You are currently browsing the Alan Spicer Marine Telecom Blog weblog archives for the day 2. April 2010.
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Mar | May » | |||||
| 1 | 2 | 3 | 4 | |||
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | ||
- 4. February 2012: 2012 version 4.0 Livewire Access Controller FB-10 (former product known as Livewire Service Selector)
- 28. January 2012: Alan Spicer Marine Telecom Web Sites, Products, Services ... please check them out
- 27. January 2012: WSVN, DirecTV reach deal
- 26. January 2012: "We're just like YouTube," Megaupload lawyer tells ...
- 26. January 2012: Apple Q1 results show why the iPhone doesn't have LTE—yet
- 26. January 2012: Shit Silicon Valley Says
- 25. January 2012: Amateur Radio Contact: HK0NA - Malpelo Island (80 Meters 3.770 Mhz)
- 24. January 2012: Ericsson MBR L13 and L21 - Mobile Broadband Routers - 4G LTE - Long Term Evolution
- 23. January 2012: Georgia Judge Orders President Obama to Appear in Atlanta Court!
- 23. January 2012: Ham Radio: VHF Contest - 6 Meters (50 Mhz) band was open nicely! (KA4UDX - Video recording)
- February 2012
- January 2012
- November 2011
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- April 2011
- March 2011
- February 2011
- January 2011
- December 2010
- November 2010
- October 2010
- September 2010
- August 2010
- July 2010
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
Archive for 2. April 2010
Pwn2Own Champ Tells Apple, Microsoft to Bug Off
2. April 2010 by admin.
http://www.pcworld.com/article/192439/pwn2own_champ_tells_apple_microsoft_to_bug_off.html
Pwn2Own Champ Tells Apple, Microsoft to Bug Off
Pwn2Own hacking contest winner won’t hand over 20 flaws he found by fuzzing Mac OS, Microsoft Office and Adobe Reader.
Gregg Keizer
Mar 25, 2010 4:16 pm
The only researcher to “three-peat” at the Pwn2Own hacking contest said today that security is such a “broken record” that he won’t hand over 20 vulnerabilities he’s found in Apple’s, Adobe’s and Microsoft’s software.
Instead Charlie Miller will show the vendors how to find the bugs themselves.
Miller, who yesterday exploited Safari on a MacBook Pro notebook running Snow Leopard to win $10,000 in the hacking challenge, said he’s tired of the lack of progress in security. “We find a bug, they patch it,” said Miller. “We find another bug, they patch it. That doesn’t improve the security of the product. True, [the software] gets incrementally better, but they actually need to make big improvements. But I can’t make them do that.”
Using just a few lines of code, Miller crafted what he called a “dumb fuzzer,” a tool that automatically searches for flaws in software by inserting data to see where the program fails. Fuzzing is a common technique used not only by outside researchers, but by developers to spot bugs before they release the software. Microsoft, for example, has long touted, and used, fuzzing as part of its Security Development Lifecycle (SDL), the term for its in-house process of baking security into products as they’re created.
Miller’s fuzzer quickly uncovered 20 vulnerabilities across a range of applications as well vulnerabilities in Apple’s Mac OS X 10.6, aka Snow Leopard, and its Safari browser. He also found the flaws in Microsoft’s PowerPoint presentation maker; in Adobe’s popular PDF viewer, Reader; and in OpenOffice.org, the open-source productivity suite.
Today, Miller was to take the floor at CanSecWest, the Vancouver, British Columbia-based security conference that also hosts Pwn2Own, to demonstrate how he found the vulnerabilities. He hoped Apple, Microsoft and other vendors would listen to what he has to say.
“People will criticize me and say I’m a bad guy for not handing over [the vulnerabilities], but it actually makes more sense to me to not tell them,” Miller said. “What I can do is tell them how to find these bugs, and do what I did. That might get them to do more fuzzing.” That, Miller maintained, would mean more secure software.
(more at the link above…)
Alan’s Note: There are many that will come out and say things about Apple or Microsoft being more vulnerable, Apple Fell First, Microsoft Falls Harder, blah … blah … blah … The real take out of this whole thing is that none of them are perfect. None of them are non-vulnerable. The real benefit over this thing is that each of them will learn from the security expert “hackers” and improve their products. I think that as long as there is software, there will be bugs, there will be exploits, and year after year these security expert “hackers” will keep coming out and winning contests showing that these computers (including portable smart phones) can be “owned” by an attacker … if given the appropriate opportunity.
Everyone should practice safe computing every day. I wouldn’t be in the habit of allowing anyone physical access to your computing devices, portable or stationary. Also I wouldn’t be in a habit of clicking on links, going to web sites, received via email or other forms of communications (e.g. Text Messaging, Twitter, Facebook, … and in general Social Networking sites et al. Because a huge part of hacking, of exploiting, is Social Engineering … = Tricking you into doing things that you SHOULD NOT do.) because as my friend in Orlando, Florida says:
“That’s how they get yah!”
—
Alan Spicer Telecom / Alan Spicer Marine Telecom
…Coming to a theater near you!
communications (at) marinetelecom.net
+1 954 683 3426
Posted in Main | No Comments »
Top 10 April Fools’ Day Fake News Items for 2010
2. April 2010 by admin.
Top 10 April Fools’ Day Fake News Items for 2010
Ian Paul
Apr 1, 2010 9:57 am
Artwork: Chip TaylorIt’s April Fools’ Day and tech firms and other online destinations are putting their best practical jokes forward.
Here is my top 10 list of April Fools’ jokes for April 1, 2010.
(more at the link above… including Google Animal Translator from Google UK, and the Topeka - Google Name Change spoof.)
—
Alan Spicer Marine Telecom
communications (at) marinetelecom.net
+1 954 683 3426
Posted in Main | No Comments »