HNNCast.2010.08.20
HNNCast for the third week of August 2010 -
Top Stories:
Free Malware from Network Solutions, Virgin’s Love Letter to the Bot Herd, V(D)-Cards, Facebook Likes Malware, iPhone Suck and Sell Scam
News:
Defacement Buffet, OhyouwantAUTH? Celebrity Twits, Month of Abyssec Bugs, Underworld Transaction Processor Popped, Facebook Hack 1.0
Tool Time:
RIPS, RS Mangler, ROPME, Halbred, SAMHAIN, nfex, URLVoid, MBSA 2.0 (NOT), nmapsi4
Quickies:
Cold Fusion’s Hot Mess, Facebook Leak, Passwords are Pointless, Insert Mens Room Joke Here, Smudge Attack, Shopping for SQL Injections
Con Phooey:
Hurricane Labs Hack Challenge, LockCon, Hack in the Box, Security B-Sides, ToonCON
Stack of Shame:
-count: 159
-Turning 1 Year Old This Week:
- RealNetworks: ZDI-CAN-569 & ZDI-CAN-568/RISK:HIGH (10=AV:N/AC:L/Au:N/C:C/I:C/A:C)&AV:N/AC:L/Au:N/C:C/I:C/A:C) Discovered 2009-08-20 (365 days ago) by: Anonymous
- Hewlett-Packard , IBM , Sun Microsystems: ZDI-CAN-561/RISK:HIGH (10=AV:N/AC:L/Au:N/C:C/I:C/A:C) Discovered 2009-08-20 (365 days ago) by: Rodrigo Rubira Branco (BSDaemon)
- Sun Microsystems: ZDI-CAN-552/RISK: HIGH (9.4=AV:N/AC:L/Au:N/C:C/I:C/A:N) Discovered 2009-08-20 (365 days ago) by: Sami Koivu
Posted: August 21st, 2010
at 10:52pm by tan
Tagged with "Network Solutions", Abysssec, Adobe, Android, Anti-Virus, API, Apple, AV, Axel Rose, binary analysis, botnet, brute force, CCBill, ColdFusion, cPanel, Dallas, darknet.org, defacement, Delaware, dictionary, dislike button, DSS, Essen, Excel, exploit, exploit database, Facebook, Facebook Hacker 1.0, Fethard Finance, file integrity, Fort Worth, gadgets, Georgia Tech Research Institute, GPS Spy, GPU, Guns and Roses, Hack In The Box, Halbred, HP, Hurricane Labs Hack Challenge, IBM, India, Indian Cyber Army, IndiShell, Internet Explorer, Intrusion Detection, iPhone, ISP, Justin Bieber, Kansas City, Koobface, lockcon, LSASS, Malaysia, malware, MBSA 2.0 (NOT), Microsoft, Microsoft codecs, MOAUB, mobile security, Month of Abysssec Undisclosed Bugs, Mozilla, Newcastle, nfex, nmapsi4, OAUTH, Ohio, online supermarket, oracle, PAK Cyber Army, PAK haxors, Pakistan, Palm, passwords, patch, PCI, Penn State, PHP, Pre, python, QT, Real Networks, RIPS, rogue facebook application, ROP Exploit, ROPME, RS Mangler, SAMHAIN, scam, Security B-Sides, securitybsides.com, Shadowserver Foundation, SIM cards, smart phone, smudge attack, sql injection, static source code analysis, Sun, Tapsnake, tcpxtract, tinyurl, Tipping Point, ToonCON, Trojan, Twitter, URLVoid, vCard, Vijay Mallya, Virgin media, virtual business card, vulnerability, WebOS, widget, ZDI, Zero Day Initiative
Comments: 1 comment
HNNCast.2010.08.06
HNNCast for the second week of August 2010
Top Stories
Jailbreak Me Demos Threat, Full Disclosure: Crappy Software Ahead
Courtnee: BlackHat/B-Sides/Defcon Wrap-Up
News
StuxNet Tongue-Twister, Masato Notoutforlong, Citi App Spills Secrets, Wake Up People
T00l Time
Aanval, Razorback, DFF, Passware, BinPack, BinNavi, PDF Dissector, PinTool, Seccubus, SotF, L0phtCrack
Quickies
