- French privacy watchdogs have hit Google with its very first fine for allowing its Street View cars to snoop on citizens' Wi-Fi data.
- Iron Brussels Beer Marathon
- The world's biggest maker of data storage computers on Thursday said that its security division has been hacked, and that the intruders compromised a widely used technology for preventing computer break-ins.
- BlackHat Europe 2011 / Day 02
Random thoughts on software development, information security, life, and any kind of (un)interesting things.
Monday, March 21, 2011
Daily links for 03/21/2011
Friday, March 18, 2011
Daily links for 03/18/2011
- After 15 years of managing cybersecurity programs and performing IT security engineering functions, Richard Tychansky, an information assurance engineer at Lockheed Martin Corp, finds his role transforming.
- So, as promised in yesterdays preview, what follows is the report of my first day at Black Hat Europe 2011.
Thursday, March 17, 2011
Daily links for 03/17/2011
- Late last week, foursquare launched an entirely revamped platform for businesses. It opens up lots of new options for creating specials and makes the process of creating specials easier to manage, especially for companies with multiple locations.
- When your computer is running a little bit slowly, how can you tell if getting more memory will help you? Here is a simple way to check whether all the RAM you have in your mac is being used. It works for any macintosh running OS X – G4, G5 or intel macs.
- Today’s interview is with SMS smartphone researcher Georgia Weidman. Georgia is is currently Director of “Cyberwarface” at Reverse Space and resident videographer at NoVa Hackers. Oh and then there is that full time day job thing.
- If you have not yet deployed FIM perhaps now is a good time to ask “why not”. If your organization is now addressing data loss prevention (DLP) by minimizing the risk of damage by malicious code and by enforcing strict access controls to mitigate unauthorized access, then FIM is something you might also want to consider.
- Dr. Charlie Miller says the Pwn2Own event is managed in a way that has dangerous exploits "left over"
- One of the biggest changes we made to Android in this release is the addition of a new rendering pipeline so that applications can benefit from hardware accelerated 2D graphics.
- a Code Swarm done for the Metasploit framework SVN trunk from the past 5 years, kinda neat to watch ^_^ enjoy.
Tuesday, March 15, 2011
Daily links for 03/15/2011
- F-Secure has apologised about a bug in its consumer-focused Mac security software that left surfers fighting against their own browsers as clean files were wrongly classified as malign.
- Whether you're an employee, leader, or entrepreneur, personal credibility is truly a "magic bullet" for success. It's simple: if you have no credibility, people won't trust you.
- With Android Applications flooding the Android Eco system, AppBrain, has introduced AppBrain Android Stats. Android Developers can view the Android Market, Android Phones, and AppBrain usage.
- As the first in an ongoing series of interviews, we got recent Pwn2Own winner Charlie Miller to answer a few questions and pull back the curtain a bit on the methods, tools and motivation for the research he does discovering security exploits.
Monday, March 14, 2011
Daily links for 03/14/2011
- Mnemonic gives 167 digits of famous geometric constant
- It is with great pleasure that we officially announce the release of the first NetBSD Amazon Images for the Amazon Elastic Compute Cloud (better known as Amazon EC2) for all currently available regions: US East (Northern Virginia), US West (Northern California), EU (Ireland), Asia Pacific (Singapore), and Asia Pacific (Tokyo).
Want to get your Plancast plans to show up in your Google Calendar?
Want to get your Plancast plans to show up in your Google Calendar? It's not that hard. It's actually a few clicks away.
- Go to your Plancast.com profile (http://plancast.com/
/). - In the "Export these Plans" section, click on the "Calendar Feed" link, a window will pop-up.
- Select the "Google" link, obviously, and follow the instructions on how to add that to your Google Calendar.
Friday, March 11, 2011
Daily links for 03/11/2011
- Microsoft says the vulnerability used by researcher Stephen Fewer to exploit Internet Explorer 8 has already been fixed in the RC and RTM versions of Internet Explorer 9.
- How can we use fun as a motivator for changing the behavior of computer users to improve information security?
- Atom is a great way of keeping track of the latest news and content published by your favourite websites as it allows individuals to control which news updates, blogs, articles, forums etc they keep up to date with.
- Research in Motion’s recent decision to add a WebKit browser to BlackBerry has immediately backfired.
- Charlie Miller kept his Pwn2Own winning streak intact with another successful hack of an Apple product.
Thursday, March 10, 2011
Daily links for 03/10/2011
- Here are a few observations regarding some browsers and their SSL/TLS implementations.
