<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>McGrew Security Blog</title>
	<atom:link href="http://www.mcgrewsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mcgrewsecurity.com</link>
	<description></description>
	<pubDate>Tue, 06 Jan 2009 19:20:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Pretending to be a Printer with Netcat</title>
		<link>http://www.mcgrewsecurity.com/2009/01/06/pretending-to-be-a-printer-with-netcat/</link>
		<comments>http://www.mcgrewsecurity.com/2009/01/06/pretending-to-be-a-printer-with-netcat/#comments</comments>
		<pubDate>Tue, 06 Jan 2009 19:20:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[fun]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=242</guid>
		<description><![CDATA[My wife has discovered just how much money she can save shopping for our groceries using all of the coupons she has found online.  There are entire communities of people who follow and report on the deals you can find.  The only problem for her has been that many of the coupons she has found [...]]]></description>
			<content:encoded><![CDATA[<p>My wife has discovered just how much money she can save shopping for our groceries using all of the coupons she has found online.  There are entire communities of people who follow and report on the deals you can find.  The only problem for her has been that many of the coupons she has found require a special application by the coupon.com folks.  The application is Windows/OS X only, and she runs Ubuntu.</p>
<p>Since I&#8217;m the one with the MacBook, it has become my duty to print the coupons that she forwards along to me.  I was happy to see there was an OS X version of the app, and installed it, only to find out the following:</p>
<p><img class="alignnone" title="Crappy Coupon Printer Rules" src="/img/printer1.png" alt="" width="500" height="233" /></p>
<p>Well that&#8217;s sort of annoying.  It just sends the job right off to the default printer, without asking about anything beforehand.  What&#8217;s worse for me is that it won&#8217;t &#8220;print&#8221; to a &#8220;graphic format like a PDF&#8221;.  A large percentage of my time, I&#8217;m not on a network with a printer, so I typically print things to postscript (.ps) files (bravo to Apple for building this into the OS and making it so easy).  When I want the hardcopies, I just tar them up and send them to a shell account on a server where I do have access to a printer.</p>
<p>Since this app doesn&#8217;t give me the usual printing dialog box with the option to &#8220;print to .ps&#8221;, I just had to hack together something.  I created a new printer in &#8220;System Preferences&#8221;-&gt;&#8221;Print &amp; Fax&#8221;, with the following settings:</p>
<p><img class="alignnone" title="Settings for a netcat printer" src="/img/printer2.png" alt="" width="561" height="514" /></p>
<p>I then set this as my default printer.  Next, I set up a netcat listener to listen on the JetDirect port (9100), wait for a print job, and dump the incoming postscript to a file:</p>
<blockquote>
<pre>nc -l 9100 &gt; output.ps</pre>
</blockquote>
<p>Once netcat is running and listening, you can print to the printer that you set up, and the result is a postscript file that you can then view, convert, print, etc.  It&#8217;s a pretty simple and painless procedure, if you&#8217;re dealing with an app that doesn&#8217;t play nicely with the printer dialog box.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/01/06/pretending-to-be-a-printer-with-netcat/feed/</wfw:commentRss>
		</item>
		<item>
		<title>25th Chaos Communication Congress Media</title>
		<link>http://www.mcgrewsecurity.com/2009/01/05/25th-chaos-communication-congress-media/</link>
		<comments>http://www.mcgrewsecurity.com/2009/01/05/25th-chaos-communication-congress-media/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 20:46:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[links]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=238</guid>
		<description><![CDATA[The 25th Chaos Communication Congress (25C3) took place in Berlin at the very end of December, and definitely had more than its fair share of interesting-looking talks.  Luckily, for those of us who were not able to go to Germany for this conference, videos of the talks have been made available a lot sooner than [...]]]></description>
			<content:encoded><![CDATA[<p>The 25th Chaos Communication Congress (25C3) took place in Berlin at the very end of December, and definitely had more than its fair share of interesting-looking talks.  Luckily, for those of us who were not able to go to Germany for this conference, videos of the talks have been made available a lot sooner than most conferences manage.  The main page for conference recordings is available here:</p>
<ul>
<li><a title="http://events.ccc.de/congress/2008/wiki/Conference_Recordings" href="http://events.ccc.de/congress/2008/wiki/Conference_Recordings" target="_blank">Conference Recordings - 25C3 Public wiki</a></li>
</ul>
<p>At the current time, many talks are not available in the official releases.  There are unofficial recordings of the streams that have talks that are not yet in the official release directories:</p>
<ul>
<li><a title="http://events.ccc.de/congress/2008/wiki/Streaming#Real_Time_Recordings" href="http://events.ccc.de/congress/2008/wiki/Streaming#Real_Time_Recordings" target="_blank">Real-time Recordings</a></li>
</ul>
<p>The mirror at <a href="http://mirror.informatik.uni-mannheim.de/pub/ccc/streamdump/">http://mirror.informatik.uni-mannheim.de/pub/ccc/streamdump/</a> seems to have the best speed for me at the moment, despite being on the other side of the pond.  Unfortunately, the stream recordings are also missing part of day 4 of the conference, which even more unfortunately means that they are missing Applebaum and Sotirov&#8217;s talk, <a title="http://events.ccc.de/congress/2008/Fahrplan/events/3023.en.html" href="http://events.ccc.de/congress/2008/Fahrplan/events/3023.en.html" target="_blank">MD5 Considered Harmful Today</a>, which has drawn a lot of attention over the past week.  Hopefully the releases of official videos will continue, and include this and some of the other missing talks.</p>
