New UK Computer Misuse Act... Yeuch

There are some amendments in the new Police and Justice Act to the Computer Misuse Act and some of them do not sound like good news for the UK Penetration testing & Security Research community.
Looking at Section 37 of the Act you get this

(1) A person is guilty of an offence if he makes, adapts, supplies or offers
to supply any article intending it to be used to commit, or to assist in
the commission of, an offence under section 1 or 3.
(2) A person is guilty of an offence if he supplies or offers to supply any
article believing that it is likely to be used to commit, or to assist in the
commission of, an offence under section 1 or 3.
(3) A person is guilty of an offence if he obtains any article with a view to
its being supplied for use to commit, or to assist in the commission of,
an offence under section 1 or 3.

(Offences in section 1 or 3 is basically unauthorised access to computer resources).
To my mind that leaves people publishing exploit code in the UK in serious trouble along with anyone selling or making open source Penetration testing software. It'd would be pretty hard to argue that you didn't believe it was likely that a tool that could be used for Pen testing could also be used by someone to break into a system, as the only thing that's really different is the intent !
The act also covers DoS (or reckless impairment of the operation of a computer as the act calls it) so would it follow that software which stress tests systems would also fall foul of the act?
I expect that what'll happen is that we'll get some chat from government officials that "legitimate security professionals won't be targeted" but I for one really don't like the idea that I could be committing an offence and I'm relying on someones definition of "legitimate" to avoid being prosecuted!

More on Database vulnerability numbers

There's some more data on comparing Oracle and MS SQL server vulnerability levels over at michael Howards blog.
There's a link to a study by David Litchfield on the numbers here which pretty much comes to a similar conclusion to looking at the secunia numbers, but does a more accurate job of analysing the findings by looking at a number of sources.
The clear point to be made is that Microsoft have done a very good job on the security of MS SQL server 2005 and if someone were to ask me about a choice between these two "enterprise database" vendors in terms of security, it would be a bit of a no-brainer!
One thing you can see is that this study, whilst still coming to the same conclusion (that MS SQL server is more secure than Oracle) actually has quite different numbers from the ESG study that was quoted in Michael's earlier blog posting here
At a rough count the NGS paper lists ~58 MS SQL vulnerabilities whilst the ESG one lists less than 10 (there's no background data so it's kinda hard to tell), and a similar story for the Oracle one with well over a hundred in the NGS paper and only 70 in the ESG one.
IMO a good reason to actually dig a bit deeper on these things rather than go with something like CVE which isn't really designed for the purpose. The same result has come out but by being able to see what's being counted it becomes more believable and less likely to have people be able to argue the stats....

Database Vulnerability numbers

There's a post over at Michael Howards Blog about a study showing that Microsoft SQL Server has a better security record than Oracle or MySQL.
Whilst I agree with the overall point, SQL server (especially 2005) is waay better than Oracle/MySQL on the security front, the numbers this study uses seem odd..
They've not specified product version and that's just going to make the numbers very odd, they've also not (that I can see) specified their exact methodology the comment above implies that their methodology may not be the best!
Here's a better (IMO) analysis, using secunia which actually breaks things down well by product
Number of advisories per product from 2003-2006
Microsoft SQL Server 2000 - 10
Microsoft SQL Server 2005 - 0
MySQL 3 - 11
MySQL 4 - 19
MySQL 5 - 5
Oracle 8i - 17
Oracle 9i Enterprise - 23
Oracle 10g - 13
Now I know it's possible to argue the point around severity etc and product age, but I'd say still a pretty clear win for Microsoft...

blog.searchinfosec.com

Well in order to keep things a bit separated, and also so that I can have a play with the cool mephisto blogging software, I've set up a new blog for searchinfosec.com related items over at blog.searchinfosec.com

searchinfosec.com

well I decided to try and work on the Information Security search engine a bit more, so in order to make it easier to find, I've setup www.searchinfosec.com .
From there you can add searchnifosec.com to your google search toolbar.

