Black

Valsmith and I took the stage at Black Hat yesterday to deliver a 150 minute presentation on what we call "Tactical Exploitation". The talk was aimed at penetration testers who find themselves limited in what they can exploit due to artificial constraints placed on their scope. The first half of the talk focused on lesser-known discovery and fingerprinting tools. Third-party services, such as DomainTools.com and the web interface to Paterva's Evolution product were discussed. The first half ended up with s read more »
addto Add this link to... report Bury 
http://www.internetnews.com/security/article.php/3728856By Sean Michael KernerInternetNews.comFebruary 19, 2008WASHINGTON, D.C. -- The name "Black Hat" for years has been synonymous with shadowy hacker activities. Many also know that the term refers to the popular annual security conference of the same name, long held in Sin City itself -- Las Vegas.This week, however, the Black Hats aren't flocking to Vegas. Instead, they're meeting in the heart of the federal government: Washington, D.C., a set read more »
addto Add this link to... report Bury 
p strong Researchers warn that the whack-a-mole approach to disabling fake banking sites is a huge waste of time. strong p ...Automate Software Builds with Visual Build Pro Easily create an automated, repeatable process for building and deploying software. read more »
addto Add this link to... report Bury 
http://www.informationweek.com/news/showArticle.jhtml?articleID=206800800By J. Nicholas HooverInformationWeekFebruary 20, 2008Security researchers presenting Wednesday at the Black Hat D.C. conference in Washington, D.C., demonstrated technology in development that they say will be able to greatly decrease the time and money required to decrypt, and therefore snoop on, phone and text message conversations taking place on GSM networks.Many mobile operators worldwide use GSM networks, including T-Mobile and read more »
addto Add this link to... report Bury 
'Instantly infect your favorite Fortune 500 company'Security researchers have uncovered a new web-based service containing security credentials for more than 8,700 websites belonging to Fortune 500 companies and government agencies. It allows miscreants to infect some of the internet's most popular destinations with a few clicks of the mouse.… read more »
addto Add this link to... report Bury 
U.S. Senator Chuck Grassley (R-Iowa) said that the White House isn't enforcing the H-1B program, and he cited a number of abuses to it in a letter released late Monday. Among the practices Grassley pointed to in his letter is the "leasing" of H-1B workers by contractors that don't have work for their foreign hires, as well as a number of court cases that point to a market for buying and selling fraudulently obtained visas. read more »
addto Add this link to... report Bury 
Forwarded from: jmoss <jmoss (at) blackhat.com>-----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256Dear past Black Hat attendee,Here is a big Black Hat update to keep inquiring minds up to date with allthe goings on in our not-so-secret lair:Black Hat Amsterdam is a go! Training: 25-26 March 2008 Briefings: 27-28 March 2008 There will be fourdifferent tracks over two days comprised of over 20+ internationallyrenowned security professionals speaking on diverse topics from interceptingGSM traffic and the evo read more »
addto Add this link to... report Bury 
A self-styled ethical hacker group plans to counter moves by companies that attempt to bury security vulnerability information in order to protect their businesses. read more »
addto Add this link to... report Bury 
http://www.pcworld.idg.com.au/index.php/id;1126249158By Jeremy Kirk IDG News Service31/03/2008 Spying programs for mobile phones are likely to grow in sophistication and stealth as the business around selling the tools grows, according to a mobile analyst at the Black Hat conference on Friday.Many of the spy programs on the market are powerful, but aren't very sophisticated code, said Jarno Niemela, a senior antivirus researchers for Finnish security vendor F-Secure, which makes security products for PCs a read more »
addto Add this link to... report Bury 
http://www.heise.de/english/newsticker/news/105717Heise Online31.03.2008At the Black Hat Security Conference [1] currently taking place in Amsterdam, researchers from the Zurich ETH (Swiss Federal Institute of Technology) have reported a new model for determining the security of operating systems. They don't just count the number of holes and how critical they are, but also determine what they call the zero-day patch rate. This indicates the ability of a vendor to make a patch available on the day a vulner read more »
addto Add this link to... report Bury 
Opera this week released a new version of the Web browser to correct at least two remotely exploitable security vulnerabilities. Separately, Microsoft said it plans to release eight updates on Tuesday as part of its regular monthly patch cycle. The latest version of Opera -- 9.27 -- is available at this link. More details on the vulnerabilities fixed are here and here. Microsoft said it most likely release eight updates, five of which will carry...Please click on the title to continue reading this entry. read more »
addto Add this link to... report Bury