Welcome Guest. | Log In | Register | Membership Benefits

New iPhone SMS Threat No Reason To Panic


Posted by David Maynor @ 09:00 AM ET | Jul 31, 2009

You may have heard that researcher Charlie Miller has released details about a vulnerability that allows an attacker to take over an iPhone remotely with a SMS message. Now everyone is rushing to offer homegrown advice on how to fix the problem. But I'm going to offer a different point of view.

Continue reading "New iPhone SMS Threat No Reason To Panic"

Comments(0)
Topics:   Hacked Off



71% Say Extradition Of UFO Hacker Gary McKinnon Is Wrong


Posted by Graham Cluley @ 05:29 AM ET | Jul 31, 2009

Self-confessed hacker Gary McKinnon has lost a judicial review in London that he hoped would have lead to a British investigation into his case, rather than extradition to the United States.

Continue reading "71% Say Extradition Of UFO Hacker Gary McKinnon Is Wrong"

Comments(0)
Topics:   SophosLabs Insights



Pwnie Awards Bring Fame And Shame


Posted by John H. Sawyer @ 02:01 PM ET | Jul 30, 2009

The third annual Pwnie Awards at Black Hat in Las Vegas, hosted by Alex Sotirov, Dino Dai Zovi, HD Moore, Halvar Flake, and Rich, celebrated the highs and lows in the security industry. As Dino said, "First we reward for great work, then we shame."

Continue reading "Pwnie Awards Bring Fame And Shame"

Comments(0)
Topics:   Evil Bytes



Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View


Posted by Sara Peters @ 12:26 PM ET | Jul 30, 2009

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.

Continue reading "Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View"

Comments(0)
Topics:   CS Island



Metasploit Meterpreter For Mac Coming Soon


Posted by John H. Sawyer @ 05:48 PM ET | Jul 29, 2009

Meterpreter is by far one of the most powerful and most advanced payloads included in the Metasploit Framework. It's been the joy of penetration testers and the bane of incident responders and until now, it's only been a payload targeted at Windows systems, while Mac users have dodged a bullet. But that won't be the case for much longer, as demonstrated by Dino Dai Zovi in a 20-minute breakout session at Black Hat today titled "Macsploitation with Meterpreter."

Continue reading "Metasploit Meterpreter For Mac Coming Soon"

Comments(0)
Topics:   Evil Bytes



UPDATE: BlackHat, Kinda: 'Real' Black Hats Hack Security Experts


Posted by Sara Peters @ 12:23 PM ET | Jul 29, 2009

The rumor here is that the attacks did indeed happen, but the significance of it is actually quite small--not worth paying attention to, since attention is clearly what the attackers are seeking. More info to come... BlackHat, Kinda: Yesterday a hacking group released details (http://r00tsecurity.org/files/zf05.txt) of a number of successful attacks they conducted, apparently with the principal purpose of embarrassing some of the security industry's most well-known experts. The group claims that they collected about 75,000 passwords, including those of a few security experts speaking at the BlackHat Briefings today and tomorrow. "Welcome one and all to the real Black Hat Briefings," reads the site. "Live from the underground, coming right at you free of charge."

Continue reading "UPDATE: BlackHat, Kinda: 'Real' Black Hats Hack Security Experts"

Comments(0)
Topics:   CS Island



West African 419 Scammers Exploit Dilbert


Posted by Graham Cluley @ 06:06 AM ET | Jul 29, 2009

The Dilbert comic strip is loved around the world for its satirical look at life in the corporate office. But now identity thieves and scammers are exploiting the popular Dilbert.com Website in their hunt for potential victims.

Continue reading "West African 419 Scammers Exploit Dilbert"

Comments(0)
Topics:   SophosLabs Insights



Obama Administration Going Soft On Cybersecurity


Posted by Rob Enderle @ 01:50 AM ET | Jul 28, 2009

Viruses, botnets with international botmasters, denial-of-service attacks on government properties, cyberbullying, and the increasing threat of identity theft plague every resident, from child to adult, regardless of whether they are actually ever online -- U.S. cybersecurity has been little more than a bad joke.

Continue reading "Obama Administration Going Soft On Cybersecurity"

Comments(0)
Topics:   Hacked Off



The BlackBerry 'Trojan Horse'


Posted by Gadi Evron @ 07:00 PM ET | Jul 23, 2009

Research In Motion's announcement that users in the United Arab Emirates (UAE) who installed an update on their BlackBerrys ended up with a surveillance application raises some key questions.

