The Security Eunoia

Blogging about Security Auditing, IdM & Access Mgmt, Web App Security etc

Entries Tagged ‘Intrusion’

Brain ‘fingerprinting’ - the future of airport security?

Keep your belt and shoes on, move swiftly through airport security carrying your hand luggage (carry-on cases) all in some 30 seconds!

That is the aim for a new so-called “paradigm shifting” security technology aimed at boosting airport security without the long waiting lines, CNN reports. But there is a price. You will be scanned for [...]

Leave a Comment

Fighting Botnets with BotHunter

Aiming to take the fight to the bot herders, a company - SRI International - has released a tool called BotHunter. It is free. The software works by monitoring the communication between compromised hosts on a corporate network and bot-herding computers also known as command & control centres.

BotHunter uses what sounds more like heuristic methods and processes (where detection is based on patterns) or than signatures (where detection is based on known attacks). This is how it works:

Leave a Comment

CAINE - A digital forensic project on Live CD

CAINE - Computer Aided INvestigative Environment -is a digital forensics project based on Ubuntu Hardy Heron. It comes complete with the full complement of Ubuntu’s traditional Gnome interface. On top of the Ubuntu kernel is an assembly of open source computer forensics tools held together by a perl wrapper. Tools included are:

Grissom Analizer
Automated Image & [...]

Comments (4)

Google quick with XSS vulnerability fix

Google acted quickly to fix a cross site scripting vulnerability reported in the vulnerability archive xssed.com. It took just hours between showing up in the archive and being reported fixed. This comes after being heavily criticsed for not acting quickly to fix other reported vulnerabilities in the past. Read more here

Leave a Comment

Get out of jail free card

This prison inmate manages to exploit a vulnerability in a legal search software to obtain the username and password to the prison management system in addition to stealing inmates personal records. I wonder what the prison management system could be used for! e.g. could it be used to set prisoner release dates, move people to [...]

Leave a Comment