<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>The Art Of Noh</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/" />
    <link rel="self" type="application/atom+xml" href="http://www.noh.ro/blog/atom.xml" />
    <id>tag:www.noh.ro,2011-05-31:/blog//1</id>
    <updated>2011-05-31T09:55:54Z</updated>
    <subtitle>The changing face of computer security.</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 5.1</generator>

<entry>
    <title>Chromebook - A New Class of Risks</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2011/05/chromebook-a-.html" />
    <id>tag:www.noh.ro,2011:/blog//1.144</id>

    <published>2011-05-31T09:18:16Z</published>
    <updated>2011-05-31T09:55:54Z</updated>

    <summary> We are certainly living in interesting times. It was less than a week ago that a rumor appeared that Apple is going to switch to ARM processors for its next generation of laptops. (http://www.pcworld.com/article/227301/apple_may_switch_to_arm_chips_in_laptops.html) Obviously, this has very interesting...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p><br /></p>

<p>We are certainly living in interesting times. It was less than a week ago that a rumor appeared that Apple is going to switch to ARM processors for its next generation of laptops. (http://www.pcworld.com/article/227301/apple_may_switch_to_arm_chips_in_laptops.html)<br />
Obviously, this has very interesting implications for the future of computing and seems to indicate the increasing need for a computing platform that uses less power and that can be used for a day without the need for charging.</p>

<p>Earlier today, Google surprised the world by announcing the Google Chromebook - a netbook (huh, aren't netbooks dead?) computer concept, built for now by Samsung and Acer around the Atom N750 CPUs. With 2GB of RAM and 16GB of SSD storage, the specifications are somehow low-end, however, this might not be a problem because as Google says in their promo, the web has more storage space than any computer. The price, when these will be available, is believed to be in the range of $400-$500.</p>

<p>When I saw the announcement, I thought to myself - why would anybody buy something like this? Low end hardware, more expensive than other netbooks and definitively not as attractive as an iPad? Obviously, the answer here is in the "cloud".</p>

<p>Google Chrome OS is the first commercially available consumer cloud-centric OS. It is designed around the concept of "expendable" terminals that you can lose, drop or simply throw away without fear of losing your data, which is safely stored into the cloud. From this point of view, the operating system could get damaged or even infected with malware and all you have to do is to reinstall it and re-authenticate with the cloud storage to get exactly the same computing experience as before the crash.<br />
Here, I would like to make a mention about the "infected with malware" part. Interesting, Google's promo claims "it doesn't need virus protection". </p>

<p><br />
<img alt="chromebook_vir.png" src="http://www.noh.ro/blog/archives/chromebook_vir.png" width="648" height="457" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" /></p>

<p><br />
Sadly, this claim comes at a pretty bad time, since the French company VUPEN Security having announced only a few days ago that they've cracked the security protections build by Google into Chrome and are now able to infect a computer through a malicious page when it's browsed.<br />
Of course, some might say, "even if I get infected, I'll just reinstall, put back my credentials and bye bye virus!". I agree that is absolutely true - Chrome OS has been designed in such a way that it's extremely resilient to modifications and has a good self healing capability. </p>

<p>Several years ago, I wrote an article saying that malware evolves based on three conditions:</p>

<p>•	When hardware and operating system evolve (eg. Windows 95 killed boot viruses)<br />
•	When security defenses change (eg. firewalls killed network worms)<br />
•	When people start using computers in a different way (eg. Social networks)</p>

<p>With the Chromebook, we have an interesting case, when all these three conditions are met. It's a (somehow-)new operating system, it has new security defenses into place (self healing, updates) and it's used in a different way - the data is not on the computer but in the cloud.<br />
So, what can we expect from a security point of view? Obviously, with all your data being available into the cloud, in one place, available 24/7 through a fast internet link, this will be a goldmine for cybercriminals. All that is necessary here is to get hold of the authentication tokens required to access the cloud account; this is actually already happening with malware that has become "steal everything" in the past years. Although the endpoint is now more secure, the situation is that the data is in a more risky place and it will be much easier to silently steal it. </p>

<p>Most of the attacks nowadays focus on infecting the machine and then hiding the presence of the malware for as much time as possible to intercept banking transactions or credit card numbers. </p>

<p>With Cloud centric OS'es, the race will be towards stealing access credentials, after which, it's game over. Who needs to steal banking accounts, when you have Google Checkout? Or, who needs to monitor passwords, when they're all nicely stored into the Google Dashboard?<br />
Of course, this could seem a bit gloomy, but these problems are inherent to any Cloud-centric OS. </p>

<p>Earlier today, I got asked by a friend- "How is Chrome OS from a security point of view, better or worse?". I answered, "It's better, but much worse".<br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Xtreamer e-TRAYz NAS</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2010/02/xtreamer-e-tray.html" />
    <id>tag:www.noh.ro,2010:/blog//1.143</id>

    <published>2010-02-10T10:53:05Z</published>
    <updated>2011-05-31T10:29:36Z</updated>

    <summary>Couple of weeks ago, I came by an interesting device - the Xtreamer e-TRAYz NAS. This is a little device that looks like an UPS and can host up to two SATA HDDs inside. After checking the features list, I...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="devicefilesystem" label="Device file system" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="etrayz" label="eTRAYz" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="harddiskdrive" label="Hard disk drive" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="linux" label="Linux" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="nas" label="NAS" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="operatingsystem" label="Operating system" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>Couple of weeks ago, I came by an interesting device - the <a href="http://www.xtreamer.net/etrayz/overview.aspx">Xtreamer e-TRAYz NAS</a>.</p>

