Home Projects Pictures Books About PGP Key

DNS Flaw Details - Mirror

July 23rd, 2008 Anthony Towry

So, if you haven't seen the details for the DNS flaw you can take a look here: http://www.ri0tnet.net/dns.html

Check out the information leak of the year.  Oh, and patch those DNS servers.  WWDKD?

Posted in Uncategorized | No Comments »

Defcon 16 Speakers List Finalized

June 28th, 2008 Anthony Towry

Defcon 16 Logo This year's Defcon event is well under way. The speakers list has been finalized and I'm already thinking about what talks I want to make it out to.

Here's my hit list so far, which I'm guessing will get totally screwed by the time slots.

  • MetaPost-Exploitation : Valsmith and Colin Ames
  • VulnCatcher: Fun with Vtrace and Programmatic Debugging : atlas
  • Playing with Web Application Firewalls : Wendel Guglielmetti Henrique
  • Grendel-Scan: A new web application scanning tool : David Byrne and Eric Duprey
  • Wide World WAF's : Ben Feinstein
  • Advanced Software Armoring and Polymorphic Kung Fu : Nick Harbour

Additionally, the EFF and All Your Sploits Are Belong to Us panels might be fun.  Oh, and whatever Dan Kaminsky has to talk about will most certainly pack the house.

Posted in Uncategorized | No Comments »

Open Source Fuzzing Tools by Noam Rathaus and Gadi Evron

April 21st, 2008 Anthony Towry

Cover of Open Source Fuzzing Tools

This weekend I finished the Syngress Publishing book Open Source Fuzzing Tools. The book didn't take long. Part of the reason is that there really isn't a ton of technical information in the book to hold up the reader in lab exercise. It's not completely devoid of detailed fuzzer usage, but it's not wall to wall "let's go break some software" either. Read the rest of this entry »

Posted in Uncategorized | No Comments »

Race to Zero Contest @ DEFCON 16

April 20th, 2008 Anthony Towry

A new contest is making it's way to Defcon 16 this year. The contest titled "Race to Zero" is challenging reversers and malcode analysts to modify viruses and malware to see if they can't slip it by several scanning engines. The contest's website racetozero.net has tips on creating a proper participant environment for analyzing the beasties.

This looks like a very cool contest for taking a look at how malware is identified by popular scanning engines. I'm already getting stoked.

Posted in Uncategorized | No Comments »

Oklahoma Leaks Social Security Numbers

April 16th, 2008 Anthony Towry

A recent post to thedailywtf.com details a long running hole in an Oklahoma Department of Corrections web application. It appears that their Sexual and Violent Offender registry was wide open to SQL injection via a specially crafted query string.

Now, SQL injection can get pretty damn creative, but come on, this is 2008. There's no reason to be open to this class of vulnerability. Shouldn't we be past creating dynamic SQL queries? So let's say you're nutso bongo enough to be creating dynamic SQL, these guys aren't even making the attacker interact with the form to discover the hole. It's a security through obscurity thing for sure (and as such just one shade of crap less offensive), but being on the hit list by way of a Google dork is just sad.

Developers don't all have to be security experts, but an understanding of the OWASP top 10 isn't too much to ask. Get out there, parameterize those queries, sanitize input and make sure that data stays data and doesn't suddenly make the jump to code!

  • Bruce Schneier and his audience weigh in on the incident

Posted in Uncategorized | No Comments »

Is Podcasting Dead?

January 13th, 2008 Anthony Towry

InformationWeek's Alexander Wolfe asks that very question. The article goes on to say that podcasting hasn't lived up to the hype and that basically it's headed the way of the buffalo. Wolfe cites his reason based on podcasts not performing as big money makers.

In that regard, he'd probably be correct, but then the question becomes "Is making money indicative of the health of podcasting?" Which it is my opinion, clearly not.

Podcasting will advance along the same lines as other media (books, newspapers, etc.), which is the push for more localized and niche content. Pushing content for the most part isn't going to make a person rich, in fact, most producers would probably be thrilled to get a free beer now and then. That's cool though, that's really not all the reward that gets paid out.

Podcasting isn't even on the ropes really. If there's an issue at all, I think it's one of misguided expectations. Who the hell's fault is that? Read the rest of this entry »

Posted in Uncategorized | No Comments »

Linux Assembly Macros

November 17th, 2007 Anthony Towry

I recently started looking back into programming IA-32 ASM using nasm on Linux and came across a hell of a book written by a former professor at Carleton University in Ontario. What's peculiar about this book is that it spends a good 100 pages banging out hardware nuances to the reader, then as soon as you get going into some of the ASM stuff it provides the reader with a sweet macro file for the day-to-day coding. It's always interesting to see what certain instructors find important.

I've looked at Linux assembly before so a lot of what is contained in the macros isn't all that surprising, but I wonder if using the file from the beginning will make my prior knowledge jell-0 before the day's out.  Moreover, I wonder if it's going to hurt me when I start looking at what I care about (deadlistings of malware/sploits/etc.).

At any rate, I figure I'll give the late Prof. Dandamudi's way of learning a try. Check out his sweet macro file and other material here.

Posted in Uncategorized | No Comments »

Pirates Temporarily Stop Pillaging To Shine the Cannons

November 6th, 2007 Anthony Towry

Pirate Flag

The file sharing rockstars at thepiratebay.org have started up a project aimed at overhauling the Bittorrent p2p protocol. The project site, http://securep2p.com, is very much in the early stages, but is starting to show up in the media.

This is very cool for a couple of reasons. First, if anyone in p2p has a following it's thepiratebay. These guys could publish a recipe for chocolate chip cookies and people would download it. Second, this is an ambitious project in an area where we know there are tons of amateur/garage research designs being built. Maybe some really smart ideas will start showing up.

Lets hope this goes somewhere.

Posted in Uncategorized | 1 Comment »

Web Marketing Reality Show Launched

August 19th, 2007 Anthony Towry

I was goofing off today looking at some videocasts and generally killing time. I came across a reality show called "The Next Internet Millionaire". The show brings talented online marketers together and to have them fight it out in a no holds barred battle royale!

Alright, it's really not that good, but it's there if you're bored. Really, really bored.

 FollowUp :: If you want some real startup fueled coolness, watch Rockstartup.com 

Posted in Uncategorized | No Comments »

  • Recent Posts

    • New ProCheckUp ValidateRequest Bypass
    • Samurai Web Test Framework 0.1
    • Altering the Mac OS X Login Access Window Text
    • Summary on the State of Nmap
    • Android Security Team Says Hi
  • Archives

    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
    • November 2007
    • October 2007
    • September 2007
    • August 2007
    • July 2007
  • Categories

    • Art
    • Books
    • Community
    • conferences
    • Hardware
    • Management
    • Operating Systems
    • Podcast
    • Programming
    • Projects
    • Security
    • Site News
    • Software
    • Testing
    • Uncategorized
    • Web development
  • Blogroll

    • Defcon 405
    • ha.ckers.org
    • Halvar Flake
    • OSVDB Blog
    • phed.org
    • Scott Berkun’s Blog
  • Tags

    .Net ASP.NET Beta Books browser buffer overflow C Community Compliance Concept conferences Credit Cards dc405 defcon Development exploit Future fuzzing hacking Linux malware Management Metasploit Microsoft oklahoma Open Source osvdb OS X Patterns PCI Perl Podcast Programming protocols Ruby secure coding Security Silverlight SQL Server Testing tools vulnerabilities vulnerability WordPress xss

Calculated Decision has Joomla! under the hood!

Podcast Powered by podPress (v8.8)