You go to a website. You decide to sign up for a new account there. You’re taken to a screen where you meticulously enter your details, making sure you dont leave out any required fields (or else you’ll have to retype your password… twice). And right before you are allowed to hit “Submit” you see the final challenge of registerering for something online– a box with some strange symbols all jumbled up (possibly incomprehensible upon first glance) with the instructions “type what’s in the box.” Its not a new scenario– in fact, it’s probably something most people have had to deal with online since Captcha really got kicked off in the late 90s. In general, a Captcha is a challenge-response[…]

Watch where you download software from. Windows 7 RC is available for free from Microsoft, but some people are getting their copies from bittorrent, or other download sites. Several pirated copies have a trojan that is creating a botnet. If you’re wanting to try Windows 7, get it through a legitimate source so that you know what you’re downloading. I know Microsoft wants to keep track of everyone with a copy of the software, so they’re asking you to register with your Live ID. I personally think that they should make public the MD5/SHA1 hash of the download to help people avoid downloading a trojan.

On Wednesday, while the virtualization and cloud computing topics were continuing to see a lot of coverage, I began to focus my attendance in some different areas. The first Wednesday keynote included a brief discussion of the 60-day cybersecurity review by Melissa Hathaway, Acting Senior Director for Cyberspace for the Obama administration. While she did not tip her hand regarding what would be in the final report, she spent a lot of time discussing the importance of the report and the work which will come out of it. You can read her speech by following the word document link on this article in The Atlantic. Also on Wednesday was a panel discussion on the increasing prominence of legal and audit[…]

I can easily sum up what nearly every talk, every keynote, and every booth vendor is discussing here at RSA.  I just need four words: “Cloud computing and virtualization”. Virtualization is important because of the desire to make things cheaper and easier to maintain, and presents a powerful argument for power savings especially the week of earth day. The security concerns in virtualization are generally no different than they are with any current system, except for attack vectors between the host and guest operating systems. Virtualizing security services may be helpful in long term cost savings, but introduces additional risks which must be considered and mitigated or accepted. During the Cryptographer’s Panel, counterarguments about cloud computing were presented. Whit Diffie[…]

I’ll be attending the 2009 RSA Conference next week.  I will likely write one or more blog posts while there, so stay tuned. I also plan to use twitter to post interesting things I come across while there.  The following link will let you see all posts by @geminisecurity and/or @pmhesse with the RSA conference hashtag:  http://bit.ly/p5BTh I look forward to connecting with some of you out west. Drop me a line if you have got a few minutes to chat.

This concludes parts 1, 2 and 3 of our Sniffing Networks series. This part is a little less technical, but I still recommend that you be familiar with the first three parts. In part 3 of our series, I showed you how to use Wireshark to sniff traffic and hopefully gather some passwords. It’s a lot of digging through a haystack to find a needle. It works, and if you know some of the protocols, you can search for keywords to help you. But if you’re just lazy, there are two excellent tools for just passwords: dsniff on Unix, and Cain & Abel on Windows. Both tools do a little bit more than sniffing and support things like ARP spoofing[…]