<p><a href="http://www.noh.ro/blog/xtreamer_etrayz.jpg"><img alt="xtreamer_etrayz.jpg" src="http://www.noh.ro/blog/assets_c/2010/02/xtreamer_etrayz-thumb-320x257-5.jpg" class="mt-image-center" style="margin: 0pt auto 20px; text-align: center; display: block;" height="257" width="320"></a></p>

<p>This is a little device that looks like an UPS and can host up to two SATA HDDs inside. After checking the features list, I decided to get one and use it at home for backup and such.</p>

<p>The device sells without HDDs. Personally, I decided to use it with two WD 2TB Green HDDs.</p>

<p>A couple of nice things about the e-TRAYz NAS: first of all, it runs Linux.</p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">~# uname -a
Linux etrayz 2.6.24.4 #1 Thu Dec 10 11:35:17 KST 2009 armv5tejl 
ARM926EJ-S rev 5 (v5l) Oxsemi NAS GNU/Linux</pre>

<p>It has ssh, apache with php support, smb, ftp and surprisingly, even mysql and unrar. </p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">~# unrar | head -3
UNRAR 3.80 freeware      Copyright (c) 1993-2008 Alexander Roshal
Usage:     unrar command...
~# file /usr/bin/unrar
/usr/bin/unrar: ELF 32-bit LSB executable, ARM, version 1 (SYSV), dynamically linked
(uses shared libs), for GNU/Linux 2.6.14, stripped</pre>

<p><br />
The hardware runs on an <a href="http://www.arm.com/products/processors/classic/arm9/arm926.php">ARM926EJ-S CPU</a>, which according to the description page is an "entry point processor capable of supporting a full Operating System such as Linux, Windows CE, and Symbian".</p>

<pre style="background: green  none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">~# cat /proc/cpuinfo
Processor       : ARM926EJ-S rev 5 (v5l)
BogoMIPS        : 183.09
Features        : swp half thumb fastmult edsp java
CPU implementer : 0x41
CPU architecture: 5TEJ
CPU variant     : 0x0
CPU part        : 0x926
CPU revision    : 5
Cache type      : write-back
Cache clean     : cp15 c7 ops
Cache lockdown  : format C
Cache format    : Harvard
I size          : 32768
I assoc         : 4
I line length   : 32
I sets          : 256
D size          : 32768
D assoc         : 4
D line length   : 32
D sets          : 256
Hardware        : Oxsemi NAS
Revision        : 0000
Serial          : 00000acbcaf52a80</pre>

<p>As an interesting note, this is probably that first CPU that I see with native Java support.</p>

<p>The system also features 128MB of RAM and during installation, is configured with 500MB of swap space:</p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">/var/log# free
             total       used       free     shared    buffers  cached
Mem:        126052      95108      30944          0       4956   46284
-/+ buffers/cache:      43868      82184
Swap:       499896       2036     497860</pre>

<p>The CPU is not very fast, for instance, it does MD5 at about 12MB/s:</p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">[11:~]$ dd if=/dev/zero  bs=10240 count=10000 | md5sum -b
10000+0 records in
10000+0 records out
102400000 bytes (102 MB) copied, 7.94591 s, 12.9 MB/s</pre>

<p>To compare, a MacMini with an Intel Core 2 Duo CPU at 2.0Ghz does about 200MB/s.</p>

<p>The 2TB WD Caviar Green disks are not fast, but in a NAS with 100Mb link, speed is not such a big issue. </p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">[13:~]$ hdparm -tT /dev/sda
/dev/sda:
 Timing cached reads:   228 MB in  2.00 seconds = 113.85 MB/sec
 Timing buffered disk reads:   52 MB in  3.11 seconds =  16.71 MB/sec</pre>

<p>Reading is around 16MB/s. Comparatively, on an Core 2 Duo machine, the same disk achieves around 97MB/s.</p>

<p>Now, for the smart stuff inside this device. Obviously, it has been designed by programmers, with programmers and heavy tech users in mind.</p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">[20:/]$ mount
/dev/md0 on / type ext3 (rw,noatime,nodiratime)
/dev/md2 on /home type xfs (rw,noatime,nodiratime,prjquota)</pre>

<p>While the root is formatted with ext3, it has noatime and nodiratime turned on - nice! Additionally, the storage partition (which is raid1 for me) is formatted not with ext3, but XFS! XFS is my preferred choice on Linux, glad to see the people designing it knew their ins and outs.</p>

<p>Additionally, there is a lot of fine tuning in /etc/rc.local to optimize power usage, temperature and fan control.</p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">echo 1 &gt; /sys/module/thermAndFan/parameters/output_flag
echo 50 &gt; /sys/module/thermAndFan/parameters/cold_limit
echo 1 &gt; /sys/module/thermAndFan/parameters/hot_limit
echo "60" &gt; /proc/sys/vm/dirty_ratio
echo "1" &gt; /proc/sys/vm/dirty_background_ratio
echo "core.%e" &gt; /proc/sys/kernel/core_pattern
</pre>

