Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, February 16, 2009

Security Briefing Time

Posted on 1:06 PM by Unknown

image

cc photo credit DSCF3001 by joelogon on Flickr

From Briefing Time, a B-25J “Mitchell” bomber.

I love bomber nose art.  Couldn’t have asked for a more perfect find this time!

  • Overwriting can occur anytime, as long as it is done once after - SANS Computer Forensics, Investigation, and Response blog.  Continuing the discussion on hard-disk wiping efficacy; one time overwrite, whatever the source, is usually sufficient.

  • BackTrack 4 Beta released 2009 – LiveCD released by Remote-Exploit.org that is focused on pen-testing.  Really nice tool for security testers. Advanced tools and utilities.  Not for mere mortals!

  • Using RegRipper for malware detection – Windows Incident Response blog – Harlan really shows the benefits for sysadmins in being familiar with some forensic tools and techniques.  Being familiar with registry research can help pin down malware detection and infection studies.

  • The Trojan solved it! Catching a fraudster with another criminal, ‘myspacce.exe’ - SANS Computer Forensics, Investigation, and Response blog.  A really great study-read on how a malware infection gave away the subject of a forensics investigation.  Again, the focus here is picking up tips for system admins on malware knowledge and user activity. Also valuable in showing how alternative data streams of NTFS can be used in research as well as looking in the System Restore points for timing of activity.

  • More tricks from Conficker and VM detection – SANS ISC Handler’s Diary blog – This time the focus is on how malware can use changes to the Access Control Lists (ACL/Windows File Permissions) settings on a particular registry key to prevent everyone (including Administrators) from removing the key.  It also checks to see if it is running on a virtual machine.  All indications is that this is a pretty sophisticated and well written nasty.

  • Keeping Conficker / Downadup malware off your network in 2009 - Napera Networks – Great breakdown of important items to know about this malware and how to keep your systems clean.

  • Best defense against malware: Smarter users – Chron.com TechBlog – local Houston reminder why a/v software itself might not be the end-all solution.  Slow DAT file updates look like it bit the H-town city government in the rear.

  • Win32/Srizbi - Microsoft Malware Protection Center blog – Brief writeup of trojan dropper/rootkit that is targeted by the MSRT tool.  Some technical information on where to look for it in the file system and registry as well as how it works.  Good stuff.

  • IE8 Security Part VIII: SmartScreen Filter Release Candidate Update – IEBlog team details some improvements in the way their product will alert users to unsafe web-pages.  Nice design work and is similar to what Firefox 3.x is using for end-user notifications as well.  i hope we can deploy this at our workplace environment not long after it is released and tested on our internal web-site pages.

  • Exploit Shield 0.60 Beta - F-Secure Weblog – New version, now Vista compatible (32-bit at least) of a tool to provide various heuristics-based security protection.  Haven’t personally tried it out yet, but likely will be tossing it on a virtual machine system in the near future.

Cheers!

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in anti-virus software, security | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ▼  February (23)
      • Oscar watch Linkpost
      • File Recovery Extravaganza
      • Rx for Prescription Management
      • Macrium Reflect: free drive imaging software
      • Kurious Kaspersky Tweaker
      • GSD guest post at TUG blog
      • Wait, Wait, I know this one!
      • A Few Fix-It notes
      • Security Briefing Time
      • Windows FE – Details Teased out of the Web
      • Helix3: Thanks for the memories…
      • Laptop DC plug protection hack: Safety on the cheap!
      • Windows 7 News Roundup #7: SKU’s, UAC’s, and VHD’s
      • This week in security and forensics
      • Windows Goodies
      • More Browser Bits
      • Miscellaneous Hard Drive Security Links
      • Utility and Software Lookout
      • Custom Win PE Boot Disk Building: Step Four – Pull...
      • Custom Win PE Boot Disk Building: Start me Up!
      • Custom Win PE Boot Disk Building: Driver Dead Ends
      • Windows micro Linkfest
      • Internet Explorer 8 RC released: What to expect an...
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile