skip to main | skip to sidebar

.:[ Layered Security ]:.

"Those who cannot remember the past, are condemned to repeat it..."

Friday, November 14, 2008

Rovio - just in time for Christmas!

















Read more...

Newer Post Older Post Home
Bryce Galbraith
(Numerous letters here...)

Layered Security
bryce{at}layeredsec.com

SANS Institute BIO
LinkedIn Profile

Follow brycegalbraith on Twitter

Contributing Author

Contributing Author

Authored/Co-Authored SANS Courses

SEC660 - Advanced Penetration Testing, Exploits, and Ethical Hacking
www.sans.org

National Debt Clock

This can't end well...

"Any society that would give up a little liberty to gain a little security will deserve neither and lose both." -- Benjamin Franklin

"There's a war out there, old friend. A world war. And it's not about who's got the most bullets. It's about who controls the information. What we see and hear, how we work, what we think... it's all about the information!"

"The world isn't run by weapons anymore, or energy, or money. It's run by little ones and zeroes, little bits of data. It's all just electrons."

-- Cosmo from, "Sneakers" (1992)

OSF Data Loss - Latest Incidents

Loading...

Toolz

  • Aircrack-ng
  • AlternateStreamView
  • Anonymizer
  • Anubis - Malware analysis
  • BackTrack
  • BCWipe
  • BeEF - Browser Explotation Framework
  • BinText
  • BotHunter
  • Browser Rider
  • BrowserSpy
  • Burp Suite
  • BVSystems (wireless gear)
  • Cain & Abel
  • CellCrypt
  • Certificate Patrol (Firefox Add-on)
  • Cheat Sheets
  • Command-line Fu
  • Command-line Kung Fu
  • DansGuardian
  • DBAN - Darik's Boot and Nuke
  • Deep Freeze
  • DEFCON Toolz
  • DNS Advisor Pro
  • DNSViz
  • DomainTools
  • DumpSec
  • Echo Mirage
  • Edge Security Tools
  • ElcomSoft
  • Emerging Threats (Snort Sigs)
  • Ettercap
  • ExifTool
  • ExifTool GUI
  • Exploit Database
  • Exploit-Me
  • Ferret and Hamster
  • FireBug
  • Firesheep
  • Firewall Builder
  • Flexi Spy
  • FOCA Online (search metadata in files)
  • Forensic Acquisition Utilities
  • Free Rainbow Tables
  • Free Rainbow Tables
  • GFI LANGuard
  • Google Hacking Database (GHDB)
  • Google Sets
  • GPO Extensions (3rd party)
  • Hacme Web Apps
  • Hashcat
  • Hiren's BootCD
  • inSSIDer
  • IP Blocks by Country
  • IPv6 Tunnelbroker
  • IronKey
  • IRS
  • ISR-Evilgrade
  • Karmasploit
  • Katana
  • Kon-Boot (password reset tool)
  • L0phtCrack
  • Layer Four Traceroute
  • Linux Command References
  • Live Sysinternals
  • Macshift
  • Mallory (mitm tool)
  • Maltego
  • Malware Bytes
  • memoryze
  • MetaSploit
  • Metasploit Decloaking Engine
  • MMC
  • Nemesis
  • Netdude
  • Netifera
  • NetMon
  • netsh
  • NetWitness Investigator
  • Nikto
  • NirSoft - freeware utils
  • NMap
  • Notepad++
  • NoVirusThanks
  • Offensive Security Exploit Archive
  • Open Source Security Information Management
  • OpenDNS
  • Ophcrack
  • OSSEC
  • PacketLife.net Armory of Toolz
  • Pass-the-Hash Toolkit
  • pathping
  • Pentest Labs: Network Penetration Lab
  • Pentest Labs: Web Application Edition
  • Pipl
  • PortableApps
  • Proxy Strike
  • PWDumpX
  • py2exe
  • Radmin
  • Rainbow Tables (web interface)
  • RainbowCrack
  • raWPacket
  • Reaver (WPS/WPA cracker)
  • Recuva - File Recovery
  • RedCurtain
  • reDuh
  • Robotex
  • RootKits (Unix)
  • RootKits (Windows)
  • saminside
  • Samurai Web Testing Framework
  • Scapy
  • Screen command (Unix)
  • Search Engine List
  • Secunia PSI
  • Security Focus Bug Database
  • ServerSniff
  • Sigcheck
  • SiteDigger
  • SNScan
  • Sociel-Engineer's Toolkit (SET)
  • Splunk
  • Spoof Card
  • SQL Cheat Sheets
  • sqlmap
  • SQLScan v1.0
  • sslsniff
  • sslstrip
  • STerm
  • Sulley
  • SuperScan v4.0
  • SysInternals Tools
  • System Explorer
  • tcpreplay
  • tcpxtract
  • TextPad
  • The Cassandra Tool
  • ThrashLM
  • ThreatExpert (automated malware analysis)
  • Top 100 Network Security Tools
  • TrapCall
  • TrueCrypt
  • Ubuntu Man Pages
  • UNetbootin
  • Unix Utils for Windows
  • URLVoid
  • VMMap
  • VMWare ThinApp
  • VoIP Hopper
  • Volatility Framework
  • Volatility Framework Plugins
  • WarVOX
  • Web Application Attack Framework (W3AF)
  • Web Application Testing
  • Web Historian
  • WebHistorian
  • Webtunnel
  • Wepawet - web-based malware analysis
  • WEPBuster
  • WhoIsHostingThis.com
  • Wigle
  • WillHackForSusi
  • Windows Power Shell
  • Windows XP Commands
  • winexe
  • WirelessKeyView
  • wlan2eth
  • WMAP
  • WMIC
  • Wordlist Generator
  • Wordlists (1)
  • Wordlists (2)
  • Wordlists (3)
  • Wordlists (4)
  • Wordlists (5)
  • Wordlists (6)
  • Wordlists (7)
  • Wordlists (Millions of words)
  • Wordlists (US Citites)
  • XSSF
  • Yersinia

