How to install an SSH Server in Windows Server 2008

Wednesday, July 23rd, 2008

SSH is the secure shell, a standard defined in RFC 4251. It is a network protocol that opens up a secure channel between two devices using TCP port 22. This channel can also be used for SFTP and SCP (secure FTP and secure copy, respectively). To make this work, you ...

FWAuto v1.1 - Firewall Auditing & Ruleset Analyzer Tool

Monday, July 14th, 2008

FWAuto (Firewall Rulebase Automation) is a Perl script and should work on any system with Perl installed. Provide the running config of a PIX firewall to fwauto. It will analyze and give you a list of weak rules in your rule base and store the result in multiple output files. Maybe ...

Massive DNS security problem endangers the internet

Wednesday, July 9th, 2008

US-CERT and other security experts have warned of a critical design problem affecting all DNS implementations. The Domain Name Service is responsible for converting readable names like www.heise-online.co.uk into the IP addresses that computers can handle, such as 193.99.144.85. DNS is thus the internet equivalent to a phonebook and without ...

IP traffic to ‘double’ every two years

Wednesday, June 18th, 2008

Web traffic volumes will almost double every two years from 2007 to 2012, driven by video and web 2.0 applications, according to a report from Cisco Systems. Increased use of video and social networking has created what Cisco calls 'visual networking', which is raising traffic volumes at a compound annual growth ...

Cisco IOS Rootkit Demonstrated

Tuesday, May 27th, 2008

Last Thursday at the EUSecwest conference, security researcher Sebastian Muniz of Core Security Technologies demonstrated a proof-of-concept rootkit for Cisco's IOS router operating system.A root kit consists of one or several related applications designed to give the program user root or administrator privileges on a given computer, whether or not ...

Cisco alums readying firewall killer

Monday, May 19th, 2008

Five former Cisco engineers have co-founded a start-up called Rohati Systems whose products take dead aim at traditional perimeter firewalls. A traditional firewall and its access control lists "is not capable of doing its job today from an access-control perspective," says CEO and President Shane Buckley. "Nowadays, your ...

Hacker writes rootkit for Cisco’s routers

Thursday, May 15th, 2008

A security researcher has developed malicious rootkit software for Cisco's routers, a development that has placed increasing scrutiny on the routers that carry the majority of the Internet's traffic. Sebastian Muniz, a researcher with Core Security Technologies, developed the software, which he will unveil on May 22 at the ...

ISPs accused of tampering with web pages

Wednesday, April 16th, 2008

About one percent of the Internet web pages are being changed in transit, sometimes in a harmful way, according to researchers at the University of Washington. In a paper, set to be delivered Wednesday, the researchers document some troubling practices. In July and August they tested data sent to about 50,000 ...

Researchers uncover undetectable chip hack

Wednesday, April 16th, 2008

For years, hackers have focused on finding bugs in computer software that give them unauthorised access to computer systems, but now there's another way to break in: hack the microprocessor. Researchers at the University of Illinois at Urbana-Champaign demonstrated how they altered a computer chip to grant attackers back-door access to ...

PayPal Outlines Strategy to Slow Phishing

Tuesday, April 15th, 2008

Over the last few years, security researchers have estimated that fake messages from PayPal and its parent company, eBay, make up more than half of all the spam sent over the Internet. So why, you may ask, isn't PayPal doing something about it? Last week at the RSA 2008 conference ...