387447?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/8665137049173387447/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=8665137049173387447' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8665137049173387447'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8665137049173387447'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/06/teaching-sec401-at-sans-community.html' title='Teaching SEC401 at SANS Community Albuquerque 2008'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-8776262776936079004</id><published>2008-06-20T06:32:00.000-07:00</published><updated>2008-06-26T10:33:55.426-07:00</updated><title type='text'>Little Things like Butterfly Wings</title><content type='html'>Little things count.  They count a lot.  In fact, attention to the little things... the details... and how they fit together makes it easy to bring the big picture to realization. &lt;br /&gt;&lt;br /&gt;There are so many times that I have experienced large system failures because someone was too busy, too tired, too lazy, too rushed, too &lt;span style="font-style:italic;"&gt;something&lt;/span&gt; to do the job correctly.  The funny thing is... it is always more work to go back and fix what wasn't done right the first time than it would have to have done the job right the first time.  Intuitively people seem to understand this, but why don't they DO it?&lt;br /&gt;&lt;br /&gt;Recently I had a network meltdown because a developer on was building a network application.  This happened behind a firewall, which is an interesting story for another time.  Even though the network was "isolated" we experienced the meltdown because the developer glossed over some "little things" ... and so did I.&lt;br /&gt;&lt;br /&gt;His mistake was deciding that on this isolated little test network, he didn't need to follow the recommendations in the &lt;a href="http://www.faqs.org/rfcs/rfc826.html"&gt;RFC&lt;/a&gt; -- required by the test network switch he was using -- to re-send ARP packets to reset the aging table timeout.  This had a fascinating effect on the test network that was only illuminated by watch the switch port traffic.  For a short, initial period of time, the switch would dutifully forward packets from the port the test generator was plugged into to the port the receiving test system was connected to.  Then, after the timeout occurred, and no new ARP packet was seen, the switch happily turned itself into a dumb hub... dutifully forwarding packets to every port with link (including the uplink to the switch where the firewall was located).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;My&lt;/span&gt; mistake was believing that I had achieved isolation by routing a VLAN though a firewall and then back into the same switch as the production network.  I convinced myself that I was concerned with stability, not clever attackers or malware... and therefore became complacent.&lt;br /&gt;&lt;br /&gt;The engineer is fixing his problem (surely customers would not appreciate this test bench behavior).  And I have learned my lesson as well.&lt;br /&gt;&lt;br /&gt;The little things count -- just like &lt;a href="http://en.wikipedia.org/wiki/Butterfly_effect"&gt;butterfly wings&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;--john&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-8776262776936079004?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/8776262776936079004/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=8776262776936079004' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8776262776936079004'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/8776262776936079004'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/06/little-things-like-butterfly-wings.html' title='Little Things like Butterfly Wings'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-4631025679505160567</id><published>2008-03-23T15:09:00.000-07:00</published><updated>2008-03-23T15:27:23.919-07:00</updated><title type='text'>Helpful software or malware?</title><content type='html'>One thing I often do when visiting relatives is fix their computers.  They normally have various theories on what the problems are, but increasingly the issues are caused by "assistants" and "helpers" and "utilities" installed by hardware and software vendors on the systems of unsuspecting users.&lt;br /&gt;&lt;br /&gt;A perfect example is TGCMD (tgshell.exe).  This site has more details on this software:  &lt;a href="http://www.answersthatwork.com/Tasklist_pages/tasklist_t.htm"&gt;http://www.answersthatwork.com/Tasklist_pages/tasklist_t.htm&lt;/a&gt;&lt;br /&gt;including this amusing (though sad) comment:&lt;br /&gt;"Absolutely nightmarish software which eats up CPU, drives the hard disk hard, causes boot-up Kernel32 errors, generates illegal operations, invalid page faults and much more."&lt;br /&gt;&lt;br /&gt;I will add that it caused my in-laws' PC to hang with a "Cannot find tgshell.exe" error and take a very long time to start up.&lt;br /&gt;&lt;br /&gt;Sorry, but this is not only spyware (as mentioned at the link above), but -- since it is launching a continual, insidious DoS on the host computer -- in my opinion it's good, old-fashioned malware.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-4631025679505160567?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/4631025679505160567/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=4631025679505160567' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/4631025679505160567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/4631025679505160567'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/03/helpful-software-or-malware.html' title='Helpful software or malware?'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-534063731088657381</id><published>2008-01-07T09:36:00.000-08:00</published><updated>2008-01-07T09:58:23.846-08:00</updated><title type='text'>People who should know better</title><content type='html'>/soapbox-on&lt;br /&gt;&lt;br /&gt;People are worried about the wrong things.  This gets my bile up sometimes because they have all kinds of crazy rationalizations for their misunderstanding of risk.  For example, they might not want to fly or sky dive, but they get in a car all the time.  They neglect to look left and right before crossing the street.  