• Anonymous Releases Very Unanonymous Press Release

    Today, December 10th, Anonymous, an Internet gathering, released a press release which you can read below. In it, a description is provided of what Anonymous is about, what Operation Payback is, and where the media is getting it wrong. Also in it, its author forgot to remove his name in the pdf’s Meta information.

  • Paypal Sender Country XSS

    A new XSS vulnerability was identified on Paypal.com earlier today, found by d3v1l and disclosed on both Security-Shell and XSSed. The problem is with the parameter sender_country in a transaction called nvpsm.

  • Turning an ATM into a Slot Machine

    In a talk originally slated for last year before it was muffled by Juniper based on the concerns of “an affected ATM vendor”, Jack demonstrates what he calls jackpotting an ATM.

  • Persistent XSS on Twitter.com

    Twitter user 0wn3d_5ys has demonstrated a persistent cross site scripting (XSS) vulnerability he found on June 21st using his own Twitter account (visit at your own risk) that appears to be due to a lack of input validation of the application name field when accepting new requests for Twitter applications.

  • The “Aurora” IE Exploit Used Against Google in Action

    The big news hit earlier this week, the attack vector that allowed bad actors presumably from China into the networks of Google, Juniper, Adobe, and some 30 other firms was an Internet Explorer zero day, a use after free vulnerability on an invalid pointer reference affecting IE 6, 7, and 8 but only used in IE 6 according to Microsoft.

Scareware Purveyors, Spammers, and Crooks Take Advantage of Haiti Earthquake

Scareware Purveyors, Spammers, and Crooks Take Advantage of Haiti Earthquake

Bad actors have taken advantage by engaging in search engine poisoning including taking over existing web sites, using techniques that boost search ranking, and installing

Jan 14, 2010 | 1 comment | View Post
Baidu.com the Latest Victim of Iranian CyberArmy

Baidu.com the Latest Victim of Iranian CyberArmy

A group called the Iranian Cyber Army has, fresh off the heels of their DNS attack on Twitter last month, hijacked the domain of

Jan 11, 2010 | 28 comments | View Post
JUNOS (Juniper) Flaw Exposes Core Routers to Kernel Crash

JUNOS (Juniper) Flaw Exposes Core Routers to Kernel Crash

A report has been received from Juniper at 4:25pm under bulletin PSN-2010-01-623 that a crafted malformed TCP field option in the TCP header of a

Jan 06, 2010 | 20 comments | View Post
Forensics: Beverages Aside, A Look at Incident Response Tools

Forensics: Beverages Aside, A Look at Incident Response Tools

In November, Microsoft's forensics tool called COFEE (Computer Online Forensic Evidence Extractor) was leaked on torrents for download. The news coverage was much hype

Dec 15, 2009 | 8 comments | View Post
  • Incident Response

  • The Anonymous PR Guy and a Greece Connection

    The Anonymous PR Guy and a Greece Connection

    The PDF's raw creation date further points to the Anonymous Press Release from yesterday being created in Greece, which happens to be the homeland of a graphic artist with the same name as the pdf's author field, Alex Tapanaris.

    Dec 11, 2010 | 12 comments | View Post

  • WinPE 3.0 & Forensics

    WinPE 3.0 & Forensics

    It is a common task for an investigator to boot a machine using bootable media in the form of DVD or USB and there are countless options available. This tutorial is not intended to replace your favorite Helix CD or

    Apr 12, 2010 | 20 comments | View Post

  • Reactivating DECAF in Two Minutes

    Reactivating DECAF in Two Minutes

    The misinformation on DECAF being shut down and a hoax is alarming and the quality of reporting on this security topic actually worse than usual. Earlier tonight we noticed this update from @slashdot on Twitter: "DECAF Was Just a

    Dec 18, 2009 | 28 comments | View Post

  • Other Recent Articles

  • The banner users were presented after the URL they visited redirected.

    DHS incorrectly associates 84,000 web sites with child pornography

    DHS Security Immigrations and Customs Enforcement incorrectly knocked out some 84,000 web sites attempting to seize domain names associated with child pornography, then glossed over the fact that it happened.

    Feb 17, 2011 | 3 comments | View Post

  • Ligatt Rap

    Ligatt Rap

    Security researcher Chris John Riley has decided to respond to death threats and lawsuits from Georgia security consultancy Ligatt and its proprietor Gregory Evans, but not in kind. Instead he’s written and recorded a rap song:

    Feb 11, 2011 | 3 comments | View Post

  • Colbert Explains Cyberwar

    Colbert Explains Cyberwar

    On the Colbert Report, host Stephen Colbert provided some background on “the First Great Cyberwar” as the hacktivist collective Anonymous has dubbed it, the “Defend Assange” sub-mission of Operation Payback.

    Dec 16, 2010 | 2 comments | View Post

  • Anonymous Turns Operation Payback Toward “The Jester”

    Anonymous Turns Operation Payback Toward “The Jester”

    The Jester, a hacktivist who is normally known for short term denial of service attacks against Jihadist web forums and who recently claimed responsibility for an outage at Wikileaks in the middle of Cablegate (Wikileaks publication of U.S. diplomatic cables) has himself become the target of the large scale hacktivist protest called Operation Payback.

    Dec 10, 2010 | 44 comments | View Post