Guest Posts

July 27, 2010, 1:52PM Threatpost Original

Escalating Privileges In the Database Can Wreak Havoc

By Alex Rothacker

Privilege escalation attacks consist of exploiting a bug or design flaw in a software application to gain access to resources which normally are protected from an application or user. The result is that the application allows actions with privileges beyond an acceptable level for the specific user.  

Shorten URL: http://threatpost.com/en_us/cCu. Click to copy to clipboard or post to Twitter

July 19, 2010, 3:16PM Threatpost Original

Bouncing RPC

By Ivan Arce

In the early years of Core Security Technologies, the company not only offered security consulting services, but often was sub-contracted to do R+D for several security vendors. The first and most intellectually rewarding of such contracts came from Secure Networks Inc. (SNI), a Canadian start-up that was developing a network vulnerability scanner named Ballista Network Auditing System. Our contract work for SNI, plus a couple of local security consulting contracts, were largely responsible for the financial viability of Core in its early days and for that I will be always thankful to the SNI team.

Shorten URL: http://threatpost.com/en_us/cON. Click to copy to clipboard or post to Twitter

July 13, 2010, 1:46PM Threatpost Original

Pay Attention to MS10-042 Update

Microsoft has released four new security bulletins in the July 2010 edition of patch Tuesday. These bulletins address five vulnerabilities.

It is not uncommon, and has become expected, for a light patch Tuesday to follow a heavy patch Tuesday release from Microsoft.  Last month, Microsoft released a hefty load of patches with 10 security bulletins addressing 34 vulnerabilities.

Shorten URL: http://threatpost.com/en_us/cl6. Click to copy to clipboard or post to Twitter

July 9, 2010, 4:57AM Threatpost Original

The Rise of the Rogue AV Testers

By Costin Raiu

Recently, I was sitting around with a number of colleagues from Kaspersky Lab, discussing everybody’s favorite subject: the state of anti-virus testing these days. During the talks, somebody brought up the name of a new, obscure testing organization in the Far East. Nobody else had ever heard of them and so my colleague Aleks Gostev jokingly called them a “rogue Andreas Marx."

Shorten URL: http://threatpost.com/en_us/cqj. Click to copy to clipboard or post to Twitter

July 7, 2010, 9:46AM Threatpost Original

How to Own a Database With SQL Injection

By Alex Rothacker

SQL injection is the most common penetration technique employed by hackers to steal valuable information from corporate databases. Yet, as widespread as this method of attack is, a seemingly infinite number of ‘sub-methods,’ or variations of SQL Injection attacks can be carried out against the database.  

Shorten URL: http://threatpost.com/en_us/Ohb. Click to copy to clipboard or post to Twitter

July 6, 2010, 2:49PM

Why You Should Write Down Your Passwords

By Gunter Ollmann

Common wisdom over the last couple of decades has been to never write down the passwords you use for accessing networked services. But is now the time to begin writing them down? Threats are constantly evolving and perhaps it’s time to revisit one of the longest standing idioms of security – “never write a password down”.

Shorten URL: http://threatpost.com/en_us/OSF. Click to copy to clipboard or post to Twitter

June 30, 2010, 10:12AM Threatpost Original

Gaining Precision in Information Leakage Attacks

By Robert Hansen

It's hard to narrow down your life's work into one interesting event or tidbit. Even picking 10 would be tough. So instead of picking something I am well-known for, I wanted to look for something I had a lot of fun coming up with that you probably didn't read. I've always been interested in information leakage as an exploit class. It's something most people like to overlook, in favor of the higher-profile exploits. Sure, it's a lot sexier to go after the direct administrative compromise, but I enjoy the nuances of piecing together big puzzles. Information leakage as a class provides me that kind of mental stimulus.

Shorten URL: http://threatpost.com/en_us/OJl. Click to copy to clipboard or post to Twitter

June 15, 2010, 9:44AM

The Pitfalls of Website Vulnerability Research and Disclosure

By Chris Wysopal

Vulnerability disclosure is in the spotlight again. First it was Tavis Ormandy disclosing a vulnerability in Microsoft Windows before Microsoft had a fix available. Now a group called Goatse Security has disclosed a vulnerability in an AT&T website that affects Apple iPad 3G owners. The Wall Street Journal reports on the repercussions against vulnerability researchers in “Computer Experts Face Backlash”.

Shorten URL: http://threatpost.com/en_us/O67. Click to copy to clipboard or post to Twitter

June 10, 2010, 12:49PM

Does Google Have a Double Standard on Full Disclosure?

By Robert Hansen

Early this morning Google’s Tavis Ormandy published a vulnerability in the hcp protocol handler. It allows the attacker to run arbitrary commands as the user. In practice it created a lot of alerts and warnings for me - but the XP install I was using is somewhat locked down. So I’m not sure how practical this attack would be over any other attack that causes an alert, as the article mentions. Later his reports says it works around the alerts (I couldn’t reproduce that, but that was his intention). Either way, though, this is some pretty amazing research. However, there are some odd things about this that really struck me the wrong way.

Shorten URL: http://threatpost.com/en_us/OHl. Click to copy to clipboard or post to Twitter

June 3, 2010, 11:47AM Threatpost Original

With the Database, Sometimes it's the Little Things That Matter

Guest editorial by Alex Rothacker

 Most users are aware of the risks connected to the default, blank and weak username/password combinations associated with most applications. Yet it amazes the research community that many companies still don’t heed the following simple advice:

1) Don’t use easily guessed passwords. 2) Change the default credentials that ship with your apps, and 3) Please do not just leave the passwords blank! 

Shorten URL: http://threatpost.com/en_us/O7C. Click to copy to clipboard or post to Twitter

 

Copyright © 2010 threatpost.com | Terms of Service | Privacy