<p>Again, respect to the people who produced the configuration, they didn't just dump some Linux on it but knew how to properly finetune it for the device.</p>

<p>Now, for the eye candy and GUI:</p>

<p><a href="http://www.noh.ro/blog/xtreamerweb.jpg"><img alt="xtreamerweb.jpg" src="http://www.noh.ro/blog/assets_c/2010/02/xtreamerweb-thumb-320x199-7.jpg" class="mt-image-center" style="margin: 0pt auto 20px; text-align: center; display: block;" height="199" width="320"></a></p>

<p>A number of very nice features can be accessed through the web interface, for instance, the BitTorrent client and rapidshare direct download client. I found the BitTorrent to be particularly funny as it features a preinstalled searchable RSS feed to ISOHUNT and Mininova:</p>

<p><a href="http://www.noh.ro/blog/xtreamertorrent.jpg"><img alt="xtreamertorrent.jpg" src="http://www.noh.ro/blog/assets_c/2010/02/xtreamertorrent-thumb-320x130-9.jpg" class="mt-image-none" style="margin: 0pt auto 20px; text-align: center; display: block;" height="130" width="320"></a></p>

<p>There are a couple of other nifty features in this device, but I'll let you discover them for yourself. The eTRAYz can be purchased in Romania from <a href="http://xtreamer.ro/comanda.php">xtreamer.ro</a>, for a promotional price of 549 RON (133 EUR).</p>

<p>Personally, I think it's worth!</p>

<p><b>Update (2010-02-11):</b></p>

<p>My friend <a href="http://razvan.musaloiu.com/">Razvan Musaloiu-E</a> asked about Gigabit support. Here's a "dmesg | grep eth0":</p>

<pre style="background: green none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;">eth0: PHY is LSI ET1011C
eth0: GMAC ver = 51, vendor ver = 17 at 0xe8000000, IRQ 8
eth0: Found PHY at address 1, type 0x0282f014 -> 10/100/1000
eth0: Ethernet addr: 00:1c:85:20:0f:dc
eth0: PHY is LSI ET1011C
eth0: LSI ET1011C PHY no Rx clk workaround start
eth0: LSI ET1011C PHY no Rx clk workaround end
eth0: PHY is LSI ET1011C</pre>

<p>So it looks like Gigabit support is there too, but to be honest, I don't have a router and cables to test it.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Why is Apple Meddling With My Windows AutoRun?</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2009/11/why-is-apple-me.html" />
    <id>tag:www.noh.ro,2009:/blog//1.142</id>

    <published>2009-11-09T14:18:27Z</published>
    <updated>2009-11-09T14:29:36Z</updated>

    <summary>In every system designed by man, there is always a balance between features, usability and security. While designing pretty, easy to use and secure systems is possible, quite often this is not what the users get, or, worse, this is...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="itunesautorunsecurityissueapplevmsmalware" label="itunes autorun security issue apple vms malware" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>In every system designed by man, there is always a balance between features, usability and security. While designing pretty, easy to use and secure systems is possible, quite often this is not what the users get, or, worse, this is not what the users want.</p>

<p>The most popular example of this applies to Apple. Focusing on eye-catching designs and easy to use products, Apple is listed in almost every marketing book as a success story.</p>

<p>Interestingly, maybe their second most popular software product, Mac OS X (after iTunes) represents a curious blend between eye-catching, easy to use, flexible, usable and decently secure, modern operating system. Please notice how I avoided saying "secure" and instead, wrote "decently secure". Not wanting to start a holy war, I'd like to state that no operating system is bulletproof. Or, if an operating system even remotely tries to achieve that, nobody really wants to use it. Take VMS for instance; it was maybe one of the most secure operating systems ever design, yet, it was a pain to use. Ten years ago, in my University, the people doing schoolwork on VMS dreamed of doing it on Linux. Yet, a computer running VMS with 4MB of RAM and a 40MB hard drive could host 50 concurrent users, while a similar Linux computer started having issues with more than 10 users. VMS was not only secure, but it was resource efficient as well. It was that good. Yet, it went into oblivion, just like it will happen to any other secure but a-pain-to-use OS.</p>

<p>With Windows 7, Microsoft made an interesting move. The developer of the most attacked operating system in the world decided to turn off an age-old option. This was one of the options that made the operating system easier to use but much, much more insecure. I'm talking of course about AutoRun.</p>

<p>You can imagine my surprise when I got the following message from iTunes, while plugging my iPod to transfer some newly purchased albums:</p>

<p><img alt="itunesfail.png" src="http://www.noh.ro/blog/itunesfail.png" width="381" height="173" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" /></p>

<p>So, iTunes detected that my system was more secure but less usable, and decided that maybe it's a good idea to change that back! My surprise was even bigger after seeing the following message from iTunes:</p>

<p><img alt="itunes_fail2.png" src="http://www.noh.ro/blog/itunes_fail2.png" width="381" height="118" class="mt-image-center" style="text-align: center; display: block; margin: 0 auto 20px;" /><br />
 <br />
Therefore, even if AutoRun is off, iTunes will still recognize my CDs! </p>

<p>With that in mind, Apple's decision with iTunes doesn't make any sense. It took Microsoft more than 25 years to finally understand how important security is, and then it took them another 5 years to understand that AutoRun is inherently flawed and insecure, so it needs to be deactivated by default.</p>

