Irongeek's News Concatenator

Google

Irongeek's Featured Links:

Security Systems !!!

security camera

Keylogger

Document Scanning Service

Document Scanning

RAID Data Recovery

Network Security Products

Notebooks

Affiliates:

Web Hosting:
Help Irongeek.com pay for bandwidth and research equipment:

 

Here are the Current headlines from all of my favorite RSS sources.

Rootsecure.net:

Slashdot: Hacking the Free La Fonera Wireless Router “possible to get shell access by connecting...
... to a serial port present on the circuit board”
ZDNet Blog: Digg vs. Diggers? “Is Kevin Rose snubbing the very diggers that digg for the sake of...
... Digg?”
Yahoo: Security Awareness Program

milw0rm: Nullsoft Winamp < 5.31 Ultravox Ultravox-Max-Msg Heap Overflow Dos POC

Tech World: Wikipedia hijacked by malware

BBC News: Britain is 'surveillance society'

Secunia: Microsoft XMLHTTP ActiveX Control Code Execution Vulnerability

Wired: The Virus That Ate DHS

Secure Works: Botnet Attack and Analysis

Windows Security: How to secure remote desktop connections using TLS/SSL based authentication

BBC News: Google 'acts on YouTube threat' “Google is trying to win permission from media compani...
...es to broadcast output legally on YouTube and avoid the threat of legal action, a report has said”
Infosec Writers: Malicious Code Injection - It’s Not Just for SQL Anymore [pdf]

Security Fix: 14 Arrested for Credit Card, Phishing Scams

Reuters: Microsoft, Novell to link on Linux -report

Michael Sutton's Blog: Top 10 Signs You Have an Insecure Web App

Seattle PI: Diebold demands that HBO cancel documentary on voting machines

CNet: Microsoft backtracks on Vista transfer limits “Microsoft said on Thursday that it will not...
... limit the number of times that retail customers can transfer their Windows Vista license to a different computer”
Computer World: Mozilla promises fix for second minor Firefox 2.0 bug “users shouldn't have any ...
...major problems caused by the flaw”
Washington Post: 'Hacking' Doesn't Crack the Code

SANS: Bluetooth 0day hacking

2600: The Hacker Quarterly:

Shadow over Long Island, Part 3
The special Halloween rebroadcast of the radio play "Shadow Over Long Island" is now available online. You can find the links to the audio files here.
Shadow over Long Island, Part 2
The special Halloween rebroadcast of the radio play "Shadow Over Long Island" is now available online. You can find the links to the audio files here.
Shadow over Long Island, Part 1
The special Halloween rebroadcast of the radio play "Shadow Over Long Island" is now available online. You can find the links to the audio files here.
2600 MEETINGS TODAY
Today is the first Friday of November which means it's once again time for the monthly 2600 meetings all over the world. To see if there are meetings in your area, check our listings.
Off the Hook show for November 1, 2006

SPECIAL HALLOWEEN RADIO BROADCAST TUESDAY
We'll be rebroadcasting a classic from the radio archives on Tuesday in place of "Off The Wall." Starting at 5 pm (one hour earlier than normal), a radio play entitled "Shadow Over Long Island" will be presented. This play is a real time production which follows the tradition of the "War of the Worlds" broadcast many years ago in which a somewhat believable scenario is presented to the public, leaving many to wonder whether or not they're listening to reality or to fiction. In this case, "Shadow Over Long Island" deals with an accident at a nuclear power plant on Long Island and the resulting chaos that ensues. At the time of the original broadcast in 1985, nuclear safety was a very controversial topic in the area as a plant was set to open in the vicinity. Since then the plant has been shut down after widespread public opposition. This radio play was written by Emmanuel Goldstein/Eric Corley in the height of the controversy and has been broadcast on a number of occasions on Long Island and Connecticut radio stations. This will be the first rebroadcast in at least a decade.
FINAL HOPE NUMBER SIX PANEL SCHEDULED AT LAST
We said we'd do it and we meant it. When the Steve Rambam talk at HOPE Number Six was disrupted by his arrest minutes before he was scheduled to go on stage, we vowed to make sure it would one day be presented to the public. That day has now been set and we trust that the FBI won't interfere this time.

