Sign in
Robert Hensing's Blog
Software Security . . . and stuff.
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Tags
No tags have been created or used yet.
Archive
Archives
December 2008
(1)
November 2008
(2)
October 2008
(11)
September 2008
(13)
August 2008
(6)
July 2008
(11)
June 2008
(24)
May 2008
(11)
April 2008
(15)
March 2008
(15)
February 2008
(11)
January 2008
(7)
December 2007
(9)
November 2007
(15)
October 2007
(23)
September 2007
(18)
August 2007
(8)
July 2007
(13)
June 2007
(10)
May 2007
(12)
April 2007
(8)
March 2007
(5)
February 2007
(4)
January 2007
(7)
December 2006
(5)
November 2006
(6)
September 2005
(1)
July 2005
(1)
March 2005
(4)
February 2005
(6)
January 2005
(8)
November 2004
(1)
October 2004
(2)
August 2004
(2)
July 2004
(1)
TechNet Blogs
>
Robert Hensing's Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Robert Hensing's Blog
Why you shouldn't be using passwords of any kind on your Windows networks . . .
Posted
over 9 years ago
by
rhensing
133
Comments
Edited 10/18/2004: This blog has gained far more attention than I could have ever imagined when I decided to create a small personal blog devoted to security incident response. I never imagined my first ever post would be as controversial or as widely...
Robert Hensing's Blog
Hybrid sleep in Vista and S0 - S5 explained
Posted
over 6 years ago
by
rhensing
1
Comments
Okay it's time for another shameless 'wow - Vista rocks' type blog post. :) So I have a notebook and a desktop that I use with Vista daily. I've never really sat down to investigate 'hybrid sleep' or what it is or how it works until this weekend (I admit...
Robert Hensing's Blog
DEP on Vista exposed!
Posted
over 6 years ago
by
rhensing
6
Comments
This is going to be a looooong blog - but its one that I've been meaning to post for a loooong time now. My hope is that you will learn something you didn't peviously know about DEP and Vista or both and that you will, after reading this blog, re-configure...
Robert Hensing's Blog
Advanced hiding techniques: The mystery of the trojaned Winlogon.exe
Posted
over 8 years ago
by
rhensing
25
Comments
So the war between the miscreants and the first responders / incident responders is just that - it's a war with casulaties (servers, workstations, work life / home life balance) and it is complete with an arms race in the form of stealthing (miscreants...
Robert Hensing's Blog
The silent war - combat evolved: Hacker Personas
Posted
over 9 years ago
by
rhensing
31
Comments
Okay, yes, I admit - I'm a little too excited about Halo 2 (note to XBox geeks out there, schedule your vacation NOW for around the launch of Halo 2 in November and make sure your XB live account is paid and up to date), but that is a fitting title for...
Robert Hensing's Blog
Windows Server 2003 spanks Red Hat's monkey?
Posted
over 8 years ago
by
rhensing
32
Comments
Interesting information from RSA, it's nice to see someone other than me notice the pure creamy goodness of WS2003 for once (I've noticed it from the incident response side of things by noting a marked absence of WS2003 hacking cases over the last 2 years...
Robert Hensing's Blog
Rootkit Revealer vs. Hacker Defender - How the miscreants are defeating Rootkit Revealer and how to fight back
Posted
over 8 years ago
by
rhensing
27
Comments
So over the last week we've started to get cases where Rootkit Revealer (having been downloaded by the customer) is not detecting any hidden files / folders / registry entries on the customers machine; yet our own rootkit tools we supply with our IR toolkit...
Robert Hensing's Blog
Wormbotdoorkit? Kitbotwormdoor? Trojwormrootbot? Malware by any other name . . . 2005 - the year of the rootkit?
Posted
over 8 years ago
by
rhensing
17
Comments
Edited 2/25/2005 to examine the multiple definitions of the word 'rootkit', added information on a LUA-friendly rootkit for the LUA folks to ponder (LUA - Limitted User Account), and added some thoughts on how they could mess with AV software. :) So this...
Robert Hensing's Blog
Anatomy of a Veritas BackupExec Agent Browser hack via TCP 6101
Posted
over 8 years ago
by
rhensing
16
Comments
I've gotten some really great feedback on my blog now that I'm actually blogging about incident response topics - I appreciate the feedback, keep it coming! So we here in PSS Security are tied into the security incident response community fairly well...
Robert Hensing's Blog
VBootkit vs. Bitlocker in TPM mode
Posted
over 6 years ago
by
rhensing
8
Comments
So at HITB in Dubai this week - some researchers announced a proof of concept 'bootkit' for Vista. A bootkit is a rootkit that is able to load from a master boot record and persist in memory all the way through the transition to protected mode and the...
Robert Hensing's Blog
Anatomy of a WINS server hack (MS04-045) . . .
Posted
over 8 years ago
by
rhensing
20
Comments
Okay - so here is my analysis of a recent WINS hack a customer experienced. The customer caught this by analyzing their netflow data from their routers . . . they suddenly started sending tremendous amounts of packet love and affection to various IP's...
Robert Hensing's Blog
Vista resume sluggishness?? (still investigating . . . )
Posted
over 6 years ago
by
rhensing
4
Comments
UPDATE 7/10/2007 : Mea culpa! So after I originally blogged this, I went to the ReadyBoost team to find out more about possible performance issues with ReadyBoost and they were kind enough to help me troubleshoot things further. Before starting some tracing...
