Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
TechNet Blogs
>
Robert Hensing's Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
Apple offering free attack surface increase to Windows users.
Posted
over 5 years ago
by
rhensing
0
Comments
This is hugely irresponsible of Apple IMHO: http://blogs.zdnet.com/Bott/?p=405&tag=nl.e622 As history has taught us - browsers are not trivial applications to write securely and they are the primary conduit by which badness often enters your PC...
Robert Hensing's Blog
The web is broken . . .
Posted
over 5 years ago
by
rhensing
0
Comments
A friend of mine made a comment to me the other day that said exactly that - and now we have the creator of JSON saying the same thing: http://www.internetnews.com/dev-news/article.php/3735341 Amen brother . . .
Robert Hensing's Blog
Cybercrime alliance?
Posted
over 5 years ago
by
rhensing
0
Comments
It's about damned time: http://www.networkworld.com/community/node/26144 http://www.fbi.gov/page2/march08/cybergroup_031708.html And you know it's gonna be a success because they've got the Mounties involved! He he he . . . jeez I crack myself up...
Robert Hensing's Blog
Mass SQL injection coming to an IIS + ASP server near you . . .
Posted
over 5 years ago
by
rhensing
0
Comments
My friend Neil has a pretty good post on the mass SQL injection stuff that was reported in the press recently. http://blogs.technet.com/neilcar/archive/2008/03/14/anatomy-of-a-sql-injection-incident.aspx
Robert Hensing's Blog
I'm closing out CanSecWest 2008?
Posted
over 5 years ago
by
rhensing
0
Comments
Well not quite - but I am the second to last speaker on the last day (Friday) - http://cansecwest.com/agenda.html Ugh - people usually skip out early on the last day to make flights and stuff - so I guess not many people will be staying for my live demos...
Robert Hensing's Blog
Walmart drops Linux PCs from stores
Posted
over 5 years ago
by
rhensing
0
Comments
"This really wasn't what our customers were looking for," said Wal-Mart Stores Inc. spokeswoman Melissa O'Brien. http://news.yahoo.com/s/ap/20080310/ap_on_hi_te/wal_mart_linux_computer Hilarious.
Robert Hensing's Blog
From China with love . . .
Posted
over 5 years ago
by
rhensing
0
Comments
So last week was a VERY interesting week. First off we had some dude going public with information that the Pentagon had apparently been succesfully hacked at some point last year by an organization whom they believe but won't officially state as being...
Robert Hensing's Blog
Jonathan Morrison's kernel blog & LOST
Posted
over 5 years ago
by
rhensing
0
Comments
So my friend Jonathan who is one of my hard-core kernel go to guys has decided to dip his toe into the waters of the blogosphere and you can start reading his blog here: http://blogs.msdn.com/itgoestoeleven/ He'll be blogging about some pretty low level...
Robert Hensing's Blog
Newton virus for Macs? Android image parsing vulns?
Posted
over 5 years ago
by
rhensing
1
Comments
Good lord - even their viruses ( no the plural of virus is NOT virii ) are sexier than PC viruses! http://www.troika.uk.com/virus.htm And from the "wtf were they thinking" files - Google decides to release the Android SDK with outdated open source...
Robert Hensing's Blog
Hypervisor based rootkit detection?
Posted
over 5 years ago
by
rhensing
0
Comments
Time marches on . . . http://northsecuritylabs.com/
Robert Hensing's Blog
The fragility of the Internets - as demonstrated by Pakistan / Youtube
Posted
over 5 years ago
by
rhensing
1
Comments
I love how fragile the Internet really is. This is demonstrated from time to time and when it is - I'm drawn to it like a police chase on live TV . . . sometimes the root name servers come under attack or someone figures out a neat way to poison DNS caches...
Robert Hensing's Blog
Practical application of the concept behind photon sails / laser elevators
Posted
over 5 years ago
by
rhensing
0
Comments
Hilarious: http://blag.xkcd.com/2008/02/15/the-laser-elevator/
Robert Hensing's Blog
Cold boot attacks on encryption keys
Posted
over 5 years ago
by
rhensing
1
Comments
UPDATE 2/27/2008: Douglas MacIver wrote an excellent and very authoritative blog post here on this topic - I highly recommend reading his blog post instead of mine. :) http://blogs.msdn.com/si_team/archive/2008/02/25/protecting-bitLocker-from-cold-attacks...