Information Security Search Engine with Google Coop

There's an interesting new beta project from google launched today, which allows you to create custom search engines which focus on a given topic area by customising which sites are indexed as part of the search. I've created a couple of one's in areas that interest me .
I think that this could be really useful for targeted searches as it can cut out a lot of the "spam" and other less relevant sites from the search results.
This one is an Information Security Search engine. At the moment it's based on some sites which I use (list below), but if there are other ones that anyone would like to see include just leave a comment, or feel free to volunteer to help out on the search engine front page.
Anyway here's a link to the Information Security Search Engine Homepage
and here's an embedded version which google provide the code for

Information Security Search Engine

Current site listing (24/10/2006)

isc.sans.org
msdn.microsoft.com/security
www.cert.org
www.securityfocus.com
www.stupidsecurity.com
www.mckeay.net/secure/
www.schneier.com/blog/
catless.ncl.ac.uk/Risks
www.networkworld.com/topics/security.html
www.sans.org/reading_room/
sunbeltblog.blogspot.com
taosecurity.blogspot.com
www.red-database-security.com
www.isc2.org
www.cccure.org
secunia.com
www.mccune.org.uk
www.securityforum.org
www.issa.org
csrc.nist.gov
www.cisecurity.com
www.dhanjani.com
financialcryptography.com

Ruby on Rails Search Engine with Google Coop

Ever gone looking for some insight into your latest rails conundrum and ended up finding answers for the wrong language that mention ruby elsewhere in the page? I know I have.
Here's an interesting new beta project from google launched today, which allows you to create custom search engines which focus on a given topic area by customising which sites are indexed as part of the search.
I think that this could be really useful for targeted searches as it can cut out a lot of the "spam" and other less relevant sites from the search results. Also while you can get the same effect by using the site: parameter, doing that about 20 or 30 times per search doesn't really appeal.
So here's a Ruby on rails Search. At the moment it's based on some sites which I use (list below), but if there are other ones that anyone would like to see include just leave a comment, or volunteer to help out on the search engine front page.
edit: Looks like quite a few people in the RoR community had this idea.... so rather than have lots of different searches doing the same thing I've removed my one.
But if you're looking for a RoR search engine head over here to the Ruby Inside Search Engine

Site Listing

http://www.rubyforge.org/
http://www.ryandaigle.com/
http://weblog.rubyonrails.com/
http://www.loudthinking.com/
http://www.slash7.com/
http://www.oreillynet.com/ruby/
http://www.rubyonrailsforum.com/
http://www.ruby-forum.com/
http://www.bigbold.com/snippets/tags/rails
http://wiki.rubyonrails.com/
http://dev.rubyonrails.org/
http://www.ruby-lang.org/en/
http://www.37signals.com/
http://www.rubyonrails.com/
http://blog.t0fuu.com/
http://weblog.jamisbuck.org/
http://www.railtie.net/
http://www.rubyonrailsblog.com/
http://cardboardrocket.com/
http://www.danwebb.net/
http://mephistoblog.com/
http://curthibbs.wordpress.com/
http://www.softiesonrails.com/
http://nubyonrails.com/
http://www.rubyinside.com/
http://www.height1percent.com/
http://www.straw-dogs.co.uk/blog/

Handy Ruby Framework for scripting

SimpleConsole - Building Console Apps
Interesting looking idea. I know that a lot of the work I do tends to revolve around writing little command-line scripts so anything that helps with that can only be a good thing

Using Google Code search to find the programming language most likely to drive you mad

After seeing all the great uses people are finding for Google's new Code Search I thought, "yeah these are useful, but what would be really useful would be to use this to find out what language is most likely to drive programmers mad!"
So I developed a rigourous methodolgy which primarily consists of searching for code invoking the name of Great Cthulhu ! What surer sign of madness than using the name of a great old one!
so without further ado, here's the results of my painstaking search.

From this we can clearly see that C is leading the pack, with TCL obviously a pretty mind-bending second place.

SQL Injection tool

.:: nothern-monkee ::.
Another interesting looking SQL injection tool to look at.