Irregular Expressions


November 28, 2011  10:41 AM

Another hacking lab



Posted by: Dan O'Connor
hacking challenges

This one is by OWASP.

https://www.hacking-lab.com/index.html

I have not used it yet, I have been pretty busy for the last bit prepping for the CoBiT exam, and a few other things.  Looks like lots of fun anyway.

November 28, 2011  10:26 AM

Pastebin



Posted by: Dan O'Connor

For the last while pastebin has been the method of choice to post your evil doings.

So do you want to know if you have had a problem?

A few people have created pastebin searching apps, so you can check to see if your email address or company is listed.

Here is one,

http://www.andrewmohawk.com/pasteLert/

Another good way to watch this is with a custom Google search that will alert you, or you can go right to pastebin and do a search.


November 23, 2011  4:31 PM

Kevin Bacon was wrong all along



Posted by: Dan O'Connor

Well Frigyes Karinthy.

http://www.bbc.co.uk/news/technology-15844230

I have been working on an idea that was similar but I was thinking more of personal contact.  How it would travel between sites, say if someone sneezed on you in LA, then you fly to Vancouver then sneeze on a few more people etc…


November 21, 2011  4:52 PM

I love free learning



Posted by: Dan O'Connor

Enjoy

http://www.crypto-class.org/


November 21, 2011  4:45 PM

Manning case date



Posted by: Dan O'Connor
bradly manning, wikileaks

I just saw this come up.

http://www.bbc.co.uk/news/world-us-canada-15829284

I am not sure if he has any chance at getting out of this.


November 21, 2011  4:36 PM

The dangerous world of interconnected devices



Posted by: Dan O'Connor

It might be worth looking at devices in the sense of do we need to connect this to the internet or not?

Just throwing a device on the LAN does not cut it, why do you need to have this connected to the workstation LAN and Internet?

Build separate infrastructures, or at least VLAN it off in to it’s own network, control and monitor your access points.  Block out bound useless services, why do people need to have web access from the server VLAN?  Does your SCADA system really need to be accessible from the Internet or have access?

The point is not to “win” but to educate the stake holders so they can make an informed decision.

http://pastebin.com/Wx90LLum


November 21, 2011  4:20 PM

Well that’s interesting, and I am not clicking on those.



Posted by: Dan O'Connor
anon, anti-sec

Anti-Sec strikes again,

http://thepiratebay.org/torrent/6827936

Anon has hit a big fish.

Just remember that ToR is good, but there has been proven attacks from time to time to break it’s security.


November 21, 2011  12:55 AM

Windows 8 Bootkit to be released



Posted by: Dan O'Connor
windows 7 bootkit, windows 8 bootkit, windows bootkit

If you check out http://malcon.org/ there is a speaker lined up to release a Windows 8 bootkit.

You can see his other releases here http://www.stoned-vienna.com/ .

I would have to admit that trying to protect software is not on my list of dream jobs, it’s not easy to do.  I would even call it difficult, as you can tell by all of the pirated software you can download.


November 19, 2011  12:03 AM

Industrial data theft



Posted by: Dan O'Connor

I am not sure if this is getting worse, or if it is just being detected more.

http://www.washingtonpost.com/world/europe/security-watchdog-norwegian-energy-defense-industries-hit-by-extensive-data-theft-attack/2011/11/17/gIQAzbMKUN_story.html

This has to be both, I know this will keep happening.  I also like to think that the people defending these systems are getting better at it.  That second part might be wishful.

The whole system needs to move from reaction to prevention, we are off to a good start but there is work to do.


November 18, 2011  11:48 PM

Web Vulnerability Assesments



Posted by: Dan O'Connor

http://www.acunetix.com/vulnerability-scanner/vulnerabilityscanner8.exe

I have used this tool a few times and I really liked it.  Comparing it to some of the others I have used, it’s got a good interface just like the big boys, but not the big price tag.

It can be used by even people that know little of Web VA’s it will hold your hand through the process.