Friday, April 20, 2007
Wednesday, April 18, 2007
FAA Advisory - Boeing 787 Hacking
On-board wired and wireless devices may also have access to parts of
the airplane's digital systems that provide flight critical functions.
These new connectivity capabilities may result in security
vulnerabilities to the airplane's critical systems. For these design
features, the applicable airworthiness regulations do not contain
adequate or appropriate safety standards for protection and security of
airplane systems and data networks against unauthorized access.
Tuesday, April 17, 2007
Last year was a hot one for UFO sightings
Chris Rutkowski says the 2006 Canadian UFO Survey recorded the third largest number of sightings in its 17-year history and shows there’s still a great deal of interest in unexplained phenomena in the sky.
Monday, April 16, 2007
cDc Launches - Cowfeed
A feed aggregator of all cDc-related content everywhere!"Based in Lubbock, Texas, CULT OF THE DEAD COW (cDc) is the most-accomplished and longest-running group in the computer underground. Founded in 1984 and widely considered to be the most elite people to ever walk the face of the earth, this think tank has been referred to as both "a bunch of sickos" (Geraldo Rivera) and "the sexiest group of computer hackers there ever was" (Jane Pratt, _Sassy_ and _Jane_ magazines). The cDc is a leading developer of Internet privacy and security tools, which are all free to the public. In addition, the cDc created the first electronic publication, which is still going strong."
Virginia Tech rampage
In my mind the only issues that should be covered at this juncture are that there has been a terrible and senseless loss of human life and that the only one at fault/to blame here - is the one who pulled the trigger...
Note: on average there are 2.4 US military fatalities every day in IRAQ - 3,308 total so far. Most the same age or younger as the VT students.
Sunday, April 15, 2007
Rock Phish
Red Tape Chronicles
Secure Future? Are mobile phones wiping out our bees?
No bees, no pollination, no food...If it is phones, then why now?
It seems like the plot of a particularly far-fetched horror film. But some scientists suggest that our love of the mobile phone could cause massive food shortages, as the world's harvests fail.
They are putting forward the theory that radiation given off by mobile phones and other hi-tech gadgets is a possible answer to one of the more bizarre mysteries ever to happen in the natural world - the abrupt disappearance of the bees that pollinate crops. Late last week, some bee-keepers claimed that the phenomenon - which started in the US, then spread to continental Europe - was beginning to hit Britain as well.
Full story here.
Saturday, April 14, 2007
Geek Accused of Videotaping Woman in Her Shower
Their mom called Best Buy's Geek Squad for help with their computer. Now two sisters are suing Best Buy, claiming the technician who showed up secretly taped one of them in the shower.Full story here.
Friday, April 13, 2007
Happy Friday - One From the Vault
Credit Union - Laptop Theft
"The computer was protected by two layers of security, a unique user-identifier and a multiple-character, alpha-numeric password."Whew, that's a relief! Press release here.
The laptop was lost by a consultant from Protiviti:
"Protiviti is a leading provider of independent internal audit and business and technology risk consulting services."Now I know where not to bank and who not to pick as my auditor...
Thursday, April 12, 2007
Wednesday, April 11, 2007
From Russia with Love

I just love Russia...
An interview with a former cyber gangster, who claims to have now joined the “white hats” and was prepared to share his experience anonymously. His first name is Victor, but his last name will be kept secret. He is 30 years old and a resident of St. Petersburg, Russia.
Tuesday, April 10, 2007
A Phishing Attack Demo Against the BOA SiteKey Authentication
A demonstration of a "deceit-augmented man in the middle attack" against the SiteKey ® service used by Bank of America.From the slight paranoia blog:
Executive Summary
We present this demonstration of a "deceit-augmented man in the middle attack" against the SiteKey ® service used by Bank of America (the underlying technology is also used by other companies). This, or a similar attack, could be used by a phisher to deceive users into entering their login details to a fraudulent website. BoA's own website tells users: "[W]hen you see your SiteKey, you can be certain you're at the valid Online Banking website at Bank of America, and not a fraudulent look-alike site. Only enter your Passcode when you see the SiteKey image and image title you selected."
See the demo here.
In the News
Microsoft Defends Effort to Patch Flaw
IT execs, researchers split over pace of work on ANI fix
Hugh McArthur, director of information systems security at Online Resources Corp. in Chantilly, Va., said that in general, Microsoft’s 100-day turnaround time for patching the so-called ANI vulnerability doesn’t seem all that unusual.
It wasn’t as if the software vendor was “just sitting back and doing nothing,” McArthur said. “My take is that Microsoft was hoping they could get the fix written and tested prior to an exploit being written. In this case, they didn’t make it.”
Despite all the hoopla, the vulnerability “ultimately wasn’t a big issue” for Online Resources, McArthur said. But he added that the online bill-processing company treated the threat “very seriously” and made sure that its antivirus software was up to date and that its monitoring tools were configured to detect any exploit attempts on its systems.
