Friday, October 07, 2005

It Never Ceases to Amaze Me... (California at its Best)

Not much to say about this except what are people thinking when they create websites like this?

Provides an easy way to make your very own fake VIN tags or...

Try a couple of vanity plates... Something like CISSP or MCSE or maybe one that might be owned by someone popularized by a TV show etc. Once you have the VIN go to carfax and get the complete history on the vehicle...

Fridays are for Fun!

Secure Manhood - Man dubbed "ball-less wonder" after losing matches to female

A male caddy who lost two golf matches to a female coworker was subjected to a barrage of insults questioning his manhood and sexual preference, according to a lawsuit filed against a New York country club by the federal Equal Employment Opportunity Commission. According to the EEOC complaint, a copy of which you'll find below, Eugene Palumbo was denigrated in newsletters distributed at Long Island's Tallgrass Golf Club, where he caddied. The newsletters mocked Palumbo as a "ball-less wonder" and recommended, the EEOC added, that he move to "a particular summer vacation spot that is generally known to have a large gay population." Oh, and there was a reference to Palumbo, 25, doing "lap dances" for unnamed "boys." The EEOC's September 30 complaint, which does not specify the monetary damages sought on Palumbo's behalf, seeks a permanent injunction barring Tallgrass from engaging in any future discriminatory employment practices. (5 pages)

Thursday, October 06, 2005

Nessus 3 will be Available Free of Charge, but...

A few weeks away from releasing Nessus 3.0.0, they are looking for testers. They also announced that Nessus 3 will be available free of charge, including on the Windows platform, but will not be released under the GPL.

Bruce Schneier on Phishing

Financial companies have until now avoided taking on phishers in a serious way, because it's cheaper and simpler to pay the costs of fraud. That's unacceptable, however, because consumers who fall prey to these scams pay a price that goes beyond financial losses, in inconvenience, stress and, in some cases, blots on their credit reports that are hard to eradicate. As a result, lawmakers need to do more than create new punishments for wrongdoers -- they need to create tough new incentives that will effectively force financial companies to change the status quo and improve the way they protect their customers' assets.

The Internet is Broken — Weird Situation Evolving

It appears as of today that the Internet itself is now two separate networks and some parts of the Internet can not talk to other parts. This is not a temporary outage. A major communication company, Level 3 has cut all traffic with another major communication company Cogent Communications.

I’ll be surprised if someone isn’t in court today asking for an emergency injunction to get this fixed.

The bottom line is that for now people who get their service from providers using Level 3 can’t go to the web sites who get their service from Cogent and vice versa. This also affects peer to peer applications like Chat and some kinds of voice over IP connections between Level 3 and Cogent customers.

The decision to disconnect is that of Level 3. They are the ones who pulled the plug fracturing the internet.

Related links:
Slashdot

Cogent Website

C-Net story

Wednesday, October 05, 2005

UK Study Shows Security Consultants' Rates are Rocketing

A massive increase in demand has seen security consultants' pay rocket by 25 percent over the past year, according to research...

Pay for qualified security consultants has soared over the past year as budgets return and demand grows around the critical issues of application and system security.

On average, security consultants are currently charging 25 percent more year-on-year, cashing in on demand in areas such as application testing, compliance and mobile device management as well as emerging technologies such as VoIP and Wi-Fi.

Skills such as penetration testing, computer forensics and ethical hacking are also increasingly in demand. With too few qualified consultants and high demand for their time, it is a situation in which the lucky few can charge a premium for their services.

Iraq Security - TDS on Iraq and our Generals

There have been a lot of questions being asked about the state of the Iraqi forces and some of the answers have not meshed with the facts.

Stewart takes a look at John McCain's reaction to some of the things being said by Rumsfield and the top generals that just don't seem to jive.


Windows: (Cut and Paste)
http://movies.crooksandliars.com/TDS-Iraq-Generals-MCain-10-03-05.wmv

QuickTime: (Cut and Paste)
http://movies.crooksandliars.com/TDS-Iraq-Generals-MCain-10-03-05.mov

Turning Off the Cameras Down Under - Call for Ban on Worker Surveillance

A ban on surveillance in toilets, change rooms, showers and bathrooms? To heck with global warming and terrorism - this is atrocious!
The final report of the Law Reform Commission has called for a new regulator to oversee the covert and overt monitoring of employees in the workplace.

The report, released today, called for new laws which would require employers to seek the permission from the regulator to test workers for drugs and alcohol and to install intrusive surveillance devices.

The report also called for the regulator to issue mandatory codes of conduct to cover video surveillance and monitoring of worker's emails.

The chairman of the commission, Marcia Neave, said an outright ban on surveillance in toilets, change rooms, showers and bathrooms was also needed to protect the basic dignity of working people - even if employees agreed to such a move.

Tuesday, October 04, 2005

N.C. Troopers Catch Ambulance Thief Transporting Deer with IV

A man reported missing from a Florida hospital was found in North Carolina dressed like a doctor and driving a stolen ambulance with a dead deer wedged in the back, authorities said.

Leon Holliman Jr., 37, was reported missing from a River Region Human Services facility in Jacksonville last month. The North Carolina State Highway Patrol found him driving the ambulance with the deer on Sunday.

``I don't know how the man got it up in there,'' said Sgt. Robert Pearson. ``It was a six point buck.''

It wasn't known where Holliman got the deer, which had been dead for some time, Pearson said.

