Cold Boot Encryption Attack – code release

Saturday, July 19th, 2008

Jacob Appelbaum, one of the security researchers who worked on the paper cold boot attack on encryption keys (featured in a previous BBtv episode, above) tells Boing Boing the code has just been released today at the [last] HOPE hacker con in NYC. It's up, it's signed, and here it ...

Reversing malware with oSpy

Friday, July 18th, 2008

Today's blog will be about a tool called oSpy, written by Andre Vadla Ravnas. oSpy is a tool which helps in reverse-engineering windows software. To demonstrate the uses of this tool and how it helps with network traffic monitoring, I have used a random malware sample from our repository. Source: http://securitylabs.websense.com/content/Blogs/3135.aspx

Researcher Offers Malware Analysis Tool

Friday, July 18th, 2008

The problem with hunting for malware is that most currently available analysis tools tip off the attacker that you're doing it. But at next month's Black Hat conference, a researcher will release a tool that is harder to detect -- and harder to avoid -- than the malware analyzers currently ...

YAMSIA (Yet Another Massive SQL Injection Attack)

Friday, July 18th, 2008

Clever mnemonics aside, last week we have seen another large scale SQL injection attack (or YAMSIA, if you prefer), this time being orchestrated by a botnet that has become known as Asprox—but first, a history lesson. The code behind the Asprox botnet seems to have been around for quite some time ...

New Worm Transcodes MP3s to Try to Infect PCs

Friday, July 18th, 2008

A new kind of malicious software could pose a danger to Windows users who download music files on peer-to-peer networks. The new malware inserts links to dangerous Web pages within ASF (Advanced Systems Format) media files. "The possibility of this has been known for a little while but this is the first ...