Hak.5 - Episode 2×09 Release (ShmooCon)
Monday, April 09, 2007
Debian GNU/Linux 4.0 released
The Debian Project is pleased to announce the official release of Debian GNU/Linux version 4.0, codenamed
etch, after 21 months of constant development. Debian GNU/Linux is a free operating system which supports a total of eleven processor architectures and includes the KDE, GNOME and Xfce desktop environments. It also features cryptographic software and compatibility with the FHS v2.3 and software developed for version 3.1 of the LSB.
Using a now fully integrated installation process, Debian GNU/Linux 4.0 comes with out-of-the-box support for encrypted partitions. This release introduces a newly developed graphical frontend to the installation system supporting scripts using composed characters and complex languages; the installation system for Debian GNU/Linux has now been translated to 58 languages.
How to get it here.
Sunday, April 08, 2007
Saturday, April 07, 2007
Friday, April 06, 2007
So prOn is Dangerous After all
Three Japanese naval officers who swapped pornography on their computers triggered a scandal over a possible leak of sensitive data linked to Japan's missile defence system, a newspaper said on Thursday. Police launched a probe last week after a navy officer married to a Chinese woman was found to have taken home a computer disk containing information about the high-tech Aegis radar system, domestic media said.
Aegis is used on Japanese destroyers that are to be fitted with SM-3 missile interceptors from this year as part of the missile defence program. The officer told police he accidentally copied the confidential data onto his computer's hard disk when copying porn from a computer belonging to a crew member from another destroyer, the Yomiuri newspaper reported.
Story here.Wednesday, April 04, 2007
Below the Hole
The no-tolerance policy fits Augusta National's image. The club fancies itself as the most tradition-bound of golf bodies, one that prohibits anything high-tech from disturbing the peace on its grounds. The scoreboards for the Masters are all manually operated. The only prominent clock at Augusta National is a sundial dedicated to Bobby Jones. Blimps are forbidden in the skies overhead. Even electric vacuum cleaners are taboo in the clubhouse.
All of this makes for great theater, as golfers, visitors, and TV viewers are transported back to a world free of Jumbotrons and Gnarls Barkley ringtones. But while the Masters brass has carefully cultivated a technology-hating image, all this Luddism is a façade. Beneath the club's manicured greenery lies an arsenal of technological wonders that keeps the course looking timeless and pristine. Indeed, take a deep enough divot at Augusta National and you'll unearth the most technologically advanced setup in golf.
The greens, for one, are state-of-the-art. Beneath each putting surface is a latticework of pipes, pressurized valves, electric motors, and radio controls.
I asked exactly what he was up to, all he would say was, "data collection." The club's PR department wouldn't elaborate.
Full story here.
From root kit to boot kit: Vista's code signing compromised
At the Black Hat Conference in Amsterdam, security experts from India demonstrated a special boot loader that gets around Vista's code signing mechanisms. Indian security experts Nitin and Vipin Kumar of NV labs have developed a program called the VBootkit that launches from a CD and boots Vista, making "on the fly" changes in memory and in files being read. In a demonstration, the "boot kit" managed to run with kernel privileges and issue system rights to a CMD shell when running on Vista RC2 (build 5744), even without a Microsoft signature.
Experts say that the fundamental problem that this highlights is that every stage in Vista's booting process works on blind faith that everything prior to it ran cleanly. The boot kit is therefore able to copy itself into the memory image even before Vista has booted and capture interrupt 13, which operating systems use for read access to sectors of hard drives, among other things.
More here.
Softer flashlights for LA cops
The new flashlight, developed specifically for the Los Angeles Police Department and expected to be acquired by police forces around the world, replaces the heavy 13-inch (33-cm) metal flashlights controversially used by city officers to strike a car theft suspect three years ago.
More here.
The 7060 LED will be available to the general public in June. More information on Pelican's 7060 is available at www.pelican7060.com.
Tuesday, April 03, 2007
Survey Shows Public Feels Safer in City Spaces Lit by LEDs
Seems like these type of lights would be a win/win for both improved safety/security and power consumption."When “LED City” Raleigh and Cree Inc. turned on new light-emitting diodes (LEDs) in the Avery C. Upchurch Government Complex’s parking garage, people’s opinions about the quality of the lighting improved threefold."More here.
NRO: 40 Years of Reconnaissance
Forty Years of Reconnaissance. This is actually a music video about the NRO. Sample lyrics:
"And we'll be there when you call
Even Friday night's all right
We'll see and hear it all
Taking it on with all our might."
[5min, 37sec]
Sunday, April 01, 2007
KcPentrix 2.0: LiveDVD
Kcpentrix is based on SLAX 5, a Slackware live DVD.
