Use Facebook Apps? Time for a Password Change

RockYou was hacked a couple of weeks ago and over 35 million passwords were stolen. RockYou may have your password if you’ve played any of their Social Networking Applications on sites like Facebook or MySpace. Their applications include Slideshow Uploadphoto Photofx Glittertext Funnotes Countdown Superhug Myspace layouts Stickers Superwall Pieces of flair Speedracing Likeness Hugme …

Continue reading ‘Use Facebook Apps? Time for a Password Change’ »

AVComparatives Corporate Review

AVComparatives has posted a review of corporate products at http://www.av-comparatives.org/comparativesreviews/corporate-reviews. This test includes AVIRA, ESET, GDATA, Kaspersky, Sophos, Symantec and Trustport. No mention of McAfee or Trend Micro who I believe would both be in the top three deployed corporate endpoint protection solutions. The report includes a detailed table comparing the available features of the …

Continue reading ‘AVComparatives Corporate Review’ »

Shmoocon 2009 Day 2

I really shouldn’t have to wake up at 7:30 am on a Saturday and take the Metro into DC. Fortunately I thought the 10am talk was worth it. Phishing Statistics and Intuitive Enumeration of Hosts and Roles by Sean Palka This talk is about a tool he created/uses in corporate engagements. But as with most …

Continue reading ‘Shmoocon 2009 Day 2’ »

Shmoocon 2009 Day 1

The next three posts will contain my notes from Shmoocon. This post contains notes from each session I attended on day 1. I’m not trying to necessarily reconstruct the notes into a coherent thought. Hopefully it will be somewhat readable. Opening Remarks by Bruce Potter People are getting owned a lot. Trends Increased success in …

Continue reading ‘Shmoocon 2009 Day 1’ »

Can MessageLabs improve Symantec Antivirus

I rescued an old comment from Akismet (the spam filter I’m using on the blog) because it asked a interesting question. How can Symantec’s acquisition of MessageLabs improve their desktop antivirus. My first reaction to this is that MessageLabs Antivirus can’t be duplicated at the desktop. They use multiple antivirus engines in addition to their …

Continue reading ‘Can MessageLabs improve Symantec Antivirus’ »

Google Docs Viagra Spam

I was going through my Cox inbox and found Viagra spam with a link to http://doc.google.com/View?id=dfpqm7ft_0tt6xhdd2. Its nothing new that spammers have been taking advantage of Google. Its just kind of annoying to me that this message was sent on October 30th, today is November 10th and the linked Viagra Google doc is still up …

Continue reading ‘Google Docs Viagra Spam’ »