<p>There&#8217;s plenty to keep you interested while you wait, though.  Here&#8217;s a couple of tips to help you understand the bare directory structures of the mirrors, if you don&#8217;t pick it up from context:</p>
<ul>
<li>&#8220;Saal&#8221; is German for &#8220;hall&#8221;, or &#8220;large room&#8221;. </li>
<li>&#8220;Tag&#8221; is German for &#8220;day&#8221;.</li>
</ul>
<p>&#8230;and that&#8217;s about as far as my German skills go.  You&#8217;re on your own for the German-language talks :)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2009/01/05/25th-chaos-communication-congress-media/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MS08-067</title>
		<link>http://www.mcgrewsecurity.com/2008/10/24/ms08-067/</link>
		<comments>http://www.mcgrewsecurity.com/2008/10/24/ms08-067/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 15:05:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[exploitation]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=230</guid>
		<description><![CDATA[I really need to get back into the habit of writing on here, so maybe a few words on the new non-Patch-Tuesday vulnerability is in order.  I just got my MacBook back from warranty service yesterday, and was reading about this on Twitter as I was getting everything set back up.  I&#8217;ll give you a [...]]]></description>
			<content:encoded><![CDATA[<p>I really need to get back into the habit of writing on here, so maybe a few words on the new non-Patch-Tuesday vulnerability is in order.  I just got my MacBook back from warranty service yesterday, and was reading about this on Twitter as I was getting everything set back up.  I&#8217;ll give you a few links that I&#8217;ve seen in my feed reader, Twitter, and IRC (shouts to #pauldotcom and #securabit on freenode), and a little commentary:</p>
<ul>
<li><a title="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">Microsoft&#8217;s Security Bulletin</a></li>
</ul>
<div>It&#8217;s been a while since we&#8217;ve had a vulnerability that is this clean and perfect for large-scale attacks: remote, pre-authentication, and something you can count on running on most Windows systems.</div>
<div>
<ul>
<li><a href="http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html" target="_blank">Gimmiv.A exploits critical vulnerability (MS08-067)</a></li>
</ul>
<div>There is active exploitation of this &#8220;in the wild&#8221;.  Whoever developed that exploit probably noticed the problem while looking at the code affected by MS08-040.  </div>
<div>ThreatExpert calls the above exploit/malware-payload a worm, and while it really doesn&#8217;t seem like this particular chunk of code will spread extremely far, it does fit the definition.  I expect to see a much leaner exploit+scanning worm developed around this vulnerability.  Such a worm could cause some serious problems, although I don&#8217;t think that it would be on quite the same level as Slammer.  For starters, this one will at least have to go through the trouble of setting up full TCP connections, instead of just flooding links with UDP :).</div>
<div>
<ul>
<li><a title="http://www.phreedom.org/blog/2008/decompiling-ms08-067/" href="http://www.phreedom.org/blog/2008/decompiling-ms08-067/" target="_blank">Decompiling the vulnerable function for MS08-067</a></li>
</ul>
<div>This is a reverse-engineered-to-C analysis of the vulnerable function, from Alexander Sotirov.  The function in question is in netapi32.dll, and if I&#8217;m reading the milw0rm exploit right, is called from _NetprPathCanonicalize.  The vulnerability results in a stack-based overflow, but the core problem is a little more subtle.</div>
</div>
<div>
<ul>
<li><a title="http://www.milw0rm.com/exploits/6824" href="http://www.milw0rm.com/exploits/6824">http://www.milw0rm.com/exploits/6824</a></li>
</ul>
<div>&#8230;and finally, a proof-of-concept exploit on Milw0rm.  This one just shows you that taking control of EIP is pretty straightforward.  I&#8217;d expect that there&#8217;ll be a pretty reliable code-execution exploit soon.</div>
<div></div>
<div><strong>Edit:</strong></div>
<div>
<ul>
<li><a title="http://www.dontstuffbeansupyournose.com/?p=35" href="http://www.dontstuffbeansupyournose.com/?p=35" target="_blank">http://www.dontstuffbeansupyournose.com/?p=35</a></li>
</ul>
<div><a href="http://www.room362.com/">Mubix</a> just pointed me at this great in-depth look at the vulnerability. Really good reading material.  Print this and read it over lunch :)</div>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/10/24/ms08-067/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Slides for a forensics class lecture on ext2/3</title>
		<link>http://www.mcgrewsecurity.com/2008/10/12/slides-for-a-forensics-class-lecture-on-ext23/</link>
		<comments>http://www.mcgrewsecurity.com/2008/10/12/slides-for-a-forensics-class-lecture-on-ext23/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 03:16:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[forensics]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=225</guid>
		<description><![CDATA[Tommorow at 8:00AM, I will be giving a lecture to the CSE 4273/6273 Computer Crime and Forensics class here at Mississippi State University.  I was asked to speak on the topic of &#8220;Linux Filesystems&#8221;, and I have chosen to focus on the ext2 and ext3 filesystem data structures.  The class is using the excellent &#8220;File [...]]]></description>
			<content:encoded><![CDATA[<p>Tommorow at 8:00AM, I will be giving a lecture to the CSE 4273/6273 Computer Crime and Forensics class here at Mississippi State University.  I was asked to speak on the topic of &#8220;Linux Filesystems&#8221;, and I have chosen to focus on the ext2 and ext3 filesystem data structures.  The class is using the excellent &#8220;File System Forensic Analysis&#8221; by Brian Carrier as its textbook, so it&#8217;s a great opportunity to cover the chapters on ext2/3 (chapters 14 &amp; 15).</p>
<p>It&#8217;s a 50-minute class, and pretty strictly so, since the Information and Computer Security class is held immediately afterwards :).  Due to the limited time I have, I&#8217;ve scaled back my coverage of these two chapters to what you see in the following slides.  I&#8217;m focusing on the basic data structures used by &#8220;extx&#8221; to point at files and metadata, such as the superblock, group descriptor tables, and inodes.  I&#8217;ve included an example of finding a file on a filesystem using only dd piped through xxd and less, and some discussion of what a forensic examiner or someone tasked with data recovery should be on the look-out for.</p>