<p>As I was saying, Apple is a success story when it comes to combining easy to use technology with eye catching design, while keeping it also decently secure. It is a real pity though when somebody finds slips like the one above. Will it also take them 5 or 10 or even 25 years or so to understand the dangers of AutoRun?</p>

<p>I certainly hope not.</p>

<p>[guest editorial written for Threatpost.com - <a href="http://threatpost.com/en_us/blogs/why-apple-meddling-my-windows-autorun-110509">check the original post here</a>]</p>]]>
        
    </content>
</entry>

<entry>
    <title>Crawling Twitter</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2009/10/crawling-twitter-malware.html" />
    <id>tag:www.noh.ro,2009:/blog//1.141</id>

    <published>2009-10-20T11:11:57Z</published>
    <updated>2009-10-20T11:34:46Z</updated>

    <summary>Slides from my Virus Bulletin 2009 presentation (together with Morton Swimmer) in Geneva: Twarfing: Malicious TweetsView more presentations from Costin Raiu. Additionally, if you can read Romanian, I&apos;ve written a short story about the project for my friend Radu Georgescu&apos;s...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="arts" label="Arts" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="geneva" label="Geneva" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="ontheweb" label="On the Web" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="onlinecommunities" label="Online Communities" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="radugeorgescu" label="Radu Georgescu" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="shortstory" label="Short story" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="socialnetworking" label="Social Networking" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="twitter" label="Twitter" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="twittersecuritycrawlerkrabkaspersky" label="twitter security crawler krab kaspersky" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>Slides from my Virus Bulletin 2009 presentation (together with Morton Swimmer) in Geneva:</p>

<div style="width: 425px; text-align: left;" id="__ss_2068376"><a style="margin: 12px 0pt 3px; font-family: Helvetica,Arial,Sans-serif; font-style: normal; font-variant: normal; font-weight: normal; font-size: 14px; line-height: normal; font-size-adjust: none; font-stretch: normal; display: block; text-decoration: underline;" href="http://www.slideshare.net/craiu/twarfing-malicious-tweets" title="Twarfing: Malicious Tweets">Twarfing: Malicious Tweets</a><object style="margin: 0px;" height="355" width="425"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=crmsvb09-090925165928-phpapp01&amp;stripped_title=twarfing-malicious-tweets"><param name="allowFullScreen" value="true"><param name="allowScriptAccess" value="always"><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=crmsvb09-090925165928-phpapp01&amp;stripped_title=twarfing-malicious-tweets" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="355" width="425"></embed></object><div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration: underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration: underline;" href="http://www.slideshare.net/craiu">Costin Raiu</a>.</div></div>

<p>Additionally, if you can read Romanian, I've written a short story about the project for my friend Radu Georgescu's blog here (thanks for the invitation, Radu!):</p>

<p><a href="http://www.radugeorgescu.ro/2009/10/15/malware-de-pe-twitter/">http://www.radugeorgescu.ro/2009/10/15/malware-de-pe-twitter/</a></p>

<p>Enjoy,<br />
Costin<br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>The dark side of teaching</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2008/08/the-dark-side-o.html" />
    <id>tag:www.noh.ro,2008:/blog//1.140</id>

    <published>2008-08-08T11:11:55Z</published>
    <updated>2008-08-08T16:29:03Z</updated>

    <summary>Grant Joy runs a program that surreptitiously records every keystroke on his machine, including user names, passwords, and credit-card numbers. And Thomas Fynan floods a bulletin board with huge messages from fake users. Yet Joy and Fynan aren&apos;t hackers—they&apos;re students...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The List of Dubious Research" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="viruswritingteachingdarkside" label="virus writing teaching dark side" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p><i>Grant Joy runs a program that surreptitiously records every keystroke on his machine, including user names, passwords, and credit-card numbers. And Thomas Fynan floods a bulletin board with huge messages from fake users. Yet Joy and Fynan aren't hackers—they're students in a computer-security class at Sonoma State University. And their professor, George Ledin, has showed them how to penetrate even the best antivirus software.</i></p>

<p><a href="http://www.newsweek.com/id/150465">http://www.newsweek.com/id/150465</a></p>

<p>Back in my university years, we had course dealing with the topic of Data Communications. Not unusual for my faculty, the lab part of the course included a couple of things which had nothing to do with communications. For instance,  there was one homework which requested the students to write a boot virus. I went to the assistant and asked for another assignment, as writing viruses is not something I wanted to do. The assistant refused my proposal, refused discussing the subject (he was 'busy') and subsequently gave me 0 points for that particular homework.</p>

<p>Every now and then, in a teaching institution, somebody comes up with the brilliant idea of teaching students about malware. I am not joking here, it IS a brilliant idea. What is however wrong with it, in 99% of the cases, is that the people who come up with the idea have absolutely no clue about ethics or just don't care about it. They also do not understand that writing malware is not the best way to teach people about how to protect against it. Actually, writing malware is the easy way; it is much easier to write malware than writing antivirus programs. Of course, there is also a dark attraction towards writing malware and young people are easy to fall prey to it.</p>

