Last updated:
Fri Nov 20 23:28:21 2009 GMT
  2008 FIRST Annual Conference in Japan - Register now


Blogroll
Security Manifest
Static in the Ether
malwarecrawler.com
McAfee Avert Labs
Infothought
Computing Research Policy Blog
darren_moffat@blog$ cat /dev/mem | grep /dev/urandom
OSSEC Blog
PandaLabs
Rick Kingslan - Will Hack 4 Food
Vulnerability Analysis Blog
Larry's Insecurity Blog
Vodun.org
Larry Osterman's WebLog : Security
A Day in the Life of an Information Security Investigator
CyberSpeak's Podcast
Schneier on Security
The Security Skeptic
Wired: Threat Level
b l o g _ m a x i m u m
Attack Research
Freedom to Tinker
Abner Stories
ADD / XOR / ROL
Cynical Security
Ivan
Jim's Bloggyness
Mark O'Neill's Radio Weblog
Norwegian Honeynet Project
Security Blanket
@CyberForge
The Evil Empire
Usable Security
OSVDB Blog
Michael Howard's Web Log
darren_moffat@blog$ cat /dev/mem | grep /dev/urandom
torsten's .NET blog - Security
Tenable Network Security
.NET Security Blog
CERIAS Blog
The Security Mentor
Federated Infrastructure : Security
BlogInfoSec.com
TaoSecurity
The WiFi Zone
antlab
Educated Guesswork
Sorry! We couldn't find your document
Dancho Danchev's Blog - Mind Streams of Information Security Knowledge
Sunbelt Blog
TrendLabs | Malware Blog - by Trend Micro
CyberCrime & Doing Time
Vastly Important Notes
KyleM.xwell
RedTeam
Speaking of Security, the RSA Blog and Podcast
LuFG Summerschool Applied IT Security
GPL
Fred Avolio's Musings
Arun Perinkolam's Weblog
websecurityblog
Essential Computer Security
MVP Jubo Security Blog
Page Not Found - ASP.NET Weblogs
Information Security News Desk
Esphion
Casper Dik's Weblog
Small Business Server
InfoWorld Gripe Line | Ed Foster
Kim Cameron's Identity Weblog
Sergey Simakov blog
Solution Accelerators - Security & Compliance
HD DVD / Randomness... : Security
IBM Internet Security Systems Frequency X Blog
George Ou
honeyblog
SophosLabs blog
Latest Blog Entires From WebSense Security Labs
Inliniac
Security Response Weblog
StillSecure, After All These Years
New Directions in Security (Comments)
John Palfrey
About Internet / Network Security
Errata Security
Stupid Security
ModSecurity Blog
Internet Insecurity
Daemon on Security
Service Provider Journal
www.rootkit.com
National Cyber Security - Blogs
Security Blog
The X Dot Com Inc. - 404 Wrong Page
Adobe Product Security Incident Response Team (PSIRT)
Will Cox: Security
Logblog
Phil Windley's Technometria
Volatile Systems
DISOG
You Know What's Stupid? Everything I Don't Understand
The ICSI Networking Group Blog
SYN|ACK
Casper Dik's Weblog
securosis.com
Information Manager Journal
worm blog
Kaspersky Lab Weblog
Fermats Security Alerts
MZL & Novatech Traffic & Bandwidth Statistics News
Kimberly L. Tripp: Improving *my* SQL skills through your questions! - Security
taint.org: Justin Mason's Weblog
The Microsoft Security Response Center Blog
Michael Howard's Web Log : Security
Information Security News Desk
Fixing Email Weblog
mcwresearch.com
Latest Analysis for All Threats
REblog
Security
DoxPara Research
The Security Development Lifecycle
Network Security
Page Not Found - ASP.NET Weblogs
::PepperTech:: Security Management News Blog
Vitalsecurity.org - A Revolution is the Solution
GnuPG.org
Greyhat of the World Unite...
weblog.cemper.com - Technology, Software Development, Project Management, Marketing News
Harry Waldron - Microsoft MVP Blog
The Day Before Zero
Anil John - Security
Caffeinated Security