Saturday, March 31, 2007
2006 Operating System Vulnerability Summary
"The summarized coverage of 2006 vulnerabilities by SANS showed the most prevalent attack vectors were not directly against the operating systems themselves.4 However, this article approaches the operating system as an entity in and of itself for analysis of only the vulnerabilities of core features. As such, vulnerability scans were conducted against 2006's flagship operating systems in various configurations to determine weakness from the moment of installation throughout the patching procedure. From Microsoft, testing included Windows XP, Server 2003 and Vista Ultimate. Examinations against Apple included Mac OS9, OSX Tiger and OSX Tiger server.5 Augmenting Apple's UNIX representation, security tests were also performed on FreeBSD 6.2 and Solaris 10. Rounding up the market share, Linux security testing included Fedora Core 6, Slackware 11, SuSE Enterprise 10 and Ubuntu 6.10. Before delving into the specifics of the vulnerabilities, it is helpful to understand the security scene of 2006."
Thursday, March 29, 2007
A Security Vendor Don't
One of the vendors (Core Impact) at ShmooCon got some unwanted attention this past weekend - they had a pretty string of USB light up hubs strung along the front of their table. Since the hubs needed to be powered to light up, they plugged the string into one of their laptops on the table...RenderMan noticed this and happened to have a USB toolkit in his pocket. He was subsequently able to plug his USB key into the string of USB hubs unnoticed and retrieved it a bit later after it had collected password files and other assorted goodies.
The whole event was relayed to the entire audience at the closing ceremonies. It's a nice lesson on what not to do when exhibiting at events such as a "hacker" con...
Wednesday, March 28, 2007
Firefox Add-on - Tamper Data
Tuesday, March 27, 2007
Sunday, March 25, 2007
ShmooCon 07 - Day 3
While his talk didn't really focus on Online Banking that much, it was a good primer on non-evasive testing of web facing applications. Chuck fits the Mandiant profile - clean cut - smart guy... The tool that Chuck used in many of his examples is Paros. Hs slides should be posted on his site soon.
I also sat in on on Joel Bruno and Eric Smith's (PSKL) talk on - VOIP, Vonage, and Why I Hate Asterisk. They have done some neat work on RTP playback and in particular Vonage VOIP calls. You can find the SIPinator v1.0 code here. They also made a nice/funny commercial for ShmooCon.
The work the folks at the OLPC project are doing is way cool. Not going into details here, but ck them out.
Quick Summary -
Can't say enough about what a great value ShmooCon is and while not every session was exceptional, the event as a whole was. More highlights in the coming days as I parse thru notes etc...
Saturday, March 24, 2007
ShmooCon 07 - Day 2
First things first, the Wirefly Marathon messed-up traffic this AM royally!The rest of the day was good - any Shmoo day is a good day...
One session was a bit different - Michael Schearer from The Church of WiFi presented: A Hacker in Iraq. A Naval Flight Officer - theprez98 talked about his experiences during his 9-month tour in Iraq embedded with Army units on the ground. He put his expertise in electronic warfare to good use against the biggest threat to coalition forces - the improvised explosive device (IED).
He also mentioned on how one of the best sources of real news from the war are the military blogs.
The Hacker Arcade was in full swing today along with Deviant and company's lock picking area. There are a couple of Nitro boxes running in the conf. NOC wonder who gave them that ideal.
Some of the security podcast folks were recording - I saw the CyberSpeak folks in action... look for Shmoo reports from Sploitcast and Hak.5.
More fun on Sunday...
Friday, March 23, 2007
ShmooCon 07 - Day 1
Eoin Miller and Adair Collins Auditing Cached Credentials with Cachedump and Johnny Long's No-Tech Hacking were probably my two favorites. Johnny's no-tech hacking talk was excellent in both content and presentation. A good deal of it focused on physical security and on demonstrating what an important hacking tool the power of observation can be.
Aviel Rubin ended things nicely with an exelent keynote. A copy of his presentation can be found here.
Dr. Rubin vs. Dr. Cole... my money is on Dr. Rubin
Thursday, March 22, 2007
Tool Time - Nessj
Nessj is an application/network security scanner client for Nessus and Nessus compatible (OpenVAS etc.) servers. In addition to an improved user interface, it provides session management with templates, report generation using XSLT including charts/graphs, and vulnerability trending. It is cross-platform, with platform specific releases available for Linux, OSX, and Windows, written in Java using SWT for a native experience, and it is open-source. It's provided by Intekras, Inc. under the Clarified Artistic License.Get it here.
Wednesday, March 21, 2007
Top 10 U.S. Government Web Break-ins of All Time
Tuesday, March 20, 2007
Identity Theft is Getting more Businesslike
Speaking of business - can you think of a better way to sell your security products than to preach doom and gloom? How neutral do you think Symantec is when the worse things are, the better life is for them?Via their semiannual Internet Security Threat Report - Symantec reported that much of the malicious computer code they identified was compiled, or translated into usable software, during standard, 9-to-5 work shifts in the country of origin.
"The hobby-horse hacker is a thing of the past. These guys work business hours,'' Huger said. "It's pretty organized, which is the scary part. Now we're seeing a well-oiled machine for stealing data.''
