HNNCast.2010.08.27
HNNCast for the last week of August 2010 -
Top Stories:
Dejavu Microsoft Style, Middle Eastern USB Sticks it to US, PayPal/iTunes Warning, SpanAir Malware not in the Air
News:
Far East Joint Police Actions, Halo Reach Leak, Yo Yo Dos, AutoTrader Raiders
Tool Time:
Fast HTTP Vulnerability Scanner, XSSer, HTTP4e, DotDotPwn, RootKitUnhooker, OpenSSH, RS Mangler Correction
Quickies:
Indian Election Integrity in Question, Miss Vietnam Election Integrity NOT in Question, Seymour’s Butt, Irish Youth Identities Likely Leaked, UN Still SQL Injectable, Holly Benson DoS’d, InfoSec M&A, a REAL MIT Hack
Con Fu:
DefCon 18 Archive, RuxCon CFP, BlackHat Abu Dhabi CFP, Source Barcelona Registration, BruCon Beta Schedule, HacKid Con Registration, Malcon CFP
Stack of Shame:
Count: 151
Birthdays:
- ZDI-CAN-381 from IBM ( 730 days )
- ZDI-CAN-375 from IBM ( 730 days )
- ZDI-CAN-374 from IBM ( 730 days )
- ZDI-CAN-373 from IBM ( 730 days )
- ZDI-CAN-372 from IBM ( 730 days )
- ZDI-CAN-371 from IBM ( 730 days )
Posted: August 29th, 2010
at 4:49pm by tan
Tagged with "South Korea", agent.btz, ATM fraud, Autotrader.com, BlackHat Abu Dhabi CFP, botnet, BruCon Beta Schedule, BSA, CAO, China, classified networks, credit card skimming, DC-9, DDoS, DefCon 18 Archive, DigiNinja, DOM, DotDotPwn, e-voting system, election fraud, Fast HTTP Vulnerability Scanner, FDC worm, Fortify, Fuzz, Germany, HacKid Con Registration, Halo reach, Hari Prasad, Holly Benson, HP, HTTP4e, IBM, Intel, Ireland, itunes, JSON, LNK bug, Malcon CFP, malware, McAffee, metasploit, Microsfot, Microsoft, Miss Vietnam World, MIT, online auction fraud, OpenSSH, password reset, Paypal Apple, process control vulnerability, Random Storm, REST, RKU, Robin, root-kit, RootKitUnhooker, RS Mangler, RuxCon CFP, Seymour Connecticut, Source Barcelona Registration, SpanAir, sql injection, Taiwan, TARDIS, telecom fraud, Tipping Point, Trojan, UN, United Nations, USB, voting machines, William J. Lynn III, Windows, XBox Live, XSSer, yoyodos, ZDI, Zero Day Initiative
Comments: 1 comment
HNNCast.2010.08.20
HNNCast for the third week of August 2010 -
Top Stories:
Free Malware from Network Solutions, Virgin’s Love Letter to the Bot Herd, V(D)-Cards, Facebook Likes Malware, iPhone Suck and Sell Scam
News:
Defacement Buffet, OhyouwantAUTH? Celebrity Twits, Month of Abyssec Bugs, Underworld Transaction Processor Popped, Facebook Hack 1.0
Tool Time:
RIPS, RS Mangler, ROPME, Halbred, SAMHAIN, nfex, URLVoid, MBSA 2.0 (NOT), nmapsi4
Quickies:
Cold Fusion’s Hot Mess, Facebook Leak, Passwords are Pointless, Insert Mens Room Joke Here, Smudge Attack, Shopping for SQL Injections
Con Phooey:
Hurricane Labs Hack Challenge, LockCon, Hack in the Box, Security B-Sides, ToonCON
Stack of Shame:
-count: 159
-Turning 1 Year Old This Week:
- RealNetworks: ZDI-CAN-569 & ZDI-CAN-568/RISK:HIGH (10=AV:N/AC:L/Au:N/C:C/I:C/A:C)&AV:N/AC:L/Au:N/C:C/I:C/A:C) Discovered 2009-08-20 (365 days ago) by: Anonymous
- Hewlett-Packard , IBM , Sun Microsystems: ZDI-CAN-561/RISK:HIGH (10=AV:N/AC:L/Au:N/C:C/I:C/A:C) Discovered 2009-08-20 (365 days ago) by: Rodrigo Rubira Branco (BSDaemon)
- Sun Microsystems: ZDI-CAN-552/RISK: HIGH (9.4=AV:N/AC:L/Au:N/C:C/I:C/A:N) Discovered 2009-08-20 (365 days ago) by: Sami Koivu
Posted: August 21st, 2010
at 10:52pm by tan
