Sunday, January 11, 2015

Vupen Security

Vupen, a French information security company, were seen in a search that found my website.

Is this a coincidence that there is major news coming out of France relating to the Charlie Hebdo Attacks?

My pages have been updated.

Vupen sell the information that they find to law enforcement and intelligence agencies which use them to achieve both defensive and offensive cyber-operations

Who knew what when and how should we all react to this.

Saturday, January 3, 2015

The FBI don't seem to have a clue

They still seem to think that the North Korean's are behind the Sony Hack.

It is also strange that my page on who the FBI think are Cyber Criminals was also accessed.

Monday, December 22, 2014

Cyberwarfare threats made using Reddit and Pastebin

The threats (supposedly) made by the North Koreans to Sony were reported to have been posted on Pastebin. What I don't understand is how this relevant to the legitimacy of the threat.

There seems to be a disconnect between reporting by the press and the source of the material that is used to support the claims. While most of the discourse relating to hacking and Cyber-crime-warfare-terrorism seems to take place on Social Media platforms, the "main-stream" media outlets, newspapers and TV, seem to give Internet sites more credibility than they should.

I can't see why we should believe reports that quote things that can be traced back to sites where anybody, with no real authority, can post whatever they like and it is quoted without any question about its validity or whether it could just have been posted by someone who just wanted to make a point.

Whenever I visit such sites such as Reddit or Pastebin, looking for backup on stories that are current, I am greeted by what is largely trivial and nonsensical postings. I am not saying that some of the things that are supposed to have been posted were not there, but they are buried in a "fog" irrelevancy. 

Saturday, December 20, 2014

SE Toolkit - an Android apk

The notion that Social Engineering tools can be run from an Android device is somewhat ludicrous. At best all that you can expect on your portable device is some `crib`notes to suggest what actions you can take to fool a potential target so that you can penetrate their security system.

The whole point of SE, or Social Engineering, is that you use techniques other than those offered to you by running a program on your computer or mobile device. The SE Attack will more than likely consist of a `cold call`in which the person making the call will post as a `Security Professional`that will attempt to gain the log-on details for an employee of a corporation.

Thursday, December 18, 2014

Command and Control Servers (C&C)

A term used by sercurity specialists to make them appear that they know what they are talking about.

Mentioned in the interview on the BBC about the Sony Hack and the pulling of The Interview from US cinemas Dec 2014.

C&C servers are more associated with Botnets and DDoS attacks than the hacking of a companies email servers and the extraction of intellectual property from a corporation or film company.