Continue reading "The BlackBerry 'Trojan Horse'"

Comments(0)
Topics:   Hacked Off



The Encryption Gap


Posted by Lorna Garey @ 10:01 AM ET | Jul 23, 2009

Things that make us say "hmmm" include these stats: The percentage of respondents to our 2009 Strategic Security Survey who rated encrytion as effective in reducing risk dropped from 57% in 2008 to 48% in 2009. Use of disk, file, and backup media encryption ALL fell year over year by at least five percentage points. Backup encryption usage is down 10 points.

Continue reading "The Encryption Gap"

Comments(0)
Topics:   Hacked Off



Using Malware In Penetration Testing


Posted by John H. Sawyer @ 03:13 PM ET | Jul 22, 2009

Huh? That's the exact reaction I had when I first read the title for the blog entry "Pentest Evolution: Malware Under Control."

Continue reading "Using Malware In Penetration Testing"

Comments(0)
Topics:   Evil Bytes



Erin Andrews Video: Get A Life Or Get A Virus


Posted by Graham Cluley @ 05:12 PM ET | Jul 20, 2009

It was early Sunday morning British time when I first heard the name "Erin Andrews." I didn't have a clue who she was -- I don't follow the American sports scene -- but one thing was certain: She was creating an enormous buzz on the Internet.

Continue reading "Erin Andrews Video: Get A Life Or Get A Virus"

Comments(0)
Topics:   SophosLabs Insights



Data Breach Laws Drive IR, Preparation Is Key


Posted by John H. Sawyer @ 03:31 PM ET | Jul 20, 2009

Fellow Dark Reading blogger Gadi Evron had an interesting take on the relationship between incident response and forensics in his post "Incident Response Is Not Forensics." I agree with him for the most part, but I don't think forensics is the most common course of action depending on who is responding to the incident.

Continue reading "Data Breach Laws Drive IR, Preparation Is Key"

Comments(0)
Topics:   Database Security Tech Center : Evil Bytes



Defensible Network Architecture Ideal For Incident Response


Posted by John H. Sawyer @ 03:06 PM ET | Jul 17, 2009

In my last blog, I talked about how incident response is more than just preparing your first responders by training them and providing them with the tools. Your network and systems need to set up in preparation, too, so that you have the information you need when handling an incident. It wasn't until yesterday that I remembered what I think is one of the best models of network design that fits the mold of what I mean by having your environment ready for an incident.

Continue reading "Defensible Network Architecture Ideal For Incident Response"

Comments(0)
Topics:   Evil Bytes



Incident Response Is Not Forensics


Posted by Gadi Evron @ 06:08 PM ET | Jul 16, 2009

Professionals who handle computer security incident response traditionally have also been charged with forensics. They find the evidence of wrongdoing, and preserve it in a court-approved fashion. This best practice is a good one, even when saving data for law enforcement is not a necessity or a priority.

Continue reading "Incident Response Is Not Forensics"

Comments(0)
Topics:   Hacked Off



IT Admin Gets Jail Time For Sabotaging Ex-Employer's Network


Posted by Graham Cluley @ 01:26 AM ET | Jul 16, 2009

Hell hath no fury like an IT support administrator scorned. At least that's the message being heard loud and clear by firms that are finding their networks at risk of attack from former employees.

Continue reading "IT Admin Gets Jail Time For Sabotaging Ex-Employer's Network"

Comments(0)
Topics:   Insider Threat Tech Center : SophosLabs Insights



Incident Response Prep Extends Beyond Tools, Training


Posted by John H. Sawyer @ 02:46 PM ET | Jul 15, 2009

Whenever you read information on how to perform forensics and incident response, there is a preparation phase that comes before anything else. Preparation steps cover how to prepare for dealing with an incident in your environment -- but what about making sure your environment is ready for an incident?

Continue reading "Incident Response Prep Extends Beyond Tools, Training"

Comments(0)
Topics:   Evil Bytes



The Security 'Unconference' In Vegas


Posted by Kelly Jackson Higgins @ 10:16 AM ET | Jul 15, 2009

Most of the security action happening later this month will be in Vegas' Caesars Palace and the Riviera Hotel, where Black Hat USA and Defcon will convene. But at a rented house at a thus-far undisclosed location a few miles off of the Las Vegas Strip, a handful of hackers will host SecurityBSides, a homegrown "unconference" alternative to the more structured format of Black Hat.