On Thursday, November 16, HOPE Number Six will finally end with the presentation: "Privacy is Dead - Get Over It" featuring Steve's revealing look at how much information on each of us is readily accessible to virtually anyone. As part of the talk, Steve will reveal all of the information he was able to find on a volunteer "victim." In addition, he will answer all sorts of questions from the audience, including what really happened back in July.

Admission to this talk is totally free. It's our way of saying thanks to the HOPE attendees and also a demonstration of the fact that our speakers will not be silenced, no matter what adversity they may have to face.

The talk will take place from 6 to 9 pm at the Stevens Institute in Hoboken, New Jersey. There's no need to panic - this location is very easily accessible from New York City and many other places. Full details are available here.

You may think you witnessed the conclusion of HOPE Number Six. But until this final talk is given, HOPE is not over.

Off the Wall show for October 24, 2006

AUTUMN ISSUE OF 2600 RELEASED
The Autumn 2006 issue is out and should be in your hands if you're a subscriber. It should also be at your local bookstore assuming they're one of the many who carry it. (If they're not, be sure to firmly request it.) If you want the convenience of having our magazine come directly to your home, office, or hideout then you should definitely subscribe. More details on the Autumn issue can be found here.
HOPE NUMBER SIX SHIRTS AVAILABLE
We've finally gotten around to putting our leftover HOPE Number Six merchandise on our online store. That means a bunch of unique shirts are now within your grasp. In addition, we're offering some extra HOPE stuff to go along with all shirt orders. Click here for details.
HOPE VIDEOS AVAILABLE
All of the HOPE Number Six videos are now available at our online store. In addition to offering individual DVDs of the talks that were held in the two main tracks, we also have a number of special package deals you may find of interest. And for those of you who have been spending the last few days trying to download all of the high fidelity audio of the conference that's available on our website, we've crammed it all onto a single DVD which is also available in our HOPE Number Six video section.
ALL HOPE AUDIO NOW ONLINE
We now have available for your listening enjoyment all of the HOPE Number Six talks and panels. To listen, simply go to http://www.hopenumbersix.net/speakers.html.

SecurityFocus News:

News: Quantum attacks worry computer scientists
Quantum attacks worry computer scientists
News: Bot nets likely behind jump in spam
Bot nets likely behind jump in spam
News: Researcher attempts to shed light on security troll
Researcher attempts to shed light on security troll

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
News: Targeted Trojan attacks on the rise
Targeted Trojan attacks on the rise
Brief: U.S., Korea top list of phishing hosts
U.S., Korea top list of phishing hosts
Brief: New, critical Microsoft Windows 0-day appears
New, critical Microsoft Windows 0-day appears

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
Brief: FBI nabs suspected identity-theft ring
FBI nabs suspected identity-theft ring
Brief: Air Force establishing cyberspace command
Air Force establishing cyberspace command
News: Microsoft offers Apple security advice
Microsoft offers Apple security advice

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
News: Skype under scrutiny for bugs
Skype under scrutiny for bugs
News: Say hello to the Skype Trojan
Say hello to the Skype Trojan
News: Shared music abuse bug hits iTunes
Shared music abuse bug hits iTunes

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
News: Nigeria enlists Microsoft to fight spam scammers
Nigeria enlists Microsoft to fight spam scammers
News: Cross-Site Scripting Worm Hits MySpace
Cross-Site Scripting Worm Hits MySpace
News: Another data security bill in the works
Another data security bill in the works

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
News: FTC sues company over spyware
FTC sues company over spyware
Infocus: Hacking Web 2.0 Applications with Firefox
Hacking Web 2.0 Applications with Firefox
Infocus: Recent Security Enhancements in NetBSD
Recent Security Enhancements in NetBSD

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
Infocus: Beginner's Guide to Wireless Auditing
Beginner's Guide to Wireless Auditing
Infocus: Analyzing Malicious SSH Login Attempts
Analyzing Malicious SSH Login Attempts
Mark Rasch: Employee Privacy, Employer Policy
Employee Privacy, Employer Policy

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
Scott Granneman: Surprises Inside Microsoft Vista's EULA
Surprises Inside Microsoft Vista's EULA
Kelly Martin: Viruses, Phishing, and Trojans For Profit
Viruses, Phishing, and Trojans For Profit
Federico Biancuzzi: ModSecurity 2.0 with Ivan Ristic
ModSecurity 2.0 with Ivan Ristic

>> Advertisement <<
ALERT: "How A Hacker Launches A Blind SQL Injection Attack Step-by-Step"!" - White Paper Blind SQL Injection can deliver total control of your server to a hacker giving them the ability to read, write and manipulate all data stored in your backend systems! Download this *FREE* white paper from SPI Dynamics for a complete guide to protection!
https://download.spidynamics.com/1/ad/bsq.asp?Campaign_ID=701600000004c29
More rss feeds from SecurityFocus
News, Infocus, Columns, Vulnerabilities, Bugtraq ...

Ten most recent posts on Irongeek.com:
Irongeek's Security Site:

A Brief Intro To Cryptographic Hashes/MD5
New Video: A Brief Intro To Cryptographic Hashes/MD5
A cryptographic hash function takes an input and returns a fixed size string that corresponds to it, called a hash. Cryptographic hashes have a lot of uses, some of which are: detecting data changes, storing or generating passwords, making unique keys in databases and ensuring message integrity. This video will mostly cover detecting file changes, but I hope it gets your mind going in the right direction for how hashes can be used. Specifically covered will be tools for creating MD5 hashes in Windows and Linux.
Irongeek In Print: Books that mention Irongeek.com
Irongeek In Print: Books that mention Irongeek.com
I did some looking around and it seems my site is mentioned in a few books. I've decided so start this page to keep track of book references to Irongeek.com. If I'm missing any please let me know, I found these first few via Google Books.
A Quick Intro To Sniffers Updated
I've updated my A Quick Intro To Sniffers article to fix a stupid error I made where I mistyped 801.11 instead of 802.11.
Text to Speech to MP3 with the freeware program DSpeech
New Video:Text to Speech to MP3 with the freeware program DSpeech
This video is on Dspeech, a freeware tool that uses Microsoft's SAPI (Speech Application Programming Interface) to convert text to spoken word. What's special about it is it lets you make an MP3 of the text, so you can listen to it on your computer, in you car or on your MP3 player. It's great for listening to study notes.

As an unrelated side note, a friend of mine want's me to mention his humor page on celebrities, politics and gadgets. Hope you enjoy it.
IGiGLE: Irongeek's WiGLE WiFi Database to Google Earth Client for Wardrive Mapping Updated
IGiGLE is a little app I wrote that lets you directly import data from the online WiGLE WiFi Wardrive database into a KML file, then view it in Google Earth.  I've made sure it works with the newest version of Google Earth 4.3, and recompiled it with the newest stable version of Autoit. If you want more details on how to use it, check out my video Wardrive Mapping With IGiGLE And WiGLE.
Getting Ubuntu Linux to connect to a PPTP Cisco VPN 3000 Concentrator
Just a quick notes page to help others that have the same problem I did. By the way, I plan to be at Conglomeration April 18th-20th. While it's not a Hacker/Security con, it's still a fun little Sci-Fi/Fantasy convention with plenty of geeky types running around. Let me know if you're a reader of Irongeek.com and plan to be there.
Irongeek's Infosec Wargame Servers Explained
I updated my post to explain that it was an April 1st joke, and link off to real ways to test your computer security skills. By the way, did anyone decode the QR Code I posted?
Irongeek's Infosec Wargame Servers
    I'd like to announce the launch of my own wargame servers for testing out your computer security skills. The host names are:

hackme1.irongeek.com
hackme2.irongeek.com
dosme1.irongeek.com

    Try out Nmap, Nessus, Metasploit and other tools on these boxes. Please let me know your findings. Thanks to my hosting provider Dreamhost. If you want to know more about Dreamhost check out my review (and coupon codes), they have been pretty good to me.


