Ethic Security
Welcome to the realm. This realm, is not your ordinary realm. Here you will find happenings in the network security world, as well as the underground and the ethical arena.
Thursday, September 17, 2009
Hack In The Box Forums • View topic - Penetration Tester's Lab - Hack your own machine (win2k sp4)
Hack In The Box Forums • View topic - Penetration Tester's Lab - Hack your own machine (win2k sp4):
"I just install windows 2000 pro sp4 into vmware & now I want to do some penetration testing on this machine…hopefully u can help me to find all vulnerabilities in this machine…"
"I just install windows 2000 pro sp4 into vmware & now I want to do some penetration testing on this machine…hopefully u can help me to find all vulnerabilities in this machine…"
CITRIX: Owning the Legitimate Backdoor | GNUCITIZEN
CITRIX: Owning the Legitimate Backdoor | GNUCITIZEN:
"The other day I was performing some CITRIX poking, so I had a lot of fun with breaking GUIs, which, as most of you probably know, are trivial to break into. I did play around with .ICA files as well, just to make sure that the client is not affected by some obvious client-side vulnerabilities. This exercise led me to reevaluate many things about ICA (Independent Computing Architecture). For example, when querying Google and Yahoo for public .ICA files, I was presented with tones of wide open services, some of which were located on .gov and .mil domains."
"The other day I was performing some CITRIX poking, so I had a lot of fun with breaking GUIs, which, as most of you probably know, are trivial to break into. I did play around with .ICA files as well, just to make sure that the client is not affected by some obvious client-side vulnerabilities. This exercise led me to reevaluate many things about ICA (Independent Computing Architecture). For example, when querying Google and Yahoo for public .ICA files, I was presented with tones of wide open services, some of which were located on .gov and .mil domains."
Wednesday, August 12, 2009
Two convicted for refusal to decrypt data • The Register
Two convicted for refusal to decrypt data • The Register:
"Two people have been successfully prosecuted for refusing to provide authorities with their encryption keys, resulting in landmark convictions that may have carried jail sentences of up to five years."
"Two people have been successfully prosecuted for refusing to provide authorities with their encryption keys, resulting in landmark convictions that may have carried jail sentences of up to five years."
Friday, July 10, 2009
Chinese Spying Claimed in Purchases of NSA Crypto Gear | Threat Level | Wired.com
Chinese Spying Claimed in Purchases of NSA Crypto Gear | Threat Level | Wired.com:
"A Chinese national was indicted this week for conspiring to violate U.S. export law, following a nearly three-year investigation into his alleged efforts to acquire sensitive military and NSA-encryption gear from eBay and other internet sources."
"A Chinese national was indicted this week for conspiring to violate U.S. export law, following a nearly three-year investigation into his alleged efforts to acquire sensitive military and NSA-encryption gear from eBay and other internet sources."
Thursday, July 9, 2009
Microsoft knew of nasty IE bug a year before attacks • The Register
Microsoft knew of nasty IE bug a year before attacks • The Register: "Microsoft was aware of a critical vulnerability in an Internet Explorer component at least 12 months before attackers started targeting it in lethal exploits that take full control of end-users' PCs, a member of its security team said Wednesday."
Online attack hits US government Web sites
Online attack hits US government Web sites:
"A botnet comprised of about 50,000 infected computers has been waging a war against U.S. government Web sites and causing headaches for businesses in the U.S. and South Korea.
The attack started Saturday, and security experts have credited it with knocking the U.S. Federal Trade Commission's (FTC's) Web site offline for parts of Monday and Tuesday. Several other government Web sites have also been targeted, including the U.S. Department of Transportation (DOT)."
"A botnet comprised of about 50,000 infected computers has been waging a war against U.S. government Web sites and causing headaches for businesses in the U.S. and South Korea.
The attack started Saturday, and security experts have credited it with knocking the U.S. Federal Trade Commission's (FTC's) Web site offline for parts of Monday and Tuesday. Several other government Web sites have also been targeted, including the U.S. Department of Transportation (DOT)."
Subscribe to:
Posts (Atom)
About Me
Blog Archive
-
▼
2009
(47)
-
►
June
(11)
- One Hacker's Audacious Plan to Rule the Black Mark...
- Superhacker Max Butler Pleads Guilty | Threat Leve...
- Pentagon signs off on Cyber Command
- Lifehacker - Geek to Live: Encrypt your data - Dow...
- L0phtCrack - Windows & Unix Password Auditing & Re...
- L3DGEWorld 2.3
- IT Security - The Industry's Web Resource
- Home | Learn Security Online
- Top Five (5) Best Criminal Computer Hackers of All...
- 5 Best Pen-Test Linux Distributions | LinuxHaxor.n...
- Hacker penetrates T-Mobile systems
-
►
April
(15)
- Swedish courts find The Pirate Bay guilty
- Electricity Grid in U.S. Penetrated By Spies - WSJ...
- Behind GhostNet - F-Secure Weblog : News from the ...
- I-Hacked.com Taking Advantage Of Technology - Insi...
- I-Hacked.com Taking Advantage Of Technology - Twit...
- FOXNews.com - Cyberspies Penetrate U.S. Electrical...
- Tenable Network Security
- Using NMAP to detect Conficker infected hosts | Th...
- PaulDotCom
- ha.ckers.org web application security lab
- Conficker - Wikipedia, the free encyclopedia
- An Analysis of Conficker C
- Passwords used by the Conficker worm | Graham Clul...
- Open Source Honeypots: Learning with Honeyd
- IDS Logbook [OS3 Website]
-
►
March
(12)
- Main Page - Business Continuity Management (BCM) a...
- The 20 Best Job Search Web Sites - Features by PC ...
- California Virtual Campus » Students » CVC Course ...
- PayPal Security Key - PayPal
- The Ethical Hacker Network - EC-Council validity
- Run Away From The CEH Certification
- InformIT: On the EC-Council's Certified Ethical Ha...
- GIAC Certifications
- Top 5 open source security tools in the enterprise...
- Hack-off contestant dubs Apple Safari 'easy pickin...
- The Register: Sci/Tech News for the World
- Been away!
-
►
June
(11)
Tags
- Backtrack (3)
- Cain Abel (1)
- Eee PC (1)
- fgdump (2)
- finger printing (1)
- fingerprinting (1)
- Hping2 (1)
- Linux (2)
- metasploit (6)
- netcat (2)
- news (16)
- nmap (5)
- Ophcrack (1)
- password cracking (5)
- RainbowCrack (3)
- rdp (1)
- Snort (2)
- tcpdump (1)
- training (25)
- vulnerabilities (12)
- WiFi (1)
- xprobe2 (1)