Skip to main content

  • Multiple Linux flaws show that Linux also has kernel issues

    • Not to defend Microsoft, as kernel exploits that provide privileged access are

      terrible flaws, but we had an interesting discussion in the talkbacks where

      several people acted as if Microsoft was the only place that could’ve made such

      mistakes. Well, the proof is in the pudding that this is a common flaw across

      operating systems that is difficult to catch due to the complexities of kernel

      code.
    • Dann Frazier of Debian posted to Full Disclosure today about four

      vulnerabilities that allow local (this means you can’t do it over the Internet,

      unless you’ve already compromised a user account in some way remotely, the same

      applied to the Windows flaw that I spoke of, but there were questions around

      what exactly local meant, it does not mean you have to sit at the box

      physically) attacks against the kernel that result in arbitrary code execution

      or Denial of Service conditions. The contents of his email are posted below:
    • 7 more annotations...
  • GMail security hack leaves my business sabotaged

    • I’m thinking the date the attack took place is a significant piece of information. It was precisely the date you would leave your web site unattended for a period of one month. You reported that you’d contacted a number of people about your plans. My guess is that within that circle you might find the culprit, — or abetter, at the very least.


      It’s not easy to pinpoint physical locations attackers. The physical location in Iran may just be the location of a zombie server.


      It’s a strange tale, to be sure.

    • I was informed that my website had disappeared, and that my domain name (www.davidairey.com) was now redirecting to some random website - bebu.net.


      I was confused, and anxious. How could this happen? I hadn’t received any notification of my domain name expiry, and I never divulge any passwords to anyone.

    • 22 more annotations...
  • David Airey's stolen domain name recovered | David Airey :: Branding and Corporate Identity

    • Corey, the issue is that your session cookie is available in the clear when using HTTP. Any web application can be hijacked by taking its session cookie, not just GMail. For example, you’re using public WiFi in a Starbucks. The guy next to you is running AirSnort/Wireshark/tcpdump/etc. and grabs your cookies out of the air. He can then send requests to the web application as you. Using https prevents this.
  • The Tinfoil Hat Toolbox: 100-Plus Tips and Resources to Protect Your Site Network from the Google Borg - Inside CRM

      Add Sticky Note
    • Google is one of the Internet's darlings, universally loved by just about everyone. Everyone, that is, but webmasters who've had their domain networks wiped from Google's results. Some sites deserve it and some don't, but the bottom line is that a Google hit doesn't have to be devastating.
    • 7 more annotations...
1 - 4 of 4
Showing 20 items per page
List Comments (0)