greebo.net
Vulnerabilities | cat slave diary
http://www.greebo.net/vulnerabilities
Mostly useless crap from me. I don’t publicly disclose the vulnerabilities I discover in course of client business. However, I do so for vulnerabilities I find by accident when I use systems. Leave a Reply Cancel reply. Your email address will not be published. Required fields are marked *. Notify me of follow-up comments by email. Notify me of new posts by email. Conferences and Travel (44). Life, the universe, and everything… (198). On Running Fortify SCA 3.80 on Ubuntu 12.04 64 bit Linux.
greebo.net
vanderaj | cat slave diary
http://www.greebo.net/author/vanderaj
Mostly useless crap from me. On backdoors and malicious code. December 18, 2015. So since the ASVS 3.0 retired much of the malicious code requirements, and after actually doing a line by line search of 20 kLOC of dense J2EE authentication code, I’ve been thinking about various methods that backdoors might be created and not be findable by both automated and line by line searches. This obviously has… Read More. Time to start rebuilding GaiaBB. July 19, 2015. Looking back at 2009 and Predictions for 2015.
greebo.net
Standing for the OWASP Board | cat slave diary
http://www.greebo.net/2014/08/15/standing-for-the-owasp-board
Mostly useless crap from me. Standing for the OWASP Board. August 15, 2014. I have formally submitted my name to be in the Board Elections 2014. I am standing for:. We need to create University level course (100, 200, 300) with the help of a university educator. I propose that we ask a range of universities to come to AppSec USA and start the process of formulating a curriculum, which once completed will become the default standard university curriculum for application security. I will expand on these po...
greebo.net
Some people don’t get the hint | cat slave diary
http://www.greebo.net/2014/09/30/some-people-dont-get-the-hint
Mostly useless crap from me. Some people don’t get the hint. September 30, 2014. 8525242.250 – – [28/Sep/2014:09:20:12 -0400] “GET / HTTP/1.1” 301 281 “-” “() { foo;};echo;/bin/cat /etc/passwd”. 8525242.250 – – [28/Sep/2014:22:30:48 -0400] “GET / HTTP/1.1” 500 178 “-” “() { foo;};echo;/bin/cat /etc/passwd”. Dear very stupid attacker, you have the opsec of a small kitten who is surprised by his own tail. Reported. Click to share on Twitter (Opens in new window). Share on Facebook (Opens in new window).
greebo.net
Looking back at 2009 and Predictions for 2015 | cat slave diary
http://www.greebo.net/2014/12/30/looking-back-at-2009-and-predictions-for-2015
Mostly useless crap from me. Looking back at 2009 and Predictions for 2015. December 30, 2014. I looked back at the “predictions” for 2010, a post I wrote five years ago, and found that besides the dramatic increase in mobile assessments this last year or two, the things I was banging on about in 2009 are still issues today:. Developer education is woeful. Agile security is woeful. Security conferences are still woeful. And SS7 insecurity (well, duh! If you’ve EVER done any telco stuff). Where ...Secure ...
greebo.net
cat slave diary | mostly useless crap from me | Page 2
http://www.greebo.net/page/2
Mostly useless crap from me. El Reg and the troubling case of climate denialism. July 17, 2013. This post is a last resort as I’ve had two comments rejected by the moderators at The Register, one of my favorite IT news websites. Lewis Page is a regular contributor to the Register. For whatever reason, around 50% of his total output there is (willful mis-) reporting on various papers and research on climate… Read More. April 17, 2013. Marketing – first against the wall when the revolution comes. Everythin...
greebo.net
Independence versus conflict of interest in security reviews | cat slave diary
http://www.greebo.net/2014/10/13/independence-versus-conflict-of-interest-in-security-reviews
Mostly useless crap from me. Independence versus conflict of interest in security reviews. October 13, 2014. I was giving a lecture to some soon to be graduating folks today, and at the end of the class, a student came up and said that he wasn’t allowed to work with auditors because “it was a conflict of interest”. No, it’s not. And here’s why. The only way the auditor is in a conflict of interest is if the auditor reviews code they wrote. This is self-review. Despite this, for independance reasons where...
greebo.net
So it’s finally happened | cat slave diary
http://www.greebo.net/2014/07/07/so-its-finally-happened
Mostly useless crap from me. So it’s finally happened. July 7, 2014. After running my blog on various virtual hosts and VPSs since 1998, my measures put into place to protect this site and the others on here were insufficient to protect against weak passwords. Let’s just say that if you are a script kiddy and know all about press.php, tmpfiles.php and others, you have terrible operational security. There will be consequences. That is not a threat. Click to share on Twitter (Opens in new window). On Conve...
greebo.net
Time to start rebuilding GaiaBB | cat slave diary
http://www.greebo.net/2015/07/19/time-to-start-rebuilding-gaiabb
Mostly useless crap from me. Time to start rebuilding GaiaBB. July 19, 2015. In a life a long time ago in early 2002, we had to move Australia’s largest Volkswagen car forum. From EzyBoard, which was distributing malicious ads and hard to get rid of pop ups to our users, to our own forum software. After a product selection, I chose XMB, which was (and is) better than all the other free forums out there, such as phpBB (didn’t have attachments until v3/0! As a code reviewer and penetration tester, you can&...
greebo.net
Installing Fedora 18 (RTM) to VMWare Fusion 5 or VMWare Workstation 9 | cat slave diary
http://www.greebo.net/2013/01/18/installing-fedora-18-rtm-to-vmware-fusion-5-or-vmware-workstation-9/comment-page-1
Mostly useless crap from me. Installing Fedora 18 (RTM) to VMWare Fusion 5 or VMWare Workstation 9. January 18, 2013. I always live in hope that just one day, the folks over at Fedora will actually have a pain free VMWare installation. Not to be. Here’s how to do it with the minimal gnashing of teeth. Bugs that get you before anything else. Virtual Machine - Settings - Display - disable 3D acceleration. We’ll come back to this after the installation of VMWare Tools. About grub2 file not found /boot/grub2...
SOCIAL ENGAGEMENT