Tagged with "Network Solutions", Abysssec, Adobe, Android, Anti-Virus, API, Apple, AV, Axel Rose, binary analysis, botnet, brute force, CCBill, ColdFusion, cPanel, Dallas, darknet.org, defacement, Delaware, dictionary, dislike button, DSS, Essen, Excel, exploit, exploit database, Facebook, Facebook Hacker 1.0, Fethard Finance, file integrity, Fort Worth, gadgets, Georgia Tech Research Institute, GPS Spy, GPU, Guns and Roses, Hack In The Box, Halbred, HP, Hurricane Labs Hack Challenge, IBM, India, Indian Cyber Army, IndiShell, Internet Explorer, Intrusion Detection, iPhone, ISP, Justin Bieber, Kansas City, Koobface, lockcon, LSASS, Malaysia, malware, MBSA 2.0 (NOT), Microsoft, Microsoft codecs, MOAUB, mobile security, Month of Abysssec Undisclosed Bugs, Mozilla, Newcastle, nfex, nmapsi4, OAUTH, Ohio, online supermarket, oracle, PAK Cyber Army, PAK haxors, Pakistan, Palm, passwords, patch, PCI, Penn State, PHP, Pre, python, QT, Real Networks, RIPS, rogue facebook application, ROP Exploit, ROPME, RS Mangler, SAMHAIN, scam, Security B-Sides, securitybsides.com, Shadowserver Foundation, SIM cards, smart phone, smudge attack, sql injection, static source code analysis, Sun, Tapsnake, tcpxtract, tinyurl, Tipping Point, ToonCON, Trojan, Twitter, URLVoid, vCard, Vijay Mallya, Virgin media, virtual business card, vulnerability, WebOS, widget, ZDI, Zero Day Initiative
Comments: 1 comment
HNNCast.2010.08.13
HNNCast for the second week of August, 2010
Top Stories
RBS Coming to a Close, Phat Patch Tuesday, Kryogeniks R0×0r3d by defiant
News
the Disclosure Game, pr0n m0de Still Unsafe Sex, Wireless Tires, moar Wargames, VxWorks because Rockwell Rox Well
Tool Time
Grid Computing Hackers Kit, Acunetix WVS beta, winAUTOPWN, listener, wpbruteforcer, Debian Live Studio, PHP IDS, IP Tables, Forensic Tool Kit, Titan Mist, Malheur, DOMScan, DOMTracer, Sploitware CORRECTION.
Quickies
RIM’s Lies, the Cyber Mongoose, Shot Heard Round the Facebook, Dutch Durka Durkas, Don’t Get Media Playa’d, Verizon Crypto Challenge, Too Many Holes
Con Phooey
the Next HOPE, Confcon 2010, DerbyCon 2011, Toorcon XII, B-Sides Abound, Notacon
Stack of Shame
count: 157
Birthdays:
ZDI-CAN-543 – v. Microsoft
Risk: 10 (High: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Discovered 2009-08-06 ( 370 days ago )
by: Peter Vreugdenhil (http://vreugdenhilresearch.nl)
Posted: August 14th, 2010
at 11:47pm by tan
Tagged with "Network Solutions", AccessData, account lockout, Acunetix WVS beta, Adobe, andriod, ATM, B-Sides Abound, Blackberry, Blackhat, Blue-infy, BSD, BSDAUTOPWN, Charlie Miller, China, Christopher Lewis, Cleaveland, Cold Fusion, Comcast, Confcon 2010, crypto challenge, Cyber Army, Cyber RAID, Debian Live Studio, Defiant, Delaware, DerbyCon 2011, disclosure, DOM, DOMScan, DOMTracer, Drupal, Dutch Intelligence Service, EBK, Eergei Tsurikov, EFF, Facebook, Firefox, firewall, font rendering engine, Forensic Tool Kit, Google, grid computing, Grid Computing Hackers Kit, GridFTP, Gridsphere, Haddonfield, HD Moore, Hilton Garden Inn, Hosni Mubarak, IBM, IE, IETF, India, IP Tables, IPSEC, Islamic, James Black, Kansas City, Kentucky, keystroke logger, Kryogeniks, listener, London, Los Angeles Times, Malheur, malware, Media Player, Michael Nebel, Microsoft, Mozilla, New Dehli, notacon, OASIS, Oleg Covelin, Opera, patch Tuesday, PHP IDS, phreak, PIN cracking, PKI, porn mode, portlet framework, premium text messages, private browsing mode, RBS WorldPay, Research in Motion, RIM, Rockwell Automation, Russian Federal Security Service, Rutgers University, Saudi Arabia, Slacker, SploitWare, Stanford University, Starving Hacker rate, static build, Tennable, the Next HOPE, Tipping Point, Titan Mist, TNG, Toorcon XII, Toronto, TPWS, Travis Ormandy, Trojan, Unix, Usenix, Verizon Data Breech Investigations Report, Viktor Pleshchuk, Vulnerability Scanner, VxWorks, webservice containers, winAUTOPWN, Windows, Wordpress, wpbruteforcer, ZDI, Zero Day Initiative
Comments: 1 comment









