Shmoocon 2008 videos are now online

Sunday, June 1st, 2008

The videos from ShmooCon 2008 have hit the shelves. Go download them at: http://www.shmoocon.org/2008/videos/ EDIT: As of the time of this post, some of the videos are incorrectly named. Here is the 1-> 1: Correctly Named: 21st Century Shellcode for Solaris Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to SPIKE land Backtrack ...

PstPassword Recovers Lost Outlook Passwords

Friday, May 30th, 2008

Windows only: When you dig up that old Outlook PST (Personal Folders) file from years ago you cleverly secured with a hard-to-guess password—and now you can't guess it—you want PstPassword. Turns out that Outlook passwords aren't that difficult to figure out, because this handy utility detects the PST's on your ...

Comcast Hijackers Say They Warned the Company First

Friday, May 30th, 2008

The computer attackers who took down Comcast's homepage and webmail service for over five hours Thursday say they didn't know what they were getting themselves into. In an hour-long telephone conference call with Threat Level, the hackers known as "Defiant" and "EBK" expressed astonishment over the attention their DNS hijacking has ...

Web 2.0 Sites a Thriving Marketplace for Malware

Friday, May 30th, 2008

A wiry young man with his head shaved and wearing a tank top points a handgun straight at the camera in a disturbing YouTube video. The man wears what appears to be a wedding ring, and he gazes vacantly away from the viewer. Though it's an odd image for an advertisement, ...

CSS exploit allows detection of social site use

Thursday, May 29th, 2008

Web developer Aza Raskin knows we visit Digg, Del.icio.us, Reddit and Facebook without even having to ask. No, he isn't employing privacy violating hackery, but he is exploiting a "cute" information leak in CSS that traditionally displays visited links differently than those that have yet to be visited. By loading in ...