Items Tagged with "Attacks"
A Security Resolution for Developers
February 22, 2012 Added by:Bill Gerneglia
You can’t understand how applications will be attacked if you don’t know how they work. Applications ultimately transmit data and operate on hardware in a network. Developers need to understand protocols, dependencies, communications, encryption, and more...
Comments (0)
IPv6 Protocol Implementation is Not a Security Panacea
February 22, 2012 Added by:Headlines
"The same thing that made the IPv6-enabled Internet valuable has also made it an increasingly valuable venue for attacks. While the frequency of attacks is relatively modest on IPv6 today, we expect that accelerated adoption will be followed in-kind by an accelerated pace of attacks..."
Comments (0)
Anonymous, NSA, Power Grids and False Flags
February 22, 2012 Added by:Scot Terban
Anonymous has never officially made a statement about attacking the power infrastructure at all. Sure, there were some drops of IP addresses in the recent past that they claimed were SCADA systems, but were only for HVAC systems. So where is the NSA getting this?
Comments (1)
Don't Be Naïve about Anonymous or the Occupy Movement
February 22, 2012 Added by:Robin Jackson
If you are an information security professional, then I urge you to quit worrying about what conferences you're going to speak at and get serious about shoring up the defenses of every computer system that you are responsible for immediately...
Comments (0)
Algorithms: When is Random Really Random?
February 22, 2012 Added by:Alan Woodward
The fact that we rely upon pseudorandom numbers is a potential problem for IT security. If a machine is using a known algorithm to generate a number that your system then treats as random, what is to stop an attacker from calculating that same number if he knows your algorithm...
Comments (0)
Prevent VoIP Toll Fraud with Proper Configurations
February 21, 2012 Added by:Enno Rey
Unfortunately the attacker was able to circumvent our first workaround. We discovered that it was possible to “dial-in” to the router directly by calling the head number. As a long-term solution the configured dial patterns have to be modified to prevent such things in the future...
Comments (0)
NSA Wary of Potential Hacktivist Threat to Power Grid
February 21, 2012 Added by:Headlines
"Grid officials said their systems face regular attacks, and they devote tremendous resources to repelling invaders, whether from Anonymous or some other source. The industry is engaged and stepping up widely to respond to emerging cyber threats..."
Comments (0)
FTC Removed Security Protocols from Website Contract
February 21, 2012 Added by:Headlines
The events appear to be a comedy of errors, where during the long process involved in awarding contracts, critical security requirements were not enforced. As the federal government races to outsource in an effort to cut costs, the risk of oversights become more probable...
Comments (0)
Antivirus Ban for Iran: A Controversial Penalty
February 20, 2012 Added by:Pierluigi Paganini
Iran will be banned from the purchase of antivirus systems, a technological embargo with clear implications for the Stuxnet virus attacks and the need to prevent further infections to control systems for critical infrastructures, namely their nuclear programs...
Comments (0)
Planned Anonymous Attack on the Internet Likely to Fail
February 20, 2012 Added by:Headlines
"The attack is no longer practical. It's such a common idea that Wikipedia has a page devoted to it. For something so obvious, defenders have spent considerable time devising solutions. There are many reasons why such an attack won't cause a global blackout..."
Comments (1)
Anonymous Hacks and Defaces FTC Websites
February 17, 2012 Added by:Headlines
The rogue hacktivist collective Anonymous has claimed credit for hacking and defacing several Federal Trade commission (FTC) websites in protest of the US government's support of the Anti-Counterfeiting Trade Agreement (ACTA)...
Comments (0)
Reflections on Suits and Spooks DC
February 17, 2012 Added by:Jeffrey Carr
We should re-assess which attacks should be investigated and which should be let go. The FBI and US-CERT are overwhelmed with tracking everything from probes against government networks to DDoS attacks to targeted attacks against the Defense Industrial Base...
Comments (0)
How I Learned to Stop Worrying and Love Cyberwar
February 16, 2012 Added by:Scot Terban
Sure, there are potential issues with regard to infrastructure and hacking/warfare, but, it is not such that we need to frame it and clothe it in the ripped flag of 9/11 do we? Obviously these guys all think so. I would beg to differ, and I find it shameful...
Comments (1)
Disclosures: How Much Sharing is Too Much?
February 15, 2012 Added by:Jack Daniel
What is the point of telling you I was compromised by spear phishing, SQL injection, cross site scripting, cross site request forgery, default credentials, or anything else we’ve know about for years? If you are ignoring all of the well-known risks, it is a waste of time...
Comments (0)
The Dangers of Non-Contextual Pattern Matching
February 15, 2012 Added by:Rafal Los
Even a system inconsistency such as an abnormal page transition velocity on your flagship web application can be overlooked - until you put all those together and realize you're being SQL Injected and someone is stealing your multi-terabyte database out from under you...
Comments (0)
Stock Exchange Websites Disrupted by DDoS Attacks
February 15, 2012 Added by:Headlines
Websites operated by Nasdaq OMX, the Chicago Board Options exchange, and Bats Trading experienced disruptions due to a spate of distributed denial of service (DDoS) attacks conducted by a hacktivist group sympathetic to the Occupy Wall Street movement called L0NGwave99...
Comments (0)
Your Own Private Island
December 24, 2011Coming Soon! Build your own Island right here!
Make your home Infosec Island with your own private vanity URL, design options and private network of followers.
Infosec Island v2
December 24, 2011The latest version of Infosec Island is now available. There are more content options and more ways to connect and interact with your peers.
Thanks to everyone for a great year, and we're looking forward to an excellent 2012!