Alert Logic
OpenPacket Blog
Mal-Aware.org
Burton Group Page Not Found
An Information Security Place
Andrew Carpenter
In-Security : Exploring Internet, Information and Infrastructure Security
netstat -a
Security Garden
Cheap Hack
Emergent Chaos
Security Fix
NetSec
bIPlog
Errata Security
Latest Blog Entires From WebSense Security Labs
Bill Sommerfeld's Weblog
Volatility
Spire Security Viewpoint
Windows Shell/User (MSN & OneCare Too)
Thomas Shinder Blog
Digital ID World Editors Corner
: 404 Not Found
The Antivirus Guy Blog
Spam Filtering Techniques
Page Not Found - ASP.NET Weblogs
Anton Chuvakin, O'Reilly Network
Crypto-World - news
Deb Shinder's MVP Blog
Security Notes
The Security Blanket
Page Not Found - ASP.NET Weblogs
Information Research
nzight
Napsterization
Glenn Brunette's Security Weblog
-- Sleeve notes of a sysadmin --
MoMusings@Arachnid.homeip.net
Infosec Events
Xavier's Security Post
Security Soapbox
ThreatFire Research Blog
SecuriTeam Blogs
whattheflex
Sorry! We couldn't find your document
turnipsecurity
Politically Motivated Computer Crime and Hacktivism
Pinpoint Labs Blog
Infosec Writers Latest Security Papers
The Dark Visitor
Fabulous Adventures In Coding : Security
Lasipalatsi
Technology Review Feed - TR Editors' Blog
BufferOverrun : Security
Carnal0wnage Blog
When {Puffy} Meets ^RedDevil^
Andreas Sterbenz's Blog
C.I.S.R.T.
BenEdelman.org
Kasun's Weblog
Roger's Information Security Blog
Windows Incident Response
Windows Security Logging and Other Esoterica
-- Sleeve notes of a sysadmin --
The Importance of...
Verizonbusiness.com
Larry Seltzer's Security Weblog
Sorry! We couldn't find your document
The Security Mentor
CERIAS Weblogs
Security and Technology for SMB's and SOHO's
MSDN: Security
Security Curve Weblog
Internet Security with Kirk
trimMail's Email Battles
blackhat for life
Nth world commentaries
1 Raindrop
Dana Epp's ramblings at the Sanctuary
Wendy's Blog: Legal Tags
Page Not Found - ASP.NET Weblogs
Lauren Weinstein's Blog
Steve Lamb's Blog : How to Articles
Page Not Found - ASP.NET Weblogs
Bkis Blog
Security Sauce
NI3
Aaron Margosis' "Non-Admin" WebLog
chandanlog(3C)
The Security Skeptic
Tim Rains' WebLog
Page Not Found - ASP.NET Weblogs
Anti Rootkit Blog
Eugene Bobukh's WebLog
cybercrime/-security sightings
Security Watch
Panda Research Blog
ADD / XOR / ROL
Latests Alerts From Websense Security Labs
Roger Thompson
Error!
F-Secure Antivirus Research Weblog
infosec « WordPress.com Tag Feed
APB Infosec blog
Security Fix
Liudvikas Bukys
1 Raindrop
Bowulf Infosec & Network Admin Blog
Glenn Brunette's Security Weblog
Robert Hensing's Blog
Mark's Blog
Open-Node.net Security Weblog
Security to the Core | Arbor Networks Security Blog
Infosec Potpourri
Network Security Blog
Compendium
Sam Gentile
Hex blog
Cybercrime
e-Government@large
eEye Digital Security - Research Blog
Wifi Security Project
TheSecure.Net
Matasano Chargen
Solution Accelerators - Security & Compliance
Dan Anderson's Weblog
Financial Cryptography
Anti-Malware Engineering Team
invulnerableit.com Blog
CGISecurity.com: Your Web Site and Application Security Resource
A Bro Blog
Paul's Down-Home Page: Exchange, messaging, collaboration, security, and more
Internet Security News and Analysis
404 - Not Found
-- Sleeve notes of a sysadmin --
Realtime Community | IT Compliance
Martin Englund's Weblog
Network Security Blog
fes' WebLog
Draft Security Blog
disLEXia 3000 blog
November 20, 2009