<p>Back to my university years and to the boot virus writing homework, only a few people bothered doing it. Of them, most actually took the <a href="http://en.wikipedia.org/wiki/Michelangelo_(virus)">Michaelangelo</a> (March6) sourcecode and shuffled it around. A few years later, I heard that homework was removed from the course's curriculum. Most of the people were just taking existing boot viruses and patching them. And it wasn't really a Data Communications assignment per-se.</p>

<p>There are many other more interesting things to teach about than writing viruses, sending spam and circumventing protection solutions. Yet, there will always be people willing to join the dark side, for one reason or another.</p>

<p>The bad thing is that their number seems to be increasing from year to year.</p>]]>
        
    </content>
</entry>

<entry>
    <title>LinkedIn 419 scam</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/10/linkedin-419-sc.html" />
    <id>tag:www.noh.ro,2007:/blog//1.139</id>

    <published>2007-10-22T14:48:30Z</published>
    <updated>2007-10-22T14:52:42Z</updated>

    <summary>Bad guys using LinkedIn for what it seems like a 419 scam: Simpson Millar’s CONSULT AND CHAMBER, LIVEPOOL UNITED KINGDOM Tel: xxxx Email: xxxx How are you? i trust you are having a nice day. I am mailing you in...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="419scamlinkedin" label="419 scam linkedin" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>Bad guys using LinkedIn for what it seems like a 419 scam:</p>

<p><i>Simpson Millar’s CONSULT AND CHAMBER,<br />
LIVEPOOL UNITED KINGDOM<br />
Tel: xxxx<br />
Email: xxxx</p>

<p>How are you? i trust you are having a nice day. I am mailing you in reference of investment in your country through you. I am delighted to let you know that, am a consultant and associate of Simpson Millar’s CONSULT AND CHAMBER, UNITED KINGDOM.</p>

<p>I have a client (Kurt Kahle) based here in the UK, who died in the year 2000 with all the members of the Family died in the Plane Crash. You can as well confirm this news at the BBC News Website:<br />
(http://news.bbc.co.uk/1/hi/world/europe/859479.stm)</p>

<p>leaving behind the sum of GBP 11, 520,000.00 (Eleven Million, Five Hundred and Twenty Thousand Pounds). Before his death he disclosed to me his intention of investing in Real Estate business in foreign country and I have not been able to contact any of his family members. He further told me that he deposited this money in Security Company GERMANY for this project.</p>

<p>Meanwhile, i would want us to discuss on how this investment we be done, I am entrusting you with the transaction, since i have not been able to contact any of his family members. As soon as i received from you the confirmation of taking care of my late client properties, we shall then been discussing on how to consult the security company in GERMANY, on how this fund should be release to you for the investment properly.</p>

<p>Wait to hear from you soonest.</p>

<p>Regards</p>

<p>Johnson Mills</p>

<p>Company: Simpson Millar LLP<br />
Job Title: Project<br />
Description: Investment Project<br />
</i></p>]]>
        
    </content>
</entry>

<entry>
    <title>Audio stock spam</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/10/audio-stock-spa.html" />
    <id>tag:www.noh.ro,2007:/blog//1.138</id>

    <published>2007-10-18T14:58:48Z</published>
    <updated>2007-10-18T15:04:14Z</updated>

    <summary>Today I&apos;ve seen a couple of reports from various people that the Storm gang has changed once again tactics and started sending out MP3 files with pump and dump stock hints. Here&apos;s one such example received by my girlfriend on...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>Today I've seen a couple of reports from various people that the Storm gang has changed once again tactics and started sending out MP3 files with pump and dump stock hints.</p>

<p><span class="mt-enclosure mt-enclosure-audio"><a href="http://www.noh.ro/blog/bbrown.mp3">Here's one such example</a></span> received by my girlfriend on her Yahoo e-mail account.</p>

<p>The stock they are spamming, as far as I can make it from the bad quality MP3 is:</p>

<p>    <a href="http://finance.google.com/finance?q=exto">http://finance.google.com/finance?q=exto</a></p>

<p>So far it seems that the method is not as good as the old fashioned plain text stock spam but I'll keep an eye on it to see if it picks up.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Restarting in 5</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/10/restarting-in-5.html" />
    <id>tag:www.noh.ro,2007:/blog//1.137</id>

    <published>2007-10-12T08:46:32Z</published>
    <updated>2008-11-21T21:06:18Z</updated>

    <summary>Earlier today I launched a wget to fetch FC7 from www.linuxusers.ro. While I was doing other things, I saw the following window appearing on my laptop: I wonder if Windows figured out I was downloading Fedora and decided to do...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="windowsrebootsin5minutes" label="windows reboots in 5 minutes" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>Earlier today I launched a wget to fetch FC7 from www.linuxusers.ro. While I was doing other things, I saw the following window appearing on my laptop:</p>

<center><img alt="restart5min.png" src="http://www.noh.ro/blog/blogpics/restart5min.png" width="428" height="171" class="mt-image-center" style="margin: 0 20px 20px 0;"/>

<p>I wonder if Windows figured out I was downloading Fedora and decided to do something about it. ;)</p>

<p>Anyways, it strikes me as a really bad thing to reboot an user's machine without asking first. Bad, Microsoft, very bad.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Some photos from VB 2007</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/10/some-photos-fro.html" />
    <id>tag:www.noh.ro,2007:/blog//1.136</id>

    <published>2007-10-08T08:02:44Z</published>
    <updated>2007-10-08T08:04:50Z</updated>

