Showing posts with label Frequency X. Show all posts
Showing posts with label Frequency X. Show all posts

Tuesday, February 17, 2009

Worlds Top Vulnerability Discoverer


Who's the worlds most frequent discoverer (and discloser) of security vulnerabilities?

It's not not a name you're likely to be familiar with (sorry "best in the world" team ;-)

With a staggering number of 612 public vulnerability disclosures through to the end of 2008, sitting in pole position, is Luigi Auriemma. Luigi managed to oust r0t (finally) sometime last year. I think that the fact that r0t appears to have "retired" from the vulnerability discovery business probably helped.

For full stats and analysis, I've posted a more detailed blog over on Frequency-X -- Top-10 Vulnerability Discoverers of All Time (as well as 2008) - Who's in Pole Position?

Monday, January 26, 2009

Attack Coordination Using Social Networking Sites

With little doubt, the fastest growing and most influential Web 2.0 technology has been that of the Social Networking site. Sure, the concepts have been around for quite some time - harking back to the first dial-up BBS' of the 1980's - but the growth of sites like Facebook and MySpace is unheralded. The amount of time people now spend "Social Networking" has even overtaken the quest for porn (see the BBC's "Porn putting on its Sunday best").

Now, if you combine the facilities of social networking sites to coordinate large groups of people incensed by another group with tools that enable members to "donate some of their computers bandwidth", you can quickly develop massive "opt-in" DDoS systems.

The first component - the groups of incensed and motivated members - are already out there. Just look at the Facebook groups that sprung up backing either Israel or Hamas in the most recent conflict, or older groups such as the animal cruelty activists like "Stop Huntingdon Life Sciences Animal Cruelty".

The future of Social Network initiated/coordinated DDoS attacks is just around the corner (if it hasn't already happened in less-than-newsworthy cases already). Welcome to the birth of SDoS - Social network Denial of Service.

I posted a longer blog on the topic, along with the tools available to activist and social conscience groups - and some future threat motivations up on the IBM Frequency-X Web site.

Take a gander at "Social Network Denial of Service (SDoS)?" for more thoughts and analysis.

Tuesday, January 20, 2009

100 million transactions per month - largest data breach ever?

I don't normally cross-post, but I'm delving in to the Heartland Payment Systems data breach. With over 100 million transactions processed monthly (apparently), and the fact that the malware appears to have been sniffer-based, this will likely be the biggest data breach so far.

Credit to Heartland for dealing with it so well thus far (except maybe the possible obfuscation factor of waiting until Obama-day to release it).

I wrote a blog about the breach on Frequency-X earlier today -- Largest Data Breach So Far? Heartland Payment Systems.

The Washington Post has more background here (I wish I'd found it before I posted to Frequency-X...)

Monday, January 5, 2009

Week of (not my) Security Predictions for 2009

For a bit of fun I'm taking a look at the multitude of "2009 Security Predictions" which all the key security vendors and magazines have been pumping out over the last month and picking at them a little.

To make it a little more exciting I'm calling it the "Week of (someone else's) Security Predictions 2009". I've posted the first blog today, and I'll continue throughout the week - short of being hit by a bus or the X-Force blog crashing (again).

You can find the first days entry on Frequency X, where I've picked on Cisco's rather lame and unimaginative predictions (as newbies on the block, I guess they're just playing it safe).