- "You may be familiar with the Emerging Threats project. They have a few Snort rules files related to known web application vulnerabilities and attacks: * emerging-web_server.rules * emerging-web_specific_apps.rules"
- "In a statement issued on Friday, Oracle announced that it intends to discontinue commercial development of the OpenOffice.org (OOo) office suite. The move comes several months after key members of the OOo community and a number of major corporate contributors forked OOo to create a vendor-neutral alternative."
- "It was a long but wonderful day! I woke up very early to catch my train from Brussels to London and arrived just in time. The room was already full of security guys, some well known faces and new ones. Let’s grab some coffee, some muffins and my bag full of goodies. Ready for the talks! The venue is nice, there is a good Wi-Fi coverage."
- "Being a property owner can be a massive headache. You end up spending thousands to protect what's yours – securing doors, windows, and every other feasible point of entry. Yet all a criminal needs is one shot – a misplaced key, say – and he is in."
Random thoughts on software development, information security, life, and any kind of (un)interesting things.
Showing posts with label daily links. Show all posts
Showing posts with label daily links. Show all posts
Friday, April 22, 2011
Daily links for 04/21/2011
Wednesday, April 20, 2011
Daily links for 04/20/2011
- "Most developers actually want to write secure code"
- "Today at Where 2.0 Pete Warden and I will announce the discovery that your iPhone, and your 3G iPad, is regularly recording the position of your device into a hidden file. Ever since iOS 4 arrived, your device has been storing a long list of locations and time stamps. We're not sure why Apple is gathering this data, but it's clearly intentional, as the database is being restored across backups, and even device migrations. "
- "Why people fail in the hiring process… by doing stupid things! Some things that I tell you NOT to do, might be what your future employer wants… it’s not easy to define."
Tuesday, April 19, 2011
Daily links for 04/19/2011
- "It’s here! Data junkies rejoice! Today we’re proud to release the third volume of our semi-annual State of Software Security report. This edition incorporates data from 4,835 applications analyzed via our cloud-based platform over the past 18 months."
- "OMG, today is The Breach Day, an official security holiday. Verizon Business has just released their super-famous “2011 Data Breach Investigations Report”"
- "This winter, the Internet passed a major milestone in its twenty-year-old wunderkind evolution from a small, experimental research network to one of the technical foundations of modern society. In a brief Miami hotel conference room ceremony, ICANN allocated the last five IPv4 address blocks on February 3 — the long anticipated endgame towards eventual Internet address space exhaustion was officially underway [1]."
Monday, April 18, 2011
Daily links for 04/18/2011
- "The Tangled Web is my second book, and a lovingly crafted guide to the world of browser security. This is an overcrowded market, but there are two reasons why you may want to care. "
Thursday, April 14, 2011
Daily links for 04/14/2011
- "Welcome to the cvechecker tool homepage. The goal of cvechecker is to report about possible vulnerabilities on your system, by scanning the installed software and matching the results with the CVE database."
- "In the tablet world right now, there’s the iPad and then there’s everyone else. Sorry, Xoom, despite your hype, you just don’t cut it yet. But a new challenger is just about to take the stage and it comes from a somewhat unlikely player: RIM."
Wednesday, April 13, 2011
Daily links for 04/13/2011
- "The company that maintains the WordPress.com blogging platform said hackers gained root access to its servers and made off with sensitive code belonging to it and its partners."
- "Content Security Policy (CSP) is an added layer of security that helps to detect and mitigate certain types of attacks, including Cross Site Scripting (XSS) and data injection attacks. These attacks are used for everything from data theft to site defacement or distribution of malware."
- "Cloud computing has quickly evolved from a hot industry buzz word into a multi-billion dollar emerging market, with all the big names striving to grab a piece of the pie. Amazon, with its Amazon Elastic Computer Cloud (EC2), is arguably the dominant leader of the cloud services market."
Tuesday, April 12, 2011
Daily links for 04/12/2011
- "I can't be the only nostalgic nerd to feel a flutter of excitement at the news that a home computer from yesteryear is making a comeback."
