Verizon Business has released their 2009 Data Breach Investigations Report [pdf] and an accompanying blog post. 2008 was a crazy year in the world of data breaches… The percentage of breaches in our caseload involving financial service organizations, targeted attacks, and customized malware all doubled in 2008. It’s sure to win me the “Captain Obvious Award” from the Securitymetrics list, but organized crime activity increased and was responsible for over 90% of the 285 million records compromised. The report is sure to be a good read. We linked last year’s report, and this year’s report has some improvements–it is based on more data was collected more often, and goes into a lot more detail than the previous report. 285 million[…]
Category: hacking
Grendel Scan is a powerful web application scanner that can help you identify potential security gaps across your websites. There are a number of web application scanners freely available (Tim reviewed w3af last week), but Grendel Scan has a number of features that make it a useful tool for administrators, in particular those who may not have much (or any) penetration testing experience but are looking to close potential vulnerabilities across their web applications. Unlike w3af, Grendel Scan’s GUI interface is fully functional. You only need to identify a place to store the scan files and a URL to get started. Grendel Scan works mostly in the background and doesn’t require much attention once the scan gets going. The final[…]
Mainstream media is beginning to sound the alarms about the Conficker-C worm which is believed to be affecting more than 2 million Windows PCs. Conficker spreads by an RPC-DCOM flaw in Windows, as well as by network shares–logging into machines that use weak passwords–and by removable media. There is a trigger in the code to download new instructions on April 1st, 2009. Much like the Mydoom or the Sobig worms of years past, researchers know a date when an update is expected to occur, but don’t know exactly what will happen. And, much like those years past, it is likely that not much will occur. Microsoft along with other security researchers created the Conficker Cabal which has put a $250,000.00 bounty[…]
Do you type passwords into web pages? Let me introduce you to your worst nightmare: sslstrip. The author of this program realized that most people don’t type in the https prefix, and don’t look closely for padlock icons. sslstrip takes advantage of this, and transparently hijacks HTTP traffic, replacing all HTTPS links and redirects with look-alikes. Read the full article to understand how this tool takes advantage of a design flaw in the world wide web.
It’s worth a discussion. Is Randall Munroe, writer of xkcd.com correct? Is there an unreasonable investment in cryptography and information security? My take: Since the ‘drug him and hit him with a wrench’ probably violates several very enforceable laws, the attacker is taking a pretty big risk going down that path. Whereas if the attacker was just trying to expose flaws or use massively parallel processing to crack a key, that may violate some laws on paper (ahem) which are harder to enforce–and an attacker would be pretty dumb to let slip that they were up to something like that. What are your thoughts?
I’m sure if you’ve been paying attention to any of the tech/geek news blogs you’ve seen the attention given to the “COMPROMISING ELECTROMAGNETIC EMANATIONS OF WIRED KEYBOARDS” article. So you already know the buzz, and are probably all running out to build Faraday cages around your offices or workstations. But there really isn’t anything terribly new or ground breaking here. It’s simply a further spin on an old trick. Anyone who can remember back might recall a little something about “TEMPEST“. It’s the codename given to compromising emanations (CE). This research dates all the way back to 1985 when the security risks of emanations from computer monitors was analyzed. By no means do I want to take away from the[…]