We have recently taken a look at Internet Explorer 6 (IE6) to try and help convince a customer of ours to stop deploying it on workstations.IE6 still holds about 33% of the browser market share, but Microsoft stopped mainstream support for it in April of 2009. IE6 runs ActiveX controls at the same privilege as the browser, which is the same privilege as the user – typically administrator level. And according to Secunia there are 23 known unpatched vulnerabilities in IE6 – including one which has been around since 2003. And in a timely post from Brian Krebs on his new site krebsonsecurity.com, there’s a very simple way to crash IE6. If you’re curious and have IE6 lying around, type[…]
Category: software
Dan Kaminsky posted on twitter the following: http://eprint.iacr.org/2010/006.pdf Is it time to deprecate 1024bit RSA for, say, 1276bit? (2048 has perf issues.) The link Dan provided is a research paper which reports the successful factorization of the 768-bit number from the original 2001 RSA challenge. I responded to him that NIST had already deprecated the use of 1024-bit RSA in the government, and it was time for industry to follow suit. Since I posted that, I’ve been surprised that a number of people don’t understand the upcoming changes in key lengths and algorithm strengths that have been mandated by NIST. So, this post offers some information about why I can confidently say the U.S. government has deprecated certain algorithms and[…]
Damn Vulnerable Web App (DVWA) has released an updated version (v1.04) of their PHP/mySQL web application that is intended to be attacked. It’s intended to be run on a local (closed) network as a learning tool for exploits and vulnerabilities. As it sits now, it pretty much contains a lot of the basics – brute force, command execution, file inclusion, SQL injection, and XSS.
With Windows holding 89.6% of the global market share, it is a very large target. This is one of the reasons Windows is targeted so much by malicious attacks. Not very hard when you’re such a big target. So, what if you could change that and make your Windows machine/server appear as something else, even to the most notable of sniffing tools (Nmap, P0f, Ettercap, etc.)? Well, you can.
Les Jordan from Microsoft recently wrote a blog post entitled Identity Management: a key to seamless CTMS and EDC. In it, he presents some of the solutions Microsoft is introducing in the identity management space, currently under the name of Microsoft Geneva including the Geneva Framework, and the Microsoft Identity Federation Gateway. The idea is fairly simple. Many (most?) large enterprises already manage their users and systems using Active Directory. Geneva allows publishing the components of your Active Directory required for doing identity federation on the Internet. The publishing is performed in a standards-compliant way (using WS-* and SAML 2.0) and allows it to be used for claims between enterprises. …the issue of Identity Management, Username and Password proliferation, and[…]
With the release of the new iPhone 3.0, I thought it would be worth visiting some useful security-related iPhone applications. These are 4 good security applications for the iPhone that will make you the coolest person at the next IT security conference. 1Password (Cost: $4.99) – This application encrypts your iPhone data using AES, effectively features single sign-on to websites, and adds an extra unlock code layer to your device – using a single password. The power of this application is in the encryption, and has some other goodies like password generation and secure notes built in as well as a desktop version and syncing (for extra). RSA SecurID Software Token (Cost: Free) – SecurID relies on 2-factor authentication, and[…]