This week in Infosec - 2008-09-22
September 22nd, 2008
A snapshot of what’s been talked about in the IT Security realm over the past week.
Threats/Countermeasures
I didn’t log any URL’s for this, but I’m seeing more and more about handheld device attacks.
Some vendors are coming out with adaptations to their AV products for mobile devices.
Attackers will go after the easiest vector. How safe is your device? Are you sure?
Attack Vectors/Trends
This past week I saw a bunch of alerts on @Risk regarding bypassing authentication using cookie and session manipulation.
It reminds me that every input that comes from the user should be treated entirely as untrusted. Verification and Validation are required.
Last week I learned that the View State mechanism that Microsoft .NET uses to store data in the browser is stored in simple base 64 encoding - so even this could, in theory, be an attack vector from the client not to mention the obvious information disclosure potential.
If the user can touch it, we better be doing V&V on it.
News and Analysis
Super-collider hacked
DHS cant’ do cyber security.
Some pondering if NSA should take over the gig
Palin’s email account hacked.
The attackers appeared to be hiding their activities behind an anonymous web proxy while they performed their deeds.
That proxy service (Ctunnel) is cooperating with authorities.
I agree with the proxy service’s position to help the investigation. We all have a basic right to privacy, and proxy services can provide this, but we do not have the right to commit a crime without threat of prosecution.
The proxy service is making the statement, “you can be safe from prying eyes here, but don’t cross the line.”
I can get down with that.
Looks like Michelle Malkin got the scoop on how the attack transpired.
From the web - surprising political bias showing in the coverage from the blogosphere…
- Sarah Palin’s right to privacy?
- Wikileaks: Sarah Palin Yahoo Account Hacked, Posted
- Sarah Palin’s Yahoo account hijacked, e-mails posted online
- “Anonymous” hackers expose Palin’s e-mail
- Palin Yahoo Email Hacked
- Hey, it can happen to anyone ;-)
- Attacker: Hacking Sarah Palin’s email was easy
Tracking the attacker:

