Slashdot Mirror


User: wiredmikey

wiredmikey's activity in the archive.

Stories
0
Comments
37
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 37

  1. Re:Physical Access = Game Over on Popular Smartphones Hacked At Mobile Pwn2Own 2014 · · Score: 1

    Physical access isn't needed for all these attacks. For example, on the iPhone, all it would take would be to get a user to visit a page hosting the malicious code. It may require some social engineering or a watering hole attack but that's not incredibly difficult.

  2. Re:What? Bad interpretations on Heartbleed Bug Exploited Over Extensible Authentication Protocol · · Score: 2

    In slides of his presentation he does mention iPads, iPhone and OSX. See Slide #18:

    http://www.slideshare.net/lgra...

  3. Re:Of course, since it's SCADA... on ICS-CERT Warns of Serious Flaws In Tridium SCADA Software · · Score: 1, Informative

    It's not really SCADA, it's different. SCADA is from Siemens, this is different and the Niagara Framework is used in places beyond big facilities such as power plants and factories. The Niagra framework reaches offices buildings, hospitals, airports and more.

    http://www.securityweek.com/niagara-vulnerabilities-put-office-buildings-airports-hospitals-risk

    That being said, this warning was originally issued back in July with ICS-CERT not really adding anything new in this warning.

    -M

  4. Same Warning Was Issued Back in July on ICS-CERT Warns of Serious Flaws In Tridium SCADA Software · · Score: 3, Informative

    This alert is actually not very new and dates back to July. ICS-CERT re-releases things all the time in order to update small things and be sre people see an update, no matter how minor. Here is the original that came out in July:

    http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-12-195-01.pdf [us-cert.gov] -- It's pretty much identical from what I can see.

  5. Re:Criminal on VISA, MasterCard Warn of 'Massive' Breach At Credit Card Processor · · Score: 1

    It's Global Payments, Inc. Will have more info on it shortly!

  6. Re:breach database? on Zappos Hacked: Internal Systems Breached · · Score: 2

    A good one also would be http://www.databreaches.net/ - M

  7. Update: Symantec Confirms Hackers Accessed Code on Symantec Looks Into Claims of Stolen Source Code · · Score: 1

    Update: It wasn't Norton, it was older versions of their Enterprise protection:

    http://www.securityweek.com/symantec-confirms-hackers-accessed-source-code-two-enterprise-security-products

  8. Re:No FISMA. on Amazon Launches 'AWS GovCloud' · · Score: 2

    According to Amazon Web Services, and as mentioned in the article, GovCloud "supports existing AWS security controls and certifications such as FISMA, SAS-70, ISO 27001" -- So it seems as though you are incorrect on the fact that GovCloud hasn't received FIMSA certification.

  9. Re:Typo in article? on Spam Drops 1/3 After Rustock Botnet Gets Crushed · · Score: 1
  10. Re:What's the penalty for HTTPS? on Twitter Joins the HTTPS By Default Party · · Score: 0

    Compaqt, because of HTTP of session hijacking works over unsecured wireless connections, it's important to use SSL beyond just the login. So even during the login process when the password is submitted, once a session is established, the session can be hijacked.

  11. Re:HTTPS by default? Not exactly, Misleading headl on Twitter Joins the HTTPS By Default Party · · Score: 2

    You're right -- It's not SET to default, but users can set the service to use HTTPS by default.The actual title of the article is "Twitter Enables Option for HTTPS by Default" - Though I agree that the /. could have been more clear.

  12. Did it really take a study to figure that out? on Study Calls Craigslist 'a Cesspool of Crime' · · Score: 1

    I would think if it wasn't obvious enough before, that the "Craigslist Killer" would make that reason enough to come to the conclusion that it's a dangerous place. That being said, there is quite a lot of success with people buying and selling. Just don't have any protections in place like something like eBay.

  13. Re:not high severity on High Severity BIND Vulnerability Advisory Issued · · Score: 1

    Assantisz, the article does link to the ISC advisory. Are you are correct, they do list it as high severity.

