HNNCast.2011.02.18
HNNCast for the third week of February, 2011
Top Story
Team Themis
News
Plenty of Breach, Stuxnet Attribution, Lush Breach Broader than Believed, Show Me THAT Money
T00l T1m3
updated: Vera, Fiddler, Dradis, Arachni, RAT, Nmap, Nessus
new: IronBee, PhoneyC, Mimic, SQueRT
Quickies
It’s the Chinese Eh, Dark Side of the Moon for Solo, /lib/keyboard, Recruiting Suckaz, One Too Many Clicks to BBC Six, WinAmp0wnage, Bad Days for Jewlers, Back to Basics Down Under, Back-peddling on AutoRun, Kingpin
Con Fu
pwn2own update, DC19 Cracking Contest, Sweet Paris
Stack of Shame
count: 58 (-7)
10 (-2) OVERDUE! 2/4/11 (-14):
ZDI-CAN-830 from Novell ( 239 days )
ZDI-CAN-767 from Microsoft ( 317 days )
ZDI-CAN-733 from Apple ( 332 days )
ZDI-CAN-713 from Sun Microsystems ( 342 days )
ZDI-CAN-691 from Apple ( 359 days )
ZDI-CAN-672 from Microsoft ( 380 days )
ZDI-CAN-244 from Borland ( 456 days )
ZDI-CAN-543 from Microsoft ( 560 days )
ZDI-CAN-533 from Microsoft ( 574 days )
ZDI-CAN-348 from RealNetworks ( 967 days )
One Response to 'HNNCast.2011.02.18'
Subscribe to comments with RSS
Leave a Reply
You must be logged in to post a comment.
Posted: February 19th, 2011
at 6:03pm by tan
Tagged with Aaron Barr, Adobe, ambulance dispatch, anonymous, APT, Arachni, autorun, Bank of America, BBC 6 Music, Berico Technologies, binary visualizer, BitTorrent, black market, breach, Brian Krebs, Canada, CanSecWest, Carders Planet, China, CMS, Crack Me If You Can, Credit Cards, David Gilmour, Days Jewlers, defacement, Defcon 19, Department of Justice, Dradis, Drive-By, eHarmony, email spools, Fiddler, Finance Department, Gary McKinnon, Greg Hoglund, hardware keyboard logger, HB Gary Federal, HoneyMonkey, honeynet project, Huton & Williams, Iran, IronBee, Isreal, Joe Grand, Kenvin Poulsen, Kingpin, Kore Logic, Lieutenant General Gabi Ashkenazi, LinkedIn, Log Visualizer, Lush, malware, Matt Moynahan, Max Bulter, Max Vision, Microsoft, Mimic, NASA, Natanz, Nessus, network scanner, nmap, One-Extra, Palantir Technologies, Paris, password cracking contest, password files, password reuse, passwords, pentest framework, phishing, Phoenix exploit kit, PhoneyC, Plenty of Fish, POS, PS2, Pwn2Own, Qualys, RAT, Real Networks, recruit ireland, remote access tool, RSA, SCAPECOM, Security B-Sides, security proxy, Snort, social engineering, Solo, South Wales Australia, SQueRT, Strider, Stuxnet, Symantec, Team Themis, Tenable, Treasury Board, Twitter, unpatched systems, US Chamber of Commerce, USB, usernames, Vera, Veracode, virus, Vulnerability Scanner, Waterville Maine, web app scanner, WikiLeaks, WinAmp, Windows 7 SP1, wordlists, XP, ZDI, zero-day
Comments: 1 comment










HNNCast for the third week of February, 2011
//Top Story/
Team Themis
http://arstechnica.com/tech-policy/news/2011/02/anonymous-speaks-the-inside-story-of-the-hbgary-hack.ars
http://www.pcworld.com/businesscenter/article/219769/hacked_and_now_vandalized_hbgary_pulls_out_of_rsa.html
http://thinkprogress.org/2011/02/10/chamberleaks-target-families/
http://uk.news.yahoo.com/16/20110212/ttc-anonymous-hack-reveals-hbgary-plan-t-6315470.html
http://www.hbgary.com/statement.htm
http://www.wired.com/threatlevel/2011/02/spy/
