<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Luciano's webpage &#187; sorry for my english</title>
	<atom:link href="http://www.lucianobello.com.ar/category/english/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lucianobello.com.ar</link>
	<description>Luciano Bello - My personal webpage</description>
	<lastBuildDate>Wed, 08 Sep 2010 18:48:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>DebConf10</title>
		<link>http://www.lucianobello.com.ar/post/debconf10/</link>
		<comments>http://www.lucianobello.com.ar/post/debconf10/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 16:59:38 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[debian]]></category>
		<category><![CDATA[geek]]></category>
		<category><![CDATA[journeys & traveling]]></category>
		<category><![CDATA[lectures & talks]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1378</guid>
		<description><![CDATA[Este es un delayed post, dado que DebConf10 New York City terminó hace 3 días. Aunque más tarde de lo esperado, no quería dejar pasar la oportunidad de comentar lo bien que la pasé. Siempre es agradable encontrarse con amigos.
Si bien pude dedicar mucho tiempo al security team (generé 3 nuevos DSA aunque, de momento, [...]]]></description>
			<content:encoded><![CDATA[<p>Este es un delayed post, dado que <a href="http://debconf10.debconf.org/">DebConf10 New York City</a> terminó hace 3 días. Aunque más tarde de lo esperado, no quería dejar pasar la oportunidad de comentar lo bien que la pasé. Siempre es agradable encontrarse <a href="http://wiki.debconf.org/wiki/DebConf10/GroupPhoto">con amigos</a>.<br />
Si bien pude dedicar mucho tiempo al security team (generé 3 nuevos <a href="http://www.debian.org/security/2010/">DSA</a> aunque, de momento, se ha publicado <a href="http://www.debian.org/security/2010/dsa-2090">uno solo</a>), me quedaron muchísimas cosas pendientes por hacer. Además tengo muchas nuevas ideas que me gustaría concretar durante el próximo año.</p>
<p>Entre los pendientes está el de subir fotos, para variar. Así que stay tunned! Para los ansiosos, hay publicadas fotos de otros asistentes <a href="http://www.flickr.com/photos/tags/debconf10/">aquí</a>. También están disponibles las <a href="http://meetings-archive.debian.net/pub/debian-meetings/2010/debconf10/high/">versiones preliminares de las charlas</a>, donde se me puede ver dado una Lightning Talk, acerca de un prototipo para documentar workflows que se me ocurrió hace unos meses (minuto 10:40 de <a href="http://meetings-archive.debian.net/pub/debian-meetings/2010/debconf10/low/1580_1580_Lightning_Talks.ogv">este video</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/debconf10/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://meetings-archive.debian.net/pub/debian-meetings/2010/debconf10/low/1580_1580_Lightning_Talks.ogv" length="112459087" type="video/ogg" />
		</item>
		<item>
		<title>/home/duijvestijn</title>
		<link>http://www.lucianobello.com.ar/post/homeduijvestijnen/</link>
		<comments>http://www.lucianobello.com.ar/post/homeduijvestijnen/#comments</comments>
		<pubDate>Tue, 13 Jul 2010 17:17:45 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[favorites]]></category>
		<category><![CDATA[geek]]></category>
		<category><![CDATA[home]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[math]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[procrastination]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1368</guid>
		<description><![CDATA[I have a new guest in my apartment. Give a warm welcome to the Adrianus Johannes Wilhelmus Duijvestijn&#8217;s spirit.

Thanks a lot to Bartu and Rezlaj, who carried out the necessary seance that make this possible.

The complete photo set is here. If you do not have the slightest idea of what I&#8217;m talking about, take a [...]]]></description>
			<content:encoded><![CDATA[<p>I have a new guest in my apartment. Give a warm welcome to the <a href="http://www.squaring.net/history_theory/duijvestijn.html">Adrianus Johannes Wilhelmus Duijvestijn</a>&#8217;s spirit.</p>
<p><center><img src="/fotos/duijvestijn/duijvestijn1.jpg"/></center></p>
<p>Thanks a lot to <a href="http://www.piumacharles.com/">Bartu and Rezlaj</a>, who carried out the necessary seance that make this possible.</p>
<p><center><img src="/fotos/duijvestijn/duijvestijn2.jpg"/></center></p>
<p>The complete photo set is <a href="/fotos/duijvestijn/">here</a>. If you do not have the slightest idea of what I&#8217;m talking about, take a look to <a href="http://en.wikipedia.org/wiki/Squaring_the_square#Simple_squared_squares">Wikipedia</a> or <a href="/post/diseccion_perfecta/">my previous post (Spanish only)</a>.</p>
<p><small>(esta entrada también <a href="/post/homeduijvestijnes/">está disponible en Español</a>)</small></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/homeduijvestijnen/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>DebConf10 meme</title>
		<link>http://www.lucianobello.com.ar/post/debconf10-meme/</link>
		<comments>http://www.lucianobello.com.ar/post/debconf10-meme/#comments</comments>
		<pubDate>Fri, 12 Mar 2010 18:57:23 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[debian]]></category>
		<category><![CDATA[journeys & traveling]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>
		<category><![CDATA[wtf?!]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1316</guid>
		<description><![CDATA[I happy to announce that I bought the tickets, so&#8230;
To save on the price, the itinerary includes a couple of long waits:

AV88 EZE-BOG: 6h 30m
Waiting at BOG: 10h 50m
AV20 BOG-JFK: 5h 35m
AV21 JFK-BOG: 6h 00m
Waiting at BOG: 9h 10m
AV87 BOG-EZE: 6h 15m

Summarizing, almost half of the trip is waiting&#8230; :P
]]></description>
			<content:encoded><![CDATA[<p>I happy to announce that I bought the tickets, so&#8230;</p>
<p><center><a href="http://debconf10.debconf.org/"><img class="aligncenter" title="im_going_to_debconf10" src="http://www.lucianobello.com.ar/blog/im_going_to_debconf10.png" alt="" width="200" height="101" /></a></center>To save on the price, the itinerary includes a couple of long waits:</p>
<ul>
<li>AV88 EZE-BOG: 6h 30m</li>
<li>Waiting at BOG: 10h 50m</li>
<li>AV20 BOG-JFK: 5h 35m</li>
<li>AV21 JFK-BOG: 6h 00m</li>
<li>Waiting at BOG: 9h 10m</li>
<li>AV87 BOG-EZE: 6h 15m</li>
</ul>
<p>Summarizing, almost half of the trip is waiting&#8230; :P</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/debconf10-meme/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>still introduction</title>
		<link>http://www.lucianobello.com.ar/post/still-introduction/</link>
		<comments>http://www.lucianobello.com.ar/post/still-introduction/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 17:21:45 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[life]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1310</guid>
		<description><![CDATA[Ladies and gentlemen, with you&#8230;

