Security: Opinions
Opinions
- +
Partially disclosing vulnerabilities does no one any good 30/09/2008 12:00:00
Partially disclosing vulnerabilities and building up hype before disclosing full details appears to be on the increase. Only problem is that it isn't doing anyone any good.What if I was to tell you that I have a secret that could end the Internet as you know it? What if I was only going to tell you at a fee-based conference once speculation had gone on for a month or more? How would you respond to that? - +
Wider implications of the Red Hat breach 29/08/2008 09:11:00
Red Hat's recent server breach isn't the first time that a Linux distribution has been targeted by attackers, but it could be one of the most important attacks in terms of the recovery and mitigation processes.Reports of data losses and system breaches are almost becoming passe but from time to time events happen that take on a life of their own and have effects far beyond what the initial breach would normally represent. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
How to avoid the Debian SSH key attacks 16/05/2008 08:35:57
It only took two days, but viable, simple attacks against the weak Debian SSH key generation flaw have surfacedIf you are running a Debian-based Linux system and haven't already caught up with the announcement [1] that there was a major flaw with the generation of SSH, OpenVPN, DNSSEC, SSL/TLS session keys and X.509 certificate key material, you might want to update your system to address the problem. - +
Pentagon hacks and Google Maps 11/03/2008 09:56:12
Pentagon gets owned via an ordinary spear phishing attackI have this nosy but absent-minded Uncle. He likes to paw through my emails, peruse my web history, and tap my phones. But when it comes to protecting his own, more important secrets, he's mostly clueless. - +
Mu Security Analyzer 04/01/2008 07:28:03
Mu-4000 fuzzer shines with wizard-driven test configuration, intelligent workflow, excellent vulnerability profiling, and auto-generated zero-day exploitsI first came across the Mu Security Analyzer when a co-worker on a multi-company government project raved about how the appliance found a zero-day vulnerability in an e-mail inspection device that was protecting a top secret government agency. It was a rather simple script bug in the other vendor's product, but it would have allowed uncontrolled code execution. The implication was that our top secret project could have been compromised by an external hacker running penetration tests against our e-mail services. Initially, the manufacturer of the compromised mail filter refused to believe that a weakness existed in its product. That is, until we sent the exploit, automatically generated by the Mu analyzer, that the vendor's engineers could run to see for themselves.
Additional Resources
Polls
LinuxWorld Member Login
Extreme Networks Ethernet Transport lowers total cost of ownership for carrier metro networks 2008-11-20 10:21:00+11
Mitel Launches Simpler Unified Communications 2008-11-19 17:40:00+11
Kingston Technology Launches HyperX T1 Series Memory 2008-11-19 11:00:00+11
Valorem uniquely deploys RSA SecurID for remote workforce management 2008-11-19 10:16:00+11
VIA Launches VIPRO Touch-Screen Panel PC 2008-11-18 21:00:00+11
Sponsored Links



