https://blog.erratasec.com/2012/06/linkedin-vs-password-cracking.html?showComment=1339075699333&m=0
Errata Security: LinkedIn vs. password cracking
I'm running through the LinkedIn password hashes right now, so I thought I'd do a live blog of the steps I'm doing. As I do each step, I'll...
errata securitylinkedinvspasswordcracking
https://blog.erratasec.com/2010/11/web-20-report-card.html?showComment=1606184797988
Errata Security: Web 2.0 Report Card
George Ou over at Digital Society has created a " report card " for the various Web 2.0 services like webmail providers and Facebook. Of t...
errata securitywebreportcard
https://blog.erratasec.com/2019/05/almost-one-million-vulnerable-to.html?showComment=1559078894080
Errata Security: Almost One Million Vulnerable to BlueKeep Vuln (CVE-2019-0708)
Microsoft announced a vulnerability in it's "Remote Desktop" product that can lead to robust, wormable exploits. I scanned the Internet to a...
errata securityone million
https://blog.erratasec.com/2013/09/we-scanned-internet-for-port-22.html?showComment=1379111241633
Errata Security: We scanned the Internet for port 22
Yesterday (Sept. 12) we scanned the entire Internet for port 22 -- the port reserved for "SSH", the protocol used by sysadmins to remotely l...
errata securitythe internetscannedport
https://blog.erratasec.com/2013/09/no-nsa-cant-spy-on-smartphone-data.html?showComment=1378747085771
Errata Security: No, the NSA can't spy on arbitrary smartphone data
The NSA has been exposed as evil and untrustworthy, but so has the press. The press distorts every new revelation, ignoring crucial technica...
errata securitythe nsa
https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1301273592393
Errata Security: The Comodo hacker releases his manifesto
Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb...
errata securitycomodohackerreleasesmanifesto
https://blog.erratasec.com/2009/05/how-to-measure-download-speed.html?showComment=1243806021649
Errata Security: How to measure download speed
There are lots of "speed tests" websites that will measure your download speed, such as the ones provided DSLreports and SpeakEasy. Or, you ...
security how toerratameasuredownloadspeed
https://blog.erratasec.com/2014/02/javascript-one-true-language.html
Errata Security: JavaScript: the one true language
Mozilla has an excellent guide " A Reintroduction to JavaScript ". It's a good read, I even found a couple points that I'd been unclear on. ...
errata securitythe onejavascripttruelanguage
https://blog.erratasec.com/2007/06/purple-pill.html?showComment=1183350300000
Errata Security: The Purple Pill?
This story highlights one of the problems in Internet security. Joanna Rutkowska has been talking about "hypervisor rootkits", a way of cre...
errata securitypurplepill
https://blog.erratasec.com/2021/11/example-forensicating-mesa-county.html
Errata Security: Example: forensicating the Mesa County system image
Tina Peters, the election clerk in Mesa County (Colorado) went rogue and dumped disk images of an election computer on the Internet. They a...
errata securitymesa countyexamplesystemimage
https://blog.erratasec.com/2012/06/linkedin-vs-password-cracking.html?showComment=1339186775146&m=0
Errata Security: LinkedIn vs. password cracking
I'm running through the LinkedIn password hashes right now, so I thought I'd do a live blog of the steps I'm doing. As I do each step, I'll...
errata securitylinkedinvspasswordcracking
https://blog.erratasec.com/2012/02/no-anonymous-cant-ddos-root-dns-servers.html?showComment=1329424923714
Errata Security: No, #Anonymous can't DDoS the root DNS servers
This is what you'd see if the DNS blackout were successful #Anonymous hackers have announced " Operation Global Blackout ", promising to ...
errata securitythe rootanonymous
https://blog.erratasec.com/2007/10/evil-rob-graham-fact-3.html?showComment=1193283600000
Errata Security: Evil Rob Graham Fact #3
and Once again I am not pointing fingers, but come on , they were separated at birth. Plus the other day at lunch Rob mentioned wanting t...
errata securityrob grahamevilfact
https://blog.erratasec.com/2008/04/racing-to-zero.html?showComment=1209491100000
Errata Security: Racing to Zero
This article claims that AV vendors are upset about an anti-AV competition during DefCon . They claim that it provides too much help to hac...
errata securityracingzero
https://blog.erratasec.com/2007/06/niiiice.html?showComment=1181663700000
Errata Security: Niiiice...
