Blog Feed: Life in the trenches as a data network and information security manager.
| Home | My Account | Directories |
Anatomy of a crimeware rootkit - scary stuff!
Published on 2010-11-19 08:37:59
I came across a recent tutorial on reverse engineering the ZeroAccess / Max++ / Smiscer Crimeware Rootkit. This is a very malicious rootkit that has features such as: Modern persistence hooks into the OS – Make it very difficult to remove without > read more
PDF Search Engine - ebooks
Published on 2010-09-16 10:20:37
I recently came across a specialized search engine for PDF’s or ebooks. I know that there are Google hacks or search strings that you can use to narrow search scope, but at times it is nice to use a specialized tool to quickly isolate what you > read more
Is there an orange ball in information security?
Published on 2010-09-10 12:05:59
In Japan many retailers have what look like orange balls or waterballoons near checkouts. Bruce Schneier, a leading information security expert, recently blogged about these orange balls as anti-robbery devices. Could we find any type of orange ball > read more
DLL hole also affects EXE files
Published on 2010-09-10 10:56:05
According to a Heise Media report, the DLL binary planting vulnerability is not just limited to DLL files but affects EXE files. The example given: An HTML file is saved along with a copy of a file called EXPLORE.EXE. The HTML file is opened and has > read more
Did you see this? - Microsoft updates Security Compliance Management Accelerator toolkit
Published on 2010-08-27 12:49:04
In 2008, I blogged about Microsoft’s release of Security Compliance Management Accelerator toolkit. Now two years later Microsoft announces an updated Security Compliance Manager. The Microsoft Security Compliance Manager is the next evolution > read more
Friday fun: HEADLINE: Microsoft Windows glider crashes
Published on 2010-08-27 09:12:36
Well, the headline may be tongue-in-cheek but this is truly a fun story for a Friday. The Register reports the Microsoft Phoenix glider fails to show the “right stuff” in the recent Red Bull Flugtag competition in Long Beach, California. > read more
Hackers send exploit code to Microsoft
Published on 2010-08-27 08:35:50
Go ahead and report why your system crashed - send Microsoft the exploit code you are working on. As most Windows users know, you can send Microsoft details about what caused a system crash. In some cases hackers respond yes and their exploit code is > read more
Online devices, applications and threats grow - predictions for 2013
Published on 2010-08-26 13:08:20
The Cisco 2010 Midyear Security Report shows some staggering statistics about the number of online devices, mobile applications and security threats projected to be around in 2013. In 2007 there were 500 million connected devices or 1/10th of a conn > read more
Whak-a-mole testing for Microsoft DLL exploit
Published on 2010-08-24 15:01:58
HD Moore of Metasploit fame has created a tool to identify applications which exhibit the DLL hijack flaw about which Microsoft recently released a security advisory. This tool in HD Moore’s own words will turn a desktop PC into a game of whack > read more
Investigation indicates trojan contributed to 2008 Spainair crash
Published on 2010-08-23 13:32:01
El Pais reports that a Spainair computer which tracks airplane maintenance and problem issues was infected by malicious software (trojans) that prevented it from operating properly. The computer should alarm when three failures happen on particular o > read more