<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" >

<channel><title><![CDATA[Tejeddine Mouelhi - Blog]]></title><link><![CDATA[https://www.mouelhi.com/blog]]></link><description><![CDATA[Blog]]></description><pubDate>Thu, 07 May 2026 20:47:51 -0700</pubDate><generator>Weebly</generator><item><title><![CDATA[Privacy in the age of COVID-19 Pandemic]]></title><link><![CDATA[https://www.mouelhi.com/blog/privacy-in-the-age-of-covid-19-pandemic]]></link><comments><![CDATA[https://www.mouelhi.com/blog/privacy-in-the-age-of-covid-19-pandemic#comments]]></comments><pubDate>Wed, 01 Apr 2020 14:47:08 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/privacy-in-the-age-of-covid-19-pandemic</guid><description><![CDATA[Very interesting and thoughtful blog post&#65279; by Bruce Schneier. In the age of COVID-19 nobody cares anymore about privacy.&nbsp;  It is indeed a sad truth that goverments worldwide are taking more and more intrusive measures to enforce containment like the ones done in&nbsp;South Korea. The key point to be understood here is that these measures should be enforced only for limited and&nbsp;"necessary and proportionate" cases instead of doing mass tracking of the whole population.&nbsp;&#8203 [...] ]]></description><content:encoded><![CDATA[<div class="paragraph">Very interesting and thoughtful blog <a href="https://www.schneier.com/blog/archives/2020/03/privacy_vs_surv.html" target="_blank">post</a><span>&#65279;</span> by Bruce Schneier. In the age of COVID-19 nobody cares anymore about privacy.&nbsp;</div>  <div class="paragraph"><span style="color:rgb(14, 67, 97)">It is indeed a sad truth that goverments worldwide are taking more and more intrusive measures to enforce containment like the ones done in&nbsp;</span><a href="http://theconversation.com/coronavirus-south-koreas-success-in-controlling-disease-is-due-to-its-acceptance-of-surveillance-134068" target="_blank">South Korea</a><span style="color:rgb(14, 67, 97)">. The key point to be understood here is that these measures should be enforced only for limited and</span><span style="color:rgb(34, 34, 34)">&nbsp;"necessary and proportionate" cases instead of doing mass tracking of the whole population.&nbsp;</span><br />&#8203;</div>]]></content:encoded></item><item><title><![CDATA[Creating a Honeypot with a Raspberry PI]]></title><link><![CDATA[https://www.mouelhi.com/blog/creating-a-honeypot-with-a-raspberry-pi]]></link><comments><![CDATA[https://www.mouelhi.com/blog/creating-a-honeypot-with-a-raspberry-pi#comments]]></comments><pubDate>Fri, 10 Aug 2018 11:45:35 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/creating-a-honeypot-with-a-raspberry-pi</guid><description><![CDATA[Here is an interesting presentation from Rémi Chipaux a former colleague from itrust consulting.He is talking about his research work on setting up some honey pots for collecting malware samples. The idea is quiet simple, buy a Raspberry PI (it costs around 20-30 euros). Install in it a honeypot tool like Cowrie. Then, just wait for getting impacted by malwares spreading in the wild. It is pretty amazing indeed to see as he explains that it takes few minutes to get a malware uploaded to your ho [...] ]]></description><content:encoded><![CDATA[<div class="paragraph">Here is an interesting presentation from R&eacute;mi Chipaux a former colleague from itrust consulting.<br>He is talking about his research work on setting up some honey pots for collecting malware samples. The idea is quiet simple, buy a Raspberry PI (it costs around 20-30 euros). Install in it a honeypot tool like Cowrie. Then, just wait for getting impacted by malwares spreading in the wild. It is pretty amazing indeed to see as he explains that it takes few minutes to get a malware uploaded to your host.<br>Here is his talk:<br><br></div><div><div id="427224660895670335" align="left" style="width: 100%; overflow-y: hidden;" class="wcustomhtml"><iframe width="560" height="315" src="https://www.youtube.com/embed/skXFNhBxIbI" frameborder="0" allow="autoplay; encrypted-media" allowfullscreen=""></iframe></div></div>]]></content:encoded></item><item><title><![CDATA[The future of testing﻿]]></title><link><![CDATA[https://www.mouelhi.com/blog/the-future-of-testing]]></link><comments><![CDATA[https://www.mouelhi.com/blog/the-future-of-testing#comments]]></comments><pubDate>Wed, 29 Jun 2016 12:58:22 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/the-future-of-testing</guid><description><![CDATA[This is a really interesting talk from Prof. James Whittaker on the future of testing. He is talking about how testing changing and how it will be in the future and he is really right in this prediction done in 2008. As predicted, crowd testing companies (like utest.com) are becoming very successful nowadays.