<p>Unfortunately with this PDF version of the slides, you won&#8217;t see the slick Keynote animations I&#8217;ve worked into my lecture.  I&#8217;m considering expanding the detail and coverage of this, and recording the slideshow as a video with narration for this site:</p>
<ul>
<li><a href="http://mcgrewsecurity.com/training/extx.pdf">Slides - PDF Format <span style="text-decoration: line-through;">(through the &#8220;Reduce File Size&#8221; Quartz Filter)<br />
</span></a></li>
</ul>
<p>Enjoy!</p>
<p><strong>Edit: </strong>Wow, that filter really killed the screenshots, uploaded the full-res version</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/10/12/slides-for-a-forensics-class-lecture-on-ext23/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Black Hat USA 2008 and Defcon 16 Audio Available</title>
		<link>http://www.mcgrewsecurity.com/2008/09/11/black-hat-usa-2008-and-defcon-16-audio-available/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/11/black-hat-usa-2008-and-defcon-16-audio-available/#comments</comments>
		<pubDate>Thu, 11 Sep 2008 15:46:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[links]]></category>

		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=218</guid>
		<description><![CDATA[A while back, I posted about darkoz having to find a new home for the hacker media archive.  Well, it appears that he has found a replacement.  The previous mirror on Easynews now points to the new location:

http://avondale.good.net/dl/bd/

&#8230;and what&#8217;s more: There are MP3&#8217;s available of the recent Black Hat USA 2008 and Defcon 16 conferences [...]]]></description>
			<content:encoded><![CDATA[<p>A while back, I <a title="http://www.mcgrewsecurity.com/2008/08/24/the-greatest-hacker-media-archive-on-the-net-needs-a-home/" href="http://www.mcgrewsecurity.com/2008/08/24/the-greatest-hacker-media-archive-on-the-net-needs-a-home/" target="_blank">posted about darkoz having to find a new home for the hacker media archive</a>.  Well, it appears that he has found a replacement.  The previous mirror on Easynews now points to the new location:</p>
<ul>
<li><a title="http://avondale.good.net/dl/bd/" href="http://avondale.good.net/dl/bd/" target="_blank">http://avondale.good.net/dl/bd/</a></li>
</ul>
<p>&#8230;and what&#8217;s more: There are MP3&#8217;s available of the recent Black Hat USA 2008 and Defcon 16 conferences :-D.  I&#8217;m looking forward to stuffing my iPod full of these:</p>
<ul>
<li><a title="http://avondale.good.net/dl/bd/blackhat-2008-usa-audio/" href="http://avondale.good.net/dl/bd/blackhat-2008-usa-audio/" target="_blank">http://avondale.good.net/dl/bd/blackhat-2008-usa-audio/</a></li>
<li><a title="http://avondale.good.net/dl/bd/defcon-16-audio/" href="http://avondale.good.net/dl/bd/defcon-16-audio/" target="_blank">http://avondale.good.net/dl/bd/defcon-16-audio/</a></li>
</ul>
<p>Many other excellent conferences have materials available in this archive, too.  I think it&#8217;s a great educational resource, and a great way to fill your head with new ideas in security between episodes of <a title="http://pauldotcom.com/" href="http://pauldotcom.com/" target="_blank">Pauldotcom Security Weekly</a>, <a title="http://mckeay.libsyn.com/" href="http://mckeay.libsyn.com/" target="_blank">Network Security</a>, and <a title="http://securabit.com/" href="http://securabit.com/" target="_blank">Securabit</a>.</p>
<p>Many thanks to <a title="http://darkoz.com/" href="http://darkoz.com/" target="_blank">darkoz</a> and the new hosts!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/11/black-hat-usa-2008-and-defcon-16-audio-available/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Lecturing on Security Principles tommorow</title>
		<link>http://www.mcgrewsecurity.com/2008/09/08/lecturing-on-security-principles-tommorow/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/08/lecturing-on-security-principles-tommorow/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 20:52:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=214</guid>
		<description><![CDATA[Tommorow, from 11:00AM to 12:15PM CDT, I will be lecturing the CSE 4233 - Software Architecture and Design class here at Mississippi State University&#8217;s computer science department, where I&#8217;m working on my Ph.D. dissertation and security research. The lecture is on the basic security principles presented in the classic paper, &#8220;The Protection of Information in [...]]]></description>
			<content:encoded><![CDATA[<p>Tommorow, from 11:00AM to 12:15PM CDT, I will be lecturing the CSE 4233 - Software Architecture and Design class here at Mississippi State University&#8217;s computer science department, where I&#8217;m working on my Ph.D. dissertation and security research. The lecture is on the basic security principles presented in the classic paper, &#8220;The Protection of Information in Computer Systems&#8221;, by Jerome H. Saltzer and Michael D. Schroeder.</p>
<p>I&#8217;m looking forward to meeting the students of this class, and I think I&#8217;ve got a pretty good lecture lined up for them.  I&#8217;ve made the slides and notes available here on my website, for the students, and anyone else who is interested:</p>
<ul>
<li><a title="http://mcgrewsecurity.com/training/Principles.pdf" href="http://mcgrewsecurity.com/training/Principles.pdf" target="_blank">Principles of Secure Software</a></li>
</ul>
<p>A web accessible edition of the original Saltzer and Schroeder paper is available <a title="http://www.cs.virginia.edu/~evans/cs551/saltzer/" href="http://www.cs.virginia.edu/~evans/cs551/saltzer/" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/08/lecturing-on-security-principles-tommorow/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mubix&#8217;s series on Maltego 2</title>
		<link>http://www.mcgrewsecurity.com/2008/09/07/mubixs-series-on-maltego-2/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/07/mubixs-series-on-maltego-2/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 05:48:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[recon]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=209</guid>
