HNNCast.2010.08.27
HNNCast for the last week of August 2010 -
Top Stories:
Dejavu Microsoft Style, Middle Eastern USB Sticks it to US, PayPal/iTunes Warning, SpanAir Malware not in the Air
News:
Far East Joint Police Actions, Halo Reach Leak, Yo Yo Dos, AutoTrader Raiders
Tool Time:
Fast HTTP Vulnerability Scanner, XSSer, HTTP4e, DotDotPwn, RootKitUnhooker, OpenSSH, RS Mangler Correction
Quickies:
Indian Election Integrity in Question, Miss Vietnam Election Integrity NOT in Question, Seymour’s Butt, Irish Youth Identities Likely Leaked, UN Still SQL Injectable, Holly Benson DoS’d, InfoSec M&A, a REAL MIT Hack
Con Fu:
DefCon 18 Archive, RuxCon CFP, BlackHat Abu Dhabi CFP, Source Barcelona Registration, BruCon Beta Schedule, HacKid Con Registration, Malcon CFP
Stack of Shame:
Count: 151
Birthdays:
- ZDI-CAN-381 from IBM ( 730 days )
- ZDI-CAN-375 from IBM ( 730 days )
- ZDI-CAN-374 from IBM ( 730 days )
- ZDI-CAN-373 from IBM ( 730 days )
- ZDI-CAN-372 from IBM ( 730 days )
- ZDI-CAN-371 from IBM ( 730 days )
Posted: August 29th, 2010
at 4:49pm by tan
Tagged with "South Korea", agent.btz, ATM fraud, Autotrader.com, BlackHat Abu Dhabi CFP, botnet, BruCon Beta Schedule, BSA, CAO, China, classified networks, credit card skimming, DC-9, DDoS, DefCon 18 Archive, DigiNinja, DOM, DotDotPwn, e-voting system, election fraud, Fast HTTP Vulnerability Scanner, FDC worm, Fortify, Fuzz, Germany, HacKid Con Registration, Halo reach, Hari Prasad, Holly Benson, HP, HTTP4e, IBM, Intel, Ireland, itunes, JSON, LNK bug, Malcon CFP, malware, McAffee, metasploit, Microsfot, Microsoft, Miss Vietnam World, MIT, online auction fraud, OpenSSH, password reset, Paypal Apple, process control vulnerability, Random Storm, REST, RKU, Robin, root-kit, RootKitUnhooker, RS Mangler, RuxCon CFP, Seymour Connecticut, Source Barcelona Registration, SpanAir, sql injection, Taiwan, TARDIS, telecom fraud, Tipping Point, Trojan, UN, United Nations, USB, voting machines, William J. Lynn III, Windows, XBox Live, XSSer, yoyodos, ZDI, Zero Day Initiative
Comments: 1 comment
HNNCast.2010.07.09
HNNCast for the first week of July, 2010
Lead Stories:
- the iTunes Blues, YouTube XSS, Pirate Bay SQL Injections, Jackpotting, Facebook Admin pwned, Cisco Live SPAM, Cyber Command Code
News:
- Disclosure Debated Again, Photo Kioskery, Cybaby, Romanian FlexiSpies, Symbian Malware, South Korean Poker Jokers, Back Track Backed to get Stacked
Tool Time:
- BinNavi, PDF Dissector, ida2sql, Deblaze, KillerBee, Ostinato, NeoPwn, Cubes, SIP Vicious, SmartCarving
Quickies:
- PAK Bugs Busted, Biden Wifi Taunter Temps Fate, Hacker Croll Update, Brit Banking Boinked by da Boys, GEXA Getsa Disgruntled Ex, PHP Attacks Continue, FBI Truely Crypt-up, Dvorsky Pulls a Palin, Another Superman III Scam, Butterflies and Octopi, I Will Never Click Again, Maine-stay for Malware, Bush gets “Hi” from Saudi Hackers, XPSP3
Cons Call:
- B-Sides Detroit, B-Sides Cleveland, B-Sides Las Vegas, CCC 2011, the NEXT HOPE, dEFFcon 18 Getaway Results, #1 Hacker Contest, DC18 Ninja Party, pwnie Award Nominations Still Open, Hacker Poker Invitational
Stack of Shame
count: 141
There is no Stack of Shame this week. ZDI seems to be split between going with CVSS2 scores or H/M/L… and went BOTH ways… Perhaps this will be worked out soon?
Posted: July 11th, 2010
at 5:57am by tan
Tagged with "cross-site scripting", "Hacker Croll", "Hi from Saudi Hackers", "I Will Never Text Again", "Offensive Security", "South Korea", 0day, 2m, 70cm, 802.11.15.4, ActionScript, Anti-Virus, Ap Store, Apple, Ashton Kuchner, ATM jackpotting, Automatic Teller Machines, B-Sides, Back Track Linux, backtrack, Badges, Barnaby Jack, BinNavi, Blackberry, Blackhat, Bluehost, Bob Dvorsky, botnet, carding forum, CCC 2011, Cisco Live, Cleveland, CnC, Cubes, Cybaby, DDoS, Deblaze, defaced, Defcon, Defcon forums, dEFFcon 18 Getaway Contest, Detroit, EFF, email, encrypted string, Ethical Disclosure, Facebook, FBI, Federal Investigative Agency of Pakistan, Flash Remoting, Flexi Spy, forensic, Francois Cousteix, fraud, Fraud Prevention Specialist, FTC, full disclosure, Gen. Keith Alexander, George Bush Presidential Library and Museum, GEXA Energy, GPS, Hack In The Box, Hacker Poker Invitational, HAM radio, ida2sql, International Roll-Call, iPhone, itunes, Japanese Manga, javascript, Joomla, Justin Beiber, KillerBee, Kraken, Las Vegas, Legatt, Lilly Allen, Maine, mainelegislature.org, malware, Mariposa, md5, Microsoft, Microsoft Security Response Center, Microsoft Spurned Researcher Collective, MSRC, N900, NeoPwn, NetBot Attacker, Ninja Networks, NSA, online poker, Ostinato, PAKbugs, PDF Dissector, photo kiosk, PHP, Pirate Bay, piratebay.org, Pokercon, President Obama, Pwnie Awards, Raoul Chiesa, responsible disclosure, Riviera, Sarah Palin, SCADA, security challenge, Service Pack 2, Service Pack 3, Shawn Merdinger, SIP Vicious, smart phone, SmartCarving, SMS, software certification, SPAM, sql injection, Superman III, Symbian, Symbian Series 60, Tavis Ormandy, the Next HOPE, the Underground Economy, the World's #1 Hacker Contest, TrueCrypt, Twitter, U.S. Cyber Command, upSploit, US House of Representatives, USB, Vice President Biden, VM, WiFi, windows mobile, Windows XP, Wireshark, Wordpress, XSS, Yahoo, YouTube, youtube.com, zero-day, Zigbee, Zynamics
Comments: 1 comment
HNNCast.2010.06.18
HNNCast for the third week of June, 2010
Lead Stories
- Ormandy’s Help Goes Unappreciated, GoatSe’s Gaping Hole, IRC Back-doored, Dark Energy Reignites
News
- Attack@Rackspace, Big Skimmer Bust, South Korean fingers China… again, Cult of the Dead Hadopi
Tool Time
- Wireshark, Hydra, JTR, Immunet Protect Free, Fierce, Maltego, Researcher’s Bot Socialization
Quickies
- Taliban – Durka’d!, World Cup – Durka’d?, Riyad Bank – Durka’d!, Reddit Popped, Patebin for Keystrokes, LikeJacking on the Rise, How NOT to be Anonymous
Cons Call
- HOPE Badges, Assange Keynote in Question, B-Side Bait, Pwnie’s Still Open, D-EFF-CON Get-Away, D-EFF-CON T’s, Poker Con NOT On, Tamper Evident Tangent
Stack of Shame
- count: 129
Posted: June 21st, 2010
at 12:38am by tan
Tagged with "Network Solutions", "South Korea", 0day, Al Jazeera, Al Madina, Andrew Auernheimer, Anti-Virus, AT&T, ATM skimmers, banks, Barry Ardolf, Blackhat, botnet, broadcasts, bruce potter, China, click-jacking, cocaine, compromise, credit card cloning, crypt hashes, cryptographic signing, Dark Energy, Dark Tangent, data mining, DDoS, Defcon, DEFFCON 18 Get-Away, DNS enumeration, ecstasy, EFF, Elite Jihad Forum, Facebook, FBI, Fierce, full disclosure, Gene Kim, Georgia, GoatSe Security, GoDaddy, Google, Hadopi, HD Moore, Hydra, IBM, ICC-ID, Immunet Protect Free, IMSI, infiltration operation, iPad, IRC, ircd, ISP, java based authentication schemes, Jeff Moss, Joe Biden, John the Ripper, JtR, Julian Assange, keylogger, keynote, Korea Culture and Information Service, like-jacking, LSD, Maltego, malware, Media Temple, metasploit, MFA, Microsoft, Ministry of Justice, Ministry of Public Administration and Security, mirrors, multi-factor-authentication, nmap, nominations, off-line password cracker, online login cracker, OpenAMD, Orange Telecom, P2P file-sharing, P2P HADOPI law, PasteBin, Patvera, phishing, PHP, Pokercon, Pwnie Awards, RackSpace, Rapid7, Reddit, reddit.com, resort, Riyad Bank, Russia, sabotage, Saudi Arabia, Security B-Sides, social engineering and information correlation bot, source code, Spain, SSH2, Taliban, Tamper Evident Contest, tarball, Tavis Ormandy, THC, The Hacker's Choice, the Last HOPE, the Next HOPE, Twitter, UK, Ukraine, Unreal IRC, Weev, WHitePhosphorus, WiFi, WikiLeaks, Windows, Windows Help System, Wireshark, Wordpress, World Cup Soccer, XP, ZDI, Zero Day Initiative
Comments: 1 comment