my (first) nephew :)
UPDATE Tue, 09 Mar 2010 15:05:51 -0300:  According to this, is a &#8220;he&#8221; (henceforth Gregorio).
]]></description>
			<content:encoded><![CDATA[<p>Ladies and gentlemen, with you&#8230;<br />
<object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/M4d2S1IU4U8&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/M4d2S1IU4U8&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></embed></object><br />
my (first) nephew :)</p>
<p><strong>UPDATE Tue, 09 Mar 2010 15:05:51 -0300</strong>:  According to <a href="http://www.youtube.com/watch?v=I0EqI0vRw7s">this</a>, is a &#8220;he&#8221; (henceforth <a href="http://www.google.com/search?q=%22gregorio+sarasate%22">Gregorio</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/still-introduction/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>boxing network</title>
		<link>http://www.lucianobello.com.ar/post/boxing-network/</link>
		<comments>http://www.lucianobello.com.ar/post/boxing-network/#comments</comments>
		<pubDate>Sat, 09 Jan 2010 19:55:33 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[procrastination]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1274</guid>
		<description><![CDATA[Since I am a housewife (i.e. since I live on my own) my concerns have been extended to foreign horizons, such as taming dust and lint. All my network devices and wires has a particular magnetism for them. To make things worse, the devices cleaning is quiet hard.
So, I decide to boxing them. All you [...]]]></description>
			<content:encoded><![CDATA[<p>Since I am a housewife (i.e. since I live on my own) my concerns have been extended to foreign horizons, such as taming dust and lint. All my network devices and wires has a particular magnetism for them. To make things worse, the devices cleaning is quiet hard.</p>
<p>So, I decide to <em>boxing</em> them. All you need is a big tupperware and few rubber bands. Here is the process to build it:<br />
<center><img src="http://www.lucianobello.com.ar/blog/boxing_process.gif" alt="boxing process" /></center><br />
And this is done:<br />
<center><img src="http://www.lucianobello.com.ar/blog/boxing.png" alt="boxing" /></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/boxing-network/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>removing your facebook photo tags automagically</title>
		<link>http://www.lucianobello.com.ar/post/rmfb-en/</link>
		<comments>http://www.lucianobello.com.ar/post/rmfb-en/#comments</comments>
		<pubDate>Tue, 24 Nov 2009 16:22:35 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[planet]]></category>
		<category><![CDATA[procrastination]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1242</guid>
		<description><![CDATA[Este post también está escrito en español aquí.
Privacy at Facebook is heavy-duty. As a big fan of the Worlds Collide Theory I hate be tagged compulsively. I would like to select in which photos appear in my profile and feed. Since I couldn&#8217;t find that option in the setting menu, I looked for the answer [...]]]></description>
			<content:encoded><![CDATA[<p><small>Este post también está escrito en español <a href="http://www.lucianobello.com.ar/post/rmfb-es/">aquí</a></small>.</p>
<p>Privacy at <a href="http://www.facebook.com/privacy/">Facebook</a> is heavy-duty. As a big fan of the <a href="http://www.urbandictionary.com/define.php?term=Worlds Collide Theory">Worlds Collide Theory</a> I hate be tagged compulsively. I would like to select in which photos appear in my profile and feed. Since I couldn&#8217;t find that option in the setting menu, I looked for the answer in my favorite scripting language: <a href="http://www.python.org/">Python</a>.</p>
<p><a href="http://python.pastebin.com/f55c5896f">This 60-lines-long script</a> removes your tag from the latests photos where you has been labelled. You can download it from <a href="http://www.lucianobello.com.ar/rmfb/">here</a>. You may run it hourly (or every 15 minutes, or every 5 minutes, depends how paranoid you are) via <a href="http://en.wikipedia.org/wiki/Cron">cron</a> or whatever.</p>
<p>Any improvement is welcome. It probably runs on Windows too. If you managed to do it, leave a comment for the others.</p>
<p><strong>NEW VERSION!</strong> (available <a href="http://www.lucianobello.com.ar/rmfb/">here</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/rmfb-en/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>aUSBusing</title>
		<link>http://www.lucianobello.com.ar/post/ausbusing/</link>
		<comments>http://www.lucianobello.com.ar/post/ausbusing/#comments</comments>
		<pubDate>Sat, 19 Sep 2009 07:02:01 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1213</guid>
		<description><![CDATA[When your laptop is being repaired (and it&#8217;s still there, since August 28) you need imaginative ways to be connected.
Here is my Nokia N800 as something near to a desktop computer.

Just few notices:

life battery is really short when you plug too many things to the USB interface.
usbcontrol rules
solder a female-female USB adapter is easy and funny [...]]]></description>
			<content:encoded><![CDATA[<p>When your laptop is being repaired (and it&#8217;s still there, since August 28) you need imaginative ways to be connected.</p>
<p>Here is my Nokia N800 as something near to a desktop computer.</p>
<p><a href="http://www.lucianobello.com.ar/blog/usbusing.png"><img src="http://www.lucianobello.com.ar/blog/usbusing_thumb.png" alt="" /></a></p>
<p>Just few notices:</p>
<ul>
<li>life battery is really short when you plug too many things to the USB interface.</li>
<li><a href="http://maemo.org/downloads/product/OS2008/usbcontrol/">usbcontrol</a> rules</li>
<li>solder a female-female USB adapter is easy and funny (it came from a broken motherboard)</li>
<li>after some weeks using Maemo, ideas about developing applications to it come to my mind</li>
<li>the mail client and the browser included with Maemo suck</li>
<li>my ocular health is being damaged</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/ausbusing/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>not yours</title>
		<link>http://www.lucianobello.com.ar/post/not-yours/</link>
		<comments>http://www.lucianobello.com.ar/post/not-yours/#comments</comments>
		<pubDate>Tue, 26 May 2009 15:12:30 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[academy]]></category>
		<category><![CDATA[depression]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1143</guid>
		<description><![CDATA[If I say &#8220;I got the third place in a scholarship application&#8221;, it doesn&#8217;t look bad.

But there is money only for the first two persons. Sometimes, close is not enough. So, without money, I won&#8217;t be able to study in Europe&#8230; damn&#8230;
Maybe next year&#8230; maybe not.
Note: The application was, as you can see, for a [...]]]></description>
			<content:encoded><![CDATA[<p>If I say &#8220;I got the third place in a scholarship application&#8221;, it doesn&#8217;t look bad.<br />
<a href="http://www.postgrado.csic.es/JAE-Pre/Listado%20Titulares%20y%20Suplentes%20JAEPRE2009%20con%20RESOLUCION.pdf"><img src="http://www.lucianobello.com.ar/blog/resolucion_beca.png" alt="" /></a><br />
But there is money only for the first two persons. Sometimes, close is not enough. So, without money, I won&#8217;t be able to study in Europe&#8230; damn&#8230;</p>
<p>Maybe next year&#8230; maybe not.</p>
<p>Note: The application was, as you can see, for a <a href="http://www.postgrado.csic.es/tesis%20doctorales_jae.htm">doctoral scholarship in Spain</a>&#8230; my broken English has no effect here&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/not-yours/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>congrats sis!</title>
		<link>http://www.lucianobello.com.ar/post/congrats-sis/</link>
		<comments>http://www.lucianobello.com.ar/post/congrats-sis/#comments</comments>
		<pubDate>Mon, 18 May 2009 13:03:33 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[life]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1136</guid>
		<description><![CDATA[Finally, my sis caught someone for ever&#8230;

Only 3 things to say:

the wedding gonna be on December 8th
Congratulations Pato! Be happy by sharing your happiness
My deepest sympathies Seba :P

