Robuta

https://blog.erratasec.com/2012/06/linkedin-vs-password-cracking.html?showComment=1339075699333&m=0 Errata Security: LinkedIn vs. password cracking I'm running through the LinkedIn password hashes right now, so I thought I'd do a live blog of the steps I'm doing. As I do each step, I'll... errata securitylinkedinvspasswordcracking https://blog.erratasec.com/2010/11/web-20-report-card.html?showComment=1606184797988 Errata Security: Web 2.0 Report Card George Ou over at Digital Society has created a " report card " for the various Web 2.0 services like webmail providers and Facebook. Of t... errata securitywebreportcard https://blog.erratasec.com/2019/05/almost-one-million-vulnerable-to.html?showComment=1559078894080 Errata Security: Almost One Million Vulnerable to BlueKeep Vuln (CVE-2019-0708) Microsoft announced a vulnerability in it's "Remote Desktop" product that can lead to robust, wormable exploits. I scanned the Internet to a... errata securityone million https://blog.erratasec.com/2013/09/we-scanned-internet-for-port-22.html?showComment=1379111241633 Errata Security: We scanned the Internet for port 22 Yesterday (Sept. 12) we scanned the entire Internet for port 22 -- the port reserved for "SSH", the protocol used by sysadmins to remotely l... errata securitythe internetscannedport https://blog.erratasec.com/2013/09/no-nsa-cant-spy-on-smartphone-data.html?showComment=1378747085771 Errata Security: No, the NSA can't spy on arbitrary smartphone data The NSA has been exposed as evil and untrustworthy, but so has the press. The press distorts every new revelation, ignoring crucial technica... errata securitythe nsa https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1301273592393 Errata Security: The Comodo hacker releases his manifesto Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb... errata securitycomodohackerreleasesmanifesto https://blog.erratasec.com/2009/05/how-to-measure-download-speed.html?showComment=1243806021649 Errata Security: How to measure download speed There are lots of "speed tests" websites that will measure your download speed, such as the ones provided DSLreports and SpeakEasy. Or, you ... security how toerratameasuredownloadspeed https://blog.erratasec.com/2014/02/javascript-one-true-language.html Errata Security: JavaScript: the one true language Mozilla has an excellent guide " A Reintroduction to JavaScript ". It's a good read, I even found a couple points that I'd been unclear on. ... errata securitythe onejavascripttruelanguage https://blog.erratasec.com/2007/06/purple-pill.html?showComment=1183350300000 Errata Security: The Purple Pill? This story highlights one of the problems in Internet security. Joanna Rutkowska has been talking about "hypervisor rootkits", a way of cre... errata securitypurplepill https://blog.erratasec.com/2021/11/example-forensicating-mesa-county.html Errata Security: Example: forensicating the Mesa County system image Tina Peters, the election clerk in Mesa County (Colorado) went rogue and dumped disk images of an election computer on the Internet. They a... errata securitymesa countyexamplesystemimage https://blog.erratasec.com/2012/06/linkedin-vs-password-cracking.html?showComment=1339186775146&m=0 Errata Security: LinkedIn vs. password cracking I'm running through the LinkedIn password hashes right now, so I thought I'd do a live blog of the steps I'm doing. As I do each step, I'll... errata securitylinkedinvspasswordcracking https://blog.erratasec.com/2012/02/no-anonymous-cant-ddos-root-dns-servers.html?showComment=1329424923714 Errata Security: No, #Anonymous can't DDoS the root DNS servers This is what you'd see if the DNS blackout were successful #Anonymous hackers have announced " Operation Global Blackout ", promising to ... errata securitythe rootanonymous https://blog.erratasec.com/2007/10/evil-rob-graham-fact-3.html?showComment=1193283600000 Errata Security: Evil Rob Graham Fact #3 and Once again I am not pointing fingers, but come on , they were separated at birth. Plus the other day at lunch Rob mentioned wanting t... errata securityrob grahamevilfact https://blog.erratasec.com/2008/04/racing-to-zero.html?showComment=1209491100000 Errata Security: Racing to Zero This article claims that AV vendors are upset about an anti-AV competition during DefCon . They claim that it provides too much help to hac... errata securityracingzero https://blog.erratasec.com/2007/06/niiiice.html?showComment=1181663700000 Errata Security: Niiiice... **PLEASE DO NOT POST A COMMENT IF ITS ABOUT SAFARI IN BETA** These bugs have been verified in the current PRODUCTION copy on OSX (Safari 2.0... errata security https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489578325022 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1600228660850 