Bash Shellcode truth

There are two Common Vulnerability and Exposure CVE-2014-6271 and CVE-2014-7169   Akamai has posted it’s response CERT has posted it’s vulnerability Note Red Hat has developed the following test: $ env x='() { :;}; echo vulnerable’ bash -c “echo this is a test” RedHat Blog also discusses it and has set up a FAQ Updating Bash on … Read more

Cyber -Crime is big business – and it is living right next to you.

NTVUganda story   Don’t look at the details of McKinnon and his extradition battle etc.  (picture also from NTVUganda.co.ug) This is what is important: “Kenya’s Cabinet Secretary for Information Fred Matiang’i estimates that the country lost nearly Ksh2 billion ($22.56 million) to cyber crime, with close to 1,000 Kenyans falling victim to Internet fraud on … Read more

OWASP has new Testing Guidelines Document

    OWASP Testing Guidelines 2014  In software development there are 5 stages: Define, Design, Develop, Deploy, and Maintain.   OWASP released some more overall testing methodology.  When to test is the question?  Ideally one tests at all stages of the SDLC (Software Development Life Cycle). But where is it most optimal to test? If … Read more

Antivirus software “dead” or does not find all viruses

Internet Storm Center has some more discussion The bottom line is Symantec has said its software products can only catch 50% or so of the viruses out there. PCMag says so what: http://securitywatch.pcmag.com/security/323419-symantec-says-antivirus-is-dead-world-rolls-eyes The comments gave a couple of good links(which I captured a couple of images from): http://www.av-comparatives.org/comparatives-reviews/ http://www.av-test.org/en/news/ So one can test the Anti-Virus … Read more