Thursday, February 27, 2003

Catweasel
Catweasel is a universal floppy disk controller that uses unmodified PC diskdrives. The Catweasel can handle nearly any disk format, you just have to find a drive for them. Normally, these drives are just 3.5 inch and 5.25 inch drives. PC floppy drives used to be known as being able to work with PC formatted disks only, but now you can access any of the disk formats listed further below.

Wednesday, February 26, 2003

CD Data Recovery
We are experts in recovery and repair of inaccessible, unreadable or deleted data, files, pictures, documents, or AutoCad® drawings etc., from optical storage media such as: CD-ROM, CD-R, CD-RW, DVD-RAM, DVD-R/W, DVD+R/W, 3-inch Mini CD-R., (Used in Mavica® MVC-CD1000 digital cameras), Home Audio Recording CDs, Compact Flash ™(CF), Smart Media ™ (SSFDC), Sony® memory sticks and PCMCIA ATA Cards.

Tuesday, February 25, 2003

The SPAM-L FAQ - Tracking Spam
This section deals with the technical aspects of spam, like telling where it came from. Having a UNIX shell account will be extremely helpful as a lot of the utilities are native to UNIX; however, you can perform most of these functions with other operating systems using third-party (usually shareware) tools, unlike UNIX, which comes with many of the tools mentioned already installed.
Reading Email Headers
This document is intended to provide a comprehensive introduction to the behavior of email headers. It is primarily intended to help victims of unsolicited email ("email spam") attempting to determine the real source of the (generally forged) email that plagues them; it should also help in attempts to understand any other forged email. It may also be beneficial to readers interested in a general-purpose introduction to mail transfer on the Internet.
Disk Splicing
Forensic Disk Splicing for Law Enforcement is designed to teach disk splicing techniques to law enforcement personnel who are already trained in computer forensics. The course teaches how to reconstruct 3.5 inch and 5.25 inch diskettes that have been cut, segmented, bent, torn, melted and/or (in the case of 3.5 inch diskettes) removed from the disk hub and recover data from the diskette.
Frontline Test Equipment
Frontline Test Equipment, Inc. is the leading provider of PC-based data communication protocol analyzers in the world. Our products are used by engineers and technicians who develop, test, install, maintain, and repair equipment and instrumentation that is interconnected by a variety of communication technologies.
Currently available products include asynchronous serial data analyzers, synchronous serial data analyzers, Bit Error Rate Testers (BERT), Ethernet protocol analyzers, Industrial Automation and SCADA communication protocol analyzers, Bluetooth™ protocol analyzers and Intelligent Traffic System (NTCIP) protocol analyzers.

Sunday, February 23, 2003

Stupid Security
We've all been there. Standing for ages in a security line at an inconsequential office building only to be given a security pass that a high school student could have faked. Or being forced to take off our shoes at an airport that can't even screen its luggage.
If you thought the accounting profession was bad news, just wait till you hear how stupid the security industry has become. Even before 9/11 a whole army of bumbling amateurs has taken it upon themselves to figure out pointless, annoying, intrusive, illusory and just plain stupid measures to "protect" our security.
It's become a global menace. From the nightclub in Berlin that demands the home address of its patrons, to the phone company in Britain that won't let anyone pay more than fifty pounds a month from a bank account, the world has become infested with bumptious administrators competing to hinder or harass you. And often for no good reason whatever.
The sensitive and sensible folk at Privacy International have endured enough of this treatment. So until March 15th 2003 we are running an international competition to discover the world's most pointless, intrusive, stupid and self-serving security measures.
How to protect yourself from snooping software
Beware: tiny software apps called adware or spyware may be tracking your behavior online right now. Don't like that idea? Robert tells you the best--and cheapest--way to get rid of these pests.
Fighting the enemy within
Fortunately, there is an answer to the risk of social engineering and the threats posed by employee use of company machines. Security policy automation, an emerging security software concept, removes many security risks by implementing a security policy across enterprise systems and consistently auditing and monitoring systems for compliance.
Security of Email
A PDF document.
Decimalisation Table Attacks for PIN Cracking
Two Cambridge University researchers have discovered a new attack on the hardware security nodules employed by banks that makes it possible to retrieve customers' cash machine PINs in an average of 15 tries. The attack takes advantage of a weakness in the cryptographic model used by many HSMs to encrypt, store and retrieve PINs. The system, used by many ATMs, reads the customer's account number that is encoded on the magnetic strip of the ATM card. The software then encrypts the account number using a secret DES key. The ciphertext of the account number is then converted to hexadecimal and the first four digits of it are retained. Those digits are then put through a decimalization table, which converts them to a format that's usable on the ATM keypad. By manipulating the contents of this table, it's possible for an attacker to learn progressively more about the PIN with each guess. Using various schemes described in the paper, a knowledgeable attacker could discover as many as 7,000 PINs in a half hour, the authors say.

