Security Blog | It’s all about Security – Security Blog -

Archive for May 2010

May/10

24

Web Warriors (CBC/HDTV)

Salut, am gasit un filmulet interesant pe internet. Are aproape 40 de minute, si zic eu ca merita.

Vizionare Placuta!

· · ·

May/10

10

Windows 7 Security – Slides

Am gasit ceva interesant despre securitatea din Windows 7.
Sper sa va placa!


Pareri ?

· · · · ·

Jarlsber

A aparut un nou tool, creat chiar de ‘marele’ Google.
Ce ofera acest tool?!

Learn how hackers find security vulnerabilities!
Learn how hackers exploit web applications!
Learn how to stop them!

This codelab shows how web application vulnerabilities can be exploited and how to defend against these attacks. The best way to learn things is by doing, so you'll get a chance to do some real penetration testing, actually exploiting a real application. Specifically, you'll learn the following:

How an application can be attacked using common web security vulnerabilities, like cross-site scripting vulnerabilities (XSS) and cross-site request forgery (XSRF).
How to find, fix, and avoid these common vulnerabilities and other bugs that have a security impact, such as denial-of-service, information disclosure, or remote code execution.

To get the most out of this lab, you should have some familiarity with how a web application works (e.g., general knowledge of HTML, templates, cookies, AJAX, etc.).

O sa il incerc si eu, dupa licenta, ca deocamdata nu am timp. Daca ati reusit sa il testati voi, va rog dati-va cu parerea, sa stiu daca merita sa il incerc.
Apropo, NU sunt fan Google.

Website: http://jarlsberg.appspot.com/
Download: http://jarlsberg.appspot.com/jarlsberg-code.zip

· · · · · · ·

De ce ?

Am reusit sa identific 5 motive “mari” pentru care hackerii sparg retele in ziua de azi:

1. Retele contin sistem ce au in dotare date sensibiel(parole, carti de credit, informatii confidentiale etc).
2. Asigura facilitati de comunicare pentru a muta datele furate prin lume(pot muta carti de credit prin mai multe retele).
3. Sistemele din retea sunt folosite pentru a cripta datele furate, inainte de a fi mutate prin lume.
4. Sistemele din retea sunt folosite pentru a stoca datele furate.
5. Sistemele sunt folosite pentru creare de troieni, si pentru a dat drumul la viermi.

Cum ?

1. Research general
2. Social engineering(pretext calls, forum-uri etc)
3. Scanning
4. User ID si password breaking
5. Exploit-uri de sistem
6. Interceptarea comunicatiilor (man-in-the-middle attacks)
7. Furt, mita si santaj

Mai stiti si alte motive sau moduri ?!

· · ·

Get Adobe Flash playerPlugin by wpburn.com wordpress themes