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496735014615 Errata Security: How The Intercept Outed Reality Winner Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ... errata securitythe interceptoutedrealitywinner https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1301655617369 Errata Security: The Comodo hacker releases his manifesto Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb... errata securitycomodohackerreleasesmanifesto https://blog.erratasec.com/2012/06/linkedin-vs-password-cracking.html?showComment=1342920951074&m=0 Errata Security: LinkedIn vs. password cracking I'm running through the LinkedIn password hashes right now, so I thought I'd do a live blog of the steps I'm doing. As I do each step, I'll... errata securitylinkedinvspasswordcracking https://blog.erratasec.com/2010/11/i-was-just-detained-by-tsa.html?showComment=1290651231378 Errata Security: I was just detained by the TSA Today, I was detained by the TSA for about 30 minutes for taking pictures while going through security. Taking pictures is perfectly legal. ... errata securitydetainedtsa https://blog.erratasec.com/2016/02/some-notes-on-apple-decryption-san.html?m=0 Errata Security: Some notes on Apple decryption San Bernadino phone Today, a judge ordered Apple to help the FBI decrypt the San Bernadino shooter's iPhone 5C. Specifically: disable the auto-erase that hap... errata securitysome notessan bernadinoappledecryption https://blog.erratasec.com/2012/10/randomizing-port-scans-part-two.html?showComment=1351422488272 Errata Security: Randomizing port scans, part two I want to randomize port scans for large-scale scanning of the Internet, so I apply a little theoretical math to the problem. The solution ... errata securityportscansparttwo https://blog.erratasec.com/2014/07/nsa-walk-mile-in-their-shoes.html?showComment=1404997108274 Errata Security: NSA: walk a mile in their shoes While this is mostly a technical blog, our most popular posts deal with cyber-rights, supporting Snowden, Weev, and Swartz. Yet sometimes I... errata securitynsawalkmileshoes https://blog.erratasec.com/2012/06/confirmed-linkedin-6mil-password-dump.html?showComment=1339011177647 Errata Security: Confirmed: LinkedIn 6mil password dump is real Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for... errata securityconfirmedlinkedinpassworddump https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489200273890 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2006/12/old-things-will-be-new-again.html Errata Security: Old things will be new again A lot of hype has been made recently over the fact a Vista exploit has been found for sale on a Russian site. There has been lots of medi... errata securityoldthingsnew https://blog.erratasec.com/2017/11/how-to-read-newspapers.html Errata Security: How to read newspapers News articles don't contain the information you think. Instead, they are written according to a formula, and that formula is as much about d... security how toerratareadnewspapers https://blog.erratasec.com/2010/11/i-was-just-detained-by-tsa.html?showComment=1290617596055 Errata Security: I was just detained by the TSA Today, I was detained by the TSA for about 30 minutes for taking pictures while going through security. Taking pictures is perfectly legal. ... errata securitydetainedtsa https://blog.erratasec.com/2016/02/weve-always-been-at-war-with-eastasia.html?showComment=1455640177568&m=0 Errata Security: We've always been at war with Eastasia Orwell's point in 1984 was that it's more than just government Though Police. The people themselves participate, willfully, in "double thi... errata securityalwayswar https://develop.fedscoop.com/radio/errata-securitys-robert-graham-on-securing-iot/ Errata Security's Robert Graham on securing IoT | FedScoop Feb 21, 2017 - Errata Security's CEO talks about the evolving security threats around IoT. errata securityrobert grahamsecuringiotfedscoop https://blog.erratasec.com/2015/09/yes-they-just-droned-hacker.html Errata Security: Yes, they just droned a hacker Many are disputing the story about a recent story about a drone strike that targeted the hacker TriCk from Anonymous group TeaMp0isoN . Th... errata securityyeshacker https://blog.erratasec.com/2012/05/tuning-linux-tcp-hash-entries.html?showComment=1338561204790 Errata Security: Tuning Linux: TCP hash entries Tuning Linux for scalable network applications is hard, partly because it's not documented anywhere. Or if it is, all the top Google results... errata securitytuninglinuxtcphash https://blog.erratasec.com/2007/06/niiiice.html?showComment=1190275800000 Errata Security: Niiiice... **PLEASE DO NOT POST A COMMENT IF ITS ABOUT SAFARI IN BETA** These bugs have been verified in the current PRODUCTION copy on OSX (Safari 2.0... errata security