**PLEASE DO NOT POST A COMMENT IF ITS ABOUT SAFARI IN BETA** These bugs have been verified in the current PRODUCTION copy on OSX (Safari 2.0...
errata security
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489578325022
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1600228660850
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496735014615
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1301655617369
Errata Security: The Comodo hacker releases his manifesto
Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb...
errata securitycomodohackerreleasesmanifesto
https://blog.erratasec.com/2012/06/linkedin-vs-password-cracking.html?showComment=1342920951074&m=0
Errata Security: LinkedIn vs. password cracking
I'm running through the LinkedIn password hashes right now, so I thought I'd do a live blog of the steps I'm doing. As I do each step, I'll...
errata securitylinkedinvspasswordcracking
https://blog.erratasec.com/2010/11/i-was-just-detained-by-tsa.html?showComment=1290651231378
Errata Security: I was just detained by the TSA
Today, I was detained by the TSA for about 30 minutes for taking pictures while going through security. Taking pictures is perfectly legal. ...
errata securitydetainedtsa
https://blog.erratasec.com/2016/02/some-notes-on-apple-decryption-san.html?m=0
Errata Security: Some notes on Apple decryption San Bernadino phone
Today, a judge ordered Apple to help the FBI decrypt the San Bernadino shooter's iPhone 5C. Specifically: disable the auto-erase that hap...
errata securitysome notessan bernadinoappledecryption
https://blog.erratasec.com/2012/10/randomizing-port-scans-part-two.html?showComment=1351422488272
Errata Security: Randomizing port scans, part two
I want to randomize port scans for large-scale scanning of the Internet, so I apply a little theoretical math to the problem. The solution ...
errata securityportscansparttwo
https://blog.erratasec.com/2014/07/nsa-walk-mile-in-their-shoes.html?showComment=1404997108274
Errata Security: NSA: walk a mile in their shoes
While this is mostly a technical blog, our most popular posts deal with cyber-rights, supporting Snowden, Weev, and Swartz. Yet sometimes I...
errata securitynsawalkmileshoes
https://blog.erratasec.com/2012/06/confirmed-linkedin-6mil-password-dump.html?showComment=1339011177647
Errata Security: Confirmed: LinkedIn 6mil password dump is real
Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for...
errata securityconfirmedlinkedinpassworddump
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489200273890
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2006/12/old-things-will-be-new-again.html
Errata Security: Old things will be new again
A lot of hype has been made recently over the fact a Vista exploit has been found for sale on a Russian site. There has been lots of medi...
errata securityoldthingsnew
https://blog.erratasec.com/2017/11/how-to-read-newspapers.html
Errata Security: How to read newspapers
News articles don't contain the information you think. Instead, they are written according to a formula, and that formula is as much about d...
security how toerratareadnewspapers
https://blog.erratasec.com/2010/11/i-was-just-detained-by-tsa.html?showComment=1290617596055
Errata Security: I was just detained by the TSA
Today, I was detained by the TSA for about 30 minutes for taking pictures while going through security. Taking pictures is perfectly legal. ...
errata securitydetainedtsa
https://blog.erratasec.com/2016/02/weve-always-been-at-war-with-eastasia.html?showComment=1455640177568&m=0
Errata Security: We've always been at war with Eastasia
Orwell's point in 1984 was that it's more than just government Though Police. The people themselves participate, willfully, in "double thi...
errata securityalwayswar
https://develop.fedscoop.com/radio/errata-securitys-robert-graham-on-securing-iot/
Errata Security's Robert Graham on securing IoT | FedScoop
Feb 21, 2017 - Errata Security's CEO talks about the evolving security threats around IoT.
errata securityrobert grahamsecuringiotfedscoop
https://blog.erratasec.com/2015/09/yes-they-just-droned-hacker.html
Errata Security: Yes, they just droned a hacker
Many are disputing the story about a recent story about a drone strike that targeted the hacker TriCk from Anonymous group TeaMp0isoN . Th...
errata securityyeshacker
https://blog.erratasec.com/2012/05/tuning-linux-tcp-hash-entries.html?showComment=1338561204790
Errata Security: Tuning Linux: TCP hash entries
Tuning Linux for scalable network applications is hard, partly because it's not documented anywhere. Or if it is, all the top Google results...
errata securitytuninglinuxtcphash
https://blog.erratasec.com/2007/06/niiiice.html?showComment=1190275800000
Errata Security: Niiiice...