- "Exactly one year ago, we launched a new version of the Google document editor, created from the ground up to take advantage of the latest capabilities in modern web browsers like Chrome. In particular, we baked in a way of supporting text features that aren’t natively included with browsers—for example, we added a ruler for controlling the margins, text that wraps around images to create eye-catching docs and discussions for a more collaborative editing experience."
- "There is a surprising number of title variations among people who work in the field that I call “information security.” I browsed through various job-search sites to get a feel for the more frequently-seen titles and created a random information security job title generator. "
Monday, April 11, 2011
Daily links for 04/11/2011
- "sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. "
- "Google has announced recently three new updates to Android’s enterprise management capabilities. This is specially developed around security and connecting with colleagues and will be available to business and education Android Applications."
Friday, April 8, 2011
Daily links for 04/08/2011
- "In announcing its cloud computing services on Thursday, IBM stressed repeatedly that private clouds -- or those that exist behind the corporate firewall -- are as important to its strategy as those in the public realm. "
- "After a few months of back and forth, the first stage of our HTTP Header research is now live on the Shodan website."
- "LinkedIn, the professional social network, has finally launched its Android App."
Thursday, April 7, 2011
Daily links for 04/07/2011
- "IBM Internet Security Systems (ISS) provides security content updates for supported products through the X-Press Update feature. IBM ISS recommends installing the latest update to ensure your products are current and your protection is maximized. "
- "The Internet Systems Consortium (ISC), a non-profit company which develops BIND and dhcpd/dhclient, has announced a new remote code execution vulnerability present in its dhclient software."
Wednesday, April 6, 2011
Daily links for 04/06/2011
- "This is a follow-up post to ModSecurity Advanced Topic of the Week: Malware Link Detection in which we will highlight a new capability within ModSecurity v2.6 that allows for removal of data within response bodies."
- "As anyone who has watched the reimagined Battlestar Galactica will tell you, Sixes are trouble. They are undoubtedly alluring, but all the while they are working covertly, following The Plan, right under the noses of their targets. Nobody realizes the true nature of the threat until it’s too late."
- "An article in the Wall Street Journal, dated April 5, 2011, disclosed that Federal prosecutors in New Jersey are investigating numerous smart phone application manufacturers for allegedly, illegally obtaining and distributing personal private information to third party advertisement groups."
Tuesday, April 5, 2011
Daily links for 04/05/2011
- "More and more of today's web application attacks are leveraging multiple weaknesses, vulnerabilities and attack methods in order to achieve a desired exploitation outcome. It is becoming more and more difficult to neatly place an attack into one specific container (such as XSS, SQL Injection, etc...). These are blended attacks."
- "Successful Attacks from Automated Malware"
- "The software that helped IBM's Watson computer reign victorious on the Jeopardy game show in February could also help the financial industry assess risk more effectively, a pair of IBM executives stated on Monday at a high-performance computing conference. "
Friday, April 1, 2011
Daily links for 04/01/2011
- Over the last few days we have been tracking a mass SQL injection attack that was first blogged by Websense On March 29th, These types of threats are nothing new to us in IBM Managed Security Services as we’ve been tracking similar attacks for years.
- Passwords from over 3,000,000 user accounts were apparently set to "password" late last night in a wide-spread hack that affected hundreds of news, retail and web 2.0 sites. Most affected users are completely unaware of the attack.
Daily links for 03/31/2011
- IBM today released results from its annual X-Force 2010 Trend and Risk Report, highlighting that public and private organizations around the world faced increasingly sophisticated, customized IT security threats in 2010.
- DroidWall - Android Firewall is a front-end application for the powerful iptables Linux firewall. It allows you to restrict which applications are permitted to access your data networks (2G/3G and/or Wi-Fi).
Wednesday, March 30, 2011
Daily links for 03/30/2011
- A massive SQL Injection campaign, similar to ones seen in the past, has hit nearly 50,000 domains across the Web, including a handful of iTunes URLs. The attacking domain, lizamoon.com, is currently offline but the server hosting it remains active. Before it disappeared, the injected domain was pointing users to Rogue anti-Virus applications.
