<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vanimpe.eu</title>
	<atom:link href="http://www.vanimpe.eu/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.vanimpe.eu</link>
	<description>Rants on Linux, Drupal, Security, ...</description>
	<lastBuildDate>Wed, 15 Feb 2012 16:20:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Mapping my neighbourhood SSIDs</title>
		<link>http://www.vanimpe.eu/2012/02/15/mapping-my-neighbourhood-ssids/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mapping-my-neighbourhood-ssids</link>
		<comments>http://www.vanimpe.eu/2012/02/15/mapping-my-neighbourhood-ssids/#comments</comments>
		<pubDate>Wed, 15 Feb 2012 16:20:21 +0000</pubDate>
		<dc:creator>koen</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2012/02/15/mapping-my-neighbourhood-ssids/</guid>
		<description><![CDATA[A recent post by @xme revealed a tool that allows for passive mapping of SSIDs. I gave it a go for 48 hours and below are the results. bbox2-1888 2126 bbox2-4344 1580 dlink 84 Veronique 123 31 bbox2-0530 28 telenet-4F11F 28 ZapFi 14 FON_BELGACOM 12 linford1986 4 Wifi 45 4 ZapFi-Gusto 4 coffee House 3 [...]]]></description>
			<content:encoded><![CDATA[<p>A recent <a href="http://blog.rootshell.be/2012/01/12/show-me-your-ssids-ill-tell-who-you-are/">post</a> by <a href="https://twitter.com/xme">@xme</a> revealed a <a href="https://github.com/xme/hoover">tool</a> that allows for passive mapping of SSIDs. I gave it a go for 48 hours and below are the results.</p>
<table border="0">
<tbody>
<tr>
<td>bbox2-1888</td>
<td>	2126</td>
</tr>
<tr>
<td>bbox2-4344</td>
<td>	1580</td>
</tr>
<tr>
<td>dlink</td>
<td>	84</td>
</tr>
<tr>
<td>Veronique 123</td>
<td>	31</td>
</tr>
<tr>
<td>bbox2-0530</td>
<td>	28</td>
</tr>
<tr>
<td>telenet-4F11F</td>
<td>	28</td>
</tr>
<tr>
<td>ZapFi</td>
<td>	14</td>
</tr>
<tr>
<td>FON_BELGACOM</td>
<td>	12</td>
</tr>
<tr>
<td>linford1986</td>
<td>	4</td>
</tr>
<tr>
<td>Wifi 45</td>
<td>	4</td>
</tr>
<tr>
<td>ZapFi-Gusto</td>
<td>	4</td>
</tr>
<tr>
<td>coffee House</td>
<td>	3</td>
</tr>
<tr>
<td>homewlan</td>
<td>	3</td>
</tr>
<tr>
<td>queenshotel</td>
<td>	3</td>
</tr>
<tr>
<td>WifiCharles</td>
<td>	3</td>
</tr>
<tr>
<td>Axip-Home</td>
<td>	2</td>
</tr>
<tr>
<td>Axip-NW</td>
<td>	2</td>
</tr>
<tr>
<td>bbox2-22b5</td>
<td>	2</td>
</tr>
<tr>
<td>SKY24721</td>
<td>	2</td>
</tr>
<tr>
<td>WLAN_38</td>
<td>	2</td>
</tr>
<tr>
<td>bbox2-c230</td>
<td>	1</td>
</tr>
<tr>
<td>BENCHIJIGUA</td>
<td>	1</td>
</tr>
<tr>
<td>BODEGON DEL MAR</td>
<td>	1</td>
</tr>
<tr>
<td>newcastle-university</td>
<td>	1</td>
</tr>
<tr>
<td>Piglet</td>
<td>	1</td>
</tr>
<tr>
<td>Rusty Bicycle</td>
<td>	1</td>
</tr>
<tr>
<td>virginmedia0830911</td>
<td>	1</td>
</tr>
<tr>
<td>virginmedia8469780</td>
<td>	1</td>
</tr>
<tr>
<td>VOYAGER2091-D5</td>
<td>	1</td>
</tr>
<tr>
<td>WiFi_62</td>
<td>	1</td>
</tr>
<tr>
<td>WLAN_69</td>
<td>	1</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2012/02/15/mapping-my-neighbourhood-ssids/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BNP Paribas, internetbanking and security/privacy marriage failure</title>
		<link>http://www.vanimpe.eu/2012/02/11/bnp-paribas-internetbanking-and-securityprivacy-marriage-failure/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=bnp-paribas-internetbanking-and-securityprivacy-marriage-failure</link>
		<comments>http://www.vanimpe.eu/2012/02/11/bnp-paribas-internetbanking-and-securityprivacy-marriage-failure/#comments</comments>
		<pubDate>Sat, 11 Feb 2012 10:49:53 +0000</pubDate>
		<dc:creator>koen</dc:creator>
				<category><![CDATA[internet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2012/02/11/bnp-paribas-internetbanking-and-securityprivacy-marriage-failure/</guid>
		<description><![CDATA[I do some of my internet banking through BNP Paribas. Today I was greeted with this message: The flash notice isn&#8217;t such a big security risk on its own but from a banking site I&#8217;d expect they would be more careful by&#160;- informing users that a (useless) banner requires Flash on your computer (Flash being [...]]]></description>
			<content:encoded><![CDATA[<p>I do some of my internet banking through <a href="https://www.bnpparibasfortis.be">BNP Paribas</a>. Today I was greeted with this message:<br /><img src="http://www.vanimpe.eu/wp-content/uploads/2012/02/bnp.jpg" /></p>
