<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Daily Dave</title>
    <link>http://seclists.org/#dailydave</link>
    <atom:link href="http://seclists.org/rss/dailydave.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
    <pubDate>Fri, 20 Nov 2009 03:45:03 GMT</pubDate>
    <lastBuildDate>Fri, 20 Nov 2009 03:45:03 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Fedora 12 Fail</title>
    <link>http://seclists.org/dailydave/2009/q4/49</link>
    <description>&lt;p&gt;Posted by Kees Cook on Nov 19&lt;/p&gt;I've seen variations on this sentence get repeated in a few places and I&lt;br&gt;
think it's valuable to point out it should read as &amp;quot;Any _local_ user...&amp;quot;&lt;br&gt;
(where &amp;quot;local&amp;quot; is defined by console-kit[1] -- see &amp;quot;ck-list-sessions&amp;quot;&lt;br&gt;
command).  This makes it a smaller scope of problem, but it should not&lt;br&gt;
discourage anyone from reading the bug report anyway:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=534047&quot;&gt;https://bugzilla.redhat.com/show_bug.cgi?id=534047&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
-Kees&lt;br&gt;
&lt;br&gt;
[1]...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 03:33:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/49</guid>
  </item>


  <item>
    <title>Re: Fedora 12 Fail</title>
    <link>http://seclists.org/dailydave/2009/q4/48</link>
    <description>&lt;p&gt;Posted by dan on Nov 19&lt;/p&gt;Michael Graham writes:&lt;br&gt;
-+--------------------&lt;br&gt;
 | &amp;quot;I don't particularly care how UNIX has always worked.&amp;quot; has already&lt;br&gt;
 | turned into a new catchphrase around here.&lt;br&gt;
 | &lt;br&gt;
&lt;br&gt;
Those who do not understand UNIX are condemned to reinvent it, poorly. &lt;br&gt;
&lt;br&gt;
    -- Henry Spencer, 1987&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 19:28:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/48</guid>
  </item>
  <item>
    <title>Re: Fedora 12 Fail</title>
    <link>http://seclists.org/dailydave/2009/q4/47</link>
    <description>&lt;p&gt;Posted by Michael Graham on Nov 18&lt;/p&gt;&amp;quot;I don't particularly care how UNIX has always worked.&amp;quot; has already&lt;br&gt;
turned into a new catchphrase around here.&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 07:42:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/47</guid>
  </item>
  <item>
    <title>Fedora 12 Fail</title>
    <link>http://seclists.org/dailydave/2009/q4/46</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Nov 18&lt;/p&gt;Probably the best Linux thread in months:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://www.redhat.com/archives/fedora-devel-list/2009-November/msg00945.html&quot;&gt;https://www.redhat.com/archives/fedora-devel-list/2009-November/msg00945.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
To sum it up, Fedora 12 is defaulting to &amp;quot;Any user can install any&lt;br&gt;
package from the repo and then exploit it to get root&amp;quot;. So like, if&lt;br&gt;
the repo signs something hilarious like &amp;quot;bob's vulnerable FTP&lt;br&gt;
server.rpm&amp;quot;, every Fedora 12 server is vulnerable. Unless you've&lt;br&gt;
uninstalled PolicyKit or something else...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 02:55:06 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/46</guid>
  </item>


  <item>
    <title>Re: &quot;We're in the top of the league.&quot;</title>
    <link>http://seclists.org/dailydave/2009/q4/45</link>
    <description>&lt;p&gt;Posted by Nate Lawson on Nov 13&lt;/p&gt;gold flake wrote:&lt;br&gt;
&lt;br&gt;
The government is just a very large company. They experience the same&lt;br&gt;
security problems as other big companies. I'm always annoyed to hear the&lt;br&gt;
&amp;quot;we're under cyber attack via cyber warfare using cyber malware&amp;quot;.&lt;br&gt;
&lt;br&gt;
Please... you're under attack just like any other big company with&lt;br&gt;
extremely valuable assets. You're not any more special than that. It's&lt;br&gt;
possible the IRS is more valuable a target than Joe Random sergeant's PC.&lt;br&gt;</description>
    <pubDate>Fri, 13 Nov 2009 15:50:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/45</guid>
  </item>