  14. Re:not "high severity" on High Severity BIND Vulnerability Advisory Issued · · Score: 1

    The ISC and US-CERT have it ranked as "High Severity"

  15. Stolen IP? on First Pictures of Chinese Stealth Fighter · · Score: 1

    Anyone else think China's progress on this is a result of stolen intellectual property?

  16. Link to Post on Android Trojan Found, Spreading From Chinese App Stores · · Score: 1

    http://blog.mylookout.com/2010/12/geinimi_trojan/ -- From the myLookout Blog who made the discovery

  17. Malware & Botnets More Profitable on The Significant Decline of Spam · · Score: 1

    Spam is declining for a few reasons -- Anti-spam technology is getting better and more widely deployed. sure with massive volumes and good spammer technology plenty is still getting through -- but it's becoming more challenging for spammers to reach the inbox these days. Cybercriminals have switched to focusing on using malware and botnets as these much more profitable over time than the basic spamming. Why would you waste time trying to get someone to buy viagra from an online pharmacy when you could capture their credit card or online banking details instead? Successfully capturing a few dozen credentials like this would likely be more profitable than reaching a million users with a spam message. Massive volumes of spam will still continue but overall the spam industry just ain't what it used to be!

  18. An Interesting Trend on Playstation 3 Code Signing Cracked For Good · · Score: 0

    Not surprising and something that's likely to be a trend in consumer devices over time, especially as more and more devices become "connected" -- An interesting research report we highlighted last week shows just how vulnerable these newly connected devices are (ok PS3 isn't newly connected but many more consumer devices are) Cellphones, iPods, digital cameras, set-top boxes, gaming systems... these devices pervade modern life. Mostly, they make our lives easier and more fun. But if they're built without the proper security technology, our favorite gizmos and gadgets can seriously compromise our privacy, finances and even our personal safety: http://www.securityweek.com/security-focus-consumer-electronics

  19. Re:This article has a lot of details... on Hacking Neighbor Pleads Guilty On Death Threats and Porn · · Score: 1

    Good link and that does have lots more on the history prior to the pleading guilty. The article was updated to link to that story for more details.

  20. Re:MSE vs Forefront Client Security on Microsoft Security Essentials 2.0 Released · · Score: 1

    According to Microsoft: "For consumers and very small businesses needing protection from malicious software including spyware, viruses, trojans and rootkits, Microsoft Security Essentials is a no-cost, high-quality anti-malware service that efficiently addresses the ongoing security needs of a genuine Windows-based PC. Forefront Endpoint Protection 2010 provides endpoint protection for business environments, including antimalware and additional protections like behavior monitoring and firewall management. Forefront Endpoint Protection 2010 also includes central deployment, configuration, and reporting features needed for ensuring protection is maintained across the enterprise." Microsoft did just release the latest version of Forefront as well (Forefront End Point Protection 2010)

  21. Re:Dupe on Chrome Throws Flash Into the Sandbox · · Score: 4, Informative

    Yes, they mentioned it earlier, today it appears to actually be in action and built into the latest beta of the product.

  22. Re:Not working here on Hidden Backdoor Discovered On HP MSA2000 Arrays · · Score: 1

    Someone else had commented that it did work via web interface as well and didn't require a serial interface. Statement from HP should be coming soon.

  23. Re:Spamvertisement on Amazon Web Services Launches DNS Service · · Score: 3, Informative

    Actually, the full press release with all the clutter and no information on the API, etc. is here: http://phx.corporate-ir.net/phoenix.zhtml?c=176060&p=irol-newsArticle&ID=1504334&highlight=

  24. If I could afford the tow... on British Aircraft Carrier For Sale On Auction Site · · Score: 1

    If I could afford to have it towed across the atlantic I'd put a bid in :)

  25. Re:...news? on Internet Routing, Looming Disaster? · · Score: 3, Insightful

    It's not so much news as it is insight. If you're an experienced network expert it may not be surprising, but too many people in the tech world still don't have a clue on some of the challenges, dangers, problems that are happening currently and that we face moving forward with the overall internet infrastructure.