https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1597227120065&m=0 Errata Security: How The Intercept Outed Reality Winner Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ... errata securitythe interceptoutedrealitywinner https://blog.erratasec.com/2016/02/twitter-has-to-change.html Errata Security: Twitter has to change Today, Twitter announced that instead of the normal timeline of newest messages on top, they will prioritize messages they think you'll be i... errata securitytwitterchange https://blog.erratasec.com/2016/06/use-freakin-debugger.html?showComment=1466766533722 Errata Security: Use the freakin' debugger This post is by a guy who does " not use a debugger ". That's stupid. Using a friendly source-level debugger (Visual Studio, XCode, Eclipse)... errata securityusedebugger https://blog.erratasec.com/2010/04/vuln-disclosure-is-rude.html?showComment=1272134704374 Errata Security: Vuln Disclosure is Rude It's amazing that after all this time, our community has not come to grips with "vulnerability disclosure". Last weekend, a lot of people tw... errata securityvulndisclosurerude https://blog.erratasec.com/2016/06/etheriumdao-hack-similfied.html?showComment=1466589560213&m=0 Errata Security: Ethereum/TheDAO hack simplified The news in the Bitcoin world is the Ethereum/DAO hack. I thought I'd write up a simplified explanation. What is Bitcoin? I'm sure you... errata securityethereumhacksimplified https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496760990008&m=0 Errata Security: How The Intercept Outed Reality Winner Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ... errata securitythe interceptoutedrealitywinner https://blog.erratasec.com/2016/03/how-media-really-created-trump_26.html?showComment=1595588673105 Errata Security: How the media really created Trump This NYTimes op-ed claims to diagnose the press's failings with regard to Trump, but in its first sentence demonstrates how little press un... errata securitythe mediareallycreatedtrump https://blog.erratasec.com/2007/08/sidejacking-with-hamster_05.html?showComment=1193685960000 Errata Security: SideJacking with Hamster NOTE: you can download the program at http://www.erratasec.com/sidejacking.zip ; make sure to read the instructions. Others have done a be... errata securityhamster https://blog.erratasec.com/2009/05/star-trek-sucked.html?showComment=1256754182636 Errata Security: Star Trek Sucked Everyone else is going to love the new Star Trek movie, but not me. It's got great visuals, great casting, great acting, great editing, and... errata securitystar treksucked https://blog.erratasec.com/2007/03/hit-pieces-and-ethical-journalism.html?showComment=1174414620000 Errata Security: Hit-pieces and ethical journalism One of the under-appreciated problems in our industry is the "hit-piece", where a reporter twists facts and quotes to attack a victim. A goo... errata securityhitpiecesethicaljournalism https://blog.erratasec.com/2014/09/bash-shellshock-scan-of-internet.html?showComment=1411633663357 Errata Security: Bash 'shellshock' scan of the Internet NOTE: malware is now using this as their User-agent. I haven't run a scan now for over two days. I'm running a scan right now of the I... errata securitybashshellshockscaninternet https://blog.erratasec.com/2012/08/common-misconceptions-of-password.html?showComment=1346310671825 Errata Security: Common misconceptions of password cracking After this great article on passwords at Ars Technica, I've seen some common misconceptions pop up. I thought I'd clarify them (even though... errata securitycommon misconceptionspasswordcracking https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489574209119&m=0 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2020/05/securing-work-at-home-apps.html?showComment=1595302064386 Errata Security: Securing work-at-home apps In today's post, I answer the following question: Our customer's employees are now using our corporate application while working from home... work at homeerrata securitysecuringapps https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1301307389092 Errata Security: The Comodo hacker releases his manifesto Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb... errata securitycomodohackerreleasesmanifesto https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489302422469&m=0 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2007/12/things-to-do-on-christmas-break.html Errata Security: Things to do on Christmas break... things to do on christmaserrata securitybreak https://blog.erratasec.com/2009/05/how-to-measure-download-speed.html?showComment=1242275760000 Errata Security: How to measure download speed There are lots of "speed tests" websites that will measure your download speed, such as the ones provided DSLreports and SpeakEasy. Or, you ... security how toerratameasuredownloadspeed https://blog.erratasec.com/2007/01/george-ou-scores.html Errata Security: George Ou scores! http://blogs.zdnet.com/Ou/?p=400 George is awesome because he is by far one of the most technical reporters I have ever talked to. Its not o... errata securitygeorgeouscores https://blog.erratasec.com/2014/09/bash-shellshock-scan-of-internet.html?showComment=1411591892504&m=0 Errata Security: Bash 'shellshock' scan of the Internet NOTE: malware is now using this as their User-agent. I haven't run a scan now for over two days. I'm running a scan right now of the I... errata securitybashshellshockscaninternet https://blog.erratasec.com/2014/07/reading-xkeyscore-rules-source.html?m=1 Errata Security: Reading the XKeyScore-rules source Today's story is about "XKeyScore source code" leak. As an expert, I'm going to read through the code line-by-line and comment on it. Let'... errata securityreadingxkeyscorerulessource https://blog.erratasec.com/2017/09/people-cant-read-equifax-edition.html Errata Security: People can't read (Equifax edition) One of these days I'm going to write a guide for journalists reporting on the cyber. One of the items I'd stress is that they often fail to ... errata securitypeoplereadequifaxedition https://blog.erratasec.com/2012/06/confirmed-linkedin-6mil-password-dump.html?showComment=1339007540538&m=0 Errata Security: Confirmed: LinkedIn 6mil password dump is real Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for... errata securityconfirmedlinkedinpassworddump https://blog.erratasec.com/2008/05/apple-still-not-playing-nice-with.html Errata Security: Apple still not playing nice with researchers... http://www.theregister.co.uk/2008/05/22/unpatched_apple_bug_flap/ errata securityapplestillplayingnice https://blog.erratasec.com/2008/01/hexlore.html?showComment=1200947340000 Errata Security: Hex.lore If I ever get around to writing a computer book, one of the first I would write would be about the lore of hexadecimal. We teach children th... errata securityhexlore https://blog.erratasec.com/2012/06/confirmed-linkedin-6mil-password-dump.html?showComment=1339011712208&m=0 Errata Security: Confirmed: LinkedIn 6mil password dump is real Today's news is that 6 million LinkedIn password hashes were dumped to the Internet. I can confirm this hack is real: the password I use for... errata securityconfirmedlinkedinpassworddump https://blog.erratasec.com/2013/08/nsa-foia-fail-is-fail.html Errata Security: NSA FOIA fail is fail I blogged about my NSA FOIA response , and how it didn't even match my request. A guy "Cody" at DefCon showed me an even better response: ... errata securitynsafoiafail https://blog.erratasec.com/2007/06/amero-part-2.html?showComment=1181674380000 Errata Security: Amero, part 2 Brian Krebs has posted an update to the Julie Amero case (the teacher convicted of harming students by letting them see porn). Krebs also l... errata securitypart https://blog.erratasec.com/2012/08/no-hacker-really-does-mean-hacker.html?showComment=1344457834694 Errata Security: No, "hacker" really does mean "hacker" The earliest known use of "computer hacker" in the press described a criminal act: Many telephone services have been curtailed because of ... errata securityhackerreallymean https://blog.erratasec.com/2008/05/activex-is-dangerous.html?showComment=1210618500000 Errata Security: ActiveX is dangerous... UPDATE: AxBan can be downloaded from here . Any questions or comments can be directed to talksec@portal.erratasec.com . We all know ActiveX... errata securityactivexdangerous https://blog.erratasec.com/2014/02/c-programming-you-are-teaching-it-wrong.html Errata Security: C programming: you are teaching it wrong It's been three decades. There is no longer an excuse for the fail way colleges teach "C programming". Let me help. Chapter 1: the debug... errata securityyou areprogrammingteachingwrong https://blog.erratasec.com/2010/06/cyberwar-is-fiction.html?showComment=1275964986346 Errata Security: Cyberwar is fiction I'm reading various articles about the Russia's proposal, with support from the UN, for a " cyberwarfare arms limitation treaty ". What ast... errata securitycyberwarfiction https://blog.erratasec.com/2009/03/hamster-20-and-ferret-20.html?showComment=1302790245702 Errata Security: Hamster 2.0 and Ferret 2.0 I updated my Sidejacking tools Hamster and Ferret. You can get them from the site http://hamster.erratasec.com (or, if DNS hasn't propagate... errata securityhamsterferret https://blog.erratasec.com/2011/10/brookfield-properties-responds-re.html Errata Security: Brookfield Properties responds re: #OccupyWallStreet (For my complete report on the protest, click here .) The #OccupyWallStreet protest is in fact occupying Zuccotti Park , a private park ... errata securitybrookfield propertiesrespondsoccupywallstreet https://blog.erratasec.com/2008/01/new-quicktime-flaw-this-is-not-deja-vu.html Errata Security: New Quicktime Flaw, this is not Deja Vu No really. Its ANOTHER QuickTime flaw. It also involves RTSP . It was posted to Full Disclosure on Thursday afternoon. We have verified a c... errata securityis notnewquicktimeflaw https://blog.erratasec.com/2010/02/nehalem-vs-ids.html?showComment=1265423284736 Errata Security: Nehalem vs. IDS Intel's latest desktop processor is code-named "Nehalem". It adds a lot of good features for intrusion-detection software. I thought I'd sum... errata securitynehalemvsids https://blog.erratasec.com/2018/05/the-devil-wears-pravda.html Errata Security: The devil wears Pravda Classic Bond villain, Elon Musk, has a new plan to create a website dedicated to measuring the credibility and adherence to "core truth" of ... errata securitythe devilwearspravda https://blog.erratasec.com/2014/07/xkeyscore-regex-foo.html?m=1 Errata Security: XKeyScore: regex foo For those of you rusty on your regex code, I thought I'd explain those found in the alleged XKeyScore source . The first one is: / bridg... errata securityxkeyscoreregexfoo https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1489560850214&m=0 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2009/07/economist-on-kindle.html Errata Security: The Economist on the Kindle You can now get a subscription to the Economist on the Kindle (or Kindle readers on devices like the iPhone). Economics is the red pill . ... errata securitythe economistkindle https://blog.erratasec.com/2011/03/comodo-hacker-releases-his-manifesto.html?showComment=1602421805232 Errata Security: The Comodo hacker releases his manifesto Somebody claiming to be the "Comodo hacker" has released a statement here http://pastebin.com/74KXCaEZ , decompiled code here http://pasteb... errata securitycomodohackerreleasesmanifesto https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1496763381678 Errata Security: How The Intercept Outed Reality Winner Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ... errata securitythe interceptoutedrealitywinner https://blog.erratasec.com/2014/05/can-i-drop-pacemaker-0day.html?showComment=1403703138644 Errata Security: Can I drop a pacemaker 0day? Can I drop a pacemaker 0day at DefCon that is capable of killing people? Computers now run our cars. It's now possible for a hacker to i... errata securitydroppacemaker https://blog.erratasec.com/2016/11/the-false-false-balance-problem.html?showComment=1479860219406 Errata Security: The false-false-balance problem Until recently, journalism in America prided itself on objectivity -- to report the truth, without taking sides. That's because big debates ... errata securityfalsebalanceproblem https://blog.erratasec.com/2016/02/some-notes-on-apple-decryption-san.html?showComment=1455867231621 Errata Security: Some notes on Apple decryption San Bernadino phone Today, a judge ordered Apple to help the FBI decrypt the San Bernadino shooter's iPhone 5C. Specifically: disable the auto-erase that hap... errata securitysome notessan bernadinoappledecryption https://blog.erratasec.com/2018/11/brian-kemp-is-bad-on-cybersecurity.html?showComment=1541482085001 Errata Security: Brian Kemp is bad on cybersecurity I'd prefer a Republican governor, but as a cybersecurity expert, I have to point out how bad Brian Kemp (candidate for Georgia governor) is ... errata securitybrian kempbadcybersecurity https://blog.erratasec.com/2021/10/fact-check-that-forensics-of-mesa-image.html Errata Security: Fact check: that "forensics" of the Mesa image is crazy Tina Peters, the elections clerk from Mesa County (Colorado) went rogue, creating a "disk-image" of the election server, and posting that im... errata securityfact check https://blog.erratasec.com/2013/04/ap-hack-stock-market-did-not-plunge.html?showComment=1367522900125 Errata Security: @AP hack: the stock market did not "plunge" According to all press outlets, the stock market "plunged" today due to @AP getting hacked and reporting explosions at the White House. In... the stock marketerrata securitydid notaphack https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1597148072391&m=0 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2017/06/some-non-lessons-from-wannacry.html?showComment=1496891916309&m=0 Errata Security: Some non-lessons from WannaCry This piece by Bruce Schneier needs debunking. I thought I'd list the things wrong with it. errata securitynonlessonswannacry https://blog.erratasec.com/2008/01/more-sidejacking.html?showComment=1225637520000 Errata Security: More SideJacking Our sidejacking stuff was named one of the top 5 hacks of 2007 . Since then, we've noticed a few more things about it. To