Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
TechNet Blogs
>
Robert Hensing's Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
Rootkit Revealer vs. Hacker Defender - How the miscreants are defeating Rootkit Revealer and how to fight back
Posted
over 8 years ago
by
rhensing
27
Comments
So over the last week we've started to get cases where Rootkit Revealer (having been downloaded by the customer) is not detecting any hidden files / folders / registry entries on the customers machine; yet our own rootkit tools we supply with our IR toolkit...
Robert Hensing's Blog
Rootkits - revealed!
Posted
over 8 years ago
by
rhensing
1
Comments
Well what do you know - that day that I was talking about in my previous post? It was today: http://www.sysinternals.com/ntw2k/freeware/rootkitreveal.shtml Make sure you check out the MSR site in the coming days / weeks (hoping that by saying it like...
Robert Hensing's Blog
Wormbotdoorkit? Kitbotwormdoor? Trojwormrootbot? Malware by any other name . . . 2005 - the year of the rootkit?
Posted
over 8 years ago
by
rhensing
17
Comments
Edited 2/25/2005 to examine the multiple definitions of the word 'rootkit', added information on a LUA-friendly rootkit for the LUA folks to ponder (LUA - Limitted User Account), and added some thoughts on how they could mess with AV software. :) So this...
Robert Hensing's Blog
Microsoft does 733t speak . . . it's like an SNL skit - only funnier.
Posted
over 8 years ago
by
rhensing
11
Comments
So yesterday this hilarious URL probably arrived in your inbox via your own personal friend network - and if it didn't, allow me to share it with you now (it's almost as entertaining as the Star Wars Kid ): http://www.microsoft.com/athome/security/children...
Robert Hensing's Blog
The MSRC @ RSA - the webspace
Posted
over 8 years ago
by
rhensing
4
Comments
Wow - this is really really cool. So . . . select members of the MSRC are off at RSA this week doing BOOTH duty and talking to our customers and then blogging about the days events in an MSN web space - check it out! http://spaces.msn.com/members/msrc...
Robert Hensing's Blog
Windows Server 2003 spanks Red Hat's monkey?
Posted
over 8 years ago
by
rhensing
32
Comments
Interesting information from RSA, it's nice to see someone other than me notice the pure creamy goodness of WS2003 for once (I've noticed it from the incident response side of things by noting a marked absence of WS2003 hacking cases over the last 2 years...
Robert Hensing's Blog
Introducing Tim 'The tool man' Rains - PSS Security Techlead, fellow blogger, maintainer of WOLFv2
Posted
over 8 years ago
by
rhensing
10
Comments
Folks it just occured to me that I haven't formally introduced you to a colleague of mine, Tim Rains. Tim Rains is also a tech-lead on the PSS Security team and is an avid C++ coder (un-like me who despises the language). In fact Tim has a long and distinguished...
Robert Hensing's Blog
WOLF sizes up the MySQL bot / worm / spreader thing . . . a live system perspective
Posted
over 8 years ago
by
rhensing
12
Comments
So it seems that there is a new MySQL bot that is spreading to Windows machines running MySQL with weak SA (or whatever MySQL's equivalent is) passwords. You can read more about it here http://news.zdnet.com/2100-1009_22-5553570.html and here: http:/...
Robert Hensing's Blog
The Blame Game - I won't go there.
Posted
over 8 years ago
by
rhensing
14
Comments
So I'm getting some 'interesting' and frankly un-expected comments on my most recent 'Anatomy of . . . ' posts where I delve into examples of a hack involving certain vulnerabilities (one of which wasn't even in one of our products I'd like to point out...
Robert Hensing's Blog
Anatomy of a WINS server hack (MS04-045) . . .
Posted
over 8 years ago
by
rhensing
20
Comments
Okay - so here is my analysis of a recent WINS hack a customer experienced. The customer caught this by analyzing their netflow data from their routers . . . they suddenly started sending tremendous amounts of packet love and affection to various IP's...
