November 2009
6 posts
2 tags
HFAIT - Shodan →
HFAIT? Click the title link, play around. No longer do you need to spend resources to scan target networks, simply query them through a search engine. Google hacking’s been around for a while, but this is beyond web content. Want to find vulnerable FTP servers running version xxxx globally? Drop it in, and away you go. Awesome. It’s one of those lovely double edged swords. Immensely...
Nov 26th
4 tags
HFAIT - NY Yankees Parade Confetti = Your PII!
HFAIT? Well, after cleaning up after the NY Yankees World Series parade - people started finding all sorts of lovely personal information scattered about. The article is a bit scant on details, but enough that I regret reading this first thing in the morning. No coffee, no breakfast, and now I just feel nauseous. We see examples of PII and other sensitive information being breached every single...
Nov 9th
4 tags
HFAIT - SSL/TLS Protocol Borked
Fun times hitting the news feeds today. The IETF has apparently been working on a fix to the SSL protocol for the last 2-3 months in secret, due to a vulnerability disclosed privately which can allow SSL sessions be intercepted and the data within these streams, manipulated. I can has your sensitive data now plz? Since this is a protocol level flaw, it’s going to affect nearly ever...
Nov 6th
5 tags
HFAIT - Canadian Bill C-47 →
How Fucked Am I Today - Bill C-47 A useful analysis of each section of the bill being proposed which is designed to allow RCMP, CSIS and likely lower level law enforcement agencies to require ISPs and other telecommunication service providers access to data transmissions. Some of the wonderful highlights include: If it’s encrypted, you have to provide access to the decryption key If it...
Nov 5th
3 tags
HFAIT - FBI DCSNet →
HFAIT? Ok, well it’s not just today and it’s been around (and will continue to exist) for some time. Anyway, the US FBI’s wiretapping system is effective, comprehensive and can be used without warrants. Trust No One!
Nov 3rd
2 tags
HFAIT? - Browser Bookmarks →
How Fucked Am I Today - Web browser bookmarks. Theoretical vulnerability at this point, but so dirt simple and cheap to exploit that I imagine we’ll be seeing some of this in the next few months, bundled in with other malware distributions.
Nov 2nd