		<description><![CDATA[I first heard about what is now called Maltego, when I read the materials for HD Moore and Valsmith&#8217;s presentation &#8220;Tactical Exploitation&#8221;, given at Black Hat USA 2007.  Back then, it was called Evolution, and while it was still in its early stages, it was very useful, and impressive for what it did.  Now, with [...]]]></description>
			<content:encoded><![CDATA[<p>I first heard about what is now called Maltego, when I read the materials for HD Moore and Valsmith&#8217;s presentation &#8220;Tactical Exploitation&#8221;, given at Black Hat USA 2007.  Back then, it was called Evolution, and while it was still in its early stages, it was very useful, and impressive for what it did.  Now, with its current name, Maltego, it has reached version 2, and there&#8217;s a lot of promise in its new and upcoming features.</p>
<p>As someone who believes that the initial stages of a proper penetration test should include an intensive passive intelligence gathering phase, more than what most testers put into it, I believe that using Maltego is a really good starting point.  This is especially the case for pentesters that aren&#8217;t as experienced in open-source information gathering as they are in the later phases of a test (due to how their training was focused).  The output from Maltego gives a good base to work from, and is likely to put the tester in the right mindset to expand upon that information.</p>
<p>Mubix, over on his <a title="http://room362.com" href="http://room362.com" target="_blank">Room362.com blog</a>, has started a series of posts on the new version of Maltego, and it should be very informative to both those new to Maltego, and those, like me, who are aware of older iterations, and would like to know how things are progressing:</p>
<ul>
<li><a title="http://www.room362.com/archives/225-Maltego-2-and-beyond-Part-1.html" href="http://www.room362.com/archives/225-Maltego-2-and-beyond-Part-1.html" target="_blank">Maltego 2 and beyond - Part 1</a></li>
</ul>
<p>The other night, Mubix did some information gathering on me, using Maltego, and I was impressed with the output.  At the very least, it will find much of the same information that an experienced intelligence gatherer will find in his or her first stages, in a very short period of time (5 minutes in this particular case).  I&#8217;m looking forward to seeing the rest of Mubix&#8217;s series on the new version.</p>
<p><strong>Edit: </strong>Chris Gates, of the <a title="http://carnal0wnage.blogspot.com/" href="http://carnal0wnage.blogspot.com/" target="_blank">Carnal0wnage</a> (definitely McGrew-approved for techie security geek content), has a nicely detailed writeup on Maltego over on the Ethical Hacker Network:</p>
<ul>
<li><a title="http://www.ethicalhacker.net/content/view/202/1/" href="http://www.ethicalhacker.net/content/view/202/1/" target="_blank">Maltego Part 1 - Intro and Personal Recon</a></li>
</ul>
<p>This looks to be a good series, too.  Definitely worth editing the post to add, as it&#8217;s too good to let flounder around down in the comments section.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/07/mubixs-series-on-maltego-2/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yousif Yalda&#8217;s friend, Mark gives me a call</title>
		<link>http://www.mcgrewsecurity.com/2008/09/07/yousif-yaldas-friend-mark-gives-me-a-call/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/07/yousif-yaldas-friend-mark-gives-me-a-call/#comments</comments>
		<pubDate>Sun, 07 Sep 2008 18:49:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=203</guid>
		<description><![CDATA[Yousif called me several times after the first post about him, however, after a while he gave up and delegated the late-night calls to his friend Mark.  In response to a recent post, Mark gave me a call at about 2AM last night.  My wife and I were up watching DVDs of Battlestar Galactica, so [...]]]></description>
			<content:encoded><![CDATA[<p>Yousif called me several times after the <a title="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" href="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" target="_blank">first post about him</a>, however, after a while he gave up and delegated the late-night calls to his friend Mark.  In response to a <a title="http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/" href="http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/" target="_blank">recent post</a>, Mark gave me a call at about 2AM last night.  My wife and I were up watching DVDs of Battlestar Galactica, so it&#8217;s not as inconvenient as you would think.</p>
<p>I was getting bored of the call, and decided to fire up Audacity, in order to record some of his profane rants and play them back to him.  Once he wrapped his head around the fact that I was able to record the call, he decided that he wanted me to record a message to post here, on my website.</p>
<p>The following, is that message.  While I took this as an opportunity to play around with iMovie, I haven&#8217;t censored any of the language or idiocy that&#8217;s present in his audio.  If you are easily offended, then you might not want to watch.  If you&#8217;re at work, well, you might want to save this till you get home, or get some headphones :)</p>
<p><strong>Edit: </strong>Yousif apparently didn&#8217;t like the fact that this video was in the &#8220;Related Videos&#8221; box for the <a title="http://www.youtube.com/watch?v=Krmx8M-AL6g" href="http://www.youtube.com/watch?v=Krmx8M-AL6g">commercial</a> he <span style="text-decoration: line-through;">made</span> <a title="http://www.youtube.com/watch?v=oDIgL4NQbNA" href="http://www.youtube.com/watch?v=oDIgL4NQbNA">ripped off from Lanier Leather</a> for his affiliate marketing site.  He managed to report the YouTube version of this video into oblivion, so here it is on metacafe:</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="345" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://www.metacafe.com/fplayer/1751334/yousif_yaldas_friend_mark_calls_me.swf" /><param name="wmode" value="transparent" /><embed type="application/x-shockwave-flash" width="400" height="345" src="http://www.metacafe.com/fplayer/1751334/yousif_yaldas_friend_mark_calls_me.swf" wmode="transparent"></embed></object></p>
