Syndicate

Syndicate content

Flattr


Flattr this

If you like this, you can use flattr. ;)

Imprint

About
eMail: wishinet at gmail . com
PGP ID: 0xCCCA5E74

Jabber: wishi@jabber.ccc.de

Malware

Malware

Postfix troubleshooting - a security nightmare

Why to hate typical Unix mailserver setups

I hate that stuff - and it's not that Postfix in particular sucks. But integrating with Postfix is absurd. Surely it works, and as long as it works nobody changes that stuff on how it's designed.


Ohne Titel.png

Even deploying an SSL/TLS setup is challenging. But no, you also need to install proper authentication. Locally, Postfix (for unknown reasons) is chrooted. People think that this is a security feature.

Windows Integrity Control - a model of trust and classification

Malicious Office Documents

On very common entry point these days are malicious office documents. If you've got no idea on how interactive these "documents" can get, take the test at decloak.net (Start button). You'll get a .doc file that's performing network connections and in this case bypassing antonymization technologies.

Bild 2.JPG

AV evasion and about rankings

Some AV Vendors Lack Efficiency

Once upon a time we were living in a world where creating protective technology, still called Anti-Virus, was a good thing to do. These days vendors seem to be too relaxed with the idea of selling the pig in a poke.
(Source: Roel Schouwenberg's rant ;) - yes I reversed his message)

Security researchers who care

Teaching?

What took the most of us to learn,
is what we teach best.

I found a good collection of IT security specific learning materials. Even if you're an old hand in the fields, you might catch something new, nevertheless I guess it's a university course intended for starters.

Introduction and Source Code Analysis, Dan Guido
Reverse Code Engineering, Stephen A. Ridley
Memory Corruption, Dino Dai Zovi
Fuzzing, Mike Zusman
Client-side attacks and Post-Exploitation, Dean De Beer
Web Hacking, Erik Cabetas

Blackhat 2008 video archives are open

About IT security and more


A63965B6-4312-4D34-8FF8-E27D37A7C14A.jpg
hey guess what: the trojan horse has got a black hat :)

The conference material at BH is always kewl. Attending to this con is highly expensive because it's far away - in my case. Well... here's the material publicly available. For personal entertainment: Follow this link.

Highlights for the moment Read more »

Memory forensics explained

Not just the disks!

CFAE6575-BF32-4BD4-8F4A-D1C02C06E385.jpg
it turns out rock climbing sometimes is easier than diving.

Generations of forensic experts just used data from the hard-disk. They dived down deeply into the filesystems to dig for all kinds of incident. But what's with the surface?

It turns out if you've got a chance to get hands on RAM nowadays, you should take it. - Even in pentesting: here's why and how.

Why? Read more »

Javascript, Acrobat, Linux and the Swine Flu

JS and the Acrobat bring the Swine Flu to Linux


2D803207-F47D-42C0-846A-54DCE90C809A.jpg
Human or swine origin - in case of spammers that's now the question.



It seems to be a strange friendship: since JavaScript in Adobe's Acrobat Reader is common, targeted Office Malware attacks against it are everywhere. What's extraordinary dangerous here is, that especially unsophisticated users who just do their Office-stuff, are affected. - Not just the Administrator or any other IT person, that'll be far away to fix this.

Save the nature. Don't print this!


I provide textual exports for every blog entry. However let's save the nature together. The nature is everything around us. Every being should be respected. Save the nature - don't print too much.


Die Umgehung dieser Ausdrucksperre ist nach § 95a UrhG verboten!
Inhaltlich Verantwortlicher gemäß § 10 Absatz 3 MDStV: Marius Ciepluch - Anschrift via eMail. Die eMail Adresse entnehmen sie dem Impresseum dieser englischsprachigen Seite.
Aus Datenschutzgründen habe ich weder offiziellen noch behördlichen Schriftverkehr via eMail. Dazu ist die postalische, beim Dienstleister hinterlegte, Anschrift zu verwenden.

Datenerfassung

Es werden keine personenbezogenen Daten erfasst. Logdaten werden anonymisiert.