&#8203;"The best way to predict the future is to invent it". Whittaker is definitely among those inventing the future of testing.        [...] ]]></description><content:encoded><![CDATA[<div class="paragraph" style="text-align:left;">This is a really interesting talk from Prof. James Whittaker on the future of testing. He is talking about how testing changing and how it will be in the future and he is really right in this prediction done in 2008. As predicted, crowd testing companies (like utest.com) are becoming very successful nowadays.<br />&#8203;<br />"The best way to predict the future is to invent it". Whittaker is definitely among those inventing the future of testing.<br /><br /></div>  <div class="wsite-youtube" style="margin-bottom:10px;margin-top:10px;"><div class="wsite-youtube-wrapper wsite-youtube-size-auto wsite-youtube-align-center"> <div class="wsite-youtube-container">  <iframe src="//www.youtube.com/embed/Pug_5Tl2UxQ?wmode=opaque" frameborder="0" allowfullscreen></iframe> </div> </div></div>]]></content:encoded></item><item><title><![CDATA[Interesting talk on Web application testing]]></title><link><![CDATA[https://www.mouelhi.com/blog/interesting-talk-on-web-application-testing]]></link><comments><![CDATA[https://www.mouelhi.com/blog/interesting-talk-on-web-application-testing#comments]]></comments><pubDate>Sun, 19 Jul 2015 14:36:03 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/interesting-talk-on-web-application-testing</guid><description><![CDATA[This is an interesting talk given by a notorious researcher in software testing, Prof. Jeff Offutt. It was given on 2010. However, it is still very insightful and really nice to watch:He is really a brilliant researcher. He is demonstrating in this talk in a very nice way how useful and practical academic research can and should be.&nbsp; [...] ]]></description><content:encoded><![CDATA[<div class="paragraph" style="text-align:left;">This is an interesting talk given by a notorious researcher in software testing, Prof. Jeff Offutt. It was given on 2010. However, it is still very insightful and really nice to watch:<br><span>He is really a brilliant researcher. He is demonstrating in this talk in a very nice way how useful and practical academic research can and should be.&nbsp;</span><br><br><br></div><div><div id="905513597768653551" align="left" style="width: 100%; overflow-y: hidden;" class="wcustomhtml"><iframe width="420" height="315" src="https://www.youtube.com/embed/lmS5ElMyIHU" frameborder="0" allowfullscreen=""></iframe></div></div><div class="paragraph" style="text-align:left;"><br><br></div>]]></content:encoded></item><item><title><![CDATA[PRISM and privacy]]></title><link><![CDATA[https://www.mouelhi.com/blog/prism-and-privacy]]></link><comments><![CDATA[https://www.mouelhi.com/blog/prism-and-privacy#comments]]></comments><pubDate>Wed, 03 Jul 2013 09:50:04 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/prism-and-privacy</guid><description><![CDATA[The US&nbsp;surveillance&nbsp;program PRISM&nbsp;is just something that have been known for years, as the french say a secret de polichinelle (open secret). You will find on the internet more information, comments, blog posts on this, like here, or here or here.&nbsp;My view on this subject is that with the popularity of social networks, the cloud service, all private information that was few years ago almost impossible to get is freely available on the social networks websites or on cloud provi [...] ]]></description><content:encoded><![CDATA[<div class="paragraph" style="text-align:left;">The US&nbsp;surveillance&nbsp;program <a href="http://en.wikipedia.org/wiki/PRISM_(surveillance_program)" target="_blank">PRISM</a>&nbsp;is just something that have been known for years, as the french say a secret de <a href="http://fr.wikipedia.org/wiki/Secret_de_Polichinelle">polichinelle</a> (open secret). You will find on the internet more information, comments, blog posts on this, like <a href="http://www.guardian.co.uk/world/2013/jun/20/fisa-court-nsa-without-warrant" target="_blank">here</a>, or <a href="http://walt.foreignpolicy.com/posts/2013/07/01/news_flash_states_spy_on_each_other?wp_login_redirect=0" target="_blank">here</a> or <a href="http://www.zdnet.com/latest-nsa-leak-details-prisms-bigger-picture-7000017487/" target="_blank">here</a>.