RSS

Archive | Security RSS feed for this section

Detecting Bot Command and Control Channels

19. February 2008

2 Comments

I came across this paper on Detecting bot C&C channels in network traffic. It is from the Georgia Institute of Technology. An interesting read if you follow the bot problem. –Chris Technorati Tags: bot, command and control, channel

Continue reading...

(ab)using Tor to spy on connections

13. February 2008

0 Comments

I saw a reference to this article recently. I knew how Tor worked but never really go under the hood of the exit servers. Well apparently some others have and are setting up their own exit servers for nefarious purposes. It seems as though if you setup an exit server you can specify what ports [...]

Continue reading...

Anyone still blocking Javascript?

6. January 2008

2 Comments

In this new age of Ajax / Web 2.0, is anyone still blocking Javascript at the perimeter or disabling it in the browser?? I remember when this was a significant issue…and it may still be one. It seems like the advantages (perceived or not) of real time page updates provided by Ajax are out weighing [...]

Continue reading...

Two job openings at my company

23. October 2007

0 Comments

My company, GreenPages, has openings for the following positions: Director of SMB & Education Solutions Senior Network Engineer If you or someone you know is interested send me an email, chris@infosecpodcast.com or Skype at chrisharrington Thanks! –Chris Technorati Tags: GreenPages, employment

Continue reading...

Backpack mounted Laser

22. August 2007

0 Comments

Ok…not security related but I thought it was interesting. A German company is producing a backpack mounted Laser system apparently designed for cleaning thinks. Think of the uses….. Is it me or are we just missing Harold Ramis wearing a white jumpsuit? –Chris Technorati Tags: laser, backpack

Continue reading...

Hacking Illustrated Videos

20. August 2007

0 Comments

I was poking around IronGeek’s site tonight and came across the Hacking Illustrated section. In it there are dozens of videos (in both avi and swf format) on subjects such as: Remote Password Auditing Using THC-Hydra Setting up a simple web proxy with CGIProxy Using Cain and the AirPcap USB adapter to crack WPA/WPA2 Using [...]

Continue reading...

Spammers using FDF file format

17. August 2007

0 Comments

In their never ending quest to evade our filters the spammers have now started using FDF attachments to spread their message. I’ll admit I had to look up what an FDF file was. It stands for Forms Document Format. This file format can be viewed using Acrobat reader the way a PDF file would. Apparently [...]

Continue reading...

Stopping 100% of web proxies?

16. August 2007

4 Comments

There have been a couple of security vendor press releases recently talking about how they solve the issue of anonymous web proxies. These proxies are web servers that allow users to circumvent URL / content filtering systems to access sites that may be prohibited at work. There are a ton of proxies for MySpace, for [...]

Continue reading...

Bad Behavior has blocked 1543 access attempts in the last 7 days.

Rodney's 404 Handler Plugin plugged in.