Apr 21 2006

What’s the point of security question?

You know what those “security questions” are. The ones that usually spell something like “what is your mother’s maiden name?” or “which city were you born?” They are usually required when you sign up a service. What were they for? It appears that some services use it for verification to reset your password, in situations [...]

Mar 8 2006

Mac OS X Locally Exploited in 30 Minutes

MacRumours reports a Mac OS X box hacked in 30 minutes in a competition. Sounds like a local exploit to me, as hackers are free to create shell accounts on the box, although it tells nothing about how remotely-exploitable Mac OS X is. However (1) a local exploit with privileged escalation is still an exploit [...]

Jan 6 2006

Microsoft released WMF patch

Microsoft has finally released security patch to a vulnerability in reading Windows Meta File (WMF). Hurry up! Run, download and apply this patch (if you haven’t got yourself infected). Unless you are running Mac or Linux of course :)

Sep 1 2005

Google Talk Account Locked

This morning when I tried to sign on with Google Talk, a warning message popped up saying “You account has been locked“, and asked me to go to Google’s website to unlock my account. As I have been reading too much AdSense forum on WebmasterWorld lately, my immediate reaction was “uh-oh“. I thought Google has [...]

May 27 2005

Ecryption = Guilty!

Via B. Schneier, a pedophile was convicted, and existence of PGP on his desktop is one evidence. That guy is guilty regardless, but now the verdict is – if you have something to hide, you might be guilty! Better go and Rot26 all my world domination plans.

Dec 22 2004

Worm Attacking phpBB

I know it is going to come sooner or later, but now there is a wide-spreading worm that attacks vulnerable phpBB installations, by exploiting its now infamous “highlight” bug prior to 2.0.10. It overwrites every .php file found on your system, which makes a quite big mess. I patched the only copy of phpBB installed [...]

Dec 14 2004

Schneier on Securing Your PC

Brice Schneier talked about how one should secure your own personal computer against uninvited intruders from the Internet. Many pure gold here, straight from one of the best security experts in the field. You might think of it as being too paranoid, but these tips might save your life one day.

Dec 9 2004

Secunia and Browser Window Injection

Saw it on /. Multiple Browsers Window Injection Vulnerability Test. Secunia claimed that all most modern browsers are vulnerable to this attack, which allows another site to replace the URL of a popup window in a legitimate site. For example, go to a bank site, click on the link to popup the login window, and [...]

Nov 2 2004

Virus & Social Engineering

As Bruce Schneier has shown in an email he has received, virus cannot spread effectively without clever social engineering. It does not work, however, when you are the one and only person in your own domain’s support team.

Jan 11 2004

A recent Postfix log on spamming attempt

I have received the following logs on my mail server regularly over the last 2-3 months, showing attempts of spammers trying to send me a junk mail. The log is generated by Postfix automatically, and send to my postmaster box.

Jul 28 2003

My PGP Keys

Well. I am not revealling my private keys so that you can read my previous post. However, somehow I felt that I might need to put my public PGP keys somewhere on this blogsite, so that in case you need to send me encrypted emails or verify my signatures, you would be able to do [...]

Jun 9 2003

What?! EveryDNS Got Hacked Again

EveryDNS, the free DNS provider that I have used for two of my domains, was under DDoS attack back in February this year. It took a few days to recover from the downtime, and many people who have hosted their domains on EveryDNS suffer as result. Unfortunately this seems to be happening again. This morning [...]

Feb 27 2003

EveryDNS Is Under DDoS Attack

The saga continues from the story yesterday… Last night at around 10′ish, I thought EveryDNS has already been fixed because I can now see their website and use their web interface to modify my DNS configuration. I woke up this morning, and found some of my spooled emails still cannot be sent because source domain [...]