Showing posts with label blogs. Show all posts
Showing posts with label blogs. Show all posts

2010-03-11

The end of an era: SecurityFocus

SecurityFocus announced in a memo yesterday that it would, for the most part, cease operations.


It is survived by Bugtraq (which SecurityFocus picked up more than a decade ago) and a few other high-volume mailing lists. In turn, SecurityFocus was picked up by Symantec in 2002. This is a sad day, indeed.

2009-01-06

MacRumorsLive Hacked?

Click for high-res:


Yesterday, it was Twitter's admin tools (potentially by Digital Gangster members according to PC World) and today, MacRumors' to-the-second outlet for live events, MacRumorsLive.com bites the dust. 4Chan's /g/ board is mentioned but it's unclear if they have anything to do with the attack directly. Both MacRumors and Live are currently down (in a redirect loop) as of writing.

[Hat-Tip: Dangerboy]

2008-11-21

Security Bloggers Network is back online

SBN is now powered by lijit networks. Here's the RSS Feed for SBN as well.

As of right now, Security Bloggers Network is the combined buzz of about 180 different blogs, all of which have at least partial focus on information security. Drop it into your RSS aggregator and start getting fed.

Update: Security4All has pointed out that the SBN site and feed aren't working right now. They were a bit ago. Keep your eyes on the links. It'll probably be back this weekend.

Okay, looks like it's online at www.securitybloggers.net now.

2008-11-14

R.I.P. Security Bloggers Network (for now)

Alan Shimel just reported that Feedburner networks are going the way of the Dodo, and the beloved Security Bloggers Network RSS feed on FeedBurner is no more.

For those who don't know what SBN was, it was a huge RSS feed with some great security blogs all rolled into one. Drop it into Google Reader or something, and you were all set. HiR just recently got on board. Too bad it had to happen this way.

Don't worry, though. Shimel assures us that there will be another, comparable spliced RSS feed coming soon. Until then, if you were watching the Security Bloggers Network, you might want to start hunting down links for your favorite reads. If you have some favorite information security sites, feel free to post links to them, or a link to an OPML file.

2008-10-25

Where Are They Now: Quentin Stafford-Fraser

I've looked up to a lot of people in my day, and sometime in the middle of 1998, I was really looking up to the guys at the Olivetti & Oracle Research Laboratory (ORL for short) because they made something that at the time I considered truly groundbreaking and now, more than a decade later, I can't see living without it. If you've been around a while (or you're paying attention to my coffee mug in the photo) you may have guessed I'm talking about VNC, which now has quite a few forks, most of which surprisingly play very nicely with one another.

In 1998, I actually wrote an article about VNC in HiR's old text-zine format. Shortly after that, AT&T Swooped in and bought ORL. I contacted the team to ask if they had any of the cool VNC Mugs I saw on their Windows CE page (Archived here) and I actually was told by the team that "they shouldn't, because they had the old contact information on them" but they shipped me a pair of them anyways. Now, some 9 years later they're still some of my favorite mugs from which to quaff my morning coffee: I've got one at work and one at home.

QSF wasn't the sole inventor of VNC, but he put quite a bit of work into it and was one of the authors of the initial VNC whitepaper, first published in IEEE Internet Computing. When poring through mailing lists in my early days of using FreeBSD and OpenBSD on the desktop, I'd often run into QSF's helpful tips when dealing with compiling or troubleshooting issues.

QSF's also one of the creators behind first Internet meme I ever experienced (in early '94): the coffee-pot web-cam.

A few months ago, Frogman pointed me to Status-Q, QSF's blog (via shared articles in Google Reader) and I must say I've been hooked ever since. His blog content offers little in the way of what he's up to for a living these days (hint: the About Quentin link has those details), but it's full of sage advice, useful quotes, and fascinating observations. I'm happy to have run into him again!

