Archive for the 'infosec' Category

APT1 Exposing One of China’s Cyber Espionage Units [PDF]

Wednesday, February 20th, 2013

report from a computer security company that links Chinese hack group APT1 to China’s government [Army] ————— aPt1 is believed to be the 2nd Bureau of the People’s Liberation army (PLa) General staff Department’s (GsD) 3rd Department (总…

APT1 Exposing One of China’s Cyber Espionage Units [PDF]

Wednesday, February 20th, 2013

report from a computer security company that links Chinese hack group APT1 to China’s government [Army] ————— aPt1 is believed to be the 2nd Bureau of the People’s Liberation army (PLa) General staff Department’s (GsD) 3rd Department (总…

http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf

Monday, November 21st, 2011

Guide to Computer Security – Log Management, NIST Publication 800-92 (SEP-2006) / Describes enterprise log management, collection & analysis from policy and technology perspectives.

http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf

Monday, November 21st, 2011

Guide to Computer Security – Log Management, NIST Publication 800-92 (SEP-2006) / Describes enterprise log management, collection & analysis from policy and technology perspectives.

JBoss Worm Exploiting Old Bug to Infect Unpatched Servers | threatpost

Saturday, October 22nd, 2011

Worm uses bug in jmx-console to execute shell code, then it installs perl-based control daemon that connects to IRS, and tries to discover other JBoss’es near by by using jgroups UDP multicast. Here is more details, including the source code http://pa…

JBoss Worm Exploiting Old Bug to Infect Unpatched Servers | threatpost

Saturday, October 22nd, 2011

Worm uses bug in jmx-console to execute shell code, then it installs perl-based control daemon that connects to IRS, and tries to discover other JBoss’es near by by using jgroups UDP multicast. Here is more details, including the source code http://pa…

BlackHat USA 2011: SSL And The Future Of Authenticity – YouTube

Tuesday, September 13th, 2011

MOXIE MARLINSPIKE talk at BlackHat USA 2011 about current problems with SSL and CA sustem, and the feature of SSL w/out CAs.

BlackHat USA 2011: SSL And The Future Of Authenticity – YouTube

Tuesday, September 13th, 2011

Penetration Testing Policy for Amazon EC2

Thursday, August 25th, 2011

read this if you need to conduct pen and security testing on / from EC2 instances

Penetration Testing Policy for Amazon EC2

Thursday, August 25th, 2011