and yet more tool updates...
SQL Power Injector Product Information
A new release of SQL Power Injector. Not a tool I've played with much yet, but could be cool to try it out in conjunction with the hacme stuff from foundstone...
SQL Power Injector Product Information
A new release of SQL Power Injector. Not a tool I've played with much yet, but could be cool to try it out in conjunction with the hacme stuff from foundstone...
Foundstone, a division of McAfee, Inc.
Seems to be tool-tastic at the moment. Foundstone have updated their hacme books and hacme bank site and released hacme travel and shipping!
Shipping is a Coldfusion app with a mysql database and travel is in C++ which should be interesting... (like the typo on the travel page which explains that the system suffers from common vulnerabilities such as "SQL injection and bugger overflows")
"Hacking iSeries" references and links
Just started to go through the blackhat europe 2006 media archives and found something useful to keep a note of (expect many more posts as I go).
iSeries (more commonly known as AS/400) is not something which there's a wide understanding of, both in IT security and pen testing (IME of course)
This site seems to have a load of good links and an eBook on hacking iSeries .. Also here's a link to the blackhat presentation which has a lot of good info. on the topic Hacking iSeries Presentation
Survey: gaping security holes - Network World
Some interesting numbers relating to security trends. It's not surprising really though it should be..
over half of companies admit they're not doing a good job of working out what's on the network (kinda' hard to patch a box you don't know you've got)
And probably the worst, over 25% of companies dedicate no resource to assessing the value of business assets.
the question is how are these companies doing risk assessments or Business Continuity Planning (with the cynical answer being..."Not Well")...
There's a new security tool called CAL9000 available over at the OWASP site here
Another one to look into...
TaoSecurity
Ethereals changing name to the snappy "wireshark ".
Sounds like good news to me for the very trivial reason that I always used to go looking for Ethereal at www.ethereal.org only to find that it wasn't there ;op
Nightmare On Wall Street: Prosecution Witness Describes 'Chaos' In UBS PaineWebber Attack - Yahoo! News
Article about a bank who suffered from an internal attack.
Regardless of whether the guy on trial is guilty or not, the numbers mentioned in this case are a good point for why internal security is something which requires a lot of attention. From the article, the defence case seems to revolve around the fact that the network had very poor security and as such there's no way to prove that it was the defendant that placed the malicious code...
the estimate is that $3.1 million was spent on repairing the damage alone and I'd guess that the loss from lost business and opportunity cost of people not being able to use systems is going to be pretty high as well.
Dark Reading - Host security - Social Engineering, the USB Way - Security
I like the idea of the trojan USB keys that the pen testing firm came up with.
given the level of success they had with this, I'd guess it won't be too long before someone who's not one of the good guys tries this as a technique...
This is another good reason to lock down USB ports on corporate machines!
SecuBat: A Web Vulnerability Scanner
Interesting looking paper which is being presented at the www2006 conference on automated web application testing.
It'll be interesting to see if they release the secubat tool they've developed as part of the work.