There has been a fair bit of blog buzz about the new SQL Injection worm that ran around infecting sites. I have not looked too deeply into it, but have not yet seen accounts of how the targeting...
a) its my birthday in a few days b) Apple just announced the new macbookair.. Coincidence??? i think not!!!
This quote reminded of something H always says: “When opportunity comes… its too late to prepare” – John Wooden – Hall of Fame Basketball coach
John is one of the bright guys over at NGS, and judging by his track record will boost the signal to noise ratio in the blogosphere.. You can read him at [aut disce, aut discede] (of course, in...
Black Hat DC this year is supposed to be “a different kind of Black Hat”. There are four tracks over the two days with a special emphasis on wireless and speakers include Chris Wysopal, FX from...
For those of you who have not yet tried it, check out Tooble. Its a point and click tool that lets you download videos from the youtube.. its pretty cool and allows u to pull/convert videos pretty...
While im into posting mac-links.. Check out [Webkit] A little while back i mentioned not understanding why anyone would run a closed source browser while a decent open source version existed.....
Old timers here will know about the concept of bruteforcing DNS using the clues available.. i.e. zone transfers disabled, but u see that the NS and MX servers are called gandalf.company.com and...
H said that there is a tool that will do the HTTP Mangler functionality out of the box. So here goes. WebScarab-NG is the tool that will do the trick. First we select the feature that will allow...
So everyone uses the live search engine with a ip: when trying to locate virtual hosts. I used domaintools in the past with good results, till they went fully pay-per-use. Checkout Reverse IP...
Many people took a crack at “what tool will work to replace mangler, out of the box” and so we have a bunch of new tools to play with.. Steven’s answer of MS-Word or PowerPoint left us scratching...
(my first X-Rated blog post.. i should hook up ad-words and watch the money roll in!) Ok.. our Zimbabwean recruit was posed the following question by some international academics: Q:”How would you...
So felten et al basically figured that cooling dram chips allows an attacker to move them to another machine where they can be leeched! The geek in me cant help but say “COOL!” According to the...
-sigh- the topic is stolen directly from the [DarkReading Article] -snip- Itâ€s yet another new spin on a pervasive attack — this time using the old standby Simple Network Management Protocol...
On a recent assessment we came across the following scenario: 1) We have command execution through a web command interpreter script (cmd.jsp) on a remote Linux webserver 2) The box is firewalled...
Peltier and Associates have released their massive “Peltier Effect – Year in Review 2007“. The collection comes in at a whopping 156 pages from a wide array of authors so there should be somethign...
“SensePost have once again been invited to join the South African Department of Trade and Industry at Cebit, as one of 10 SA companies, to exhibit on their pavilion. Visitors to this show range in...
Ok.. so the title clearly isnt true.. but it made more sense than saying something about the altered geographic location of someone’s dairy products. It is however true, that this particular blog...
At last years BlackHat USA a bunch of us played some American geeks a game of late night parking lot football.. Our victory there, and the 6 months of victorious memories from that night filled us...
Apparently the two _are_ mutually exclusive.. [according to the NY Times…] -snip- According to the study, published in February in Oikos, a highly respected scientific journal, the more beer a...
SourceBoston completed its first conference earlier this month, and some of the slide decks and videos are up.. While the image of the young hax0rs indeed brings back fond memories of surfing...
from the SourceBoston videos i blogged about: Dr Geer never dissapoints, and kicked it off with the 4 rules on his office wall: Work like hell, Share all you know, Abide by your handshake, Have...
Whoa! time flies when you having fun… (click for orig.)
Uninformed has certainly done awesomely at filling in the gap left when phrack went silent, but there is something nostalgic about reading phrack… it seems like issue 65 has just hit the streets..
Hello All, Some of you might remember that I climbed Mount Kilimanjaro two years ago. What you might not know is the REASON I did this (apart from the jol) was to o raise funds for CNCF, a...
Then you probably should get on this one… [Problems with Random Number Generator] While it looks like an arb openssl bug, 2 seconds of reading should get you to: -snip- It is strongly recommended...
Earlier this week we had an internal presentation on Attacking ActiveX Controls. The main reason we had it is because of the ridiculously high hit rate we have whenever we look at controls with a...
Some of the DC16 speaker summaries have been posted, and these 2 caught my eye: Time-Based Blind SQL Injection using heavy queries and New Tool for SQL Injection with DNS Exfiltration Both...
but since it made me eat crow, i figured i would share it.. Although i read a fair bit, i stopped really reading fiction many many moons ago. Its something i often feel ill try to get back into...
The recent Safari Carpet Bombing bug reported by Nitesh Dhanjani and ignored by Apple had all the makings of an egg-on-face incident. We were discussing it over foosball, and the obvious consensus...