Continue reading "The Security 'Unconference' In Vegas"

Comments(0)
Topics:   Dark Dominion



Internet Explorer Hit With 1-2 Punch Of Zero-Day Attacks


Posted by John H. Sawyer @ 03:03 PM ET | Jul 13, 2009

It's Monday: Do you know what Web browser your users are running? If it's Internet Explorer, don't look now, but for two weeks in a row, IE has taken two jabs straight to the face with ActiveX zero-day exploits that let attackers stomp all over users who are tricked into clicking on a malicious link or get redirected from a compromised site. Browser alternatives starting to look a little more enticing?

Continue reading "Internet Explorer Hit With 1-2 Punch Of Zero-Day Attacks"

Comments(0)
Topics:   Evil Bytes



DDoS Cyberwarfare Hurts Us All


Posted by Gadi Evron @ 11:55 AM ET | Jul 09, 2009

A distributed denial of service (DDoS) attack has been in the news in recent days due to attacks against the U.S. government -- with fingers pointed at North Korea. But people forget a few basic truths people when it comes to information warfare (or cyberwarfare) and DDoS attacks.

Continue reading "DDoS Cyberwarfare Hurts Us All"

Comments(0)
Topics:   Hacked Off



Hacking And Exploit Site Milw0rm Closes Its Doors


Posted by John H. Sawyer @ 02:18 PM ET | Jul 08, 2009

Milw0rm is by far one of the best-known public sites to get the latest proof-of-concept exploit code. Or at least it was until it closed its doors today. The closing comes as a shock to the security community given that milw0rm had become a valuable resource for proof-of-concept and weaponized exploit code, demonstration videos, and papers on all areas of information security.

Continue reading "Hacking And Exploit Site Milw0rm Closes Its Doors"

Comments(0)
Topics:   Evil Bytes



Kantara Initiative: Another Effort To Get Identity 2.0 Out Of The Gate


Posted by Sara Peters @ 05:09 PM ET | Jul 06, 2009

We've been saying for a while now that better identity management -- more so than secure Web app coding or even more secure browsers -- could fuel a quantum leap in Web security. The "Identity 2.0" community can be credited with wonderful research and truly significant advancements in identity management technology. In many ways, we're poised for an identity revolution. However, the efforts have been hampered by a lack of public awareness, a lack of interoperable standards, usability concerns, and a fundamental chicken/egg problem.

Continue reading "Kantara Initiative: Another Effort To Get Identity 2.0 Out Of The Gate"

Comments(0)
Topics:   CS Island



Would Your Users Take The Bait?


Posted by John H. Sawyer @ 03:13 PM ET | Jul 06, 2009

Military leaders would never send their troops into war without preparing them for the threats they'd be facing on the battleground. Likewise, you shouldn't let your users go about their daily activities without educating them about the dangers they face when opening an e-mail or clicking on a link returned from a seemingly innocuous Google query.

Continue reading "Would Your Users Take The Bait?"

Comments(0)
Topics:   Evil Bytes



Independence Day Fireworks Video Carries Malware Payload


Posted by Graham Cluley @ 02:41 AM ET | Jul 04, 2009

Hackers are taking advantage of American Independence Day celebrations by spamming out what pretends to be a link to a Fourth of July fireworks show, but is really an attempt to infect computers.

Continue reading "Independence Day Fireworks Video Carries Malware Payload"

Comments(0)
Topics:   SophosLabs Insights



The Only Two Reliable Cloud Security Controls


Posted by Rich Mogull @ 05:00 PM ET | Jul 02, 2009

It seems that we in the information technology profession are just as fickle as the fashionistas strutting around Milan or New York. While we aren't quite as locked to a seasonal schedule, we do have a tendency to fawn over the latest technology advances as if they were changing colors or hem lengths. Some are new, some are old, some are incredibly useful, and others are completely frivolous, but we can't deny their ability to enter and steer our collective consciousness -- at least until the next spring. Take cloud computing.

Continue reading "The Only Two Reliable Cloud Security Controls"

Comments(0)
Topics:   Hacked Off



Security Design Goes With Secure Coding


Posted by Gadi Evron @ 04:20 PM ET | Jul 01, 2009

When professionals without security awareness plan a project, security is often left out. The result costs money in the long run. What can we do to make it better?

Continue reading "Security Design Goes With Secure Coding"

Comments(0)
Topics:   Hacked Off



It's Time To Take Bot Infections Seriously


Posted by John H. Sawyer @ 03:26 PM ET | Jul 01, 2009

The soapbox is a place I hate to be, but sometimes a topic just rubs me raw enough that I climb up to try and get my point across. The topic of bots, botnets, and their impact on corporate data is one of those issues.

Continue reading "It's Time To Take Bot Infections Seriously"

Comments(0)
Topics:   Evil Bytes




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
  May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008