Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Organizations/Events - Page 17

Discover Organizations/Events News

Analyzing Changes in Hacker Mindset and Perception at Defcon

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

When I first went to Defcon in 1995, the halls were mobbed with teenagers and attendees seemed more concerned with freeing Kevin Mitnick and seeing strippers than hacking each others' computers. Jump forward to Defcon 17 this year, which was held over the weekend in Las Vegas, things certainly have changed. The attendees are older and wiser and employed, most of the feds aren't in stealth mode, and even the most savvy of hackers is justifiably paranoid.

Security Experts' Private Data Exposed Before Black Hat Conference

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

On the eve of the Black Hat security conference, crackers published a comprehensive text document in the underground magazine Zero for Owned (ZF0), containing masses of emails, chat records, passwords and other private information belonging to famous members of the security industry. Evidently they captured the data by breaching the web servers of Kevin Mitnick, Dan Kaminsky and Julien Tinners. They boast of having captured 75,000 clear-text passwords this way, most of them from the databases of the forum systems running on the affected servers.

Global Gaming Factory X Acquisition Of The Pirate Bay Amid Copyright Issues

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Pirate Bay, a file-sharing site entangled in a court case over pirated music, will be bought by a Swedish software company. Global Gaming Factory X (GGF) announced the deal Tuesday. The company, which provides digital distribution tools for Internet cafes, will buy The Pirate Bay for cash and shares amounting to $7.76 million. The acquisition is expected to be completed in August.

Veiled: New Browser-Based Darknet for Secure Communication

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

A pair of researchers has discovered a way to use modern browsers to more easily build darknets -- those underground, private Internet communities where users can share content and ideas securely and anonymously. Billy Hoffman, manager for HP Security Labs at HP Software, and Matt Wood, senior security researcher in HP's Web Security Research Group, will demonstrate a proof-of-concept for Veiled, a new type of darknet, at the Black Hat USA conference in Las Vegas next month.

Essential Strategies For Winning Security Job Interviews

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The pickings are slim in the job market and the time line of interviewing and then hiring new people is slow. But there are positions available in the security field, according to three veteran security recruiters that we spoke with recently. If you're looking for a change in your career, or are simply looking to get back to work, there is simply no room for anything less than the best impression these days.

Cloud Security Alliance Overview on Cloud Computing Guidance

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Cloud Security Alliance (CSA) made its inaugural splash at last week's RSA Security Conference 2009 in San Francisco. The group kicked off an ambitious white paper that attempts to define everything from the architecture of cloud services to the impact of cloud services on litigation and encryption. It was a herculean effort to try to get this off the ground. And there is still much more work to do -- especially in the one area the group left out.This is a great article that talks about the problems of putting all your security eggs into one basket.

Exploring Full and Partial Disclosure in Security Research Practices

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This question was recently debated by a panel at SOURCE Boston. Has the security researcher community given up all hope of full disclosure that it has resigned itself to debating partial disclosure? And is partial disclosure the new responsible disclosure? Those are heady and polarizing questions; so much so that two hours of spirited sparring Thursday during a panel discussion at SOURCE Boston brought us no closer to answers. Personally I think partial disclosure is perfectly fine; it's much more effective to control a fire if there are already extinguishers on the premise. As long as Vendors can be trusted it is in everybody's best interest to give them advanced notification, so they can have patches ready on disclosure day. However, most of this discussion is just academic.

Exploring Web 2.0 Security Risks In Social Networking Environments

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

At LinuxWorld today, SPI Dynamic's senior security engineer, Matt Fisher, talked about the vulnerabilities of Web 2.0. One think that I found interesting about this article was when it talks about how users of social-networking can submit html code. We all know this is definitely a security risk that no one should allow to happen. How can these types of sites safely check the html code submitted from users? Are they protecting their users enough?

DefCon: NBC Dateline's Hacker Coverage Controversy and Its Implications

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This article presented is in defense of the NBC Dateline reporter and a different view of the matter at the recent DefCon. Ryan Naraine brings up valid points on why the actions of those in attendance at the conference could be considered 'childish' and 'over-the-top' and 'unnecessary'. He mentions key points of what the reporter Madigan did, specifically breaking the rules, as what the DefCon subculture is built upon. Read the actual article for a full alternative perspective. How do you feel about the actions taken against the NBC Dateline reporter?

Exploring the Role of Media Critique in Hacker Conference Culture

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

First thing's first - I'm extremely biased in favor of this type of article because I identify with the creative hacker. The media-slanted definition of 'hacker' does the title no justice for the innovative, out-of-the-box, dedicated minds of the world which make word processing programs or the 'Internets' easy for even the media to use. This article covers the general feel of both Blackhat and DefCon conferences with a nod towards the NBC Dateline incident.

Crucial Tips for Safely Navigating DefCon 2023 Experience

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Now that DefCon is upon all of us in an age where laptops flow free like wine, one still has to wonder - why would anyone jump on the "free public WiFi" offered at the event? It doesn't take a mastermind to sum up that 1. I'm at a hacker's conference, 2. I'm at a hacker's conference just teeming with BlackHats and 3. oh look, what's this "Wall of Sheep" I'm looking at? And why is my name on it??? Anyone wishing to attend the conference might want to take a quick review of this article just to make sure you won't be walking in with a huge bullseye over your forehead. If you do go, be sure to come back here and let us know of the best (and worst!) of DefCon by posting here!