Category: InfoSec
-
Book Review: Hack Attacks Revealed
[This was originally published on Enterprise Zone and mirrored on attrition.org.] Hack Attacks RevealedA Complete Reference with Custom Security Hacking ToolkitJohn Chirillo047141624X, 960 Pages, Wiley Computer PublishingHack Attacks RevealedPartially Hack Attacks Revealed begins with a solid technical foundation but soon unravels without revealing true hacking. Hackers understand that the true art and spirit of hacking…
-
Cyberwar with China: Self-fulfilling Prophecy
[This was written by Sioda and myself and originally published on attrition.org.] Voltaire once wrote, “If God didn’t exist, Man would have to invent Him.” It would seem that the popular press has taken this axiom and turned it on its ear. At the time of this writing, we are inundated with Chicken Little style…
-
Cashing in on Vaporware
“The CERT Coordination Center is a center of Internet security expertise“, and they have a new product to sell you. Only it isn’t really new – and it was never a stellar product to begin with. For years, CERT has been a federally funded group handling incident response, vulnerability analysis and published security alerts. They…
-
Should you spy on your employees?
[This was originally published on IBM Developer Works.] Should you spy on your employees?Why, when, and how to electronically monitor your staff Brian MartinDSIC Security GroupFebruary 2001 If you run a warehouse, you can spot pilfering by the number of empty boxes, or perhaps by noticing that employees are walking out with TV sets on…
-
A Note on Security Disclosures
[This was originally published in ;Login magazine. A pretty PDF version is available with the charts that are missing below.] In recent months, a handful of outspoken security professionals have begunto openly challenge the philosophy of full disclosure. For years, most ofus in the security community have held this philosophy as a basic tenantof vulnerability…
-
Defacement-Commentary Address
[This was originally published on attrition.org.] “CyberWar Rages in the Middle East!!! YOUR Servers could be next!!!“ This is the kind of crap coming out of so-called security companies and news media lately. The real irony is that they are using data from the Attrition web defacement mirror to support their hyped conclusions. Let’s take…
-
Convict them all! A new breed of ambulance chasers
[This is a rebuttal/rant in which I ‘reply’ to various parts of a news article, originally published on attrition.org. This version has been updated for style.] Computer crime: Changing the public’s perception12 Oct 2000https://seclists.org/isn/2000/Oct/51 You remember Jonathan James? He made national news a couple of weeks ago. You know, he’s that nice 16-year-old young man…
-
Screw the thief. Convict the state department morons…
[This is a rebuttal/rant in which I ‘reply’ to various parts of a news article, originally published on attrition.org. This version has been updated for style.] Desperate US offers 25,000 dollars for missing State Department laptophttps://seclists.org/isn/2000/Aug/53 (Original now 404)Thursday, August 10 4:20 AM SGT WASHINGTON, Aug 9 (AFP) – Apparently frustrated and desperate for leadsafter…
-
The Not-So-Scientific Process
[This was originally published on attrition.org.] During a recent trip to New York to attend HOPE 2000, I was introduced to a new project underway to help “dispel the myths about hackers”. Founded by a four person team at the Laurentian University School of Commerce, they have devised a survey to help “further Hackerdom’s growth by enabling…
-
Hacker attacks welcomed…
[This was originally published on attrition.org, and reprinted on Linux Security.] Hacker attacks welcomed.. I’m sure they are. The new article reads: Openhack data will help e-businesses develop the appropriate balance of Net security, opennesshttp://www.zdnet.com/eweek/stories/general/0,11011,2593631,00.html Does this bring flashbacks of any previous contest? Does for me. I seem to recall the same group running a…