**PLEASE DO NOT POST A COMMENT IF ITS ABOUT SAFARI IN BETA** These bugs have been verified in the current PRODUCTION copy on OSX (Safari 2.0...
errata security
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1597227120065&m=0
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2016/02/twitter-has-to-change.html
Errata Security: Twitter has to change
Today, Twitter announced that instead of the normal timeline of newest messages on top, they will prioritize messages they think you'll be i...
errata securitytwitterchange
https://blog.erratasec.com/2016/06/use-freakin-debugger.html?showComment=1466766533722
Errata Security: Use the freakin' debugger
This post is by a guy who does " not use a debugger ". That's stupid. Using a friendly source-level debugger (Visual Studio, XCode, Eclipse)...
errata securityusedebugger
https://blog.erratasec.com/2010/04/vuln-disclosure-is-rude.html?showComment=1272134704374
Errata Security: Vuln Disclosure is Rude
It's amazing that after all this time, our community has not come to grips with "vulnerability disclosure". Last weekend, a lot of people tw...
errata securityvulndisclosurerude
https://blog.erratasec.com/2016/06/etheriumdao-hack-similfied.html?showComment=1466589560213&m=0
Errata Security: Ethereum/TheDAO hack simplified
The news in the Bitcoin world is the Ethereum/DAO hack. I thought I'd write up a simplified explanation. What is Bitcoin? I'm sure you...
errata securityethereumhacksimplified
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496760990008&m=0
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2016/03/how-media-really-created-trump_26.html?showComment=1595588673105
Errata Security: How the media really created Trump
This NYTimes op-ed claims to diagnose the press's failings with regard to Trump, but in its first sentence demonstrates how little press un...
errata securitythe mediareallycreatedtrump
https://blog.erratasec.com/2007/08/sidejacking-with-hamster_05.html?showComment=1193685960000
Errata Security: SideJacking with Hamster
NOTE: you can download the program at http://www.erratasec.com/sidejacking.zip ; make sure to read the instructions. Others have done a be...
errata securityhamster
https://blog.erratasec.com/2009/05/star-trek-sucked.html?showComment=1256754182636
Errata Security: Star Trek Sucked
Everyone else is going to love the new Star Trek movie, but not me. It's got great visuals, great casting, great acting, great editing, and...
errata securitystar treksucked
https://blog.erratasec.com/2007/03/hit-pieces-and-ethical-journalism.html?showComment=1174414620000
Errata Security: Hit-pieces and ethical journalism
One of the under-appreciated problems in our industry is the "hit-piece", where a reporter twists facts and quotes to attack a victim. A goo...
errata securityhitpiecesethicaljournalism
https://blog.erratasec.com/2014/09/bash-shellshock-scan-of-internet.html?showComment=1411633663357
Errata Security: Bash 'shellshock' scan of the Internet
NOTE: malware is now using this as their User-agent. I haven't run a scan now for over two days. I'm running a scan right now of the I...
errata securitybashshellshockscaninternet
https://blog.erratasec.com/2012/08/common-misconceptions-of-password.html?showComment=1346310671825
Errata Security: Common misconceptions of password cracking
After this great article on passwords at Ars Technica, I've seen some common misconceptions pop up. I thought I'd clarify them (even though...
errata securitycommon misconceptionspasswordcracking
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489574209119&m=0
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2020/05/securing-work-at-home-apps.html?showComment=1595302064386
Errata Security: Securing work-at-home apps
In today's post, I answer the following question: Our customer's employees are now using our corporate application while working from home...
work at homeerrata securitysecuringapps
https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1301307389092
Errata Security: The Comodo hacker releases his manifesto
Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb...
errata securitycomodohackerreleasesmanifesto
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489302422469&m=0
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2007/12/things-to-do-on-christmas-break.html
Errata Security: Things to do on Christmas break...
things to do on christmaserrata securitybreak
https://blog.erratasec.com/2009/05/how-to-measure-download-speed.html?showComment=1242275760000
Errata Security: How to measure download speed
There are lots of "speed tests" websites that will measure your download speed, such as the ones provided DSLreports and SpeakEasy. Or, you ...
security how toerratameasuredownloadspeed
https://blog.erratasec.com/2007/01/george-ou-scores.html
Errata Security: George Ou scores!
