CISCO IOS Rookits are da bomb

Filed under:Blogs — posted by Consultant on June 6, 2008 @ 9:20 am

Sebastian Muñiz also known as “topo” who worked hard on creating the first public IOS Rookit, which among several things is platform independent, has now created a blog named “Ret2Libc - REVERSE ENGINEERING AND RELATED”

He mentions a document disclosed by CISCO in response to his presentation on IOS rootkits (the one he also gave at EuSecWest 2008) which includes several security measures administrators can take to protect their routers.

Take a look at the blog right here: http://ret2libc.blogspot.com/

Later,

Voice of VOIPSA Blog - VOIP Security

Filed under:Blogs — posted by Consultant on January 3, 2008 @ 7:58 am

If you’re ever going to mess with Voice Over IP, then check out the following blog - it is all about VOIP Security.

http://voipsa.org/blog/

Just wanted to share that quick link - I’ll be writing something related to VOIP pentesting soon.

RSS syndicating content

Filed under:Blogs — posted by Consultant on October 12, 2007 @ 7:35 am

A couple days ago I discovered these wordpress plugins which are meant to grab any syndicated content published through  RSS (either using ATOM or other means) in Blogs and after grabbing the content, the plugins republish it in your own blog.

The first tool is called feedwordpress and can be found here:

http://projects.radgeek.com/feedwordpress/

There’s a whole discussion on how this is actually stealing content - given the increase in the amount of websites on the Internet these days, the only way of telling crappy from non-crappy sites is through actual “content”, which makes “borrowing” content a critical crime :)

Well there’s a whole purpose behind using these tools for “good” - I know they are very common in the porn industry where simple blogs created to do nothing but earn money need daily content and through these tools they can use the RSS feeds provided by the “affiliate companies” (the ones who pay the webmasters money per sale, recursive sale, whatever) to host new content every day.

Another tool that can be used for hosting remote content is also WP-o-matic:

http://devthought.com/wp-o-matic-the-wordpress-rss-agreggator/ 

I haven’t tried that one, the site looks nice tho’ :)

So where was I going.. oh, yeah - well there are plenty of blogs created by information security experts out there, plenty, and having a unique space where their content meets would be nice - not relying on stand alone RSS feed readers. But then again, I thought about it twice and decided to create my own posts referencing their content. That way I get to force myself into reading every single blog and getting the sweetest posts here.

Hope that makes sense.

Mark Curphey’s blog, a must read

Filed under:Blogs — posted by Consultant on @ 7:18 am

I don’t even know this guy - never had a verbal nor written word exchanged with him. Nevertheless, his blog is interesting and could be considered a must-read for someone in the information security industry. It sure looks like he has some years experience on penetration testing and participates in OWASP related meetings/events.

He recently joined the ACE Team, one of Microsoft’s security oriented teams where a series of known names have worked at in the past and several are currently working. It looks like the ACE Team is performing some heavy head hunting.

This guy is based in the UK and looks friendly, he is even inviting anyone in the UK to join him and his Bank friends for dinner & drinks in his “London Security Supper Club” post at,

http://securitybuddha.com/2007/09/26/london-security-supper-club/

So, again, I will probably be quoting this guy a few times through any future posts, but definitely add his posts to your RSS feed. The base url of his blog is:

http://www.securitybuddha.com/

Talk to you all later.



image: detail of installation by Bronwyn Lace