The entire team of VNC people were and are, in my opinion, "real hackers" and visionaries. They might not be penetration testers or security researchers. They're certainly anything but cyber-terrorists. The team saw a need, filled it elegantly, and built something extensible and open-source that to this day is relied on by more people than I could count.

2008-10-17

Response: "Is Twitter the newest data security threat?"

Lori MacVittie posted a compelling piece asking "Is Twitter the newest data security threat?"

In my opinion, the answer is "No." It's merely one of tens of thousands of potential avenues of exploitation that can be used intentionally or unintentionally by the real security threat: Those whom you trust to access your data in the first place.

Data Loss Prevention suites, Network Access Control, filtering web proxies and other technological solutions are only masking the problem while making it harder for your employees to work efficiently. Michael J. Santarcangelo, II's book, Into The Breach concisely discusses the real problem behind breaches and a sound Strategy to make it better. It takes everything we already acknowledge as security professionals and re-arranges it in a way that makes a lot of sense.

In short, security researchers, employers, and journalists need to wake up. Use technology to assist properly-trained employees who are held accountable for their mistakes instead of using technology to restrict clueless employees, and allowing the blame to fall on some software package when things go wrong. When do you start ACTUALLY trusting the people you trust with your data?

The issue of customer service via Twitter is a different bag of worms. The decision to use twitter as an enterprise avenue of support is a strategic decision that's better left to marketing, PR and CxO-types. I'd hope they'd analyze the potential impact of making a subset of their customer list public.

2008-08-29

Ye-Olde Tech: 8- and 16-bit video game music!


Local geek and friend of HiR, (jeff)isageek threw me a serious curve-ball today. 8-bit music. I used to totally dig Module Music and had a pretty serious archive of it somewhere. It's probably still around on floppy disks somewhere. I also really enjoyed some of the lo-fi tunes that came out of arcade cabinets and olde-school game consoles.

I can't contain my joy. I can't stream music at work, but as I write this, I'm recording as much of it as I can to my MiniDisc recorder!

2008-08-14

Weekly Technolust! Hak.5 Joins Revision3

Our buddies over at Hak.5 have some celebrating to do. It's confirmed that Darren Kitchen is going to start cranking up the Technolust with the help of Revision3, according to a press release issued this afternoon

The hints have been in the air for a while now. When I drove out to destroy my windshield hang out with Darren, it sounded like there might be something going on with Rev3. Going from monthly production to weekly is a huge step. I know I'll be sure to tune in! With Hak.5's wits and the production and distribution skills of Revision3, I really don't see how this partnership will be anything less than a home run.

Congrats, guys!

2008-07-30

H.D. Moore: Punk't, not pwned.

Oh, how we love drama, and there's plenty of drama in the world of information security.

As you've probably figured out by now, Dan Kaminsky's report of a DNS static source port bug (and the simple exploitation of the same) has fueled a considerable source of recent controversy and drama. Shortly after details hit the security blogs, H.D. Moore (author of Metasploit) and |)ruid put together some checks for the vulnerability. Even yesterday, he released a third Metasploit plugin to check between two different DNS servers in an attempt to detect poisoning.

A few days ago, HD stumbled across a DNS server "in the wild" which had been poisoned to redirect all Google traffic to a batch of rogue sites meant to monetize google ads by automatically clicking them in hidden iframes. After discussing this DNS server in the wild with a reporter for IDG News Service, the reporter went on to write a piece (which is not worth linking to) blatantly stating that BreakingPoint Systems (where H.D. serves as Director of Security Research) was "owned", when there was no such pwnage.

A second article was published which clarified some points, but the original article is being linked to like mad on some social news sites, and it hasn't been edited yet as of the time of writing here.

For H.D.'s side of the story, check out his post on the Metasploit Blog.

2008-07-25

Friday Geek-Out: July 25, 2008 and upcoming KC gatherings

I showed up a bit early to the Geek-Out. So did (jeff)isageek. We've been gabbing about podcasting, blogging and random geekery. I don't know how long Jeff's hanging out, but I'll be here probably until well after midnight. If you see this before then (and if you're near Overland Park, KS), come on out! We're at Daily Dose!