Robert Hensing's Blog
MOICE - Microsoft Office Isolated Conversion Environment
Posted
over 6 years ago
by
rhensing
3
Comments
A couple weeks ago I did a lightening talk with David LeBlanc at Bluehat for MSFT employees about MOICE. MOICE is the Microsoft Office Isolated Conversion Environment. What the hack is that?!? Well it's no secret that Office was used in some targetted...
Robert Hensing's Blog
More miscreant hiding techniques and some interesting observations on the Hacker Defender rootkit . . .
Posted
over 8 years ago
by
rhensing
My last blog post was about miscreant hiding techniques . . . unfortunately one can probably write a book devoted to some of the more popular techniques . . . I'm just going to blog from time to time about the ones my team is encountering (call it miscreant...
Robert Hensing's Blog
Miscreant hiding techniques: Would the real explorer.exe please stand up? And the relevance of 1979 when doing searches . . .
Posted
over 8 years ago
by
rhensing
6
Comments
At long last - a blog post about Incident Response in the self-proclaimed 'Incident Response' blog! Before I finally crash for the night there are two things I wanted to bring to the attention of folks interested in Windows IR that my team has come across...
Robert Hensing's Blog
Robert Hensing’s Incident Response Blog – Reloaded
Posted
over 8 years ago
by
rhensing
11
Comments
After nearly 7 years in Product Support Services helping our customers on issues ranging from debugging IIS failures, to identifying performance issues to helping customers with security investigations I have taken on a new challenge and accepted a job...
Robert Hensing's Blog
WOLF sizes up the MySQL bot / worm / spreader thing . . . a live system perspective
Posted
over 8 years ago
by
rhensing
12
Comments
So it seems that there is a new MySQL bot that is spreading to Windows machines running MySQL with weak SA (or whatever MySQL's equivalent is) passwords. You can read more about it here http://news.zdnet.com/2100-1009_22-5553570.html and here: http:/...
Robert Hensing's Blog
Password vs. Passphrase redux
Posted
over 9 years ago
by
rhensing
12
Comments
So today Jesper Johannson a gentlemen whom I have the pleasure of speaking with on occasion has posted his 2nd installment on the topic of passwords here . I encourage you all to read it - in this installment he goes deep into the math and science behind...
Robert Hensing's Blog
Strange DLLHost crashes on Vista
Posted
over 6 years ago
by
rhensing
1
Comments
EDITED: 7/22/2007 I have traced the problem to Urge . . . I buy music from MTV Urge and it installs some components that appear to be responsible for the crash. Moreover I discovered that there are two dllhosts on a 64bit version of Windows - there is...
Robert Hensing's Blog
Microsoft does 733t speak . . . it's like an SNL skit - only funnier.
Posted
over 8 years ago
by
rhensing
11
Comments
So yesterday this hilarious URL probably arrived in your inbox via your own personal friend network - and if it didn't, allow me to share it with you now (it's almost as entertaining as the Star Wars Kid ): http://www.microsoft.com/athome/security/children...
Robert Hensing's Blog
New Rootkit Revealer available!
Posted
over 8 years ago
by
rhensing
3
Comments
Sysinternals yesterday released a new version of Rootkit revealer after receiving feedback that people using rootkits were starting to add Rootkit Revealer to the 'root process' to continue to avoid detection. The new version uses a randomly named executable...
Robert Hensing's Blog
Ever found malware hiding in the "Default User" profile on Windows? Ever wonder how it got there or why it was there?
Posted
over 7 years ago
by
rhensing
2
Comments
(Edited to fix idiotic bug – I meant to refer to the ‘Default User’ profile on disk not the ‘All Users’ profile! I blame Vista.) (Edited again to make the hyperlinks a more viewable color and to fix some font size issues with the shellcode that happened...
Robert Hensing's Blog
Hak5 produces 120GB LM hash rainbow table - complete charset!!!
Posted
over 6 years ago
by
rhensing
2
Comments
So the Hak5 folks have produced complete hash tables for the LM version of the password hash used by Windows and the tables are good for all valid characters that can be used in an LM password for the 1-7 password length. The "1-7 characters" part might...
Robert Hensing's Blog
2007 FIRST conferrence featured at the FIA GT race at Silverstone 5/6/2007
Posted
over 6 years ago
by
rhensing
0
Comments
This weekend, fellow racing enthusiast and driver Terry Pudwell has agreed to display the 2007 FIRST conferrence logo on his awesome GT car in the FIA GT race at Silverstone to promote awareness of the conferrence! The car featuring the logo will be...
Robert Hensing's Blog
Breaking out of the Chrome sandbox - 2 interesting vulns in 24 hours? Got IE8? :)
Posted
over 5 years ago
by
rhensing
1
Comments
So it hasn't even been out 24 hours yet but Chrome is, as predicted, getting scrutinized heavily and well . . . it's falling down at a pretty alarming rate (as say compared to say - IE8 beta 2 which has been out longer :)) So yesterday Aviv Raff discovered...
Page 1 of 12 (296 items)
1
2
3
4
5
»