Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Thursday, May 29, 2014
Saturday, April 12, 2014
Wednesday, April 2, 2014
Keybase
A little article about Keybase that I'm too tired to understand right now. I'll get back to it.
Thursday, January 2, 2014
Sleuthing back doors in routers
This stuff is so cool. Guy in Holland finds a Linksys back door (blow-by-blow courtesy HNN) and figures marvy stuff out using magic. Here's another one for another situation. I freaking love this stuff.
Sunday, December 22, 2013
GPG audit
GPG is, of course, an important piece of software in the security world. It's kinda crufty and old. It probably needs an audit. Tptacek on HNN says more than that, it needs some decent code documentation, hence my idea of an exegesis, a deliteralization of sorts.
Anyway, multilevel code understanding and presentation.
Anyway, multilevel code understanding and presentation.
Saturday, November 16, 2013
Tools for treason
Here's a good point: if security tools aren't strong enough for crime, they aren't strong enough.
July bookmarks: let's start with security
Along about July I thought I'd try to get a handle on the many bookmarks I was accumulating without blogging them, so I ended up with a bunch of categorized bookmarks that still never got posted. Oy. And I should warn you, as I'm getting caught up with the summer's bookmarks I've been accumulating lots and lots more on various topics up here in November. Fortunately they group a little better, so they'll probably fit into bulk posts better.
To get July started off well, let's post a big bunch of security-related stuff that caught my eye in the first half of the year:
To get July started off well, let's post a big bunch of security-related stuff that caught my eye in the first half of the year:
- A little primer on breaking Web security
- A book on security engineering from Ross Anderson ("Security engineering is about building systems to remain dependable in the face of malice, error, or mischance." I like it.)
- Secure your REST API ... the right way.
- How the Syrian Electronic Army hacked the Onion's Twitter account. Social engineering is pretty cool, actually.
- Are hackers a step ahead? A kind of overview blog post about Web security.
- Mesh networking to protect against NSA eavesdropping (Mother Jones, so more of a political article than a technical one, obviously).
Saturday, June 15, 2013
Good sources for security knowledge
So there's an online course coming up on Web security, and HNN weighs in with useful resources for people interested in this stuff.
Wednesday, May 29, 2013
You can't handle security
In fact, nobody can. Here's an entertaining article giving three examples that will convince you of this.
There's a Matasano Challenge that will step you through the basics of security. I think I may work through this sometime soon.
There's a Matasano Challenge that will step you through the basics of security. I think I may work through this sometime soon.
Sunday, May 19, 2013
Sunday, May 5, 2013
Understanding scam victims
Nice article about looking at security flaws from the victim's point of view.
Security problems with server-generated JS responses
I inherently like code generation, but here's an article on security flaws in Ruby-generated JS (RJS) architectures.
Reverse engineering RDS-TMC
A fun article about reverse-engineering the encryption on RDS-TMC traffic updates in Europe.
Friday, March 8, 2013
A couple of sysadmin/security posts
Two good ones:
- My First 5 Minutes On A Server; Or, Essential Security for Linux Servers | Bryan Kennedy
- mmb.pcb.ub.es/~carlesfe/unix/tricks.txt
That last one has a lot of stuff I don't see great use for (personally) but I want to kind of get a little database of snippets going for this kind of thing.
Thursday, January 10, 2013
Sunday, December 9, 2012
Hacking Pokemon from inside and language security
A very cool playthrough of Pokemon Yellow that manipulates the item list to make it play a song [HNN thread] - related to "language security", which is limiting the security exposure due to overly Turing-powerful interfaces in unexpected places.
In other news, there is a whole community of people who spend their free time writing bots to play Pokemon for them. That's pretty cool.
In other news, there is a whole community of people who spend their free time writing bots to play Pokemon for them. That's pretty cool.
Friday, December 7, 2012
SQL injection for fun and profit
An absolutely fantastic article about SQL injection. Don't treat SQL like a string! You will come to regret it.
Subscribe to:
Posts (Atom)