- A pair of security researchers from Germany demonstrated several techniques at the CanSecWest conference here Wednesday that enable them to remotely reboot, shut down or even completely disable many popular mobile phones with SMS messages.
- When the Pwn2Own contest began in 2007, it was dismissed by some in the industry as nothing more than a publicity stunt meant to inflate the egos of researchers while embarrassing software vendors
- A team of security researchers from the French pen-testing firm VUPEN successfully exploited a zero-day flaw in Apple’s Safari browser to win this year’s Pwn2Own hacker challenge.
- Using three different vulnerabilities and clever exploitation techniques, Irish security researcher Stephen Fewer successfully hacked into a 64-bit Windows 7 (SP1) running Internet Explorer 8 to win this year’s CanSecWest hacker challenge.
Wednesday, March 9, 2011
Daily links for 03/09/2011
- he reasons that Android phones are either slow to get system updates, or fail to get them entirely are pretty clear. The process of getting an update ready to push to a handset is decidedly non-trivial
- The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.
- It was almost exactly two years today that Naveen and I flipped the switch on foursquare, jumped on a plane to Austin and introduced the folks at SXSW 2009 to our idea of “turning life into a game
Monday, March 7, 2011
Daily links for 03/07/2011
- Google is always looking for new ways to make it easier for developers to get started with our APIs. When you come across a new Google API, you often want to try it out without investing too much time. With that in mind, we are happy to announce the Google APIs Explorer, an interactive tool that lets you easily try out Google APIs right from your browser.
- The actual vulnerability was an incredibly low-hanging naive persistent XSS in the Android web market. When posting an Android application through the publishing interface, there’s a description field for you to describe your application
- A vulnerability that a researcher planned to use to compromise an Android cellphone at a hacking contest later this week got squashed after Google fixed the underlying bug in the Android Market.
- During the latest Apple Special Event of March 2011, Apple CEO Steve Jobs announced new features and products. One of those masterpieces is a new option called “Personal Hotspot”. This new functionality transforms your iPhone into a Wireless Access Point, so that you can share your 3G connections. This will be released in few days with the next iPhone update (iOS 4.3).
Friday, March 4, 2011
Daily links for 03/04/2011
- If you paid attention to the news this week, you'll know that there were a bunch of Android apps pulled from the Android Market because they contained malware. There were over 50 infected applications - these apps were copies of "legitimate" apps from legitimate publishers that were modified to include two root exploits and a rogue application downloader.
- Welcome to the Penetration Testing Execution Standard homepage. This will be the ultimate home for the penetration testing execution standard.
- We are pretty busy these days with malicious samples on Android. You probably haven’t missed DroidDream (Android/DrdDream.A!tr) which trojaned several applications on the Android Market and several blog posts on the matter
Wednesday, March 2, 2011
Daily links for 03/02/2011
- As part of our continuous efforts to help our users protect their information, we recently launched 2-step verification for all Google accounts. Starting March 14, we will also increase the minimum password length requirement for Google Apps accounts from 6 characters to 8.
- Google has just pulled 21 popular free apps from the Android Market. According to the company, the apps are malware aimed at getting root access to the user's device, gathering a wide range of available data, and downloading more code to it without the user's knowledge.
- Every day, we see more reports about malware in the Android Market. This time three developers known as MYOURNET, Kingmall2010, and we20090202, possibly the same person, were offering a number of Android apps for free download.
- A new IBM report found that more than 70 percent of organizations are allowing nontraditional endpoint devices -- think smartphones, iPads, and point-of-sale devices -- to connect to their corporate networks, but some 36 percent say these devices aren't properly secured.
Tuesday, March 1, 2011
Daily links for 03/01/2011
- Apple last week introduced a new line of MacBook Pros. Chief among the improvements was the introduction of Thunderbolt, the name Apple bestowed upon Intel’s Light Peak transfer technology that can impressively transfer data at 10 Gbps both up and down.
- Imagine the sinking feeling of logging in to your Gmail account and finding it empty. That’s what happened to 0.02% of Gmail users yesterday, and we’re very sorry.
- Intel announced the acquisition of McAfee is complete.
Monday, February 28, 2011
Daily links for 02/28/2011
- For as much as Mac OS X has a reputation for being safer than Windows, security researchers won’t hesitate to point out that the opposite is, in fact, true. Indeed, the primary reason why the Mac has been relatively immune from security threats often found on Windows is because the Mac’s relatively paltry market share makes it an unattractive target for malicious hackers.