http://publicintelligence.net/hbgary-team-themis-corporate-information-reconnaissance-cell-documents/
//News/
Plenty of Breach
http://krebsonsecurity.com/2011/02/eharmony-hacked/
Stuxnet Attribution
http://blogs.pcmag.com/securitywatch/2011/02/new_details_on_stuxnet_emerge.php
http://www.foxnews.com/scitech/2011/02/15/anonymous-hackers-offer-stuxnet-worm-online/
http://translate.google.com/translate?js=n&prev=_t&hl=en&ie=UTF-8&layout=2&eotf=1&sl=iw&tl=en&u=http://www.haaretz.co.il/hasite/spages/1215246.html
http://www.telegraph.co.uk/technology/news/8326274/Israeli-security-chief-celebrates-Stuxnet-cyber-attack.html
Lush Breach Broader than Believed
http://www.heraldsun.com.au/news/national/lush-customers-warned-of-hacker-threat-to-credit-cards/story-e6frf7l6-1226006067629
http://www.theregister.co.uk/2011/02/14/lush_hacked_in_oz/
http://www.youtube.com/watch?v=tmPgKe0E7-k
Show Me THAT Money
http://www.veracode.com/ceo-blog/2011/02/the-price-of-a-zero-day-exploit/
http://www.infosecurity-magazine.com/view/15889/interview-matt-moynahan-ceo-veracode
//T00l T1m3/
updates-
http://www.vulnerabilitydatabase.com/toolswatch/2011/02/14/vera-v0-31-visualizing-executables-for-reversing-and-analysis-released/
http://www.vulnerabilitydatabase.com/toolswatch/2011/02/14/fiddlercore-the-web-debugging-proxy-v2-3-2-3-has-been-released/
http://www.vulnerabilitydatabase.com/toolswatch/2011/02/14/dradis-v2-6-1-released-the-pentest-sharing-information/
http://dradisframework.org/screenshots.html http://www.vulnerabilitydatabase.com/toolswatch/2011/02/14/nmap-v5-51-released/ http://www.vulnerabilitydatabase.com/toolswatch/2011/02/14/arachni-web-application-security-scanner-framework-v0-2-2-1-released/
http://www.nessus.org/
new-
https://www.ironbee.com/
http://chuvakin.blogspot.com/2011/02/honeynet-project-releases-new-tool.html
http://research.microsoft.com/en-us/um/redmond/projects/strider/honeymonkey/
http://www.vulnerabilitydatabase.com/toolswatch/2011/02/14/mimic-data-log-management-v1-0-released/
http://www.scapecom.com/index.php/mimic-gallery
http://blog.snort.org/2011/02/squert-08-has-been-released.html
//Quickies/
http://www.cbc.ca/politics/story/2011/02/16/pol-weston-hacking.html
http://www.contactmusic.com/news.nsf/story/gilmour-paying-for-mckinnons-therapy_1201788
http://nakedsecurity.sophos.com/2011/02/14/hardware-keyloggers-discovered-public-libraries/
http://www.breakingnews.ie/business/eysncwqlidql/
http://www.theregister.co.uk/2011/02/10/job_site_breach/
http://community.websense.com/blogs/securitylabs/archive/2011/02/15/bbc6-website-injected-with-malicious-code.aspx
http://www.theregister.co.uk/2011/02/16/winamp_forum_hack_password_reset/
http://www.boston.com/news/local/new_hampshire/articles/2011/02/15/maine_jewelry_store_chains_computers_hacked/
http://forums.cnet.com/7726-6132_102-5082083.html
http://www.f-secure.com/weblog/archives/00002099.html
http://www.amazon.com/Kingpin-Hacker-Billion-Dollar-Cybercrime-Underground/dp/0307588688
//Con Fu/
http://cansecwest.com/
http://security.goldsby.com/2011/02/16/defcon-2011-crack-me-if-you-can-password-lists/
http://contest.korelogic.com/wordlists.html
http://www.honeynet.org/node/602
//Stack of Shame/
http://www.zerodayinitiative.com/advisories/upcoming/
tan
19 Feb 11 at 6:12 pm