<p>The flash notice isn&#8217;t such a big security risk on its own but from a banking site I&#8217;d expect they would be more careful by<br />&nbsp;- informing users that a (useless) banner requires Flash on your computer (Flash being a popular attack vector is good for gaming sites, from a banking site I&#8217;d expect something else)<br />&nbsp;- informing users upfront what &#8216;<a href="http://www.profacts.be/">Profacts.be</a>&#8216; is about and a detailed explanation on what kind of data they are sharing with that partner (&#8220;Profacts is a market research agency&#8221; does not sound the kind of agency I&#8217;d be happy to share my data with, a banner with &#8216;gegevens blijven volledig vertrouwelijk&#8217; isn&#8217;t sufficient)</p>
<p>You get these kinds of notices often when you visit newspaper or general interests sites and that&#8217;s fine. However when visiting a banking site &#8216;everything&#8217; that might raise suspicion or confusion should be avoided.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2012/02/11/bnp-paribas-internetbanking-and-securityprivacy-marriage-failure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Favorite iPhone apps</title>
		<link>http://www.vanimpe.eu/2011/12/16/top-10-favorite-iphone-apps/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=top-10-favorite-iphone-apps</link>
		<comments>http://www.vanimpe.eu/2011/12/16/top-10-favorite-iphone-apps/#comments</comments>
		<pubDate>Fri, 16 Dec 2011 20:26:47 +0000</pubDate>
		<dc:creator>koen</dc:creator>
				<category><![CDATA[geek]]></category>
		<category><![CDATA[internet]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2011/12/16/top-10-favorite-iphone-apps/</guid>
		<description><![CDATA[The iPhone is such a nice piece of gadgetry but it would not be nothing without the numerous apps. I&#8217;ve been using an iPhone (iOS 3, 4 and 5) for more that a year and a half and these are the apps (*) I can&#8217;t live without.(*) only apps that are not part of the [...]]]></description>
			<content:encoded><![CDATA[<p>The iPhone is such a nice piece of gadgetry but it would not be nothing without the numerous apps. I&#8217;ve been using an iPhone (iOS 3, 4 and 5) for more that a year and a half and these are the apps (*) I can&#8217;t live without.<br />(*) only apps that are not part of the default install.</p>
<p>
<h3>1. Evernote </h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/evernotelogo.png" height="32" /><i><br />Evernote makes it easy to remember things big and small from your everyday life using your computer, phone, tablet and the web.</i>
<p>Evernote (<a href="http://www.evernote.com/evernote/">http://www.evernote.com/evernote/</a>) is available for iPhone, Mac and Windows and allows you to make lists of things you don&#8217;t want to remember. Besides the &#8216;todo-list&#8217; it also allows you to save entire websites (with the use of browser plugins) in your Evernote repository. This is the feature I like most, it allows me to store an entire website for later (offline) reading on my iPhone.</p>
<h3>2. Reeder</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/reederlogo.jpeg" width="32" /><i><br />Reeder is a Google reader client</i>
<p>Reeder (<a href="http://itunes.apple.com/us/app/reeder/id325502379">http://itunes.apple.com/us/app/reeder/id325502379</a>) is an RSS reader that allows you to read your feeds, mark interesting articles and then have them synced once you get back online.</p>
<p>
<h3>3. Foursquare</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/foursquareicon-300x300.png" width="32" /><br /><i>Make the real world easier to user</i>
<p>Foursquare (<a href="https://foursquare.com/">https://foursquare.com/</a>) is a social app allows you to track where you have been. It allows you to keep track of where your friends are and notifies you if you &#8216;check in&#8217; to a building where one of your friends is.</p>
<p>
<h3>4. Echofon</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/echofon.png" width="32" /><br /><i>Echofon (<a href="http://www.echofon.com/">http://www.echofon.com/</a> is a family of Twitter apps.</i>
<p>Echofon is my preferred twitter app on iPhone because it&#8217;s straightforward to use and I&#8217;ve rarely had it crash.</p>
<p>
<h3>5. Gorillacam</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/gcam-logo2.gif" height="32" /><br /><i>camera app for iPhone</i>