Among the other items reported was that China had 26 percent of the world's bot-infected computers, more than any country, a statistic mostly explained by the torrid growth of the Chinese technology industry. Also noted was that more than half of all underground economy servers known to Symantec were based in the United States.
However, a recent report from Symantec competitor McAfee tells us that Internet domains from Romania, Russia, and the tiny island of Tokelau are among the riskiest.What we do know is that phishing and spam is up... now apparently we just need a way to figure out where it is coming from. Unfortunately it is more often the destination that counts, not the journey and the US might be the way and/or the means, but it certainly isn't the end.
Sunday, March 18, 2007
Super Bowl Hack?
Prank or Hoax? What do you think? If a hoax, it's was a very nice job. If a prank, it was quite the stunt. Either way, it's worth a look."To promote the new ZUG book, PRANK THE MONKEY, we wanted to show how easy it would be to broadcast a secret terrorist message not just on national TV, but on TV's biggest event. "
Saturday, March 17, 2007
Friday, March 16, 2007
Friday Fun - WiFi Vibrator
I Make Projects posted plans for "giving yourself a sixth sense for wireless networks" through a small wearable device. It's made from a cannibalized Wi-Fi detector, microcontroller, vibrating motor, and a bit of custom electronics.
Hackers get bum rap for corporate America's digital delinquency
If Phil Howard's calculations prove true, by year's end the 2 billionth personal record -- some American's social-security or credit-card number, academic grades or medical history -- will become compromised, and it's corporate America, not rogue hackers, who are primarily to blame.
Howard and Erickson also found that:
- Malicious intrusions by hackers make up a minority (31 percent) of 550 confirmed incidents between 1980 and 2006; 60 percent were attributable to organizational mismanagement such as missing or stolen hardware; the balance of 9 percent was due to unspecified breaches.
- Likely as a result of California's law and similar legislation adopted by other states, the number of reported incidents more than tripled in 2005 and 2006 (424 cases) compared to the previous 24 years (126 cases).
- The education sector, primarily colleges and universities, amounted to less than 1 percent of all lost records, but accounted for 30 percent of all reported incidents.
Wednesday, March 14, 2007
File-sharing Software could Jeopardize National Security
"This report also reveals that these filesharing programs threaten more than just the copyrights that have made the United States the world’s leading creator and exporter of expression and innovation: They also pose a real and documented threat to the security of personal, corporate, and governmental data."
"But such condemnations just beg a more fundamental question: Why do children, grandparents, and poor single mothers end up sharing hundreds or thousands of infringing files inadvertently?"
Tuesday, March 13, 2007
The Silver Bullet Security Podcast
How can you go wrong? When you have vicodin, music and security...On the 12th episode of The Silver Bullet Security Podcast, Gary talks with Becky Bace, Advisor to Venture Capital firm Trident Capital. Becky spent twelve years at the NSA working on intrusion detection and cryptography from 1984 until 1996, followed by a stint at Los Alamos National Laboratory. Gary and Becky discuss growing up in rural America, explosives, and Becky’s Jimmy Hoffa sponsored college funding situation. They also talk about the evolution of security cirricula in academia, rampant commercialization of computer security, Becky’s involvement in tracking down the notorious Kevin Mitnick, vicodin-induced creativity, and eclectic music.
French Pick Ubuntu
When French MPs and their assistants return from their summer break this June, they will conduct parliamentary business on PCs running Ubuntu. From the next session of parliament, 1,154 desks will feature the Linux-based PCs.
More here.
Friday, March 09, 2007
The 50 Most Important People on the Web
PC World's list of the 50 most important people on the web.Personal favorites:
31. Bruce Schneier - Cryptographer
32. Kevin Rose - Founder, Digg
47. Leo Laporte - Creator, This Week in Tech (TWiT) podcast
Who did they miss?
Thursday, March 08, 2007
Independent Comparatives of Anti-Virus software
Surprise! Microsoft's OneCare was on the bottom of the list...
BTW when the was the last time you had a virus on your system? Seems that a little common sense can go a long way in keeping a system clean, but don't tell the AV vendors that.
Network Information with Javascript
Sunday, March 04, 2007
Police use MySpace
He's about 60, with graying hair and a bald spot on the crown of his head -- and he looks forward to meeting "more bank tellers so that I can continue my crime spree!!!"As police continue searching for a suspect in four bank robberies across Arkansas, one local department has taken the unusual step of creating the man a profile on the social networking Web site MySpace, hoping someone will recognize him.
Story here.
Saturday, March 03, 2007
True? BBC Reported Building 7 Had Collapsed 20 Minutes Before It Fell
Revealing, shocking video shows reporter talking about collapse with WTC 7 still standing in background. Google has removed the clip.More here.
Friday, March 02, 2007
Friday Fun - School Security
As authorities stormed into a middle school office to arrest an alleged meth-dealing principal inside, they found an even more surprising scene inside.Story here.
Sources said 50-year-old John Acerra, of Allentown, was naked and watching gay pornography when they arrived at Nitschmann Middle School in Bethlehem to arrest him on Tuesday.
