Welcome Guest. | Log In | Register | Membership Benefits

Analyzing Android, iOS Apps For Weak Data Protection, Cleartext Passwords


Posted by John H. Sawyer @ 02:54 PM ET | May 04, 2012

Analysis reveals mobile apps designed to protect things like photos and passwords do a poor job, often storing them in plain text with no encryption at all.

Continue reading "Analyzing Android, iOS Apps For Weak Data Protection, Cleartext Passwords"


Topics:   Evil Bytes



Quick-Start Guide: Compiling Mac-Robber For iOS Vuln Research


Posted by John H. Sawyer @ 06:41 PM ET | Apr 05, 2012

How to compile, copy, and run mac-robber on jailbroken iOS devices

Continue reading "Quick-Start Guide: Compiling Mac-Robber For iOS Vuln Research"


Topics:   Evil Bytes



Quick-Start Guide: Compiling Mac-Robber For Android Vuln Research


Posted by John H. Sawyer @ 05:15 PM ET | Apr 02, 2012

How to compile, copy, and run mac-robber on rooted Android devices

Continue reading "Quick-Start Guide: Compiling Mac-Robber For Android Vuln Research"


Topics:   Evil Bytes



Forensic Approach To Mobile App Vulnerability Research


Posted by John H. Sawyer @ 10:30 AM ET | Mar 30, 2012

Intro to a unique approach for vulnerability research on mobile apps using traditional PC forensic tools

Continue reading "Forensic Approach To Mobile App Vulnerability Research"


Topics:   Evil Bytes



Fun With REMnux -- And New Malware Analysis Book


Posted by John H. Sawyer @ 10:05 AM ET | Mar 22, 2012

"Practical Malware Analysis" provides in-depth knowledge on malware analysis and includes useful lab exercises. We take REMnux for a spin with the labs

Continue reading "Fun With REMnux -- And New Malware Analysis Book"


Topics:   Evil Bytes



Linux Live Environments: Cool Tools Even For Windows Folks


Posted by John H. Sawyer @ 04:56 PM ET | Feb 14, 2012

Preconfigured Linux environments provide powerful tools to aid in pen testing, mobile security testing, malware analysis, and forensics

Continue reading "Linux Live Environments: Cool Tools Even For Windows Folks"


Topics:   Evil Bytes



Passive Network Fingerprinting; p0f Gets Fresh Rewrite


Posted by John H. Sawyer @ 02:19 PM ET | Feb 03, 2012

Passive network analysis can reveal OS, service, and even vulnerabilities -- just by sniffing the network

Continue reading "Passive Network Fingerprinting; p0f Gets Fresh Rewrite"


Topics:   Evil Bytes



Penetration Tests: Not Getting 'In' Is An Option


Posted by John H. Sawyer @ 12:29 PM ET | Nov 28, 2011

Pen testers must get beyond just breaking in and clients need to understand how the tester's results map to business risk

Continue reading "Penetration Tests: Not Getting 'In' Is An Option"


Topics:   Evil Bytes



Plugging The Kiosk-Sized Security Hole


Posted by John H. Sawyer @ 01:44 PM ET | Nov 15, 2011

Companies like to set up Internet kiosks for customers and job applicants, but their convenience can be their undoing

Continue reading "Plugging The Kiosk-Sized Security Hole"


Topics:   Evil Bytes



Basic Baselining For Quick Situational Awareness


Posted by John H. Sawyer @ 01:00 PM ET | Oct 28, 2011

Baselines can be extremely valuable in knowing what's going on within your network, but they can't help if they're not created. Start with the basics and adapt to meet your needs.

Continue reading "Basic Baselining For Quick Situational Awareness"


Topics:   Evil Bytes



DerbyCon Fosters Community -- Videos Available Online


Posted by John H. Sawyer @ 04:11 PM ET | Oct 07, 2011

DerbyCon's successful first year reminds us of what the security community is all about: sharing and learning from others, promoting new ideas, and advancing the art of security.

Continue reading "DerbyCon Fosters Community -- Videos Available Online"


Topics:   Evil Bytes



0-Day SCADA Exploits Released, Publicly Exposed Servers At Risk


Posted by John H. Sawyer @ 01:50 AM ET | Sep 16, 2011

Italian researcher releases 0-day SCADA exploits leaving companies vulnerable to exploit. Community-based IDS signature project releases update to help detect attacks.

Continue reading "0-Day SCADA Exploits Released, Publicly Exposed Servers At Risk"


Topics:   Evil Bytes



Metasploit Gets Covert Forensics And PXE Boot Attack Capabilities


Posted by John H. Sawyer @ 04:52 PM ET | Sep 09, 2011

New Metasploit modules released during the Vegas security cons add cool new features like covert forensics and PXE boot pwnage.

Continue reading "Metasploit Gets Covert Forensics And PXE Boot Attack Capabilities"


Topics:   Evil Bytes



Smartphones And Tablets Targets For Getting 'Juiced'


Posted by John H. Sawyer @ 11:42 AM ET | Aug 29, 2011

Awareness campaign at DEFCON shows how easy data can be stolen from smartphones using free charging kiosks.