recap: websites ty... errata security https://blog.erratasec.com/2016/11/in-which-i-have-to-debunk-second-time.html?showComment=1478208902946 Errata Security: In which I have to debunk a second time So Slate is doubling-down on their discredited story of a secret Trump server. Tip for journalists: if you are going to argue against an e... errata securityhave to https://blog.erratasec.com/2016/12/iot-saves-lives.html Errata Security: IoT saves lives but infosec wants to change that The cybersecurity industry mocks/criticizes IoT. That's because they are evil and wrong. IoT saves lives. This was demonstrated a couple wee... errata securityiotsaveslives https://blog.erratasec.com/2009/03/hamster-20-and-ferret-20.html?showComment=1236805500000 Errata Security: Hamster 2.0 and Ferret 2.0 I updated my Sidejacking tools Hamster and Ferret. You can get them from the site http://hamster.erratasec.com (or, if DNS hasn't propagate... errata securityhamsterferret https://blog.erratasec.com/2008/10/errata-security-endorses-mccain.html?showComment=1225379400000 Errata Security: Errata Security endorses McCain The choice in this election is between a small or large left-ward shift. McCain is a moderate Republican, Obama is a radical Democract. A bi... errata securitymccain https://blog.erratasec.com/2015/07/more-proxyham-nonsense.html Errata Security: More ProxyHam stuff Somebody asked how my solution in the last post differed from the " ProxyGambit " solution. They missed my point. Just because I change the... errata securitystuff https://blog.erratasec.com/2017/03/some-comments-on-wikileaks-ciavault7.html?showComment=1600229405859 Errata Security: Some comments on the Wikileaks CIA/#vault7 leak I thought I'd write up some notes about the Wikileaks CIA "#vault7" leak. This post will be updated frequently over the next 24 hours. Th... errata securityon thecommentswikileakscia https://blog.erratasec.com/2007/08/sidejacking-with-hamster_05.html?showComment=1188527640000 Errata Security: SideJacking with Hamster NOTE: you can download the program at http://www.erratasec.com/sidejacking.zip ; make sure to read the instructions. Others have done a be... errata securityhamster https://blog.erratasec.com/2012/06/falsehoods-programmers-believe-about.html Errata Security: Falsehoods programmers believe about networks Inspired by falsehoods programmers believe about time and usernames , I thought I'd start collecting falsehoods programmers have about netw... errata securityprogrammersbelievenetworks https://blog.erratasec.com/2009/04/ssl-acceleration.html Errata Security: SSL acceleration This Slashdot article discusses building an SSL accelerator for $5k worth of hardware rather than $50k for a "hardware" accelerator like F... errata securitysslacceleration https://blog.erratasec.com/2014/09/bash-shellshock-bug-is-wormable.html?showComment=1411640799471&m=0 Errata Security: Bash 'shellshock' bug is wormable Early results from my scan: there's about 3000 systems vulnerable just on port 80, just on the root "/" URL, without Host field. That doesn'... errata securitybashshellshockbug https://blog.erratasec.com/2021/11/example-forensicating-mesa-county.html?showComment=1636444113783&m=0 Errata Security: Example: forensicating the Mesa County system image Tina Peters, the election clerk in Mesa County (Colorado) went rogue and dumped disk images of an election computer on the Internet. They a... errata securitymesa countyexamplesystemimage https://blog.erratasec.com/2016/10/yes-we-can-validate-wikileaks-emails.html?showComment=1477604021408 Errata Security: Yes, we can validate the Wikileaks emails Recently, WikiLeaks has released emails from Democrats. Many have repeatedly claimed that some of these emails are fake or have been modifie... yes we canerrata securityvalidatewikileaksemails https://blog.erratasec.com/2013/01/nytimes-and-more-rainbow-table-nonsense.html?showComment=1359697545217 Errata Security: NYTimes and more Rainbow Table nonsense Today's NYTimes article on how it got hacked is full of inaccurate information. Take, for example, this paragraph: While hashes make h... errata securityand morerainbow tablenytimesnonsense https://blog.erratasec.com/2017/06/how-intercept-outed-reality-winner.html?showComment=1604968757767 Errata Security: How The Intercept Outed Reality Winner Today, The Intercept released documents on election tampering from an NSA leaker. Later, the arrest warrant request for an NSA contractor ... errata securitythe interceptoutedrealitywinner https://blog.erratasec.com/2015/01/platitudes-are-only-skin-deep.html?m=1 Errata Security: Platitudes are only skin deep I overdosed on Disney Channel over the holidays, because of course children control the remote. It sounds like it's teaching kids wholesome ... errata securityskindeep