Our Blog

reDuh reVisited…

We’ve had a number of issues with reDuh and the various server versions published. Some clients worked with some versions of the server, and didn’t play nicely with others. I am happy to say that these have all been resolved now. The single reDuhClient now works with JSP, ASPX and PHP versions of reDuh. Its been tested on a number of different platforms. Additionally, the new reDuh client supports some enhancements. These are: SSL…

Should InfoSec companies be betting on PCI ?

The United States committee on Homeland Security’s Subcommittee on Emerging Threats, Cybersecurity, and Science and Technology recently held a hearing to determine if “the Payment Card Industry Data Standards Reduce Cybercrime?” Risky Business played snippets of the hearing under the apt title: “Washington spanks PCI DSS” – Like most episodes of RB, its well worth the listen.. One of the “merchants” giving testimony made his point quite succinctly. The credit…

#include fakeNewsStory.h

what? on April 1st???? Never!

Ranum Reloaded..

A little while back i commented on Marcus Ranums HiTB talk “Cyberwar is Bullshit!“. I ended the post with the words “Ranum is indeed much better than this..“. Ranum spoke recently at Source Boston, and his talk [The Anatomy of Security Disasters] indeed shows this is true.. If you are in the industry to make a quick buck, or because it beats flipping burgers at McD’s, you probably dont need…

Hello World (With an LED)

Way back when i was a sysadmin, i recall reading a quote from one of the ATT greybeards who said something to the effect of “every competent sysadmin should be able to build his own network card”. Of course most of us have spent tons of time ripping apart electronics and “watching what happens when you connect X and Y”, but unlike the electronic engineers with their oh-so-cool multi-meters ive…

HBN Developer Edition Training

Hi All We have scheduled our first Developer course for April in Pretoria, should you know of anyone in your area that would like to attend. – Hacking by Numbers – Developer Edition (28-30th April) Information about the course: HBN – Developer Edition ‘Hacking By Numbers – Developer Edition’ is a course aimed at arming web application developers with knowledge of web application attack techniques currently being used in the…

!exploitable [Vuln finding freebie from MSFT]

Microsoft released !exploitable at CanSecWest this year. The debugger extension, and the accompanying slide deck can be found [here]. I have not looked at it, but a glance at the slides implies that they aim to solve the problem of too many dumps – not enough time.. Its pretty cool.. and that Microsoft is releasing this is even cooler..

Jack C. Louis: Jan 5, 1977 – March 14, 2009

Truly tragic. We are all poorer for it.. It really was an honor and a privilege to have known him..

Like deja-vu (all over again)

Those of you who were around in 2001 will recall http://anti.security.is (anti-sec f.a.q).. The sentiment pops up periodically (in different forms) and it seems like CansecWest this year has seen a resurgence of it.. From Charlie Millers comments on the Safari bug: “Did you consider reporting the vulnerability to Apple? I never give up free bugs. I have a new campaign. It’s called NO MORE FREE BUGS. Vulnerabilities have a…

Hack Like You Mean It – we’re taking PCI to Vegas

We’ve been busying ourselves with the PCI DSS in one way or another for more than a year now here at SensePost. Its been a frustrating exercise of mixed messages, politics, tokenism, mixed in with a healthy dose of mixed feelings about what the standard offers and whether that’s good for anyone at all. Now, finally, we’re accredited to do this that and the other under the standard so we…