Thursday, January 3, 2008

Hacking exercise

I think that every hacker should be able to go through this exercise, so readers please test yourself
clipped from news.zdnet.com
A Microsoft executive calls the ease with which two British e-crime specialists managed to hack into a Windows XP computer as both "enlightening and frightening."


The demonstration took place Monday at an event sponsored by Get Safe Online--a joint initiative of the U.K. government and industry. At the event, which was aimed at heightening security awareness among small businesses, two members of the U.K. government intelligence group Serious Organized Crime Agency connected a machine running Windows XP with Service Pack 1 to an unsecured wireless network. The machine was running no antivirus, firewall, or anti-spyware software and contained a sample target file of passwords to be stolen.

 blog it

Wednesday, December 19, 2007

Cracking passwords to web applications

Many web applications can be broken into. How?

Some common vulnerabilities that can easily lead to an attacker cracking Web passwords include the following:

  • No intruder lockout after a certain number of failed attempts
  • Intruder lockout time that's too short
  • Allowing simultaneous logins from the same or multiple hosts
  • Transmitting login traffic via HTTP and not using SSL
Want to see tools and examples? See the article by Kevin Beaver.

Monday, November 26, 2007

Avoid licensed software

Meaning, do not use software which requires a license. Why? This is why: the makers of it will screw you. See here.

Rather, invest your time in understanding open source alternatives. To quote from this article,

"It's not like they have really good software. It's just that it's widespread and it's commonly used," Gaertner said. "It's going to be a while, but eventually, we plan to get completely disengaged from those software vendors that participate in the BSA."

Tuesday, October 30, 2007

Have you ever sent an email which you immediately wanted back?

Well, this government employee revealed the email addresses of 150 secret informers by clicking on "Reply all". Then a few hours later he sent a recall notice. However, this notice also included all the email addresses again.

I am sure I could create a special rule warning one on sending such kinds of emails, and add it to most email clients. Anybody wants to take me up on that?

Wednesday, October 24, 2007

Forensics Delivery? - Why not!

Another quote from Christy Burke's article is below. Top8 has trained drivers for this, and some have concealed handgun licenses.

Sometimes, commercial carriers are perfectly adequate to transport evidence, but occasionally greater security is warranted. Computer forensics expert and Sensei Enterprises President Sharon Nelson says that FedEx is often sufficient for transporting e-discovery materials, since they require a signature on each end and record the time and date of receipt. However, Nelson has seen many more "hands-on" approaches to bringing in the data.

"A lot of our clients won't go through FedEx," Nelson says. "We have had famous people show up personally with armed guards, carrying their CPU towers in their hands. Or they sometimes send a lawyer, a trusted agent or an employee to bring it in. Once it's in our care, we're responsible for it -- we image the drive and return it to the representative." Other highly secure transportation alternatives include armored car transport and bonded messengers.

Tuesday, October 23, 2007

Who needs discovery? - Well, who does not?

In a very informative on its own right article, "Examining E-Discovery Chain of Custody", Christy Burke brings an interested quote:

"Tom O'Connor, a litigation support consultant and director of the Legal Electronic Document Institute in Seattle, says that the No. 1 request for e-discovery that he's seeing in Washington state is for divorce cases, not criminal ones. Investigators confiscate and search laptops and home computers for proof of adulterous affairs, hidden financial assets and the like -- a far cry from the notorious bloody glove in the O.J. case."

I remember a divorce lawyer, a friend of mine, telling me that "my clients only want to discover the other party's checkbook", only a year ago. It seems this has changed lot.

Monday, October 22, 2007

E-Discovery Law a Boon for Lawyers

We are at your service
clipped from www.pcworld.com
The fourth annual "Litigation Trends Survey Findings" conducted by Fulbright & Jaworski L.L.P, a global law firm based in Austin, Texas, found that corporate lawyers -- over two-thirds based in the United States and the rest mainly in Britain -- cited a big jump in use of outside vendors and outside law firms specializing in the e-discovery field. The industry sectors primarily represented are financial services, technology/communications, manufacturing, healthcare, energy and retail.
 blog it