Links

  • A "Grey Hat" Guide
  • Anti-Rookit
  • Bitpipe.com
  • Black Hat
  • BlackViper
  • Browser Security Handbook
  • Center for Internet Security
  • Cryptography Portal (Wikipedia)
  • Cybercrime.gov (US DoJ)
  • Dark Operator
  • Data Loss Database
  • Dataloss Database
  • Deal Extreme
  • DEFCON
  • DISA
  • DistroWatch
  • DoD Cyber Crime Center
  • EventID
  • Great quote
  • Hakin9 Magazine
  • Integrity Global Security
  • Market Share
  • Milw0rm
  • Mitre's Measurable Security
  • NewsNow (31000+ news sources)
  • NIST Computer Security Division
  • OSF Data Loss Database
  • Packet Storm
  • Packetstan
  • Privacy is Dead - Get Over It (Part I)
  • Privacy is Dead - Get Over It (Part II)
  • Process Library
  • RFID (1)
  • RFID (2)
  • SANS - Consensus Audit Guidelines (CAG)
  • SANS - Securing The Human
  • SANS 20 Critical Security Controls
  • SANS Computer Forensics
  • SANS Information Security Buyers Guide
  • SANS Institute
  • SANS Internet Storm Center
  • SANS Top 20
  • SANS Top 25 Programming Errors
  • SANS Top Twenty Critical Controls for Effective Cyber Defense: Consensus Audit
  • Secunia
  • Security Laboratory: Thought Leaders
  • TaoSecurity
  • The Ethical Hacker Network
  • The Evolution of the Web
  • The Honeynet Project
  • User Account Control Explained
  • VirusTotal
  • VulnerabilityAssessment.co.uk
  • White Wolf Security
  • Wikileaks