- When an application fails to perform as expected, the network is often the first thing blamed. I suppose this is because end users typically view the network as the sole limiting factor with regard to throughput, unaware of the intricacies of application, database, and storage performance.
Thursday, February 24, 2011
Daily links for 02/24/2011
- As a second-generation Indian who has grown up in the United States, I’ve developed a taste for great home-cooked Indian food, but not a knack for how to make it. Somehow my cooking efforts result in foods that taste over-spiced yet bland at the same time. My parents follow the art of cooking by intuition, where the right amount of each spice is measured out by gut feel, but that’s never worked very well for me.
- Yep, I’m the Bastard Security Officer From Hell.
Wednesday, February 23, 2011
Daily links for 02/23/2011
- One of the most under-appreciated capabilities of web application firewalls (WAFs) is traffic monitoring and analysis. Due to the fact that WAFs have access to the full inbound request and outbound response payloads, they are able to glean valuable insight into vulnerabilities and configuration issues such as missing HttpOnly or Secure cookie flags, etc...
- As a web developer you’re always told you need to keep up to date on the latest and greatest technologies. Usually this is for creating applications which can take advantage of new technologies to deliver a better experience to your users. However, I think there is another angle to this, in particular; Code Rot.
- Thanks to the hard work of Anders "Ragge" Magnusson and his team plus the help of donors from around the world, the Portable C Compiler is now ready for final beta testing in preparation for its 1.0 release.
- We are pleased to announce that the full SDK for Android 3.0 is now available to developers. The APIs are final, and you can now develop apps targeting this new platform and publish them to Android Market. The new API level is 11.
Daily links for 02/19/2011 - 02/22/2011
- Citicus MoCA is a new, free risk management application for the iPhone, iPad or iPod touch. It provides a simple way for decision-makers to identify the business impact of their organization's assets and processes being disrupted.
- Security researchers have set up a site designed to prod social networking websites into practising what they preach about web security.
- SAN FRANCISCO, CA and ATLANTA, GA--(Marketwire - February 15, 2011) - RSA Conference, Booth # 2754 -- ipTrust, a leading provider of security intelligence as a service, is announcing a partnership with IBM to integrate ipTrust's reputation analytics into IBM Managed Security Services.
- First Meeting of IPv6 Council Location:UCL Campus of Woluwe-St-Lambert Date: 16 of February 2011.
Wednesday, February 16, 2011
Daily links for 02/15/2011
- SAN FRANCISCO, Feb. 15, 2011 /PRNewswire/ -- In an effort to help clients proactively identify and prevent potential threats to their organization, IBM (NYSE: IBM) today at the RSA Conference introduced the industry's fastest and most comprehensive network security appliance.
- This post documents an XSS vulnerability that I discovered in the default Gmail app (v1.3) provided by Google in Android 2.1 and prior.
Monday, February 14, 2011
Daily links for 02/14/2011
- Qualys announced IronBee, a new open source project to provide the next-generation of web application firewall (WAF) technology.
- This year at RSA 2011 the conference has made things a little easier. Rather than lugging around a large printed schedule (which they still provide) they now have an app.
Thursday, February 10, 2011
Daily links for 02/10/2011
- Google just launched two-step verification for all Google accounts, a system which makes your Google/Gmail account—the account possibly containing the lion's share of your private communication online—considerably more secure.
- Chris Hadnagy gets paid to fool people, and he's gotten pretty good at it over the years. A co-founder of social-engineering.org and author of Social Engineering: The Art of Human Hacking, Hadnagy has been using manipulation tactics for more than a decade to show clients how criminals get inside information.
Wednesday, February 9, 2011
Daily links for 02/09/2011
- Short? HP has a winner that other players MUST consider now.
- Here is another new release from the Project: a release of a new tool called PhoneyC, a virtual client honeypot.
- It's an "important, non-security update" that restricts "AutoRun entries in the AutoPlay dialog to only CD and DVD drives".
- If you are involved in vulnerability research, reverse engineering or penetration testing, I suggest to try out the Python programming language. It has a rich set of useful libraries and programs. This page lists some of them.
- Bluepot is a Bluetooth Honeypot written in Java, it runs on Linux.
- The venture capital arm of web search giant Google has joined the latest round of funding for Dasient, a Web security start-up founded by a pair of ex-Googlers.
Tuesday, February 8, 2011
Daily links for 02/08/2011
- Safer Internet Day is organised by Insafe each year in February to promote safer and more responsible use of online technology and mobile phones, especially amongst children and young people across the world.
Subscribe to:
Posts (Atom)