2007-09-01から1ヶ月間の記事一覧

IE pwns SecondLife

http://www.gnucitizen.org/blog/ie-pwns-secondlife

Using Google Analytics to subvert privacy

http://www.tssci-security.com/?p=303

AWS Start-Up Challenge http://www.amazon.com/gp/browse.html?node=377634011 #Amazonからのチャレンジ Vista Gadget関連の話 Next generation malware: Windows Vista's gadget API http://www.portcullis-security.com/165.php Vista Gadgets gone wild…

Capture-HPC 2.0 https://www.client-honeynet.org/creleases.html Netjuke 1.0-rc2 - sql injection & XSS http://sourceforge.net/projects/netjuke Technitium MAC Address Changer v4.7 Released http://tmac.technitium.com/tmac/index.html #なにかに…

Security Bites Podcast: The rise of crimeware http://news.com.com/Security+Bites+Podcast+The+rise+of+crimeware/2324-12640_3-6206809.html #podcastだったので,この欄に載せました.

Google Hacking for MPacks, Zunkers and WebAttackers http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html How to make money with XSS http://www.gnucitizen.org/blog/how-to-make-money-with-xss #過激なタイトルやねぇ…

個人認証型セキュリティ製品出荷、2006年度は前年比28.5%増 http://www.computerworld.jp/news/sec/78829.html #バイオメトリクス製品がこんなに売れるとは・・・ #やはり日本人は安全より安心感にはお金を払うのねぇ #バイオメトリクス認証自体は適切に…

Technitium MAC Address Changer v4.7 Released

http://tmac.technitium.com/tmac/index.html #なにかに役に立つかも? #まぁ,レジストリキーをいじっているだけですがFreeなツールなので

HoneyMole 2.0 Released

http://www.honeynet.org.pt/index.php/HoneyMole

Next generation malware: Windows Vista's gadget API

http://www.portcullis-security.com/165.php Vista Gadgets gone wild http://aviv.raffon.net/2007/08/16/VistaGadgetsGoneWild.aspx Vista Gadget Patches in MS07-048 https://strikecenter.bpointsys.com/articles/2007/08/26/vista-gadget-patches-in-…

個人認証型セキュリティ製品出荷、2006年度は前年比28.5%増

http://www.computerworld.jp/news/sec/78829.html

AWS Start-Up Challenge

http://www.amazon.com/gp/browse.html?node=377634011

Capture-HPC 2.0

https://www.client-honeynet.org/creleases.html

Security Bites Podcast: The rise of crimeware

http://news.com.com/Security+Bites+Podcast+The+rise+of+crimeware/2324-12640_3-6206809.html

VoIP Hopper: New test tool

http://voiphopper.sourceforge.net/ VoIP Hopper is a GPLv3 licensed security tool, written in C, that rapidly runs a VLAN Hop into the Voice VLAN on specific Ethernet switches.

Vulnerable test application: Simple Web Server (SWS)

http://www.beyondsecurity.com/sws_overview.html

g00gle CrewBots "How to firesmith a battleship"

http://www.gray-world.net/projects/papers/gbots-1.0.txt

XSIO - Cross Site Image Overlaying

http://www.disenchant.ch/blog/xsio-cross-site-image-overlaying/81 http://www.disenchant.ch/blog/wp-content/uploads/2007/09/xsio.pdf FYI, this was discussed as a "Trojaned Navigation Menu" attack, detailed on the Month of Myspace Bugs page …

IisShield 2.2 released

http://www.codeplex.com/iisshield IisShield is an IIS ISAPI Filter preventing any known and unknown attacks from disrupting IIS.

How to make money with XSS

http://www.gnucitizen.org/blog/how-to-make-money-with-xss

Google Hacking for MPacks, Zunkers and WebAttackers

http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html

Netjuke 1.0-rc2 - sql injection & XSS

http://sourceforge.net/projects/netjuke

さしえショーに触発されてGigazinizeというのを作りました http://blog.fulltext-search.biz/articles/2007/09/03/gigazinize http://blog.fulltext-search.biz/gigazine htmlをhtml.gzに圧縮しても*.htmlのままでアクセスできるようにしてディスク容量を節…

CSK (CSS Scripting Kit) http://www.thespanner.co.uk/2007/08/31/csk-demo/ SE-PostgreSQL 8.2.4-1.0がリリース http://code.google.com/p/sepgsql/downloads/list http://code.google.com/p/sepgsql/wiki/install_memo_Fedora7 sqlninja 0.1.3 released h…

第5回SKUF Meeting開催のお知らせ http://skuf.s-lines.net/hiki/?SKUF+Meeting#l0 DeepSec IDSC 2007 Vienna Registration Now Open http://deepsec.net/register/ http://deepsec.net/schedule/ WASC Announcement: 'Script Mapping Project' Call for Par…

第一人者がやさしく教える新SELinux入門 http://itpro.nikkeibp.co.jp/article/COLUMN/20070827/280411/?ST=oss 話題の動画サイト「Ustream」でPCから生放送! http://itpro.nikkeibp.co.jp/article/Watcher/20070828/280423/ #本当に一部で大人気ですよね…

NEC、ノートパソコンに「顔認証」 http://it.nikkei.co.jp/security/news/index.aspx?n=AS1D0100J%2002092007 NEC、“顔パス”でVistaにログオン可能なノートPC「LaVie C」など http://pc.watch.impress.co.jp/docs/2007/0903/nec2.htm #声帯認証もそうだ…

Inguma 0.0.3 - A Free Penetration Testing and Vulnerability Research Toolkit

http://sourceforge.net/projects/inguma

7th OWASP AppSec Conference - San Jose 2007/Training

http://www.owasp.org/index.php/7th_OWASP_AppSec_Conference_-_San_Jose_2007/Training

Five wireless security threats you may not know

#SANSの講師をつとめている人の個人ページみたいです http://www.willhackforsushi.com