July 2006 Archives

Oracle Exploit Code

| No Comments

Oracle Exploits

Location with some good explanations and exploit code for various Oracle versions. Also some links to other locations with exploit code.

- VMTN Virtual Appliances Directory

The vmware virtual appliances directory looks very very cool to me. It's a collection of pre-installed pre-configured virtual machines setup for specific purposes... need a media-wiki server... no problem... need a network security scannng server ... no problem...

just download and go...

And if you combine it with the release of vmware server FOR FREE then you really have something cool...

One thing I did notice is that, unsurprisingly, all the VM's I looked at are based on Linux, and I expect this kind of thing will really drive the takeup of linux. If you think about it.. you're asked to demo a say e-mail security server to handle your burgeoning Virus/SPAM problems...

you could pay for a windows server license, buy it, configure it, get some software to do the filtering, install it, configure it, etc etc

or you could download a pre-configured Linux VM using Pre-configured Open source software ...

If you were a small overworked IT department... which would you choose?

2-Factor Auth in banking Attacked

| No Comments

Security Fix - Brian Krebs on Computer and Internet Security - (washingtonpost.com)

Post about a MITM attack on Citibanks two-factor authentication system. The relaying of error messages from Citi by the attacker is a nice touch as it makes it seem a lot more legitimate...

Well not really a surprise that the attackers have worked this out. Of course it's slightly easier to detect/shut down as they have to do the attack in real-time as opposed to gathering the credentials and then using them at their leisure, which can happen with standard phishing.

Still, goes to show that there's more work neeeded to be done on this.

List of data breaches

| No Comments

A Chronology of Data Breaches Since the ChoicePoint Incident


this list of all the data breaches since 2005 that the privacy rights clearing house have assembled looks quite handy.

Cool Pen Testing Mind Map

| No Comments

Penetration Test

I'm a bit of a fan of Mind maps so seeing this information in that format works pretty well for me...


Pages

Powered by Movable Type 4.32-en

About this Archive

This page is an archive of entries from July 2006 listed from newest to oldest.

June 2006 is the previous archive.

August 2006 is the next archive.

Find recent content on the main index or look in the archives to find all content.