A Practical Use for a SHA1 Collision, (Mon, Apr 3rd)
[This is a guest diary by Paul Bolton] First I it is not a new attack against sha1. When Google announced a sha1 collision in February (here) it reminded me of a detour I took in Nov 2015 when...
View ArticleISC Stormcast For Tuesday, April 4th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleEncryption inside Utility Industrial Control Systems (ICS) communication...
Industrial control systems are sensitive systems that must make decisions in real time to ensure the operation of the industrial process they govern. The latency and reliability in packet transmission...
View ArticleISC Stormcast For Wednesday, April 5th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleWhitelists: The Holy Grail of Attackers, (Wed, Apr 5th)
As a defender, take the time to put yourself in the place of a bad guy for a few minutes. Youre writing some malicious code and you need to download payloads from the Internet or hide your code on a...
View ArticleJava Struts2 Vulnerability Used To Install Cerber Crypto Ransomware, (Thu,...
[We do have a special webcast about the Struts2 Vulnerability scheduled for 11am ET today. Sign up here] Since about a month, we are tracking numerous attempts to exploit the Java Struts2 vulnerability...
View ArticleISC Stormcast For Thursday, April 6th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleISC Stormcast For Friday, April 7th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleTracking Website Defacers with HTTP Referers, (Fri, Apr 7th)
In a previous diary, I explained how pictures may affect your website reputation[1]. Although asuggestedrecommendation was to prevent cross-linking by using the HTTP referer, this is a control that I...
View ArticleDomain Whitelisting With Alexa and Umbrella Lists, (Sat, Apr 8th)
I read an interesting blogpost: Domain Whitelist Benchmark: Alexa vs Umbrella The author reported that around 1400 domains on Malwarebytes hpHosts EMD blacklist were in the top 1,000,000 domains Alexa...
View ArticleDomain Whitelisting With Alexa and Umbrella Lists - update, (Sun, Apr 9th)
A was asked if I could share the files of my last diary entry: text-align:left">You can find the files on my">site here. And to teach you how to fish :-), here are the commands I used to produce...
View ArticleISC Stormcast For Monday, April 10th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticlePassword History: Insights Shared by a Reader, (Mon, Apr 10th)
When extracting hashes from an active directory database for password auditing purposes, it can also possible to extract hashes of a user font-size:11pt">I work for a global Fortune 500 company...
View ArticleDridex malspam seen on Monday 2017-04-10, (Tue, Apr 11th)
Introduction Malicious spam (malspam) pushing the Dridex banking Trojan disappeared in mid-2016, but it reappeared in January 2017 starting with a small campaign targeting UK financial institutions...
View ArticleISC Stormcast For Tuesday, April 11th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article2017-04-11 - Multiple security updates from Adobe for Flash Player, Adobe...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleApril 2017 Microsoft Patch Tuesday, (Tue, Apr 11th)
Today on Tuesday 2017-04-11, Microsoft announced its monthly security release (also known as Patch Tuesday). Reviewing Microsofts Security Update Guide, it looks like theres 644 updates with 210 of...
View ArticleISC Stormcast For Wednesday, April 12th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View ArticleMalspam on 2017-04-11 pushes yet another ransomware variant, (Wed, Apr 12th)
Introduction I ran across some interesting malicious spam (malspam) on Tuesday morning 2017-04-11. At first, I thought it had limited distribution. Later I found several other examples, and they were...
View ArticleISC Stormcast For Thursday, April 13th 2017...
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
View Article