&nbsp;<br />My view on this subject is that with the popularity of social networks, the cloud service, all private information that was few years ago almost impossible to get is freely available on the social networks websites or on cloud providers data centers. Take for instance, the location based services (for users of twitter, facebook, android, ios, windows phone) &nbsp;is really a gold mine for secret services, a dream come true. They are able to know location of millions of people around the work. As smartphones, social networks get more adopted by the world population (there is already <a href="http://news.cnet.com/8301-1035_3-57534132-94/worldwide-smartphone-user-base-hits-1-billion/" target="_blank">one billion smartphone users</a>&nbsp;and this stat is from last year!) , secret services will be able to monitor all these people on daily basis.&nbsp;<br />A program like PRISM is in my opinion already outdated because there is much more to get easily from all the data available thanks to social networks and smartphones. The big issue is no more how to get this data but is how to sort it, how to find and locate the most relevant pieces among this huge amount of data.<br />Finally, we have to admit that privacy is almost <a href="http://www.zdnet.com/privacy-is-dead-so-what-if-you-friended-the-nsa-7000016507/" target="_blank">dead</a> and it is getting difficult to protect your privacy.<br /><br /><br /><br /><br /></div>]]></content:encoded></item><item><title><![CDATA[Apple maps or the perfect example of the worst way to test an application]]></title><link><![CDATA[https://www.mouelhi.com/blog/apple-maps-or-the-perfect-example-of-the-worst-way-to-test-an-application]]></link><comments><![CDATA[https://www.mouelhi.com/blog/apple-maps-or-the-perfect-example-of-the-worst-way-to-test-an-application#comments]]></comments><pubDate>Thu, 04 Oct 2012 15:29:27 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/apple-maps-or-the-perfect-example-of-the-worst-way-to-test-an-application</guid><description><![CDATA[It made the news in almost all around the world. Apple maps is really badly tested, contains a lot of inaccurate maps/pictures. Many websites are making jokes and having fun showing a list of apple maps mistakes/bugs.It is obvious this software was not tested right. It is really surprising because it seems that the basic concepts/methods of the software testing were not followed.The basic testing approach would be to get some end-user tester perform system testing. At least, trying and running t [...] ]]></description><content:encoded><![CDATA[<div class="paragraph" style="text-align:left;">It made the <a href="http://www.google.co.uk/search?hl=en&amp;gl=uk&amp;tbm=nws&amp;q=apple+maps+bugs&amp;oq=apple+maps+bugs&amp;gs_l=news-cc.3..43j43i400.3672.3672.0.4283.1.1.0.0.0.0.52.52.1.1.0...0.0...1ac.2.LBNMk7A_YSw" target="_blank">news</a> in almost all around the world. Apple maps is really badly tested, contains a lot of <a href="http://www.forbes.com/sites/petercohan/2012/09/27/apple-maps-six-most-epic-fails/" target="_blank">inaccurate</a> maps/pictures. Many websites are making jokes and having fun showing a <a href="http://theamazingios6maps.tumblr.com/" target="_blank">list</a> of apple maps mistakes/bugs.<br />It is obvious this software was not tested right. It is really surprising because it seems that the basic concepts/methods of the <a href="http://en.wikipedia.org/wiki/Software_testing#Testing_methods">software testing</a> were not followed.<br />The basic testing approach would be to get some end-user tester perform <a href="http://en.wikipedia.org/wiki/System_testing">system testing</a>. At least, trying and running the application, trying it with famous and known locations.<br />This apple maps, I think will remain for a long time and the perfect example ever of what you should not do when testing an application.</div>]]></content:encoded></item><item><title><![CDATA[Funny paper review]]></title><link><![CDATA[https://www.mouelhi.com/blog/funny-paper-review]]></link><comments><![CDATA[https://www.mouelhi.com/blog/funny-paper-review#comments]]></comments><pubDate>Fri, 09 Mar 2012 14:02:28 GMT</pubDate><category><![CDATA[funny]]></category><category><![CDATA[research]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/funny-paper-review</guid><description><![CDATA[I came across this website. It is citing some real examples of funny, hilarious paper reviews. This is always done during scientific conferences peer-review process. Other researchers in the same research field are invited to review and evaluate the quality of papers submitted to conferences. They choose to accept or reject the publication of the paper.