<p>Gorillacam (<a href="http://joby.comgorillacam">http://joby.com/gorillacam</a>) allows you to create pictures with your phone. An &#8220;anti-shake&#8221; provides a way to take pictures when your phone is steady, helping you get blur-free photos.</p>
<p>
<h3>6. Toggl</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/TogglDesktop.png" width="32" /><br /><i>Time Tracking that works</i>
<p>Toggl (<a href="https://www.toggl.com/">https://www.toggl.com/</a> is an easy of way of keeping track of the amount of time you spend on different projects. It&#8217;s a must have if you want to get organised.</p>
<p>
<h3>7. Tap&amp;Track</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/taptrack.jpg" width="32" /><br /><i>Calorie Counter (Diets &amp; Exercises)</i>
<p>Tap&amp;Track (<a href="http://itunes.apple.com/be/app/tap-track-calorie-counter/id307749752">http://itunes.apple.com/be/app/tap-track-calorie-counter/id307749752&#8243;</a> allows me to keep track of what I&#8217;m eating and how much I&#8217;m doing sports.</p>
<p>
<h3>8. Opera Mini</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/opera.jpeg" width="32" /><br /><i>Smarter Mobile Browsing</i>
<p>Opera Mini (<a href="http://www.opera.com/mobile/">http://www.opera.com/mobile/</a>) is fast and easy to use browser and a good alternative to the default Safari.</p>
<p>
<h3>9. UITagenda</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/uitagenda.png" height="32" /><br /><i>De meest volledige cultuur- en vrijetijdsagenda voor Vlaanderen en Brussel!</i>
<p>UITagenda (<a href="http://www.uitinvlaanderen.be/iphone">http://www.uitinvlaanderen.be/iphone</a>) is an easy way to keep track of what events are happening in Flanders and Brussels.</p>
<p>
<h3>10. mijnTVgids</h3>
<p><img src="http://www.vanimpe.eu/wp-content/uploads/2011/12/mijntvgids.png" width="32" /><br /><i>De mijnTVgids app is volledig gratis beschikbaar op iPhone, iPod Touch, Android, Windows Phone, Nokia smartphones en HP Web connected printers.</i>
<p>mijnTVgids (<a href="http://mijntvgids.appstrakt.be/">http://mijntvgids.appstrakt.be/</a>) gives a slick interface on what&#8217;s playing on television.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2011/12/16/top-10-favorite-iphone-apps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Basic template for WordPress</title>
		<link>http://www.vanimpe.eu/2011/11/23/basic-template-for-wordpress/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=basic-template-for-wordpress</link>
		<comments>http://www.vanimpe.eu/2011/11/23/basic-template-for-wordpress/#comments</comments>
		<pubDate>Tue, 22 Nov 2011 23:13:09 +0000</pubDate>
		<dc:creator>koen</dc:creator>
				<category><![CDATA[internet]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2011/11/23/basic-template-for-wordpress/</guid>
		<description><![CDATA[I recreated my site recently and moved the custom PHP and WordPress code to a central WordPress code base. I had to recreate some files in the template to get the site to behave the way I wanted it. This is the list of changed files in a WordPress template. 404.php comments.php content-page.php footer.php header.php [...]]]></description>
			<content:encoded><![CDATA[<p>I recreated my site recently and moved the custom PHP and WordPress code to a central WordPress code base. I had to recreate some files in the template to get the site to behave the way I wanted it. This is the list of changed files in a WordPress template.</p>
<p><b>404.php</b><br />
<b>comments.php</b><br />
<b>content-page.php</b><br />
<b>footer.php</b><br />
<b>header.php</b><br />
<b>index.php</b><br />
<b>page.php</b><br />
<b>sidebar.php</b><br />
<b>single.php</b></p>
<p>Of course you&#8217;ll have to add the <b>style.css</b> file and include custom Javascript and CSS files in your header.php file.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2011/11/23/basic-template-for-wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New design</title>
		<link>http://www.vanimpe.eu/2011/11/20/new-design/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-design</link>
		<comments>http://www.vanimpe.eu/2011/11/20/new-design/#comments</comments>
		<pubDate>Sun, 20 Nov 2011 12:30:21 +0000</pubDate>
		<dc:creator>koen</dc:creator>
				<category><![CDATA[design]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[php]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2011/11/19/new-design/</guid>