<p><strong>Edit: </strong>Awesome comments down below.  Glad you could join us, Mark.  I guess this is where you can contact him for the time being.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/07/yousif-yaldas-friend-mark-gives-me-a-call/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Looks like I&#8217;ve been &#8220;Google Bowled&#8221;</title>
		<link>http://www.mcgrewsecurity.com/2008/09/06/looks-like-ive-been-google-bowled/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/06/looks-like-ive-been-google-bowled/#comments</comments>
		<pubDate>Sat, 06 Sep 2008 23:38:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=195</guid>
		<description><![CDATA[After seeing some very &#8220;spammy&#8221; referral links to a recent post re-exposing an ill-tempered script kiddie, and other interesting traffic in my logs, I noticed that the post in question dropped like a rock off Google search results for terms it should hit on.  Notice here how even searching for the title of the post [...]]]></description>
			<content:encoded><![CDATA[<p>After seeing some very &#8220;spammy&#8221; referral links to <a title="http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/" href="http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/" target="_blank">a recent post re-exposing an ill-tempered script kiddie</a>, and other interesting traffic in my logs, I noticed that the post in question dropped like a rock off Google search results for terms it should hit on.  Notice <a title="http://www.google.com/search?q=%22yousif+yalda+part+2%3A+script+kiddies+in+the+mist%22" href="http://www.google.com/search?q=%22yousif+yalda+part+2%3A+script+kiddies+in+the+mist%22" target="_blank">here</a> how even searching for the title of the post will turn up links to it, but not the post itself.  I&#8217;ve noticed this phenomenon once before on this site, with <a title="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" href="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" target="_blank">another post</a>.  Smart and avid readers of this blog probably already have some theories about who&#8217;s responsible, and what&#8217;s going on ;-)</p>
<p><strong>Edit (Sun Sep  7 12:22:02 CDT 2008): </strong>As of this particular moment, the page seems to have reappeared on Google&#8217;s search.  Not sure why (glitch in the matrix), or for how long.  I&#8217;m going to leave this post up, though, as the topic is still very interesting.</p>
<p><strong>Edit (Thu Sep 11 19:12:31 CDT 2008): </strong>Annnd now it&#8217;s back down, hard.</p>
<p>I&#8217;m definitely no SEO expert, and certainly not anywhere near an expert on the more arcane aspects of negative or blackhat SEO.  I did, however, have a good time reading about a tactic that some call &#8220;Google Bowling&#8221;.  The term makes it sound like a lot of fun, and I imagine it is&#8211;for the people taking part in it.  Here&#8217;s some links:</p>
<ul>
<li><a title="http://www.webmasterworld.com/google/3677877.htm" href="http://www.webmasterworld.com/google/3677877.htm" target="_blank">Google Bowling - Can We Fight it?</a></li>
<li><a title="http://www.webmasterworld.com/google/3615824.htm" href="http://www.webmasterworld.com/google/3615824.htm" target="_blank">Google Should Offer Self-Defense Against Spammy Inbound Links</a></li>
</ul>
<p>The idea here is: by creating links to a page on sites that are blatantly &#8220;spammy&#8221; and subject to a very negative weight by a search engine&#8217;s ranking algorithms (in this case, Google&#8217;s), the ranking of the target page can be dragged down, or, apparently delisted completely.  A little poking around in search results for &#8220;Google Bowling&#8221; reveals several groups that will do this for you, for a fee.  I doubt that the perpetrator in this case has the resources and skill to pull this off on his own, so I certainly hope it was worth whatever he paid :-).</p>
<p>This isn&#8217;t really the site you want to go for, regarding SEO information, and it&#8217;s little more than a curiosity when it happens to isolated posts on a blog, but it&#8217;s definitely something you might be interested in when it&#8217;s your organization being seriously targeted by a competitor that implements these tactics.  It&#8217;s difficult to see it happening, except for an occasional referer from a spam site.  The negative sites linking to you are almost certainly such SEO black holes that you won&#8217;t be able to find them reliably using Google.  It&#8217;s also difficult to figure out who&#8217;s responsible, unless the answer presents itself in the pages that have been &#8220;bowled&#8221;, as it has in this case.</p>
<p>The only real defense, from what I&#8217;ve read, is to minimize the impact of negative links by overwhelming them with positive links.  This is pretty easy for larger sites, and makes the cost of &#8220;bowling&#8221; pages on those sites quite a bit higher.  Smaller blogs, like this one, that average a few good incoming links per post are much more vulnerable.  In this particular case, I&#8217;m grateful to the guys at (the larger-than-this-site) <a title="http://attrition.org" href="http://attrition.org" target="_blank">attrition.org</a>, who have kindly mirrored the Yousif Yalda posts on this site in their extremely informative and entertaining <a title="http://attrition.org/errata/charlatan.html" href="http://attrition.org/errata/charlatan.html" target="_blank">Charlatans</a> pages.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/06/looks-like-ive-been-google-bowled/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yousif Yalda Part 2: Script Kiddies in the Mist</title>
		<link>http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/</link>
		<comments>http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/#comments</comments>
		<pubDate>Mon, 01 Sep 2008 19:46:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[fun]]></category>

		<category><![CDATA[skiddies]]></category>

		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=184</guid>
		<description><![CDATA[&#8230;in which, our intrepid security geek finds out that there is a $400 bounty on his head.