    <summary>http://picasaweb.google.com/costin.raiu/VirusBulletinConference2007...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
    <category term="vb2007vienna" label="vb2007 vienna" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p><a href="http://picasaweb.google.com/costin.raiu/VirusBulletinConference2007">http://picasaweb.google.com/costin.raiu/VirusBulletinConference2007</a></p>]]>
        
    </content>
</entry>

<entry>
    <title>Yahoo&apos;s baaad habit</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/07/bad-habit.html" />
    <id>tag:www.noh.ro,2007:/blog//1.135</id>

    <published>2007-07-09T10:13:36Z</published>
    <updated>2007-07-09T10:31:10Z</updated>

    <summary>Looks like Yahoo Messenger has gotten a very bad habit recently, of installing the Yahoo Toolbar in IE without consent. If you use Yahoo Messenger but install it without the IE Toolbar, then you get a security patch install warning...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>Looks like Yahoo Messenger has gotten a very bad habit recently, of installing the Yahoo Toolbar in IE without consent. </p>

<p><img alt="yahootoolbar.png" src="http://www.noh.ro/blog/yahootoolbar.png" width="493" height="162" /></p>

<p>If you use Yahoo Messenger but install it without the IE Toolbar, then you get a security patch install warning from Messenger and accept it, then apparently the security patch will also install the Yahoo Toolbar, without any question, warning and of course, consent.</p>

<p>I'm personally not necessarily against the Yahoo Toolbar, but installing it without the user's consent strikes me as something that a respectable company should not be doing.<br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Eggs you&apos;ll take to heart</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/05/cholesterol-ad.html" />
    <id>tag:www.noh.ro,2007:/blog//1.134</id>

    <published>2007-05-25T09:58:52Z</published>
    <updated>2007-05-25T10:03:55Z</updated>

    <summary> Cholesterol AD on a car in Kuala Lumpur....</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p><a href="http://www.noh.ro/blog/eggsDSC00675.JPG"><img alt="eggsDSC00675.JPG" src="http://www.noh.ro/blog/eggsDSC00675.JPG" width="540"  /></a></p>

<p>Cholesterol AD on a car in Kuala Lumpur.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Cryptovirology</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/03/cryptovirology.html" />
    <id>tag:www.noh.ro,2007:/blog//1.132</id>

    <published>2007-03-18T16:47:57Z</published>
    <updated>2007-03-18T16:58:56Z</updated>

    <summary>The List of Dubious Research - 3 A copy and paste from: http://www.cryptovirology.com/ This chapter presents an experimental implementation of cryptoviral extortion, an attack that we devised and presented at the 1996 IEEE Symposium on Security &amp; Privacy [16] and...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The List of Dubious Research" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p><b>The List of Dubious Research - 3</b></p>

<p>A copy and paste from:</p>

<p><a href="http://www.cryptovirology.com/">http://www.cryptovirology.com/</a></p>

<p><i>This chapter presents an experimental implementation of cryptoviral extortion, an attack that we devised and presented at the 1996 IEEE Symposium on Security & Privacy [16] and that was recently covered in Malicious Cryptography [17]. The design is based on Microsoft's Cryptographic API and the salient aspects of the implementation were presented at ISC '05 and in the International Journal of Information Security [14,15]. Cryptoviral extortion is a 2-party protocol between an attacker and a victim that is carried out by a cryptovirus, cryptoworm, or cryptotrojan. In a cryptoviral extortion attack the malware hybrid encrypts the plaintext of the victim using the public key of the attacker. The attacker extorts some form of payment from the victim in return for the plaintext that is held hostage. </i></p>

<p>GPCode was the first real world malware to implement a PK "cryptoviral" extortion attack. In 2006, we've been able to break the 660-bit RSA encryption employed by GPCode.ag. That was only possible because of several clever observations of our analysts, however, it is pretty obvious for anybody that a properly implemented attacks of this type would be impossible to defeat. As I write these lines, I wonder how much the research from www.cryptovirology.com influenced the person behind GPCode.</p>]]>
        
    </content>
</entry>

<entry>
    <title>Evolution of network attacks</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/03/evolution-of-ne.html" />
    <id>tag:www.noh.ro,2007:/blog//1.131</id>

    <published>2007-03-02T11:33:53Z</published>
    <updated>2007-03-02T11:40:05Z</updated>

    <summary>&quot;The developments of 2006 have highlighted two major trends in the evolution of attacks carried out via the Internet. The first trend is the apparition of the now constant “background noise”, which is caused by the Slammer worm and the...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>"The developments of 2006 have highlighted two major trends in the evolution of attacks carried out via the Internet.</p>

<p>The first trend is the apparition of the now constant “background noise”, which is caused by the Slammer worm and the bot armies which exploit relatively old vulnerabilities. [...]</p>

<p>The second trend is probably far more significant in terms of the evolution of the Internet"</p>

<p>From my recent article: <a href="http://www.viruslist.com/en/analysis?pubid=204791921">"Kaspersky Security Bulletin 2006: Internet Attacks"</a></p>]]>
        
    </content>
</entry>

<entry>
    <title>Catching fast worms</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/02/catching-fast-w.html" />
    <id>tag:www.noh.ro,2007:/blog//1.130</id>

