Robert Hensing's Blog
Home of the "Fail Open Goat" Award
May 2008 - Posts
MediaDefender DDoS's Revision3
So Revision3 seems to be using BitTorrent to distribute legitimate / legal content that they either own or properly license. They found some folks using their Torrents without permission and blocked them . . . then they came under attack from a fairly
Read More...
Adobe (non)0-day
Nice blog from Adobe laying some authoritative smack down: http://blogs.adobe.com/psirt/2008/05/more_information_on_recent_fla.html Yeah I know this is old news - I'm on the road . . . I was pretty sure the day that this released that this was Dowd's
Read More...
Dear China, I can haz power now plz? okthxbai
Interesting read: http://www.nationaljournal.com/njmagazine/cs_20080531_6948.php Some interesting parts: A second information-security expert independently corroborated Bennett’s account of the Florida blackout. According to this individual, who cited
Read More...
SensePost blog on arbitrary file downloads in a Juniper AX
Fascinating blog over @ SensePost about a Juniper AX control that allowed arbitrary file downloads to a predictable location ala Apple/Safari: http://www.sensepost.com/blog/2237.html Haroon makes some excellent points about the inability of standard fuzzers
Read More...
Safari "carpet bombing" Fail Open Goat Award
So last week Nitesh and Billy Rios found a vuln in Safari that lets a remote attacker / malicious web site drop any file(s) they want on a users desktop if you're using Safari on Windows. Apple doesn't see this as a security vulnerability and thus isn't
Read More...
F-Response
So I admit I'm a bit out of date on the 'incident response' scene since I don't really do it for a living anymore. Well fortunately Harlan Carvey isn't and he has a blog post up with a mini-review of some bad-ass new software that could be *really* interesting
Read More...
Live.com video search!
Whoa - check this out: http://search.live.com/video/results.aspx?q=ferrari&form=QBVR Use Live.com to search videos . . . hover the mouse over a video and see what happens. Wow. I'm so easily amused. :)
Read More...
All your SSH keys are belong to HD Moore
Today's Fail Open Goat Award goes to the Debian / Ubuntu distros (a friend assures me that Ubuntu is derived from Debian and as such is also vulnerable?). HD Moore has decided to completely rape the Debian predictable RNG bug by generating all of the
Read More...
Microsoft Research - World Wide Telescope
This is the official unveiling of the app that made Scoble cry . . . now available to anyone on the Internets. http://www.worldwidetelescope.org/ So what is it? MSR has essentially used something like Photosynth (I'm guessing) to stitch together images
Read More...
Gmail - Fail Open Goat Award
Gmail is this month's winner of the Fail Open Goat Award: http://arstechnica.com/news.ars/post/20080510-security-flaw-turns-gmail-into-open-relay-server.html
Read More...
Security news feed
Here's a great RSS feed to subscribe to if you're into getting interesting securtiy news: http://www.team-cymru.org/News/
Read More...
Search
This Blog
Home
Email
Tags
No tags have been created or used yet.
Archives
December 2008 (1)
November 2008 (2)
October 2008 (11)
September 2008 (13)
August 2008 (6)
July 2008 (11)
June 2008 (24)
May 2008 (11)
April 2008 (15)
March 2008 (15)
February 2008 (11)
January 2008 (7)
December 2007 (9)
November 2007 (15)
October 2007 (23)
September 2007 (18)
August 2007 (8)
July 2007 (13)
June 2007 (10)
May 2007 (12)
April 2007 (8)
March 2007 (5)
February 2007 (4)
January 2007 (7)
December 2006 (5)
November 2006 (6)
September 2005 (1)
July 2005 (1)
March 2005 (4)
February 2005 (6)
January 2005 (8)
November 2004 (1)
October 2004 (2)
August 2004 (2)
July 2004 (1)
Syndication
RSS 2.0
Atom 1.0