
7:35 PM

Justin
, Posted in
forensics
,
security
,
0 Comments
Came across this interesting article today about a new anti-forensics tool that can basically add a bunch of stuff into memory to obfuscate what an attacker has really been up to, or even plant evidence to implicate someone else! Interesting stuff, I'm looking forward to hearing more about it!

5:12 PM

Justin
, Posted in
DDOS
,
security
,
0 Comments
I came across this advisory today, which i believe is the result of the DDoS attacks that were launched against a number of online games platforms such as Steam and the Playstation Network over the Christmas break.
Team Cymru have s secure NTP template available for Cisco, Juniper and Unix systems, the Canadians have more information available here and CERT have some information; including how to verify if you're vulnerable; here.

5:01 PM

Justin
, Posted in
government
,
Law
,
privacy
,
0 Comments
明けましておめでとございます!
Happy New Year from Security-Samurai.net!
Some interesting articles that recently caught my eye on the impending changes to the Privacy Act in Australia (courtesy of itnews.com.au):
Is your IP address personal information?
The Privacy Act and the cloud
Consent and the Privacy Act in the Big Data era
Are you ready for a data request deluge?
The posts raise some interesting points (such as is your IP address or mobile phone number PII?) and highlight some of the challenges Governments now face when trying to legislate privacy today.

4:55 PM

Justin
,
0 Comments
If true, this just leaves me speechless....

5:32 PM

Justin
, Posted in
hardening
,
security
,
vmware
,
0 Comments
The VMware hardening guide for vSphere 5.5 has been released and is available here: https://www.vmware.com/support/support-resources/hardening-guides.html
I've only had a chance to have a cursory look at it so far, but it looks pretty good.

1:25 PM

Justin
, Posted in
passwords
,
security
,
0 Comments
You know I'm referring to passwords right?
Also from the article:
"studies suggest red-haired women tend to choose the best passwords and men with bushy beards or unkempt hair, the worst."
Did that study include *nix admins?
Also from the BBC, an an analysis on the Adobe passwords that were leaked. No real news here, except to say people still choose terrible passwords....
Top 20 passwords
- 123456
- 123456789
- password
- adobe123
- 12345678
- qwerty
- 1234567
- 111111
- photoshop
- 123123
- 1234567890
- 000000
- abc123
- 1234
- adobe1
- macromedia
- azerty
- iloveyou
- aaaaaa
- 654321
We've probably all done it. I have. You know you have too. Go on, admit it!
Done what you ask? Scrounged around for some free WiFi when travelling. With data roaming costs being so high, free wifi can be a blessing - except when it's a curse!
Here's a fun article from tripwire highlighting how easy it can be to capture credentials from unwitting travellers at an airport and how poor the information security practices in some hotels can be.
What Nabil describes in his article about default passwords and poorly segmented networks pretty much matches some of the stuff I've seen when travelling. What makes it worse is when the place is charging a small fortune for daily internet access - where is that money going? Not on security apparently!
Long story short - don't let down your guard even when connected to 'safe' networks and VPN is your friend!
Oh and Nabil's http://www.toolswatch.org/ page is pretty cool too. Go check it out!