Posts like this don&#8217;t have much technical content, but they&#8217;re fun, and the last one has been a wildly popular part of the site.  While you&#8217;re laughing your butt off, I hope you take away the real message here: [...]]]></description>
			<content:encoded><![CDATA[<p><em>&#8230;in which, our intrepid security geek finds out that there is a $400 bounty on his head.</em></p>
<p>Posts like this don&#8217;t have much technical content, but they&#8217;re fun, and the last one has been a wildly popular part of the site.  While you&#8217;re laughing your butt off, I hope you take away the real message here: do some background research on who you&#8217;re dealing with in the computer security scene.  If you got here by googling up information on this particular skiddie, then you&#8217;re already one step ahead of the game.  Just because someone has a <a title="http://vapt-sec.com/" href="http://vapt-sec.com/" target="_blank">legit-looking website</a> and <a title="http://yousifyalda.blogspot.com" href="http://yousifyalda.blogspot.com" target="_blank">blog</a> doesn&#8217;t mean they&#8217;re on the up-and-up :)</p>
<p>Since my <a title="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" href="http://www.mcgrewsecurity.com/2008/03/26/the-strange-case-of-yousif-yalda/" target="_blank">first post about Yousif&#8217;s activities</a>, I&#8217;ve had the pleasure of many late-night phone calls from him, being DOS&#8217;d for about a half hour, and having his friend threaten to hack my coffee maker.  I was promised a beat-down at Black Hat, although I unfortunately could not make it.  I am, however, sort of disappointed that I don&#8217;t warrant being stabbed, like <a title="http://writequit.org/blog/?p=158" href="http://writequit.org/blog/?p=158" target="_blank">Yousif has threatened to do to Lee Hinman</a> over at the excellent <a title="http://writequit.org/blog/" href="http://writequit.org/blog/" target="_blank">writequit.org</a> blog.  He is, however, willing to pay someone else to do the dirty work.</p>
<p>In the meantime, he hasn&#8217;t let up in his activities.  He has been hanging out on an <a title="http://forums.digitalpoint.com/" href="http://forums.digitalpoint.com/" target="_blank">Internet marketing forum</a>, although his taste for script-kiddie hacking has not subsided.  He still has a penchant for <a title="http://mcgrewsecurity.com/img/yy2_1.png" href="http://mcgrewsecurity.com/img/yy2_1.png" target="_blank">attacking sites outside of well-defined pen-tests</a>, still loves to <a title="http://mcgrewsecurity.com/img/yy2_2.png" href="http://mcgrewsecurity.com/img/yy2_2.png" target="_blank">threaten people who correct him</a>, and <a title="http://mcgrewsecurity.com/img/yy2_3.png" href="http://mcgrewsecurity.com/img/yy2_3.png" target="_blank">runs his own small botnet</a>.</p>
<p>Apparently looking to supplement his <a title="http://vapt-sec.com" href="http://vapt-sec.com" target="_blank">vapt-sec.com</a> income with some <a title="http://en.wikipedia.org/wiki/Cost_per_action" href="http://en.wikipedia.org/wiki/Cost_per_action" target="_blank">cost-per-action</a> fraud, he&#8217;s been hunting around for cohorts to <a title="http://mcgrewsecurity.com/img/yy2_5.png" href="http://mcgrewsecurity.com/img/yy2_5.png" target="_blank">develop software to fill out forms and offers on CPA advertisers</a>, and to <a title="http://mcgrewsecurity.com/img/yy2_4.png" href="http://mcgrewsecurity.com/img/yy2_4.png" target="_blank">come in through his referral links from multiple IP addresses to fill out forms</a>.  I took this as an opportunity to form my own &#8220;black hat&#8221; alter-ego, and have a good heart-to-heart chat with Yousif.  After a couple of boring evening chat sessions building up my &#8220;black hat&#8221; cred with him, he began to open up.</p>
<p><em>The following are some choice excerpts and quotes.  I&#8217;ve censored both his language and mine.  I do swear in-person, occasionally on IRC, and rarely on the blog, however I did ratchet it up about 12 notches with &#8220;elite yousif&#8221;, to build rapport. </em></p>
<p>Since he gets others to write his software for him, he occasionally gets his languages confused:</p>
<blockquote><p>11:03:05 PM elite yousif: So<br />
11:03:12 PM elite yousif: You know anyone who has botnets<br />
11:03:39 PM bhb: i have a couple friends who might.  have a need?<br />
11:03:50 PM elite yousif: Yeah<br />
11:04:37 PM elite yousif: It&#8217;s quite helpful in CPA<br />
11:05:16 PM bhb: yeah i was thinking of writing some code to work through a botnet, filling stuff and using the random ID generator<br />
11:05:27 PM elite yousif: No need, lol.<br />
11:05:35 PM elite yousif: I&#8217;m making something like that as we speak.<br />
11:05:39 PM bhb: nice<br />
11:05:50 PM bhb: what language do you code in<br />
11:06:01 PM elite yousif: What language did I code this in?<br />
11:06:11 PM bhb: yah<br />
11:06:41 PM elite yousif: Net<br />
11:06:54 PM bhb: c#<br />
11:06:55 PM bhb: ?<br />
11:07:21 PM elite yousif: nope<br />
11:07:22 PM elite yousif: .NET &lt;<br />
11:07:29 PM elite yousif: Microsoft, ya know?<br />
11:08:01 PM bhb: .net&#8217;s a platform, theres lots of languages you can code targeting .net<br />
11:08:06 PM bhb: vb.net maybe?<br />
