Handy listing of MS Vulns to bulletins
ElseNot Project ~ History of Microsoft Exploits and Security Bulletins
Link to a useful site with a list of all the publicly available exploits for a given MS bulletin.
ElseNot Project ~ History of Microsoft Exploits and Security Bulletins
Link to a useful site with a list of all the publicly available exploits for a given MS bulletin.
Perl.com: Web Testing with HTTP::Recorder
Tutorial on HTTP::Recorder module for perl. To an extent this is the functionality that you can get from webscarab or burp, but looks like it could be handy all the same...
CNET News.com's Blog 100
Cool list over at CNET of 100 top blogs (ITHO). Some interesting ones to add..
Justice versus legality - the case of Daniel Cuthbert | Samizdata.net
some coverage here of the case of Daniel Cuthbert who's been convicted of breach of the Computer Misuse Act for (if the articles I've read are accurate) putting ../../../ into a URL to see if a site he'd just given his credit card to was insecure..
I'm in two minds about this case, on the one hand he shouldn't have done that really it could be construed as an attack and he should've realised that it would trip IDS (although how quiet must they've been in the BT offices that they were investigating ever IDS alarm of that type!)
On the other hand, the Internet is a public place and websites are public resources by definition (unless they have access control configured). what concerns me is that people accessing websites in unusual ways run the risk of being prosecuted.. for example if they see a parameter in a URL and think "I'll just skip ahead by changing that by 5 instead of clicking forward 5 times" ... is that a breach of the computer misuse act..?
also it's waaay to easy to abuse this kind of thing.. how long before someone sends an email with a link which has something like "../../../" in it , causing a recipient who clicks it to appear to be a "hacker"...
Not sure either of those are great reasons, but this case does make me feel uncomfortable for some reason.
Espion automates e-mail encryption
Maybe I'm missing something here but reading this article it seems that someone's come up with an encrypted mail product that's pretty insecure... from the article
"MXLock uses two-key encryption; one of the 1,024-bit keys resides at the sender
Wired News: Nun Terrorized by Terror Watch
This is a liitle bit scary... The terrorist watch list has an AFGHANI MAN using an alias of McPhee on it... and they start stopping an AMERICAN WOMAN because her surname is McPhee.....
I actually think I can see why something like this might happen. I reckon that the culture in this environment is one where everyone is really scared of making a mistake that leads to a successful terrorist attack so they follow instructions to the letter, no matter how stupid..
The only problem is that that approach ignores the opportunity cost and allows people to avoid your checks
- if you spend loads of time with people who are not really suspects, there's less time to look for people who are...
- if you rely on stupid basic measures like surnames, then it's really easy for someone who needs to (and doesn't mind breaking the law), to avoid them...
TomsNetworking Product Reviews : TomsNetworking :
Review of a very interesting product from Airmagnet. I've used their laptop analyser product, which is great for Wireless Security Site Surveys, but the spectrum analyser is more focused on the performance site survey side of things.
V.cool to be able to track down all the sources of interference (and find the microwave in a big building!)
Following on from Marcus Ranum's piece on the six dumbest ideas in computer security which I talked about earlier there's been some chat on the CISSPforum which mentions some companies which have software which moves away from the idea of badness enumerators and more towards the idea of whitelists for allowed software...
I've not had a good chance to review the products, but sounds very interesting in concept at least.
these are the two I've seen mentioned, but I'd be interested to hear of any others....
http://bit9.com/products.html
http://www.sanasecurity.com/
Microsoft: Software Security Trendsetter?
Interesting article on Microsofts continued moved to improve the security in their new applications...
It's good stuff and I'm very happy to see the quantity of information about software security that Microsoft make available for free on their website... Hopefully will encourage windows developers in general to take software security more seriously...
Now all Microsoft need to do is allow users to not to have to install millions of lines of unnecessary code on servers (hint think Media player, Internet Explorer etc) and re-write the older legacy code that still seems to cause problems, and they'll be sorted :o)
Hacking Network Printers (Mostly HP JetDirects, but a little info on the Ricoh Savins)
Really interesting article on fun things to do with hacking HP jetdirect boxen...