Acerra also had sex toys, drugs, cash and a pipe in his school office when authorities stormed his office, the sources added.
Wednesday, February 28, 2007
What a day...
- Air Force Officer Found Guilty of Raping 4 Men
- Miracle U.K. Baby Comes Back From the Dead
- Rats Chew Off Newborn Baby's Nose, Upper Lip in Kansas City, Mo., Apartment
- Human Head, Hand Found Along San Diego Freeway After Unidentified Body Found in River
- Wolfgang Puck Catering May Have Exposed Sports Illustrated's Swimsuit Issue Party Revelers to Hepatitis
Monday, February 26, 2007
Sunday, February 25, 2007
Hacking with Metasploit on a Nokia N800
"Its not as fast as a laptop but it's still pretty quick," Maynor said, explaining that he was able to break into a Windows 2000 SP4 server using a Metasploit exploit.
David's blog here.
Saturday, February 24, 2007
Lab Rats! Episode 61: Windows Security 101
Episode 61: Windows Security 101
Release date: February 19, 2007
In episode 61, Andy and Sean show you how to tighten security on Windows XP and Vista PCs.
Friday, February 23, 2007
Friday Fun - Foul-mouthed CDs get Blown in Church
Three CD players hidden under a cathedral's pews blared sexually explicit language in the middle of an Ash Wednesday Mass, leading a bomb squad to detonate two of the devices.Authorities determined the music players were not dangerous and kept the third one to check it for clues, said police Capt. Gary Johnson.
The CD players, duct-taped to the bottoms of the pews, were set to turn on in the middle of noon Mass on Wednesday at the Roman Catholic Cathedral Basilica of St. Francis of Assisi.
More here.
Wednesday, February 21, 2007
Home Security - When one sword in hand deserves another...
Who said chivalry was dead..."It was a woman screaming," he recalled Tuesday. "She was screaming for help."
Sword in hand, he bounded up the stairs, kicked in the door and confronted a man who turned out to be alone - watching a pornographic movie.
"Now I feel stupid," Van Iveren said.
Worse yet, police seized his sword - a family heirloom - carted him to jail and referred the case to a prosecutor who charged Van Iveren with three criminal counts.
Full story here.Tuesday, February 20, 2007
Smokers may be the weak IT security link
The company hired NTA to test if it was possible to get inside the premises without proper identification, Hills said. The penetration tester waited until the smokers finished their break, then slipped in through the unlocked door, which wasn't the main one but publicly accessible.
The tester -- who skirted past other employees by saying the IT department had sent him -- made his way to a meeting room, where he hooked up his laptop to the company's VOIP (voice over Internet Protocol) network, Hills said. The tester could have launched a denial-of-service attack or intercepted phone calls.
The Silver Bullet Security Podcast #11
Get it here.
Sunday, February 18, 2007
Product Spotlight - USB Keylogger
Got a spare $80.00 bucks in your pocket?2 Megabytes (16 Mbit) over 2,000,000 keystrokes
(around 1 years worth of intensive typing)
This keystroke recorder has up to 8 Megabytes memory capacity, organized into an advanced flash file system. Super fast data retrieve is achieved by switching into Flash Drive mode for download. Completely transparent for computer operation, no software or drivers required. Supports national keyboard layouts.
Buy it here.
Saturday, February 17, 2007
Missing FBI Laptops Still a Problem
Nice example for the rest of us...Three or four FBI laptop computers are lost or stolen each month and the agency is unable to say in many instances whether information on the machines is sensitive or classified, the Justice Department's inspector general said Monday.
Of the 160 laptops lost or stolen over a 44-month period, 10 contained sensitive or classified information. The bureau did not have records on whether 51 others contained such data.
In a report five years ago, the inspector general said 354 weapons and 317 laptop computers were lost or stolen during a 28-month review.
Full Story form the AP here.
Home Security - Apperanntly TV can Kill You!

Mummified body found in Hampton Bays home
Southampton police responding to burst water pipes in a Hampton Bays home found the mummified body of the owner -- dead for more than a year -- sitting in a chair in front of a television, officials said Friday.Full Story.
The television was still on.
Vincenzo Ricardo, 70, appeared to have died of natural causes in his home on Wakeman Road, said Dr. Stuart Dawson, Suffolk deputy chief medical examiner.
The medical examiner's office considered his body mummified because the lack of humidity in his home preserved his features, morgue assistant Jeff Bacchus said.
Judge Limits New York Police Taping
In a rebuke of a surveillance practice greatly expanded by the New York Police Department after the Sept. 11 attacks, a federal judge ruled yesterday that the police must stop the routine videotaping of people at public gatherings unless there is an indication that unlawful activity may occur.NY Times story here.
Four years ago, at the request of the city, the same judge, Charles S. Haight Jr., gave the police greater authority to investigate political, social and religious groups.