  <item>
    <title>Re: &quot;We're in the top of the league.&quot;</title>
    <link>http://seclists.org/dailydave/2009/q4/44</link>
    <description>&lt;p&gt;Posted by gold flake on Nov 12&lt;/p&gt;I am not from US and was for almost 10 years part of my government's&lt;br&gt;
cyber security setup.  I can vouch for the claims regarding &amp;quot;some&lt;br&gt;
foreign power&amp;quot;'s attacks.  These are systematic, planned and&lt;br&gt;
relentless attacks that we also faced.  The vector was spear phishing&lt;br&gt;
in most cases and the thumb drive method was used to propagate the&lt;br&gt;
malware to the internal segment.  The malware called home (mostly&lt;br&gt;
China) and downloaded backdoors,...&lt;br&gt;</description>
    <pubDate>Thu, 12 Nov 2009 21:15:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/44</guid>
  </item>
  <item>
    <title>Re: &quot;We're in the top of the league.&quot;</title>
    <link>http://seclists.org/dailydave/2009/q4/43</link>
    <description>&lt;p&gt;Posted by Richard Bejtlich on Nov 12&lt;/p&gt;Aaron and everyone,&lt;br&gt;
&lt;br&gt;
If anyone has doubts, or just wants to read some excellent&lt;br&gt;
unclassified reporting on advanced persistent threat, please check out&lt;br&gt;
this report by Northrop Grumman:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://taosecurity.blogspot.com/2009/10/report-on-chinese-government-sponsored.html&quot;&gt;http://taosecurity.blogspot.com/2009/10/report-on-chinese-government-sponsored.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Sincerely,&lt;br&gt;
&lt;br&gt;
Richard&lt;br&gt;</description>
    <pubDate>Thu, 12 Nov 2009 20:41:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/43</guid>
  </item>


  <item>
    <title>Re: &quot;We're in the top of the league.&quot;</title>
    <link>http://seclists.org/dailydave/2009/q4/42</link>
    <description>&lt;p&gt;Posted by Dobbins, Roland on Nov 09&lt;/p&gt;Here's a pretty accurate assessment of the 60 Minutes story, IMHO:&lt;br&gt;
&lt;br&gt;
&amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://erratasec.blogspot.com/2009/11/brazil-outage-not-caused-by-hackers.html&quot;&gt;http://erratasec.blogspot.com/2009/11/brazil-outage-not-caused-by-hackers.html&lt;/a&gt; &lt;br&gt;
 &amp;gt;&lt;br&gt;
&lt;br&gt;
-----------------------------------------------------------------------&lt;br&gt;
Roland Dobbins &amp;lt;rdobbins () arbor net&amp;gt; // &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.arbornetworks.com&quot;&gt;http://www.arbornetworks.com&lt;/a&gt;&amp;gt;&lt;br&gt;
&lt;br&gt;
     Injustice is relatively easy to bear; what stings is justice.&lt;br&gt;
&lt;br&gt;
                         -- H.L. Mencken&lt;br&gt;</description>
    <pubDate>Tue, 10 Nov 2009 03:10:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/42</guid>
  </item>


  <item>
    <title>a brief interlude between exploits</title>
    <link>http://seclists.org/dailydave/2009/q4/41</link>
    <description>&lt;p&gt;Posted by dave on Nov 09&lt;/p&gt;There's been a lot happening in the world, and usually everyone is too&lt;br&gt;
busy to comment on it. Exploit devs sometimes think of the world as the&lt;br&gt;
dark troughs in a storm ocean, where the peaks are the sudden insights&lt;br&gt;
of truth provided by a really good exploit, where all of a sudden you&lt;br&gt;
can see for miles. Or maybe I just made all that up. In any case:&lt;br&gt;
&lt;br&gt;
CBS says that someone turned off Brazilian power using cyber attack:...&lt;br&gt;</description>
    <pubDate>Mon, 09 Nov 2009 19:40:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/41</guid>
  </item>
  <item>
    <title>&quot;We're in the top of the league.&quot;</title>
    <link>http://seclists.org/dailydave/2009/q4/40</link>
    <description>&lt;p&gt;Posted by Aaron on Nov 09&lt;/p&gt;Anyone else catch the 60-minutes story about Cyber warfare? There are a lot of interesting anecdotes from Admiral Mike &lt;br&gt;
McConnell (described in the story as the former top spy of the nation), Jim Lewis (director of the Center for Strategic &lt;br&gt;
and International Studies), and Jim Gosler.&lt;br&gt;
&lt;br&gt;
Some of the more WTF things admitted were:&lt;br&gt;
 - &amp;quot;Some foreign power&amp;quot; was able to penetrate the Pentagon by leaving infected thumbnail drives where military...&lt;br&gt;</description>
    <pubDate>Mon, 09 Nov 2009 18:57:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/40</guid>
  </item>


