10.31.2007

eWeek's "12 Scariest Applications"

eWeek.com posted a great list of 12 applications that are in common use but suffer from an assortment of vulnerabilities. The list has some applications that will surprise you. Don't be surprised that Internet Explorer is not on the list...for good or bad, they do have a reason.

Chalmer

Online identities and expert witnesses

For the astute readers who are looking for a future in expert testimony or may be pursuing to advance your career, some words of advice: be cautious about what you post online in online forums, especially about what questions you ask. During expert testimony, if the opposing counsel can't discredit your facts, they will attempt to discredit you. One method that has been used to do this is to Google your online activity and then try to use that against you. For example, if you post a perfectly innocent question early on in your career that any skilled professional should know the answer to, the opposing counsel can try to make you out to be a bumbling fool.

An associate of mine, in the forensics field, uses several online identities to bolster and protect his reputation. He uses his "professional identity" to answer other newbies' questions and present himself as an expert in the field and he uses his "throw away identities" to ask questions.

Chalmer

10.05.2007

TouchGraph...visually representing web connections

Very interesting tool that helps show how subjects are linked with other subjects on the web. This is particularly useful for seeing how people are characterized on the web.
Try TouchGraph and see for yourself.

Chalmer

10.02.2007

Hacked by YouTube...

This article from CBS News outlines the potential for malicious code to be found in online media sources, such as the video files served up by YouTube and similar video websites.

The take home message here is not so much that videos are getting corrupted...we knew that it was only a matter of time.  The real story is the focus on how creative and ingenius the cracker community is at spreading their malware.

Chalmer

9.26.2007

Phishing attacks...

Interesting article:  Going Undercover in the Slimy World of Phishing in eWeek, that describes the criminal business of phishing.

Don't doubt that cyber crime is big business.

Chalmer

9.20.2007

Hacking toolkits...IcePack

Interesting podcast on eWeek.com about IcePack, a hacking toolkit and the spread of hacking tool kits in general.

Some points that stuck out to me include:
* the value associated with malware...meaning the money that people will spend to buy malware
* the interplay between hackers in the community, who buy a toolkit and then modify it to spy on the hackers that they sell or give it to
* the growth in the malware industry in general

Chalmer

9.19.2007

Infected even before you connect to the Internet???

Story in the Register about hard disks from Maxtor (recently acquired by Seagate) that come pre-formatted AND pre-infected.

Rumors on the street are that the virus that infects the hard disks from Maxtor steal gaming passwords and delete mp3's.

Nice.

Chalmer

9.18.2007

Wireless War "Walking" and WiGLE

Tim Wilson of Dark Reading shares his experiences during a walk around the White house scanning for open wireless networks.

Several points are pertinent for the astute reader:
* There are a ton of unsecured or poorly secured wireless networks in the world.  OK...so that is not a newsflash.
* The author refers to WiGLE, the wireless geographic logging engine.

Read the article and take a look at WiGLE.

Chalmer

9.16.2007

From Bastille Linux to Bastille Unix

In case you hadn't heard, there was a change in name from Bastille Linux to Bastille Unix.

Apparently a domain-name squatter acquired the rights to the domain name that Bastille Linux was using.

He tried to get the original owners of the name to fork over big bucks to get the name back, but they are gonna rely upon the arbitration process to get the name back.

In the meantime, they are gonna take advantage of this opportunity to create a new web-site that reflects the changed nature of their product...

For a period of time, Bastille Linux has been ported to operating systems besides just Linux, so the name really didn't fit any more. They have changed the name to Bastille Unix.

If you have never heard of Bastille Linux, it is a script that walks through the security features of your operating system and either adjusts them for you or teaches you how and why to adjust them. Very good learning tool.

Chalmer

Google