They get complacent about all the little, important things their parents taught them when they were a kid.  Instead they are wooed by the F.U.D. spread by mass media.&lt;br /&gt;&lt;br /&gt;Fast-forward to the digital age.  It's the same thing.  It's not the little lock icon on the web site that makes you secure.  It's your behavior.  And, even worse is when the people who should know better, system administrators and system architects, build systems where the windows have bars, but the front door is left wide open.&lt;br /&gt;&lt;br /&gt;And complacency is not only for the uninformed.  Sometimes it's willful ignorance (or even flat-out stupidity) from people who should know better that creates the problems.  If someone says, "Oh, it's SSL encrypted," you had better challenge them by asking, "SSLv2 or SSLv3?  What is the cipher used?  Are you sure it is sent to encrypt?  Better yet, I'll sniff packets and check myself."  This happens because the people who should know better don't do their jobs.  And then (this is the best part), they defend their position vehemently.  As in, "Well, SSLv2 is good enough.  Do you think hackers really want this data?"  Or, as I heard not long a go (I kid you not), "Who the heck would crack a non-priveleged account?"&lt;br /&gt;&lt;br /&gt;Sigh.  It's a tough world out there folks.  If you should know better, act better.&lt;br /&gt;&lt;br /&gt;/soapbox-on (still)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-534063731088657381?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/534063731088657381/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=534063731088657381' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/534063731088657381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/534063731088657381'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2008/01/people-who-should-know-better.html' title='People who should know better'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114912809601666411</id><published>2006-05-31T19:09:00.000-07:00</published><updated>2006-05-31T19:14:56.020-07:00</updated><title type='text'>Trip to Chicago: Day 5</title><content type='html'>Day 5:  Union Railroad Museum&lt;br /&gt;This cool railroad museum is only 15 minutes from my grandmother's house.&lt;br /&gt;Even though it was stifling hot (and humid), we had fun riding on two different trains.  At one point, our train (which was electric) had to stop because we lost about 400 volts on the line.  This apparently happened because they were putting away some of the older trains.  After a few minutes of waiting, we were able to start up again.  Train travel must have require a measure of patience.&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02813.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02813.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02816.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02816.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02817.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02817.jpg" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a href='http://picasa.google.com/blogger/' target='ext'&gt;&lt;img src='http://photos1.blogger.com/pbp.gif' alt='Posted by Picasa' style='border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: initial; -moz-background-origin: initial; -moz-background-inline-policy: initial;' align='middle' border='0' /&gt;&lt;/a&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114912809601666411?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114912809601666411/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114912809601666411' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114912809601666411'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114912809601666411'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/trip-to-chicago-day-5.html' title='Trip to Chicago: Day 5'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114912767592965649</id><published>2006-05-31T18:55:00.000-07:00</published><updated>2006-05-31T19:07:55.943-07:00</updated><title type='text'>Trip to Chicago: Day 4</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02793.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02793.jpg" border="0" /&gt;&lt;/a&gt;  Day 4:  Fishing at Busha's house&lt;br /&gt;It was a rather pleasant day, and the girls and I fished for quite awhile -- a pretty strange thing for all of us.  The water was clear and we could cast right in front of the fish.  We caught two bass and a bluegill before everyone, including the fish, became bored.  Mica demonstrated some excellent casting skills... better than mine.&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02799.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02799.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02796.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02796.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02810.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02810.jpg" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a href='http://picasa.google.com/blogger/' target='ext'&gt;&lt;img src='http://photos1.blogger.com/pbp.gif' alt='Posted by Picasa' style='border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: initial; -moz-background-origin: initial; -moz-background-inline-policy: initial;' align='middle' border='0' /&gt;&lt;/a&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114912767592965649?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114912767592965649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114912767592965649' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114912767592965649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114912767592965649'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/trip-to-chicago-day-4.html' title='Trip to Chicago: Day 4'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114903142698153258</id><published>2006-05-30T16:23:00.000-07:00</published><updated>2006-05-31T18:51:24.510-07:00</updated><title type='text'>Dinner at Frontera Grill</title><content type='html'>&lt;p class="mobile-photo"&gt;&lt;img src="http://photos1.blogger.com/blogger/6334/828/0/05-30-06_1808-726981.jpg" width="320" /&gt;&lt;/p&gt;&lt;p class="mobile-post"&gt;Carly grimaces for the camera at Frontera Grill.  I decided to pass on the huitlecoche.  