iPhone forensics

Posted in Video on June 13th, 2009 by admin – Be the first to comment

If you’re interested in iPhone forensics, I can’t imagine a better video on teaching you doing iPhone forensics in a lifetime.

So, here it is: (warning, 1 hour 4 minutes long, NSFW ;) )

Тигрови мерки

Posted in Securing the OS on June 10th, 2009 by admin – Be the first to comment

Те могат да бъдат използвани както от държавни агенции за сигурност, така и от големи, средни, малки компании. Наричат ги “тигрови екипи”, защото начинът по който работят заедно прилича на лов – лов за слаби точки в компютърни системи. В случая обаче, те работят за вас – защото обикновено “tiger team” е вътрешен екип, борещ се с вътрешни уязвимости, постоянно атакуващ собствената си мрежа, плътно до персоналните компютри, лаптопи, фирмени смартфони на служителите в компанията

Александър Свердлов read more »

Incident response gone Wild

Posted in Securing the OS on May 31st, 2009 by admin – Be the first to comment

Today a friend of mine called me and asked for help. His website apparently was hacked, but he did not know how, why… when… Ok, so I open up my browser, and see… “This site has been reported of malware” red screen of death, the Firefox one. If you try to Google for this page, same thing happens – Google had forbidden access to his site, although he was ranked №1 there. Strange? Not really. But it was devastating to his business, and a solution had to be found asap. His Twitter account got suspended for the same reason, too..

Ok… our next steps? Source code audit. A quick browse through the source code revealed a home-grown CMS, where NONE of the variables were protected, and a few files were infected with a known chinese web worm. Clean the worm? Not so fast security-boy! The CMS apparently was written in such a way, that if you try to strip out JS functionality, the whole system breaks up. If you try to clean the JS file, the whole system breaks up. In the end, I ended up manully modifying the core code of the CMS just to prevent future infections and clean it up. Not nice… not your regular virus/worm infection.

A quick remote check on his computer revealed trojans too – so who knows where the infection originated from. A complete reinstall was suggested, as well as thorough follow-up on the videos on this site in order to prevent the same thing from happening agian.

Update: his site is restored in Google and Firefox rankings after the clean-up, just 24 hours later.

Workbench

Posted in Securing the OS on May 30th, 2009 by admin – Be the first to comment

I’m working on a all-in-one server for small/medium businesses, that will cover all the needs of a small office – spam filtering, web site filtering, PDC, file sharing, dns service etc.

From what my testing shows, it’s amazing in performance and will serve more than well almost everybody.

Stay tuned!

Quckly find if you’re vulnerable to the latest WebDav/IIS vulnerability:

Posted in Securing the OS on May 20th, 2009 by admin – Be the first to comment

Quckly find if you’re vulnerable to the latest WebDav/IIS vulnerability:
http://epixoip.pastebin.com/f9512361A

And if you care exploiting… yourself? http://www.skullsecurity.org/blog/?p=285

Do you own an IIS&WebDAV *combination*? Disable WebDAV.  Microsoft will probably be here with a patch in 1/2/n weeks.

“Whitelisting” или най-кратката статия за информационна сигурност

Posted in Published on May 18th, 2009 by admin – Be the first to comment

Много може да бъде написано за сигурността на информацията. Това как да не бъде изнесена от вътрешни хора, как да не бъде открадната от външни, как да се предпази от унищожение или да бъде осигурена нейната постоянна достъпност. Тук ще се концентрирам върху предпазване от кражба на информация чрез проникване отвън – и ще ви представя най-лесния, най-ефективния, и най-краткия откъм описания метод

Александър Свердлов read more »

100 free ITSEC-related courses

Posted in Securing the OS on May 12th, 2009 by admin – Be the first to comment

I just got a message from Kelly Sonora, regarding a list of free courses they’ve assembled – it’s really good, so you should definitely check it out! http://www.computer-colleges.com/blog/2009/diy-ciss-degree-100-open-courses-on-computer-information-systems-and-security/