http://blogs.zdnet.com/Ou/?p=400 George is awesome because he is by far one of the most technical reporters I have ever talked to. Its not o...
errata securitygeorgeouscores
https://blog.erratasec.com/2014/09/bash-shellshock-scan-of-internet.html?showComment=1411591892504&m=0
Errata Security: Bash 'shellshock' scan of the Internet
NOTE: malware is now using this as their User-agent. I haven't run a scan now for over two days. I'm running a scan right now of the I...
errata securitybashshellshockscaninternet
https://blog.erratasec.com/2014/07/reading-xkeyscore-rules-source.html?m=1
Errata Security: Reading the XKeyScore-rules source
Today's story is about "XKeyScore source code" leak. As an expert, I'm going to read through the code line-by-line and comment on it. Let'...
errata securityreadingxkeyscorerulessource
https://blog.erratasec.com/2017/09/people-cant-read-equifax-edition.html
Errata Security: People can't read (Equifax edition)
One of these days I'm going to write a guide for journalists reporting on the cyber. One of the items I'd stress is that they often fail to ...
errata securitypeoplereadequifaxedition
https://blog.erratasec.com/2012/06/confirmed-linkedin-6mil-password-dump.html?showComment=1339007540538&m=0
Errata Security: Confirmed: LinkedIn 6mil password dump is real
Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for...
errata securityconfirmedlinkedinpassworddump
https://blog.erratasec.com/2008/05/apple-still-not-playing-nice-with.html
Errata Security: Apple still not playing nice with researchers...
http://www.theregister.co.uk/2008/05/22/unpatched_apple_bug_flap/
errata securityapplestillplayingnice
https://blog.erratasec.com/2008/01/hexlore.html?showComment=1200947340000
Errata Security: Hex.lore
If I ever get around to writing a computer book, one of the first I would write would be about the lore of hexadecimal. We teach children th...
errata securityhexlore
https://blog.erratasec.com/2012/06/confirmed-linkedin-6mil-password-dump.html?showComment=1339011712208&m=0
Errata Security: Confirmed: LinkedIn 6mil password dump is real
Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for...
errata securityconfirmedlinkedinpassworddump
https://blog.erratasec.com/2013/08/nsa-foia-fail-is-fail.html
Errata Security: NSA FOIA fail is fail
I blogged about my NSA FOIA response , and how it didn't even match my request. A guy "Cody" at DefCon showed me an even better response: ...
errata securitynsafoiafail
https://blog.erratasec.com/2007/06/amero-part-2.html?showComment=1181674380000
Errata Security: Amero, part 2
Brian Krebs has posted an update to the Julie Amero case (the teacher convicted of harming students by letting them see porn). Krebs also l...
errata securitypart
https://blog.erratasec.com/2012/08/no-hacker-really-does-mean-hacker.html?showComment=1344457834694
Errata Security: No, "hacker" really does mean "hacker"
The earliest known use of "computer hacker" in the press described a criminal act: Many telephone services have been curtailed because of ...
errata securityhackerreallymean
https://blog.erratasec.com/2008/05/activex-is-dangerous.html?showComment=1210618500000
Errata Security: ActiveX is dangerous...
UPDATE: AxBan can be downloaded from here . Any questions or comments can be directed to talksec@portal.erratasec.com . We all know ActiveX...
errata securityactivexdangerous
https://blog.erratasec.com/2014/02/c-programming-you-are-teaching-it-wrong.html
Errata Security: C programming: you are teaching it wrong
It's been three decades. There is no longer an excuse for the fail way colleges teach "C programming". Let me help. Chapter 1: the debug...
errata securityyou areprogrammingteachingwrong
https://blog.erratasec.com/2010/06/cyberwar-is-fiction.html?showComment=1275964986346
Errata Security: Cyberwar is fiction
I'm reading various articles about the Russia's proposal, with support from the UN, for a " cyberwarfare arms limitation treaty ". What ast...
errata securitycyberwarfiction
https://blog.erratasec.com/2009/03/hamster-20-and-ferret-20.html?showComment=1302790245702
Errata Security: Hamster 2.0 and Ferret 2.0
I updated my Sidejacking tools Hamster and Ferret. You can get them from the site http://hamster.erratasec.com (or, if DNS hasn't propagate...