Articles & How To's

  • Backtrack 4 Tutorials
  • Black Hat Archives
  • Covert Channels
  • DEFCON Archives
  • Erasing hard drives
  • Google Guide Quick Reference
  • Hacking demo videos (John Strand)
  • How to setup a secure web tunnel
  • IDA Pro Book
  • Identifying Load Balancers in Penetration Testing
  • Injecting Meterpreter into Excel files
  • Linux From Scratch
  • Lock picking issues
  • Metasploit Unleashed (free training)
  • Metasploit's route pivot
  • NTLMv2 - Demystified
  • Pass-the-hash with Meterpreter
  • Port-redirection how-to
  • SecurityTube - security videos
  • Simultaneous Sniffing of Multiple 802.11b Channels with Kismet
  • Social-Engineer.org
  • Wirelessdefence.org

Conferences

  • Black Hat
  • CanSecWest
  • ChicagoCon
  • CONFidence
  • DEFCON
  • DOJOCON
  • FOSE Expo (#1 Gov contractor expo)
  • Hack In The Box
  • Hacker Halted
  • RSA
  • SECurity Organizer & Reporter Exchange
  • ShmooCon
  • SOURCE
  • SyScan
  • ToorCon

Useful Stuff

  • 10 add-ons for Firefox: Privacy and security
  • 7 Steps to a Pain-Free Life: How to Rapidly Relieve Back and Neck Pain
  • Acronym Finder
  • AV Test
  • BetterPrivacy (deletes "super cookies")
  • Bluecoat's K9 Web Protection (free)
  • Browser Security Test
  • Cellphone radiation info
  • Data Execution Prevention
  • Evernote
  • FreeMind
  • FreeNAS
  • Geekonomics: The Real Cost of Insecure Software
  • Gethuman Database
  • Google Blog Search
  • Google Body Browser
  • Google Book Search
  • Google Reader
  • How to save your keyboard after a spill
  • HTTPS Everywhere Firefox Add-on
  • IIS 7.0 Config Ref
  • Inbox Zero Presentation
  • KeePass Password Safe
  • Kindle
  • LIFE photo archive by Google
  • Lifehacker
  • Linux Directory Structure
  • MindMapper
  • National Do Not Call Registry
  • No more lower back pain!
  • OptOutPrescreen
  • P90X iPhone App
  • P90X Workout
  • Packetlife.net packet captures
  • Power plugs around the world
  • Quotations Page
  • SANS Buyers Guide
  • SpaceMonger
  • Stay Safe Online
  • TRX Suspension Trainers
  • US Constitution
  • US Debt Clock
  • US Public Debt
  • Use Bluetooth headsets to make VoIP calls on your computer
  • Username Check
  • Virus Bulletin
  • Wall outlet w/ USB ports
  • Wireless Spectrum (PDF)
  • Wireless Spectrum (PNG)
  • Zimbra
  • ZoomIt

Just for Fun

  • "Series of Tubes"
  • Apple - control freak
  • Best Tech Guy Caller
  • Best-ever cease and desist!
  • Brian Regan (comedian)
  • Bubble Wrap
  • Certified Application Security Specialists
  • Despair, Inc.
  • DIY Demotivator
  • Larry David - How to Handle Annoying Bluetooth Guys
  • Let Me Google That For You (lmgtfy)
  • Pandora
  • PicLens
  • R2D2 Projector
  • Sheepdog conspiracy
  • Surprised Kitty
  • Tech Supoort Cheat Sheet
  • ThinkGeek
  • White Hat Hacker Man
  • Will it blend?
  • ¡ʇı dılɟ