Bulletin on vBulletin, Houston We Have a < 140 Character Problem, Carbon Trading Site Polluted, the Mets Bust Some Marlins, Ausi Malware Author Pleas, Virus Variants Spike, Inside Mumba, Moving Money from QA
Hong CON Phooey
Excaliber Con, H2H, HoaP, Thotcon 2, Shmoocon, HacKid Con, HNN in the Defcon Badge
Stack of Shame
count: 117
Posted: August 8th, 2010
at 1:47pm by tan
Tagged with "cross-site scripting", "open source", Aanval, ACME Pharm, activists, Adobe, airpwn, android rootkit, Anthony Harrison, anti-carbon trading, Apple, arrest, ATM, B-Sides, back door, banking credentials, Banking Trojan, barcode, Barnaby Jack, Behind the Firewall, binary analysis, BinNavi, BinPack, Blackhat, botnet, Brad Threatt, breeches, bugs, c, cancelled talks, Capture the Flag, carbon trading, Central e-Crime Unit, Chinese Cyber Army, Chymine, Cigigroup, CityBank, compiler optimization, coordinated disclosure, Cross Site Scripting Filters, CTF, Dark Tangent, debugging, decrypt, Defcon 18, Defcon 19, Defcon Badge, DFF, Digital Forensic Framework, digital forensics, disclosure, distribution, distro, driver debugging, dynamic instrumentation, dynamic instrumentation framework, eBay, emo, emulator, enterprise equipment, Excaliber Con, exploit, filters", flat screen TV, forensic framework, Forrester, forum software, framework, full disclosure, Goat Bar, Google, GPU, Grand Idea Studio, grandideastudio.com, GSM eavesdropping, guilty, H2H, Hacker News, Hacker News Network, HacKid Con, hacktivism, high speed trading, HNN, HoaP, IBM, IDA Pro, IE, Intel, Internet Explorer 8, iPad, iPhone, jackpotting, jailbreaking, jailbreakme.com, java script, javascript, Jeff Moss, Joe Grand, kernel debugging, keynote, L0phtCrack, Las Vegas Edition, LNK, local, malware, management console, manga octopus, manga sea urchin, manga squid, Masato Nakatsuji, McAffee, Members 1st Federal Credit Union, metasploit, Metropolitan Police, Microsoft, mobile banking, mobile device security, Most Epic Fail, Mozilla, Mumba, NASA, Nessus, obfuscated java script, Octopus virus, Passware, passwords, patches, PDF, PDF Dissector, phishing, PIN, PinTool, plea, Power Point, profiling, Pwnie Awards, python, Razorback, RC4, remote, remote debugging, remote jailbreak, responsible disclosure, Rio, Riv, Riviera, Robin Sage, Sality, SANS, SANS Boston, SCADA, Seccubus, Security, security research, security researchers, security tools, Seimans, ShmooCon, SIMATIC, smart phone botnet, SMTP, Snort, social engineering contest, social networking, SotF, Sourcefire, stack of shame, Stuxnet, syslog, Thotcon 2, Tipping Point, TrueCrypt, Twitter, University of Virginia, UPC, usernames, vBulletin, Vegas, Verizon Data Breach Investigations Report, Vobfus, vulnerability reporting, website defacement, West Coast Hackers, Win32 driver debugging, Win32 kernel debugging, WinCC, Word, worm, XSS, ZDI, Zero Day Initiative, Zeus, Zeus botnet, Zynamics
Comments: 1 comment
HNNCast.2010.07.09
HNNCast for the first week of July, 2010
Lead Stories:
- the iTunes Blues, YouTube XSS, Pirate Bay SQL Injections, Jackpotting, Facebook Admin pwned, Cisco Live SPAM, Cyber Command Code