Robert Hensing's Blog
Anatomy of a Veritas BackupExec Agent Browser hack via TCP 6101
Posted
over 8 years ago
by
rhensing
16
Comments
I've gotten some really great feedback on my blog now that I'm actually blogging about incident response topics - I appreciate the feedback, keep it coming! So we here in PSS Security are tied into the security incident response community fairly well...
Robert Hensing's Blog
Advanced hiding techniques: The mystery of the trojaned Winlogon.exe
Posted
over 8 years ago
by
rhensing
25
Comments
So the war between the miscreants and the first responders / incident responders is just that - it's a war with casulaties (servers, workstations, work life / home life balance) and it is complete with an arms race in the form of stealthing (miscreants...
Robert Hensing's Blog
More miscreant hiding techniques and some interesting observations on the Hacker Defender rootkit . . .
Posted
over 8 years ago
by
rhensing
My last blog post was about miscreant hiding techniques . . . unfortunately one can probably write a book devoted to some of the more popular techniques . . . I'm just going to blog from time to time about the ones my team is encountering (call it miscreant...
Robert Hensing's Blog
Miscreant hiding techniques: Would the real explorer.exe please stand up? And the relevance of 1979 when doing searches . . .
Posted
over 8 years ago
by
rhensing
6
Comments
At long last - a blog post about Incident Response in the self-proclaimed 'Incident Response' blog! Before I finally crash for the night there are two things I wanted to bring to the attention of folks interested in Windows IR that my team has come across...
Robert Hensing's Blog
Admin Personas - at long last . . .
Posted
over 8 years ago
by
rhensing
4
Comments
Okay so this post is several months late - what can I say, I'm easily distracted and overly busy. Hopefully if you are reading this post you've already read the post on hacker personas. Having been on the PSS Security team for over three years now I've...
Robert Hensing's Blog
Admin Personas? Not yet - the final word on Passwords vs. Passphrases
Posted
over 9 years ago
by
rhensing
5
Comments
So yesterday Jesper posted his final installment in his 3 part series in passwords vs. pass-phrases and while I had some issues with some of the assumptions he used to draw conclusions in his 2nd installment, I have no such issues with the conclusions...
Robert Hensing's Blog
Password vs. Passphrase redux
Posted
over 9 years ago
by
rhensing
12
Comments
So today Jesper Johannson a gentlemen whom I have the pleasure of speaking with on occasion has posted his 2nd installment on the topic of passwords here . I encourage you all to read it - in this installment he goes deep into the math and science behind...
Robert Hensing's Blog
Weekend update
Posted
over 9 years ago
by
rhensing
3
Comments
It's been a while since I have posted and I wanted to give folks a quick update and explanation on why things haven't progressed as quickly as I'd hoped. I'd like to try to not be a one hit wonder and continue to improve the security of our customers...
Robert Hensing's Blog
The future of passwords?
Posted
over 9 years ago
by
rhensing
1
Comments
Given what I do, I tend to be pretty interested in technologies that will allow me to do away with passwords altogether. One area that's shown promise in the past is the use of graphical passwords (again, demonstrating that passwords are an antiquated...
Robert Hensing's Blog
The silent war - combat evolved: Hacker Personas
Posted
over 9 years ago
by
rhensing
31
Comments
Okay, yes, I admit - I'm a little too excited about Halo 2 (note to XBox geeks out there, schedule your vacation NOW for around the launch of Halo 2 in November and make sure your XB live account is paid and up to date), but that is a fitting title for...
Robert Hensing's Blog
Why you shouldn't be using passwords of any kind on your Windows networks . . .
Posted
over 9 years ago
by
rhensing
133
Comments
Edited 10/18/2004: This blog has gained far more attention than I could have ever imagined when I decided to create a small personal blog devoted to security incident response. I never imagined my first ever post would be as controversial or as widely...
Page 12 of 12 (296 items)
«
8
9
10
11
12