Support us by visiting our sponsors and win a €20 Amazon Voucher every month

Follow maltainfosec on TwitterTwitter or RSS 2.0 feed

Jul 31

Sit back, relax and learn cryptography using CrypTool

CrypTool is a windows-based e-learning software with which can be used to apply and analyze cryptographic mechanisms used in Information Security.

It contains exhaustive online help with tutorials/scenarios, visualizations (e.g. AES, number theory, Enigma) and a comprehensive script with more detailed information about primes, hash functions, digital signatures and more.

Screenshots:


Continue reading "Using CrypTool to learn cryptography"

Posted by

4924 hits
Jul 28


With over a year of inactivity, the latest alpha of nUbuntu 8.04 Security LiveCD has finally surfaced.
All of the latest security and penetration tools are included to make this you’re primary pentesting livecd.

View Screenshots
Direct Download

More info on the 10 best security Live CD Distros (Pen-test, Forensics & Recover) here



Posted by Donald Tabone

3229 hits
Jul 25

Couple of interesting tools that seem to have been released recently:

ManTech Memory DD ManTech Memory DD captures a record of physical, or random access memory which is lost when the computer is shutdown. Released at no charge under the GPL license for government and private use, ManTech’s Memory DD (MDD) is capable of acquiring memory images from the following Microsoft® products: Windows® 2000, Windows Server 2003, Windows XP®, Windows Vista®, and Windows Server 2008.


ManTech’s Memory DD 1.0 acquires a forensic image of physical memory and stores it as a raw binary file. To help verify data integrity and aid in the preservation of the evidence, the information captured by ManTech Memory DD is checked by the Message-Digest algorithm 5 (MD5), the common Internet standard used in security applications. The binary file can then be analyzed using external tools to identify items of interest to the examiner... can be downloaded here

Suiche - of 'Sandman' fame released a memory dumping tool

The main difference between ManTech tool and win32dd, is that win32dd is mainly a kernel mode application — then it avoids to use user-land API to write to an output file, everything is done with native functions. Thus, it means a faster dumping… This point isn’t negligible when you have one million page to dump in one single.

Source1

Source2


Posted by Donald Tabone

2933 hits
Jul 17

Extracts from the original article found here... include some sane advice to those who get thrilled by the term 'hacker' by none other than the infamous Kevin Mitnick.

Reformed hacker-turned-security-consultant Kevin Mitnick served five years in federal prison for breaking into phone and software company networks. He talks about his past hacking exploits, computer security, and how he turned an illegal hobby into a useful career.


Learn the rules before you play the game. I knew hacking was sneaky when I started, but I didn't think it would get me into trouble. Back in my day, they didn't teach us about ethics in respect to hacking or using computers. Now, I tell kids to not follow in my footsteps. As computers become more accessible, there are more ethical ways to learn about computer security. Plus, there are laws now.

Use your powers for good, not evil.

Before, I was doing something exciting-but it was unauthorized and illegal. Now, I do the same thing that got me in trouble, except I do it with authorization. Clients hand me their network and tell me to break in so they can fix security vulnerabilities. To me, it's the same act but it helps my clients and it's legal and ethical, so it's a win-win situation.

Even hackers get hacked. Attackers found a way onto my Web server.

Source


Posted by Donald Tabone

1296 hits
Jul 15

The European Commission today granted its first privacy "seal of approval" to an online service, paving the way for e-businesses across Europe to certify their practices for protecting users' personal information.

The privacy seal, dubbed EuroPriSe (European Privacy Seal), is a detailed conformance and testing program designed to certify that an online service meets all of the European Union's laws and regulations regarding the handling of customer data.


In a nutshell, the seal assures the user that a Website or online business doesn't store personal data (including IP addresses) for long periods of time or monitor user behavior in ways that are not allowed under EU regulations. The seal also assures users that the personal information collected by the site is kept secure.

Is it a matter of time before we have to comply?


Continue reading "Europe Grants First Privacy Certification"

Posted by Donald Tabone

1427 hits
Jul 15


Posted by Donald Tabone

1976 hits
Jul 8

GMail

Google have added a cool feature for users of GMail - the ability to sign out from previously logged in sessions - therefore if you have the habbit of signing into GMail from multiple PC's and "forget" to logoff, scroll to the bottom of you current GMail screen and you will see the new feature titling "Last account activity: xx minutes ago on this computer. Details.."

Click the <details> link and you're presented with a list of previous sessions which allows you to quickly verify that all the GMail activity was indeed yours. To be extra cautious you can click on "Sign out all other sessions" - this way you prevent any unauthorised usage of previous sessions.

Full report can be read here

An update to the features recently released...


Continue reading "Protecting your GMail account"

Posted by Donald Tabone

3788 hits