Reports indicae, commercial banking institutions in the United States are peeved with the federal response to data security related attacks (evidence fingers Iranian sources for the specific attacks under scrutiny)...
Reports indicae, commercial banking institutions in the United States are peeved with the federal response to data security related attacks (evidence fingers Iranian sources for the specific attacks under scrutiny)...
Posted by Marc Handelman on 2013.05.02 at 08:00 in Data Loss, Data Loss Prevention, Data Security, Database Security, Economics, Electronic Warfare, Information Security, War, Web Security | Permalink
News, via Raphael Mudge, of the removal of graphical user interfaces utilized within the Metasploit environment. In essence, Armitage has been dropped in the
Metasploit 4.6 distribution.
Ostensibly dropped by the Metasploit Project to disambiguate supported product responsibility, both are still availble and under active development for inclusion in customized environments for your penetration testing efforts. Notwitstanding the lack of a default install [through the Kali Linux install routines] the Kali Linux team has included an Armitage package [apt-get install armitage] in the repository.
Posted by Marc Handelman on 2013.04.15 at 08:00 in All Is Information, Information Security, Penetration Testing, Vulnerabilities, Web Security | Permalink
News, via Rapid7's Christian Kirsch, of the Metasploit 4.6 release. This time, with the inclusion of OWASP Top Ten 2013 testing capability support - once the Top Ten 2013 (currently in release candidate stage, as of this posting) are unleashed, that is.
Posted by Marc Handelman on 2013.04.12 at 08:00 in All Is Information, Application Security, Information Security, Penetration Testing, Web Security | Permalink
Posted by Marc Handelman on 2013.03.29 at 09:00 in Application Security, Information Security, Web Security | Permalink
Posted by Marc Handelman on 2013.03.25 at 10:00 in Blatant Stupidity, Information Security, Useless Web Security Design, Web Security | Permalink
News, via the inimitable Brian Krebs, detailing the astonishing malfeasance displayed by Google Inc. (NasdaqGS: GOOG) in policing the Google Play storefornt. Essentially, Krebs On Security reports discovering a thriving marketplace in the buying and selling of verified developer accounts by Android malware authors. Thinking about moving to the Android platform? Think again. Read it and weep.
Posted by Marc Handelman on 2013.03.08 at 08:00 in All Is Information, Data Security, Electronic Crime, Information Security, Mobile Device Security, Mobile Telephony, Web Security, You Are Google Inventory | Permalink
Saturday, twas a wet and stormy day... First came a new sub-version update to Evernote, then comes word of a service-wide password reset due to suspicious activity...
'The investigation has shown, however, that the individual(s) responsible were able to gain access to Evernote user information, which includes usernames, email addresses associated with Evernote accounts, and encrypted passwords.' - Evernote' Operations & Security Team
Posted by Marc Handelman on 2013.03.04 at 08:00 in Data Loss, Data Loss Prevention, Information Security, Web Security | Permalink
via the Association for Computing Machines [ACM], panelists Vint Cerf, John Hopcroft, Bob Kahn, Ron Rivest and Adi Shamir:
"explore some specifics of the digital information revolution, notably theory and practice in securing, authenticating and maintaining the integrity of information (Cerf); and roots of modern cryptography and current topics in this area (Rivest and Shamir)..." - ACM
Simply Outstanding.
Posted by Marc Handelman on 2013.01.25 at 09:00 in All Is Information, Cryptography, Information Science, Information Security, Network Security, Web Security | Permalink
Meanwhile, in flawed intelligence analysis news (now promoted by elected officials) the latest 'Iranian State Sponsored Financial Institution Attacks' attribution statements lack both clarity and firm evidential artifacts. Kudos to InformationWeek's' Mathew J. Schwartz for making the appalling flaws clear.
Notwithstanding the reported lack of evidence, the reality of the overt linkage between and betwixt the Iranian national defense infrastructure (e.g., the IRIA, Gendarmerie, IRGC, Oghab 2, Quds Force, and the Army of the Guardians of the Islamic Revolution, etc.) and external-to-the-government hacker collectives is is just that - overt, rather than covert.
The smoking gun, as it were, will likely target those Iranian nationals [rather than the theocratic State]; but again, predicated on conjecture, rather than evidentiary proof.
Whilst a multitude of electronic acts of warfare can be sourced to the Islamic Republic of Iran or the nations-states' thralls, the current activities cannot yet be attributed with finality of judgment. The key concept here is evidence leading to a reasoned and prudent understanding of attribution within the scope of information security and electronic warfare realms, specifically focused on the attacks under scrutiny.
Posted by Marc Handelman on 2013.01.14 at 06:00 in All Is Information, Cybercrime, CyberWarfare, Information Security, War, Web Security | Permalink
Newly released cookie hijacking hijinks targeting Microsoft Corporation's (NasdaqGS: MSFT) on-line Outlook mail service.
Posted by Marc Handelman on 2012.12.17 at 06:00 in Data Loss, Data Security, Information Security, Web Security | Permalink
News, of the latest release of Burp, now at version 1.5 by PortSwigger. A superb solution for discovering vulnerabilities in your web applications, the free version is available as well. Outstanding.
Posted by Marc Handelman on 2012.11.05 at 10:00 in All Is Information, Information Security, Web Security | Permalink
$5.oo for nearly 1 million UIDs revealed during supposedly confidential discssion between social network behemoth Facebook and Czech blogger Bogomil Shopov.
