Monthly Archives: May 2007

Protecting Consumers and Merchants Online

For more than thirty years, Visa has helped to set industry standards for secure payments between consumers and merchants. Verified by Visa protects online merchants in the following ways: You, as merchant, are not liable for fraud resulting from the … Continue reading

Share
Posted in Internet Security | Leave a comment

Has Globalization Made Software Development a US National Security Issue?

Software development has been transformed into a issue of national security as a result of IT globalization, according to a warning from former U.S. cybersecurity czar Andy Purdy. “Companies are looking for the least expensive source of production, but there … Continue reading

Share
Posted in Secure Programming | Leave a comment

Comments on the Hash Algorithm Requirements and Evaluation Criteria

In recent post I wrote about NIST competition for new cryptographic hash function. NIST (National Institute for Standards and Technology) published now comments received on the hash algorithm requirements and evaluation criteria. Among others, big companies (Microsoft, IBM) sent their … Continue reading

Share
Posted in Cryptography | Leave a comment

PCI DSS compliance low as June deadline looms

Interesting article: Software – PCI DSS compliance low as June deadline looms: Survey reveals alarmingly low levels of compliance for PCI DSS with only 3% of merchants ready. Top line survey findings include: 85% of respondents are aware of the … Continue reading

Share
Posted in Internet Security | Leave a comment

Cracking Passwords

Here is small list of tools for cracking passwords. It is listed in order: tool, URL, and short description. Dictionaries / Wordlists ftp://coast.cs.purdue.edu/pub/dict/, http://packetstormsecurity.org/Crackers/wordlists/dictionaries/ – Word lists that can be used in most password-cracking utilities. Hydra http://www.thc.org/thc-hydra/ A fast network logon cracker that supports … Continue reading

Share
Posted in Security, Tools and Utilities | Leave a comment

Cisco – Password Recovery Procedures

This, recently updated page, is an index of password recovery procedures for Cisco products. For security reasons, the password recovery procedures listed, require physical access to the equipment. See: Cisco – Password Recovery Procedures.

Share
Posted in Hardware Security, Internet Security | Leave a comment

WordPress Redoable Theme “s” Cross-Site Scripting

Recently, this blog experienced attacks or better to say XSS bug testing which, fortunately, was unsuccessful. Yesterday John Martinelli has discovered a vulnerability in the Redoable theme for WordPress (I don’t use this theme – lucky again), which can be … Continue reading

Share
Posted in Secure Programming, Security | Leave a comment

Internet Explorer 7 navcancl.htm Cross-Site Scripting Vulnerability

Here is test to see an example of how this vulnerability can be exploited, and also to determine whether or not your browser is vulnerable: Internet Explorer 7 navcancl.htm Cross-Site Scripting Vulnerability – Secunia. If you are vulnerable, text similar to this will … Continue reading

Share
Posted in Internet Security | Leave a comment

Cracking WEP

WEP is dead and here’s the proof – explanation how attack on the 802.11 wireless security protocol works: Gone in 120 seconds: cracking Wi-Fi security | The Register.

Share
Posted in Wireless Security | Leave a comment

OSSEC v1.2 released

Availability of new version of OSSEC (Open Source Host-based Intrusion Detection System) has been announced today at SecurityFocus mail list dedicated to intrusion detection systems. OSSEC performs log analysis, file integrity checking, Windows registry monitoring, rootkit detection, real-time alerting and active response. … Continue reading

Share
Posted in Intrusion Detection / Prevention Systems | Leave a comment