]]></description>
			<content:encoded><![CDATA[<p>Finally, my sis caught someone for ever&#8230;</p>
<p style="text-align: center;"><a href="http://www.lucianobello.com.ar/wp-content/uploads/2009/05/abuelos-tios-primos_20090315-000006.jpg"><img class="alignnone size-medium wp-image-1137" title="abuelos-tios-primos_20090315-000006" src="http://www.lucianobello.com.ar/wp-content/uploads/2009/05/abuelos-tios-primos_20090315-000006-300x225.jpg" alt="" width="385" height="288" /></a></p>
<p>Only 3 things to say:</p>
<ul>
<li>the wedding gonna be on December 8th</li>
<li>Congratulations Pato! Be happy by sharing your happiness</li>
<li>My deepest sympathies Seba :P</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/congrats-sis/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>new camera</title>
		<link>http://www.lucianobello.com.ar/post/new-camera/</link>
		<comments>http://www.lucianobello.com.ar/post/new-camera/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 01:42:50 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[hardware]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=1118</guid>
		<description><![CDATA[Some days ago, my new camera arrived. I bougth it via Amazon and the parents of a friend brought it to my country.
The selected model was a Canon PowerShot SX110 IS. My last camera was a Canon PowerShot A700. It has been in service since April 2006, until a terrible fall ended with its nice [...]]]></description>
			<content:encoded><![CDATA[<p>Some days ago, my new camera arrived. I bougth it via Amazon and the parents of a friend brought it to my country.</p>
<p>The selected model was a <a href="http://www.usa.canon.com/consumer/controller?act=ModelInfoAct&#038;tabact=SupportDetailTabAct&#038;fcategoryid=225&#038;modelid=17480&#038;kbpage=yes">Canon PowerShot SX110 IS</a>. My last camera was a <a href="http://www.dpreview.com/reviews/specs/Canon/canon_a700.asp">Canon PowerShot A700</a>. It has been in service since <a href="http://www.lucianobello.com.ar/post/say-cheese/">April 2006</a>, until a terrible fall ended with its nice capability of taking good pictures, during the 25C3 in Berlin.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/new-camera/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>the root of all mistake: the overgeneralization</title>
		<link>http://www.lucianobello.com.ar/post/the-root-of-all-mistake-the-overgeneralization/</link>
		<comments>http://www.lucianobello.com.ar/post/the-root-of-all-mistake-the-overgeneralization/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 02:11:19 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[academy]]></category>
		<category><![CDATA[crypto]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=941</guid>
		<description><![CDATA[Yes, it&#8217;s me again with this DSA-1571 exploitation issue. The discovery, explanation and exploitation of the bug is now part of my final coursework for my postgraduate degree career. So, yes&#8230; sorry.
Some weeks ago I started suspecting about the attack to PFS in SSL with EDH. The key point is: the key space is dependent [...]]]></description>
			<content:encoded><![CDATA[<p>Yes, it&#8217;s me again with this DSA-1571 exploitation issue. The discovery, explanation and exploitation of the bug is now part of my final coursework for my <a href="http://cripto.iese.edu.ar/">postgraduate degree career</a>. So, yes&#8230; sorry.</p>
<p>Some weeks ago I started suspecting about <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/">the attack to PFS in SSL with EDH</a>. The key point is: the key space is dependent of the PRNG state. The bug affects the initialization of the PRNG, but the random string has not a pattern by it self. If you ask for many random numbers to the PRNG, you gonna get numbers that differ among them, since they are the output of a hash function of them self. So each random number depends on, besides the PID, the state of the PRNG pool in the moment (in other words, amount of bytes that you already pull from the PRNG pool before)</p>
<p>The <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/">explained attack</a> was based in <a href="http://www.citefa.gov.ar/si6/dh-private-keys.tar.gz">a fixed list of private exponents</a> (which are selected randomly during the <a href="http://en.wikipedia.org/wiki/Diffie-Hellman_key_exchange">DHE handshake</a>), presupposing that all the application call RAND_bytes() the same number of times before get it. To make the list of exponent I ran the <tt>openssl s_client</tt> with all the possible PIDs, hoping that all the applications behaves the same way.</p>
<p>After more tests I notice that that was an overgeneralization. The proof is in the pudding: <a href="http://www.gnu.org/software/wget/">wget</a> and <a href="http://en.wikipedia.org/wiki/CURL">cURL</a>, two simple <a href="http://en.wikipedia.org/wiki/Command_line_interface">CLI</a> file retrievers, gets different exponent between them, even running with the same PID.</p>
<p>I was working on this when I accidentally found <a href="http://www.educatedguesswork.org/2008/08/the_debian_openssl_prng_bug_an.html">a really nice Eric Rescorla&#8217;s post</a> which is deeply related with this. The post goes further and analyzes the interaction between how Apache forks off and how it generates SSL handshakes.</p>
<p>So, I made lists of secret exponents for <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/wget.keys.zip">wget</a>, <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/curl.keys.zip">curl</a>, <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/openssl-s_client.key.zip">openssl s_client</a> and <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/openssl-s_server.key.zip">openssl s_server</a> with a modification version of libssl (appling <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/dh_tmp_data.patch">this messy patch</a>) and running scripts like this:</p>
<pre>for i in $(seq $((2**15)));
do
  export MAGICPID=$i;
  LD_LIBRARY_PATH="openssl.broken/" LD_PRELOAD="./getpid.so" \
     wget --no-check-certificate https://localhost/ -q  -O /dev/null ;
  echo $i ;
done</pre>
<p>As you can see, I used the <a href="http://metasploit.com/users/hdm/tools/getpid-preload.tar.gz">HD Moore&#8217;s GetPID faker shared library</a> and a normal local Apache with mod_ssl. The broken libssl (which is in .openssl.broken/) store up in /tmp/data.key a <a href="http://en.wikipedia.org/wiki/Comma-separated_values">csv</a> with command name, PID and all the DH components (g, x, y and p).</p>
<p>But this way is farly unconfortable for others SSL deamon servers. Have you got any better idea?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/the-root-of-all-mistake-the-overgeneralization/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>8 days a week</title>
		<link>http://www.lucianobello.com.ar/post/8-days-a-week/</link>
		<comments>http://www.lucianobello.com.ar/post/8-days-a-week/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 15:22:27 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>
		<category><![CDATA[wtf?!]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=925</guid>
		<description><![CDATA[
Maybe the LHC is robing the planet of angular momentum. Maybe  having played with quantum gravity has unpredictable consequences. Who cares the reason, it&#8217;s my dream becoming true.
And you, haven&#8217;t got any plans for the extra day in October yet? Luckily it&#8217;s weekend.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.lucianobello.com.ar/blog/zimbra-bug.png"><img src="http://www.lucianobello.com.ar/blog/zimbra-bug_.png" alt="Zimbra buggy" align="center" /></a></p>
<p>Maybe the LHC is <a href="http://xkcd.com/162/">robing the planet of angular momentum</a>. Maybe <a href="http://physicsworld.com/cws/article/print/839"> having played with quantum gravity</a> has unpredictable consequences. Who cares the reason, it&#8217;s my dream becoming true.</p>
<p>And you, haven&#8217;t got any plans for the extra day in October yet? Luckily it&#8217;s weekend.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/8-days-a-week/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>in the process of moving</title>
		<link>http://www.lucianobello.com.ar/post/in-the-process-of-moving/</link>
		<comments>http://www.lucianobello.com.ar/post/in-the-process-of-moving/#comments</comments>
		<pubDate>Fri, 12 Sep 2008 20:32:13 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[blogging]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=910</guid>