    <published>2007-02-22T13:49:14Z</published>
    <updated>2007-02-22T14:00:22Z</updated>

    <summary>While going through my e-mail backlog, I came by a story on DarkReading. It seems that a group of researchers from the Penn State University have launched a startup which sells their newly developed worm catching technology. Based on my...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="The Art of Noh" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>While going through my e-mail backlog, I came by a story on DarkReading. It seems that a group of <a href="http://www.darkreading.com/document.asp?doc_id=117037&WT.svl=news1_1">researchers from the Penn State University have launched a startup which sells their newly developed worm catching technology</a>. </p>

<p>Based on my statistics from Smallpot and MailPot, two honeypots I've developed during the past 4 years at Kaspersky Lab, fast spreading worms are a thing of the past. Actually, even slow spreading, network aware are more or less dying, being replaced by automatic hacking tools and direct network attacks. More about the death of network worms and the rise of targeted attacks in an article I have written for <a href="http://www.viruslist.com/">viruslist.com</a>, scheduled for publishing next week.</p>

<p>I guess new ways to fight worms are always welcome, but unfortunately, I suspect those designed to catch fast moving malware will not very successful in the next 5 years. With Microsoft producing more secure versions of Windows and CPU developers trying to mitigate security issues in software through prevention of code execution in data segments, worms that spread automatically between computer systems might become a thing of the past pretty soon. They will be replaced by malware based upon social engineering techniques, malware that is exploiting the weakest link of any computer system: its user.<br />
</p>]]>
        
    </content>
</entry>

<entry>
    <title>Trenul cu vedere la ferestre</title>
    <link rel="alternate" type="text/html" href="http://www.noh.ro/blog/archives/2007/01/trenul-cu-veder.html" />
    <id>tag:www.noh.ro,2007:/blog//1.129</id>

    <published>2007-01-31T19:59:07Z</published>
    <updated>2007-01-31T20:42:53Z</updated>

    <summary>De cateva zile, in lumea Trenului Polar tras de Pinguini (tm), umbla un zvon. Confirmat de anumite persoane si infirmat de altele, zvonul se raspandeste cel putin cu viteza luminii, deoarece in galaxia trenului polar, limitele fizice sunt cu totul...</summary>
    <author>
        <name>craiu</name>
        <uri>http://www.craiu.com/</uri>
    </author>
    
        <category term="Povestiri fantastice din trenul polar tras de pinguini (Romanian only)" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en" xml:base="http://www.noh.ro/blog/">
        <![CDATA[<p>De cateva zile, in lumea Trenului Polar tras de Pinguini (tm), umbla un zvon. Confirmat de anumite persoane si infirmat de altele, zvonul se raspandeste cel putin cu viteza luminii, deoarece in galaxia trenului polar, limitele fizice sunt cu totul altele decat in lumea oamenilor care citesc bloguri de pe Internet. </p>

<p>In orice caz, zvonul, ingrijorator din anumite puncte de vedere, spune ca undeva spre Polul Nord, la sediul companiei Trenurilor cu Ferestre (r), se lanseaza un nou tren:</p>

<p>Trenul '<i>cu vedere la ferestre</i>'.</p>

<p>--</p>

<p>Persoana 1: Salut, omule bun!<br />
Persoana 2: Salut frate calator!<br />
P1: Ai auzit?<br />
P2: Aaah?<br />
P1: Au dat drumul la trenul cel nou!<br />
P2: Nu, pe bune!?<br />
P1: Da!<br />
P2: ...<br />
P1: Se aude ca acum au si locuri la geam! Adica poti sa vezi din tren, in timp ce mergi!<br />
P2: Incredibil! </p>

<p>--</p>

<p>Undeva, in stanga mea, cam la zece metri, doi tipi cu barba discuta despre noul tren cu vedere la geamuri. "La FE-RES-TRE!", ma corecteaza un calator de langa mine, ce trage cu ochiul peste umar la ce scriu. Ma trag mai intr-un colt, in speranta in care omul spion se va muta si el in alta parte cu spionatul.</p>

<p>Dupa cum spuneam, noul tren cu vedere la g... ferestre a devenit subiectul fierbinte al zilei. In toate garile de pe traseul trenului polar, reclame mari, in care un tren cu ferestre multe si mari - cum e mai bine - trece printr-o zona cu dealuri verzi, ca de basm. "Calatoriti cu noul tren cu vedere la ferestre!". Parerile sunt impartite. Unii deja au cumparat bilet, desi trenul a inceput sa circule abia ieri, altii spun ca nu vor merge cu el nici daca intra in greva pinguinii - mai bine merg pe jos!</p>

<p>In timp ce scriu, langa mine se aseaza un alt calator. Dupa expresia senina si nestiutoare, pare sa fie un client al trenului cu o mie si una de ferestre. Ma uit la el, se uita la mine, ne privim. Expresia senina se transforma intr-o masca superioara - imi imaginez ce gandeste: "asta e dus cu pinguinul!". </p>

<p>Recunosc, cu inima si borcanul de muraturi deschise, ca in ultima vreme am calatorit din ce in ce mai mult cu Trenul Polar tras de Pinguini. Complet gratuit, trenul polar tras de pinguini este din ce in ce mai frumos, vine regulat si se opreste din ce in ce mai rar - tot ce conteaza este ca pasagerii sa ajunga la destinatie fara probleme. </p>