Posted by Marc Handelman on 2012.10.29 at 12:30 in All Is Information, Database Security, Information Security, Web Security, You Are Facebook Inventory | Permalink
Posted by Marc Handelman on 2012.09.26 at 09:00 in All Is Information, Application Security, Blatant Stupidity, Information Security, Web Security | Permalink
Posted by Marc Handelman on 2012.09.25 at 09:00 in All Is Information, Blatant Stupidity, Web Security, You Are Pandora Inventory | Permalink
Posted by Marc Handelman on 2012.09.19 at 09:00 in All Is Information, Data Security, Information Security, Physical Security, Web Security | Permalink
Not the conventional view of a happy ending - more on the eHarmony dump and crack, with reports of the majority of password objects cracked by Trustwave's SpiderLabs (utlizing two of our favorites - John the Ripper and oclHashcat).
Posted by Marc Handelman on 2012.07.13 at 09:00 in All Is Information, Data Security, Database Security, Host Security, Information Security, Vectors, Web Security | Permalink
Another well crafted screed from the inimitable John Leyden of El Reg - this time detailing the dust-up between and betwixt CyberRoam and the TOR project. Allegations of mass surveillance are rampant, whilst answers are apparently not up to snuff...
Posted by Marc Handelman on 2012.07.12 at 09:00 in All Is Information, Data Security, Database Security, Information Security, Network Security, Network Topologies, Web Security | Permalink
Posted by Marc Handelman on 2012.06.29 at 09:00 in All Is Information, Data Loss Prevention, Data Security, Database Security, Information Security, Information Security Awareness, Privacy Violators, Thievery, Web Security, You Are Spokeo Inventory | Permalink
Evidently, the Germans have their very own electronic warfare unit... What next - an electronic Ligne Maginot française - on the opposite side of the now, non-existent, electronic border? Astonishing.
Posted by Marc Handelman on 2012.06.14 at 09:00 in All Is Information, CyberWarfare, Data Security, Electronic Warfare, Military, Threat Intelligence, Threat Vector, War, Web Security | Permalink
Posted by Marc Handelman on 2012.06.13 at 09:00 in All Is Information, CyberWarfare, Electronic Warfare, Heroes, Information Security, National Security, Network Security, Physical Security, Web Security | Permalink
Posted by Marc Handelman on 2012.06.12 at 09:00 in All Is Information, Information Security, Information Security Awareness, Infosec Humor, Sarcasm, Threat Intelligence, Threat Vector, Web Security | Permalink
via the comic genius of Nitrozac and Snaggy at The Joy of Tech™
Posted by Marc Handelman on 2012.05.22 at 09:30 in Death of Privacy, Sarcasm, Tech Humor, Web Security, You Are Facebook Inventory | Permalink
Outstanding screed, crafted with thoughtful erudition, by the inimitable Dustin Curtis; in which, the good Curtis illuminates the peccadiloes of Twitter, et al.
Posted by Marc Handelman on 2012.05.21 at 09:00 in Death of Privacy, Information Security, Sarcasm, Web Security, You Are Twitter Inventory | Permalink
Posted by Marc Handelman on 2012.05.10 at 09:00 in Blatant Stupidity, Data Loss Prevention, Data Security, Database Security, Host Security, Information Security, Sarcasm, Web Security | Permalink
Insightful article, via The Atlanic's Dr. Patrick Lin [The Good Doctor is the director of the Ethics + Emerging Sciences Group, at California Polytechnic State University, San Luis Obispo] , targeting the Cyber Intelligence Sharing and Protection Act (CISPA). Dr. Lin's screed is far more erudite than any comment I could make, as such, I highly recommend detailed scrutiny of his post. Today's MustRead.
Posted by Marc Handelman on 2012.05.09 at 09:00 in Government, Information Security, Web Security | Permalink
via Ivan Ristić, author of ModSecurity, and Apache Security, and one of the great minds in information security today, comes news of The Trustworty Internet Movement SSL Pulse. SSL Pulse, is essentially, a information dashboard provisioning significant data relevant to the current state of the SSL ecosystem, if you will. Absolutely Outstanding.
Posted by Marc Handelman on 2012.05.08 at 09:00 in Application Security, Communications, Data Security, Information Security, TLS/SSL, Web Security | Permalink
Evidently, site and web administrator's need a refresher course in socket and transport layer security configurations... Not particularly surprising, that.
Posted by Marc Handelman on 2012.05.01 at 09:00 in Application Security, Awareness, Blatant Stupidity, Confidentiality, Cryptography, Data Security, Host Security, Information Security, Information Security Awareness, TLS/SSL, Vectors, Web Security | Permalink
News, of a thirteen year old Oracle Corporation (NasdaqGS: ORCL) Transparent Network Substrate Listener (TNS) flaw, reported, in error (a timing error, not in essence)... Regardless, flawed listener bits permit egregious Oracle Database attacks. Oops, all-around.
Posted by Marc Handelman on 2012.04.30 at 09:00 in Blatant Stupidity, Data Security, Database Security, DBMS, Information Security, Information Security Awareness, Intelligence Gathering, National Security, Network Security, Threat Vector, TLS/SSL, Web Security | Permalink
