NetSec
  corner   



HOME

LINUX

CYBERLAW

VIRTUALIZATION

Bugtraq

Packetstorm

FD

GrokLaw


RSS Feed


Netsec, comsec, infosec and IA news, research and trends

 

10.02.2004

 
The Mozilla Foundation releases an important security update for Firefox

 
Pads is a signature based detection engine used to passively detect network assets. It is designed to complement IDS technology by providing context to IDS alerts.



10.01.2004

 
More on Departure of Cybersecurity Czar Amit Yoran

 
realPlayer Heap Overflow ==> Critical Update (Tools > Check for Update)
Reported by eEye on bugtraq

 
ContentCentral Technical Papers from Keith

 
CyberSecurity Czar Yoran Resigns from DHS Citing Disappointment in Organizational Cybersecurity Awareness

 
A Bit of History on Computer Viruses mentions John Brunner's Shockwave Rider and other works of science fiction that preceded the creation of the first wild viruses. The earliest instance of virus writing of which I am aware involved the legendary Robert Morris Sr, Doug McIlroy and Victor Vyssotsky. In 1961 they laid down the ground rules for their game Darwin. Here you can learn a bit about it in this letter to Aleph-Null (no relation I assume to Aleph-One).



9.30.2004

 
Warspammer Found Guilty Under CAN-SPAM

 
INDUCE Act Vote Delayed Until Next Week Due to Lawmaker Reports of Stiff Consumer Oppostion Orrin Hatch, Chair of the Judiciary Committee stated in response that "If I have to, I will lock all of the key parties in a room until they come out with an acceptable bill."

 
Cracking HOWTO by Mixter

 
"Improving the Security of Your Site by Breaking Into It" by Dan Farmer and Wietse Venema

 
UnicornScan was released at ToorCon last weekend. It is a distributed TCP/IP stack aimed at protocol level security research. Features include:
# Asynchronous stateless TCP scanning with all variations of TCP Flags.
# Asynchronous stateless TCP banner grabbing
# Asynchronous protocol specific UDP Scanning (sending enough of a signature to elicit a response).
# Active and Passive remote OS, application, and component identification by analyzing responses

 
Quantum Cryptography: Privacy through Uncertainty

NEC Recently Attained a Quantum Crypto Speed Record



9.29.2004

 
Who has Mid Level M$ Windows/Exchange Admin Skills and needs a job with a local firm? Let me know if you are interested.

 
Absentee Voting Via Email

 
New Helix ISO Released



9.28.2004

 
Help Stop the INDUCE Act

In 1984 the Supreme Court ruled in Sony V Universal that we have a “Fair Use” right to own home recording equipment like VCR’s, Cassette Recorders and CD-R’s. The INDUCE Act would, if passed, act to overturn the Supreme Court and discourage innovation in the development of multimedia hardware and software.

INDUCE undermines innovation, market economics and consumer rights.

The Association of Research Librarians Opposes INDUCE

The Institute for Electrical and Electronic Engineers Opposes INDUCE

The Consumers Union Opposes INDUCE

The Consumer Electronics Association Opposes INDUCE

We Should Oppose INDUCE.

Please Call Your Senators in Opposition Wednesday, September 29th between the hours of 9am and 5 pm EDT. In Virginia this is Senator George Allen (202-224-4024) and Senator John Warner (202-224-2023).

Read about the US businesses that will be undermined by INDUCE

 
Phishing IQ Test

 
Passive Information Gathering by Gunter Ollman

 
Port80Software: ServerMask Allows IIS Server Header Modification. They also have a web application for pulling server headers through their site.

 
NSA Information Assurance Directorate - Sponsored Events - Red/Blue Team Symposium

 
Japanese School Children Tracked with RFIDs



9.27.2004

 
Information Leakage from Optical Emanations

 
New Rose Attack

 
JPEG Virus Reported In the Wild

 
The GDIscan Tool from SANS Will Scan a system for DLL's (gdiplus.dll, sxs.dll, wsxs.dll, mso.dll) Vulnerable to the JPEG Overflow. Many applications may install their own instance so it is highly recommended systems be scanned.

 
The Case for "Ethical" Hacking by Brandt and Vines

 
Beetle's Wireless Weapons of Mass Destruction for Windows from ToorCon

BTW: You Only Have Until September 30th to get the $99 Rate for ShmooCon Registration

 
iPods Increasingly Banned from Secure Facilities

 
Symantec Firewall Hard Coded SNMP Write Community String = "public" and other great news. It's been a bad week to be a user of Symantec "firewall" products.

 
Windows XP SP2 Firewall Bypass Vulnerability



9.26.2004

 
Microsoft May Run Afoul of the Law in Cloning Radio Stations

 
40 Tech Firms Ask for Hearing on Induce Act

 
Activists Find More Diebold E-Voting Server Flaws

 
Ken Thompson: Reflections on Trusting Trust

 
"JPEG of Death" Reverse Shell Exploit





This page is powered by Blogger.


Site Meter Locations of visitors to this page