		<description><![CDATA[Digamos que este post solo tiene sentido si es visto desde mi antiguo gestor de blog. De todas formas decidí portarlo aquí por razones históricas.
Desde ya hace tiempo que tenía intensiones de irme de LiveJournal. No es que funcione mal. Es que simplemente tiene cosas que no me cuadran. Me la paso adaptándome a lo [...]]]></description>
			<content:encoded><![CDATA[<p>Digamos que este post solo tiene sentido si es visto desde <a href="http://lbello.livejournal.com/">mi antiguo gestor de blog</a>. De todas formas decidí portarlo aquí por razones históricas.</p>
<p>Desde ya hace tiempo que tenía intensiones de irme de <a href="http://www.livejournal.com/">LiveJournal</a>. No es que funcione mal. Es que simplemente tiene cosas que no me cuadran. Me la paso adaptándome a lo que puede darme (como el caso de <a href="http://community.livejournal.com/lbello_english/">hack</a> para el bloguear en <a href="http://planet.debian.org">planet.debian.org</a>) y tiene limitaciones de diseño. La publicidad que empezó a surgir a la derecha de la pantalla es la gota que derramó el vaso. No es solo antiestética, sino que si decido tener publicidad es porque espero cobrar por ella.</p>
<p>Dado que <a href="http://www.raqlink.com/">RaqLink</a> puede proveerme un hosting gratuito y que otros amigos han ofrecido espacio y ancho de banda, decidí mudarme y tener mi propio Blog que dependa de mi mismo.</p>
<p>Así fue como me decidí por <a href="http://www.wordpress.com">Wordpress</a>. Es lindo, sencillo y flexible. Por otro lado, dudo de su seguridad. Y este último punto no es menor. Veremos que tal anda durante los próximos meses. Si da mucho problema&#8230; volará por otra opción. Escucho opciones.</p>
<p>Una cosa es segura. No más LiveJournal. Este <a href="http://lbello.livejournal.com/">blog (es decir, lbello.livejournal.com)</a> deja de existir como tal. Puedes acceder al nuevo en <a href="http://www.lucianobello.com.ar/">www.lucianobello.com.ar</a>. Todos los post antiguos está migrados. Incluso los comentarios. En la pasada se han perdido los tags y el threading de los comentarios. Los primeros irán emergiendo con el correr del tiempo y de mi ratos libros. El segundo está definitivamente perdido. Aunque los nuevos comentarios si pueden anidarse, los viejos han quedado planos.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/in-the-process-of-moving/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>a black hat speaker after all</title>
		<link>http://www.lucianobello.com.ar/post/a-black-hat-speaker-after-all/</link>
		<comments>http://www.lucianobello.com.ar/post/a-black-hat-speaker-after-all/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 00:21:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[lectures & talks]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=892</guid>
		<description><![CDATA[Finally, this alternative speaker became an speaker, nothing more. Maxi and I will be given a lecture during Black Hat, as you can see here.
Just think about being in the same rostrum than Fyodor makes me feel so small&#8230;
]]></description>
			<content:encoded><![CDATA[<p>Finally, this <em>alternative speaker</em> became <em>an speaker, nothing more</em>. <a href="http://www.google.com/search?q=Maximiliano+BERTACCHINI">Maxi</a> and I will be given a lecture during <a href="http://www.blackhat.com/">Black Hat</a>, as you can see <a href="http://www.blackhat.com/html/bh-usa-08/bh-usa-08-speakers.html#Bello">here</a>.</p>
<p>Just think about being in the same rostrum than <a href="http://insecure.org/fyodor/">Fyodor</a> makes me feel so small&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/a-black-hat-speaker-after-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Exploiting DSA-1571: How to break PFS in SSL with EDH</title>
		<link>http://www.lucianobello.com.ar/post/exploiting-dsa-1571-how-to-break-pfs-in-ssl-with-edh/</link>
		<comments>http://www.lucianobello.com.ar/post/exploiting-dsa-1571-how-to-break-pfs-in-ssl-with-edh/#comments</comments>
		<pubDate>Sun, 20 Jul 2008 05:10:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[crypto]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[free software]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=891</guid>
		<description><![CDATA[( I love acronyms  :-D ) Tal vez quieras leer esto en español.
At this point, all of you should know and see how the H D Moore’s toys work. Those toys attack SSH public-key authentication using clone keys and online brute force.
Furthermore, many of you know that there are other effects produced by a [...]]]></description>
			<content:encoded><![CDATA[<p>( I love acronyms  :-D ) <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/index_es.html">Tal vez quieras leer esto en español</a>.</p>
<p>At this point, all of you should know and see how the <a href="http://metasploit.com/users/hdm/tools/debian-openssl/">H D Moore’s toys</a> work. Those toys attack SSH public-key authentication using clone keys and online brute force.</p>
<p>Furthermore, many of you know that there are other effects produced by a biased PRNG besides this one.</p>
<p>Strangely, I could not find more of those toys exploiting these aspects. So, I would like to show you <a href="http://people.debian.org/~luciano/wireshark-Exploiting-DSA-1571/20_cve_2008_0166_attack.dpatch">a Wireshark patch</a> which attacks <a href="http://en.wikipedia.org/wiki/Perfect_forward_secrecy">Perfect Forward Secrecy (PFS)</a> provided by <a href="http://www.rsa.com/products/bsafe/documentation/mesuite21html/dev_guide/group__EPH__DH.html">Ephemeral Diffie Hellman (EDH)</a>.</p>
<h1>Introduction to EDH</h1>
<p>Let’s put it in plain words (if you know what we are talking about, ignore this and jump to the next heading):<br />
In an insecure communications channel the parties agree a common key to cipher their dialog. This is what happens in SSL (in most of the cases, depending on the cipher suite):</p>
<ul>
<li> The server selects a random <a href="http://en.wikipedia.org/wiki/Prime_number">prime</a> <i>p</i> and a generator <i>g</i> of the <a href="http://en.wikipedia.org/wiki/Group_(mathematics)">field</a> <i>Z*<sub>p</sub></i> (Let’s ignore the mathematical properties of these values). So, the components <i>p</i> and <i>g</i> are public.</p>
<li> The server picks a secret random number <i>X<sub>s</sub></i> and calculates <i>Y<sub>s</sub>=g<sup><i>X<sub>s</sub></i></sup> mod p</i>. <i>Y<sub>s</sub></i> is public and is sent to the client (just like <i>p</i> and <i>g</i>).
<li> The client does something similar, selecting a secret random number <i>X<sub>c</sub></i> and calculating <i>Y<sub>c</sub>=g<sup><i>X<sub>c</sub></i></sup> mod p</i> too. The client makes <i>Y<sub>c</sub></i> public by sending it to the server.
<li> The shared secret <i>s</i> is the public key of the other part to the exponential of the own private number, all in p modulus. That is, for the client <i>s=Y<sub>s</sub><sup><i>X<sub>c</sub></i></sup>mod p</i> and for the server <i>s=Y<sub>c</sub><sup><i>X<sub>s</sub></i></sup>mod p</i>.
<li>With this shared secret the parties can encrypt all the following messages in a secure way.
<li>In the Ephemeral Diffie Hellman (EDH), the private numbers are ruled out, so <i>s</i> is mathematically secure and nobody can obtain it even having access to one of the parties after the aforementioned handshake.
</ul>
<h1>The “exploit”</h1>
<p>If an eavesdropper can explore the complete private key space (the all possible numbers for X<sub>c</sub> or X<sub>s</sub>), he/she will be able to get access to the shared secret. With it all the communication can be deciphered. That’s what this patch can do.</p>
<p>A <a href="http://www.wireshark.org/">Wireshark</a> with this patch and a list of possible private keys will try to brute force the share secret. If one of the parties is using the vulnerable OpenSSL package the communication is totally insecure and will be decrypted.</p>
<p><center><a href="http://www.lucianobello.com.ar/blog/wireshark_PFS_attack_big.jpg"><img src='http://www.lucianobello.com.ar/blog/wireshark_PFS_attack_small.jpg' /></a></center></p>
<ul>
<li>The patch for <a href="http://www.wireshark.org/download/src/wireshark-1.0.2.tar.gz">Wireshark 1.0.2</a> can be downloaded from <a href="http://people.debian.org/~luciano/wireshark-Exploiting-DSA-1571/20_cve_2008_0166_attack.dpatch">here</a>.</p>
<li>Debian packages with the patch applied can be found <a href="http://people.debian.org/~luciano/wireshark-Exploiting-DSA-1571/">here</a>.
<li><a href="http://www.citefa.gov.ar/si6/dh-private-keys.tar.gz">This</a> is a list of all 2<sup>15</sup> possible 64 and 128 bit DH private keys in systems vulnerable to the predictable OpenSSL PRNG described by <a href="http://www.debian.org/security/2008/dsa-1571">DSA-1571</a>.
