网页聚合

Infocon: green

isc.sans - 周四, 11/20/2008 - 22:10
Large quantity SQL Injection mitigation
分类: 安全动态

VoIPshield 10.08.08 and 11.11.08 Vulnerabilities

voipsec - 周四, 11/20/2008 - 22:09
Dustin D. Trammell: VoIPshield 10.08.08 and 11.11.08 Vulnerabilities: Since I've been fairly vocal regarding VoIPshield's questionable advisory practices in the past, pointing out their blatant advisory duplication tactic that essentially turned a handful of single vulnerabilities into an exponential number of extraneous associated [...]
分类: 安全动态

If you are out at VoiceCon this week in San Francisco...

voipsec - 周四, 11/20/2008 - 22:09
Dan York: If you are out at VoiceCon this week in San Francisco...: .... I am there too (currently flying cross-country). Feel free to drop me a note if you want to meet somewhere at the show. <br /> Jonathan Zar and I are also planning to meet and maybe even do a live BlueBox episode. <br /> Dan <br /> Sent from my iPhone <br />
分类: 安全动态

UCSniff VoIP v1.0 Tool Released!

voipsec - 周四, 11/20/2008 - 22:09
Jason Ostrom: UCSniff VoIP v1.0 Tool Released!: http://ucsniff.sourceforge.net <br /> Sipera VIPER Lab has finally released UCSniff. <br /> Have a great weekend. Jason <br />
分类: 安全动态

Cybercrooks making easy money from virtual worlds

theregister - 周四, 11/20/2008 - 21:05
EU agency launches campaign

Online gamers have become a soft target for cybercrime, with three in 10 users reporting the loss of items of virtual property through fraud.…

分类: 安全动态

Quotes of Security 3

zhaol(赵粮) - 周四, 11/20/2008 - 15:19
“You don’t know who is swimming naked until the tide goes out.” In our world, we don’t know whose systems are running naked, with no controls, until they are attacked. Share To:

Theme changed to Clean Press

zhaol(赵粮) - 周四, 11/20/2008 - 14:37
I changed the theme to “Clean Press“. It’s very simple, concise, crisp. As Dave said it focuses on content. I slightly modified it by changing the sidebar to right. If you like this one, Click to download Clean Press (right sidebar). Share To:

Large quantity SQL Injection mitigation , (Thu, Nov 20th)

isc.sans - 周四, 11/20/2008 - 13:00
Normal 0 false false false EN-CA ZH-TW X-NONE ...(more)...
分类: 安全动态

How to Handle DDoS Incidents?, (Wed, Nov 19th)

isc.sans - 周四, 11/20/2008 - 12:58
The incident handling cheat sheets in an earlier diary applied to many types of security incidents. ...(more)...
分类: 安全动态

An Ad for DDoS Services - Network, Phone, Competition, (Wed, Nov 19th)

isc.sans - 周四, 11/20/2008 - 12:57
The oldfashioned way to launch a network DDoS attack involved building one's own bot network that wo ...(more)...
分类: 安全动态

[Chinese]百度变态“竞价”会输掉竞争

zhaol(赵粮) - 周四, 11/20/2008 - 12:11
近日,央视接连两天对百度竞价排名的弊端进行了报道,各大媒体也没有放过这个机会,百度的媒体形象一度跌入低谷。联系到Google深入人心的“不作恶”形象,两形之下,给人高低立判之感。当公司发展到一定阶段,“民心所向”和“政治”就成为一个非常重要的环节。 虽然百度在国内市场占有率遥遥领先,但是由于其“竞价”方式的排名,搜索结果往往让人难以接受,从而放弃。尤其是专业人士,很依赖搜索结果的公正和客观,如果发现搜索出来的是一个报价的排名,还不如直接看广告了。 我在Google和百度上面分别搜索“信息安全”和”Security”,搜索结果大家一看就可以感觉到百度“竞价”排名对你的嘲弄: 1 百度搜索 “Security” 看不懂百度搜出来的是什么东西。好,百度是中文搜索引擎,搜索英语属于分外要求,暂且放下。 2 Google搜索 “Security” 3 百度搜索 “信息安全” 轮到中文了,可是看到的还是个广告版。 4 Google搜索 “信息安全” 感兴趣的话,不妨试一试在你的关键词上试一试。 Share To:

Congratulations, Barack - Now fix your websites

theregister - 周四, 11/20/2008 - 10:24
Change? Start with security

President elect Barack Obama's embrace of online video and social networking may have propelled him to victory, but unless he's careful, his administration could be brought down by the same sloppy security problems that have plagued MySpace, Facebook, and dozens of other Web 2.0 properties.…

分类: 安全动态

[Chinese]奥巴马胜选演说·文言版

zhaol(赵粮) - 周四, 11/20/2008 - 09:38
朋友分享来的”东东枪”译版的奥巴马选举胜利后的演说稿,非常精彩。与大家共享: Hello,Chicago! 芝城父老,别来无恙, If there is anyone out there who still doubts that America is a place where all things are possible, who still wonders if the dream of our founders is alive in our time, who still questions the power of our democracy, tonight is your answer. 余尝闻世人有疑,不知当今美利坚凡事皆可成就耶?开国先贤之志方岿然于世耶?民主之伟力不减于昔年耶?凡存诸疑者,今夕当可释然。 It’s the answer told by lines that stretched around schools and [...]

Are We Doomed?, (Wed, Nov 19th)

isc.sans - 周四, 11/20/2008 - 07:38
In no particular order: We Are Doomed ...(more)...
分类: 安全动态

2 Cheat Sheets for Incident Handling, (Wed, Nov 19th)

isc.sans - 周四, 11/20/2008 - 03:40
People only see what they are prepared to see. -- Ralph Waldo Emerson Maybe your syste ...(more)...
分类: 安全动态

Computer virus quarantines London Hospital for second day

theregister - 周四, 11/20/2008 - 00:51
Plucky Brits shrug off Mytob network blitz

IT staff at three major London hospitals have spent a second day struggling to restore IT systems following a major computer virus outbreak.…

分类: 安全动态

dz终于出补丁了

superhei - 周四, 11/20/2008 - 00:34

这个就是传说中的:不见棺材,不掉泪? 前面我在dz论坛苦苦却说他们早出补丁的.....

http://bbs.chinaz.com/Club/thread-1192527-1-1.html

http://www.discuz.net/thread-1113736-1-1.html

具体补丁了那些bug 还没时间去看 有兴趣的朋友对比下 告诉我 :)


类别:默认分类 查看评论

Security Awareness Training is Boring, (Wed, Nov 19th)

isc.sans - 周四, 11/20/2008 - 00:19
I love the directness of Marcum Ranum's perspective on security awareness training. If it was ...(more)...
分类: 安全动态

Lame Mac Trojan limps into view

theregister - 周三, 11/19/2008 - 21:54
Malware targets grumble-flick fans

Security researchers have uncovered a rare example of a Trojan that affects Mac PCs.…

分类: 安全动态

近来江湖多凶险,有线无线都危险

tombkeeper - 周三, 11/19/2008 - 21:07
加固保安全,改改更健康:

1、打开secpol.msc,把“网络安全:LAN Manager 身份验证级别”修改为“仅发送 NTLMv2 响应\拒绝 LM 和 NTLM”:



2、打开你的AP的配置界面,修改WPA的加密方式为AES(大多数AP默认都是TKIP):

阅读全文
类别:技术探索 research 查看评论
聚合内容

快速链接

JSky
Pangolin
Pangolin帮助手册
渗透测试

投票

赞助

NOSEC所有开发的安全工具和资源都是免费的,以后也都会免费。如果您认为这些工具和资源对您有所帮助的话,您可以考虑进行一些赞助。您的支持将加快开发进度以及版本更新的速度,同时也能够让我们有动力开发更多的安全工具来支持您的工作 ;)
赞助你们我有什么好处?

用户登录