errata securityhamsterferret
https://blog.erratasec.com/2011/10/brookfield-properties-responds-re.html
Errata Security: Brookfield Properties responds re: #OccupyWallStreet
(For my complete report on the protest, click here .) The #OccupyWallStreet protest is in fact occupying Zuccotti Park , a private park ...
errata securitybrookfield propertiesrespondsoccupywallstreet
https://blog.erratasec.com/2008/01/new-quicktime-flaw-this-is-not-deja-vu.html
Errata Security: New Quicktime Flaw, this is not Deja Vu
No really. Its ANOTHER QuickTime flaw. It also involves RTSP . It was posted to Full Disclosure on Thursday afternoon. We have verified a c...
errata securityis notnewquicktimeflaw
https://blog.erratasec.com/2010/02/nehalem-vs-ids.html?showComment=1265423284736
Errata Security: Nehalem vs. IDS
Intel's latest desktop processor is code-named "Nehalem". It adds a lot of good features for intrusion-detection software. I thought I'd sum...
errata securitynehalemvsids
https://blog.erratasec.com/2018/05/the-devil-wears-pravda.html
Errata Security: The devil wears Pravda
Classic Bond villain, Elon Musk, has a new plan to create a website dedicated to measuring the credibility and adherence to "core truth" of ...
errata securitythe devilwearspravda
https://blog.erratasec.com/2014/07/xkeyscore-regex-foo.html?m=1
Errata Security: XKeyScore: regex foo
For those of you rusty on your regex code, I thought I'd explain those found in the alleged XKeyScore source . The first one is: / bridg...
errata securityxkeyscoreregexfoo
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489560850214&m=0
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2009/07/economist-on-kindle.html
Errata Security: The Economist on the Kindle
You can now get a subscription to the Economist on the Kindle (or Kindle readers on devices like the iPhone). Economics is the red pill . ...
errata securitythe economistkindle
https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1602421805232
Errata Security: The Comodo hacker releases his manifesto
Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb...
errata securitycomodohackerreleasesmanifesto
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496763381678
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2014/05/can-i-drop-pacemaker-0day.html?showComment=1403703138644
Errata Security: Can I drop a pacemaker 0day?
Can I drop a pacemaker 0day at DefCon that is capable of killing people? Computers now run our cars. It's now possible for a hacker to i...
errata securitydroppacemaker
https://blog.erratasec.com/2016/11/the-false-false-balance-problem.html?showComment=1479860219406
Errata Security: The false-false-balance problem
Until recently, journalism in America prided itself on objectivity -- to report the truth, without taking sides. That's because big debates ...
errata securityfalsebalanceproblem
https://blog.erratasec.com/2016/02/some-notes-on-apple-decryption-san.html?showComment=1455867231621
Errata Security: Some notes on Apple decryption San Bernadino phone
Today, a judge ordered Apple to help the FBI decrypt the San Bernadino shooter's iPhone 5C. Specifically: disable the auto-erase that hap...
errata securitysome notessan bernadinoappledecryption
https://blog.erratasec.com/2018/11/brian-kemp-is-bad-on-cybersecurity.html?showComment=1541482085001
Errata Security: Brian Kemp is bad on cybersecurity
I'd prefer a Republican governor, but as a cybersecurity expert, I have to point out how bad Brian Kemp (candidate for Georgia governor) is ...
errata securitybrian kempbadcybersecurity
https://blog.erratasec.com/2021/10/fact-check-that-forensics-of-mesa-image.html
Errata Security: Fact check: that "forensics" of the Mesa image is crazy
Tina Peters, the elections clerk from Mesa County (Colorado) went rogue, creating a "disk-image" of the election server, and posting that im...
errata securityfact check
https://blog.erratasec.com/2013/04/ap-hack-stock-market-did-not-plunge.html?showComment=1367522900125
Errata Security: @AP hack: the stock market did not "plunge"
According to all press outlets, the stock market "plunged" today due to @AP getting hacked and reporting explosions at the White House. In...
the stock marketerrata securitydid notaphack
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1597148072391&m=0
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2017/06/some-non-lessons-from-wannacry.html?showComment=1496891916309&m=0
Errata Security: Some non-lessons from WannaCry
This piece by Bruce Schneier needs debunking. I thought I'd list the things wrong with it.
errata securitynonlessonswannacry
https://blog.erratasec.com/2008/01/more-sidejacking.html?showComment=1225637520000
Errata Security: More SideJacking
Our sidejacking stuff was named one of the top 5 hacks of 2007 . Since then, we've noticed a few more things about it. To recap: websites ty...
