Real Interesting Post: Microsoft in trouble?

christopher baus dot net
This is a really interesting post covering why the author thinks microsoft is in trouble. There's a lot in it I agree with. Definately Microsoft's current attitude to parts of the developer community (VB6 in particular) seems likely to drive people to the competition...
However I see Microsofts problem, from a security standpoint one the of their major problems is having to maintain backwards compatibility, for example Windows Server 2003 has many improvements to security, which are partially neutralised if you have to run it in backwards compatibility mode (eg, using LM/NTLM for NT4 compatibility).
That said Microsoft doesn't always help themselves from a security point of view... as is mentioned in the article they deploy a MEDIA PLAYER and a POP3 Client by default on their SERVER OS!!! That's just crazy, especially when those components start having critical vulnerabilities . Can you imagine a large enterprise having to deploy a patch to thousands of servers because the media player which will probably never run on any of them needs a patch!
ok this is turning into a bit of a rant, but that is a pet hate of mine... onto one other thought I have about this, which is.. how Microsoft may intend to save themselves (not saying I have some prescient knowledge of their strategy, but this does seem to fit current facts)
It's easy, force people to run your products because all your documents songs movies etc, will only play on those products and use DRM technology so that the content is encrypted such that there's no way for competitors to, legally, access it... Simple and if Microsoft pulls it off, I'm not actually sure how you'd stop them. If the majority of the media out there gets into encrpyted DRM protected Microsoft proprietary formats, it will really stuff the competition...

More Pen Test Resources

Professional Security Testers resources warehouse
More info on Pen testing. Especially on this site, there's a good link section.

Handy list of Security Whitepapers

White Papers - Web Application Security Consortium

Gmail File System

Gmail Filesystem
Not that I'd ever want to rely on this for any data I cared about, but it's a really interesting idea and at current rates with the ~150 invites I've got access to I could create a 300GB filesystem all stored in gmail.......

Mac OSX security site

[ hardening your macintosh ]
Looks like this site has loads of good information on Mac OSX security including stuff regarding Pen testing OSX machines...

unicornscan - fast port scanner...

Unicornscan
Interesting sounding port scanner to try out.

Alternate data streams

SecurityFocus HOME Infocus: Windows NTFS Alternate Data Streams
A good security article at securityfocus.com covering Alternate data streams in windows. There are 2 tools mentioned in the article which I think are well worth using, either on a periodic basis as a audit tool, or on a machine which you think may have been compromised.....

Security Forest... now here's interesting

Main Page - SecurityForest
Now this is interesting, I've not had the chance to download/look at the software from the site but it claims to be similar to metasploit but with far more exploits.....
Which would be cool. one to look at anyway...

Another good example of social engineering

Ask me no secrets and I'll tell you no lies
A write up at Arstechnica of another successful social engineering excercise in London.... of course there's the usual point about how much of the information gathered is actually accurate, but I think it's still a good example of why humans can, in many cases, be the weak link in a security solution.

publicly available FTP web interface

Surftp - Web Based FTP
handy site for accessing FTP sites from locations where you only have HTTP access. Of course, if you're paranoid like me then you wouldn't trust this service to transfer any sensitive data in the clear, as while they say they won't use any of the info. gained there's nothing to guarantee that..... (not that I'm implying they will, I'm just paranoid !!)