Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Input Validation, du Jour →

October 13, 2014 by Marc Handelman in All is Information, Cruft, Data Security, Information Security, Operating System Security, Vulnerabilities

Not to be undone by the well reported Bourne Again Shell vulnerability of two weeks past, now, via, Robert Lemos, writing at ArsTechnica, comes this sordid tale of poor punctuation coupled with input validation issues. In which, the vulnerability at hand, opens up a logical path within the Microsoft Corporation (NasdaqGS: MSFT) Windows in-built shell, where all the badness is vectored...

October 13, 2014 /Marc Handelman
All is Information, Cruft, Data Security, Information Security, Operating System Security, Vulnerabilities

Flaws of iOS

October 03, 2014 by Marc Handelman in All is Information, Cruft, Information Security, Operating System Security, Sarcasm

No pun intended...

October 03, 2014 /Marc Handelman
All is Information, Cruft, Information Security, Operating System Security, Sarcasm

Shellshock Bequeathed →

October 02, 2014 by Marc Handelman in All is Information, Cruft, Information Security, Operating System Security

Much ado about something, nearly a quarter century in the offing, and further evidence to support our Theory of Cruft, or the Things that are Left Over, and Getting in the Way...

October 02, 2014 /Marc Handelman
All is Information, Cruft, Information Security, Operating System Security

MAC Rotator

September 29, 2014 by Marc Handelman in All is Information, Application Security, Information Security, Right to Privacy, Operating System Security, Intelligence, Identity Theft

Ladies and Gentlemen, Girls and Boys, here's why Apple Inc. (NasdaqGS: AAPL) iOS 8.x driven devices are marginally better for privacy concerns: Rotating (Programmatic MAC Spoofing) Media Access Control addresses. Today's MustRead; whilst, another view of tracking iOS devices has surfaced.

September 29, 2014 /Marc Handelman
All is Information, Application Security, Information Security, Right to Privacy, Operating System Security, Intelligence, Identity Theft

ShellShock

September 26, 2014 by Marc Handelman in All is Information, Information Security, Operating System Security

Newly discovered BASH vulnerability finds Apple Inc.'s (NasdaqGS: AAPL) MAC OS X operating system with it's shell environment cracked; of course, this pernicious bug also finds its way into most Linux and/or other Unix-like and UNIX systems. Interestingly, there are workarounds and patches available for the version of BASH resident on your OS X systems. If you look hard enough, there is a workaround in the StackExchange article (linked to above).

September 26, 2014 /Marc Handelman
All is Information, Information Security, Operating System Security

Elcomsoft, New iOS Forensics Tools

September 16, 2014 by Marc Handelman in All is Information, Cruft, Data Security, Information Security, Memory, Network Security, Operating System Security

News, of the release of astonishingly capable bits, targeting [forensically speaking in this case] Apple Inc.  (NasdaqGS: AAPL) iOS devices, by Russian Federation based Elcomsoft.

September 16, 2014 /Marc Handelman
All is Information, Cruft, Data Security, Information Security, Memory, Network Security, Operating System Security
  • Newer
  • Older