In yesterday’s ruling, Judge Haight, of United States District Court in Manhattan, found that by videotaping people who were exercising their right to free speech and breaking no laws, the Police Department had ignored the milder limits he had imposed on it in 2003.
Friday, February 16, 2007
Friday Fun - Batman Sighting Puts Schools on Lockdown
SCOTTSDALE, Ariz. (AP) -- To an Arizona middle school, Batman! Three schools in the north Phoenix suburb of Cave Creek were on lockdown for about 45 minutes Wednesday morning after a student at Desert Arroyo Middle School reported seeing a person dressed as Batman run across campus, jump a fence and disappear into the desert, Scottsdale police Sgt. Mark Clark said.More here.
Wow, lockdown.... Holy panic Batman!
Thursday, February 15, 2007
Fine for Stolen Laptop
The fine follows the theft of a laptop from a Nationwide employee's home which contained confidential customer data.
The Financial Services Authority (FSA) found security was not up to scratch after the man had put details of nearly 11 million customers on his computer.
The FSA also found that the Nationwide did not start an investigation until three weeks after the theft occurred.
Full story here.
Do you think fines on this side of the pond would help?
Wednesday, February 14, 2007
Substitute Teacher Faces Jail Time Over Spyware
A 40-year-old former substitute teacher from Connecticut is facing prison time following her conviction for endangering students by exposing them to pornographic material displayed on a classroom computer.Brian Krebs from the Washington Post, has an update on the case here.
Tuesday, February 13, 2007
Hiatus is over, posting returns....
TRENTON, Ohio -- Two Edgewood High School students were arrested Thursday and accused of hacking into the school district’s Web site to schedule an unplanned – and unauthorized – snow day.
School officials had originally planned a one-hour delay for Monday morning, following an established procedure, so they were surprised to see an announcement Sunday night that classes were canceled.
Full story here.
"I asked for a car, I got a computer. How's that for being born under a
bad sign?" - Ferris Bueller
Saturday, February 03, 2007
Hack5 Episode 2×07 LIVE February 3rd
The folks from hak5 will be broadcasting live today...
We’re excited to be announcing that episode 2×07 will be broadcasted LIVE over the Internets this February 3rd at 3:00 PM EST (-5 GMT). This schedule should work better for our European viewers.
We welcome you to sign up at hak5.org/live if you have a question for the cast and would like to be a guest on the show. There you can also find information on the stream and connecting.
Friday, February 02, 2007
Friday Fun - Humvee driving in Iraq
On the one hand, the story with this video says that American soldiers have to drive like this to limit the risk of attack. Some in the comments say its arrogant, and it’s no wonder Iraqis hate Americans. Others says if the driver slows down, gunfire would start, and thats not safe for anyone. What do you think?
Thursday, February 01, 2007
Monday, January 29, 2007
Securing a 'Buzz' - Just what the Doctor Ordered...
Dr. Robert Bohannon wants you in his world. It's fast, upbeat, jovial and driven by caffeine -- lots of it.
But four to six cups of coffee a day aren't enough for Bohannon. And he believes others share his need for more options when it comes time to pursue that caffeine buzz.
So the molecular scientist who moonlights as a café owner developed a way to add caffeine to baked goods, one that eliminates the natural, bitter taste of caffeine.
"This gives people the opportunity if they want to have a glass of milk and want to have caffeine. It will get them going," Bohannon said.
The amount of caffeine in his creations can vary, but Bohannon can easily put 100 milligrams of caffeine -- the equivalent of a 5-ounce cup of drip-brewed coffee -- into the treats he plans to market under the "Buzz Donuts" and "Buzzed Bagels" names.
Full story here.
X-ray cameras 'see through clothes'
From across the pond...The Government is considering installing X-ray cameras on lampposts to spot armed terrorists and other criminals.
According to a leaked memo seen by The Sun, "detection of weapons and explosives will become easier" if the scheme drawn up by Home Office officials is adopted.
However, officials acknowledged that it would be highly controversial as the cameras can "see" through clothing.
"The social acceptability of routine intrusive detection measures and the operational response required in the event of an alarm are likely to be limiting factors," the memo warned.
"Privacy is an issue because the machines see through clothing."
Full story here.Sunday, January 28, 2007
Kaspersky Lab releases an article about Vista and security
You can read the full version of the article, Vista vs. Viruses, on Viruslist.com.
Saturday, January 27, 2007
National Security
While you were sleeping (Bush took over the Government)
United States President stealthily took over the Federal Government last week through a new executive order last week that takes away all autonomy from Agencies, according to public interest organizations.
The order amends a series of previous executive orders that culminated in Executive Order No. 12,866, which the White House has used to give itself the power to review regulations before they can be officially published in the Federal Register.
