Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
July, 2008
TechNet Blogs
>
Robert Hensing's Blog
>
July, 2008
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
Today's Fail Open Goat Award goes to: Insecure 3rd party software updaters
Posted
over 5 years ago
by
rhensing
3
Comments
You'll notice Microsoft's auto-updaters (Windows Update / Microsoft Update / Automatic Updates) are not on the list. Why? Because we're paranoid, and we anticipated this type of threat years ago and mitigated it by signing all of our binaries and only...
Robert Hensing's Blog
Adobe Acrobat 9 - Creamy Security Goodness (on Vista / WS2008)
Posted
over 5 years ago
by
rhensing
4
Comments
So I noticed yesterday that Adobe had quietly released Acrobat 9 to the web. I decided to download it and check it out to see if they had finally gotten a copy of memo (it's just that we're putting cover sheets on all of our TPS reports now) and decided...
Robert Hensing's Blog
Vulnerable Web Browser Study - Full of Fail
Posted
over 5 years ago
by
rhensing
2
Comments
So came across an interesting report today from various security folks (including Gunter Ollmann from ISS): http://www.techzoom.net/papers/browser_insecurity_iceberg_2008.pdf I can appreciate what they are trying to do - and I believe they were probably...
Robert Hensing's Blog
Memory dumpers for Windows
Posted
over 5 years ago
by
rhensing
1
Comments
So I still get IR related questions on occasion . . . one of which being 'what is the best way to dump memory on Windows'. I honestly am hopelessly out of touch - I haven't done IR in many years now - but I came across some intersting tools that seem...
Robert Hensing's Blog
Dan's DNS checker - We need a new ship!
Posted
over 5 years ago
by
rhensing
1
Comments
Heres' an interesting, somewhat reflective blog from Kaminsky on security researcher drama, and how in an ideal world lots of trusted peers would get to review your vulns and fix plans before the patches ship: http://www.doxpara.com/?p=1164 Sadly - in...
Robert Hensing's Blog
Microsoft Mojave
Posted
over 5 years ago
by
rhensing
0
Comments
"We are here in San Francisco, where we've secretly replaced the fine operating system these people usually use with Windows Vista, Let's see if anyone can tell the difference!" http://news.cnet.com/8301-13860_3-9998336-56.html?tag=nefd.lede
Robert Hensing's Blog
Chris Rohlf joins Matasano
Posted
over 5 years ago
by
rhensing
0
Comments
I have mad respect for Matasano and I can't believe a friend of mine now works there! http://www.matasano.com/log/1088/hello-a-self-introduction-by-chris-rohlf/ Congrats dude!
Robert Hensing's Blog
Antivirus fail . . .
Posted
over 5 years ago
by
rhensing
0
Comments
Lately I'm not a big fan of AV and it amazes me that AV hasn't been beaten up more badly than it has given how it runs on pretty much every desktop in the civilized world and how critical writing solid, secure code is these days. It looks like .Nruns...
Robert Hensing's Blog
DNS Fail Open Goat Award
Posted
over 5 years ago
by
rhensing
1
Comments
Kaminsky's flaw has a metasploit module: http://www.caughq.org/exploits/CAU-EX-2008-0002.txt On the Internet - no one hears your screams.
Robert Hensing's Blog
2% of a big number, is a big number
Posted
over 5 years ago
by
rhensing
1
Comments
Don't be evil. http://blogs.pcmag.com/securitywatch/2008/07/google_blogger_hosts_2_of_worl.php
Robert Hensing's Blog
Pwnie Awards - Vista nominated for . . .
Posted
over 5 years ago
by
rhensing
0
Comments
Most Epic Fail: http://pwnie-awards.org/2008/awards.html#fail Gee . . . I hope we . . . win? No . . . wait . . . Windows Vista for proving that security does not sell $100,000,000 invested in security and what does Microsoft have to show for...
Page 1 of 1 (11 items)