Archive

Archive for the ‘General’ Category

Malvertizing just got a whole lot smarter.

December 7, 2016 Leave a comment

With a stroke of genius, a new approach allows hackers to determine if you are running IE without up to date antivirus and then using several flash vulnerabilities, attack your pc using steganography.

It’s like a ninja sneaking up on you, deadly, virtually undetectable and very smart.

http://m.slashdot.org/story/319693

Categories: General

Thinking of using your debit card at the pump, think again

December 2, 2016 Leave a comment

Visa Delays Chip Deadline for Pumps To 2020 https://krebsonsecurity.com/2016/12/visa-delays-chip-deadline-for-pumps-to-2020/

Caving to the Convenience store lobby, Visa has delayed making the move to chip and pin which can make your debit cards huge win in a skimmer. If you are at a pump that does not use a chip reader, DO NOT USE YOUR DEBIT CARD!

Categories: General

Newly discovered router flaw being hammered by in-the-wild attacks | Ars Technica

November 29, 2016 Leave a comment

It seems painfully clear to most security researchers now that the Mirai botnet is not finished and may never be unless providers take security seriously.

In an article from Arstechnica,

http://arstechnica.com/security/2016/11/notorious-iot-botnets-weaponize-new-flaw-found-in-millions-of-home-routers/

They explain that the loophole being exploited now deals with remote management ports for devices that our cable and DSL providers use. With most of the home users struggling to setup these devices when they get them home, they seldom change the default passwords and that allows hackers to exploit them. Vendors are also leaving application ports open to the Internet without proper source filtering which allows them to be enumerated by tools like Shodan and Censys.

We simply need to get better at taking ownership of our security posture, both consumers and vendors alike. Let’s all step up out game…

Categories: General

SafetyNet: Google’s tamper detection for Android · John Kozyrakis ~ blog

November 28, 2016 Leave a comment

Interesting article about Google’s idea to test for rooted phones for developers who want to make sure that your phone is ‘safe’ to run their applications.

https://koz.io/inside-safetynet/

Categories: General

Stay tuned for more hacking…

November 28, 2016 Leave a comment

I was reading this article about the sentencing of a 17 year old in the UK for a Web attack that happened in 2015. He says he won’t do it again but do we really want that?

http://www.infosecurity-magazine.com/news/talktalk-breach-17yearold-confesses/

It tells us that several websites were vulnerable to a SQL injection attack which leaked personally identifiable info (Pii).

Aren’t we punishing the wrong people here? I mean his motives were to show off his abilities and not to obtain and exploit the data. It also appears that the site already knew about the attack and was not able to do anything to mitigate?

I know that we would all like to live in a world where lost wallets are always returned to us with all the money inside but isn’t the company primarily responsible for continuing to neglect the security of the data?

Until we start legislative accountability for companies that hold service availability over security, we will continue to have breaches. To penalize individuals who help to find these flaws instead of congratulating them is like forgiving the dog and scolding the bone for just being there.  

Categories: General

Cirque du Soleil – Ole

November 25, 2016 Leave a comment

Had a great night out in Mexico watching the new Cirque du Soleil production called ‘Joya’. I saw golfer Greg Norman at the event and the only thing I could think of saying to him was ‘Happy 20Th Anniversary’ 😦

http://www.golfdigest.com/story/the-sharks-collapse-20-years-later&sa=U&ved=0ahUKEwiqjojX_sTQAhWG2SYKHROPC4sQFggaMAQ&usg=AFQjCNGzj3xeuushjxvo5w5em-zuVYJ0Jg

Categories: General

Bruce Schneier on the most recent attack vector, USB sticks

November 19, 2016 Leave a comment

Think of it, you walk into a building, see a computer that (hopefully) is locked and you plug in a USB device and walk away. Just like James Bond, you look at your watch and a few minutes pass by. You unplug your device and head back to the Astin Martin…

Well okay this part is fictitious but the rest isn’t. Read more about the the technique in this article.

https://www.schneier.com/blog/archives/2016/11/hacking_passwor.html

Categories: General

Feeling better that you bought an IPhone?

April 12, 2016 Leave a comment
Categories: General

Getting ready to take more underwater pictures

February 18, 2016 Leave a comment

I got another strobe and a new macro lens for our underwater rig today. Can’t wait to take some great pictures in Florida. Check out the flip mount for our diopter…

image

Categories: General Tags: ,

Article on Krebs about IoT security

February 12, 2016 Leave a comment

If you haven’t already read about it, I wanted to alert my readers to a story regarding the Trane ComfortLink thermostats – yes I said Thermostats. If you were one of the ‘lucky’ one to purchase this and thought it would be cool to enable your thermostat over your WiFi at home you should read more about this story that come to us from KrebsonSecurity – https://krebsonsecurity.com/2016/02/iot-reality-smart-devices-dumb-defaults/

Categories: General