I had the good fortune to attend ShmooCon 2011 last weekend. A new tradition at ShmooCon is evening “firetalks” on Friday and Saturday. Basically, after the conference has ended for the day, a bunch of folks decide to put off parties for a few more hours in order to do a bunch of 15-minute “get right to the point” talks. This year had a good selection of topics and speakers, with one that jumped out to me as a perfect topic for this week’s “Technology & Tool Thursday” post. Armitage was written by Raphael Mudge (not to be confused with Peiter “Mudge” Zatko). It’s a GUI interface for using Metasploit to pwn your targets. Metasploit is a tremendous framework for[…]
Sometimes you receive an encrypted e-mail that you can’t open. I don’t know about other clients, but Outlook doesn’t allow you to do much with e-mails that aren’t encrypted for you, and if you’re like me, you want more information. You want to know exactly what went wrong. So, here is a quick way of retrieving the information you need from an Outlook e-mail in order to find out which certificates were used to encrypt the e-mail. (Note: This method may not always work, but I have found it useful many times in the past.)
Unless you work for a network or internet service provider, there’s only so much you can do about the IPcalypse. But you can be ready for the IPv6 transition, and you really should be. We’ve seen this day coming for years now.
What is the first step to creating a new building? Is it grading the land? Building a foundation? No, the first step to creating a new building is to architect it. I might be able to learn enough about engineering and architecture to design a house. I doubt anything I came up with would be elegant enough to be on the cover of Architectural Digest – I don’t have enough experience! And likewise, my friend who is an artist could probably come up with some really fantastic, charming design for a house, sure to stun anyone who walks by… but her design might not be sufficient to meet building codes or even support its own roof. Architecture is the process of design,[…]
Although we’ve made many posts about the importance of password security, have you ever wondered just how long it would take for a well-equipped attacker (having access to clusters or supercomputers) to brute force your password? Or how much more protection you gain from adding some special characters? If you’re not inclined to crank out the numbers yourself, you might find the answers you’re looking for here. Here are some basic stats: With access to super-computing-like power (trying over 1 billion per second), it only takes about 84 days to crack the common 8 character password (alphanumeric mixed case, including special characters). With access to a less powerful class of attack machines (10k per second), without including special symbols, an[…]
I wrote a bit about Stuxnet on my own blog last November, but we’ve not really addressed it here on Security Musings. By most accounts, this is one of the single-most important incidents in 2010, with the possibility to change the game. There has been a lot of discussion this week about attributing the source of Stuxnet, which is particularly interesting. First, for a bit of background, check out Bill Brenner’s post over at CSO Online covering “Three takes on Stuxnet” as he includes a couple of the links I’d originally planned to use here. He links to presentations on Stuxnet from Symantec, Kaspersky, and – my personal favorite – Mikko Hyppönen, Chief Research Officer at F-Secure. Given the scenario[…]