Wednesday, February 12, 2003

Darik's Boot and Nuke
Darik's Boot and Nuke ("DBAN") is a self-contained boot floppy that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which makes it an appropriate utility for bulk or emergency data destruction.

Sunday, February 09, 2003

Physical Security Standards for Sensitive Compartmented Information Facilities
Physical security standards are hereby established governing the construction and protection of facilities for storing, processing, and discussing Sensitive Compartmented Information (SCI) which requires extraordinary security safeguards.

Thursday, February 06, 2003

The Great IDS Debate
Intrusion detection systems (IDS) have rapidly become a crucial component of any network defense strategy. Over the past few years, their popularity has soared as vendors have refined their results and increased performance capabilities. At the heart of intrusion detection systems lies the analysis engine. It reviews each packet, determines if it is malicious, and logs an alert if necessary – the core tasks of an IDS. Two different IDS techniques, each favored by separate and loyal camps, have emerged as the preferred engine behind the software. Despite the copious marketing material and fiery online debates, each method has distinct strengths and weaknesses. In this article, we'll examine and compare the two different techniques: signature analysis and protocol analysis.

Tuesday, February 04, 2003

LogAnalysis.Org
This is the new loganalysis.org! We're dedicated to pulling together a repository of useful information on log analysis for computer security.

Log Analysis is one of the great overlooked aspects of operational computer security. Many organizations spend hundreds of thousands of dollars on intrusion detection systems (IDS) deployments - but still ignore their firewall logs. Why? Because the tools and knowledge are often not there, or the tools that exist are too inconvenient. You should expect that to change. Right now, IDS vendors are up against the wall with the volumes of data they produce; the next wave in security is to try to usefully correlate and process the contents of multiple logs.

Monday, February 03, 2003

Macintosh Security Site
This site is devoted to the security of your Macintosh computer and the programs or servers you run on it. SecureMac started in February of 1999. Over the past years we have served thousands of people, helping them secure their networks and detect hackers.

On this site you will learn how to secure your Macintosh, detect any hackers present on it, while viewing the most reliable source of security related products, with extensive reviews and ratings evaluated by the top Macintosh security experts. We feel that to create a secure product, the product must be tested, explored, and look at thoroughly. Every product on SecureMac.com is evaluated to its fullest, from secure programming, concept and design. Every product is given a rating and explained in details, each developer or developing group is notified of any security issues or advisories before released to the public to ensure a safe transition for all of their users.
i-Catcher
i-Catcher is an innovative PC-Video integration package with sophisticated motion detection and alerting features. Originally devised as a security/surveillance product, i-Catcher is as successful in capturing wildlife images as it is in identifying intruders in your home or business.

In its simplest form i-Catcher is a single application that detects motion in a camera feed, then captures the images and posts them to a web site (look at these examples), or sends them via email (there is also an option for SMS alerting). The i-Catcher Wildlife and Sentry applications can also be connected to i-Catcher Console to provide network-wide monitoring of up to 255 cameras.
WinGrab
Freeware screen capture program for Windows 9x/Mill/NT4/Win2k

Sunday, February 02, 2003

chkrootkit
chkrootkit is a tool to locally check for signs of a rootkit.

Saturday, February 01, 2003

TightVNC: VNC-Based Free Remote Control Solution
TightVNC is a free remote control package derived from the popular VNC software. With TightVNC, you can see the desktop of a remote machine and control it with your local mouse and keyboard, just like you would do it sitting in the front of that computer.