MPAA Says Copyright-Treaty Critics Hate Hollywood
Wired: Threat Level

If you don’t back a copyright treaty being negotiated in secret, you must want to destroy Hollywood, its blockbuster movies and all the jobs they create. At least that’s the message from the Motion Picture Association of America. It’s sp


Prosecutors Drop Plans to Appeal Lori Drew Case
Wired: Threat Level

Federal prosecutors in Los Angeles have filed a notice that they do not intend to pursue an appeal in the Lori Drew cyberbullying case, thus ending the controversial and lengthy case. “We have a notice with the 9th Circuit that we are withdrawing ou


Explaining the Air Traffic Breakdown
Technology Review Feed - TR Editors' Blog

It wasn't the fault of a creaky old radar system, but of high-tech flight-monitoring computers.


Curse of the Were-Laptop
Speaking of Security, the RSA Blog and Podcast

Richmond, Virginia - Sunday 8:00 PM ET

The storm outside sent wave after wave of heavy rain drops that banged on the large window, trickling down into the garden bushes below. Distant thunderc


Hacker exposes global warming researcher
Errata Security


Firefox Vulnerabilities: Souvenirs of Windows 95
CERIAS Weblogs


Black(hat) Friday
PandaLabs

If you plan on shopping online for "Black Friday", or "Cyber Monday", you might be in for more than you bargained for. Cyber criminals behind the Rogueware epidemic have their


Hacked E-Mails Fuel Global Warming Debate
Wired: Threat Level

An online debate over global warming science has broken out after an unknown hacker broke into the email server at a prominent, U.K. climate research center, stole more than a thousand e-mails about global warming research and posted them online. Global w


Alpha Software disclosure leads to confusion
Security Fix

A few days ago, Security Fix heard from a reader who received a breach notification so casual in tone that he asked me to verify whether it was for real.


Firefox Vulnerabilities: Souvenirs of Windows 95
CERIAS Weblogs


FailBlog on Security
Schneier on Security

Funny: career fair fail.


Interview with Me
Schneier on Security

Yet another interview with me. This one is audio, and was conducted in Rotterdam in October.


Alpha Software disclosure leads to confusion
Security Fix

A few days ago, Security Fix heard from a reader who received a breach notification so casual in tone that he asked me to verify whether it was for real. Sure enough, Burlington, Mass.-based database application company Alpha Software Inc. recently told c


None
None


Forefront TMG RTM Overview Interview
Thomas Shinder Blog

With the RTM of Forefront Threat Management Gateway (TMG), David Cross tells us about what's new and gives some real-world examples of how Microsoft IT has benefited from TMG over ISA 2006.  He also discusses the following: Why TMG only utilizes Mi


BranchCache and TMG Interoperability
Thomas Shinder Blog

There are two main scenarios for the interoperability of Forefront TMG and BranchCache: Forefront TMG and BranchCache are deployed on the same host. For a description of this scenario, see Forefront TMG and BranchCache Hosted Cache deployed on the same h


Hex-Rays Plugin Contest
Hex blog

We are glad to announce the results of our first plugin contest! For the contest rules, please check this page:

http://www.hex-rays.com/contest.shtml

Or you may directly go to the contes


Curiosity as a Malicious PDF
McAfee Avert Labs

What would you do if you saw in your inbox, an email with a PDF named, U.S. ship thwarts second pirate attack November 18, 2009.pdf? Would the title pique your curiosity? Hopefully not enough for you open the document! The PDF is the latest in the ugly li


COFEE Break Turns Messy
McAfee Avert Labs

A common challenge of cybercrime investigations is the need to conduct forensic analysis on a computer before it is powered down and restarted. As some active system processes and network data are volatile and may be lost after the computer is turning off


Contrarianism on Sequoia's Disclosed Source Voting System
Educated Guesswork


Secure Audit Logging Class
1 Raindrop

Yesterday, I debuted a new software security training class on Secure Audit Logging, this is a class aimed developers, architects and security people. There are a lot of products out there that help enterprises manage logs for PCI compliance and such, but


Denial-of-Service Attack Against CALEA
Schneier on Security

Interesting:

The researchers say they've found a vulnerability in U.S. law enforcement wiretaps, if only theoretical, that would allow a surveillance target to thwart the aut


RedTeam@TV: Dangerous Online Banking
RedTeam

RedTeam is on TV again: Sunday, 22. November 2009, SAT1 Planetopia: Gefhrliches Onlinebanking (Dangerous Online Banking) Online banking is still a hot topic, with all the new systems cropping up after the traditional PIN/TAN and the more recent PIN/iTAN (


Learn: Windows 7 Multi-Touch Overview
MSDN: Security

Watch Reed Townsend and Yochay Kiriaty as they explore multi-touch in Windows 7. They will cover basic out-of-the-box support for legacy applications, as well as for applications optimized for multi-touch, and explain the "Good, Better, and Best" programm


Get the SQL Server 2008 R2 November CTP
MSDN: Security

SQL Server 2008 R2 delivers several breakthrough capabilities that will enable your organization to scale database operations with confidence, improve IT and developer efficiency, and enable highly scalable and well-managed business intelligence on a self


Job Spam Uses Twitter
TrendLabs | Malware Blog - by Trend Micro

TrendLabs researchers were alerted to the discovery of spammed messages thatcontained Twitter URLs.The spam uses subjects such as N3 Earn Extra Income! 7L, C2 Exrtra Income Daily 4P, and Q0 $$$ Oppurtunity 6O. It informs users about supposed work-from-hom

November 19, 2009


None
None

None


Introducing the InfoSec Assessment & Protection Suite
The Security Development Lifecycle

None


Feds Charge Three With Comcast.net Hijacking
Wired: Threat Level

Three alleged members of the hacker gang Kryogeniks were hit with a federal conspiracy charge Thursday for a 2008 stunt that replaced Comcast’s homepage with a shout-out to other hackers. Prosecutors identified Christopher Allen Lewis, 19, and Ja


A Molecular Machine in Action
Technology Review Feed - TR Editors' Blog

X-ray imaging reveals a motor-like biological protein at work.


