Google: "State-sponsored attackers may be attempting to compromise your account"
Google has said that it will start to proactively warn internet users when it suspects that "state-sponsored attackers" have attempted to break into accounts.
View ArticleWebDAV Server to Download Custom Executable or MSF Generated Executables
Metasploit comes with dllhijacker moduleThe current module does not allow you to download exe's, in fact these are specifically blacklisted. This makes sense because that's not what the exploit is for....
View ArticleSimplifying Firewall Audits and Ensuring Continuous Compliance: Part 4 of 6
We've now crossed over the halfway point in our series on simplifying firewall audits and ensuring continuous compliance and that brings us to a major housekeeping project that admitedly is not fun,...
View ArticleOSSEC Community Symposium, July 12-13 2012
Please join me at the first OSSEC Symposium, sponsored by Trend Micro. This is a forum for the OSSEC community to come together and discuss all things OSSEC. We’ll not only talk about what makes OSSEC...
View ArticleLinkedIn Passwords Leaked In Apparent Breach
A quick heads up for our readers. LinkedIn appears to have had their passwords dumped and people are popping them with reckless abandon. Rough 24 hours for LinkedIn. Just yesterday we heard that...
View ArticleMillions of LinkedIn passwords reportedly leaked – take action NOW
Although not yet confirmed by the business-networking website, it is being widely speculated that over six million passwords belonging to LinkedIn users have been compromised.
View ArticlePublic Service Annoucement: LinkedIn Users Change Your Passwords
Rumors are quickly spreading on the web that approximately 6.5 million password hashes may have been leaked via a Russian hacker site. Regardless of the accuracy of the rumors many of you might want to...
View ArticleFascinating air travel trivia
Here's a bit of trivia that came up at a standards meeting that I recently sat through: why would it be interesting to fly from Stanton, Minnesota to Nantucket, Massachusetts? (It turned out that I...
View ArticleReports of 6.4 Million Stolen LinkedIn Passwords
LinkedIn is investigating reports that approximately 6.4 million user passwords have been posted on the Web. While the breach is still unconfirmed by LinkedIn (as of the time that we wrote this blog),...
View Article“Blonde-ness” Prevails, The Animals Benefit, Calling IT Risk Professionals,...
Well, CipherBlonde was Super Blonde. My Product-related survey, for IT Risk Mgt. Executives & Senior Management was flawed- a little operator error in creation and comprehensive testing. Thanks to...
View Article284,000 WordPress sites hacked? Probably not.
This Amazon order confirmation email is a fake. Every link leads to malware. Every link (there are 8 in this example – similar to this attack) leads to a different compromised WordPress site. And...
View ArticlePossible LinkedIn Data Breach, Affecting 6.5 Million Accounts
It appears that the developers at LinkedIn may not have had “encryption training” on their own resumes. Two stories about potential user data leakage at the networking company trickled out late...
View ArticleSecuraBit Episode 105: Flaming Bluetooth Penetration!
Hosts Chris Gerling – @secbitchris Chris Mills - @chrisam Andrew Borel – @andrew_secbit Mike Bailey – @mpbailey1911 Guests Jason Andress – @jason_andress Ronin – @r0wnin Topics APT and Penetration...
View ArticleInterview with Josh Corman at SOURCE Boston 2012 – Part 2
document.write(unescape("%3Ciframe src='http://www.facebook.com/plugins/like.php?href=" + document.URL +...
View ArticleSummarizing ZDNet’s Zero Day Posts for May
The following is a brief summary of all of my posts at ZDNet's Zero Day for May, 2012. You can subscribe to my personal RSS feed, Zero Day's main feed, or follow me on Twitter: 01. Is Mozilla's...
View ArticleConfirmed: LinkedIn 6mil password dump is real
Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for LinkedIn is in that list. I use that password NOWHERE ELSE....
View ArticleLittle Boots is back baby! Video: Little Boots – Headphones (official video)
Little Boots is back baby!Video: Little Boots - Headphones (official video)
View ArticleLeakedIn Passwords Linked
LinkedIn has been having problems as of late. Earlier this week it was their iOS app sending calendar data back to their servers (bad) and further transmitting it unencrypted (bad, bad). And now it...
View Article