		<description><![CDATA[I thought it was time for a new design of this website. The old setup was a combination of my own code with a WordPress blog. I now moved everything to WordPress with a custom theme and some template coding. The old site used to look like this : This site uses Google Fonts so [...]]]></description>
			<content:encoded><![CDATA[<p>I thought it was time for a new design of this website. The old setup was a combination of my own code with a WordPress blog. I now moved everything to WordPress with a custom theme and some template coding.</p>
<p>The old site used to look like this :<br />
<a href="http://www.vanimpe.eu/wp-content/uploads/2011/11/oldvanimpe_eu.jpg" rel="lightbox[668]"><img src="http://www.vanimpe.eu/wp-content/uploads/2011/11/oldvanimpe_eu.jpg" width="320" /></a></p>
<p>
This site uses <a href="http://www.google.com/webfonts">Google Fonts</a> so you might want to turn on Javascript for all visual effects.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2011/11/20/new-design/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Use ONLY_FULL_GROUP_BY with WordPress</title>
		<link>http://www.vanimpe.eu/2011/11/13/use-only_full_group_by-with-wordpress/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=use-only_full_group_by-with-wordpress</link>
		<comments>http://www.vanimpe.eu/2011/11/13/use-only_full_group_by-with-wordpress/#comments</comments>
		<pubDate>Sun, 13 Nov 2011 22:14:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[internet]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[php]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2011/11/13/use-only_full_group_by-with-wordpress/</guid>
		<description><![CDATA[Something I came across recently when installing WordPress gave me headaches. Everything seemed to work properly except when selecting posts by category no results were returned. I debugged the problem by looking at the SQL-queries performed by WordPress. One query returned an error : Because the MySQL server was configured to honor ONLY_FULL_GROUP_BY it gave [...]]]></description>
			<content:encoded><![CDATA[<p>Something I came across recently when installing WordPress gave me headaches. Everything seemed to work properly except when selecting posts by category no results were returned.</p>
<p>I debugged the problem by looking at the SQL-queries performed by WordPress. One query returned an error :</p>
<pre class="brush: sql; title: ; notranslate">
SELECT SQL_CALC_FOUND_ROWS  wp_posts.* FROM wp_posts  INNER JOIN wp_term_relationships ON (wp_posts.ID = wp_term_relationships.object_id) WHERE 1=1  AND ( wp_term_relationships.term_taxonomy_id IN (1) ) AND wp_posts.post_type = 'post' AND (wp_posts.post_status = 'publish') GROUP BY wp_posts.ID ORDER BY wp_posts.post_date DESC LIMIT 0, 10
</pre>
<p>Because the MySQL server was configured to honor <strong>ONLY_FULL_GROUP_BY</strong> it gave the error &#8220;&#8216;test.wp</em>posts.post_author&#8217; isn&#8217;t in GROUP BY&#8221;.</p>
<p>I could not disable ONLY_FULL_GROUP_BY serverwide so I had to insert it in the WordPress-code.</p>
<p>The best place to do this was in the <strong>wp-includes/wp-db.php</strong>. Look for the function <strong>db_connect()</strong> and add the code below as the last line of the function.</p>
<pre class="brush: php; title: ; notranslate">
mysql_query( &quot; SET sql_mode='ANSI,TRADITIONAL' &quot;, $this-&gt;dbh);
</pre>
<p>Note that every time you perform an upgrade of WordPress you&#8217;ll have to add this line back to the source code.</p>
<h2>UPDATE</h2>
<p>After implementing this change I was unable to post new posts or pages through the WordPress interface. Doing Quick Posts (through the dashboard) and update via XML-RPC works without a problem.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2011/11/13/use-only_full_group_by-with-wordpress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lookup external IP</title>
		<link>http://www.vanimpe.eu/2011/11/01/lookup-external-ip/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=lookup-external-ip</link>
		<comments>http://www.vanimpe.eu/2011/11/01/lookup-external-ip/#comments</comments>
		<pubDate>Tue, 01 Nov 2011 12:56:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[internet]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2011/11/19/lookup-external-ip/</guid>
		<description><![CDATA[If you are behind a router or gateway and you need to get your public IP then you can use dyndns.org with this wget line:]]></description>