I'm pondering the usefulness of a full-on laptop while I'm at DefCon. I may try making do with only the Jornada 720 and jLime Linux. I probably won't have my digital camera with me (I loaned it out to a good friend who is currently on a road trip) but I can mobile blog with my cell phone and its camera. For the essentials, the Jornada should do everything else I really need. Here, I have BrightKite and GMail up on Minimo in the background and the Hak.5 IRC channel in a terminal window with irssi. It's surprisingly responsive and dare I say peppy. Peppy enough that I might not need a real laptop on the convention floor.



Next Friday is 2600 Night. We meet in the food court at Oak Park Mall in Overland Park, KS and then afterwards get a bite to eat. We wrap things up with a late-night Geek-Out at the Dose where you can pick your poison of uppers (caffeine) or downers (get your beer and cocktails on!).

No Friday Geek-Out on the 8th, because we'll all be at DefCon, hopefully!

See you around!

2008-04-21

Who's down for a trip to Springfield, MO this weekend?

Midwest-region hackers.

Darren
from Hak5 will be kicking it in Springfield, MO this weekend (April 24-29th, actually) and I'm planning on heading down there to hang out, get a few drinks, and what have you. Drop a comment and I'll try to get more info to you.

2008-04-09

Shell script for Flickr/Blogger Goodness

Embed your Flickr images into blogger while linking to their page (as opposed to just the image itself). Like this (not my image, just an interesting one I found):



Just edit the flickrbase url in the script, and enjoy. Run the script with the image URL in the command-line, and it gives you the HTML to paste into blogger.

Note, this won't link to other peoples' flickr pages as-is, nor can it tell you the username for any given flickr image. If you want to embed someone else's flickr images, you'll need to edit the flickrbase url to match that of the person whose images you wish to use. Although I don't advise shameless ripping of other peoples' stuff.

Script is available here:
http://stuff.h-i-r.net/blogstuff/fr.sh

2008-03-24

Why high-sec locks are pickable

Ross Kinard put out this paper on high sec locks earlier this month (found via [blackbag] today).

It outlines why several high-security locks are still vulnerable to manipulation and picking. Although it's often a more complex task to pick a Medeco or a Mul-T-Lock, the same flaws in manufacturing and normal wear end up creating many of the same vulnerabilities. It's just more difficult to pick these locks because there are more hoops to jump through, if you will.

Ross discusses the Two-Stage method of unlocking -- something that few lock manufacturers employ -- and why it's crucial to making a lock more difficult to pick. Ross uses Abloy's Disc Blocking System as an example of a very strong system that is highly resistant to straight-forward manipulation attacks.

If you like physical security, lockpicking, high-res photos of locky goodness and technical diagrams, this is a great read. It's not terribly verbose, either. I think it also goes without saying that Blackbag belongs in your RSS reader. Right now.

2008-03-23

Hak.5 - Shmoocon Special

The Hak.5 guys went to Shmoocon and pumped out an hour.5 long interview with five high-profile hackers. Vista (in)security, GSM Cracking, SSD/Flash data recovery, and the new version of BackTrack are covered, among other things. It's worth a watch, but don't get caught slacking off at work! An hour and a half is a long lunch break.

Hak.5 Season 3 Ep. 8

2008-02-07

Exploiting Online Games

Kansas City native game hacker, tinkerer and developer Josh Kriegshauser discussed Greg Hoglund and Gary McGraw's book, Exploiting Online Games.  Josh is an old friend, former co-worker, and former classmate to various HiR writers.  He went from tinkering with Ultima Online while he was in school, to being a big name in the MMO industry in the last decade.  


I found Josh's discussion about the book interesting, and thought I'd share it here.  I'm definitely not a gamer in any sense of the word, but things like this interest me enough that I'm seriously considering picking up a copy.