Skip to content
The Grumpy Security Guy

Opinions about security you did not ask for

FBI CSRF and Jail How to Get Someone Raided

  • Post author:
  • Post published:April 8, 2008
  • Post category:Uncategorized

This seems pretty scary. Apparently the FBI posted a link on some online forum that claimed to display illegal content. Upon reading this the first thing that popped into my…

Continue ReadingFBI CSRF and Jail How to Get Someone Raided

Worst Security I Have Seen in a Long Time

  • Post author:
  • Post published:March 20, 2008
  • Post category:Uncategorized

When the clueless are on the internet this is what happens. I came across a site that had the most spectacularly bad security I have seen in a very long…

Continue ReadingWorst Security I Have Seen in a Long Time

What a Cyber Security Assessment Actually Involves (And What Vendors Won’t Tell You)

  • Post author:
  • Post published:March 15, 2008
  • Post category:Industry

I have sat through more cyber security assessment sales pitches than I care to count, and they all follow the same pattern. A vendor in a nice suit shows up…

Continue ReadingWhat a Cyber Security Assessment Actually Involves (And What Vendors Won’t Tell You)

The Big Announcement

  • Post author:
  • Post published:March 10, 2008
  • Post category:Uncategorized

I have not been this pumped about something in a long time. Jeremiah actually has been pulling me into liking this idea for a very long time. I hated it…

Continue ReadingThe Big Announcement

HP Corners the Market on Hackers

  • Post author:
  • Post published:February 14, 2008
  • Post category:Uncategorized

I thought this was a pretty funny quote from an article about HP: Nine out of the world's top 11 security hackers came to HP through the SPI Dynamics acquisition,…

Continue ReadingHP Corners the Market on Hackers

ScanAlert – XSS is Cool with Us

  • Post author:
  • Post published:January 15, 2008
  • Post category:Uncategorized

Sometimes I just want to give up. I really hate XSS because it is really a tricky issue to explain to people that do not understand. It basically boils down…

Continue ReadingScanAlert – XSS is Cool with Us

PCI Security: 2007 Was the Worst Year

  • Post author:
  • Post published:January 10, 2008
  • Post category:PCI

The Payment Card Industry Data Security Standard was supposed to fix credit card security. After 2007, I think it is fair to say it has not. TJX lost 45 million…

Continue ReadingPCI Security: 2007 Was the Worst Year

Top 10 Security Stories of 2007

  • Post author:
  • Post published:January 9, 2008
  • Post category:Industry

Another year, another collection of security disasters. Here are my picks for the top 10 security stories of 2007, in no particular order because they are all depressing. 1. TJX…

Continue ReadingTop 10 Security Stories of 2007

Source Code Scanning is Dead

  • Post author:
  • Post published:December 24, 2007
  • Post category:Rants

I am going to make a bold statement: automated source code scanning as a primary application security strategy is dead. It just does not know it yet. Before the vendor…

Continue ReadingSource Code Scanning is Dead

Penetration Test vs Assessment

  • Post author:
  • Post published:December 22, 2007
  • Post category:Industry

I cannot tell you how many times I have seen someone confuse a vulnerability assessment with a penetration test. They are not the same thing. Not even close. And yet…

Continue ReadingPenetration Test vs Assessment
  • Go to the previous page
  • 1
  • 2

Recent Posts

  • The Tabletop Exercise Everyone Passed
  • Compliant Is Not Secure, and It Never Was
  • Every Defense You Buy Comes With an Off Switch
  • Top 10 “Underground” Security Resources
  • Firewall Management Tools: What to Look For

Recent Comments

No comments to show.
Copyright - WordPress Theme by OceanWP