Someday I *will* try this corn fungus, but today it sounded too plain -- especially next to the other platas poqueños.&lt;/p&gt;&lt;p class="mobile-post"&gt;We did see Rick Bayless.  He was working behind the bar, and Karen noticed.  Later he came to talk to a couple at the table next to us.  Apparently they had moved from Chicago to Atlanta and wanted to come back to see how Frontera was doing.  They gushed for several minutes, but that must've been the highlight of their meal, because they frowned a lot after that.&lt;/p&gt;&lt;p class="mobile-post"&gt;I had a few small plates:  Gorditas (teeny, tiny tacos) filled with duck carnitas and garnished with some seriously hot sauce.   The sopes (tiny masa tarts) I ordered were also delicious.  They were contained an assortment of fillings, including chicken in mole rojo and guacamole.  Mica ordered some really good peach ice cream for dessert.  It came with cajeta (goat milk caramel), which was pretty good but a little heavy on the cinnamon.&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114903142698153258?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114903142698153258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114903142698153258' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114903142698153258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114903142698153258'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/dinner-at-frontera-grill.html' title='Dinner at Frontera Grill'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114861925599922229</id><published>2006-05-25T21:43:00.000-07:00</published><updated>2006-05-25T21:54:16.010-07:00</updated><title type='text'>Soap Box:  Greedy Music Moguls</title><content type='html'>I think the artists are awesome.  I think they are creative, work really hard, and often want to make the world a better place.  The music labels and the RIAA, on the other hand, boil my blood.&lt;br /&gt;&lt;br /&gt;I was looking at some statistics on how much was being made for them via iTunes, and how much they felt they should be making from music sales overall.  Their reaction:  Waaah!  People aren't generating enough revenue in music sales for us.  My reaction:  Egads!  These jerks should feel lucky that they are making as much as they are.  They point out that 99 cent downloads don't earn as much for them as a $15 CD does.  Ummm... Duh!  That is exactly why people are buying those downloads.  I always hated buying a CD full of songs I didn't care about just to get the two or three that I wanted.  I think most people feel this way -- at least about a portion of the artists whose music they like.&lt;br /&gt;&lt;br /&gt;I think these music execs need to crawl on hands-and-knees over to Steve Jobs and thank him profusely.  While they are at it, they should send a little gratitude my way.  I'm sick of listening to them disparage us all for not buying more overpriced music we didn't want anyway.   :-p&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114861925599922229?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114861925599922229/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114861925599922229' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114861925599922229'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114861925599922229'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/soap-box-greedy-music-moguls.html' title='Soap Box:  Greedy Music Moguls'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114861814820678652</id><published>2006-05-25T21:13:00.000-07:00</published><updated>2006-05-25T21:55:27.893-07:00</updated><title type='text'>Vacation to Chicago: Day 2</title><content type='html'>Day 2: Denver to Lincoln&lt;br /&gt;On the second day of our trip, we stopped at a visitors' center in Nebraska and asked for recommendations of things to see.  Karen was hoping for something like the world's biggest ball of twine.  What the nice old lady at the visitors' center recommended was almost as good:  &lt;a href="http://www.archway.org/"&gt;The &lt;/a&gt;&lt;a href="http://www.archway.org/"&gt;&lt;img style="margin: 0px 10px 10px 0px; float: right;" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02777.jpg" border="0" /&gt;&lt;/a&gt;&lt;a href="http://www.archway.org/"&gt;Great Platt River Road Archway Monument&lt;/a&gt; was equal parts Disney, American cheese, and pioneer pride.  There was a, as Carly put it, "ginormous" bison statue; an outdoor maze; an escalator leading up into the interactive tour with a wagon train projected on the screen around you as you "entered" the pioneer life; and a procession of exhibit areas that led up through the Pony Express, to the railroads, to the Eisenhower highway project.  &lt;em&gt;Random factoid #1&lt;/em&gt;:  Eisenhower was so impressed by the autobahn during the war that he came back to adopt the idea in the States.  All of this in a wood, stone, and acid-treated stainless steel monumount stretching over I-80 in Kearny, Nebraska.  Oh, and we can't forget &lt;em&gt;Random factoid #2&lt;/em&gt;:  The hapless Albert Schmidt (Jack Nicholson) in About Schmidt visited the monument on his post-retirement trip from Omaha to Denver.&lt;br /&gt;Now this, ladies and gentlemen, is the very definition of American Heartland!&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02780.jpg"&gt;&lt;img style="margin: 0px 10px 10px 0px; float: right;" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02780.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02786.jpg"&gt;&lt;img style="margin: 0px 10px 10px 0px; float: right;" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02786.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02788.jpg"&gt;&lt;img style="margin: 0px 10px 10px 0px; float: right;" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02788.jpg" border="0" /&gt;&lt;/a&gt; &lt;a href="http://picasa.google.com/blogger/" target="ext"&gt;&lt;img src="http://photos1.blogger.com/pbp.gif" alt="Posted by Picasa" style="border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial;" align="middle" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114861814820678652?