Security Guru Gives Hackers a Taste of Their Own Medicine

Friday, April 11th, 2008

Malicious hackers beware: Computer security expert Joel Eriksson might already own your box. Eriksson, a researcher at the Swedish security firm Bitsec, uses reverse-engineering tools to find remotely exploitable security holes in hacking software. In particular, he targets the client-side applications intruders use to control Trojan horses from afar, finding vulnerabilities ...

How to Choose a Home PC Backup Method

Friday, April 11th, 2008

It's not only mission-critical business information that should be backed up. The data on your home PC needs to be backed up as well. But how should you choose between the traditional method of saving files on storage media yourself and a newer method of storing your data offsite with ...

The IronKey - World’s Most Secure Flash Drive

Thursday, April 10th, 2008

The IronKey, designed to be the world’s most secure flash drive, protects your data, online passwords, and Internet privacy. Now you can safely carry your digital life with you wherever you go—with confidence and peace of mind. While it uses advanced security technologies previously only available to government agents and ...

Biometric Hacking Tool Debuts

Wednesday, April 2nd, 2008

A British security researcher has demonstrated a "biologging" system for intercepting biometric authentication data, warning that attacks on biometric systems could become relatively straightforward if current practices don't change. Matthew Lewis, of London-based Information Risk Management, demonstrated a proof-of-concept biologger last week at Black Hat Amsterdam and released the tool's source ...

Session Hijacking in Windows Networks

Saturday, March 29th, 2008

I found a great write-up over at SANS that goes over session hijacking in amazing detail.  Click the link below to read the full 49-page white paper. Session Hijacking in Windows Networks

Guarding the guardians: A story of PGP key ring theft

Thursday, March 27th, 2008

A couple of weeks ago, we received a CHM, or Windows Help file, embedded in e-mail as part of a targeted attack campaign against an NGO. Virus detection was near zero. On Virustotal.com, two solutions actually flagged it as malicious. After decompiling the CHM file, which you can easily do using tools ...

New Technique Eases Encryption for Databases

Thursday, March 20th, 2008

Voltage Security offers to make deploying encryption at the database level less painful with a technique called Format-Preserving Encryption. Shocking the encryption market is not easy to do, but officials at Voltage Security must hope their new approach to encryption will do exactly that. The company's flagship SecureData product uses a cryptographic ...

Wi-Fu! Attacking the 802.11 Client

Monday, March 17th, 2008

Wi-Fu! More than just a statement, it reflects you wireless security skill set from knowledge and practical experience. This covers everything from using the tools out there to profile and attack your wireless network, to checking the security of your client devices yourself. If you feel your Wi-Foo is slipping, ...

TrueCrypt 5.1 Is Out

Tuesday, March 11th, 2008

TrueCrypt is a software system for establishing and maintaining an on-the-fly-encrypted volume (data storage device). On-the-fly encryption means that data are automatically encrypted or decrypted right before they are loaded or saved, without any user intervention. No data stored on an encrypted volume can be read (decrypted) without using the ...

What is fveNotify.exe in Windows Vista?

Saturday, March 8th, 2008

You may see a Startup entry called fveNotify.exe and not know what it's for because the description you see in the msconfig utility is not that clear.Here's the details:File Name: fveNotify.exe Display Name: Microsoft BitLocker Drive Encryption Notification Utility Description: BitLocker Drive Encryption Notification Utility Publisher: Microsoft Corporation Digitally Signed By: Microsoft Windows Verification ...