Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, May 29, 2014

Saturday, April 12, 2014

Cracking Google

Here's a fun article on pen testing a Google property...

Wednesday, April 2, 2014

Keybase

A little article about Keybase that I'm too tired to understand right now. I'll get back to it.

Thursday, January 2, 2014

Sleuthing back doors in routers

This stuff is so cool. Guy in Holland finds a Linksys back door (blow-by-blow courtesy HNN) and figures marvy stuff out using magic. Here's another one for another situation. I freaking love this stuff.

Sunday, December 22, 2013

GPG audit

GPG is, of course, an important piece of software in the security world. It's kinda crufty and old. It probably needs an audit. Tptacek on HNN says more than that, it needs some decent code documentation, hence my idea of an exegesis, a deliteralization of sorts.

Anyway, multilevel code understanding and presentation.

Saturday, November 16, 2013

Tools for treason

Here's a good point: if security tools aren't strong enough for crime, they aren't strong enough.

GPG tutorial

GPG tutorial for those of us who still can't quite figure out that whole GPG thing.

Handbook of Applied Cryptography

Another book!

July bookmarks: let's start with security

Along about July I thought I'd try to get a handle on the many bookmarks I was accumulating without blogging them, so I ended up with a bunch of categorized bookmarks that still never got posted.  Oy. And I should warn you, as I'm getting caught up with the summer's bookmarks I've been accumulating lots and lots more on various topics up here in November. Fortunately they group a little better, so they'll probably fit into bulk posts better.

To get July started off well, let's post a big bunch of security-related stuff that caught my eye in the first half of the year:

Saturday, June 15, 2013

Good sources for security knowledge

So there's an online course coming up on Web security, and HNN weighs in with useful resources for people interested in this stuff.

Reverse-engineering the NSA backdoor in Lotus Notes

This is cool.

Wednesday, May 29, 2013

You can't handle security

In fact, nobody can.  Here's an entertaining article giving three examples that will convince you of this.

There's a Matasano Challenge that will step you through the basics of security.  I think I may work through this sometime soon.

Sunday, May 19, 2013

Cross-site request forgery

CSRF exploration tool.  Interesting. Also provides mitigation techniques.

Sunday, May 5, 2013

Understanding scam victims

Nice article about looking at security flaws from the victim's point of view.

Security problems with server-generated JS responses

I inherently like code generation, but here's an article on security flaws in Ruby-generated JS (RJS) architectures.

Reverse engineering RDS-TMC

A fun article about reverse-engineering the encryption on RDS-TMC traffic updates in Europe.

Friday, March 8, 2013

A couple of sysadmin/security posts

Two good ones:
That last one has a lot of stuff I don't see great use for (personally) but I want to kind of get a little database of snippets going for this kind of thing.

Thursday, January 10, 2013

Sunday, December 9, 2012

Hacking Pokemon from inside and language security

A very cool playthrough of Pokemon Yellow that manipulates the item list to make it play a song [HNN thread] - related to "language security", which is limiting the security exposure due to overly Turing-powerful interfaces in unexpected places.

In other news, there is a whole community of people who spend their free time writing bots to play Pokemon for them.  That's pretty cool.

Friday, December 7, 2012

SQL injection for fun and profit

An absolutely fantastic article about SQL injection.  Don't treat SQL like a string! You will come to regret it.