  <item>
    <title>MITM Attack on Smartphones whitepaper</title>
    <link>http://seclists.org/dailydave/2009/q4/39</link>
    <description>&lt;p&gt;Posted by Mayank Aggarwal on Nov 05&lt;/p&gt;SMobile has released a detailed report on research indicating that smartphone users are just as susceptible to &lt;br&gt;
man-in-the-middle (MITM) attacks as PC users. This report details the results of attempts to produce MITM attacks to &lt;br&gt;
determine whether it is possible to intercept SSL encrypted communications between various smartphone devices and &lt;br&gt;
servers. Of the devices that were tested, each of the major smartphone operating systems appeared to lack...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 01:54:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/39</guid>
  </item>


  <item>
    <title>Re: PrevX and other projects</title>
    <link>http://seclists.org/dailydave/2009/q4/38</link>
    <description>&lt;p&gt;Posted by Shane Macaulay on Oct 30&lt;/p&gt;The chart on their main page would be a lot more compelling if they had&lt;br&gt;
conversely applied whatever method they used to collect that information.&lt;br&gt;
&lt;br&gt;
&amp;quot;&amp;quot;&amp;quot;&amp;quot;These statistics are provided to show that all vendors miss threats&lt;br&gt;
and cannot be interpreted to compare the effectiveness of one product to&lt;br&gt;
another.&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&lt;br&gt;
&lt;br&gt;
That seems to indicate they would show us their failure rate when&lt;br&gt;
compared to these vendors?  And...&lt;br&gt;</description>
    <pubDate>Fri, 30 Oct 2009 12:06:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/38</guid>
  </item>


  <item>
    <title>PrevX and other projects</title>
    <link>http://seclists.org/dailydave/2009/q4/37</link>
    <description>&lt;p&gt;Posted by dave on Oct 28&lt;/p&gt;So you can read one Immunity deliverable linked here:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.prevx.com/&quot;&gt;http://www.prevx.com/&lt;/a&gt; (look for &amp;quot;Independent Review&amp;quot;).&lt;br&gt;
&lt;br&gt;
Likewise, if you have wondered where all the Immunity Debugger scripts&lt;br&gt;
ran off to, they were on the old Immunity Forum. We ripped the old forum&lt;br&gt;
content out of the old database and imported into the new hotness, so&lt;br&gt;
you can seem them all here:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://forum.immunityinc.com/&quot;&gt;https://forum.immunityinc.com/&lt;/a&gt;. I don't think Google spiders HTTPS sites&lt;br&gt;
for some reason...&lt;br&gt;</description>
    <pubDate>Wed, 28 Oct 2009 18:24:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/37</guid>
  </item>


  <item>
    <title>B. Aggressive. B. E. Aggressive. (or &quot;One 0day is	enough&quot;)</title>
    <link>http://seclists.org/dailydave/2009/q4/36</link>
    <description>&lt;p&gt;Posted by dave on Oct 27&lt;/p&gt;When you go into security consulting engagements with a new business&lt;br&gt;
unit you usually face a few questions from the developers and business&lt;br&gt;
owners. &amp;quot;What is it exactly that you're going to tell us?&amp;quot;&lt;br&gt;
&lt;br&gt;
We always answer this the same way: &amp;quot;Things that will surprise you.&amp;quot;&lt;br&gt;
&lt;br&gt;
Most developers have read a lot about security these days - they&lt;br&gt;
understand SQL Injection, Cross Site Scripting, access control, not to&lt;br&gt;
use their own...&lt;br&gt;</description>
    <pubDate>Tue, 27 Oct 2009 15:56:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/36</guid>
  </item>
  <item>
    <title>Last mile || InfoSys 2010 [ICAS, ICNS, INTENSIVE,	LMPCNA] March 7-13, 2010 - Cancun, Mexico</title>
    <link>http://seclists.org/dailydave/2009/q4/35</link>
    <description>&lt;p&gt;Posted by Jaime Lloret Mauri on Oct 26&lt;/p&gt;Last mile || InfoSys 2010 [ICAS, ICNS, INTENSIVE, LMPCNA] March 7-13, &lt;br&gt;
2010 - Cancun, Mexico&lt;br&gt;
&lt;br&gt;
INVITATION&lt;br&gt;
&lt;br&gt;
Note that we are entering the last few days of submission for the events &lt;br&gt;
collocated in Cancun, Mexico&lt;br&gt;
&lt;br&gt;
Please consider to contribute and encourage your team members and fellow &lt;br&gt;
scientists to contribute to the following federated events.&lt;br&gt;
&lt;br&gt;
The submission deadline has now been moved to November 1, 2009.&lt;br&gt;
&lt;br&gt;
Publisher: CPS ( see:...&lt;br&gt;</description>
    <pubDate>Tue, 27 Oct 2009 01:39:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/35</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
