Loong break from blogging and announcing www.isobelellis.com

Started putting stuff on here again after a long while off... have been busy doing things with Wireless networks and the like which I may get round to posting some time.
I've also been trying my hand at website design. After looking at many Content Management Systems and not really finding any that suited what I wanted (a quick simple site with content about a given subject, no forums, no news section, no logins...) I reverted to the fine art of the text editor, a book on HTML and CSS and some websites..
At the end of it is a site about Scottish Artist Isobel Ellis (or the mother-in-law as she's also known!)

The eternal tradeoff... performance annd security

SSL > Banks Abandoning SSL On Home Page Log-Ins > August 23, 2005" href="http://www.informationweek.com/story/showArticle.jhtml?articleID=169600305">InformationWeek > SSL > Banks Abandoning SSL On Home Page Log-Ins > August 23, 2005
Interesting story noting that some big financial players in the US are changing their banking login pages from SSL for the whole page, to just creating an SSL session when the credentials are submitted...
The obvious point is made in the story, that this makes a Man in the Middle attack against the bank far easier as the content of the page can be modified without any pesky encryption getting in the way...

Insight into worm authors motives

Security Fix
story covering a conversation with the alleged author of the zotob worm. What's interesting from this is that his goal appears to have been to make it easy for spyware and other nasties to get installed on PC's through the modification of IE security levels...
It's a nasty attack as I bet most people wouldn't notice that the change had been made... (when was the last time you checked your IE Security Levels...)

V. Handy new IIS exploit

SecuriTeam.com ™ - IIS Information Disclosure
(NB I've not tested/run this yet so dunno if it does what it says on the tin)
Interesting looking new exploit for IIS over at securiteam... This may allow you to get access to error information on IIS6 which would be very handy when looking for SQL injection /XSS vulnerabilities...

Today's IE vulnerability ...

Security Fix
story referring to a new IE vulnerability, sounds reasonably nasty. According to the advisory here it affects XP SP2, which is interesting.
Upatched at the moment... so time to use Firefox/Opera for a while :o)

Mobile phone virii

Bluetooth adverts spark virus fears - vnunet.com
Story discussing a new advertising technique whereby content is transmitted directly to bluetooth phones, and pointing out the risks of getting users in the habit of accepting content beamed to them.
The comments from the company making the advertising mechanism are interesting. They seem to be saying it's ok because their campaigns only contain music and video and not applications, and that users should never install unrecognised applications...
To me this seems either a bit naive. If you look at the PC market, you see exploits where malicious code pretending to be music or video files can be executed due to vulnerabilities in media players. Also you're relying on users to be able to tell the difference, and spyware makers have proven very good at getting people to believe that their content is not an "unrecognised application" in order to get installed....

17799 User Group

ISO 17799 and BS7799 User Group
A useful source of information about 17799.

Mobile Phone Tracking

BBC NEWS | Technology | Tracking a suspect by mobile phone
A decent description of the ease with which people can be tracked, based on their mobile phones. In this case used to track down a terrorist suspect.
Also describes potential methods of phone tapping used by the police.

Interesting Story about DDoS attacks

How a Bookmaker and a Whiz Kid Took On an Extortionist and Won - CSO Magazine - May 2005
The story recounts the efforts of one company to resist an extortion attempt based on DDoS of the targets website. This seems to be an increasing trend at the moment, and is additional evidence that the worm and virus writers we'll be seeing in the future won't be kids looking for kudos on IRC, but professionals who view compromised systems as a resource to be used, in this case, for criminal ends.

Thought provoking post on terrorism and statistics

The Musings of Harry: Let's not loose our heads
This is a very interesting post. "Harry" has done some work looking at the number of deaths from terrorism as opposed to other causes, in the UK and asks some questions about the level of emphasis and spending on those topics.
It's pretty obvious that a lot of this is based on the shock effect and media coverage. If you take heart disease as an example.. what sort of coverage do the 110,000 people who died in the UK of preventable heart disease, get... compared with the coverage of the London bombings...
Also if you think about it, if the governments goal was preventing the deaths of UK citizens, would they not be better legislating to ban (not just get rid of direct advertising for) unhealthy foods and cigarettes, instead of passing legislation which has a dubious effect, at best, on terrorism....