• Domain Transfer Confirmation Email? No, It’s Not From ICANN… BUT…
    Domain Transfer Confirmation Email? No, It’s Not From ICANN… BUT…

    [3/7/2026 Update: So after all this, and me saying such a mail is a scam, it is not. The new hosting provider chosen by Mauvehed, for attrition.org, uses this entity as a “partner registrar”. This new provider demonstrates they are amateur hour at security. First, the mail doesn’t identify the hosting provider, and doesn’t identify…

  • NSA, Theft, and the Original Quantum Lazlo
    NSA, Theft, and the Original Quantum Lazlo

    Back in November, 2009, Attrition.org staff (including me) finally got around to finalizing the name for our new mascot (archive.org), the angry squirrel firmly associated with Attrition and myself. In a cheeky letter from the mascot, it was signed ‘Lazlo’. Since that date, the mascot has seen a wide variety of iterations as Lazlo was…

  • Support Charity or Shatter Dreams
    Support Charity or Shatter Dreams

    A few days ago, a friend linked me to a contest that her daughter’s art was entered in, where voting is done online. I’m sure we’ve seen this for a wide variety of things in our lives these days, so it is easy to miss some of the little details that render the competitions unfair.…

  • Abert’s Squirrels and Wonderful Variations
    Abert’s Squirrels and Wonderful Variations

    After moving from Denver to the nearby mountains, I was quite happy to learn that I had four different kinds of squirrels in the area. The Golden Mantle Ground Squirrel, Least Chipmunk, Douglas Pine Squirrel, and the Abert’s Squirrel. The last is also known as the tassel-eared squirrel. Native to the southern Rockies, they can…

  • Random Movie/TV Thoughts and Reviews (February 2026)
    Random Movie/TV Thoughts and Reviews (February 2026)

    Reviews One Battle After Another (2025) is the kind of movie, to me, that seems to have everything right; good acting, interesting plot, good character development. And yet somehow it just doesn’t click for me. I understand why it would win an award for any given acting role, but overall as a movie I think…

  • The Database That Shouldn’t Have Been Continues To Fail The Community
    The Database That Shouldn’t Have Been Continues To Fail The Community

    [This article was originally published on Dark Reading, titled “Hand CVE Over to the Private Sector“. Note that it underwent editing by the staff there. Below is my original version and this copy is titled the way I had proposed.] Created in 1999, the Common Vulnerability Enumeration (CVE), now dubbed Common Vulnerabilities and Exposures, was…

  • Bob’s “CVE Quality-by-Design Manifesto” – The Hit and Misses
    Bob’s “CVE Quality-by-Design Manifesto” – The Hit and Misses

    Almost every time Bob Lord blogs, I feel the need to write a rebuttal to what is arguably abject stupidity and shortsightedness. One he published a couple days ago, titled “CVE Quality-by-Design Manifesto“, is missing several core concepts in the realm of vulnerability intelligence. While his overall point is certainly valid, the order in which…

  • Shadow, Ghost, and Phantasmawhatever Vulnerabilities – The Reality
    Shadow, Ghost, and Phantasmawhatever Vulnerabilities – The Reality

    Back in September of 2024, I took some notes on a blog I wanted to write about “Shadow” vulnerabilities, based on a corporate blog with a poor concept and misunderstanding of CVE. The title was to be “Shadow Vulnerabilities – Rebuttal” and pretty straight-forward. Vulnerability life is crazy when you help manage a true vulnerability…

  • Random Movie/TV Thoughts and Reviews (January 2026)
    Random Movie/TV Thoughts and Reviews (January 2026)

    Reviews I finished Trigger (2025), a Korean cop/crime/action series that was pretty good. The most interesting aspect was the entire premise that is “what if guns flooded into South Korea?” So it basically becomes a gun epidemic that the police are fighting which is obviously a stark contrast to the United States. It’s simple, yet…

  • Vulnerability Disclosure Forensics: /cgi-bin/upload.cgi
    Vulnerability Disclosure Forensics: /cgi-bin/upload.cgi

    Yesterday, Chris Sullo of Nikto fame, asked me a simple question; in so many words, what was the “first web vuln”. To be clear, he is asking about the first vulnerability in a web server / service / program. Seems relatively straight-forward but I challenge anyone to answer it with their own data set, especially…