Website data: (Actual information extracted from website) Meta title: TaoSecurity Meta description: Website needs meta description | This listing is not rated yet. Rate it! | Report it! TaoSecurity Blog http://taosecurity.blogspot.com Richard Bejtlich founded TaoSecurity to help clients detect, contain, and remediate intrusions using network security monitoring (NSM) principles. Category: Blog Directory » Computer Blogs » Security Hits: 3 Date added: 2006-03-30 21:51:18 Alexa traffic rank: 412,586 Site average load time: 1.718 Second(s) Fast Faster than 49% of websites Site language: EN Site encoding: WINDOWS-1252 |
TaoSecurity Blog Latest Posts
What Should Dan Have Done?
I answered a question on the Daily Dave mailing list, so now a few of you are asking "what should Dan have done?" about his DNS discovery. Keeping in mind my thoughts on keeping vulnerabilities in perspective, I have the following suggestions.Black Hat and/or Def Con should not be the place... Read more...
Published 5 hours ago
Vulnerabilities in Perspective
It's been nine days since Dan Kaminsky publicized his DNS discovery. Since then, we've seen a Blackberry vulnerability which can be exploited by a malicious .pdf, a Linux kernel flaw which can be remotely exploited to gain root access, Kris Kaspersky promising to present Remote Code Execution... Read more...
Published a day ago
Packet Anonymization with PktAnon
I noticed a new tool on Packetstorm recently: PktAnon by Christoph P. Mayer, Thomas Gamer, and Dr. Marcus Schöller. This tool seems powerful because you can apply a variety of anonymization policies based on settings you apply in an XML configuration file. It was easy to install the tool on... Read more...
Published a week ago
Robert Graham on TurboCap
I liked Robert Graham's post on CACE Technologies TurboCap. I don't necessarily think TurboCap is that exciting, but I learned a lot of tricks reading Robert's explanation of how to collect packets quickly for traffic inspection purposes. I've discussed some of them, like device polling on... Read more...
Published a week ago
Hint of Visibility in the Cloud
Visibility in the cloud is one of my concerns these days. When someone else hosts and processes your data, how can you tell if it is "secure?" I found Robert Graham's post Gmail now shows IP address log to be very interesting. Robert explains how Gmail using HTTPS doesn't always use HTTPS... Read more...
Published a week ago
Proposed Air Force Cyber Badge
The Air Force published New cyberspace career fields, training paths, badge proposed earlier this month. I found the proposed cyber badge to be interesting. From the story:The badge features: lightning bolts to signify the cyberspace domain; center bolts taken from the navigator badge and the... Read more...
Published a week ago
Thoughts on Latest Kaminsky DNS Issue
It seems Dan Kaminsky has discovered a more effective way to poison the DNS cache of vulnerable name servers. This is not a new problem, but Dan's technique apparently makes it easier to accomplish.One problem is we do not know exactly what Dan's technique is. He is saving the details for Black... Read more...
Published a week ago
Reviews of FreeBSD Books Posted
Amazon.com just published my four star review of BSD UNIX Toolbox: 1000+ Commands for FreeBSD, OpenBSD and NetBSD by Christopher Negus and Francois Caen . From the review:BSD Unix Toolbox (BUT) is a straightforward system administration book that could apply to many Unix-like operating systems.... Read more...
Published 2 weeks ago
Air Force Cyber Panel
Last month I participated in a panel hosted by the US Air Force. One of my co-panelists, Jim Stogdill, summarized some of the event in his recent post Sharing vs. Protecting, Generativity on DoD Networks. I'd like to add the following thoughts. Before the event most of the panelists met for... Read more...
Published 2 weeks ago
Making Decisions Using Randomized Evaluations
I really liked this article from a recent Economist: Economics focus: Control freaks; Are “randomised evaluations” a better way of doing aid and development policy?:Laboratory scientists peer into microscopes to observe the behaviour of bugs. Epidemiologists track sickness in populations.... Read more...
Published 2 weeks ago
Green Security
You all know how environmentally-conscience I am. Actually, I don't consider myself to be all that "green," aside from the environmental science merit badge I earned as a Scout. However, working for a global company (and especially the Air Force, in a prior life) reinforces one of my personal... Read more...
Published 2 weeks ago
Pascal Meunier Is Right About Virtualization
I love Pascal Meunier's post Virtualization Is Successful Because Operating Systems Are Weak:It occurred to me that virtual machine monitors (VMMs) provide similar functionality to that of operating systems...What it looks like is that we have sinking boats, so we’re putting them inside a... Read more...
Published 4 weeks ago