			<content:encoded><![CDATA[<p>If you are behind a router or gateway and you need to get your public IP then you can use dyndns.org with this wget line:</p>
<pre class="brush: bash; title: ; notranslate">
wget -q -O - checkip.dyndns.org|sed -e 's/.*Current IP Address: //' -e 's/&amp;amp;lt;.*$//'
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2011/11/01/lookup-external-ip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Parse logfiles for entries from IP lists</title>
		<link>http://www.vanimpe.eu/2010/05/25/parse-logfiles-for-entries-from-ip-lists/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=parse-logfiles-for-entries-from-ip-lists</link>
		<comments>http://www.vanimpe.eu/2010/05/25/parse-logfiles-for-entries-from-ip-lists/#comments</comments>
		<pubDate>Tue, 25 May 2010 19:28:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[internet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/?p=393</guid>
		<description><![CDATA[I sometimes have to parse log files for different IP addresses and then group them by network owner. This becomes tedious If the number of IP addresses is rather long. The script below can help with automating this manual task. It reads a log file and looks for a match based on keys in an [...]]]></description>
			<content:encoded><![CDATA[<p>I sometimes have to parse log files for different IP addresses and then group them by network owner. This becomes tedious If the number of IP addresses is rather long. The script below can help with automating this manual task.</p>
<p>It reads a log file and looks for a match based on keys in an iplist. Afterwards the result is summarized and grouped by a specified field. For example, say you have the log file<br />
<code><br />
192.168.1.1 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
192.168.1.3 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
192.168.1.1 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
192.168.1.2 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
192.168.1.3 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
192.168.1.2 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
192.168.1.3 - - [1/Apr/2010:1:1:39 +0200] "GET /favicon.ico HTTP/1.1"<br />
</code><br />
and you would like to have all the entries for IPs 192.168.1.2 and 192.168.1.3. Instead of grepping the content for every IP manually you can use the script below. Put all the IPs in an iplist similar to this<br />
<code><br />
1234    | 192.168.1.1   | MyNet<br />
4567    | 192.168.1.2   | MyNet<br />
8901    | 192.168.1.3   | MyNet<br />
2345    | 192.168.1.4   | MyNet<br />
</code></p>
<pre class="brush: php; title: ; notranslate">
&lt;?php
/**
 *
 * Parse a log file and group by entries from another file
 *
 * This script reads a log file and then groups the entries
 * according to keys found in an iplist
 * There's no input validation so make sure neither the
 * log file or iplist contain malicious code
 *
 * This script is useful if you want to group log file entries
 * based on AS number or network name.
 *
 * 		Koen Van Impe				cudeso.be
 *		20100525
 *
 **/

// Configuration array
$config = array(	// file containing the IPs
					&quot;iplist&quot; =&gt; &quot;BE.txt&quot;,
					// logfile with the individual entries
					&quot;logfile&quot; =&gt; &quot;Log_BE.txt&quot;,
					// what field to use as a separator in iplist
					&quot;separator&quot; =&gt; &quot;|&quot;,
					// position of the IP (0-based)
					&quot;ippos&quot; =&gt; 1,
					// position of the groupby field (0-based)
					&quot;groupby&quot; =&gt; 0,
					// newline after a logfile
					&quot;newline&quot; =&gt; false
				);

// Array for the resultset
$result = array();
$matchcount = 0;

// walk through the IP list
if (file_exists($config[&quot;iplist&quot;])) {
	$file_handle = fopen($config[&quot;iplist&quot;], &quot;r&quot;);
	while (!feof($file_handle)) {
		$fields = explode(&quot;|&quot;, fgets($file_handle));
		$key = (string) trim($fields[$config[&quot;groupby&quot;]]);
		if (strlen($key) &gt; 0) {
			$data = trim($fields[$config[&quot;ippos&quot;]]);
			$result[$key][] =  $data;
		}
	}
	fclose($file_handle);

	// read the log file
	if ((file_exists($config[&quot;logfile&quot;])) &amp;&amp; count($result) &gt; 0) {
		$logfile = file($config[&quot;logfile&quot;]);

		echo &quot;Parsing &quot;.$config[&quot;logfile&quot;].&quot;n&quot;.
