Dear Anti virus vendors,
Your clients are getting compromised this very minute, instead of spending your time to please gamers (??) how about you spend 0,001% of your budget to implement generic methods of detection, especially for gateways.
Welcome to my personal Blog where I blog about Information Security and in general anything I regard as newsworthy. On the professional side I am currently working as a Lead of Threat and Vulnerability Management at Verizon Business.
TrustZone and Security Usability
-
Cem Paya has a really thought-provoking set of blog posts on “TrustZone,
TEE and the delusion of security indicators” (part 1, part 2“.) Cem makes
the poin...
One-Shot vs. Iterated Prisoner's Dilemma
-
This post by Aleatha Parker-Wood is very applicable to the things I wrote
in *Liars & Outliers*:
A lot of fundamental social problems can be modeled as a...
NC Fuel Distributor Hit by $800,000 Cyberheist
-
A fuel distribution firm in North Carolina lost more than $800,000 in a
cyberheist this month. Had the victim company or its bank detected the
unauthorized...
Network-based Malware Detection 2.0: Evolving NBMD
-
In the first post updating our research on Network-based Malware Detection,
we talked about how attackers have evolved their tactics, even over the
last ...
Meeting Alexander Bonde
-
Am Rande des Frühjahrsgipfels des NATO Parlamentes in Luxemburg hatte ich
ein informelles Gespräch mit Alexander Bonde, Minister für Ländlichen Raum
und Ve...
Quickpost: Signed PDF Stego
-
A signed PDF file is just like all signed files with embedded signatures:
the signature itself is excluded from the hash calculation. Open a signed
PDF doc...
On cellular encryption
-
If you're interested in technology/privacy issues then you probably heard last
week's big news out of the Boston Marathon case. It comes by way of former...
Giving Away HackRF
-
The HackRF project has been open source from the very beginning. Even before we started the project, Jared Boone and I wanted to have an open source hardwar...
Keeping skills current in a changing world
-
I came across this article on how older tech workers are having trouble
finding work. I’m sure many others have written about whether this is true,
whose f...
You know stuff. Share it. We’ll help.
-
You know stuff, you’ve seen interesting things, done interesting research,
have a unique perspective. You also know that the ability to communicate
effe...
Finding All Paths Between Two Functions in IDA
-
A common need that I have when reversing code is to find all possible code
paths between two functions. Say for example that I’m looking for calls to
dange...
Blackhole redirect story
-
Blackhole 2 redirect story
*1. Victim searches for jobs and internships on Google, and the sun is
shining*
GET
/url?sa=t&rct=j&q=internships%2008734&sou...
Could the AP Twitter hack have been prevented?
-
Twitter hacks can cause a lot of damage. It is news of this week that the
Associated Press Twitter account got compromised, and sent a tweet
announcing tha...
NoSuchCon : le programme est (vraiment) en ligne
-
L e programme de No Such Conference est en ligne. Vous pouvez le consulter
ici : http://www.nosuchcon.org/#schedule Speakers :
http://www.nosuchcon.org/#sp...
Rails - Guard, Brakeman, and Bundler-Audit
-
Thanks to the efforts of Justin Collins (@presidentbeef - Brakeman) and
Hal Brodigan (@postmodern_mod3 - Bundler-Audit), Rails developers (and
Sinatra) ca...
Teamspy: bulbanews or vulvanews – a funny note?
-
From Wikipedia: Bulba From Wikipedia, the free encyclopedia Bulba (Бульба,
[ˈbulʲba]) is a concert dance based on Belarusian folk traditions,
choreographed...
File updates to go with site change
-
I've been quite happy with the quick turn around that those that are using
or have links to Satori have been able to update blog posts, urls, and in
this c...
snorbert v1.0.8
-
Changes Fixed bug in copy functionality Modified the NetWitness query
generation as the generated query was too complex. Thanks ChrisB Added Find
window/fu...
Red Dawn: Unit 61398 – Now What?
-
Some of my ‘so-called’ friends that help organize the RSA Security Bloggers
event have decided that folks that attend should actually have blogged
somethin...
#RSAC is what you make of it
-
… Q: Are you going to RSA? A: Of course. RSA is mandatory punishment for
people like me. Like I said just before RSA USA 2012, each year at RSA I
want to q...
Exploiting 64-bit Linux like a boss
-
Back in November 2012, a Chrome Releases blog post mysteriously stated:
"Congratulations to Pinkie Pie for completing challenge: 64-bit exploit".
Chrome pa...
Androguard 1.9
-
Hi folks !
After pacsec conference in Tokyo, we finished few things to have a new version. And it is the time to release it !
We fixed a lot of things, bug...
My Journey to OSCP
-
This all started when I enrolled for PWB, the most exciting course in
network security. I had enough days to spend in lab but the pressure was to
complet...
Announcing first release of PVT
-
I am happy to announce first public release of my project - PVT. Excerpt
from the documentation:
PVT is a PHP extension designed to make search of security...
L’échec du e-commerce français
-
J'ai envie d'un Google Galaxy Nexus. C'est quand même pratique pour tester Android
4.1 ou webOS 1.0. Pas de problème, puisque la page officielle de Google
...
Mobile Device Forensics - Course Update
-
It's been a few weeks since the last update, but things have been busy. The
Fall 2012 term is now in Week 5 (wow, the semester is flying by). We've
covered...
Pwn2Own Pre-Game
-
Just in time to get warmed up for Pwn2Own, we are delivering a joint
offering of the training courses “Bug Hunting and Analysis 0×65” by Aaron
Portnoy and ...
NWScript JIT engine: Wrap-up (for now)
-
Yesterday, I provided a brief performance overview of the MSIL JIT backend
versus my implementation of an interpretive VM for various workloads.
Today, I’l...
0 comments
Post a Comment