SEARCH RESULTS
 
Showing 1-10 of 134 records
 
Expand article

Diminutive XSS Worm Contest Drama and Status Update

2008-01-06 17:34:38 by RSnake in ha.ckers.org web application security lab
 
...actual XSS propagation, for which there has been little research done to date Ive always said, you dont understand a problem until you see it and play with it. This is why having experience is always more valuable than schooling in a topic. Its like trying to get in a fist fight with a professional boxer having never sparred before and...
 
 
 
 
 
Expand article

Kn1ghtl0rd and Lowtek Mystik's RFID 2.0 PhreakNIC Presentation

2007-09-21 05:05:54 by Editor in Irongeek's Security Site
 
...actual circuitry of an RFID tag and what it takes to make them operate more consistently. The presentation will also cover actual tag data and coding schemes with standardization including EPC Gen 2 and other ISO standards such as PayPass RFID enabled credit cards. There will be reader/writer demonstrations as well as other proof of concept...
 
 
 
 
 
Expand article

Moto Q9 DoS and Fingerprinting

2008-01-12 18:10:21 by RSnake in ha.ckers.org web application security lab
 
...actual device type! So then I turn the setting to desktop computer it turns to Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) Opera 8.65 [en] UP.Link/6.3.1.17.0. Okay, fair enough, that appears to be the more secure setting as at least it doesnt say the revision and model number of the phone That is, of course, until you look at the...
 
 
 
 
 
Expand article

Measuring Vulnerability

The Article has images
2008-04-14 14:31:38 by JonesJ in RiskAnalys.is
...actual tornado data In order to determine the probability of being vulnerable, wed use a Monte Carlo function to Take a random value from the tornado distribution and from the structural resistance distribution Compare the values i.e., for this iteration, determine whether wind speed was greater than resistance If wind speed was greater,...
 
 
 
 
 
Expand article

What Would Galileo Think

The Article has images
2008-06-05 03:08:00 by Richard Bejtlich in TaoSecurity
...actual relation to ground truth Enter Galileo , his telescope, and his invention of science. Suddenly a man is defending the heliocentric model proposed by Copernicus using measurements and data, not eloquent speech and debating tactics. If you disagree with Galileo (and people tried), you have to debate his experimental results, not his...
 
 
 
 
 
Expand article

The War on Photography

2008-06-05 06:44:54 by schneier in Schneier on Security
 
...actual movies and television shows. These movie plots resonate in our minds and in the minds of others we talk to. And many of us get scared Terrorists taking pictures is a quintessential detail in any good movie. Of course it makes sense that terrorists will take pictures of their targets. They have to do reconnaissance, don't they? We need...
 
 
 
 
 
Expand article

So, you think youve removed that sensitive data (part II)

2008-06-03 00:55:25 by Slavik in Musings on Database Security
 
As I wrote in a previous post, truncating tables or scrambling content might not remove the actual data from the datafiles. The examples I gave in that post were Oracle related and now Ill show the same using MS SQL Server 2005. Id like to thank Dmitriy Geyzerskiy for providing the actual working example. create database
 
 
 
 
 
Expand article

Fast Track to Botnet Central

The Article has images
2008-07-01 09:41:45 by Chris Mannon in SpywareGuide Greynets Blog
...actually attempting to purchase the fake product. FastTrackBot inserts a fake security center that appears identical to the one found in Windows XP As you can see in the address bar, this is not the actual security center. Clicking anywhere on this window means almost certain doom in the worst way possible...a never ending stream of fake...
 
 
 
 
 
Expand article

Some IPFW students exposed through malware

The Article has images
2007-11-29 13:26:49 by Evan Francen in The Breach Blog
...actual, and not some sort of scam," said Dougal It's through IPFW's network, so I think they can limit what people can do, I think... I hope," said IPFW student Casey Bowman I trust that most of the systems pick-up things, and I would probably continue to do what I'm doing," said IPFW student Jermaine Porter Commentary Think for second...
 
 
 
 
 
Expand article

You Can't Tell the Malware Kits Without A Scorecard!

2007-08-24 13:57:55 by Editor in Cheap Hack
 
...actual malicious software that we download and install after confusing it with an e-card or free pornography. Here's a blog that specializes in monitoring these kits. There's dangerous stuff in the links there, so be careful. It's at sites like this that you wonder about the line between malware authors and malware analysis. This site is...