Full story here:
Friday, January 26, 2007
Some "Brief" Friday Fun
From the website:The "Brief Safe" is an innovative diversion safe that can secure your cash, documents, and other small valuables from inquisitive eyes and thieving hands, both at home and when you're traveling. Items can be hidden right under their noses with these specially-designed briefs which contain a fly-accessed 4" x 10" secret compartment with Velcro closure and "special markings" on the lower rear portion. Leave the "Brief Safe" in plain view in your laundry basket or washing machine at home, or in your suitcase in a hotel room - even the most hardened burgler or most curious snoop will "skid" to a screeching halt as soon as they see them. (Wouldn't you?) Made in USA. One size. Color: white (and brown).
To add realistic smell, check out "Doo Drops".
Thursday, January 25, 2007
One Hacker Kit Accounts For 71% Of Dec Attacks
Exploit Prevention Labs launched a line of exploit detection tools -- LinkScanner Lite and LinkScanner Pro -- in November. The former is free, while the latter is priced at $19.99 for a one-year subscription.
More info here:
Tuesday, January 23, 2007
Low Tech Fix for High Tech Problem
Handheld Paper Shredder The Shredder Hand is the most convenient and compact way to get rid of those expired coupons, unwanted papers and old, confidential paper documents. At first glance it's just a pair of scissors, but with further exploration you will see that you can shred documents, or just parts of documents, without any electric or battery-operated power. Being the cheapest shredding option around it is amazing to think that it also has a long life and is small enough to be transported easily from the home to the office or classroom.
Monday, January 22, 2007
The Silver Bullet Security Podcast


The tenth episode of The Silver Bullet Security Podcast features a panel discussion with the Fortify Software Technical Advisory Board, several of whom have been featured on previous episodes. The group discusses what commercial software tools can learn from academic research, the state of software security in China, real world lessons learned while using static analysis tools, and software security pedagogy.
Sunday, January 21, 2007
Aircrack-ng 0.7 is Released
Aircrack-ng is the next generation of aircrack with lots of new features (planned and wanted).
Saturday, January 20, 2007
Risky Business - Greynets
A new FaceTime study reports -
2007's Biggest Risk: Employees Undermining Corporate Security
The danger of this new breed of malware is compounded by the increasingly risky behavior of today's employees, who frequently introduce consumer greynet applications onto the corporate network– most often without the sanction of their IT department. The user is squarely at the cornerstone of enterprise security concerns, according to FaceTime's Second Annual Greynets Survey (October, 2006). The survey revealed that:
- Four in ten end users (39%) believe they should be allowed to "install the applications they need on their work computers," independent of IT oversight or policy.
- Fifty-three percent of end users report they "tend to disregard" company policies that govern greynet usage, specifically IM and peer-to-peer file sharing.
- Eight in ten IT managers are at locations that have experienced greynet-related attacks within the last six months
- The number of greynet applications installed on a typical enterprise network have increased dramatically; work locations where eight or more greynet applications are in use have doubled, growing from 20 percent of all locations in 2005 to 41 percent in 2006.
- Sixty percent of managers report that within the past six months, security attacks have been more likely to have invisible effects (like keyloggers) rather than outcomes apparent to the end user, such as a hijacked browser, making compromised PCs more difficult to detect.
Friday, January 19, 2007
Swedish bank hit by 'biggest ever' online heist
One - this wasn't an online bank heist, this was just a plain old dumb user heist.
Nordea spokesman for Sweden, Boo Ehlin, said that most of the home users affected had not been running antivirus applications on their computers.Two - why should the bank be responsible for this? If I break into your house and steal your checkbook and/or a credit card, is the bank responsible? How is this different?Ehlin blamed successful social engineering for the heist, rather than any deficiencies in Nordea's security procedures.
"It is more of an information, rather than a security problem," said Ehlin. "Codes are a very important thing. Our customers have been cheated into giving out the keys to our security, which they gave in good faith."
The bank has borne the brunt of the attacks and has refunded all the affected customers.
Thursday, January 18, 2007
RF Jammer
Ninja Strike Force member Lady Ada has posted a design for a self-tuning, microprocessor controlled, wide band RF jammer.This website details the design and construction Wave Bubble: a self-tuning, wide-bandwidth portable RF jammer. The device is lightweight and small for easy camoflauging: it is the size of a pack of cigarettes.
Lost HOPE?
HOTEL PENN THREATENED WITH DEMOLITION - HOPE CONFERENCES IN JEOPARDY
We received this disturbing news earlier in the month. Apparently the realty company that owns the Hotel Pennsylvania, site of our HOPE conferences, wants to tear down the historic hotel and replace it with a huge financial tower. Such a move could spell the end of HOPE.
The Hotel Pennsylvania was built in 1919 and has a very rich history. It has been home to many a "big band" concert in its early years and was the inspiration for the famous Glenn Miller song "PEnnsylvania 6-5000," a phone number that still rings at the Hotel Pennsylvania switchboard. The building itself, as any HOPE attendee knows, is filled with hidden corridors, rooms, and even floors. Being right across the street from Penn Station (New York's main train station), it's extremely easy to get to for those coming to New York for the first time. And because it's not an overly expensive place to stay, it's proven very popular for travelers from all over the world.