Blog Archive

  • ►  2011 (46)
    • ►  July (1)
      • Resistance is futile - moving to Twitter...
    • ►  April (6)
      • **MISSING IMAGES**
      • Hacker 'handshake' hole found in common firewalls
      • USPS.gov Website Infected with Blackhole Exploit K...
      • Recreating the Legendary Commodore 64
      • How is SSL hopelessly broken? Let us count the way...
      • What Location Tracking Looks Like
    • ►  March (3)
      • Mozilla regrets keeping quiet on SSL certificate t...
      • 2010: The year of the hacker
      • Can Data Stored on an SSD Be Secured?
    • ►  February (11)
      • Black Ops: How HBGary wrote backdoors for the gove...
      • FBI Pushes for Surveillance Backdoors in Web 2.0 T...
      • Global Energy Industry Hit In “Night Dragon” Attac...
      • International Monetary Fund (IMF) calls for a US D...
      • Egypt's Assault on the World-Wide Web
      • Nmap 5.50 released! (major update)
      • Microsoft says RIP Windows XP AutoRun
      • TSA Told To Tell Children That Groping Them Is A G...
      • Pwn2Own lets Chrome in, after all
      • EFF Uncovers Widespread FBI Intelligence Violation...
      • As Egypt goes offline US gets internet 'kill switc...
    • ►  January (25)
      • Interesting virtual machine escape hacking demo vi...
      • Passenger cleared after TSA checkpoint stare-down ...
      • US cyberwar firing range to demo by July
      • Erasing drives should be quick and easy
      • Apple Plans Service That Lets IPhone Users Pay Wit...
      • WSJ - What They (Smart phone apps) Know
      • Abine - Privacy Suite
      • Wall Street Journal: What They Know
      • IPv4 Exhaustion Report
      • Wikileaks volunteer detained and searched (again) ...
      • 7 Cyber Crime Facts Executives Need to Know
      • One-Third of All Malware in Existence Appeared in ...
      • Google Goggles Solves Sudoku Puzzles
      • Text Message of 'Death' Threatens Phone Security
      • $1.5 billion "Spy Center" under way
      • Demo of CANVAS owning Android phone
      • Special Webcast: A Taste of SANS Security 660 - Ad...
      • Online anonymity will come as standard on a Tor ro...
      • Add Google SSL Search Provider to Firefox Search B...
      • Is Google poised to take over NFC-based mobile pay...
      • Softbank brings NFC payment technology to iPhone 4...
      • The Stripping of Freedom: A Careful Scan of TSA Se...
      • What is Traitorware?
      • Android Mobile Malware Has Botnet-like Traits
      • Hotmail Data Loss Reveals Cloud Trust Issues
  • ►  2010 (194)
    • ►  December (43)
      • Abbreviation Fail ;-)
      • Google Chrome for business released
      • IE Blows Away Rivals in Browser Security
      • Google adds site hacking notifications in search r...
    • ►  November (34)
    • ►  October (5)
    • ►  September (17)
    • ►  August (1)
    • ►  July (14)
    • ►  June (9)
    • ►  May (8)
    • ►  April (14)
    • ►  March (10)
    • ►  February (20)
    • ►  January (19)
  • ►  2009 (261)
    • ►  December (9)
    • ►  November (35)
    • ►  October (36)
    • ►  September (26)
    • ►  August (9)
    • ►  July (26)
    • ►  June (7)
    • ►  May (41)
    • ►  April (13)
    • ►  March (13)
    • ►  February (32)
    • ►  January (14)
  • ▼  2008 (231)
    • ►  December (35)
    • ▼  November (83)
      • System Explorer
      • Guided sniper round
      • "Long-Range" RFID readers being used at border cro...
      • memoryze - memory forensics tool
      • Major IP Addresses Blocks By Country
      • Linux on the iPhone
      • Secunia Personal Software Inspector (PSI) - Versio...
      • This speaks volumes, doesn't it?
      • A "Grey Hat" Guide
      • “Browser Rider” - browser hacking framework
      • Metasploit and WMAP
      • Spy Coins - smuggle data inside coins