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114861814820678652/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114861814820678652' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114861814820678652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114861814820678652'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/vacation-to-chicago-day-2.html' title='Vacation to Chicago: Day 2'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114861287231226981</id><published>2006-05-25T20:02:00.000-07:00</published><updated>2006-05-25T20:07:52.320-07:00</updated><title type='text'>Vacation to Chicago:  Day 1</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02761.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02761.jpg" border="0" /&gt;&lt;/a&gt;  Day One:  Albuquerque to Denver&lt;br /&gt;On the way to Denver, we decided, impromptu, to stop at the US Olympic Center in Colorado Springs.  It had been about 22 years since I had been there for a Junior Olympics Judo tournament.  Things had really changed... a lot.  We took a great little tour, saw the synchronized swimmers practicing, and heard about a rising shotgun star (I'm sad to say that I heretofore had no idea shotgun was an Olympic sport).  Everyone really enjoyed this little excursion, and we had dinner afterward in downtown Colorado Springs at Old Chicago.  That seemed like an appropriate way to start off our trip to Chi Town!&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02762.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02762.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02766.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02766.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02770.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02770.jpg" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a href='http://picasa.google.com/blogger/' target='ext'&gt;&lt;img src='http://photos1.blogger.com/pbp.gif' alt='Posted by Picasa' style='border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: initial; -moz-background-origin: initial; -moz-background-inline-policy: initial;' align='middle' border='0' /&gt;&lt;/a&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114861287231226981?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114861287231226981/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114861287231226981' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114861287231226981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114861287231226981'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/vacation-to-chicago-day-1.html' title='Vacation to Chicago:  Day 1'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114790677852873009</id><published>2006-05-17T15:57:00.000-07:00</published><updated>2006-05-17T15:59:38.533-07:00</updated><title type='text'>Mother's/Father's Day Preformance</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02727.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02727.jpg" border="0" /&gt;&lt;/a&gt;Mica's class prepared for their "Mother's/Father's Day Performance" for several weeks. All of the children read inspirational poems (deep for 2nd grade), sang songs and read dedications to their parents. Mica read clearly and loudly (good projection skills!) and had a great smile on her face. I took the first picture before they started. I told her it might be the last clear one I got of her.&lt;br /&gt;&lt;br /&gt;Carly and Hannah were wearing the exact same dress, so I had to take a picture.  They are both hams, can you tell?&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02726.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02726.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02728.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02728.jpg" border="0" /&gt;&lt;/a&gt; &lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/3894/2930/640/DSC02729.jpg"&gt;&lt;img style="CLEAR: all; FLOAT: right; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/3894/2930/320/DSC02729.jpg" border="0" /&gt;&lt;/a&gt;&amp;nbsp;&lt;a href='http://picasa.google.com/blogger/' target='ext'&gt;&lt;img src='http://photos1.blogger.com/pbp.gif' alt='Posted by Picasa' style='border: 0px none ; padding: 0px; background: transparent none repeat scroll 0% 50%; -moz-background-clip: initial; -moz-background-origin: initial; -moz-background-inline-policy: initial;' align='middle' border='0' /&gt;&lt;/a&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114790677852873009?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114790677852873009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114790677852873009' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114790677852873009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114790677852873009'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/mothersfathers-day-preformance.html' title='Mother&apos;s/Father&apos;s Day Preformance'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-27774445.post-114712549727613531</id><published>2006-05-08T14:50:00.000-07:00</published><updated>2006-05-08T17:07:20.526-07:00</updated><title type='text'>Woot! First Blog Entry</title><content type='html'>Woot!  My first blog posting!  Except... does anyone really care?  I am not really a big fan of weblogs.  However, I have come to realize three things that became the impetus for the creating of this blog:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Venting on a blog, like talking to yourself, can be therapeutic,&lt;/li&gt;&lt;li&gt;Most web logs are more intersting to look at than free web-hosting template home pages,&lt;/li&gt;&lt;li&gt;If I post an idea here first, and then someone patents it... I can claim prior work!  Right?&lt;/li&gt;&lt;/ol&gt;--john&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27774445-114712549727613531?l=perpetual-soap-box.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://perpetual-soap-box.blogspot.com/feeds/114712549727613531/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=27774445&amp;postID=114712549727613531' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114712549727613531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27774445/posts/default/114712549727613531'/><link rel='alternate' type='text/html' href='http://perpetual-soap-box.blogspot.com/2006/05/woot-first-blog-entry.html' title='Woot! First Blog Entry'/><author><name>John Jarocki</name><uri>http://www.blogger.com/profile/11963202442967768759</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