We've hosted five HOPE conferences at the Hotel Pennsylvania since 1994 and the next one is set for 2008. In preparation for this, and to discuss the fate of the hotel among other things, we are today launching a web-based forum for all things HOPE-related. You can reach this brand new forum at talk.hope.net.
Wednesday, January 17, 2007
Secure Relationship?
1 in 8 men would dump their girlfrend for an iPod
Yes, this is a fairly silly survey conducted on behalf of a company that wants you to use it to buy more gadgets. But still, the fact that one in eight men would apparently consider swapping their partner for the latest iPod, widescreen TV, home cinema system or fridge freezer is pretty shocking.
Tuesday, January 16, 2007
Verisign's ongoing Quarterly Vulnerability Challenge
Vulnerability Challenge Ground Rules:
- The vulnerability must be remotely exploitable and must allow arbitrary code execution in a default installation of one of the technologies listed above
- The vulnerability must exist in the latest version of the affected technology with all available patches/upgrades applied
- 'RC' (Release candidate), 'Beta', 'Technology Preview' and similar versions of the listed technologies are not included in this challenge
- The vulnerability must be original and not previously disclosed either publicly or to the vendor by another party
- The vulnerability cannot be caused by or require any additional third party software installed on the target system
- The vulnerability must not require additional social engineering beyond browsing a malicious site
Sunday, January 14, 2007
Security Now 74: Peter Gutmann On Vista Content Protection
Steve Gibson's Security Now podcast just aired a very good interview with Peter Guttman, the security researcher who wrote "A Cost Analysis of Windows Vista Content Protection".Saturday, January 13, 2007
Personal Security - Dirty Hospitals
Two million patients are infected in hospitals each year and 90,000 of those Americans die.Of every 20 people who go into a U.S. hospital, one of them picks up something extra: an infection. It's a lousy card to draw. Infection stalls recovery, sometimes requiring weeks of intravenous antibiotics or a grueling round of surgeries to remove infected tissue. And for 90,000 Americans a year, the infections are a death sentence.
Full story here.
Friday, January 12, 2007
WTF or TGIF... It's Friday - Teacher found guilty of exposing kids to smut
State Prosecutor David Smith said he wondered why Julie Amero didn't just pull the plug on her classroom computer.The six-person jury Friday may have been wondering the same thing when they convicted Amero, 40, of Windham of four counts of risk of injury to a minor, or impairing the morals of a child. It took them less than two hours to decide the verdict. She faces a sentence of up to 40 years in prison.
Full story here.
Those poor kids! I imagine they will be scared for life and their morals impaired forever...
Thursday, January 11, 2007
Secure World? Not
The surge in troops will do nothing to change the underlying dynamics that continue to drive the violence in Iraq: deep-seated religious, ethnic, and tribal divisions and hatreds; and a high and rising level of antipathy among Iraqis across the sectarian divide towards the continuing occupation of their country by Western armies...
Wednesday, January 10, 2007
Bedtime reading...
Metaeye defines itself as metamorphic security that relates to definite change in the structural components of computer security with the passage of time and to incarnate itself by providing protective and innovative solutions.The Metaeye generically sets an element of metamorphism to this present security world.
Did the NSA Fix Vista?
Things that make you go hmmm... Wonder what else they have stuck in there?When Microsoft introduces its long-awaited Windows Vista operating system this month, it will have an unlikely partner to thank for making its flagship product safe and secure for millions of computer users across the world: the National Security Agency.Full story here.
For the first time, the giant software maker is acknowledging the help of the secretive agency, better known for eavesdropping on foreign officials and, more recently, U.S. citizens as part of the Bush administration's effort to combat terrorism. The agency said it has helped in the development of the security of Microsoft's new operating system -- the brains of a computer -- to protect it from worms, Trojan horses and other insidious computer attackers.
That's Nice... Do Something That Looks Illegal, But Isn’t, Then Sue
A U.S. college student imprisoned for three weeks for trying to take flour-filled condoms onto an airplane has settled her lawsuit against Philadelphia for $180,000, a city spokesman said on Friday.
Janet Lee, 21, a student at Bryn Mawr College in Pennsylvania, was arrested at Philadelphia International Airport in 2003 after police and security officials thought the flour was an illegal drug.
She was held in Philadelphia on drug-trafficking charges and released only when tests proved the substance in the three condoms was flour.
The condoms, which are sometimes used to smuggle drugs, were a joke among the students, and Lee was taking them home to Los Angeles.
Her civil rights case against Philadelphia, which had been set to go to trial on Thursday, was settled for $180,000, said Ted Qualli, spokesman for Philadelphia Mayor John Street.
Tuesday, January 09, 2007
System/Software Inspection Tool
Feature Overview - The Secunia Software Inspector:
* Detects insecure versions of applications installed
* Verifies that all Microsoft patches are applied
* Assists you in updating your system and applications
* Runs through your browser. No installation or download is required.