Robert Hensing's Blog
SWI Defense in the news
Posted
over 5 years ago
by
rhensing
0
Comments
My boss is apparently allowed to speak to the press. :) http://www.eweek.com/c/a/Security/Behind-the-Scenes-at-Microsofts-Secure-Windows-Initiative/
Robert Hensing's Blog
Blackhat Day 4 - DTrace and PINK
Posted
over 5 years ago
by
rhensing
0
Comments
This morning I attended a session on DTrace which is a sort of tracing capability created by Sun for Solaris 10 that can be ported to other OS's. Some engineers from SAIC have figured out how to make this useful for reverse engineering, vuln discovery...
Robert Hensing's Blog
Blackhat Federal - Notes from Days 1-3
Posted
over 5 years ago
by
rhensing
1
Comments
So I'm at Blackhat Federal this week - doing the training thing (IDA class with Chris Eagle - fairly good / broad intro to IDA and it's capabilities) and today was the first day of the sessions. It's been a great con so far . . . Monday and Tuesday I...
Robert Hensing's Blog
Asus / Apple / Wii pwnage & The press starts to wonder if maybe it's time to consider 3rd party apps dangerous?
Posted
over 5 years ago
by
rhensing
1
Comments
Asus Eee PC owned out of the box (hint runs Linux): http://www.risesecurity.org/blog/entry/6/ Yet another Apple Quicktime 0-day posted 2 days ago: http://seclists.org/fulldisclosure/2008/Feb/0304.html The Wii has been pwn3d via a stack smash to...
Robert Hensing's Blog
SecureWorks / Team Cymru solve the mystery of the Mega-D Trojan
Posted
over 5 years ago
by
rhensing
1
Comments
Joe Stewart is the man . . . I have a ton of respect for him and everyone at Team Cymru. They teamed up to find the C&C for the Mega-D trojan and Joe has done another one of his excellent write-ups here: http://www.secureworks.com/research/threats...
Robert Hensing's Blog
New measure of code quality
Posted
over 5 years ago
by
rhensing
2
Comments
http://www.veracode.com/blog/?p=77 Hilarious . . . I can finally explain what my team does to my less technical friends / family with that simple drawing.
Robert Hensing's Blog
The Stig
Posted
over 5 years ago
by
rhensing
0
Comments
I would not be surprised at all if it were Hamilton - but alas - given his hectic travel schedule during F1 season - I doubt that it is: http://www.autoblog.com/2008/02/04/the-stig-some-say-hes-lewis-hamilton/ Top Gear - my favorite show on TV next...
Robert Hensing's Blog
Massive Linux / Apache hacks spewing forth browser based malware
Posted
over 5 years ago
by
rhensing
0
Comments
And NO one knows how it's being done? http://www.linux.com/feature/125548 Pure insanity . . . how can this be going on for months and no one has a clue and all they can do is guess that maybe a password was guessed and used for logon? If these...
Robert Hensing's Blog
Mommy? Where do servers come from?
Posted
over 5 years ago
by
rhensing
1
Comments
Farking hilarious!!! http://gizmodo.com/342499/microsofts-brainwashing-childrens-book-mommy-where-do-servers-come-from Here's the official book web site: http://www.stayathomeserver.com/book.aspx And this video isn't half bad either: http://video...
Robert Hensing's Blog
GMER discovers a new MBR based rootkit in the wild . . .
Posted
over 5 years ago
by
rhensing
1
Comments
EDITED : 1/10/2008 to remove information about possibly using ntbtlog.txt to detect the rootkit. The driver load routine for the rootkit seems to be non-standard and thus unlikely to appear in ntbtlog.txt You can read the gory details of it here: http...
Robert Hensing's Blog
Did Bill Gates just say Windows sucks?
Posted
over 5 years ago
by
rhensing
1
Comments
No - I believe he is implying that he belives *Vista* sucks. :) http://gizmodo.com/342920/holy-crap-did-bill-gates-just-say-windows-sucks
Robert Hensing's Blog
Bill's last day . . .
Posted
over 5 years ago
by
rhensing
0
Comments
This video is just all sorts of awesome: http://www.istartedsomething.com/20080107/bill-gates-last-day-microsoft-video/
Page 5 of 12 (296 items)
«
3
4
5
6
7
»