SEARCH RESULTS
 
Showing 1-10 of 44 records
 
Expand article

U.S. Spies Use Custom Videogames to Learn How to Think

2008-04-24 03:30:00 by Michael Peck in Wired Security
 
The U.S. Defense Intelligence Agency commissions three custom games to teach new recruits critical thinking skills, while the Army builds its own simulator to instruct intelligence officers in the art of interrogation. No virtual waterboarding allowed
 
 
 
 
 
Expand article

CNN Custom Alerts Spam

The Article has images
2008-08-10 17:28:40 by Christopher Boyd in SpywareGuide Greynets Blog
In general, my anti-spam filters and tools are pretty effective. So when I start to see something like this it's obvious that a huge spam wave is underway. These are, of course, related to the fake CNN Spam from a few days ago. Here, the emails take the form of "custom alerts Click to Enlarge I've seen two types of this mail - one...
 
 
 
 
 
Expand article

Better exception reporting in ASP.NET

2008-08-01 20:30:05 by keith-brown in Security Briefs
 
In my last post , I commented on how ASP.NET health monitoring doesn't output stack traces for inner exceptions, which can be problematic due to its heavy reliance on reflection. I spent the morning doing some further spelunking with reflector , and my first solution was to implement a custom WebEvent that overrides ToString() to format itself...
 
 
 
 
 
Expand article

NSA Attacks West Point! Relax, It's a Cyberwar Game

2008-05-10 01:00:00 by David Axe in Wired Security
 
Five hours into their assault on West Point, the hackers got serious The SQL [structured query language] inserts that came earlier were just pablum intended to lull the Army cadets into a false sense of security. But then the bad guys unleashed a stealthy kernel-level rootkit that burrowed into one workstation, started scraping data and "calling...
 
 
 
 
 
Expand article

Identity Framework Probable Feature List

The Article has images
2007-12-16 06:42:00 by Keith Brown in Security Briefs
Vittorio has just concluded a series of posts where he's sharing a sneak preview of the Identity Framework (Fx for this post). Based on what he's shown and his descriptions, I've put together a little list of some features we can probably expect from the Fx. This is all pre-alpha stuff and the API will probably change, but the core features...
 
 
 
 
 
Expand article

Some Burning Logging Questions - Answered!

2008-04-23 16:20:00 by Dr Anton Chuvakin in Anton Chuvakin Blog -
 
I was wandering down a street and somebody came out and confronted me with these logging questions :-) So I answered them - now I am posting them here since they might be useful for my readers Q1: For those companies that have successfully implemented enterprise-wide logging, what were the big nasty surprises that they encountered A1: Here are a...
 
 
 
 
 
Expand article

Corrupted Heap Termination Redux

2008-06-07 04:00:00 by sdl in The Security Development Lifecycle
 
Hi, Michael here In a previous post I explained how to use HeapSetInformation correctly. In short there's an option when calling this function that will terminate your application if the heap manager detects some form of heap corruption, or the potential to cause heap corruption I would recommend you read the previous post before continuing You...
 
 
 
 
 
Expand article

Streaming SQL Approaches Insist in Ignoring Causality by PatternStorm

2008-09-05 14:25:35 by Tim Bass in The Complex Event Processing Blog
 
The following excellent discussion is reposted from Streaming SQL approaches insist in ignoring causality by PatternStorm The recent paper Towards a Streaming SQL Standard by Oracle and Streambase unifies and generalizes two different execution models of Streaming SQL: Oracles and StreamBases While its true that the generalization succeeds in...
 
 
 
 
 
Expand article

DIY Fake MSN Client Stealing Passwords

The Article has images
2008-01-17 10:06:24 by HASH0x8b6b58c in Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
This tool deserves our attention mostly because of its do-it-yourself (DIY) nature , just like the many other related ones I discussed before. Custom error messages, two options for to kill or restore MSN after the password is obtained, and custom FTP settings to upload the accounting data. Why did they choose FTP compared to email as the leak...