11:08:13 PM elite yousif: Yeah, that&#8217;s right.<br />
11:08:21 PM elite yousif: Vb.NET &lt;</p></blockquote>
<p>Don&#8217;t mess with this guy.  Especially in school:</p>
<blockquote><p>11:56:56 PM elite yousif: No one ***** w/ me..<br />
11:56:59 PM elite yousif: No one @ all.<br />
11:57:02 PM elite yousif: Not even in school<br />
11:57:03 PM elite yousif: They know<br />
11:57:05 PM elite yousif: I can change their grade<br />
11:57:09 PM elite yousif: expell them<br />
11:57:10 PM elite yousif: frame them<br />
11:57:11 PM elite yousif: etc<br />
11:57:17 PM elite yousif: I can drop your docs too<br />
11:57:21 PM elite yousif: know what shoe size you wear<br />
11:57:23 PM bhb: heh nice<br />
11:57:25 PM elite yousif: know your fam history<br />
11:57:27 PM elite yousif: CC<br />
11:57:29 PM elite yousif: S#<br />
11:57:30 PM elite yousif: where u live<br />
11:57:30 PM elite yousif: etc<br />
11:57:59 PM bhb: knock some kiddies on their ***** online lol<br />
11:58:18 PM elite yousif: lol<br />
11:58:59 PM bhb: ***** haters lol<br />
11:59:09 PM elite yousif: I know AOL internals too<br />
11:59:11 PM elite yousif: ppl who work there<br />
11:59:13 PM elite yousif: with high privs.<br />
11:59:14 PM elite yousif: can easily<br />
11:59:16 PM elite yousif: hi jack<br />
11:59:19 PM elite yousif: any AOL/AIM account<br />
11:59:22 PM elite yousif: and get info behind it<br />
11:59:23 PM elite yousif: =D<br />
11:59:31 PM elite yousif: i social engineer as well<br />
12:00:08 AM bhb: hah that&#8217;s useful</p></blockquote>
<p>A social engineering mastermind, to be sure.</p>
<p>Here, he&#8217;s a little sore that his affiliate program dropped him after figuring out his referrals weren&#8217;t legitimate:</p>
<blockquote><p>12:03:12 AM elite yousif: you haven&#8217;t made any money in CPA yet?<br />
12:03:43 AM bhb: haven&#8217;t even started.  just been reading up on it on the side, besides coding and work<br />
12:04:30 AM elite yousif: ah<br />
12:04:40 AM bhb: you made much?<br />
12:04:42 AM elite yousif: I got my account terminated<br />
12:04:45 AM elite yousif: 2 days ago<br />
12:04:48 AM elite yousif: from a network<br />
12:04:52 AM elite yousif: ***** bro, i swear<br />
12:04:52 AM bhb: haters<br />
12:04:53 AM elite yousif: I lost<br />
12:04:56 AM elite yousif: 2000+ dollars<br />
12:04:59 AM elite yousif: I better get my ***** back<br />
12:05:00 AM elite yousif: OR<br />
12:05:08 AM elite yousif: I&#8217;m gonna make my affiliate managers life a living HELL<br />
12:05:14 AM elite yousif: I have access to her AIM account<br />
12:05:15 AM elite yousif: verizon<br />
12:05:17 AM elite yousif: photobucket<br />
12:05:19 AM elite yousif: paypal<br />
12:05:20 AM elite yousif: blogger<br />
12:05:23 AM elite yousif: and some other *****<br />
12:05:25 AM elite yousif: and facebook<br />
12:05:29 AM elite yousif: she doesn&#8217;t know it yet<br />
12:05:31 AM elite yousif: but I phished that *****</p></blockquote>
<p>Bragging about taking down RSnake&#8217;s site (note: there&#8217;s an excellent chance this never really happened):</p>
<blockquote><p>3:00:44 AM elite yousif: you know rsnake?<br />
3:00:46 AM elite yousif: robert hansen<br />
3:00:48 AM elite yousif: famous as *****..<br />
3:00:49 AM bhb: yeah<br />
3:00:51 AM elite yousif: k<br />
3:00:51 AM elite yousif: well<br />
3:00:53 AM elite yousif: his site<br />
3:00:54 AM elite yousif: let me find it<br />
3:01:03 AM bhb: ha.ckers.org or something<br />
3:01:22 AM elite yousif: nah<br />
3:01:23 AM elite yousif: his company<br />
3:01:29 AM bhb: oh i dunno<br />
3:02:26 AM bhb: sectheory?<br />
3:02:58 AM elite yousif: yeah<br />
3:02:59 AM elite yousif: rofol<br />
3:03:02 AM elite yousif: i ddosed that<br />
3:03:03 AM elite yousif: with my friend<br />
3:03:04 AM elite yousif: in like<br />
3:03:05 AM elite yousif: what<br />
3:03:06 AM elite yousif: maybe<br />
3:03:09 AM elite yousif: 3 mins<br />
3:03:10 AM elite yousif: it was down<br />
3:03:14 AM elite yousif: some security expert eh?</p></blockquote>
<p>If there were any doubts about how he&#8217;s taking part in CPA fraud:</p>
<blockquote><p>4:44:10 PM bhb: how are you supposed to make any money at it if you arent botting it anyways lol<br />
4:44:25 PM elite yousif: what do you mean?<br />
4:44:48 PM bhb: like automating it through a bunch of proxies/bots<br />
4:45:02 PM bhb: how can you find that many people wanting to do it legit to keep making money<br />
4:45:14 PM elite yousif: lol<br />
4:45:17 PM elite yousif: u infect more victims<br />
4:45:22 PM elite yousif: you market your trojan or w.e.<br />
4:45:27 PM elite yousif: and more ppl open it<br />
4:45:37 PM bhb: heh yeah so a loose definition of &#8220;legit&#8221; lol :D<br />
4:45:48 PM elite yousif: yep<br />
4:45:48 PM elite yousif: lol<br />
4:45:59 PM elite yousif: you know what company is cool though?<br />
4:46:03 PM bhb: you have nice custom trojans for it?<br />
4:46:03 PM elite yousif: ******<br />
4:46:10 PM elite yousif: i talked to the owner<br />
4:46:10 PM bhb: cool you work with them too?<br />
4:46:12 PM elite yousif: really cool guy<br />
4:46:14 PM elite yousif: says<br />
4:46:18 PM elite yousif: i can do black hat if i want<br />
4:46:21 PM elite yousif: and he wont term. my account</p></blockquote>