				&quot;for matches in &quot;.$config[&quot;iplist&quot;].&quot;n&quot;.
				&quot;on field pos #&quot;.$config[&quot;ippos&quot;].&quot;n&quot;.
				&quot;group by field pos #&quot;.$config[&quot;groupby&quot;].&quot;nnn&quot;;
		// walk through the resultset; scan the
		// log file for every entry
		// three foreachs ... optimization
		foreach ($result as $key =&gt; $value) {
			echo &quot;n******************n$keyn******************n&quot;;
			foreach ($logfile as $line) {
				foreach ($value as $match) {
					// is position 0 and is not BOOLEAN
					if ((strpos($line, $match) === 0) or
					// position bigger than 0
						(strpos($line, $match) &gt; 0)) {

							// we have a match
							echo &quot;$line&quot;;
							if ($config[&quot;newline&quot;]) echo &quot;n&quot;;
							$matchcount++;
					}
					else $misscount++;
				}
			}
			echo &quot;nnnn&quot;;
		}

		echo &quot;nn$matchcount relevant entries found in &quot;.$config[&quot;logfile&quot;];
	}
}

?&gt;
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2010/05/25/parse-logfiles-for-entries-from-ip-lists/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing notice from Deutsche Bank</title>
		<link>http://www.vanimpe.eu/2010/05/02/phishing-notice-from-deutsche-bank/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phishing-notice-from-deutsche-bank</link>
		<comments>http://www.vanimpe.eu/2010/05/02/phishing-notice-from-deutsche-bank/#comments</comments>
		<pubDate>Sun, 02 May 2010 16:50:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[internet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2010/05/02/phishing-notice-from-deutsche-bank/</guid>
		<description><![CDATA[A couple of days back I received an e-mail from Deutsche Bank. I&#8217;m not a customer from DB. About a year ago I applied for some information and I guess my email addresses ended up in their mailinglist. The mailing warns customers that there is a phishing attack ongoing. According to the mail, once infected, [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of days back I received an e-mail from Deutsche Bank. I&#8217;m not a customer from DB. About a year ago I applied for some information and I guess my email addresses ended up in their mailinglist.</p>
<p>The mailing warns customers that there is a phishing attack ongoing. According to the mail, once infected, a virus on your computer lures you to a fake page where you are asked to enter your details.</p>
<p>So far so good. It seems like a good practice that banks try to warn their customers.</p>
<p>The mail contains a couple of links that should point you to sites that allow you to check if you are infected or not. Unfortunately the links point to another website. That website seems to have nothing to do with DB. It is a website for a &#8220;relationship marketing suite&#8221;. It is understandable that DB uses an external company to handle their mailings but I don&#8217;t get it &#8230; The message to their customers is &#8220;be on your guards&#8221; and then they ask you to click on a link that has nothing to do with DB?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2010/05/02/phishing-notice-from-deutsche-bank/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Complete Guide to XSS</title>
		<link>http://www.vanimpe.eu/2010/03/24/the-complete-guide-to-xss/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-complete-guide-to-xss</link>
		<comments>http://www.vanimpe.eu/2010/03/24/the-complete-guide-to-xss/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 18:59:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[internet]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.vanimpe.eu/2010/03/24/the-complete-guide-to-xss/</guid>
		<description><![CDATA[There is a good writeup on XSS on Security Override.]]></description>
			<content:encoded><![CDATA[<p>There is a good <a href="http://securityoverride.com/articles.php?article_id=13&amp;article=The_Complete_Guide_to_XSS">writeup on XSS</a> on Security Override.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.vanimpe.eu/2010/03/24/the-complete-guide-to-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

