Anonymity on the 'net

I've been giving some thought as to whether it's possible to be completely anonymous when connected to the 'net. Whilst I can think of obscure cases where it might be possible to track this setup, I reckon using the following list it would be next to impossible to track the user.
* Laptop with Wireless card
* bootable Linux Distro (preferrably from something like a Magazine cover disc purchased with cash). Use a different distro each time you boot.
* No persistant storage in the laptop at all (remove the hard disk)
* Change the MAC address of the Wireless and Wired Network cards on boot. Use a different one each time you boot.
* Find free wireless access, for this use something like the backnet nodes..
* use a decent gain antenna, so you can be further from the Wireless AP.
* Connect to the TOR network and direct all traffic through it.
* Don't put ANY personal information into any site
Now some of the steps there, eg, changing distro and using only magazine cover discs are only for the extremely extremely paranoid, but a basic version where you boot off the CD change the mac address connect over wireless and use TOR, would make it very difficult to tie up Internet activity to any real-world person....

HTML validation in .NET 1.1

Inside the new ValidateRequest feature
Good posting on the XSS protection features in .NET v1.1 from a developer perspective.
From the PenTesters P.O.V I reckon the most interesting bit is the comments on what fields are not run through this validation, by default...

Cool List of firefox plugins for pentesters

Firefox Extensions for Web App Testing | SecGuru
I've use some of the plugins here, mainly webdeveloper (way cool) and switchproxy (also handy). But some of them I'll have to try out on the next test....

Cool overview of XSS attacks

Commonly Asked Cross-Site Scripting Questions | SecGuru
There's a good guide to how Cross site Scripting attacks occur and some of the ways to defend against them over at secguru.
One thing I'd add, is that if you're working in a Microsoft world, using ASP.NET is a very good idea as the default config. seems to make XSS a lot harder to execute (can't remember the exact settings at the moment, ust remembering my frustration last time I had to test an asp.net site...)

Cross Site Scripting Vulnerability scanner

ScreamingCSS - Vulnerability Detector | SecGuru
Not tried this out yet but it could be quite interesting. Especially as it's written in perl, so I'll have some chance of understanding/tweaking it....

Interesting Wireless Security Development

Mobilised com au - BETTER WIRELESS SECURITY
This announcement from Intel and Cisco could be good for wireless networking security, although at the moment it does seem a touch light on detail. Of course the worry I'd have with this kind of partnership is that the parties might choose to keep their enhancements proprietary, which would not be a good thing...!
I like NAC as an idea, but I've not seen any large deployments of it yet, so I'm unsure as to whether it would be a manageable/scalable solution.

Out of date opinions...

SC Magazine
I was looking for some wireless security articles this morning and came across this one which appears to be saying that wireless networks are fundamentally insecure and therefore the answer is to run VPN's over them....
Now this might have been the only answer before 802.11i was agreed and issued, but nowadays I'd say that a possibly better alternative to running a VPN over wireless is to run a decently secured client, use multi-factor authentication with PEAP, use AES for encryption and put some decent level of firewalling in between the wired and wireless networks to restrict what can be transferred from one to the other.This way you leverege your existing investment in wireless equipment...
Of course a cynic might also have pointed out that the author of the article is Chief Technology Officer of a company who make......... wireless VPN's!

Web Site Design Template Site

Open Source Web Design - Home /^/
Remember how I mentioned that I was looking for a site template that wasn't part of a Content Management System..... Now I find it!!

Template Worm announcement

Spire Security Viewpoint: *[Adjective] Computer Worm [verb] Internet*
As homer said... "it's funny 'cause it's true"

Loong break from blogging and announcing www.isobelellis.com

Started putting stuff on here again after a long while off... have been busy doing things with Wireless networks and the like which I may get round to posting some time.
I've also been trying my hand at website design. After looking at many Content Management Systems and not really finding any that suited what I wanted (a quick simple site with content about a given subject, no forums, no news section, no logins...) I reverted to the fine art of the text editor, a book on HTML and CSS and some websites..
At the end of it is a site about Scottish Artist Isobel Ellis (or the mother-in-law as she's also known!)