computer crimes

How to get beyond mindless blindness - every-day social engineering

Is everybody being deceptive?

When we're not there, we aren't there to know that we're not there.


telepathie1.jpg



I recently listened to the 7th episode of the Social Engineering podcast. - That made me take some notes, and I think I remember some quotes.
In short it was simply about using familiar routines - or those routines which should be familiar - in order to successfully blind somebody else's mind into a routine workflow.

Using Threat Modeling to analyse entry points

How to think security


by Ivan Ristic, just a part of it

People in application development generally have different perspectives. Developers often focus on getting stuff up and running in an efficient feature-rich way, testers focus on confidentiality, integrity or stability/availability issues... Marketing focuses on getting Outlook to display yesterday's i-Mails with smilies. :) Well, lets forget these people here.

AV evasion and about rankings

Some AV Vendors Lack Efficiency

Once upon a time we were living in a world where creating protective technology, still called Anti-Virus, was a good thing to do. These days vendors seem to be too relaxed with the idea of selling the pig in a poke.
(Source: Roel Schouwenberg's rant ;) - yes I reversed his message)

The story of website password generators


That's a good PW generator. There're others.

A lesson learned

A lesson a co-worker, Bob, learned recently was: never trust. He's a security minded and competent administrator and specialized at security. However - something we have in common: lazy.

When Bob recently created a bunch of new passwords, he used a website, created an account, and what's very convenient: all the generated passwords are stored in a table. He added some usernames and used the website a while. There're password recovery functions. A real work-saver, however the setup is not local and does not belong to the company.

So fast - so weekly: teaching the hacks

D9F4EE06-4CCA-4728-8631-AA03854D6BC1.jpg
nowadays with "Agent Smith sunglasses" and TFT

We don't teach you...

I recently joined a channel on Freenode IRC and asked where to find some documentation for a special Metasploit auxiliary module, that was very new in the SVN repro. hdm sometimes is lurking around, people there normally are very friendly and helpful. It turned out not to be that typical day: "We don't teach you how to hack [...] use Google" - But we use your exploits?!

Blackhat 2008 video archives are open

About IT security and more


A63965B6-4312-4D34-8FF8-E27D37A7C14A.jpg
hey guess what: the trojan horse has got a black hat :)

The conference material at BH is always kewl. Attending to this con is highly expensive because it's far away - in my case. Well... here's the material publicly available. For personal entertainment: Follow this link.

Highlights for the moment

Greetings from Chinopa - about the art of indirect restrictions

958AD525-40C0-47B3-B19B-96818CC7E379.jpg
old DDR customs official's watchtower


There's no censorship in free democratic states?

The Federal Republic of Germany begins to restrict information access for its citizens (again) - in the uttermost dubious and ineffective way. Due consistent lack of technical knowledge and unnatural high resistance against arguments freedom of speech is about to cease to exist. Within the borders where some time ago poets, thinkers and libertines had a right to simply express themselves, those troublemakers nowadays are to be silenced.

Syndicate content

Ihr Browser versucht gerade eine Seite aus dem sogenannten Internet auszudrucken. Das Internet ist ein weltweites Netzwerk von Computern, das den Menschen ganz neue Möglichkeiten der Kommunikation bietet.

Da Politiker im Regelfall von neuen Dingen nichts verstehen, halten wir es für notwendig, sie davor zu schützen. Dies ist im beidseitigen Interesse, da unnötige Angstzustände bei Ihnen verhindert werden, ebenso wie es uns vor profilierungs- und machtsüchtigen Politikern schützt.

Sollten Sie der Meinung sein, dass Sie diese Internetseite dennoch sehen sollten, so können Sie jederzeit durch normalen Gebrauch eines Internetbrowsers darauf zugreifen. Dazu sind aber minimale Computerkenntnisse erforderlich. Sollten Sie diese nicht haben, vergessen Sie einfach dieses Internet und lassen uns in Ruhe.

Die Umgehung dieser Ausdrucksperre ist nach §95a UrhG verboten.

Mehr Informationen unter www.politiker-stopp.de.