Surviving the Week 8/3/12

HTML5 Top 10 Attacks

Last week at Blackhat, our team member Shreeraj Shah presented on threats against HTML5. The talk discussed the Top 10 Threats and Security.  If you missed unfortunately it, you can read the brief.  His whitepaper and presentation can be found here -
http://shreeraj.blogspot.in/2012/08/blackhat-2012-html5-top-10-threats.html

5 Takeaways From Vegas

Mr. Diaz from Kaspersky labs highlights 5 interesting talks from his Blackhat 2012 trip.  I have to agree that these were talks that with important security concerns for the future.  He did miss to point out Shreeraj Shah’s presentation, see above.

http://www.securelist.com/en/blog/208193749/5_takeaways_from_Las_Vegas

Dropbox confirms it was hacked, offers users help

I don’t think it is clear to say that Dropbox was hacked.  What is clear from the Dropbox investigation is that users use the same credentials across internet sites.  They reported that some 300 Dropbox accounts were compromised because credentials stolen from other website cracks were active on Dropbox.  Although this is a small number of accounts it does shed light on the problem of users with bad habits.  Correlation engines are becoming better all the time, look at Google, or Spokeo, for example.  Feeding cracked account information into correlation engines to find other patterns of account holders is key to exploiting an individual.  I give Dropbox two thumbs up for the mitigation strategies they are putting into place; two-factor authentication, active login history, and forced password changes.
http://news.cnet.com/8301-1009_3-57483998-83/dropbox-confirms-it-was-hacked-offers-users-help/

Temenos T24 R07.03 Authentication Bypass

Temenos is one of the world’s leading banking software vendors. An authentication bypass vulnerability was discovered in the password reset functionality because the application failed to properly enforce access control on the password reset functionality. Evidentially, Temenos knew of this vulnerability and released a patch, T24 R8.x.  NTOSpider could help software vendors to discover this type and other types of web app vulnerabilities.
http://packetstormsecurity.org/files/115127/temenos-bypass.txt

Media hype over security tools.  Not everything you read is true.

This is a great article about media over hyping security products/solutions. We’re all too familiar with those free subscriptions to industry magazines.  In some, we read really amazing reviews about solutions we might have tried before and which have completely failed in our environments.  Then you scratch your head and ask if it’s possible for the vendor to have paid for the review which funded your subscription.  The next article looks at media hype from a different perspective and how one media expert feeds other media experts to start a solution revolution.  Notice I didn’t say media and technology experts.
http://paranoia.dubfire.net/2012/07/tech-journalists-stop-hyping-unproven.html

 

 

Last updated by at .

About Dan Kuykendall

Dan Kuykendall is the CTO and Co-CEO at NT OBJECTives. Dan is a founder of NT OBJECTives and has been with the company for more than 10 years. He is responsible for the strategic direction and development of products and services and works closely with technology partners to make sure integrations are both deep and valuable. As a result of Dan’s dedication to security, technology innovation and software development, NTO application security scanning software is often recognized as the most accurate because of its sophisticated automation techniques. Dan joined NT OBJECTives from Foundstone, where he was responsible for the portal interface to the company’s flagship product, FoundScan. Prior to Foundstone, Dan was the founder of the Information Security team in the United States branches of Fortis. Dan is a regular blogger on web application security issues on ManVsWebApp.com and co-hosts An Information Security Place Podcast. His has presented on the topics of mobile and application security at many of the top security industry conferences such as ISSA (2011), B-Sides (2012-2013), OWASP AppSecUSA (2012), HouSecCon (2010-2012), ToorCon (2013) and THOTCON (2013). Dan has been involved with Web Application Security Consortium and is a regular contributor to many open source development projects including founding the RPM Builder, phpGroupWare and podPress projects. Connect with Dan on Google+

Leave a Reply

Your email address will not be published. Required fields are marked *