Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
April, 2008
TechNet Blogs
>
Robert Hensing's Blog
>
April, 2008
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
On Vista, OSX and security researchers
Posted
over 5 years ago
by
rhensing
2
Comments
So I made an interesting observation at Cansec last week. By day 3 I realized that I was the sole presenter running Vista. Hell I may have been the sole *attendee* running Vista. In fact if I had to break out the presenter laptop OS's it would go something...
Robert Hensing's Blog
Flash NULL pointer + offset code execution . . .
Posted
over 5 years ago
by
rhensing
2
Comments
I tend to agree - Mark Dowd is clearly not human: http://www.matasano.com/log/1032/this-new-vulnerability-dowds-inhuman-flash-exploit/ This kind of thing makes me want to like . . . go work on cars or something. :) So here's what's sort of scary...
Robert Hensing's Blog
IE8 - DEP enabled by default?
Posted
over 5 years ago
by
rhensing
1
Comments
W00t!!! So I guess this is public now: http://www.eweek.com/c/a/Security/Microsoft-Details-IE-8-Security-Default-Change/ This is huge . . . DEP is a fairly complex process on Windows today . . . far less trivial than I would like. By default on our...
Robert Hensing's Blog
Yet another product with 360 in the name . . .
Posted
over 5 years ago
by
rhensing
1
Comments
Ferrari F 360 :) Xbox 360 Anderson Cooper 360 Symantec Norton 360 Nordick Track 360 Fortify 360 ? http://www.internetnews.com/dev-news/article.php/3737696/Taking+a+Wider+View+of+Code+Security.htm Seriously . . . when will the 360 product naming madness...
Robert Hensing's Blog
Bitlocker protecting me from myself?
Posted
over 5 years ago
by
rhensing
1
Comments
So tonight I rebooted my notebook and was prompted by Bitlocker that my boot configuration had changd. I sort of freaked out. I didn't want to insert my USB key with the BDE key on it until I figured out what BDE was trying to tell me. For all I knew...
Robert Hensing's Blog
Apple opting into /GS, DEP and ASLR?
Posted
over 5 years ago
by
rhensing
1
Comments
Somebody pinch me . . . I must be dreaming: http://www.eweek.com/c/a/Security/Apple-Adds-AntiHacker-Features-to-QuickTime/
Robert Hensing's Blog
Mac vs. PC - can't we all just get along?
Posted
over 5 years ago
by
rhensing
1
Comments
So I'm on the road with my boss . . . he brought his Mac . . . I brought my Vista x64 Dell. They only offered wired internet so I decided to try out Vista's connection sharing stuff . . . I figured I would plug in the cable and share the connection out...
Robert Hensing's Blog
Fail open goats (the new LOL cats?)
Posted
over 5 years ago
by
rhensing
1
Comments
So there are these goats - that when you scare them - they lock up, and their legs stiffen and they end up falling over and landing on their back - invariably with their legs sticking straight up in the air. It's a genetic thing. The goats are fine after...
Robert Hensing's Blog
Mah Bluehat blogz - let me show you them!
Posted
over 5 years ago
by
rhensing
0
Comments
My somewhat random thoughts on the battle for your PC and how it may play out in the coming year . . . (and by your PC I really mean your Mom's since you're of course running IE7 on Vista with UAC enabled and DEP forced on etc. right?): http://blogs.technet...
Robert Hensing's Blog
Get Kraken!
Posted
over 5 years ago
by
rhensing
0
Comments
So much ado is being made about Kraken in the press with people speculating this bot is bigger than storm - which was already terribly over-hyped in terms of numbers by the press. If you're curious - here's our AV team's write-up on it here: http://www...
Robert Hensing's Blog
I feel dirty . . .
Posted
over 5 years ago
by
rhensing
0
Comments
So I've been running WS2008 for a while now. I've got a nice beefy machine that I do all my repro work on. It's an Intel quad proc box with 4GB of RAM and an ATI Radeon x1950Pro. I've got some nice LCDs and run multi-mon. And I absolutely hate what we...
Robert Hensing's Blog
"Counting vulnerabilities is a natural way to measure security. If you're a retard."
Posted
over 5 years ago
by
rhensing
0
Comments
Got your attention didn't I? :) So Mike Howard, one of the founding fathers of the SDL, is an amazing guy. In my group we joke around with him and tease him quite a lot (he is a Kiwi after all) but at the end of the day there are few people in Microsoft...
Robert Hensing's Blog
Espionage using Office documents in the news
Posted
over 5 years ago
by
rhensing
0
Comments
First a Wired article: http://www.wired.com/politics/security/news/2008/04/chinese_hackers Next a Businessweek article: http://www.businessweek.com/magazine/content/08_16/b4080032218430.htm We live in 'interesting' times.
Robert Hensing's Blog
Hyper-V
Posted
over 5 years ago
by
rhensing
0
Comments
So Brandon Baker is a senior guy on the Hyper-V team. I just came across this blog post of his: http://blogs.msdn.com/rsa2008/archive/2008/04/07/isolation-of-virtual-machines.aspx If you read my blog - you may have seen my blog from CanSec where Oded...
Robert Hensing's Blog
PayPal throws down . . .
Posted
over 5 years ago
by
rhensing
0
Comments
This is VERY interesting and I wonder what sort of time frame they plan on doing this in - because right now AFAIK their list of supported browsers would be IE7 and IE8 (based on the EVSSL statements). :) http://www.eweek.com/index2.php?option=content&task...
Page 1 of 1 (15 items)