FDA targets rogue Internet pharmacies
Security Fix

The U.S. Food and Drug Administration is pressuring a number of Internet service providers to shut off nearly 12 dozen Web sites alleged to be selling counterfeit or unapproved prescription drugs.

FDA targets rogue Internet pharmacies
Security Fix

The U.S. Food and Drug Administration is pressuring a number of Internet service providers to shut off nearly 12 dozen Web sites alleged to be selling counterfeit or unapproved prescription drugs. The FDA's office of criminal investigations said it sent 2


Copyright Czar Vote Heads to Full Senate
Wired: Threat Level

The Senate Judiciary Committee unanimously approved Victoria Espinel’s nomination Thursday, paving the way for a full Senate vote to confirm the nation’s first copyright czar. No Senate vote date was set immediately for a nominee who was appla


Health Insurer Loses 1.5 Million Patient Records
Wired: Threat Level

A health insurer lost 1.5 million patient records last May but waited six months to disclose the incident. The data, which was stored on a portable disk drive that disappeared from the insurer’s office, was unencrypted and included patient Social Se


Judge Calls Bull on Psycho-Acoustic Beatles Covers
Wired: Threat Level

A federal judge dealt what may be a death blow to a Santa Cruz company marketing Beatles music and other tunes as 25-cent downloads, despite the company’s claim that the tracks were computer-generated cover versions produced by a process called R


Koobface, new promises?
SophosLabs blog

Koobface started life compromising Twitter accounts. It then diversified to attack various social networking sites including Facebook, MySpace, Bebo, hi5, GeoCities, Friendster among the prominent ones. Recently I came across what could possibly be the ne


Chrome Browser Is Coming to Mac and Linux
Technology Review Feed - TR Editors' Blog

Google expects to make announcements before the end of the year.


A Taxonomy of Social Networking Data
Schneier on Security

At the Internet Governance Forum in Sharm El Sheikh this week, there was a conversation on social networking data. Someone made the point that there are several different types of data, and it would be useful to separate them. This is my taxonomy of


Computer Glitch Grounds Air Traffic
Wired: Threat Level

An unspecified computer glitch is being cited as the cause for commercial flights being canceled or temporarily delayed on Thursday. The glitch was related to a key Federal Aviation Administration flight-processing system, according to ABC News. The probl


UK Confused About Piracy
Emergent Chaos

According to BoingBoing, "Leaked UK government plan to create "Pirate Finder General" with power to appoint militias, create laws:" What that means is that an unelected official would have the power to do anything without Parliamentary oversight or debate


Health Care Providers to Self-Police Themselves on Privacy Harm
Logblog

In an article that hit the web this week, a new DHHS rule is purported to allow health care providers to determine if their privacy breaches have caused any harm. While I understand the nature of assigning the reporti


Malicious Java Applet attack surfaces as Carrie PreJean video
McAfee Avert Labs

McAfee has observed various spam runs exploiting the sensational Carrie Prejean news. The Carrie Prejean video is rapidly becoming one of the most searched topics on the net ever since the existence of the tape became common knowledge. Source: Google Tre


Stabbing People with Stuff You Can Get Through Airport Security
Schneier on Security

"Use of a pig model to demonstrate vulnerability of major neck vessels to inflicted trauma from common house


Call for Papers: CARO2010 Workshop
F-Secure Antivirus Research Weblog

F-Secure is organizing the next CARO Technical Workshop. It will be held in the end of May in Helsinki, Finland. Previous workshops have been in Iceland, The Netherlands and Hungary.

Call for Papers is open. We're looking for technical p


Sports Doping Drugs Available Online
Technology Review Feed - TR Editors' Blog

Drugs not yet approved for medical use are easily accessible online to cheating athletes.


Tomorrow's spam - today
Kaspersky Lab Weblog

None


Fake Blogs Lead to FAKEAV
TrendLabs | Malware Blog - by Trend Micro

Media reports have revealed the existence of fake blogs that were used to spread FAKEAV malware. The blogs do not actually contain any useful content. Instead, they have posts that contain nothing but images with post titles that use a wide variety of top


Deception in Post-Transaction Marketing
BenEdelman.org

Post-transaction marketers have attracted criticism for solicitations that tend to deceive consumers. Offers often promise a savings or discount while actually charging customers on an ongoing basis. Offers often appear while customers are finishing the


all content is copyright its respective owner or owners.

the technology behind infosec daily is partially copyright © 2003-2008 jose nazario.