Violet Blue

Violet Blue is the author of The Smart Girl's Guide to Privacy. She contributes to ZDNet, CNET, CBS News, and SF Appeal.

Larry Seltzer

Larry Seltzer has long been a recognized expert in technology, with a focus on mobile technology and security in recent years

Latest Posts

HD Moore pwned with his own DNS exploit, vulnerable AT&T DNS servers to blame

A week after |)ruid and HD Moore release part 2 of DNS exploit, HD Moore's company BreakingPoint has suffered a traffic redirection to a rogue Google site, thanks to the already poisoned cache at AT&T servers to which his company was forwarding DNS traffic :"It happened on Tuesday morning, when Moore's company, BreakingPoint had some of its Internet traffic redirected to a fake Google page that was being run by a scammer.

July 30, 2008 by Dancho Danchev

14 Comments

OS fingerprinting Apple's iPhone 2.0 software - a "trivial joke"

Just like every decent web service out there wanting to identify the iPhone's mobile Safari browser in order to serve custom applications, in this very same way malicious attackers would like to remotely identify iPhone devices through a basic pen-testing practice known as OS detection or OS fingerprinting. It seems that the difficulty level of identifying an iPhone device using nmap's criteria is a "trivial joke", namely, it's too easy to accomplish :"So, nmap 4.

July 30, 2008 by Dancho Danchev

4 Comments

Gary McKinnon – 'world's most dangerous hacker' – to be extradited

The Guardian, out of the United Kingdom, is reporting that Gary McKinnon, the "world's most dangerous hacker", will be extradited to the United States to face criminal hacking charges. McKinnon, a 42 year old unemployed systems administrator from north London, allegedly hacked into systems belonging to the US army, navy, air force, and Nasa in 2001.

July 30, 2008 by Nathan McFeters

23 Comments

Evolution is punctuated equilibria

Guest editorial by Dino Dai ZoviIn evolutionary biology, the theory of punctuated equilibiria states that evolution is not a gradual process but instead consists of long periods of stasis interrupted by rapid, catastrophic change.  This is supported by fossil evidence that shows little variation within a species and new species that appear to come out of nowhere.

July 29, 2008 by Ryan Naraine

11 Comments

Fortify warns of configuration weaknesses in SOA deployments

Security code review specialists Fortify Software has issued a warning about major configuration weaknesses affecting SOA (service oriented architecture) deployments from IBM, Microsoft and Apache.According to Fortify, certain configurations of Apache Axis, Apache Axis 2, IBM WebSphere 6.

July 29, 2008 by Ryan Naraine

1 Comment

Passports worth £2.5 million stolen in van hijack

Graham Tibbetts of the UK Telegraph is reporting that the British Foreign Office has admitted to losing around 3,000 passports and visa stickers, which were stolen on their way from Manchester to RAF Northolt in London, where they were to be sent to British embassies.  From the article:Officials claimed the chip technology incorporated in the passports would prevent them being used.

July 29, 2008 by Nathan McFeters

10 Comments

Neosploit exploit kit shutters operations?

The distributors of Neosploit, one of the more dangerous drive-by download exploit kits on the Internet, have shut down operations because of financial problems, according to malware researchers at RSA FraudAction Research Labs.In a blog entry, the company said it found evidence that Neosploit will no longer be supported (yes, the do-it-yourself malware installation kit comes with terms of service and customer support!

July 28, 2008 by Ryan Naraine

4 Comments

DNS cache poisoning attacks exploited in the wild

UPDATE: Arbor Networks have provided more details in their "30 Days of DNS Attack Activity" analysis, SANS confirmed HD Moore's statement on DNS cache poisoned AT&T DNS servers. Numerous independent sources are starting to see evidence of DNS cache poisoning attempts on their local networks, in what appears to be an attempt to take advantage of the "recent" DNS cache poisoning vulnerability :" client 143.

July 28, 2008 by Dancho Danchev

54 Comments