      • PLA armor brigade exercise fails due to computer v...
      • Police Cars To Transmit Real-Time Video
      • PDFs are harmless, right??
      • Process Explorer v11.3 Released
      • Do AntiVirus Products Detect Bots?
      • NetWitness Investigator (free download)
      • Memory Forensic Acquisition and Analysis 101
      • FOIA docs show feds can lojack mobiles without tel...
      • Pushing the Limits of Windows: Virtual Memory
      • Pushing the Limits of Windows: Physical Memory
      • Military's ban of USB thumb drives highlights secu...
      • Kindle: Amazon's Wireless Reading Device
      • Mercedes-Benz previews new internet-based command ...
      • ¿¿ǝƃuɐɹʇs ƃuıɥʇʎuɐ ƃuıɔuǝıɹǝdxǝ ǝslǝ ǝuoʎuɐ sı
      • LIFE Photo Archive available on Google Image Searc...
      • NVIDIA Tesla Makes Personal SuperComputing A Reali...
      • Secure OS Gets Highest NSA Rating, Goes Commercial...
      • Cheat Sheets: Where have these been all my life!?
      • Russian spy in Nato could have passed on missile d...
      • New RFID SD Card for Mobile Market Unveiled
      • Real-time Steganography with RTP
      • Exploiting Tomorrow's Internet Today Penetration T...
      • RedCurtain - Discover suspicious binaries
      • flowgrep
      • BotHunter
      • Emerging Threats
      • Hacking the Pyramid mystery.
      • Hosting Locations of the Million Busiest Websites
      • Internet Hacker Attacks at an All-Time High
      • Hacker accesses 344,000 UF dental patient records
      • Encrypting hard drives on their way
      • Will an iPhone blend?
      • Malware Forensics: Investigating and Analyzing Mal...
      • User Account Control - explained
      • SANS Security West 2009 - Las Vegas, NV
      • RedSeal Systems
      • "Understanding the WPA/WPA2 Break" Webcast featuri...
      • "Scratch Input" used as new input mechanism?
      • Chinese hackers hit International Monetary Fund
      • In a New History of NSA, Its Spies' Successes Are ...
      • SuperSpeed USB 3.0 to be Formally Unveiled Next Mo...
      • Intrepid iPhone developers bypass security for fun...
      • Apple issues 11 security updates for Safari browse...
      • American Airlines first to offer iPhone mobile boa...
      • I wonder how many hits this gets...
      • Rovio - just in time for Christmas!
      • Writing malicious macros using Metasploit
      • The world’s most super-designed data center – fit ...
      • World's Most Powerful Computer
      • Pentagon Clears Flying-Car Project for Takeoff
      • Google reveals wireless hopes in a patent
      • Malware exploits Background Intelligent Transfer S...
      • Wi-Fi Internet access under light fixtures could s...
      • Boffins publish hack for world's most popular smar...
      • Test Shows Shortcomings of Antivirus Programs
      • Top NSA Scribe Takes Us Inside The Shadow Factory
      • New Software Duplicates Keys With Photo Taken From...
      • Microsoft Security Intelligence Report (SIR)
      • Undetectable data-stealing trojan nabs 500,000 vir...
      • Visa trials PIN payment card to fight online fraud...
      • Chinese hackers turn PCs into zombies with MS08-06...
      • 2009 Security Predictions - by Stephen Northcutt a...
      • FBI: Several nations eyeing U.S. cyber targets
      • Air Force Base Deploys Wi-Fi/GPS RFID System Acros...
      • Woman out $400K to 'Nigerian scam' con artists
      • When Malware Attacks (Anything but Windows)
      • KARMA + Metasploit 3 == Karmetasploit
      • Battered, but not broken: understanding the WPA cr...
      • Chinese hack into White House network
      • TrueCrypt 6.1 Released
      • Google Book Search
    • ►  October (21)
    • ►  September (44)
    • ►  August (13)
    • ►  July (12)
    • ►  June (4)
    • ►  May (4)
    • ►  April (1)
    • ►  March (8)
    • ►  February (6)