<li>An example of a pcap file can be found <a href="http://people.debian.org/~luciano/wireshark-Exploiting-DSA-1571/test.pcap">here</a> (it was built with a vulnerable client and one of the Moore toys, <a href="">a hacked getpid</a> by running <tt>$ MAGICPID=101 LD_PRELOAD=‘getpid.so’ ./vulnerable-openssl/apps/openssl s_client -connect db.debian.org:443</tt> )</ul>
<p>The patch <a href="https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=2725">was submitted</a> in order to be committed on the Wireshark trunk. There you can find <a href="https://bugs.wireshark.org/bugzilla/attachment.cgi?id=2029">the patch against the on-develop source revision 25765</a>.</p>
<h1>Issues that can be improved</h1>
<p>We (the other developers and myself) detected few things to be improved. But we will do nothing for them. So, if you want to contribute with some code, start from these items and submit the patches to the <a href="">Wireshark’s bugzilla</a>:
<ul>
<li> When the packets are out-of-order the decipher with stop itself.</p>
<li> The brute force attack should run in a background process (and with a progres bar)
<li> Check the length of the keys before trying to brute force them.
<li> The patch also implements the display of public DH parameters in the packet tree. It’s incomplete.</ul>
<h1>Credits</h1>
<p>Paolo Abeni &lt;paolo.abeni at email.it&gt;<br />
Luciano Bello &lt;luciano at debian.org&gt;<br />
Maximiliano Bertacchini &lt;mbertacchini at citefa.gov.ar&gt;</p>
<p>This work was partially supported by <a href="http://www.citefa.gov.ar/si6">Si6 Labs</a> at <a href="http://www.citefa.gov.ar/">CITEFA</a>, Argentina.</p>
<p><b>UPDATE Jul. 21st</b>: See more and updated info <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/index.html">here</a>, especially <a href="http://www.lucianobello.com.ar/exploiting_DSA-1571/index.html#related">this</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/exploiting-dsa-1571-how-to-break-pfs-in-ssl-with-edh/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>looking for a sponsor to travel to defcon16</title>
		<link>http://www.lucianobello.com.ar/post/looking-for-a-sponsor-to-travel-to-defcon16/</link>
		<comments>http://www.lucianobello.com.ar/post/looking-for-a-sponsor-to-travel-to-defcon16/#comments</comments>
		<pubDate>Mon, 02 Jun 2008 19:25:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[debian]]></category>
		<category><![CDATA[journeys & traveling]]></category>
		<category><![CDATA[lectures & talks]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=889</guid>
		<description><![CDATA[Warning: read the last update first. No more contributions are needed :D
The last weeks have been very active. A lot of e-mails from people and magazines, a lot of congratulations and a lot of free beer made me feel like a rock star :) Thanks a lot to everyone. I really appreciated that.
And maybe this [...]]]></description>
			<content:encoded><![CDATA[<p><center><b>Warning: read the last update first. No more contributions are needed :D</b></center><br />
The last weeks have been very active. A lot of e-mails from people and magazines, a lot of congratulations and a lot of free beer made me feel like a rock star :) Thanks a lot to everyone. I really appreciated that.</p>
<p>And maybe this petition would sound you like an abuse of this situation. And maybe you are right.</p>
<p>The fact is, I need an sponsor to travel to <a href="http://www.defcon.org/">Defcon16, in Las Vegas, the next August</a>. I need a flight ticket, 3 or 4 nights in a hotel and 2 meals per day.</p>
<p>I’ve been accepted to <a href="http://www.defcon.org/html/defcon-16/dc-16-speakers.html#Bello">explain the Debian/OpenSSL problem</a> and I’m dying to be there. If you work for a company which is looking for a nice way to say “thank you”, please consider this option :)</p>
<form name="_xclick" action="https://www.paypal.com/cgi-bin/webscr" method="post">
<input type="hidden" name="cmd" value="_xclick">
<input type="hidden" name="business" value="lbello@gmail.com">
<input type="hidden" name="item_name" value="Defcon trip">
<input type="hidden" name="currency_code" value="USD">
<input type="hidden" name="amount" value="">
<input type="image" src="http://www.paypal.com/en_US/i/btn/btn_donate_LG.gif" border="0" name="submit" alt="Make payments with PayPal - it's fast, free and secure!">
</form>
<p>Contact me at <a href="http://qa.debian.org/developer.php?login=luciano">luciano &lt;alt+64&gt; debian.org</a> for more details. Thanks.</p>
<p><b>update (13 minutes later)</b>: I just received confirmation from the <a href="http://www.blackhat.com/">Black Hat</a> organization to be an alternative speaker there too! So I will need to fund 5 extra nights&#8230; :D</p>
<p><b>update (Jun. 6th)</b>: I already have a sponsor! :D. Thanks a lot to all the contributors/mentors/impeller ppl, especially to <i>physical</i> people for the monetary-small-but-emotionally-significant colaborations: Juan Tula and Alejandra García.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/looking-for-a-sponsor-to-travel-to-defcon16/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>cryptographic apocalypse</title>
		<link>http://www.lucianobello.com.ar/post/cryptographic-apocalypse/</link>
		<comments>http://www.lucianobello.com.ar/post/cryptographic-apocalypse/#comments</comments>
		<pubDate>Tue, 13 May 2008 18:10:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[crypto]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[planet]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=887</guid>
		<description><![CDATA[Well, maybe I was a little noisy with my first DSA. I will try to be quieter next time :)
I think that many people are being very unfair with the OpenSSL’s maintainers. They made (and are making) a really good job. Was an accident, that things happens.
What we need is a real auditory process of [...]]]></description>
			<content:encoded><![CDATA[<p>Well, maybe I was a little noisy with my first <a href="http://www.debian.org/security/2008/dsa-1571">DSA</a>. I will try to be quieter next time :)</p>
<p>I think that many people are being very unfair with the OpenSSL’s maintainers. They made (and are making) a really good job. Was an accident, that things happens.</p>
<p>What we need is a real auditory process of the Debian specific patches. It’s hard, but it’s necessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/cryptographic-apocalypse/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Debian Logo and Messier 74</title>
		<link>http://www.lucianobello.com.ar/post/debian-logo-and-messier-74/</link>
		<comments>http://www.lucianobello.com.ar/post/debian-logo-and-messier-74/#comments</comments>
		<pubDate>Tue, 04 Dec 2007 04:31:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=870</guid>
		<description><![CDATA[  Many years ago I heard that the Debian logo represents a galaxy. And I always thought “There is no galaxy that looks like that”. Of course, I was wrong.
The Astronomy Picture of the Day from few days ago is a really nice picture of the Messier 74 galaxy.
Any resemblance is purely coincidental :)
]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.seds.org/messier/JpgSm/m74.jpg" alt="" align="left" /> <img src="http://www.debian.org/logos/openlogo-nd-100.jpg" alt="" align="right" /> Many years ago I heard that the Debian logo represents a galaxy. And I always thought “<a href="http://observatorio.info/2001/04/27/">There is no galaxy that looks like that</a>”. Of course, I was wrong.</p>
<p>The <em><a href="http://apod.nasa.gov/">Astronomy Picture of the Day</a></em> from few days ago is a <a href="http://antwrp.gsfc.nasa.gov/apod/ap071201.html">really nice picture</a> of the <a href="http://www.seds.org/messier/m/m074.html">Messier 74</a> galaxy.</p>
<p>Any resemblance is purely coincidental :)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/debian-logo-and-messier-74/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It&#8217;s a party&#8230; and you are invited!</title>
		<link>http://www.lucianobello.com.ar/post/its-a-party-and-you-are-invited/</link>
		<comments>http://www.lucianobello.com.ar/post/its-a-party-and-you-are-invited/#comments</comments>
		<pubDate>Wed, 21 Nov 2007 20:48:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=868</guid>
		<description><![CDATA[Better than just a party, it’s a bug squashing party! Imagemagick needs your help. It a very important package for Debian and its really outdated. It has more than 100 bugs.