&nbsp;In this website, there is a list of funny comments on submitted papers, read and judge by yourself:There is no experimental demonstration o [...] ]]></description><content:encoded><![CDATA[<div class="paragraph" style="text-align:left;">I came across this <a href="http://www.loria.fr/~quinson/Research/fun/brfh/" target="_blank">website</a>. It is citing some real examples of funny, hilarious paper reviews. This is always done during scientific conferences peer-review process. Other researchers in the same research field are invited to review and evaluate the quality of papers submitted to conferences. They choose to accept or reject the publication of the paper.&nbsp;<br />In this <a href="http://www.loria.fr/~quinson/Research/fun/brfh/">website</a>, there is a list of funny comments on submitted papers, read and judge by yourself:<ul style=""><li style="">There is no experimental demonstration of your theorem.</li><li style="">My name only appears in the Acknowledgements section where I could have signed this paper.</li><li style="">You shoudl let a native english speaker reads the paper to checking the ortographe and gramar of the paper.</li><li style="">Your contribution is so trivial that somebody must have published this somewhere already.</li><li style="">I may have accepted your paper, but I had better things to do so I didn't read it.</li><li style="">I had a headache just by looking at the data structures of your linear-time optimal algorithm. No doubt an exhaustive algorithm would be more efficient in practice.</li><li style="">Reject: Figure 3 is unclear.</li><li style="">Your research agenda is so outdated that your results are on a Wikipedia page already.</li><li style="">Being 37% better than a complete moron does not make you a genius.</li><li style="">This article does not deserve the paper and ink used to print it.</li><li style="">In the future, don't waste your time writing articles manually. Use a generator such as http://pdos.csail.mit.edu/scigen/ to ensure they are gramatically correct, if not instructive.</li><li style="">I can't believe the authors took the time to present, analyze and prove an algorithm for this middle-school problem.</li><li style="">Honnestly, I really wonder whether this article is a joke or not. Anyway, I can assure you it gave me a good laugh and put me in a good mood for the rest of the day.</li><li style="">The used notations are unclear and confusing. Since clear writing leads to clear thinking, I doubt that the authors really understood their own article.</li><li style="">The only merit of this paper is to demonstrate all what you have to not do when writing an article.</li><li style="">The practical effectiveness of the algorithm may be somewhat overstated since the experimental results prove its inability to fulfill its goals.</li><li style="">Strengths: What are the major reasons to accept the paper? [Be brief.] I did not find strengths; I stopped reading the paper on page 12, so I may have missed something. <br /></li><li style="">This paper is original, well written and fully matches the topic, but its subject is so boring that I strongly recommend its rejection.</li><li style="">Some Monthy Python sketches are far more logical than this paper.</li><li style="">This paper needs a major rewrite to fix the English, make it more concise, explain clearly what exactly is the performance evaluation methodology, and how it is different from the obvious. (this one was seen for real as I was PC member...)</li></ul><br /></div>]]></content:encoded></item><item><title><![CDATA[Duqu the new threat]]></title><link><![CDATA[https://www.mouelhi.com/blog/duqu-the-new-threat]]></link><comments><![CDATA[https://www.mouelhi.com/blog/duqu-the-new-threat#comments]]></comments><pubDate>Mon, 07 Nov 2011 12:18:34 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/duqu-the-new-threat</guid><description><![CDATA[A new malware is spreading right now. It is an important threat since this malware is very similar to the famous Stuxnet malware (an interesting talk about analysing stuxnet). It installs a keylogger that records all the keystrokes and the system configuration, then encrypt all this data and stores then in an image.To detect and remove this threat, you can use this tool. [...] ]]></description><content:encoded><![CDATA[<div class="paragraph" style="text-align:left;">A new <a href="http://thehackernews.com/2011/11/duqu-another-stuxnet-in-making.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Daily+Cyber+News+Updates%29">malware</a> is spreading right now. It is an important threat since this malware is very similar to the famous Stuxnet malware (an interesting <a href="http://www.youtube.com/watch?v=rOwMW6agpTI">talk</a> about analysing stuxnet). It installs a keylogger that records all the keystrokes and the system configuration, then encrypt all this data and stores then in an image.