Tuesday, March 29, 2011
Daily links for 03/29/2011
- We often have requests on mobile malware statistics and although statistics are only an imperfect representation of reality, this is what we can share.
- Today, as every ordinary Monday, I went to my e-mail box and checked messages from the security community in Full-Disclosure. As usual I came across an advisory pointing out some web security vulnerabilities that differently from usual certainly had my attention.
- Some users, when flashing new ROMs, have noticed that their battery life goes down a little bit. With just a simple wipe of the battery stats file, though, you can get your battery back up and running to its full capacity.
- Google (NASDAQ:GOOG) has snapped up James Gosling who invented the Java programming language while at Sun Microsystems.
- For anyone sketched out by the privacy implications of Color, the highly hyped, highly funded, and highly public iOS and Android social media app that launched last week, now would be a good time to ratchet your creep-o-meter up another notch or two.
- Who controlled the Rustock botnet? The question remains unanswered: Microsoft’s recent takedown of the world’s largest spam engine offered tantalizing new clues to the identity and earnings of the Rustock botmasters.
Monday, March 28, 2011
Daily links for 03/28/2011
- Please excuse my profanity, but I could think of nothing else to title this article. According to Adam Nason of BeerNews.org, Anheuser-Busch, Inc. will buy Goose Island Beer Company and brewmaster Greg Hall is stepping down.
- Privacy Blocker is an Android application that stops other installed applications from gathering your personal information.
- Proving that no website is ever truly secure, it is being reported that MySQL.com has succumbed to a SQL injection attack.
Friday, March 25, 2011
Daily links for 03/25/2011
- How to Practice Your Web Application Testing Skill... - HP Software Solutions Community online forumFor those who are learning web application security testing (or just trying to stay sharp) it's often difficult to find quality websites to test one's skills. There are a few scattered around the Internet (see the link in the notes section below) but it would be nice to have a solid collection of test sites all in one place.
- If you interact with the social media world at all, you know what an immense opportunity there is to gather, analyze, and act on all the great data floating around.
- Although the Firefox team has an entire page on the mozilla.com website dedicated to the new security features in Firefox 4, they seem to have forgotten to mention HTTP Strict Transport Security (HSTS).
- GIAC is launching a new certification for developers and application security professionals involved in defending web applications.
- In the great mobile-device wars, Google (GOOG) has portrayed itself as the open-source crusader doing battle against the leaders in proprietary software—Apple (AAPL), Microsoft (MSFT), and Research In Motion (RIM:CN).
- Apple’s iPad is just one year old, and more than 15 million customers have voted with their wallets. The tablet is officially mainstream.
Thursday, March 24, 2011
Daily links for 03/24/2011
- When conducting a pen-test, the process typically starts with the reconnaissance phase, the process of gathering information about your target(s) system, organization or person. Today, we want to present a tool that can be added to your reconnaissance toolkit.
- Behold the new HP. After a series of scandals, a change in CEOs and a rebuilding of its board, the tech giant revealed the new HP to the world: It's still very much a company that wants to be another company -- IBM.
- The Dalvik runtime may be garbage-collected, but that doesn't mean you can ignore memory management. You should be especially mindful of memory usage on mobile devices, where memory is more constrained.
- This morning at CTIA 2011, Samsung brought us a revised Galaxy Tab 10.1″ that has beat out the iPad 2 in its thinness and light weight specs. This of course brings to question how long does your tech stay current these days?
Wednesday, March 23, 2011
Daily links for 03/23/2011
- Today, RIM began taking advance orders on its new tablet. The first Playbook will connect to the internet via Wi-Fi and, at $499, will compete on price with the iPad.
- McAfee announced this morning its intention to acquire Sentrigo, a Database Activity Monitoring company. McAfee has had a partnership with Sentrigo for a couple years, and both companies have cooperatively sold the Sentrigo solution and developed high-level integration with McAfee’s security management software.
Subscribe to:
Posts (Atom)