<p>Then, I managed to get him on the subject of yours truly :):</p>
<blockquote><p>5:02:12 PM elite yousif: LOL<br />
5:02:19 PM elite yousif: http://archives.neohapsis.com/archives/fulldisclosure/2008-08/0545.html<br />
5:02:21 PM elite yousif: that link u sent me<br />
5:02:25 PM elite yousif: i know the guy who wrote that<br />
5:02:27 PM elite yousif: wesley mcgrew<br />
5:02:30 PM elite yousif: that dude is such a *****<br />
5:02:36 PM bhb: he talks like one<br />
5:03:01 PM elite yousif: he started talking ***** about my business and me because he claims that i hack around sites without permission and that i gave him access to my computer, WTF..<br />
5:03:25 PM elite yousif: so i told him to go to black hat in vegas, and he said hes not going this year &#8212; i told him if i saw him id tackle him</p></blockquote>
<p>I&#8217;m not really sure if the following about the director of Black Hat contacting him is true (I never contacted the Black Hat folks about it, since it&#8217;s not really a credible threat).  He probably just made it up after he found out how much Black Hat costs:</p>
<blockquote><p>5:05:11 PM elite yousif: u know what he did<br />
5:05:11 PM elite yousif: he spoke with teh director of black hat<br />
5:05:11 PM elite yousif: and he told him that i would beat his ***** if i saw him<br />
5:05:11 PM elite yousif: so he got scared<br />
5:05:11 PM elite yousif: so the director listened to him<br />
5:05:20 PM elite yousif: and said i cant attend black hat this yea<br />
5:05:20 PM elite yousif: year*<br />
5:05:38 PM bhb: lol that&#8217;s hilarious did the director email you or something<br />
5:05:44 PM elite yousif: no he IM&#8217;d me<br />
5:05:51 PM bhb: ahah<br />
5:05:52 PM elite yousif: then i followed his profile and he actually WAS the director of black hat<br />
5:05:54 PM elite yousif: oh well<br />
5:05:59 PM elite yousif: he knew i wasn&#8217;t kidding</p></blockquote>
<p>This did happen, although he and his friends would usually get bored and give up after a few calls:</p>
<blockquote><p>5:06:00 PM elite yousif: i called him<br />
5:06:03 PM elite yousif: 1000 times<br />
5:06:07 PM elite yousif: i cussed him out badly<br />
5:06:12 PM elite yousif: and i demanded to talk to his wife<br />
5:06:14 PM elite yousif: so i can cuss her outtoo<br />
5:06:17 PM elite yousif: her out too*<br />
5:06:18 PM elite yousif: but he wouldn&#8217;t elt<br />
5:06:20 PM elite yousif: let*</p></blockquote>
<p>Remember kids, don&#8217;t DDOS on a school night:</p>
<blockquote><p>5:14:51 PM elite yousif: ask him if i DDoSed his *****<br />
5:15:03 PM elite yousif: he&#8217;ll either lie and say &#8216;it&#8217;s server issues @ night&#8221; or he&#8217;ll admit like a ***** i owned him<br />
5:15:25 PM bhb: hah what an idiot.  how long did you ddos him for<br />
5:15:36 PM elite yousif: for about 2-3 hrs<br />
5:15:42 PM elite yousif: i was bored and it was late<br />
5:15:45 PM elite yousif: i had school next morninig<br />
5:15:47 PM elite yousif: so i let him go<br />
5:15:48 PM elite yousif: lol</p></blockquote>
<p>There&#8217;s a $400 bounty on my head.  My wife, a friend, and I considered faking some photos and video to claim it, but I guess we&#8217;re just too nice:</p>
<blockquote><p>5:33:36 PM elite yousif: can you go to missipi?<br />
5:33:39 PM elite yousif: ill pay you like<br />
5:33:42 PM elite yousif: 400<br />
5:33:44 PM elite yousif: to beat his ***** for me<br />
5:33:46 PM elite yousif: no joke<br />
5:34:03 PM bhb: lol maybe if im hard up for some money one day<br />
5:34:14 PM bhb: you should definitely go though, that ***** would be classic<br />
5:34:28 PM elite yousif: do u know anyone would do it?<br />
5:34:34 PM bhb: show all the whitehats that you dont ***** with the blackhats cause they take it into RL<br />
5:34:36 PM elite yousif: i seriously will pay $400 for it<br />
5:35:06 PM bhb: i dont know anyone up for that but it shouldnt be too hard to find<br />
5:35:20 PM bhb: lol craigslist, i bet theres tons of local rednecks there that would do it<br />
5:35:27 PM elite yousif: lol<br />
5:35:35 PM elite yousif: id rather talk to someone i already know<br />
5:36:03 PM bhb: hah just tell them the money transfers when you see a jpg of his bloody nose lol<br />
5:36:33 PM elite yousif: rofl<br />
5:36:35 PM elite yousif: good idea<br />
5:37:28 PM bhb: http://northmiss.craigslist.org/<br />
5:38:10 PM bhb: i dunno what category lol<br />
5:38:15 PM elite yousif: lol<br />
5:38:17 PM elite yousif: murder<br />
5:38:20 PM bhb: loool<br />
5:39:57 PM bhb: services - labor &amp; moving, that probably has the most steroid pumped rednecks<br />
5:40:15 PM elite yousif: lol<br />
5:40:21 PM elite yousif: bro i would never do it off tehre<br />
5:40:27 PM elite yousif: ***** u know feds just hang out there<br />
5:40:30 PM elite yousif: waiting for somone to ***** up</p></blockquote>
<p>I&#8217;ll leave you with the last words he had to say to my dummy AIM account:</p>
<blockquote><p>7:28:14 PM elite yousif: yo<br />
7:28:30 PM elite yousif: is there a way to make your cd burner recognize dvd-r&#8217;s?</p></blockquote>
<p>Brilliant.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.mcgrewsecurity.com/2008/09/01/yousif-yalda-part-2/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
