Última actualització: 01/09/2005; 09:07:42
Weblog d'en Xavi Caballé Weblog d'en Xavi Caballé
«I can't listen to that much Wagner. I start getting the urge to conquer Poland»
(Woody Allen)
Publicitat

dilluns, 8 / agost / 2005


Einafwknop, que significa «Firewall Knock Operator» és una eina que permet implementar un sistema d'autorització a Netfilter i libpcap per tal d'oferir un nivell addicional de seguretat, per tal de fer que l'aprofitament de vulnerabilitats per a les quals no hi ha cap actualització sigui més difícil. Abans de permetre l'execució d'un servei, fwknop requereix que s'enviï un paquet amb un format especial.
fwknop implements an authorization scheme based around Netfilter and libpcap that requires only a single encrypted packet in order to communicate various pieces of information including desired access through a Netfilter policy and/or complete commands to execute on the target system. The main application of this program is to protect services such as SSH with an additional layer of security in order to make the exploitation of vulnerabilities (both 0-day and unpatched code) much more difficult. The authorization server passively monitors authorization packets via libcap and hence there is no "server" to which to connect in the traditional sense. This method is similar to the Single Packet Authorization scheme proposed by Simple Nomad.
 


14:00 (# Enllaç permanent) | Comentaris: | Trackback:


[Whitedust] SSH Brute-Force Attacks, sobre com són els atacs de força bruta contra servidors SSH, com s'originen i com protegir-nos-en.


13:10 (# Enllaç permanent) | Comentaris: | Trackback:


[IT Conversations] Opening Move per Scott Chasin (CTO de MX Logic) sobre SPF i la lluita contra el correu brossa.

Finally, the war on spam is shifting to controlling outbound email traffic. This has profound implications for Internet service providers and for their customers. Zombie spambot attacks are being met with responses including blacklisting of users and entire ISPs. At Inbox-IT 2005 in San Jose, Scott Mace spoke with Scott Chasin, CTO of MX Logic, Inc. about efforts from Silicon Valley and Washington D.C. to control the spambots.

How can adoption rates be increased for SPF, Sender ID and DomainKeys? What role will the FTC's recently-released best practices recommendations for outbound email play? What are Port 25 blocking, subscriber reputation filtering, and acceptable use policies? What is the symbiotic relationship between service providers and the enterprise? How are enterprises liable for the spambot traffic they send out? What's the growing distinction between message submission vs. message transfer? What's the role of the IETF's RFC 2476? What is the challenge and opportunity that identity management poses for the messaging industry? Is SMTP broken? What are malicious opt-out attacks?
 



13:02 (# Enllaç permanent) | Comentaris: | Trackback:


EinaBiDiBLAH és una eina per a l'automatització de les auditories de seguretat, utilitzant .NET, Nessus, Google i Metasploit. Podeu trobar més detalls tot seguint la presentació realitzada al Black Hat.


09:08 (# Enllaç permanent) | Comentaris: | Trackback:


L'altra dia ja ho anunciava... però ara ja són «oficials»: els vídeos de les presentacions realitzades al What The Hack.

La Mercè Molist també ha passat una sèrie d'enllaços sobre les coses que hi ha vist.


09:05 (# Enllaç permanent) | Comentaris: | Trackback:


Microsoft anuncia sis noves actualitzacions de seguretat per als seus productes:
6 Microsoft Security Bulletins affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. These updates will require a restart.
 
Estaran disponibles a partir de demà.


09:02 (# Enllaç permanent) | Comentaris: | Trackback:


El primer video-joc fa vint-i-cinc anys: Happy Birthday, Mr Pac-Man.


08:58 (# Enllaç permanent) | Comentaris: | Trackback:


[News.com] Worm hole found in Windows 2000. Descoberta una vulnerabilitat crítica a un dels components del sistema operatiu Windows 2000, sense cap possibilitat de solució temporal fins a la disponibilitat de l'actualització.
A serious flaw has been discovered in a core component of Windows 2000, with no possible work-around until it gets fixed, a security company said.

The vulnerability in Microsoft's operating system could enable remote intruders to enter a PC via its Internet Protocol address, Marc Maiffret, chief hacking officer at eEye Digital Security, said on Wednesday. As no action on the part of the computer user is required, the flaw could easily be exploited to create a worm attack, he noted.
 
També en parlen a «The Register»: Worm risk over Win2K flaw:
Mainstream support of Windows 2000, which is still widely used in corporate environments, came to an end at the start of July 2005. Microsoft released a final update rollup for Windows 2000 on 28 June, just two days before expiration of regular support.

"Whilst news of this latest Microsoft flaw is presently fairly opaque to the industry, we cannot expect that it is, or will remain secret from the so-called 'black hats'. One can expect one or more worms to exploit this flaw as an attack vector very shortly".
 


08:56 (# Enllaç permanent) | Comentaris: | Trackback:

© Copyright 2003-2005 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.

350

Wishlist
Agost 2005
Diu Dil Dim Dim Dij Div Dis
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      
Jul   Set

Click to see the XML version of this web page.




Contingut actualitzat




Categories


Darrers comentaris

Arxiu

Contingut antic
(ja no s'actualitza)


Articles
(fins maig 2003)



Versions anteriors
d'aquesta pàgina

Webs d'amics
jcea
Vicent Partal
Jordi Mas
Toni Hermoso
Mercè Molist
Mina Nabona-Jassans

Gurus
Scripting News
Jon Udell
Bruce Sterling
Bruce Schneier
Howard Rheingold
Reflexiones e irreflexiones
Atalaya
Cuaderno de bitácora
Linotipo
Pedro Jorge Romero

Seguretat
reversing.org
Seguridad de la información
Somiatruites, Ciberderechos
     en la red

eN Espiral ~> Juanma Merino
Navega seguro

PDA
CosesPalm
PalmCat
CanalPDA.com

Cultura
El Llibreter