Authorities tracked the stolen ambulance through three rural North Carolina counties and one county in southern Virginia before its tires were punctured and it wound up in a ditch, Pearson said.

Holliman was admitted to a North Carolina hospital for a psychiatric evaluation. Police said they would decide whether to charge Holliman after that evaluation is complete.

Underwater Security - The Coast Guard's Integrated Anti-Swimmer System

The Coast Guard announces the availability of the Draft Programmatic Environmental Assessment (PEA) of the Integrated Anti-Swimmer System (IAS). The Coast Guard is proposing to deploy and operate the IAS for temporary periods at various U.S. ports throughout the U.S. Maritime Domain, when necessary. The purpose of the Proposed Action is to increase the Coast Guard's ability to detect, track, classify, and interdict, if necessary, potential underwater threats and as a result, protect personnel, ships, and property from sabotage and/or other subversive acts.

Monday, October 03, 2005

How Would You Respond to a Disaster?

As Michael Brown showed us (perhaps for different reasons) it ain’t easy running FEMA. Think you can do better? Try this interactive game created by the BBC for a TV show on supervolcanos.

Sunday, October 02, 2005

Secure Handling (or what GP needs to know)

A study by the American Society for Microbiology has found, that one out of four men leave public rest rooms without washing their hands. Women are cleaner: Ninety percent wash their hands.

WHAX and Auditor = Backtrack

The folks over at Remote-Exploit were recently dropped from Google Adsense and need funding. Why should you be concerned? They’ve recently rolled the excellent Auditor and WHAX live cds into a new distro called Backtrack. Why be concerned? They were dropped for “Hacking/cracking content”.

Friday, September 30, 2005

Debian Firewalls

Sitting around like a Dan on the weekend with nothing to do? Then isn't it time you built that firewall you have been missing?
Most networks these days run behind some type of network router/firewall device. Most commonly home office and SOHO networks use small firewall/routers made by companies such as Linksys, D-Link, and Netgear to provide their network connectivity. The problem is these devices are often weak, underpowered, and feature limited. The solution? Building your own!

Thursday, September 29, 2005

Sniffing the Air (or How I learned to stop worrying and love the Pig)

For anyone who wants to learn more about wireless network traffic "sniffing". Here is a pretty good how to guide.

Wednesday, September 28, 2005

Defeating Citi-Bank Virtual Keyboard Protection

Good site for vulnerability research, including PoCs.

Description: Early this year, Citi-Bank introduced the concept of Virtual Keyboard to defend against malicious programs like keyloggers, Trojans and spywares etc. However, the Virtual Keyboard concept can be easily defeated by using Win32 APIs to access HTML documents. Refer the PoC (Proof of Concept) for more details.

More details can be found at:

http://xforce.iss.net/xforce/xfdb/21727

http://www.us-cert.gov/cas/bulletins/SB05-222.html

http://www.hackinthebox.org/modules.php?op=modload&name=News&file=article&sid=17684

http://www.virus.org/Article151.html


Download link of the PoC:

http://www.hackingspirits.com/vuln-rnd/defeat-citibank-vk.zip

BatteryUniversity.com

Things that every geek should know... Battery University is an on-line resource that provides practical battery knowledge for engineers, educators, students and battery users alike. The papers address battery chemistries, best battery choices and ways to make your battery last longer.

The presentations are easy-to-read and are limited to about 1000 words. The material is based on the book Batteries in a portable World - A handbook on rechargeable batteries for non-engineers, and is written in condensed form.

Gas Thief Found Asleep at the Scene of the Crime

A Swifty gas station in Muncie wasn't open for business when the driver of a white van attempted to fill up.

But 38-year-old Brad Hodson wasn't filling his tank. Police say a 55-gallon barrel was in the back of his van.

Muncie Police Chief Joe Winkle explains, "He had pulled up next to the underground tank and had put a homemade siphoning hose in the underground tank."

Hodson used batteries to do the actual siphoning. But in the process, Chief Winkle says Hodson apparently fell asleep. "The fact it was 5:30 in the morning, he may have just got tired trying to fill that large drum up with gasoline. I'm not sure how fast that happened, but it probably took a little while and he probably just sat back."

And that's how the station manager discovered Hodson when he came to open shop for the day just after five a.m.

Tuesday, September 27, 2005

Think Your Anonymizer is Foolproof?

Internet users hoping to protect their privacy by using Web anonymizers, false identities and disabled cookies on their computer's Web browser have something new to think about – a patent filed by the National Security Agency (NSA) for technology that will identify the physical location of any Web surfer.

A patent granted last week, describes a process based on latency, or time lag between computers exchanging data, of "numerous" known locations on the Internet to build a "network latency topology map" for all users. Identifying the physical location of an individual user could then be accomplished by measuring how long it takes to connect to an unknown computer from numerous known machines, and using the latency response to display location on a map.

Monday, September 26, 2005

Dolphin Assassins Menace Gulf of Mexico

Every once in a while, a story based on pure speculation starts circulating, and picked up and re-picked up by otherwise legitimate media outlets as if it were based on actual facts. Here comes a doozy. The UK's Guardian is reporting that killer dolphins, trained by the Navy in the art of DEATH and armed with poison darts may have escaped their tanks during Katrina and are now hunting down surfers and divers in the Gulf of Mexico...
 
Copyright 2018 e2e Security. Powered by Blogger Blogger Templates create by Deluxe Templates. WP by Masterplan