Category: Information Security
Everything filed under Information Security.
WEIS 2011 :: Session 1 :: Attacks :: The Impact of Immediate Disclosure on Attack Diffusion & Volume
WEIS 2011 :: Session 1 :: Attacks :: The Impact of Immediate Disclosure on Attack Diffusion & Volume — rud.is blog archive
WEIS 2011 :: Keynote :: Dr Christopher Greer
Dr Greer [cgreer at ostp.eop.gov] is Assistant Director, Information Technology R&D, Office of Science & Technology Policy, The White…
Dropbox 1.2.0 Experimental Build "Fixes" Security Issue
If you are concerned about the Dropbox design flaw exposed by the dbClone attack, then have we got a link for…
A Fully Operational OS X dbClone
The app can now backup/restore of local config, clone dropbox configs to a URL/file and also impersonate a captured Dropbox…
dbClone "hack" for OS X
Moloch built a Windows & Linux impersonation/cloning utility in Python that was/is meant to be used from a USB/external volume. The utility can save the cloned host id to a local file and also has the capability to use a simple HTTP GET…
Crossroad of ERM and the Parallels to IRM
I was reviewing the - er - highlights? - from the ninth ERM Symposium in Chicago over at Riskviews this morning and was intrigued by some of the parallels to the current situation in enterprise security risk management (the ERM symposium…
Behind The Mask : Supporting The New CIO Personas
This morning, @joshcorman linked to an article in the Harvard Business Review " The Conversation " blog that put forth the author's view of The Four Personas of the Next-Genereation CIO . The term persona is very Jungian and literally…
Micropwns :: Risk Microprobabilities for Infosec?
I had not heard the term micromort prior to listening to David Spiegelhalter's Do Lecture and the concept of it really stuck in my (albeit thick) head all…
Never A Better Time To Baseline
If you're preparing to install Windows 7 or Windows Server 2008 R2 Service Pack 1 , now would be a good time to give Microsoft's Attack Surface Analyzer a spin. ASA takes a baseline snapshot of your system state and then lets you take…
Herding [Fire]sheep
By now, many non-IT and non-Security folk have heard of Firesheep , a tool written by @codebutler which allows anyone using Firefox on unprotected networks to capture and hjijack active sessions to popular social media sites (and other web…