<br />To detect and remove this threat, you can use this <a href="https://github.com/halsten/Duqu-detectors">tool</a>.</div>]]></content:encoded></item><item><title><![CDATA[Google chrome attack]]></title><link><![CDATA[https://www.mouelhi.com/blog/google-chrome-attack]]></link><comments><![CDATA[https://www.mouelhi.com/blog/google-chrome-attack#comments]]></comments><pubDate>Wed, 18 May 2011 12:48:16 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/google-chrome-attack</guid><description><![CDATA[A security company VUPEN claims that they were able to successfully perform an attack on Google chrome. According to them&nbsp;v11.0.696.68 and v12.0.742.30. Their attack bypasses the sandbox security mechanisms, and works on Windows 7, 64 bits which has the data execution prevention (DEP) and address space layout randomisation (ASLR) security features.VUPEN does not give any details on the exploits. They did not even share it with google, which is very unusual. and surprising. They say that the [...] ]]></description><content:encoded><![CDATA[<div  class="paragraph editable-text" style=" text-align: left; ">A security company <a title="" href="http://www.vupen.com/english/"><span style="text-decoration: underline;">VUPEN</span></a> claims that they were able to successfully perform an <a title="" href="http://www.vupen.com/demos/VUPEN_Pwning_Chrome.php">attack</a> on Google chrome. According to them&nbsp;v11.0.696.68 and v12.0.742.30. Their attack bypasses the sandbox security mechanisms, and works on Windows 7, 64 bits which has the data execution prevention (<a title="" href="http://en.wikipedia.org/wiki/Data_Execution_Prevention">DEP</a>) and address space layout randomisation (<a title="" href="http://en.wikipedia.org/wiki/Address_space_layout_randomization">ASLR</a>) security features.<br />VUPEN does not give any details on the exploits. They did not even share it with google, which is very unusual. and surprising. They say that they are sharing the exploits with their goverment customers. This is not clear whetther they meant that they are sharing the exploit or the vulnerability and the way to protect from.<br /><span>This means that there is out there a <a href="http://en.wikipedia.org/wiki/0day">0day</a></span>vunerability that allows to hack into your system just by visiting a malicious website. <br /></div>  ]]></content:encoded></item><item><title><![CDATA[Anonymous the hacktivist]]></title><link><![CDATA[https://www.mouelhi.com/blog/anonymous-the-hacktivist]]></link><comments><![CDATA[https://www.mouelhi.com/blog/anonymous-the-hacktivist#comments]]></comments><pubDate>Wed, 06 Apr 2011 19:53:39 GMT</pubDate><category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">https://www.mouelhi.com/blog/anonymous-the-hacktivist</guid><description><![CDATA[The anonymous group succeeded to attack several targets among them visa, paypall and mastercard (they did this to support wikileaks).&nbsp;These attacks used DDOS, quite simple, however they were able to attack the HBGary an important security company. This time it was a more sophisticated attack, they were able to find an sql injection vulnerability in the HBGary website, they used it, then they managed to get most of the company emails to make them public (torrent) &nbsp;and with social engine [...] ]]></description><content:encoded><![CDATA[<div  class="paragraph editable-text" style=" text-align: left; ">The <a href="http://en.wikipedia.org/wiki/Anonymous_(group)">anonymous group</a> succeeded to attack several targets among them <a href="http://www.neowin.net/news/visa-to-be-targeted-next-by-anonymous">visa, paypall and mastercard</a> (they did this to support wikileaks).&nbsp;<br />These attacks used DDOS, quite simple, however they were able to attack the <a href="http://www.hbgary.com/open-letter-from-hbgary">HBGary </a>an important security company. This time it was a more sophisticated attack, they were able to find an sql injection vulnerability in the <a href="http://arstechnica.com/tech-policy/news/2011/02/anonymous-speaks-the-inside-story-of-the-hbgary-hack.ars">HBGary website</a>, they used it, then they managed to get most of the company emails to make them public (torrent) &nbsp;and with social engineering they had access to the famous rootkit.com server.<br />Lesson to learn from this attack, it is amazing to see that a security company like HBGary can become victim of this kind of attack (how difficult it is to protect against targeted attack from skilled hackers).&nbsp;<br />The second lesson is on how important it is to secure the company emails. The information inside them can be very harmful if leaked.<br />&nbsp;</div>  ]]></content:encoded></item></channel></rss>