Archiv der Kategorie link

Link: Best Security Certificate

Hi all,

There are a lot of IT security certificates out there.

But I believe one of the best you can get is:

http://www.ces-approved.org/

Check it out.

Cheers,

Matti

Link: Antivirus stuff

Just as a reminder of different tools to get rid of malware.

Live CDs

Avira AntiVir Rescue System
http://www.avira.com/de/support-download-avira-antivir-rescue-system

F-secure Rescue-cd
http://www.f-secure.com/en/web/labs_global/removal/rescue-cd

BitDefender Rescue CD
http://www.heise.de/software/download/bitdefender_rescue_cd/56298dl_7469f31745ca2bd873d8a959cd9bf6ef_1328034493

Kaspersky Rescue Disk
http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/

G Data BootCD
http://www.gdata.de/support/downloads/tools.html

Dr.Web LiveCD
http://www.freedrweb.com/livecd/

Trinity Rescue Kit
http://trinityhome.org/Home/index.php?content=TRINITY_RESCUE_KIT_DOWNLOAD&front_id=12&lang=en&locale=en

Tools

Malwarebytes
http://www.malwarebytes.org/

Spybot - Search & Destroy 2.0
http://www.safer-networking.org/de/spybotsd2/index.html

Hijackthis
http://www.trendsecure.com/portal/de/tools/security_tools/hijackthis

Keep it clean…
Cheers,
Matti

Link: Fun with Audits

http://download.101com.com/pub/itci/Files/ITCi_ITACL-InfoSec_0612_finalweb.pdf

http://www.revision-online.info/index.php/Hauptseite

http://www.sans.org/score/checklists/ISO_17799_checklist.pdf

http://www.auditnet.org/docs/ITAuditCL.pdf

and http://www.t2pa.com/

WordPress blogs hit with mass malware attack - mass SQL Injection?

[Source - http://www.downloadsquad.com/2010/04/12/wordpress-blogs-hit-with-mass-malware-attack/]

“Hundreds of WordPress blogs, particularly those hosted by Network Solutions, have been hit with an attack that cripples the blogs and redirects visitors to a URL that loads malware. The attack has been reported by both Sucuri Security Labs and Trend Micro. It works by replacing the contents of a WordPress blog’s “siteurl” field (under wp_options) with some HTML code. That field isn’t supposed to contain HTML, so it effectively breaks the blog.Security companies haven’t figured out how the blogs were exploited, although Sucuri says it was probably SQL injection or a database problem at Network Solutions. Network Solutions is investigating, and looking to blame a WordPress theme or plugin for the security hole, Trend Micro says. Trend Micro also has some info on the malware that the blogs are now redirecting to: it’s a known malware family called BUZUS, and antivirus software should be able to identify it.

If your blog was affected, change your siteurl bac k to its old value.You can find it under manage database, in the wp_option table. ”

This kind of platform attack is the most galling,  because it’s something individual users of the software are powerless to protect themselves against. The onus is entirely on the hosting company, and it seems that in this case  Network Solutions have a lotta  ’splaining to do.

Link: I love Russian ransomware


Here the story from CA:

 

http://community.ca.com/blogs/securityadvisor/archive/2009/11/30/ransomware-blocks-internet-access.aspx

 

Funny, that they produce a key code generator :-)

 

 

Link: same old same old

http://www.icann.org/en/topics/new-gtlds/high-security-zone-verification-04oct09-en.pdf

Somehow this idea sticks now around for a few years now. I think I first read about it 2 years ago.

This is just a typical example of a decision making process involving too many parties.

I think the Internet should be ruled by one person who is not interested in ruling of the Internet at all.

Douglas Adams had the idea for the whole galaxy so this should also work for the Internet.

 

 

Link: BB + PhoneSnoop = fun

http://www.us-cert.gov/current/index.html#blackberry_phonesnoop_application_used_to

here in full:

BlackBerry PhoneSnoop Application Used to Spy on Users
added October 27, 2009 at 11:59 am

US-CERT is aware of public reports of a new software application called PhoneSnoop. This software allows an attacker to call a user’s BlackBerry and listen to personal conversations. In order to install and setup the PhoneSnoop application, attackers must have physical access to the user’s device or convince a user to install PhoneSnoop.

US-CERT encourages users to only download BlackBerry applications from trusted sources and to password protect and lock BlackBerry devices.

Link: Education Education Education

 

http://www.offensive-security.com/metasploit-unleashed/

 

And do not forget to donate for HFC!!!

 

 

Link: Links to exploits

http://www.packetstormsecurity.org/assess/exploits/

 

http://www.milw0rm.com/

 

http://www.securiteam.com/exploits/

 

http://www.securityfocus.com/vulnerabilities

 

http://www.securityforest.com/cgi-bin/viewcvs.cgi/ExploitTree/

 

http://securityvulns.com/exploits/

 

http://osvdb.org/

 

http://www.vupen.com/english/security-advisories/

 

http://www.red-database-security.com/exploits/oracle_exploits.html

 

http://www.joomlaexploit.com/

 

 

Short one…


http://releases.portswigger.net/2009/10/v1217.html -> XML export -> http://dradisframework.org/