Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

haqs

How to get beyond mindless blindness - every-day social engineering

Is everybody being deceptive?

When we're not there, we aren't there to know that we're not there.


telepathie1.jpg



I recently listened to the 7th episode of the Social Engineering podcast. - That made me take some notes, and I think I remember some quotes.
In short it was simply about using familiar routines - or those routines which should be familiar - in order to successfully blind somebody else's mind into a routine workflow.

The story of website password generators


That's a good PW generator. There're others.

A lesson learned

A lesson a co-worker, Bob, learned recently was: never trust. He's a security minded and competent administrator and specialized at security. However - something we have in common: lazy.

When Bob recently created a bunch of new passwords, he used a website, created an account, and what's very convenient: all the generated passwords are stored in a table. He added some usernames and used the website a while. There're password recovery functions. A real work-saver, however the setup is not local and does not belong to the company.

A Paimei tutorial - simple heap-traceing - part 2

Abstract

The following tutorial builds on the basics which are documented in the first part. For vulnerability discovery, debugging and fuzzing are essential. Furthermore the proper knowledge of memory management, assembly instructions and Python will still be needed. You cannot just scratch the surface while trying to explore these techniques. I wrote this tutorial to inspire people, or to help people coping with Windows and its restrictions. But most people in the fields will laugh at this and call it primitive. It is.

Windows 7 on a MacBook - dude, WTF?



Yes, it works! How to make the possible easier

Normally on a MacBook you'd expect lots of compatibility issues. However this is not the case.
You just get "Error 2229" if you're going to install the standard BootCamp drivers. Well... here's an unofficial patch. It's using the old install trick: the installer has been extracted, the checkup has been modified, and it has been repacked. Without any guarantee - but it works. Afterwards use the official Vista update. That's it.

Johnny Long interviewed by Joseph McCray

So fast - so weekly: a week of reading


2B779D97-6894-45EC-935C-6EB677B270DE.jpg
funny japanese wireless toilet control (source)

I just thought - because there's enough to read for everybody in IT security at the moment: keep this short and just list the stuff with some tiny little annotations.

So fast - so more or less weekly: programming in pentesting is more than essential


F6466C6E-8240-46A4-A4E9-12ACBDCBA800.jpg

dangerous Confickr

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.