Hardware Keyloggers In Action 2: The KeyLlama 2GB USB Keylogger
This video will demonstrate one of the KeyLlama brand of hardware keyloggers in action, specifically the 2GB USB model. I know some of you are getting sick of me talking about hardware keyloggers, so I plan on this being my last entry on them for awhile.
Irongeek Campuses Page Updated
I've updated the Irongeek Campuses page with a few new schools, please contact me if your university uses my materials for teaching information security. Also, I've started to help out the The Mitzvah Group with their charity work. Check out and join their Myspace page, especially if you live in the Southern Indiana/Louisville Kentucky area.
Ghost 11 Plugin for Bart's PE Builder (BartPE)
I took the on Ghost 8 plugin and modified it a bit to work with Ghost 11.
Hardware Key Logging Part 3: A Review Of The KeyLlama USB and PS/2 Keyloggers
This article is about the KeyLlama brand of hardware keylogger, specifically the 2MB PS/2 model and the 2GB USB model.
Updated video on "Encrypting The Windows System Partition With Truecrypt 5.0"
Update:I made a small note at the top of my recent "Encrypting The Windows System Partition With Truecrypt 5.0" video. I used Photorec to do some file carving to see how secure Truecrypt's Windows system partition encryption was. Photorec was only able to recover two files, one ASP/TXT file and one PCX, but on closer examination both were false positives. They just contained seemingly random data, which Photorec mistook as real file headers. Truecrypt seems to do a very good job of securing the data on your system drive.

As a side note, if anyone else is using LinkedIn please feel free to add me and give me a recommendation for the work I've done on this site. Who knows, it may help me find a good career opportunity in my area.

Encrypting The Windows System Partition With Truecrypt 5.0
New Video: Encrypting The Windows System Partition With Truecrypt 5.0
Truecrypt 5.0 adds many new features, most importantly Windows system partition encryption. To put it in slightly inaccurate layman's terms, this means encrypting your entire C: drive. Even if you already write your sensitive data to an encrypted space, files are sometimes squirreled away in unencrypted temp space or in the page file where they may be recovered. Using Truecrypt to encrypt your Windows XP system partition will help eliminate this problem.
Hardware Keyloggers In Action 1: The KeyLlama 2MB PS/2 Keylogger
New Video:Hardware Keyloggers In Action 1: The KeyLlama 2MB PS/2 Keylogger
This video will demonstrate one of the KeyLlama brand of hardware keyloggers in action, specifically the 2MB PS/2 model. I hope this video will give the viewer a better grasp of how these hardware keyloggers work.
Encrypting VoIP Traffic With Zfone To Protect Against Wiretapping
New Video:Encrypting VoIP Traffic With Zfone To Protect Against Wiretapping
Some people worry about the easy with which their voice communications may be spied upon. Laws like CALEA have made this simpler in some ways, and with roaming wiretaps even those not under direct investigation may lose their privacy. Phil Zimmermann , creator of PGP, has come up with a project called Zfone which aims to do for VoIP what PGP did for email. Thanks to DOSMan for his help with this video.
Hacking and Pen-Testing With The Nokia 770/800/810 Notes Updated
I've updated my notes with a little more info on the n810 and links to new repositories (thanks to Andrew Lemay.)
Using GPG/PGP/FireGPG to Encrypt and Sign Email from Gmail
New Video:Using GPG/PGP/FireGPG to Encrypt and Sign Email from Gmail
This tutorial will show how to use GPG and the FireGPG plug-in to encrypt and decrypt messages in Gmail. GPG is an open source implementation of OpenPGP (Pretty Good Privacy) , a public-key-encryption system. With public key encryption you don?t have to give away the secret key that decrypts data for people to be able to send you messages. All senders need is the public key which can only be used to encrypt, this way the secret key never has to be sent across unsecured channels.
Nuclear War Survival Myths
I did not write this article, and while it's not about computer security it is about security. My interest in this subject was renewed after watching the TV series Jericho (watch it so it stays on the air). I thought this article was interesting enough to warrant mirroring, and it seems to jive pretty well with what I have read from other authors such as Duncan Long and Cresson H. Kearny on the subject. Please don't think I'm a paranoid, tin-foil-hat wearing freak, but I am a child of the 80's and a fan of post-apocalyptic fiction. Don't worry, my video on PGP/GPG is on its way.
Personal Privacy Programs
Hi all. I've decided it's time to start focusing on software that helps users maintain their privacy. I've already done videos on DBAN, Eraser, CCleaner, TrueCRYPT and Tor. I hope to have one on PGP/GPG/FireGPG up soon. What other must have privacy software do you recommend I cover? Let me know via my contact page, to which I've recently added my OpenPGP key.

Fatal error: Cannot redeclare showrss() (previously declared in /home/.giga/irongeek/irongeek.com/newscat.php:22) in /home/.giga/irongeek/irongeek.com/footer.php on line 9