FBI CSRF and Jail How to Get Someone Raided
This seems pretty scary. Apparently the FBI posted a link on some online forum that claimed to display illegal content. Upon reading this the first thing that popped into my…
This seems pretty scary. Apparently the FBI posted a link on some online forum that claimed to display illegal content. Upon reading this the first thing that popped into my…
When the clueless are on the internet this is what happens. I came across a site that had the most spectacularly bad security I have seen in a very long…
I have sat through more cyber security assessment sales pitches than I care to count, and they all follow the same pattern. A vendor in a nice suit shows up…
I have not been this pumped about something in a long time. Jeremiah actually has been pulling me into liking this idea for a very long time. I hated it…
I thought this was a pretty funny quote from an article about HP: Nine out of the world's top 11 security hackers came to HP through the SPI Dynamics acquisition,…
Sometimes I just want to give up. I really hate XSS because it is really a tricky issue to explain to people that do not understand. It basically boils down…
The Payment Card Industry Data Security Standard was supposed to fix credit card security. After 2007, I think it is fair to say it has not. TJX lost 45 million…
Another year, another collection of security disasters. Here are my picks for the top 10 security stories of 2007, in no particular order because they are all depressing. 1. TJX…
I am going to make a bold statement: automated source code scanning as a primary application security strategy is dead. It just does not know it yet. Before the vendor…
I cannot tell you how many times I have seen someone confuse a vulnerability assessment with a penetration test. They are not the same thing. Not even close. And yet…