Continue reading "Smartphones And Tablets Targets For Getting 'Juiced'"


Topics:   Evil Bytes



Medical Device Security Under Fire At Black Hat, DefCon


Posted by John H. Sawyer @ 05:05 PM ET | Aug 18, 2011

New research on medical device security is shining light on potentially deadly vulnerabilities.

Continue reading "Medical Device Security Under Fire At Black Hat, DefCon"


Topics:   Evil Bytes



WarVOX Gets An Overhaul; Wardialing Added To Metasploit


Posted by John H. Sawyer @ 04:00 PM ET | Aug 12, 2011

Rewrite of WarVOX brings new features, better audio fingerprinting, and a Ruby VoIP stack that's been integrated into Metasploit.

Continue reading "WarVOX Gets An Overhaul; Wardialing Added To Metasploit"


Topics:   Evil Bytes



New Metasploit Tools Help Find Security Blind Spots


Posted by John H. Sawyer @ 05:00 PM ET | Jun 27, 2011

Upcoming Metasploit Framework vSploit modules can help to identify security blindspots.

Continue reading "New Metasploit Tools Help Find Security Blind Spots"


Topics:   Evil Bytes : SMB Security Tech Center



WAFs Have Benefits, But Are Not A Security Cure-all


Posted by John H. Sawyer @ 01:47 PM ET | Jun 15, 2011

WAFs can provide a good layer of defense against attacks, but can't solve all web app sec problems as vendors would like you to think.

Continue reading "WAFs Have Benefits, But Are Not A Security Cure-all"


Topics:   Evil Bytes : SMB Security Tech Center



Logging Isn't Hard -- Getting Started Is


Posted by John H. Sawyer @ 11:47 PM ET | Jun 02, 2011

The biggest hurdle SMBs face with logging is actually starting. Even the most rudimentary setup can provide immeasurable value when faced with a breach.

Continue reading "Logging Isn't Hard -- Getting Started Is"


Topics:   Evil Bytes : SMB Security Tech Center



The Power Of Open-Source Security Tools


Posted by John H. Sawyer @ 03:30 PM ET | Feb 25, 2011

Free, open source tools like the Metasploit Framework and w3af exemplify the power of community involvement and support.

Continue reading "The Power Of Open-Source Security Tools"


Topics:   Evil Bytes



Frequency Hopping Spread Spectrum, Project Ubertooth Detailed At ShmooCon


Posted by John H. Sawyer @ 08:54 AM ET | Feb 10, 2011

Two new wireless security projects discussed at ShmooCon focus on bringing low-cost hardware to security researchers

Continue reading "Frequency Hopping Spread Spectrum, Project Ubertooth Detailed At ShmooCon "


Topics:   Evil Bytes



ShmooCon Panel Discusses Ease, Speed Of Password Cracking


Posted by John H. Sawyer @ 12:08 PM ET | Feb 01, 2011

Panel of security professionals discussed new tools and techniques to accelerate password cracking, highlighting need for multi-factor authentication

Continue reading "ShmooCon Panel Discusses Ease, Speed Of Password Cracking"


Topics:   Evil Bytes



Security Researcher Targets SCADA, Releases Exploit


Posted by John H. Sawyer @ 04:45 PM ET | Jan 13, 2011

Exploit for SCADA software emphasizes need for organizations to review their network design, device exposure before they become a victim.

Continue reading "Security Researcher Targets SCADA, Releases Exploit"


Topics:   Evil Bytes



Mining Web Proxy Logs For Interesting, Actionable Data


Posted by John H. Sawyer @ 12:06 PM ET | Jan 04, 2011

Simple statistical analysis of Web proxy logs provides wealth of information & incidents sometimes by AV.

Continue reading "Mining Web Proxy Logs For Interesting, Actionable Data"


Topics:   Evil Bytes



New Snort Front-End Adds Speedy Analysis, Ease Of Use


Posted by John H. Sawyer @ 12:13 PM ET | Dec 30, 2010

Snorby is a new free, open-source analysis front-end to the popular Snort IDS that is fast and usable.

Continue reading "New Snort Front-End Adds Speedy Analysis, Ease Of Use"


Topics:   Evil Bytes




Go on to the weblog archives...






  1. Cookies, Social Media And FireSheep
  2. SMB Guide To Credit Card Regulations, Part 2: The Low-Hanging Fruit
  3. HP And The Scary Corporate Fifth Column Concept
  4. Taking USB Attacks To The Next Level
  5. NoSQL: Not Much, Anyway
  1. Taking Cybersecurity Lessons To The Bank
  2. Researchers See Real-Time Phishing Jump
  3. 'BlackSheep' Sniffs Out Firesheep WiFi-Hacking
  4. Slideshow: Ten Free Security Monitoring Tools
  5. A Different Spin On Sleuthing Stuxnet
  6. M&A Activity Muddles Database Security
  1. Secure Managed Web Hosting Saves 960.gs from Malicious Hackers
  2. Access Governance as a Business Service: An Integrated Strategy for Automation with ITSM
  3. Business Driven Access Management and Governance: Simplifying the Delivery and Governance of Access Throughout
 
 


 
  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag
 
  May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
  June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
 
Featured Webcasts
Featured Whitepapers
Featured Reports