The objective, is to reduce the bugs to less than 20 in a month in in the version in development. Let’s go for them! :)
]]></description>
			<content:encoded><![CDATA[<p>Better than just a party, it’s a bug squashing party! <a href="http://packages.debian.org/source/imagemagick">Imagemagick</a> <a href="http://bugs.debian.org/452314">needs your help</a>. It a very important package for Debian and its really outdated. It has more than 100 bugs.<br />
<center><a href="http://www.lucianobello.com.ar/blog/im_needs_you.png"><img border="0" src="http://www.lucianobello.com.ar/blog/im_needs_you_small.png" /></a></center></p>
<p>The objective, is to reduce the bugs to less than 20 in a month in in <a href="http://svn.debian.org/wsvn/pkg-gmagick">the version in development</a>. Let’s go for them! :)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/its-a-party-and-you-are-invited/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>captchas: The Good, the Bad and the Ugly</title>
		<link>http://www.lucianobello.com.ar/post/captchas-the-good-the-bad-and-the-ugly/</link>
		<comments>http://www.lucianobello.com.ar/post/captchas-the-good-the-bad-and-the-ugly/#comments</comments>
		<pubDate>Wed, 31 Oct 2007 05:17:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=866</guid>
		<description><![CDATA[Some months ago, I commented about a weak implementation in a fancy captcha. Today I would like to comment about other bad implementations, but in other ways.
The good
A captcha should have big Shannon entropy, finite, but big. The session ID and the challenge must not be reused. The images must be resistant to OCR but [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://lbello.livejournal.com/2007/07/23/">Some months ago</a>, I commented about a weak implementation in a fancy captcha. Today I would like to comment about other bad implementations, but in other ways.</p>
<h1>The good</h1>
<p>A captcha should have big Shannon entropy, finite, but big. The session ID and the challenge must not be reused. The images must be resistant to OCR but should be understandable by a human.</p>
<h1>The bad</h1>
<p>Here is the first example:<br />
<center><img src='http://www.lucianobello.com.ar/blog/captchaBug.png' /></center><br />
Believe it or not.. This is a real case. So incredible eh?</p>
<h1>The ugly</h1>
<p>The victim, in this case, is this one: <img src='http://www.teppichservicetaifun.de/manager/includes/captchanumbers/captchaNumber.php' /><br />
This is an implementation of <a href="http://kinghost.mirrors.phpclasses.org/browse/package/2598.html">captchanumbers</a>, by <a href="http://www.keynetik.co.il/">Hadar Porat</a>. This captcha and many others generated by captchanumbers are weak and can be read with <a href="http://home.lucianobello.com.ar/scripts/read.sh">this script</a>.</p>
<p>The idea is simple. As the numbers are nearly in the same place, they can be cut. Those parts can compared independently, reducing the entropy. May be <a href="http://home.lucianobello.com.ar/scripts/read.sh">the script</a> and this image would be more enlightening than my limited English:<br />
<center><img src='http://www.lucianobello.com.ar/blog/captchaExplanation.png' /></center><br />
The 10,000 possibilities was reduced to 159. No OCR, 100% deterministic.</p>
<p><center>Second moral: <i>Understand the fundamentals first, write code later.</i></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/captchas-the-good-the-bad-and-the-ugly/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>ocurrencia</title>
		<link>http://www.lucianobello.com.ar/post/ocurrencia/</link>
		<comments>http://www.lucianobello.com.ar/post/ocurrencia/#comments</comments>
		<pubDate>Tue, 18 Sep 2007 17:00:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[debian]]></category>
		<category><![CDATA[geek]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=863</guid>
		<description><![CDATA[In Spanish, occurrence and stupid idea are the same word.
j=`w3m planet.debian.org -dump -no-graph -l 200 &#124; tr -d -C [:alpha:] &#124; tr [:upper:] [:lower:]`; for i in `seq ${#j}`; do echo $j &#124; cut -b $i; done &#124; sort &#124; uniq -c &#124; while read w; do y=`echo $w &#124; cut -f 1 -d ' [...]]]></description>
			<content:encoded><![CDATA[<p>In Spanish, <em>occurrence</em> and <em>stupid idea</em> are the same word.<br />
<tt>j=`w3m planet.debian.org -dump -no-graph -l 200 | tr -d -C [:alpha:] | tr [:upper:] [:lower:]`; for i in `seq ${#j}`; do echo $j | cut -b $i; done | sort | uniq -c | while read w; do y=`echo $w | cut -f 1 -d ' '`; echo -n $(echo "scale=5; $y/${#j}" | bc); echo " `echo $w | cut -f 2 -d ' '`" ;done | sort -rn</tt></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/ocurrencia/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Eppur si muove</title>
		<link>http://www.lucianobello.com.ar/post/eppur-si-muove/</link>
		<comments>http://www.lucianobello.com.ar/post/eppur-si-muove/#comments</comments>
		<pubDate>Tue, 31 Jul 2007 19:58:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=857</guid>
		<description><![CDATA[yes &#124; w3m -M -F -dump http://nm.debian.org/nmlist.php 2> /dev/null &#124; grep -A 60 "Luciano Bello" > /tmp/DAM-`date +%F`.txt ; ! diff /tmp/DAM-`date -d yesterday +%F`.txt /tmp/DAM-`date +%F`.txt > /dev/null &#038;&#038; echo "Eppur si muove"
Thanks and continue like this. Go for them^W us :)
]]></description>
			<content:encoded><![CDATA[<p><tt>yes | w3m -M -F -dump http://nm.debian.org/nmlist.php 2> /dev/null | grep -A 60 "Luciano Bello" > /tmp/DAM-`date +%F`.txt ; ! diff /tmp/DAM-`date -d yesterday +%F`.txt /tmp/DAM-`date +%F`.txt > /dev/null &#038;&#038; echo "Eppur si muove"</tt></p>
<p>Thanks and <a href="https://nm.debian.org/nmlist.php#dam">continue like this</a>. Go for them^W us :)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/eppur-si-muove/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>fancy /mathematical /insecure /unofuscated /reused captchas</title>
		<link>http://www.lucianobello.com.ar/post/fancy-mathematical-insecure-unofuscated-reused-captchas/</link>
		<comments>http://www.lucianobello.com.ar/post/fancy-mathematical-insecure-unofuscated-reused-captchas/#comments</comments>
		<pubDate>Mon, 23 Jul 2007 21:10:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=856</guid>
		<description><![CDATA[Few days ago, Gunnar told me about a quite curious captcha:

But, in the other hand, it had been implemented insecurely. With just one answer, you can submit many times:

Furthermore, I notice that the captcha was precomputed and, therefore, finite and reused. I made more than 15,000 requests and I had less than 5% unique (there [...]]]></description>
			<content:encoded><![CDATA[<p>Few days ago, <a href="http://www.gwolf.org/">Gunnar</a> told me about a quite curious captcha:<br />
<center><img src='http://www.lucianobello.com.ar/blog/captcha1.png' /></center><br />
But, in the other hand, it had been implemented insecurely. With just one answer, you can submit many times:<br />
<center><img src='http://www.lucianobello.com.ar/blog/captcha.png' /></center><br />
Furthermore, I notice that the captcha was precomputed and, therefore, finite and reused. I made more than 15,000 requests and I had less than 5% unique (there is no motivation to solve 700 differential equations :P).</p>
<p><center>Moral: <i>Sometimes, extravagance goes against security.</i></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/fancy-mathematical-insecure-unofuscated-reused-captchas/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>sometimes, unusual things happens (x2)</title>
		<link>http://www.lucianobello.com.ar/post/sometimes-unusual-things-happens-x2/</link>
		<comments>http://www.lucianobello.com.ar/post/sometimes-unusual-things-happens-x2/#comments</comments>
		<pubDate>Wed, 14 Mar 2007 13:44:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=842</guid>
		<description><![CDATA[Causality I:
The Cause: CVE-2007-1365
The Effect:

Causality II:
The Cause: DAM has an idle evening
The Effect:

]]></description>
			<content:encoded><![CDATA[<h2>Causality I:</h2>
<p><b>The Cause:</b> <a href="http://www.coresecurity.com/?action=item&amp;id=1703">CVE-2007-1365</a></p>
<p><b>The Effect:</b><br />
<a href="http://www.openbsd.org" border="0" ><img border="0" src='http://www.lucianobello.com.ar/blog/openbsdVuln.png' /></a></p>
<h2>Causality II:</h2>
<p><b>The Cause:</b> DAM has an idle evening</p>
<p><b>The Effect:</b><br />
<a href="http://nm.debian.org" border="0" ><img border="0" src='http://www.lucianobello.com.ar/blog/DAMnone.png' /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/sometimes-unusual-things-happens-x2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dear Santa Pyro</title>
		<link>http://www.lucianobello.com.ar/post/dear-santa-pyro/</link>
		<comments>http://www.lucianobello.com.ar/post/dear-santa-pyro/#comments</comments>
		<pubDate>Tue, 19 Dec 2006 17:11:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=832</guid>
		<description><![CDATA[Dear Santa Pyro,
I&#8217;ve been a really good maintainer this year and I hope not to get coal. Don&#8217;t let my not-updated-lintian-page fool you. My packages hasn&#8217;t got any RC bug in unstable or testing and they are all updated.
What I really want for Christmas is Task and Skill step finished. That will look great under [...]]]></description>
			<content:encoded><![CDATA[<p>Dear Santa <a href="http://bignachos.net/">Pyro</a>,<br />
<img align=left src='http://home.lucianobello.com.ar/blog/santaPyro.png' />I&#8217;ve been a really good maintainer this year and I hope not to get coal. Don&#8217;t let my <a href="http://lintian.debian.org/reports/mLuciano_Bello.html">not-updated-lintian-page</a> fool you. My packages hasn&#8217;t got any <a href="http://bugs.debian.org/luciano%40linux.org.ar">RC bug in unstable or testing</a> and they are all updated.<br />
What I really want for Christmas is <a href="http://www.debian.org/devel/join/nm-step4">Task and Skill step</a> finished. That will look great under Christmas tree :)<br />
Thanks in advance.</p>
<p>Your eternal <a href="https://nm.debian.org/nmstatus.php?email=luciano%40linux.org.ar">applicant</a>, luciano</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/dear-santa-pyro/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>cuasi-custom kernel in a non-traditional way</title>
		<link>http://www.lucianobello.com.ar/post/cuasi-custom-kernel-in-a-non-traditional-way/</link>
		<comments>http://www.lucianobello.com.ar/post/cuasi-custom-kernel-in-a-non-traditional-way/#comments</comments>
		<pubDate>Wed, 02 Aug 2006 14:57:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=811</guid>
		<description><![CDATA[I&#8217;m averse to compile programs for productive machines. Lot&#8217;s of developers and maintainers have been working (and work) hard to make a wonderful binary for you. But sometimes you need a customization. Especially if it&#8217;s about a kernel. I was needed support for 8GB ram.
Most of the people would download a kernel from www.kernel.org, would [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m averse to compile programs for productive machines. <a href="http://qa.debian.org/developer.php?all=1">Lot&#8217;s of developers and maintainers</a> have been working (and work) hard to make a wonderful binary for you. But sometimes you need a customization. Especially if it&#8217;s about a kernel. I was needed support for 8GB ram.</p>
<p>Most of the people would download a kernel from <a href="http://www.kernel.org">www.kernel.org</a>, would configure it and would compile it.</p>
<p>If it&#8217;s about a Debian user, he would  probably compile it <i>by-the-Debian-way</i>, with <a href="http://packages.debian.org/kernel-package">make-kpkg</a>.</p>
<p>But I only needed a really small change from the <a href="http://packages.debian.org/kernel-image-2.6-686-smp">debian official kernel image</a>. So, I tried to made a custom kernel image, without wasting the work from the <a href="http://alioth.debian.org/projects/kernel/">kernel team</a>, making as less changes as possible.</p>
<p><tt>$ apt-get source kernel-image-2.6.8-3-686-smp</tt><br />
<tt>$ vi kernel-image-2.6.8-i386-2.6.8/config/686-smp</tt></p>
<p>Add support for HighMem64G:</p>
<p><tt>CONFIG_HIGHMEM64G=y</tt></p>
<p><tt>wq!</tt></p>
<p>In order to not generate all the images for all the platforms (I&#8217;m not sure that i386, k7, etc. are <i>platforms</i>) I delete those files from <tt>kernel-image-2.6.8-i386-2.6.8/config</tt>:</p>
<p><tt>$ rm 386 686 k7 k7-smp</tt></p>
<p>Then&#8230; let&#8217;s bulid a package (compile in a DD-way :P)!</p>
<p><tt>dpkg-buildpackage</tt></p>
<p>And now I have a package with my non-too-much-custom-kernel-image, ready to be used.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/cuasi-custom-kernel-in-a-non-traditional-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>the WTF survey</title>
		<link>http://www.lucianobello.com.ar/post/the-wtf-survey/</link>
		<comments>http://www.lucianobello.com.ar/post/the-wtf-survey/#comments</comments>
		<pubDate>Tue, 18 Jul 2006 00:28:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=807</guid>
		<description><![CDATA[Sometimes, if you don’t blog for a while, you need a good excuse for do it. Today I have one.
Click to see the whole page 
You don’t speak Spanish? You should :P. 
It’s a survey (or an opinion poll, i’m not sure). The newspaper La Razón ask to the readers: Are you agree that the [...]]]></description>
			<content:encoded><![CDATA[<p>Sometimes, if you don’t blog for a while, you need a good excuse for do it. Today I have one.</p>
<p><center><a href="http://home.lucianobello.com.ar/blog/encuesta.jpg"><img src='http://home.lucianobello.com.ar/blog/encuesta-recuadro.jpg' /><br />Click to see the <i>whole</i> page </a></center></p>
<p>You don’t speak Spanish? You should :P. </p>
<p>It’s a survey (or an opinion poll, i’m not sure). The newspaper <a href="http://www.larazon.com.ar/"><i>La Razón</i></a> ask to the readers: <i>Are you agree that the tubal ligation and the vasectomy are allowed?</i>. The answers are: <i>between 9 and 7 hours</i> (49.8%), <i>between 6 and 4 hours</i> (46.1%), <i>ten or more</i> (2.6%) and <i>neither, I can’t sleep</i> (1.5%).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/the-wtf-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ASCII football world cup</title>
		<link>http://www.lucianobello.com.ar/post/ascii-football-world-cup/</link>
		<comments>http://www.lucianobello.com.ar/post/ascii-football-world-cup/#comments</comments>
		<pubDate>Fri, 16 Jun 2006 19:47:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=804</guid>
		<description><![CDATA[In the geek world exist funny useless things. If you are freak and football fan, you would enjoy this.
Now you can see all the football matches LIVE in ASCII !!
telnet ascii-wm.net 2006
BTW, Argentina won 6-0 :D. Let&#8217;s go for the cup!
]]></description>
			<content:encoded><![CDATA[<p><img align=right src='http://home.lucianobello.com.ar/blog/asciifootball.jpg' />In the geek world exist funny useless things. If you are freak and football fan, you would enjoy <a href="http://ascii-wm.net/">this</a>.</p>
<p>Now you can see all the football matches LIVE in ASCII !!</p>
<p><tt>telnet ascii-wm.net 2006</tt></p>
<p>BTW, Argentina won 6-0 :D. Let&#8217;s go for the cup!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/ascii-football-world-cup/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>tag &lt;bug number&gt; + mañana</title>
		<link>http://www.lucianobello.com.ar/post/tag-bug-number-manana/</link>
		<comments>http://www.lucianobello.com.ar/post/tag-bug-number-manana/#comments</comments>
		<pubDate>Mon, 15 May 2006 23:56:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=793</guid>
		<description><![CDATA[Tagging bugs with Amaya, she propose create a new tag: Mañana
I ask my self, which would be the difference with wontfix? xD
]]></description>
			<content:encoded><![CDATA[<p>Tagging bugs with Amaya, she propose create a new tag: <i>Mañana</i></p>
<p>I ask my self, which would be the difference with <i>wontfix</i>? xD</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/tag-bug-number-manana/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Soccer geeks at DebConf6</title>
		<link>http://www.lucianobello.com.ar/post/soccer-geeks-at-debconf6/</link>
		<comments>http://www.lucianobello.com.ar/post/soccer-geeks-at-debconf6/#comments</comments>
		<pubDate>Fri, 31 Mar 2006 16:16:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=780</guid>
		<description><![CDATA[Get ready for the first Debian Soccer Cup in Oaxtapec. :P
As we all know, sports are good for geeks&#8230;. that&#8217;s why I&#8217;m organizing a Debconf Football Championship/Match. I would like to invite you all (yes, girls included) to join this championship/match.
Depending of how many people we will be and the field size that will be [...]]]></description>
			<content:encoded><![CDATA[<p><img align=right src='http://home.lucianobello.com.ar/blog/debianSoccer.jpg' />Get ready for the first Debian Soccer Cup in <a href="http://debconf6.debconf.org/">Oaxtapec</a>. :P</p>
<p>As we all know, sports are good for geeks&#8230;. that&#8217;s why I&#8217;m organizing a <a href="http://debconf6.debconf.org/">Debconf</a> Football Championship/Match. I would like to invite you all (yes, girls included) to join this championship/match.</p>
<p>Depending of how many people we will be and the field size that will be a single match or a championship. </p>
<p>All DebConf6 attendees are <a href="http://wiki.debian.org/DebConf6Soccer">invited</a>!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/soccer-geeks-at-debconf6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Happy Anniversary, Pyro!</title>
		<link>http://www.lucianobello.com.ar/post/happy-anniversary-pyro/</link>
		<comments>http://www.lucianobello.com.ar/post/happy-anniversary-pyro/#comments</comments>
		<pubDate>Tue, 28 Mar 2006 11:46:00 +0000</pubDate>
		<dc:creator>luciano</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[sorry for my english]]></category>

		<guid isPermaLink="false">http://www.lucianobello.com.ar/?p=779</guid>
		<description><![CDATA[Today is an special day.
One year ago we (yes, you and me), started a beautiful path together. A long path with wisdoms and mistakes. I learned about Debian and you about correcting me, but both learned to wait each other. 
Dear Pyro, for not to many years together, with this wonderful relation ApplicationManager-Applicant, I say [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/March_28">Today</a> is an special day.</p>
<p><a href="https://nm.debian.org/nmstatus.php?email=luciano@linux.org.ar">One year ago</a> we (yes, <a href="http://bignachos.net/">you</a> and <a href="http://www.lucianobello.com.ar/">me</a>), started a beautiful path together. A long path with wisdoms and mistakes. I learned about Debian and you about correcting me, but both learned to wait each other. </p>
<p>Dear Pyro, for not to many years together, with this wonderful relation ApplicationManager-Applicant, I say you: <b>Happy Anniversary!</b></p>
<p><img align=center src='http://home.lucianobello.com.ar/blog/HappyAnniversaryPyro.png' /></p>
<p><font size=-3>PD: don&#8217;t get angry, I&#8217;m just joking (c:</font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.lucianobello.com.ar/post/happy-anniversary-pyro/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