News:
- Disclosure Debated Again, Photo Kioskery, Cybaby, Romanian FlexiSpies, Symbian Malware, South Korean Poker Jokers, Back Track Backed to get Stacked
Tool Time:
- BinNavi, PDF Dissector, ida2sql, Deblaze, KillerBee, Ostinato, NeoPwn, Cubes, SIP Vicious, SmartCarving
Quickies:
- PAK Bugs Busted, Biden Wifi Taunter Temps Fate, Hacker Croll Update, Brit Banking Boinked by da Boys, GEXA Getsa Disgruntled Ex, PHP Attacks Continue, FBI Truely Crypt-up, Dvorsky Pulls a Palin, Another Superman III Scam, Butterflies and Octopi, I Will Never Click Again, Maine-stay for Malware, Bush gets “Hi” from Saudi Hackers, XPSP3
Cons Call:
- B-Sides Detroit, B-Sides Cleveland, B-Sides Las Vegas, CCC 2011, the NEXT HOPE, dEFFcon 18 Getaway Results, #1 Hacker Contest, DC18 Ninja Party, pwnie Award Nominations Still Open, Hacker Poker Invitational
Stack of Shame
count: 141
There is no Stack of Shame this week. ZDI seems to be split between going with CVSS2 scores or H/M/L… and went BOTH ways… Perhaps this will be worked out soon?
Posted: July 11th, 2010
at 5:57am by tan
Tagged with "cross-site scripting", "Hacker Croll", "Hi from Saudi Hackers", "I Will Never Text Again", "Offensive Security", "South Korea", 0day, 2m, 70cm, 802.11.15.4, ActionScript, Anti-Virus, Ap Store, Apple, Ashton Kuchner, ATM jackpotting, Automatic Teller Machines, B-Sides, Back Track Linux, backtrack, Badges, Barnaby Jack, BinNavi, Blackberry, Blackhat, Bluehost, Bob Dvorsky, botnet, carding forum, CCC 2011, Cisco Live, Cleveland, CnC, Cubes, Cybaby, DDoS, Deblaze, defaced, Defcon, Defcon forums, dEFFcon 18 Getaway Contest, Detroit, EFF, email, encrypted string, Ethical Disclosure, Facebook, FBI, Federal Investigative Agency of Pakistan, Flash Remoting, Flexi Spy, forensic, Francois Cousteix, fraud, Fraud Prevention Specialist, FTC, full disclosure, Gen. Keith Alexander, George Bush Presidential Library and Museum, GEXA Energy, GPS, Hack In The Box, Hacker Poker Invitational, HAM radio, ida2sql, International Roll-Call, iPhone, itunes, Japanese Manga, javascript, Joomla, Justin Beiber, KillerBee, Kraken, Las Vegas, Legatt, Lilly Allen, Maine, mainelegislature.org, malware, Mariposa, md5, Microsoft, Microsoft Security Response Center, Microsoft Spurned Researcher Collective, MSRC, N900, NeoPwn, NetBot Attacker, Ninja Networks, NSA, online poker, Ostinato, PAKbugs, PDF Dissector, photo kiosk, PHP, Pirate Bay, piratebay.org, Pokercon, President Obama, Pwnie Awards, Raoul Chiesa, responsible disclosure, Riviera, Sarah Palin, SCADA, security challenge, Service Pack 2, Service Pack 3, Shawn Merdinger, SIP Vicious, smart phone, SmartCarving, SMS, software certification, SPAM, sql injection, Superman III, Symbian, Symbian Series 60, Tavis Ormandy, the Next HOPE, the Underground Economy, the World's #1 Hacker Contest, TrueCrypt, Twitter, U.S. Cyber Command, upSploit, US House of Representatives, USB, Vice President Biden, VM, WiFi, windows mobile, Windows XP, Wireshark, Wordpress, XSS, Yahoo, YouTube, youtube.com, zero-day, Zigbee, Zynamics
Comments: 1 comment