<p>Nici trenul pe baza de mere nu o duce rau. Baietii de la firma cu mere muncesc din greu si desi in ultima vreme sunt mai mult preocupati de <a href="http://www.apple.com/itunes/">sertarele muzicale</a>, nici trenul nu a fost uitat. Dotat cu noi imbunatatiri la mere, care acum sunt mai mult <a href="http://www.intel.com/">inteligente</a> decat <a href="http://www-03.ibm.com/chips/power/powerpc/">puternice</a>, trenul cel alb (uneori negru, sau argintiu) este visul multor calatori chiar din trenul polar tras de pinguini.</p>

<p> - Ce parere aveti de trenul cu vedere la ferestre?</p>

<p>Calatorul nou venit incearca probabil sa deschida o conversatie pe tema zilei.</p>

<p> - Pai nu prea stiu ce sa zic, am auzit de la unii oameni ca ar fi o mare descoperire<br />
 - Desigur! Este revolutionar. Acum poti sa te uiti pe geam in timp ce mergi cu trenul!<br />
 - Aaah... dar asta stiti, se cam poate la toate trenurile<br />
 - Nu stiu, pe mine ma intereseaza doar trenurile de la compania ferestrelor (r)<br />
 - OK. Dar alte noutati...?<br />
 - Desigur! Este revolutionar. Acum ferestrele sunt transparente!<br />
 - Incredibil! Dar auziti, mai sunt si alte trenuri cu ferestre transparente... trenul pe baza de mere<br />
 - Tot ce se poate. Nu stiu cum e la alte trenuri.<br />
 - Dar, altceva?<br />
 - Usile se pot incuia mult mai bine. Daca vrei sa deschizi usa, esti <a href="http://technet.microsoft.com/en-us/windowsvista/aa905108.aspx">intrebat</a> mai intaii daca esti sigur ca vrei sa deschizi usa. Cred ca se vor rezolva multe probleme in felul acesta, mai ales cu calatorii care cadeau din tren.</p>

<p>Intr-adevar, numarul de calatori cazuti din tren a fost in ultima vreme incredibil de mare pentru trenurile de la compania trenurilor cu ferestre. Umbla vorba ca unii calatori, cazuti din tren, s-au imbolnavit grav, necesitand tratament cu <a href="http://www.kaspersky.com">medicamente puternice</a>.</p>

<p> - Remarcabila, treaba cu usile. La trenul polar tras de pinguini nu prea se cade din tren, stiti...<br />
 - Tot ce se poate.<br />
 - Si alte noutati?<br />
 - Sute! Este revolutionar! Acum se poate pune <a href="http://en.wikipedia.org/wiki/BitLocker_Drive_Encryption">parola la borcanul cu muraturi</a>! Direct in tren!<br />
 - Incredibil. Dar stiti, asta se poate...<br />
 - DA - tot ce se poate; nu ma intereseaza alte trenuri.<br />
 - Inteleg. Altceva? Poate la roti, ceva modificari?<br />
 - La roti? Rotile sunt noi! Acum trenul functioneaza doar cu <a href="http://www.microsoft.com/whdc/system/platform/64bit/kmsigning.mspx">roti certificate</a>! <br />
 - Pai cum si daca vrei sa pui rotile tale?<br />
 - Cum sa pui rotile tale??<br />
 - Pai stiti... eu imi fac singur rotile la vagon...<br />
 - Daca vrei sa pui rotile tale, mergi cu ele la compania trenurilor cu ferestre, se semneaza pe roti si le poti pune.<br />
 - Altfel nu?<br />
 - NU!<br />
 - Inteleg...<br />
 - Da, este fantastic! Iar biletul costa foarte putin. Iar daca ai mai calatorit cu trenuri mai vechi, costa si mai putin.<br />
 - Dar stiti, trenul polar tras de pinguini este gratuit...<br />
 - Tot ce se poate.</p>

<p>Ma indepartez de calator, care pare un pic dezamagit ca nu poate sa imi enumere si celelalte avantaje ale noului tren cu vedere la fereastra. </p>

<p>In timp ce ma indrept spre trenul polar tras de pinguini, aud ca seful de la compania ferestrelor este foarte <a href="http://www.jurnalul.ro/articol_71233/event__bill_gates_visits_bucharest.html">ocupat</a> sa deschida un nou centru de suport tehnic pentru calatori. Intrucat acum este posibil sa vada afara din tren mult mai bine, se asteapta mari probleme. Oamenii nu sunt obisnuiti sa priveasca in afara lumii lor - socul realitati poate fi uneori covarsitor. </p>

<p>Un tren cu vedere la ferestre, comparabil cu trenul pe baza de mere sau trenul polar tras de pinguini. </p>

<p>Un lucru cel putin remarcabil, intr-adevar. Chiar daca are o intarziere de cam 10 ani. </p>

<p>Urcandu-ma in trenul polar tras de pinguini, o voce anunta tare la megafoane:</p>

<p>"Uimirea incepe acum! Priviti! Pe fereastra!"</p>

<p>Le urez si eu in gand, pasagerilor de la geam, <a href="http://www.microsoft.com/windows/products/windowsvista/default.mspx">calatorie placuta</a>!</p>]]>
        
    </content>
</entry>

</feed>