errata security
https://blog.erratasec.com/2016/11/in-which-i-have-to-debunk-second-time.html?showComment=1478208902946
Errata Security: In which I have to debunk a second time
So Slate is doubling-down on their discredited story of a secret Trump server. Tip for journalists: if you are going to argue against an e...
errata securityhave to
https://blog.erratasec.com/2016/12/iot-saves-lives.html
Errata Security: IoT saves lives but infosec wants to change that
The cybersecurity industry mocks/criticizes IoT. That's because they are evil and wrong. IoT saves lives. This was demonstrated a couple wee...
errata securityiotsaveslives
https://blog.erratasec.com/2009/03/hamster-20-and-ferret-20.html?showComment=1236805500000
Errata Security: Hamster 2.0 and Ferret 2.0
I updated my Sidejacking tools Hamster and Ferret. You can get them from the site http://hamster.erratasec.com (or, if DNS hasn't propagate...
errata securityhamsterferret
https://blog.erratasec.com/2008/10/errata-security-endorses-mccain.html?showComment=1225379400000
Errata Security: Errata Security endorses McCain
The choice in this election is between a small or large left-ward shift. McCain is a moderate Republican, Obama is a radical Democract. A bi...
errata securitymccain
https://blog.erratasec.com/2015/07/more-proxyham-nonsense.html
Errata Security: More ProxyHam stuff
Somebody asked how my solution in the last post differed from the " ProxyGambit " solution. They missed my point. Just because I change the...
errata securitystuff
https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1600229405859
Errata Security: Some comments on the Wikileaks CIA/#vault7 leak
I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th...
errata securityon thecommentswikileakscia
https://blog.erratasec.com/2007/08/sidejacking-with-hamster_05.html?showComment=1188527640000
Errata Security: SideJacking with Hamster
NOTE: you can download the program at http://www.erratasec.com/sidejacking.zip ; make sure to read the instructions. Others have done a be...
errata securityhamster
https://blog.erratasec.com/2012/06/falsehoods-programmers-believe-about.html
Errata Security: Falsehoods programmers believe about networks
Inspired by falsehoods programmers believe about time and usernames , I thought I'd start collecting falsehoods programmers have about netw...
errata securityprogrammersbelievenetworks
https://blog.erratasec.com/2009/04/ssl-acceleration.html
Errata Security: SSL acceleration
This Slashdot article discusses building an SSL accelerator for $5k worth of hardware rather than $50k for a "hardware" accelerator like F...
errata securitysslacceleration
https://blog.erratasec.com/2014/09/bash-shellshock-bug-is-wormable.html?showComment=1411640799471&m=0
Errata Security: Bash 'shellshock' bug is wormable
Early results from my scan: there's about 3000 systems vulnerable just on port 80, just on the root "/" URL, without Host field. That doesn'...
errata securitybashshellshockbug
https://blog.erratasec.com/2021/11/example-forensicating-mesa-county.html?showComment=1636444113783&m=0
Errata Security: Example: forensicating the Mesa County system image
Tina Peters, the election clerk in Mesa County (Colorado) went rogue and dumped disk images of an election computer on the Internet. They a...
errata securitymesa countyexamplesystemimage
https://blog.erratasec.com/2016/10/yes-we-can-validate-wikileaks-emails.html?showComment=1477604021408
Errata Security: Yes, we can validate the Wikileaks emails
Recently, WikiLeaks has released emails from Democrats. Many have repeatedly claimed that some of these emails are fake or have been modifie...
yes we canerrata securityvalidatewikileaksemails
https://blog.erratasec.com/2013/01/nytimes-and-more-rainbow-table-nonsense.html?showComment=1359697545217
Errata Security: NYTimes and more Rainbow Table nonsense
Today's NYTimes article on how it got hacked is full of inaccurate information. Take, for example, this paragraph: While hashes make h...
errata securityand morerainbow tablenytimesnonsense
https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1604968757767
Errata Security: How The Intercept Outed Reality Winner
Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ...
errata securitythe interceptoutedrealitywinner
https://blog.erratasec.com/2015/01/platitudes-are-only-skin-deep.html?m=1
Errata Security: Platitudes are only skin deep
I overdosed on Disney Channel over the holidays, because of course children control the remote. It sounds like it's teaching kids wholesome ...
errata securityskindeep